Without a threat model, teams either over-block harmless use or ignore the attacks that actually matter. AI threat models include prompt injection, data exfiltration through tools, jailbreaks, and training-data poisoning. The document should name assets, attackers, and mitigations you will actually enforce outside the model.