31 of 36 real-world LLM applications were vulnerable to prompt injection.
That finding, published in March 2026, is not a forecast. It is a measurement of deployed systems. If your organisation has rolled out AI-powered tooling — and the data suggests it has — the probability that anyone has audited what those tools accept as instructions is low.
The productivity case for AI is not in dispute. Workflows compress. Code ships faster. Tickets close. But the same integrations delivering that output — RAG pipelines, email parsers, agent runtimes, ticket bots — are where injected instructions can bypass model guidelines and reach live APIs. The liability is embedded in the productivity gain, unpriced and largely unexamined.
Two Structural Shifts That Widened the Gap
AI deployment outpaced security review. Developers now generate code faster than security teams can read it. Shadow AI use is widespread. Only 17% of companies can automatically block employees from pasting confidential data into public AI services — the remaining 83% rely on training or nothing at all.
Simultaneously, attackers operationalised AI faster than defenders could govern it. Security incidents involving AI spiked 56% in one year. Palo Alto Networks’ State of GenAI 2025 report found the average monthly number of GenAI-related data security incidents increased 2.5 times, now accounting for 14% of all data security incidents across SaaS traffic. Organisations were running an average of 66 GenAI apps, with 10% classified as high risk.
Scott Gerlach, speaking on the Cloud Security Newsletter, described the resulting position plainly: “Before, I would say even the end of last year, the AppSec programs were really still kind of reactive and just trying to keep up as best they could. And then AI gets down and everyone’s like, wow, we’re way behind now.” (Cloud Security Newsletter, April 2026)
The Two Vectors Most Teams Are Not Auditing
Prompt injection is ranked #1 in the OWASP LLM Top 10 for 2025. The mechanism is straightforward: an adversary embeds instructions inside content the model is expected to read — a document, an email, a webpage — and the model follows those instructions rather than the operator’s. Palo Alto Networks AI Research found prompt-based attacks can succeed at rates as high as 88%.
Indirect injection is the more consequential variant. Google Cloud noted in July 2026 that when AI tasks are open-ended, interpretive, or adversarial, error rates rise by more than 40% and susceptibility to injection increases sharply. An agent browsing on your behalf, summarising inbound email, or pulling context from third-party tools is reading untrusted content continuously. Each read is a potential injection surface.
AI supply chain attacks are ranked #3 in the OWASP LLM Top 10 and #4 in the OWASP Agentic Top 10 2026. The mechanism mirrors the NPM problem: a compromised dependency — a model, a dataset, a tool wrapper — executes with the trust level of your own infrastructure. The TeamPCP supply chain campaign required no zero-day exploit. It abused default configuration.
An author writing in the Data Science Collective on Medium framed the underlying pattern: “Most of these vulnerabilities aren’t exotic. Prompt injection is confused deputy. Output handling is input validation applied to a new source. Supply chain is the NPM problem applied to AI components. Excessive agency is least privilege, which we’ve been preaching for 30 years.” The concepts are not new. The attack surface is.
Where Exposure Is Highest — and a Fair Counterpoint
Agentic workloads — systems where the model takes actions rather than just producing answers — carry the greatest exposure. Per the Cloud Security Newsletter’s editorial synthesis, non-deterministic AI code operating with overprivileged identities is the defining runtime security risk of 2026. For Vertex AI Agent Engine workloads specifically, an advisory was issued to audit P4SA permission scopes and move to bring-your-own-service-account architectures before any agentic workload reaches production.
The counterpoint is legitimate: not every AI deployment is agentic. A read-only summarisation tool with no API access and no persistent memory has a materially smaller blast radius than an autonomous agent with write permissions. The audit recommendation does not mean every AI tool carries equal risk. It means the tools with tool-call access, external retrieval, or elevated permissions warrant a security review before the next sprint builds further on top of them. A lower-capability deployment with a narrow permission scope is genuinely lower risk — that concession does not weaken the case for auditing the higher-capability ones.
A Triage Audit You Can Start This Week
This is not a transformation programme. It is a triage across three areas:
- Map AI integrations against trust boundaries. For each tool, establish what external content the model reads and whether it has downstream API or data-write access. RAG pipelines pulling from uncontrolled sources are the highest-priority injection surface. Document the boundary explicitly — if it is not documented, it has not been reviewed.
- Apply least privilege to every AI identity. Agents and service accounts running LLM workloads accumulate permissions faster than human accounts and are rarely reviewed on the same cycle. Audit scope now and revoke what the workload does not require. The TeamPCP campaign succeeded on default permissions, not stolen credentials — that failure mode is entirely preventable.
- Audit your AI dependency chain. Identify every model, dataset, and tool wrapper in your stack. Verify provenance. Flag any component updated without a corresponding security review. Treat AI components with the same scrutiny applied to third-party code libraries — version-pin where possible, and establish a review gate for updates.
The Center for Internet Security has published a dedicated report on prompt injection risks that provides a structured framework suitable for handing to a security team or board. It is a practical starting point for organisations formalising their AI security posture.
The productivity gains from AI are real. So is the attack surface they introduce. The gap between the two is an audit problem, and audit problems have a known fix.
Join the conversation or subscribe for weekly breakdowns — the next issue covers how to structure an AI red-team exercise your existing AppSec team can actually run.
— Abhijit Ghosh
Eagentix helps growth-focused enterprises redesign and automate manual business processes. We combine executive strategy, implementation support, and managed services to build dependable operations across Southeast Asia.
Eagentix helps growth-focused enterprises redesign and automate manual business processes. We combine executive strategy, implementation support, and managed services to build dependable operations across Southeast Asia.
Sources
- – The Hidden Cost of AI Adoption: Data Leakage, Compliance, and Risk | by Nishthaanand | Medium
- – AI in Cyber Security — What Actually Changes When Attackers and Defenders Both Have Models
- – Supply Chain Attack on Trivy, LiteLLM & Axios: AppSec Lessons for CISOs in 2026
- – If you’re building multi-agent systems, standard prompt injection isn’t …
- – Prompts, paste actions, tool calls: AI risk happens fast. See what …
- – AI Supply Chain Risks Every Federal Leader Must Know – YouTube
- – AI & supply chain risks top cyber security agenda
- – Kiteworks’ Evil Breach 2 at AI4 2026 in Las Vegas – Facebook
- – AI Research for CXOs – Palo Alto Networks
- – What are the risks of using an AI bot to browse the web on … – Quora
- – Medium
- – New CIS Report Warns Prompt Injection Attacks Pose Growing Risk to Generative AI
- – AI Agent Skills Security: Prompt Injection and Supply Chain Risks …
- – Why Prompt Injection Attacks Are GenAI’s #1 Vulnerability
- – Indirect prompt injection hides malicious instructions inside the …
- – Prompt injection protection: Detecting and blocking malicious AI instructions
- – [PDF] Artificial intelligence and machine learning Supply chain risks and …
- – Top AI Risks Every Security Team Should Be Testing For – OffSec
- – AI Supply Chain Security: The Hidden Risks Behind Models, Datasets and AI Tools | Cloud Engineer Lab
- – AI Usage Monitoring: Detect Shadow AI & Stop Leakage | Adaptive Security
- – AI Agents & Prompt Injection: The Security Crisis You Cannot Ignore — Flutteris
- – Resilient Cyber Newsletter #83 – by Chris Hughes
- – AI boosts software delivery, but unevenly distributed | Jérôme Robert posted on the topic | LinkedIn
- – FINOS AI Governance Framework
- – Prompt injection breaks today’s AI agents, study warns | CSO Online
- – AI Amplifies Supply Chain Attacks: A New Threat Vector | Chukwunonso Aneke posted on the topic | LinkedIn
- – Prompt Injections: The Inherent Threat to Generative AI
