Organizations are increasingly using artificial intelligence (AI) tools to improve efficiency, automateworkflows and support decision-making. Earlier AI tools, including rule-based chatbots and generative
AI assistants, primarily focused on providing information and generating content. In contrast, evolvingagentic AI systems can independently plan, execute and adapt to tasks in real time. Depending on theirdesign, these systems may browse the web, analyze documents, access databases and execute code,enabling them to interact directly with business systems and workflows. However, as AI becomes moredeeply integrated into business operations, new security risks are emerging. One such risk is promptinjection.
This article explains what prompt injection is, explores its potential impact and highlights several practicalmeasures organizations can take to mitigate its risks.
What Is Prompt Injection?
In contrast to social engineering attacks, which attempt to manipulate people, prompt injection attacksaim to manipulate AI systems into performing unintended actions. There are two primary attack types asfollows:
1. Direct prompt injection—Threat actors enter malicious instructions directly into an AI system fornefarious purposes. For instance, they may ask AI to ignore its normal rules or reveal sensitiveinformation.
2. Indirect prompt injection—Threat actors embed malicious instructions within external contentprocessed by AI, which the system mistakenly interprets as legitimate commands. For instance, attackers may hide instructions within a document, email or webpage that direct the AI to ignore itsoriginal task or perform unauthorized actions.
Prompt injection attacks exploit a fundamental limitation in how many AI systems process information.Specifically, large language models (LLMs) process system instructions, user requests and external data through the same mechanism, which can make it difficult for these models to distinguish betweenlegitimate system or user commands and malicious instructions embedded in external content.
According to OWASP, an organization that tracks security risks in AI applications, prompt injection is consistently ranked among the top security risks for LLM applications.
Prompt Injection Example
The following example illustrates how a prompt injection attack could occur in a typical business environment.
A customer service AI assistant helps support agents responding to customer inquiries. The assistant
processes customer-submitted content, such as messages, documents and images, to understand issues and recommend appropriate actions. A threat actor posing as a customer uploads what appears to be a screenshot of a billing issue. Embedded within the image is hidden text that is not visible to the human eye, such as white-on-white text or extremely small font. When the AI processes the image, it interprets
the hidden instructions alongside the legitimate content. The hidden prompt directs the AI to ignore its original task and instead retrieve information from other customer accounts or reveal internal support
procedures. As a result, the organization inadvertently exposes sensitive customer data, resulting in security, privacy and compliance concerns.
Why the Risk Is Growing
Prompt injection risk grows as AI systems take on more direct access to business applications, internal documents, financial systems and other organizational resources. A successful attack can do more than generate a misleading response. A compromised system may manipulate workflows, retrieve data from connected applications or perform unauthorized actions, potentially disrupting business processes and exposing sensitive information.
Prompt injection also differs from most traditional cyberattacks, which typically exploit software vulnerabilities or bypass technical controls. In contrast, prompt injection attacks target the way AI systems interpret and act on information. Consequently, the more deeply AI is integrated into connected systems, the greater the potential impact of successful manipulation.
Potential Business Impact
Possible consequences from prompt injection attacks include exposure of confidential business or customer information, financial losses from fraudulent payments or unauthorized purchases, and operational disruption from unintended AI actions. Prompt injection may also cause AI systems to disregard organizational policies, undermining established controls and potentially contributing to poor business decisions. Notably, these impacts can occur even in the absence of a traditional network breach or software compromise.
Risk Mitigation Tips
To reduce the risk posed by prompt injection, organizations should consider the following risk mitigation measures:
- Limit AI permissions using the principle of least privilege. Organizations should give AI systems access only to the data, applications and functions needed to perform their intended tasks. In addition, credentials and API tokens must be kept separate from the AI, so a compromised system cannot directly access or act on connected systems.
- Require human approval for high-risk actions. Organizations should require human review and approval before AI systems can initiate financial transactions, access customer information, modify policies or carry out other sensitive actions. Human-in-the-loop processes provide an additional safeguard against harmful or unauthorized outcomes.
- Treat external content as untrusted input. Organizations should treat content from external or untrusted sources as data to be analyzed, not instructions to be followed. In practice, this involves filtering and scanning incoming content for potential prompt injection attempts and applying content tagging (or “spotlighting”) to highlight untrusted content and separate it from the AI system’s instructions.
- Monitor AI activity for unusual behavior. Organizations should monitor AI systems for unexpected activity that may indicate a prompt injection attack, including unusual API calls, communications or actions that users did not request, and deviations from intended task flows.
- Train employees in AI-specific security risks. Organizations should educate employees on the security risks associated with AI, including prompt injection. Training should emphasize that, like
people, AI systems can be deceived and that AI-generated outputs should be scrutinized. Employees should also be trained to understand the risk of using unauthorized AI tools—known as “shadow AI”—which can introduce additional security, privacy and compliance risks. - Review cyber insurance and other applicable coverages. Organizations should work with an insurance professional to assess whether their existing cyber insurance and other policies provide
adequate coverage for AI-related risks. Regular reviews can help identify potential coverage gaps and ensure policies remain aligned with the organization’s evolving use of AI technologies.
Conclusion
As organizations continue to integrate AI tools into their business practices, prompt injection attacks have emerged as a key threat. Organizations can reduce their exposure by implementing technical controls, maintaining strong human oversight of AI tools and training employees to identify potential manipulation of AI systems. Organizations should also review their insurance coverage to ensure adequate financial protection.
Contact an Agent
We’d love to talk with you about the superior products and services offered by Unland Insurance & Benefits. Complete the contact form, and we’ll get back to you soon with the customized information and advice you need.