CISOs Struggle with AI Threat Modeling Today
🔎 A brief report explains how threat-modeling expert Adam Shostack developed PHANTOM-B, a focused framework for quickly identifying LLM-specific risks such as prompt injection, hallucination, and bias. The approach complements existing methods like STRIDE by targeting components that interact with large language models and enabling useful results in short sessions. The article outlines why traditional threat modeling falls short for generative and agentic AI and stresses that fundamentals of application security must still be applied alongside new AI-focused controls.
