As organisations become more concerned about AI-enabled cyber-attacks, one of the technology’s most persistent weaknesses risks receiving less attention than more familiar threats.

As organisations become more concerned about AI-enabled cyber-attacks, one of the technology’s most persistent weaknesses risks receiving less attention than more familiar threats.
Okta’s Global CISO Insights 2026 found AI-powered phishing was the most commonly cited AI threat among the 306 security executives surveyed, identified by 61% of respondents. Malicious AI agents followed at 49%, while 45% pointed to deepfake authentication bypass. Prompt injection, despite its growing relevance to agentic systems, does not feature among the headline concerns.
Prompt injection involves manipulating the instructions followed by an AI system, either directly or through malicious instructions hidden in content it processes, such as webpages, emails or documents. The UK’s National Cyber Security Centre has warned that the problem cannot necessarily be addressed in the same way as conventional injection vulnerabilities because large language models process instructions and data together.
The consequences are also changing as AI systems gain greater autonomy. A manipulated chatbot might generate an unwanted response, while an agent connected to external tools could potentially perform an unwanted action. Earlier this year, Microsoft researchers identified vulnerabilities in the Semantic Kernel agent framework where prompt injection could ultimately lead to host-level remote code execution.
Researchers are also finding attempts to exploit the technique outside controlled environments. Palo Alto Networks Unit 42 reported discovering indirect prompt injections on public websites designed to influence AI agents and crawlers, including instructions intended to manipulate reviews and alter how AI systems represented particular sites.
The risk becomes more significant when agents have broad access to corporate systems. Okta found only 46% of respondents were confident they could centrally control what their AI agents accessed, while 21% of organisations were using shared credentials or broadly permissioned service accounts for AI access.
This makes permissions as important as the prompt injection itself. An attacker may be able to influence what an agent attempts to do, but the identity and access controls surrounding that agent determine what it is actually capable of doing.
The NCSC has recommended applying established security principles to agentic AI, including appropriate access controls, monitoring and accountability. Preventing every malicious instruction from reaching an AI system may be difficult, but restricting the permissions available to it can limit the consequences when an attack succeeds.
As AI moves from generating information to performing tasks, prompt injection is becoming less about manipulating what a model says and increasingly about controlling what it can be persuaded to do.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543