Definition
A newly named category of security incident where attackers take over an AI model or the systems running it — not just steal data through it, but seize control of the AI itself (its weights, pipeline, or hosting infrastructure). Industry threat catalogs now track this as its own line item because the damage pattern differs from a normal data breach.
Why it matters
Boards need a distinct budget line and incident-response playbook for 'the AI itself got hijacked' rather than assuming existing breach plans cover it — insurers and auditors are starting to ask about it by name.