Securing AI together: GitLab’s... Note
GitLab

Securing AI together: GitLab’s partnership with security researchers

GitLab's Senior Director of Application Security is focused on protecting customers from software vulnerabilities, a mission amplified by AI's role in development. AI platforms enhance productivity but also introduce new security challenges like prompt injection attacks. These attacks can manipulate AI into making harmful recommendations or taking unintended actions. GitLab proactively addresses these risks by working with external security researchers, such as Persistent Security. This collaboration is crucial for identifying and mitigating AI-specific threats.GitLab emphasizes transparent collaboration, detailing its AI ethics and development practices in its AI Transparency Center. When Persistent Security identified a significant prompt injection issue, GitLab's Product Security Response Team quickly investigated and implemented necessary mitigations. These fixes were deployed before the public beta of the GitLab Duo Agent Platform. External researchers are vital for staying ahead of rapid AI threat evolution and providing real-world testing insights. Their diverse expertise and innovative approaches strengthen GitLab's security posture.GitLab remains committed to supporting the security research community by offering clear guidance, maintaining rapid response times, and sharing learnings. The future of AI security relies on this collaborative effort. GitLab encourages researchers to participate through its HackerOne program and learn more at its AI Transparency Center. The director will be available at Black Hat 2025 to connect with AI security researchers.