Protecting AI in retail: risks, best practices and lessons from the automotive sector
AI is already part of a wide range of retail processes, from customer service and conversational assistants to personalised offers, sales automation and support for internal operations.
At the same time, as these tools gain access to corporate information, connect to other systems or become involved in business processes, their security increasingly depends on the data, permissions, integrations, processes and people involved in how they are used.
David Alonso, Cybersecurity Practice Manager at Telefónica Tech, addressed this challenge during his participation in Faconauto's 2nd Observatory on Innovation, AI and Technological Transformation with his presentation “Protect your AI”. His central message was that, to use AI more securely and with greater confidence, businesses first need to understand where it is being used, how it connects to their operations and what needs to be protected.
David Alonso (Telefónica Tech) presenting his session, 'Protect your AI'
The presentation followed a practical sequence: begin with familiar scenarios, analyse what could go wrong and finish with measures that companies and their teams can apply. Although the examples come from automotive retail, many of the risks are common to other businesses that use AI in their interactions with customers, employees or suppliers.
AI security does not depend on the model alone: it also depends on the data, permissions, integrations, processes and people involved in how it is used.
When a chatbot is no longer just a customer service channel
One of the examples David used to open the discussion was the well-known case of a user who managed to get a car dealership chatbot to generate a response agreeing to sell a car for one dollar. Although the incident did not result in an actual sale at that price, it demonstrated something more significant than the anecdote itself: a publicly accessible AI assistant can be manipulated into behaving in ways it was not designed for.
That risk is not limited to car dealerships. It can arise in an ecommerce chatbot, an after-sales service or an internal tool used by employees. Its potential impact increases when AI moves beyond simply generating a response and starts retrieving information, interacting with other applications or becoming part of a sales process.
At that point, business need to assess what the AI has access to, what it can do and what the consequences would be if its behaviour were manipulated.
When an assistant can access information or act on other systems, the risk is no longer limited to what it says.
What can go wrong when AI is deployed in retail
David's presentation focused the analysis on four main areas: data leakage, fraud or reputational damage, denial of service and LLMJacking, with an additional dimension specific to the automotive context: road safety.
Because not all threats follow the same logic or require the same measures, it is important to avoid treating them as a single category of “AI attacks”.
Manipulating an assistant to access information it should not reveal
One of the best-known threats affecting AI models is prompt injection: instructions designed to alter the system's intended behaviour, bypass certain controls or cause it to misuse the information or tools available to it.
It is related to jailbreaks, although the two are not exactly the same. Jailbreaks primarily aim to make a model ignore the restrictions under which it has been configured and generate responses that should otherwise be blocked. In our Secure Journey to AI paper, we distinguish between these two forms of manipulation and place them alongside other techniques designed to extract information or compromise model behaviour.
In an enterprise environment, the important issue is not simply whether the chatbot produces an unexpected response. If it can access corporate information or use other tools, those permissions may also be exploited.
■ Data leakage can occur even without a sophisticated attack. An employee may enter sensitive data into an unauthorised tool, one of the risks associated with Shadow AI, while a misconfigured application may return information to users who should not be able to see it. In retail, this means monitoring both what is entered into a tool and what that tool is able to access or return.
When AI enables fraud or brand impersonation
Risk can also arise around the brand, its channels and the trust customers place in them. In this respect, David's presentation also focused on fraud and reputational damage. One of the examples shown in the analysis was the cloning of dealership websites to advertise non-existent vehicles: a fraudulent website imitates the appearance of a legitimate company and exploits that trust to deceive users.
It is a pattern that is easily transferable to the wider retail sector. It may take the form of a fake store, a non-existent promotion, a fraudulent customer service channel, a fake advert or even a QR code that directs the user to a page designed to steal information or obtain a payment.
AI can make these types of content easier to create and adapt, and the risk to a company does not always depend on its own systems having been compromised. A customer may associate the fraudulent experience with the brand being impersonated, leading to complaints, loss of trust and reputational damage.
■ Protection should not be limited to a business's own applications. It is also important to monitor fraudulent use of the brand, its channels and communications with customers or employees.
Availability and LLMJacking: two different forms of resource abuse
Denial of service also appears explicitly among the risks discussed in the presentation. An excessive volume of requests or intensive resource consumption can degrade an application and affect a customer service channel, online store, sales platform or internal process that depends on it.
LLMJacking, sometimes described as the theft or misuse of access tokens, starts from a different scenario. In this case, a third party gains access to legitimate credentials, keys or access mechanisms and uses them to use AI model services without authorisation.
The impact may take the form of an unexpected increase in usage and costs and may even reduce the resources available to legitimate users.
■ Both problems can ultimately affect service continuity and the business, but they need to be understood differently: one focuses on degrading or exhausting capacity, while the other involves unauthorised use of that capacity.
Digital risk can have consequences in the physical world
The automotive sector introduces an additional dimension. Given the context of the presentation, David specifically highlighted road safety risks alongside the other threats.
This risk can be illustrated by so-called adversarial attacks targeting traffic-sign recognition: modifications designed to try to alter how a vehicle's computer vision system interprets a sign.
The example helps illustrate an important distinction. In some AI applications, manipulation does not necessarily end with an incorrect response or data leakage: it can affect how a system perceives its physical environment.
This does not mean that any alteration will compromise any driving system. Robustness depends on the model, the design of the solution and the security measures in place. But it does show why, when AI is involved in functions related to vehicles, machinery or other physical systems, risk assessment must also consider the potential consequences beyond the digital environment.
What is an 'adversarial attack'? From automotive to retail
The example of altered traffic signs helps explain how a visual modification can attempt to change the way a computer vision system interprets what it sees. Scenarios of this kind have been analysed in experimental tests involving traffic signs, in which certain patterns, stickers or physical modifications can affect the detection of some signs.
The same principle can extend to other systems that rely on computer vision, including in retail; for example, applications may be used for product recognition and assessment, inventory control, loss prevention or interactive experiences such as virtual fitting rooms. In these cases, it is important to assess whether certain visual inputs (images, patterns, labels or changes to the environment) could alter the system's expected behaviour.
However, not every visual manipulation is an adversarial attack. Replacing a legitimate QR code with one that directs users to a fraudulent website is a different type of attack, although it illustrates a related issue: when a retail experience connects the physical environment with digital systems, it is also important to protect the elements that people and machines use as entry points.
Key AI risks in retail and one shared challenge: protecting information, operations and customer trust.
Data leakage, fraud, denial of service and LLMJacking do not follow the same logic; each risk requires its own analysis and response.
Protecting AI requires technology, processes and people
The response requires a combination of technical measures, clear processes and good practices. David highlighted secondary verification, awareness, digital hygiene, recognising social engineering, identity verification and immediately reporting anomalies, as well as the importance of working with trusted technology providers and partners.
These recommendations may appear straightforward, but they reflect an important point already mentioned: many incidents do not begin with an exceptionally sophisticated vulnerability. They may start with exposed credentials, a poorly verified identity, a transaction that no one verifies or an employee entering information into a tool they should not be using.
From there, technical protection needs to be adapted to the context of each application.
Knowing where AI is being used and what it can do
Before protecting an AI application, a business needs to know where it is being used and what role it plays. A retailer needs to understand which solutions it uses, what information they handle, who can access them and what actions they can perform.
This includes both tools approved by the company and those that may have been adopted in day-to-day work without formal approval.
Not all of them require the same level of protection. An assistant that works only with public information does not pose the same risk as one connected to customer data, internal systems or processes capable of acting on other systems.
■ Before deploying an AI application, it is advisable to review its integration points and test how it responds to malicious or unintended use. This analysis may include testing against prompt injection, API reviews, access-control assessments, and adversarial testing techniques.
Limiting access and verifying sensitive actions
When an application needs to access corporate information, its permissions should be limited to what it genuinely needs to perform its function.
This means applying principles such as explicit verification and least-privilege access, protecting credentials and human and non-human identities, classifying sensitive information and using controls that help reduce the risk of data leakage. Measures within this approach include multi-factor authentication, access policies, data loss prevention and activity log reviews.
But control does not have to be purely technological. The double-checking highlighted by David is particularly relevant when an action has financial implications, modifies sensitive data or could directly affect a customer.
■ Although AI can help automate decisions and processes, that does not mean that all of them should be carried out automatically and without human oversight.
Preparing people to recognise deception
The techniques may evolve, but social engineering continues to exploit familiar mechanisms: urgency, trust, authority and impersonation.
The ability to generate text, images and other content quickly can make fraud attempts more convincing. Teams need clear criteria for recognising warning signs and knowing when to escalate a concern.
■ Checking the source of a request, verifying an identity through a second channel when an action is sensitive and reporting any anomaly as quickly as possible remain highly effective measures.
Detecting and responding when something does not look right
No control eliminates risk completely. In addition to prevention, businesses need the ability to detect anomalous behaviour act before an incident escalates.
Logs and monitoring make it possible to investigate an incident and determine which users, data or systems may have been affected. Depending on the circumstances, it may be necessary to revoke a credential or token, temporarily restrict a capability, block an integration or correct a configuration.
This approach can be understood as a continuous improvement cycle: identify risks, adjust controls and learn from every incident or deviation detected.
■ It is also important to know in advance who needs to act. If an application depends on models, Cloud services or external providers, response channels and responsibilities should be clear before an incident occurs.
Protecting AI requires knowing what is being used, limiting what it can do, verifying sensitive actions and preparing teams to recognise warning signs.
Conclusion
AI can improve customer service, automate tasks and optimise retail processes. These benefits coexist with specific risks: manipulated assistants, data leakage, brand impersonation, resource abuse and, in certain areas such as automotive or industry, potential consequences beyond the digital environment.
Applying controls without understanding the specific use of each tool only adds friction. The starting point is knowing where AI is being used, what role it plays and what would happen if someone managed to use it in a way that was not intended.
In retail, adopting AI requires more than simply choosing a tool or enabling a new channel. The difference lies in deploying it with clear boundaries, protected data and a genuine ability to act when risk emerges.
■ At Telefónica we support businesses throughout this process by combining risk analysis, protection measures and response capabilities across the entire AI lifecycle. Our Secure AI proposition helps structure the secure adoption of AI across three complementary areas: identifying risks, protecting against threats and responding when something deviates from what was expected.
______
Cloud & Business Apps
Cybersecurity
Data & AI
IoT & Connectivity
Industry
Health
Banking and Finance
Public Sector
Retail
Tourism and Leisure
Transport & Logistics
Energy & Utilities
Smart Cities
