A widely shared AI security playbook maps twenty enterprise AI threats, from prompt injection to shadow AI. Sixteen of them describe risks that simply did not exist in a pre-AI security program. Here is which threats your existing controls already cover, which ones require new governance entirely, and the four questions every board should ask before approving the next AI deployment.