AV Does Not Need a New Security Model. We Need to Use the One We Already Have

By Richard Jonker, vice president of commercial business development at NETGEAR
David Danto’s recent piece on rAVe, “The Weakest Link Is Listening,” makes a warning AV needs to hear: microphones, cameras, displays, video bars, smart glasses and AI recorders are endpoints, and they can leak some of the most sensitive information in the building. That warning is right. Where we differ, based on our experience, is the conclusion that AV needs a new security model. From my perspective, it does not. The model already exists; it simply has not received the attention it needs in AV environments.
The networking and IT security industries have spent decades dealing with untrusted endpoints, uncontrolled applications, data exfiltration and compromised supply chains. We have moved from perimeter firewalls and air-gapped networks to VLANs, network access control, microsegmentation, secure access service edge (SASE) and zero-trust architectures. None of it is perfect; we are dealing with people. Together it adds up to a mature playbook for containing exactly this kind of risk.
The problem is that AV keeps exempting itself from that playbook.
Stop Connecting AV Devices as If They Were Trusted Appliances
A smart display is a computer. So is a video bar, a networked camera, a DSP and an AI-enabled room controller. And everyone’s cellphone. That does not make these products inherently dangerous. It makes connecting them to a general-purpose corporate network with broad outbound access indefensible.
Good network design starts with separation. Audio and video devices should run on purpose-built network infrastructure or, at minimum, tightly segmented AV networks with their own VLANs, access control policies and management boundaries. Devices should not be able to discover or reach finance systems, engineering repositories, HR platforms or arbitrary user endpoints just because they share a building.
For the most sensitive spaces, including boardrooms, M&A rooms, government facilities and product-development labs, physical separation or an air-gapped design can still be justified. The value of what gets discussed in these rooms justifies the extra isolation.
Segmentation alone is not security.
A VLAN without enforced policy is just a different address range. Network access control should identify every device before admission. East-west traffic should be limited to defined dependencies. Management interfaces should be reachable only from authorized administration systems. Default passwords, shared credentials and dormant services should have disappeared years ago.
The design principle is simple: an AV endpoint gets only the connectivity it needs to do its job, nothing more.
Allowed Traffic Still Needs Scrutiny
Many AV compromises and data leaks will not look like attacks. The device may use a legitimate encrypted session to talk to a legitimate vendor cloud. An employee may use an authorized browser to send a recording to an unauthorized AI service. A meeting bot may walk in the front door because somebody clicked “allow.”
That is why filtering only known-malicious traffic is not enough. Inbound and outbound traffic should be restricted, logged and, where technically and legally appropriate, inspected, even when the destination looks fine. Approved does not mean permanently trusted.
Use destination allowlists, DNS filtering, egress controls, application-aware firewalls and cloud access policies. Baseline expected device behavior and investigate deviations. If a conferencing camera normally talks to three known services, why is it suddenly opening a session to one it has never talked to before? If a display needs no internet access, why give it any?
SASE and security service edge controls extend the same discipline past the building’s walls: identity, data loss prevention and cloud access policy applied to users and devices wherever they connect. Zero trust finishes the job. Authenticate explicitly. Authorize narrowly. Assume compromise.
Keep Agentic AI in a Box
Recording and transcription are only the start. Agentic AI can search, decide and act. An assistant that hears a meeting may also be able to open documents, send messages, update CRM records, schedule activity or trigger workflows. That turns a confidentiality problem into an authorization problem.
Do not give an AI agent ambient access to the enterprise. Give it a dedicated identity, narrowly scoped data, approved tools and explicit limits on what it can do. Put high-impact actions, payments, external communications, credential changes, legal commitments and deletion behind human approval. Log every retrieval, instruction and action. Apply retention limits. Build in a kill switch. Test whether prompt injection through a document, webpage or spoken command can get the agent to leave its cage.
An AI assistant should run like a junior contractor: useful, supervised and kept out of systems it does not need to touch.
No recording without permission. They post that rule in every gym locker room now. AV should follow it too.
The Meeting Room Also Has a Physical Perimeter
Network controls cannot stop a privately owned 5G phone, watch or AI pin from recording a discussion locally. Sensitive meetings need physical and policy controls too, not just technical ones.
Corporate phones should be enrolled in mobile device management: encrypted, patched and subject to application, recording, sharing and data loss prevention policies. Private phones and wearables should not be allowed in confidential meetings.
Provide secure storage outside the room and post the rule before people walk in. For lower-risk meetings, require disclosure and consent before recording or transcription starts. Make unauthorized recording a fireable offense, and make sure everyone in the room knows it before anyone walks in.
Classification should drive all of this. A routine project update does not need the controls a legal discussion does. Organizations already classify documents, restrict downloads and control USB storage. Conversations deserve the same treatment: which room, which devices, whether remote participants join, whether transcription is running, where recordings live and when they get deleted.
No Policy Matters More Than Procurement and Operations
Security cannot start after installation. Buyers should insist on commercial displays without consumer advertising or content-recognition services, hardware microphone and camera disconnects where it matters, signed firmware, secure boot, unique credentials, certificate-based authentication, a vulnerability disclosure process and a stated support lifetime.
Every device needs an owner, an inventory record and an end-of-support date. Firmware updates get tested and deployed. Configuration drift gets monitored. Logs feed the security operations process. Review vendor cloud dependencies and subprocessors before purchase, not during an incident. When a product stops getting security updates, isolate it or replace it.
The same discipline applies to recordings: approved platforms, minimal collection, encryption, restricted access, automatic retention and no bulk export. Treat voice and facial data as biometric material, not meeting-room exhaust. Test the incident-response plan for compromised AV endpoints and leaked recordings before the board has to ask whether it already happened.
None of this is exotic. What is missing is coordination: AV, networking, security, collaboration, facilities and procurement still operate as separate domains. Attackers do not care about your org chart.
This Is an Opening for the AV Channel
Integrators should not try to become cybersecurity companies overnight. They should stop delivering systems that security teams have to retrofit after commissioning.
The commercial model that works is secure-by-design AV: documented traffic flows, tested configurations, segmented architectures, device inventories, update commitments, monitoring and lifecycle services. It produces better outcomes for the customer and recurring revenue beyond hardware margin for the integrator. It also earns integrators a real seat at the table with CIOs and CISOs because they can own the meeting-room experience without pretending the room sits outside enterprise policy.
Every practice needed here—network design, endpoint management, zero trust and data governance—already exists. Apply it to every device and person in the building, and the room stops looking special.
The technology for this is, as I have seen many times, already available. What is missing is enforcement.




