From data poisoning to prompt injection, threats against enterprise AI applications and foundations are beginning to move from theory to reality.