Threat modeling AI systems

At CanSecWest 2025, I presented on threat modeling AI systems. This included a broad discussion of the AI security landscape, covering many of the threats companies face today. I presented a model for considering these risks by separating them out into who is primarily responsible for them. Last, I presented a live demo of an AI integrated logstics system that I created, and demonstrated some common prompt injection attacks against it, resulting in OS command injection via prompt injection.