My Top Ten AI Attack Vectors
- Lindsay Timcke

- Jun 24
- 2 min read
Everyone is watching the IPOs, the mega mergers, and the giant data centers. I have been in those conversations as much as anyone.
For months the argument was whether AI security was a real concern. That argument is over. Two weeks later it is the main one. It is time to design the defense perimeter, agree on how we defend it, and be honest about what the attack vectors even are.
You cannot protect what you have never mapped. So here is my starting point. For firms up to three hundred million dollars, in any industry, these are the ten I watch. This list will change for every firm so I do not think it’s the bible more a jumping off point.
1. Prompt injection, the direct kind and the indirect kind hidden in documents and web pages your model reads.
2. Data poisoning of your training and fine tuning data.
3. Sensitive data walking out through model outputs.
4. Shadow AI, your own people pasting confidential material into public tools nobody approved.
5. Supply chain risk in the models, APIs, and dependencies you did not build and cannot fully see.
6. Poisoning and leakage of your RAG and vector databases.
7. Agents and plugins handed too much permission and left to act with no guardrails.
8. API keys and over scoped tokens sitting right there in your code.
9. Deepfake voice and video aimed at your finance team to push through a wire you will spend months regretting.
10. No logging, no monitoring, no governance, so you never even know when one through nine already happened.
And do not treat AI as a special case that skips the basics. If you are implementing it, it goes through your SDLC, your System Development Life Cycle, like anything else you build. Once it is live it falls under your Change Management controls, not a free pass to push changes on a whim.
Build in Segregation Of Duties so no one person owns it all, and Logical Security around who can touch what. Here is the part people forget. The control environment behind the firewall matters as much as ever. Once they breach your perimeter, and they will try, your internal controls are the next line of defense. Layered controls are your saving grace. Let’s also add in Training for new hires and hold a Q4 all hands training for all existing staff. Last thing let’s get a inventory of all AI instances being used.
None of this needs a hyperscaler budget. It needs you to decide your controls matter before the breach, not during the cleanup. I have spent thirty years looking at controls the way an attacker does, and the attacker is already thinking that way about your AI stack right now. The only question is whether you get there first, while you still have time.
So let me ask you straight. If someone asked you tomorrow to name your AI attack surface, could you, or would you be guessing?
