Enterprise AI risk is shifting from model alignment and jailbreaks to production workflows. Agents read live CRM records, tickets and web content, call APIs, write to databases and sometimes act without a human—each step a new attack surface. Attackers need not access the model; instructions hidden