@inproceedings{alali-etal-2026-llms,
title = "{LLM}s in the Enterprise: A Systematic Review of Security Architectures for {RAG}-Augmented Chatbots",
author = "Alali, Fatimah A. and
Aldawsari, Haya and
Ezzini, Saad and
Mahmood, Sajjad",
editor = "Mitkov, Ruslan and
Mu{\~n}oz, Rafael and
Lloret, Elena and
Ranasinghe, Tharindu and
Estevanell-Valladares, Ernesto L. and
Lamsiyah, Salima and
Montoyo, Andr{\'e}s and
Ezzini, Saad",
booktitle = "Proceedings of the Second International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security",
month = jun,
year = "2026",
address = "Alicante, Spain",
publisher = "Department of Languages and Information Systems, University of Alicante",
url = "https://aclanthology.org/2026.nlpaics-1.25/",
pages = "232--243",
abstract = "Enterprise sectors increasingly require AI-driven solutions that handle large volumes of domain-specific documentation securely and efficiently. While Retrieval-Augmented Generation (RAG) extends the capabilities of Large Language Models (LLMs) by grounding responses in external knowledge bases, the security and adoption concerns that define industrial deployment remain largely unaddressed. A Systematic Literature Review (SLR) was conducted targeting empirical studies published between 2020 and 2025 across five academic databases, guided by research questions covering RAG performance, industrial applicability, and security requirements. While findings indicate RAG outperforms base LLM configurations, the analysis reveals that security coverage across the corpus is limited and inconsistent. A critical, recurring gap identified is that security architecture is not adequately covered by the current work, with studies failing to provide detailed security architecture guidance. The literature has not yet addressed the complete set of enterprise deployment requirements, particularly those relating to data privacy. We conclude that while RAG provides a strong foundation, establishing robust security architectures and privacy guidelines are the primary directions required for future research and safe enterprise adoption."
}<?xml version="1.0" encoding="UTF-8"?>
<modsCollection xmlns="http://www.loc.gov/mods/v3">
<mods ID="alali-etal-2026-llms">
<titleInfo>
<title>LLMs in the Enterprise: A Systematic Review of Security Architectures for RAG-Augmented Chatbots</title>
</titleInfo>
<name type="personal">
<namePart type="given">Fatimah</namePart>
<namePart type="given">A</namePart>
<namePart type="family">Alali</namePart>
<role>
<roleTerm authority="marcrelator" type="text">author</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Haya</namePart>
<namePart type="family">Aldawsari</namePart>
<role>
<roleTerm authority="marcrelator" type="text">author</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Saad</namePart>
<namePart type="family">Ezzini</namePart>
<role>
<roleTerm authority="marcrelator" type="text">author</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Sajjad</namePart>
<namePart type="family">Mahmood</namePart>
<role>
<roleTerm authority="marcrelator" type="text">author</roleTerm>
</role>
</name>
<originInfo>
<dateIssued>2026-06</dateIssued>
</originInfo>
<typeOfResource>text</typeOfResource>
<relatedItem type="host">
<titleInfo>
<title>Proceedings of the Second International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security</title>
</titleInfo>
<name type="personal">
<namePart type="given">Ruslan</namePart>
<namePart type="family">Mitkov</namePart>
<role>
<roleTerm authority="marcrelator" type="text">editor</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Rafael</namePart>
<namePart type="family">Muñoz</namePart>
<role>
<roleTerm authority="marcrelator" type="text">editor</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Elena</namePart>
<namePart type="family">Lloret</namePart>
<role>
<roleTerm authority="marcrelator" type="text">editor</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Tharindu</namePart>
<namePart type="family">Ranasinghe</namePart>
<role>
<roleTerm authority="marcrelator" type="text">editor</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Ernesto</namePart>
<namePart type="given">L</namePart>
<namePart type="family">Estevanell-Valladares</namePart>
<role>
<roleTerm authority="marcrelator" type="text">editor</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Salima</namePart>
<namePart type="family">Lamsiyah</namePart>
<role>
<roleTerm authority="marcrelator" type="text">editor</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Andrés</namePart>
<namePart type="family">Montoyo</namePart>
<role>
<roleTerm authority="marcrelator" type="text">editor</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Saad</namePart>
<namePart type="family">Ezzini</namePart>
<role>
<roleTerm authority="marcrelator" type="text">editor</roleTerm>
</role>
</name>
<originInfo>
<publisher>Department of Languages and Information Systems, University of Alicante</publisher>
<place>
<placeTerm type="text">Alicante, Spain</placeTerm>
</place>
</originInfo>
<genre authority="marcgt">conference publication</genre>
</relatedItem>
<abstract>Enterprise sectors increasingly require AI-driven solutions that handle large volumes of domain-specific documentation securely and efficiently. While Retrieval-Augmented Generation (RAG) extends the capabilities of Large Language Models (LLMs) by grounding responses in external knowledge bases, the security and adoption concerns that define industrial deployment remain largely unaddressed. A Systematic Literature Review (SLR) was conducted targeting empirical studies published between 2020 and 2025 across five academic databases, guided by research questions covering RAG performance, industrial applicability, and security requirements. While findings indicate RAG outperforms base LLM configurations, the analysis reveals that security coverage across the corpus is limited and inconsistent. A critical, recurring gap identified is that security architecture is not adequately covered by the current work, with studies failing to provide detailed security architecture guidance. The literature has not yet addressed the complete set of enterprise deployment requirements, particularly those relating to data privacy. We conclude that while RAG provides a strong foundation, establishing robust security architectures and privacy guidelines are the primary directions required for future research and safe enterprise adoption.</abstract>
<identifier type="citekey">alali-etal-2026-llms</identifier>
<location>
<url>https://aclanthology.org/2026.nlpaics-1.25/</url>
</location>
<part>
<date>2026-06</date>
<extent unit="page">
<start>232</start>
<end>243</end>
</extent>
</part>
</mods>
</modsCollection>
%0 Conference Proceedings
%T LLMs in the Enterprise: A Systematic Review of Security Architectures for RAG-Augmented Chatbots
%A Alali, Fatimah A.
%A Aldawsari, Haya
%A Ezzini, Saad
%A Mahmood, Sajjad
%Y Mitkov, Ruslan
%Y Muñoz, Rafael
%Y Lloret, Elena
%Y Ranasinghe, Tharindu
%Y Estevanell-Valladares, Ernesto L.
%Y Lamsiyah, Salima
%Y Montoyo, Andrés
%Y Ezzini, Saad
%S Proceedings of the Second International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security
%D 2026
%8 June
%I Department of Languages and Information Systems, University of Alicante
%C Alicante, Spain
%F alali-etal-2026-llms
%X Enterprise sectors increasingly require AI-driven solutions that handle large volumes of domain-specific documentation securely and efficiently. While Retrieval-Augmented Generation (RAG) extends the capabilities of Large Language Models (LLMs) by grounding responses in external knowledge bases, the security and adoption concerns that define industrial deployment remain largely unaddressed. A Systematic Literature Review (SLR) was conducted targeting empirical studies published between 2020 and 2025 across five academic databases, guided by research questions covering RAG performance, industrial applicability, and security requirements. While findings indicate RAG outperforms base LLM configurations, the analysis reveals that security coverage across the corpus is limited and inconsistent. A critical, recurring gap identified is that security architecture is not adequately covered by the current work, with studies failing to provide detailed security architecture guidance. The literature has not yet addressed the complete set of enterprise deployment requirements, particularly those relating to data privacy. We conclude that while RAG provides a strong foundation, establishing robust security architectures and privacy guidelines are the primary directions required for future research and safe enterprise adoption.
%U https://aclanthology.org/2026.nlpaics-1.25/
%P 232-243
Markdown (Informal)
[LLMs in the Enterprise: A Systematic Review of Security Architectures for RAG-Augmented Chatbots](https://aclanthology.org/2026.nlpaics-1.25/) (Alali et al., NLPAICS 2026)
ACL