Prompt Injection: A Major Security Risk for AI Applications
- Prompt injection is ranked as the number one security threat for AI applications by the Open Worldwide Application Security Project.
- OpenAI admitted in December 2025 that prompt injection issues are “unlikely to ever be fully solved.”
- The UK’s National Cyber Security Centre warned that large language models are “inherently confusable” and could lead to significant breaches.
- Google DeepMind reported a significant increase in malicious indirect prompt injections, with a rise of over 32% between November 2025 and February 2026.
- Anthropic disclosed a large-scale cyberattack executed by AI, involving intrusions against approximately thirty targets.
Prompt injection attacks pose a critical security risk for AI applications, with major organizations acknowledging the challenge in resolving this vulnerability. The attacks exploit the inability of language models to distinguish between instructions and data, leading to potential breaches on a massive scale.
Given the inherent vulnerabilities in AI systems, experts emphasize limiting what an AI can do when compromised, highlighting the importance of maintaining control over these technologies to mitigate risks effectively.(Source)