SolutionsWorkshopsBlogNewsAboutLet's Talk
HomeNewsAI security and governance
Security

NIST: Mathematical proof against one-time AI security

NIST mathematical proof shows you cannot secure an AI system once and close the project. Organisations must shift to continuous monitoring and updates.

Automush
Published 31.07.2026
What this means for your business

If you are commissioning or building an AI system, demand a continuous monitoring and update plan from your vendor, not just one-time delivery. This changes the pricing model: instead of a one-off payment, budget a monthly cost for maintenance and defence updates. Ask to see how the vendor plans to identify and handle adversarial prompts over time.

On 9 June 2026, NIST published a mathematical proof showing that a fixed set of guardrails placed on an AI system cannot universally withstand adaptive adversarial prompts. The proof extends the logic of Gödel’s incompleteness theorems to AI. The findings show that developers and organisations operating AI systems must dedicate resources to finding prompts that could bypass defences, and shift from a one-time security model to continuous monitoring and updates.

What NIST proved

NIST’s mathematical proof shows that it is impossible to build a final, perfect defence system for an AI application. Similar to Gödel’s incompleteness theorems, which proved that any sufficiently powerful formal system contains statements that cannot be proven or disproven within it, an AI system with a fixed set of guardrails will always be vulnerable to new adversarial prompts. This is not an engineering failure that can be fixed, but a built-in mathematical limitation.

The practical implication is that every organisation operating an AI system must dedicate ongoing resources to identifying prompts that could bypass existing defences, and update the system accordingly. A “one and done” model - where you build a system, add defences, and close the project - does not pass the mathematical test.

Why this changes the procurement model

Most organisations in Israel commissioning an AI system treat it like a regular software project: one-time budget, delivery, warranty for a limited period. NIST’s proof shows this is insufficient. A bank commissioning an AI system for risk analysis, an insurance company building a customer service chatbot, or a government body operating a system for processing requests - all must understand they are committing to an ongoing process, not a one-time project.

This changes tender requirements and pricing models. Instead of requesting “a secure AI system”, you should request “a continuous monitoring and update plan”, with a clear definition of testing frequency, response times to new threats, and a mechanism for updating guardrails. Instead of a one-time budget, you need to budget a monthly or annual cost for security maintenance.

What to do this week

If you are in the process of procuring an AI system, add a section to your requirements on continuous monitoring and updating of defences. Ask the vendor to present how they plan to identify adversarial prompts, how frequently they will test the system, and what their response time is to a new threat. If you are already operating an AI system, check with the vendor whether there is an existing monitoring plan, and if not - demand one.

In the systems we build, monitoring and updating defences are a built-in part of the agreement, not an optional add-on. This is not a matter of good service, but an architectural requirement arising from the mathematical limitations of the systems themselves. If you need to build an AI system under banking security and regulatory standards, it is worth consulting with someone who understands the difference between AI agents for business built with embedded governance and tools designed for demonstration only.

Sources

Frequently asked

How much does continuous monitoring and updating of an AI system cost?

It depends on the type of system and regulatory requirements, but a rule of thumb is 15-25% of initial development cost per year. A bank or insurance company with high security requirements will need to budget more. It is important to include this cost in the ROI calculation from the start.

Does a simple customer service chatbot need continuous monitoring?

Yes, if it is connected to sensitive information or internal systems. Even a "simple" chatbot can be vulnerable to prompt injection that causes it to expose information that should not be accessible. The frequency and depth of monitoring depend on the level of risk.

Want to know what this means for you?

A short call, no commitment, and we will tell you whether it is relevant to your business or not.