Why RAG creates a new security boundary
Retrieval-augmented generation (RAG) enables AI systems to answer questions using enterprise documents, knowledge bases and other external sources. That additional context can improve relevance, but it also creates a security boundary that conventional application controls may not fully address.
A RAG system can retrieve poisoned content, expose information across authorization boundaries, follow instructions hidden in documents, or produce outputs that trigger unsafe links, tools and external requests. These risks span the complete pipeline: ingestion, chunking, embedding, retrieval, context assembly, generation and output delivery.
The new Retrieval-Augmented Generation (RAG) Security Cheat Sheet provides a practical guide for securing that pipeline without treating any checklist, framework or model-layer defence as a guarantee.
What the practitioner resource covers
- A structured RAG threat and risk landscape
- Secure architecture and implementation patterns
- A 24-control security matrix
- Detection, monitoring and incident-response guidance
- Audit evidence and assurance questions
- Implementation checklists and release gates
- Lessons from documented RAG security research and incidents
One security lifecycle across three frameworks
The guide places three complementary operational frameworks at the centre of the security lifecycle. The Global AI Safety and Security Framework (GAISSF™) structures security controls and assurance expectations. The Unified AI Incident Framework (UAIF™) records incident identity, classification, assumptions and evidence limitations. The AI Incident Response Framework (AI-IRF™) connects detected RAG failures to containment, investigation, recovery and improvement.
Together, these mechanisms help teams move from high-level AI principles to controls that can be implemented, tested and evidenced. They do not establish that retrieved content is true, safe or authorized merely because it is relevant.
Designed for implementation and review
Whether you design RAG applications, review their security or govern their deployment, the cheat sheet can help identify weak points before production release. It covers the entire boundary rather than treating vector-store configuration as the complete security problem.
Use it alongside the Vector Database Security Checklist and AI Security Incident Response Playbook to connect retrieval controls with datastore protection and incident handling.
