Start here. This is the direct spoken answer to practice first.
Overview
An AI threat model extends ordinary application security to cover probabilistic behavior and model-mediated data flow.
I start with the user goal, data, identities, model, retrieval sources, tools, outputs, and side effects, then draw the trust boundaries between them. I mark every place untrusted content can influence the model and every place model output can influence code, a person, or an external system. For each path I ask what could expose data, corrupt a decision, misuse authority, exhaust resources, or mislead a user.