Restrict who and what can reach AI models, APIs, and training pipelines. The principle: a credential or token should be the smallest possible footprint for the task it enables.
SPECIFIC ACTIONS
- Enforce least-privilege API keys scoped per model endpoint; rotate on a 90-day maximum cycle
- Require MFA on all accounts with access to training data, model registries, and inference APIs
- Implement service mesh mTLS between AI microservices to prevent lateral movement
- Audit and prune stale service accounts in ML pipelines quarterly
- Gate model-management consoles behind jump hosts or PAM vaulting, not VPN alone