In 2003, ChatGPT changed the industry by introducing the need for artificial intelligence (AI) security. AI has a large attack surface due to its foundational models, which are trained on expansive data sets and made open source. Traditional software development is blended with these models, but they have all the existing vulnerabilities of the software supply chain, plus AI’s new mathematical threats. There is no widespread practice of enumerating model versions before release, and traditional attacks like SQL injection took 20 years to extinguish. It is difficult to solve mathematical exploits of large unstructured inputs, and some believe that, despite patching, there will always be ways to change inputs to attack foundational models.