Prompt injection
Instructions hidden in a document, a web page or a support ticket that your assistant follows as if they came from you.
Your customers ask, your board asks, and — depending on where you operate — the law now asks too. Here is the risk your AI actually carries, the frameworks you’ll be measured against, and the evidence that satisfies the people asking.
A chatbot that says something wrong is embarrassing. An agent with credentials, tools and memory that says something wrong moves money, sends data or deploys code. These are the risks the industry ranks highest going into 2026.
Instructions hidden in a document, a web page or a support ticket that your assistant follows as if they came from you.
An assistant trusted with more reach than the job needs. Once it can act — refund, email, deploy — a bad answer becomes a bad action.
System prompts, tool schemas and policy rules leaking out, handing an attacker the map of how your AI decides.
One crafted request that sets off a cascade of model calls and tool invocations, with your cloud bill as the payload.
Retrieval stores and long-term memory an attacker can write to today and harvest from for months.
Models, adapters, plugins and connectors pulled in from outside — each one code you didn’t write, running next to your data.
Ranking follows the OWASP Top 10 for LLM Applications (2026) and the OWASP Top 10 for Agentic Applications.
Shadow-AI incidents more than doubled last year, reaching 43% of breached organizations, and a high level of it added roughly $670,000 to the cost of a breach. You cannot govern, test or defend what nobody has written down.
The first useful step is rarely a policy. It’s an honest inventory of what your people and your vendors have already switched on.
Ask us what we’d look forSix names come up in nearly every AI security conversation. Only one of them is law — but your customers and auditors will ask about the rest, and they mostly agree with each other.
| Framework | What it is | What it asks of you |
|---|---|---|
| EU AI Act | Binding law | Risk management, documentation and real human oversight for high-risk uses. General-purpose model duties are already in force, Commission enforcement begins August 2026 and high-risk obligations follow in December 2027. Penalties reach €15M or 3% of global turnover. |
| ISO/IEC 42001 | Certifiable standard | A management system for AI that you can be audited and certified against — the ISO 27001 pattern, applied to the AI you build and use. |
| NIST AI RMF | Voluntary baseline | Govern, map, measure and manage AI risk, with a generative-AI profile that calls for testing before deployment and disclosure when something goes wrong. |
| OWASP — LLM & Agentic Top 10 | Engineering risk list | The risks your developers are expected to design against, refreshed for 2026 and extended to autonomous, tool-using agents. |
| MITRE ATLAS | Adversary knowledge base | ATT&CK for AI: the tactics and techniques used against machine-learning and agentic systems, now including agent-specific attacks. |
| CSA AI Controls Matrix | Control set & assurance | More than 240 AI control objectives across 18 domains, mapped to ISO 42001, NIST and the EU AI Act, with an assurance track for showing customers. |
Figures cited: IBM / Ponemon Institute, Cost of a Data Breach Report 2026 · OWASP Top 10 for LLM Applications (2026) and OWASP Top 10 for Agentic Applications · MITRE ATLAS · Cloud Security Alliance AI Controls Matrix · the EU AI Act. Penetration testing price ranges are published industry averages for 2026, not our pricing. Dates and obligations here are a plain-language summary, not legal advice — check them against your own counsel.
Every one of these frameworks converges on the same thing: not a policy saying oversight exists, but proof it was working. Here’s what satisfies the people who ask.
Every model, assistant and agent in use — including the ones nobody approved.
Someone outside your build team having genuinely tried to break it, and written down what happened.
Not just logs showing something ran: proof the guardrails and human checks were working while it ran.
What each agent can reach and do, scoped and reviewed. In AI-related breaches last year, 92% of organizations had no proper AI access controls.
The same testing expressed in the language of the EU AI Act, ISO 42001 or NIST, so you answer once and file it everywhere.
A named, certified person standing behind the result — what auditors and enterprise buyers ask for when the answer matters.
Tell us what your AI touches. A certified tester will tell you what we’d test and what you could show.
Not sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.
Free. No obligation.