Prompt Injection Is Driving AI Security Offerings for Runtime Controls; a Boon for the IAM Space
By Michela Menting |
24 Sep 2026 |
IN-8288
Log In to unlock this content.
You have x unlocks remaining.
This content falls outside of your subscription, but you may view up to five pieces of premium content outside of your subscription each month
You have x unlocks remaining.
By Michela Menting |
24 Sep 2026 |
IN-8288
NEWSThe New SQL Injection of Agentic AI |
Prompt injection is moving quickly from being viewed as an unusual Large Language Model (LLM) failure mode to a mainstream technique, leveraged by threat actors with increasing success. Earlier this year, Forcepoint X-Labs identified 10 verified indirect-prompt-injection payloads on public websites. Concurrently, Google’s April public-web sweep found a 32% increase in malicious indirect-prompt-injection content between November 2025 and February 2026, based on repeated scanning of roughly 2–3 billion crawled pages per month (through Common Crawl). OWASP had already placed prompt injection at the top of LLM risks in 2025 (LLM01). The advantage of prompt injection techniques means that threat actors don’t need to have any access to the model itself or the training data; they simply exploit the public-facing function of the Artificial Intelligence (AI), making this accessible to anyone with Internet access.
IMPACTA Fast-Maturing Commercial Opportunity for the Cybersecurity Sector |
Prompt injection is a growing issue. The business impact can be significant, notably when a compromised agent has authority to access internal resources and otherwise private assets such as inboxes, files, credentials, source code, cloud environments, payment tools, or business applications. As LLMs do not reliably distinguish operator instructions from untrusted data within the same context window, threat actors can compromise dependencies and exploit quite a large number of inputs that an AI coding agent ingests as trusted context. The large uptake of Model Context Protocols (MCPs) within the enterprise sector makes this particularly relevant as they serve as the gateway for AI and agents to interact with lot of corporate assets, from internal databases, to security platforms, to operating systems. A successful attack on an MCP could have disastrous consequences, with Agentic AI a force multiplier for prompt injections targeting MCPs.
Though prompt injection attacks have been discussed in professional and academic circles for almost a decade, the cybersecurity industry is only countering the trend now, as it really has only become a successfully viable threat vector with the rise of Generative Artificial Intelligence (Gen AI). A spate of new product launches and Mergers and Acquisitions (M&A) activity is scrambling to offer viable solutions, notably around AI gateways, AI application security, and agent runtime protection. HackerOne launched Agentic Prompt Injection Testing and Arcjet revealed prompt-injection protection for its application layer security platform, both in March of this year. Constellation Network announced Gate AI (which includes prompt-injection defense). Most recently OpenAI stepped up its offensive efforts with GPT-Red, which automates red-teaming systems to adversarially train models for prompt-injection robustness.
What’s clear is that prompt-injection is fast becoming a feature of AI security, and M&A activity has already concentrated the key specialists (e.g., Palo Alto Networks with Protect AI, Check Point and Lakera, SentinelOne with Prompt Security, Cisco with Robust Intelligence, and F5 with CalypsoAI).
RECOMMENDATIONSRuntime Controls to Identity & Access Management |
At its core, prompt injection is an authority and trust boundary issue. In large part, this follows similar evolutions in the application security market (e.g., Application Programming Interface (API) security, identity, and runtime policy enforcement).
However, prompt injection may be a little harder to solve. AI interaction is largely non-deterministic, so the same prompt can produce different results depending on variable parameters (e.g., model, version, descriptors, prior context, etc.). So a binary security solution will not work as well. The key lies around minimizing the ability of prompt-injection attacks to acquire legitimate authority; especially in cases where there is a high-risk point of failure (e.g., MCP, multi-hop delegation, autonomous sub-agent creation, etc.). This is on a different scale compared to the issues dealt with by traditional Identity and Access Management (IAM) solutions and providers need to adapt accordingly.
Runtime controls offer a good angle and the market response for effective mitigation should focus on various, but interrelated techniques: identity, constrained tool permissions, external authorization, policy enforcement, sandboxing, output validation/filtering, provenance-aware Retrieval-Augmented Generation (RAG), Data Loss Prevention (DLP), monitoring, and user confirmation for consequential actions. Prompt-injection cannot effectively be eliminated; but its impact and ability to move laterally can be minimized by integrating basic identity, authorization, and access controls adapted to the AI age.
Written by Michela Menting
Michela Menting leads ABI Research’s coverage of digital security, IoT, and space technologies. She delivers end-to-end research, closely analyzing technology trends, growth opportunities, and industry-specific implementations in end markets, including enterprise, government, financial, telecommunications, industrial, and IoT. She has extensive experience and industry insight into the latest solutions in digital security technologies, from trusted silicon and hardware to secure applications and infrastructures.
- Competitive & Market Intelligence
- Executive & C-Suite
- Marketing
- Product Strategy
- Startup Leader & Founder
- Users & Implementers
Job Role
- Telco & Communications
- Hyperscalers
- Industrial & Manufacturing
- Semiconductor
- Supply Chain
- Industry & Trade Organizations
Industry
Services
Spotlights
5G, Cloud & Networks
- 5G Devices, Smartphones & Wearables
- 5G, 6G & Open RAN
- Data Centers
- Enterprise Connectivity
- Space Technologies & Innovation
- Telco AI
AI & Robotics
Automotive
Bluetooth, Wi-Fi & Short Range Wireless
Cyber & Digital Security
- Citizen Digital Identity
- Digital Payment Technologies
- eSIM & SIM Solutions
- Quantum Safe Technologies
- Trusted Device Solutions