Five Steps to AI & LLM Security for Agri-Food

A practical guide for agribusiness leaders adopting AI with confidence.

Every executive I speak with these days seems to sit somewhere between excited and uneasy about AI. On the upside, they have watched AI tools such as ChatGPT, Copilot and Gemini find and analyze information, draft reports, and compress days of work into an afternoon. On the other hand, they’ve started wondering (often late at night) whether a nutritionist pasted a proprietary feed formulation into a public chatbot, or a salesperson uploaded a customer list to get help writing a pricing email, and if that information can leak.

Both reactions are justified.

AI is rapidly becoming part of how agribusiness competes. The World Bank’s Harnessing Artificial Intelligence for Agricultural Transformation describes its growing role across crop forecasting, food security and farm-level decision-making worldwide.

But the risks are real too.

The good news is that the greatest AI risk facing most businesses isn’t the technology itself, it’s how people use it. And just as organizations have had to adapt their processes to reflect other new technologies (from telephones to the internet), there are steps you can take to contain that risk, while still getting the benefits.

Putting in good governance mechanisms takes care and leadership from the top but get it right and it will give your team the confidence and freedom to use AI effectively. Governance isn’t a brake pedal on AI adoption: it’s what lets you press the accelerator with confidence.

Here are five steps you can put into place to get the best from AI while avoiding the worst:

1. Write your AI policy before your employees write their own

If you don’t tell people what’s acceptable, they’ll decide for themselves — usually by trial and error, with whatever tool happens to be open in another browser tab.

Don’t make a big, comprehensive AI manual. Instead, start with a one-page policy covering three things:

  • what can and cannot go into an AI tool?

  • which platforms are approved?

  • who to ask when in doubt.

NIST’s AI Risk Management Framework provides a useful structure for thinking about governance, risk and accountability. Just don’t let perfection become the enemy of useful. A clear policy that people actually read beats a comprehensive one they don’t.

2. Lean into the enterprise AI you already have

Many agribusinesses already own a secure AI option and haven’t realized it.

For example, if your company runs on Microsoft 365, Copilot works within the permissions you’ve already established: It doesn’t give an employee access to a confidential HR file simply because they ask AI to find it; it can only surface organizational data that person already has permission to access.

Before buying another AI subscription check to see if the tool you already pay for is sufficient for your needs.  Rather than chasing every new model, choose tools that fit your existing workflows and learn to use them well. Often, the safest AI tool is the one already sitting inside your existing systems.

Of course, that means making sure that the existing permissions are good ones, so review them before connecting AI to sensitive data. If your employees can access information they shouldn’t, connecting AI can make that problem much more visible, because information becomes dramatically easier to find, summarize and circulate. So, before connecting AI to sensitive business data, audit who can see what.

The same principle applies to third-party systems. Outsourcing an AI capability doesn’t outsource responsibility for what it does. A processing plant’s food-safety records or a feed mill’s formulation library should carry the same restrictions in an AI-connected environment that they did before AI arrived. AI hasn’t changed who should have access, but it has changed how quickly information can move once they do.

3. Train your team to prompt with care

There are three things your team needs to understand: which tools they can use, what information they can put into them, and what information they may be revealing without realizing it.

First, and most critically: make sure that you and your team know what tools they can use.

To do that, you need to know the terms of your AI platforms. Tools that look very similar on screen can have very different rules about what happens to the information you put into them. Before approving a platform, make sure you know the answers to a few basic questions:

  • Can our data be used to train the model?

  • How long is it retained? Who can access it?

  • What security and privacy controls are available?

Don’t assume that the free version an employee uses at home offers the same protections as a business or enterprise account. Choose the level of protection appropriate to the information your people will be putting into it. Using the wrong tool can cost considerably more than the price of an enterprise subscription.

Have your IT lead or a trusted advisor explain the distinction to your leadership team in plain English, so that they can make decisions about what products to use and then make sure that your employees understand what platforms they can and can’t use- and why. You probably don’t want a worker in the field asking ChatGPT a quick question on the free chatbot they use on their phone!

Next, make sure that your team understands what confidential information looks like in your organization. This needs to be very specific: nutritionists, salespeople and plant managers handle very different data, so be explicit and train accordingly.

Finally, understanding that the implicit information in a prompt can be revealing is important. For example, if a grain merchandiser asking an AI tool to “analyze this position against our current basis strategy” they have unwittingly just revealed the strategy.

Treat a prompt with the same discipline you’d apply to an email or shared drive. If you wouldn’t send it to a competitor, don’t type it into a prompt. Most employees don’t intend to leak sensitive information. They don’t think of a prompt as something that can give away proprietary data. It is.

4. Monitor the interface between your company and AI

Knowing what company information is going out into the world, and where it is going, is a logical extension of the controls you already apply to other communication platforms.

Internally, it means accepting that your employees are going to use AI, and you would rather they not do it on their personal accounts! So, provide approved tools people genuinely want to use, track broad usage patterns and periodically review how AI is being applied. Give employees a safe road and most will use it. Visibility protects a business better than prohibition.

Externally, make sure that you know what your vendors are doing with your information.  Any AI or software vendor working with your business should be able to answer three questions clearly:

  • Does our data train your models?

  • How long do you retain it?

  • Who can access it?

And don’t ask only the obvious AI platform providers: the same questions apply to feed formulation software, herd-management systems, precision livestock platforms, grain-merchandising tools and other specialist applications that increasingly incorporate somebody else’s AI model behind the scenes. If a vendor answers basic data questions with marketing language rather than specifics, treat that as a red flag. A vague answer about data handling is a data risk, not a communication problem.

5. Make AI governance an executive responsibility

The risks and rewards associated with integrating AI tools into your organization can’t be delegated away from senior management. The IT department oversees systems that collect, manage and distribute information, and many executives are happy to let them at it.

As AI becomes more deeply integrated into company systems and increasingly influences consequential decisions, governance can no longer be treated simply as an IT responsibility. Someone at leadership level needs to own it, just as someone owns food safety, financial controls or cybersecurity.

In particular, it is critical to keep a human accountable for consequential decisions. AI models are remarkably capable. They can also fabricate information with remarkable confidence. NIST calls this “confabulation”; most of us know it as hallucination. A sustainability report containing an invented emissions figure or a ration based on a hallucinated nutrient value can do real damage before anyone notices.

AI can help people make better decisions about livestock health protocols, customer contracts or capital investments, but it shouldn’t make consequential decisions unsupervised. This is true for any system-supported decision process: a person still needs to own the decision.

You don’t necessarily need a ‘Chief AI Officer’ role: deciding who in the leadership team is accountable for policy (including the approval process of consequential decisions), approved tools, training, vendor standards, and periodic review is probably enough.

Conclusions

What leadership prioritizes, the organization adopts. What leadership ignores, the organization improvises around. Usually badly.

The objective isn’t zero risk, it’s prudent use. None of this requires an agribusiness leader to become a technologist. It does require the same discipline businesses have always applied to protecting genetics, formulations, customer relationships, financial information and reputation, etc., just extended to a new category of tools.

The companies that get this right won’t simply avoid AI-related mistakes. They’ll move faster. While competitors are still debating whether to allow AI in the building, your people will already understand what they can use, which tools they can use it with, what information needs protection and when human judgment must take over.

That may turn out to be the real competitive advantage in the next phase of agribusiness AI: not simply having access to the technology but having an organization confident enough to use it well.

Thanks to Camila Ulloa for writing and researching, Kate Phillips Connolly for substantial edits condensing from 10 to 5 steps, and to Shail Khiyara, David Hunt, John Power for their comments and contributions.

Previous
Previous

Agriculture Has Adopted AI. So Why Isn't It Transforming the Industry?

Next
Next

AI’s Bullet Train Moment – Are you, your business ready?