Name: Towards AI Legal Name: Towards AI, Inc. Description: Towards AI is the world's leading artificial intelligence (AI) and technology publication. Read by thought-leaders and decision-makers around the world. Phone Number: +1-650-246-9381 Email: pub@towardsai.net
228 Park Avenue South New York, NY 10003 United States
Website: Publisher: https://towardsai.net/#publisher Diversity Policy: https://towardsai.net/about Ethics Policy: https://towardsai.net/about Masthead: https://towardsai.net/about
Name: Towards AI Legal Name: Towards AI, Inc. Description: Towards AI is the world's leading artificial intelligence (AI) and technology publication. Founders: Roberto Iriondo, , Job Title: Co-founder and Advisor Works for: Towards AI, Inc. Follow Roberto: X, LinkedIn, GitHub, Google Scholar, Towards AI Profile, Medium, ML@CMU, FreeCodeCamp, Crunchbase, Bloomberg, Roberto Iriondo, Generative AI Lab, Generative AI Lab VeloxTrend Ultrarix Capital Partners Denis Piffaretti, Job Title: Co-founder Works for: Towards AI, Inc. Louie Peters, Job Title: Co-founder Works for: Towards AI, Inc. Louis-François Bouchard, Job Title: Co-founder Works for: Towards AI, Inc. Cover:
Towards AI Cover
Logo:
Towards AI Logo
Areas Served: Worldwide Alternate Name: Towards AI, Inc. Alternate Name: Towards AI Co. Alternate Name: towards ai Alternate Name: towardsai Alternate Name: towards.ai Alternate Name: tai Alternate Name: toward ai Alternate Name: toward.ai Alternate Name: Towards AI, Inc. Alternate Name: towardsai.net Alternate Name: pub.towardsai.net
5 stars – based on 497 reviews

Frequently Used, Contextual References

TODO: Remember to copy unique IDs whenever it needs used. i.e., URL: 304b2e42315e

Resources

Free: 6-day Agentic AI Engineering Email Guide.
Learnings from Towards AI's hands-on work with real clients.
Prompt Injection and Agent Security: The Unsolved Problem
Artificial Intelligence   Latest   Machine Learning

Prompt Injection and Agent Security: The Unsolved Problem

Last Updated on August 25, 2026 by Editorial Team

Author(s): Shrashti Singhal

Originally published on Towards AI.

Your agent can’t tell your instructions from an attacker’s. Nobody’s fully fixed that — and the more capable your agent gets, the more that costs you. Part nine of a series on building production AI agents.

In June 2025, security researchers disclosed a vulnerability in Microsoft 365 Copilot that they named EchoLeak. It worked like this: an attacker sends you an ordinary-looking email. You never open it, never click anything, never even read it. But Copilot reads it — because Copilot reads your whole inbox to answer your questions — and hidden inside that email are instructions telling Copilot to gather sensitive data from your other documents and quietly ship it to an external server through an auto-loading image. Zero clicks. The victim does nothing wrong. The agent does exactly what it was told, by the wrong person.

Prompt Injection and Agent Security: The Unsolved Problem

Image 01: same-channel.png

The article argues that prompt injection remains fundamentally unresolved for agentic systems because the model receives both trusted instructions and untrusted attacker content through the same in-band token stream, so it can’t reliably distinguish “friend” from “foe.” It explains why agents amplify risk compared to chatbots: an agent’s outputs are actions with real tools and privileges, creating a “lethal trifecta” where (1) access to private data, (2) exposure to untrusted content, and (3) external communication can combine into data exfiltration. Using incidents like EchoLeak and the GitHub MCP heist, it shows that the most effective fixes are architectural rather than purely model-based—breaking or preventing the trifecta via policy controls, scoped/least-privilege credentials, permission ladders with enforced harness rules, and separating planning from untrusted data (e.g., Dual LLM/CaMeL-style provenance-tagging). It also emphasizes layered defense: classifiers help as a cost-raiser but are never sufficient against adaptive attackers, while tracing/“flight recorder” observability enables detection and forensics. The piece concludes that the path forward is to assume the model will be fooled and to move the security boundary into the surrounding harness and system design—rather than relying on smarter prompts.

Read the full blog for free on Medium.

Join thousands of data leaders on the AI newsletter. Join over 80,000 subscribers and keep up to date with the latest developments in AI. From research to projects and ideas. If you are building an AI startup, an AI-related product, or a service, we invite you to consider becoming a sponsor.

Published via Towards AI


Towards AI Academy

We Build Enterprise-Grade AI. We'll Teach You to Master It Too.

15 engineers. 100,000+ students. Towards AI Academy teaches what actually survives production.

Start free — no commitment:

6-Day Agentic AI Engineering Email Guide — one practical lesson per day

Agents Architecture Cheatsheet — 3 years of architecture decisions in 6 pages

Our courses:

AI Engineering Certification — 90+ lessons from project selection to deployed product. The most comprehensive practical LLM course out there.

Agent Engineering Course — Hands on with production agent architectures, memory, routing, and eval frameworks — built from real enterprise engagements.

AI for Work — Understand, evaluate, and apply AI for complex work tasks.

Note: Article content contains the views of the contributing authors and not Towards AI.