The AI Security Playbook Has 20 Threats. 16 Are New.
- 6 days ago
- 5 min read
A widely circulated AI security playbook recently listed twenty enterprise AI threats side by side, from prompt injection and data poisoning through model extraction, shadow AI, and unsafe fine-tuning. What struck me was not the number twenty. It was how many of those twenty describe a risk category that simply did not exist five years ago, and how confidently some security leaders assume their existing program already covers them.
It does not, mostly. Of the twenty threats on that list, roughly sixteen are AI-native: they emerge specifically from how large language models and AI agents are trained, prompted, and connected to tools, and they have no clean equivalent in a traditional network security program. The remaining four, denial of service, API abuse, unauthorized access, and supply chain risk, are familiar categories that AI has simply given a new attack surface. Conflating the two is exactly how a security leader tells a board that AI risk is covered, when what is actually covered is the smaller, older half of the list.

Why It Matters
The scale of the gap is measurable. Gartner has found that the average enterprise AI deployment now carries 14.3 distinct attack surface components, up from 3.2 in 2023, a 347% expansion in two years, and that expansion has outpaced the speed at which most security teams have added new controls. Gartner separately projects that AI-driven applications will account for 50% of all enterprise cybersecurity incident response effort by 2028, which means half of a security team's future workload will involve threat categories that, for most organizations, do not yet have a documented playbook.
The cost of treating AI-native threats as a subset of traditional security is already visible in breach data. IBM's research found that AI-related data breaches now average $10.22 million, with the overwhelming majority occurring where proper access controls were never in place. Prompt injection alone, the single most cited threat on the list, is now ranked the top risk in the industry's own LLM security taxonomy, and industry tracking has recorded triple-digit year-over-year growth in attempts against production systems, concentrated heavily in indirect attacks delivered through documents and connected tools rather than direct user prompts.
The Core Framework: Which Threats Are Old, and Which Are Genuinely New
Sorting the playbook's twenty threats into two categories clarifies where a security program's existing controls actually apply, and where they do not.
The four inherited threats, denial of service, API abuse, unauthorized access, and supply chain risk, are extensions of categories every mature security program already has controls for: rate limiting and traffic management, authentication and role-based access control, and vendor risk assessment. AI expands the surface area of each, but the control discipline is not new.
The sixteen AI-native threats are a different problem entirely, and they cluster into three groups. The first is model manipulation: prompt injection, data poisoning, adversarial attacks, model evasion, and insecure training pipelines, all of which target the model's inputs or training process rather than a network or credential. The second is model exposure: model inversion, membership inference, model extraction, and sensitive data leakage, all of which describe an attacker learning something the model was never supposed to reveal, sometimes without ever breaching a system in the traditional sense.
The third is operational drift: hallucinations, algorithmic bias, data drift, poor monitoring and logging, shadow AI, and unsafe fine-tuning, which describe a model's behavior degrading or escaping oversight over time rather than being attacked directly. None of the sixteen is covered by a firewall, an MFA policy, or a standard vulnerability scan. They require model-specific controls: differential privacy, output perturbation, red teaming, watermarking, dataset validation, and continuous drift detection, most of which sit outside a traditional security team's existing toolkit and training.
Governance Section
What is the board's role? Ask, explicitly, whether the security program's AI coverage addresses the sixteen AI-native threats or only the four inherited ones, because a program built entirely on traditional controls will report itself as covered while missing most of what is actually new. NIST's AI Risk Management Framework was built to give organizations a structure for exactly this kind of model-specific risk, and a board should expect its security leadership to reference it directly, not fold AI risk quietly into the existing cybersecurity report.
What risks exist? Beyond the sixteen technical categories, the underlying governance risk is a false sense of coverage. The World Economic Forum's Global Cybersecurity Outlook 2026 found that visibility gaps, not attacker sophistication, are the recurring theme across the risks organizations rate highest, and AI-native threats are precisely where visibility is weakest, since most monitoring tools were built for network traffic, not model behavior.
What metrics matter? Whether red teaming has ever been run against the organization's own AI systems specifically, not just its network. Whether any AI deployment has documented protection against prompt injection, the most exploited threat on the list. Whether shadow AI, unapproved tools connected without governance, has ever been formally inventoried rather than assumed to be rare.
What oversight is required? A standing report that separates AI-native threat coverage from traditional security coverage, reviewed on its own line item, because Gartner's own data shows AI-driven incidents will soon dominate incident response capacity, and a board that has never seen that line item separated out has no way to know whether the organization is actually prepared for it.
Executive Actions
CISOs should map every current AI deployment against the sixteen AI-native threat categories specifically, not the general cybersecurity framework already in place, and name which ones have a documented control and which do not. CIOs should treat prompt injection defense, least-privilege tool permissions, and red teaming as standing requirements for any AI system connected to real data or real workflows, the same way Microsoft's own research on account compromise has shown that a small number of well-chosen controls block the overwhelming majority of traditional attacks, a lesson that applies equally to AI-specific controls once they are actually implemented. Boards should require this sixteen-versus-four breakdown at the next security update, because McKinsey's research on AI adoption finds that most organizations still lack comprehensive visibility into how AI is actually being used inside the business, and that same blind spot is exactly where the newest threats on this list live undetected. This is the discipline BetterWorld Technology builds into its managed AI governance practice, treating AI-native threats as their own category rather than a rounding error inside an existing security budget.
Final Thoughts
Twenty threats on a single page make AI security look like a longer version of the same problem security teams have always solved. It is not. Sixteen of those twenty threats describe risks that did not exist in a pre-AI world, and they require controls, monitoring, and expertise that most security programs have not yet built. Harvard Business Review's research found that only 6% of companies fully trust AI agents to run core business processes autonomously, and that trust gap will not close by applying old controls to new threats. It closes when a security program can name, specifically, which of the sixteen it has actually addressed. For more on how BetterWorld Technology helps leadership teams close that gap, see the AI governance advisory practice and the companion piece on the four things executives must govern in their AI tool settings, and for the underlying operating model discipline behind both, see Working Excellence's guidance on scaling leadership systems for AI-era risk.




Comments