The standard reference for what can actually go wrong in an AI product: prompt injection, data leakage, and the rest, with mitigations.