Attack surface is the set of points through which an unauthorized or malicious actor could access, manipulate, disrupt, or extract data from a system. In AI systems, it may include model endpoints, training data pipelines, plugins, credentials, user interfaces, dependencies, and operational infrastructure.