The current conversation around AI and LLM security is a mess. On one side, we have breathless takes about prompt injections, jailbreaks, rogue agents, and existential model failures. On the other hand, we have security teams who can’t yet answer a very simple question: Where is AI actually being used in our environment?