THE AI VULNERABILITY WITH NO PATCH

The Four Places to Lock Down an AI Assistant That Can't Tell a Command From Content

Friday, August 28, 2026, at 12PM ET
Live Virtual Session

Last October, researchers from OpenAI, Anthropic, and Google DeepMind took twelve of the leading defenses against prompt injection and broke almost all of them, most better than nine times out of ten. Prompt injection is the trick of burying instructions inside the content an AI reads (a web page, a document, a plugin's output) so the assistant carries out commands the user never gave and never sees.

It's the number one risk on the industry's official AI list, OWASP, and even that list admits there's no way to fully stop it. The defenses meant to catch it are the ones that just fell.

This month's SecOps hands you a repeatable way to lock down the AI assistants your clients are turning on, starting with the one flaw you can't wait on a vendor to fix.

WHY THIS MATTERS 

A normal app knows the difference between a command and everyday content. AI doesn't. It reads the instructions you give it and the outside text it pulls in as one and the same, so a booby-trapped web page or plugin can slip it orders the user never sees. Nothing is broken and there's nothing to patch, because the AI is working exactly as built.

That's why the fix has to happen around the AI tool itself, in four places you can already reach.

WHAT YOU’LL WALK AWAY WITH 

  • The Control Boundary Checklist, covering the four places you enforce this, each one checkable against your own stack right away:
    • Input: what reaches the model, and whether anything flags where it came from.
    • Tool: what the model is allowed to invoke, and whether that's scoped per task.
    • Action: what can run without a human signing off, especially anything irreversible.
    • Egress: where data can travel when an injection lands, and what shows up in the logs.
  • The Injection Teardown, a recorded walkthrough of an AI assistant getting hijacked through a trusted plugin. A blunt "ignore all previous instructions" gets caught and blocked, but the same command hidden inside what looks like normal documentation slips right through and quietly leaks the entire conversation.
  • The Client Translation, a two-sentence version of why no filter can make an AI safe, plus the follow-up for the client who insists their vendor already handles it.

THE BOTTOM LINE

Prompt injection has ranked number one on OWASP's AI risk list through every version to date and there's still no patch coming, because the flaw is baked into how AI reads everything you give it as one and the same.

What does work is the stuff you already do every day: scoping access, gating risky actions behind a human, and watching what leaves the environment. Put those in the four right places and the exposure closes. That’s what this session helps you do.

When a client asks whether the assistant they turned on last week is safe, you won't be guessing or waiting on a vendor to weigh in. You'll have already checked the four places it matters, and you'll be able to walk them through exactly what you found and why it holds.

Friday, August 28, 2026, at 12pm ET
Live Virtual Session

Reserve Your Spot