Why it matters
AI expands the attack surface through prompts, retrieval layers, third-party models, plugins, and autonomous decisions. Security controls must now cover both classic application risks and AI-specific failure modes.
- Prompt injection and instruction override
- Data leakage through prompts and outputs
- Excessive agent permissions and tool abuse
- Untrusted model and dependency supply chain