Analysis and Design of a Framework Handling Information Security in AI‑Powered Service Bots
DOI:
https://doi.org/10.70917/ijcisim-2026-4343Keywords:
AI-powered service bots, information security, framework, security threatsAbstract
While AI-powered service bots have become an important building block in digital service delivery-e.g., in banking, healthcare, e-commerce, and public services-their pervasive handling of sensitive personal and transactional data opens up new information security risks. Recent incidents involving conversational AI systems have demonstrated many vulnerabilities related to data leakage, prompt injection, model inversion, and insecure integration with the host's legacy backends, challenging the traditional security controls designed for static web applications rather than continuously learning AI stacks. This paper analyzes contemporary information security threats specific to AI-powered service bots, and reviews state-of-the-art security mechanisms and standards for proposing a layered framework, which integrates secure model lifecycle management, privacy-preserving data pipelines, robust identity and access management, and continuous security monitoring. The framework is conceptually validated for its properties by mapping it against a taxonomy of chatbot information security dimensions and current best practices, thus proving its appropriateness for improving confidentiality, integrity, availability, and trust in AI-enabled services with the support for regulatory compliance and scalability in its deployment.