LLMs in the Enterprise: A Systematic Review of Security Architectures for RAG-Augmented Chatbots

Fatimah A. Alali, Haya Aldawsari, Saad Ezzini, Sajjad Mahmood


Abstract
Enterprise sectors increasingly require AI-driven solutions that handle large volumes of domain-specific documentation securely and efficiently. While Retrieval-Augmented Generation (RAG) extends the capabilities of Large Language Models (LLMs) by grounding responses in external knowledge bases, the security and adoption concerns that define industrial deployment remain largely unaddressed. A Systematic Literature Review (SLR) was conducted targeting empirical studies published between 2020 and 2025 across five academic databases, guided by research questions covering RAG performance, industrial applicability, and security requirements. While findings indicate RAG outperforms base LLM configurations, the analysis reveals that security coverage across the corpus is limited and inconsistent. A critical, recurring gap identified is that security architecture is not adequately covered by the current work, with studies failing to provide detailed security architecture guidance. The literature has not yet addressed the complete set of enterprise deployment requirements, particularly those relating to data privacy. We conclude that while RAG provides a strong foundation, establishing robust security architectures and privacy guidelines are the primary directions required for future research and safe enterprise adoption.
Anthology ID:
2026.nlpaics-1.25
Volume:
Proceedings of the Second International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security
Month:
June
Year:
2026
Address:
Alicante, Spain
Editors:
Ruslan Mitkov, Rafael Muñoz, Elena Lloret, Tharindu Ranasinghe, Ernesto L. Estevanell-Valladares, Salima Lamsiyah, Andrés Montoyo, Saad Ezzini
Venue:
NLPAICS
SIG:
Publisher:
Department of Languages and Information Systems, University of Alicante
Note:
Pages:
232–243
Language:
URL:
https://aclanthology.org/2026.nlpaics-1.25/
DOI:
Bibkey:
Cite (ACL):
Fatimah A. Alali, Haya Aldawsari, Saad Ezzini, and Sajjad Mahmood. 2026. LLMs in the Enterprise: A Systematic Review of Security Architectures for RAG-Augmented Chatbots. In Proceedings of the Second International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security, pages 232–243, Alicante, Spain. Department of Languages and Information Systems, University of Alicante.
Cite (Informal):
LLMs in the Enterprise: A Systematic Review of Security Architectures for RAG-Augmented Chatbots (Alali et al., NLPAICS 2026)
Copy Citation:
PDF:
https://aclanthology.org/2026.nlpaics-1.25.pdf