Your AI model is not the only thing that can be attacked.
AI systems include data, APIs, libraries, pipelines, monitoring tools and people.
Attackers look for the weakest link.
That's why AI security cannot be a final checklist before deployment.
It should be an AI lifecycle.