AI security is being sold as a feature. It's an architecture problem.
Traditional security assumes a system only does what its code says. AI systems don't. They act on untrusted input as if it were instruction, and their outputs can carry real authority. A guardrail in a prompt is not a control. A vendor's assurance is not evidence.