Prompt injection is your AI feature's front door
The number one risk in the OWASP Top 10 for LLM Applications, explained for founders. What it is, why it is really an access problem, and five things to test before your AI launch.
Every AI feature has a front door, and it is the prompt.
Anything that reaches your model's context can steer it: a user's message, a support ticket, a PDF a customer uploaded, a web page your agent reads. If your model treats that text as instructions, someone else is now giving orders inside your product.
That is prompt injection. It sits at number one in the OWASP Top 10 for LLM Applications.1
This is no longer theoretical
In a Gartner survey of 302 security leaders, 32% said they had faced an attack on AI applications that used the application prompt in the previous 12 months.2
IBM's 2026 Cost of a Data Breach study found that one in four malicious breaches were AI-enabled, and those cost an average of USD 6 million, about USD 1 million more than the average breach.3 Among organisations that reported an AI-related breach, 92% lacked proper AI access controls.4
The good news: teams are catching on. The World Economic Forum's 2026 outlook found that 64% of organisations now assess the security of AI tools before deploying them, up from 37% a year earlier. That still leaves about a third with no such process.5
It is really an access problem
Here is the part founders miss. You cannot fully stop a model from being talked into something. Models are built to follow text.
So the real question is not "can the model be tricked?" It is "what can the model do once it is?"
If your assistant can only answer questions from public docs, a successful injection is embarrassing. If your agent can read every customer's records, send email, or call internal APIs with an admin token, the same injection is a breach.
That is why we test AI features the way we test any system with privileges: by mapping what each tool and data source can reach, then trying to make the model reach further.
Five things to test before your AI launch
- Indirect injection. Put instructions inside content your model reads: a document, a web page, a ticket. See whether it obeys them.
- Tool permissions. List every tool your agent can call and the identity it calls with. Each should work with the user's permissions, not the platform's.
- Data boundaries. Ask the model, directly and indirectly, for another user's data, your system prompt and anything in retrieval it should not show.
- Output handling. Check what happens to model output downstream. If it is rendered as HTML, run as code, or passed to another system, injection travels with it.
- Cost and abuse. Try long, looping or expensive requests. An agent that can be made to run forever is a bill, and sometimes an outage.
How we approach it
Our AI security engagements follow the OWASP Top 10 for LLM Applications and MITRE ATLAS, combine automated attacks with manual testing, and end with the same thing every DXCL engagement does: a report your engineers can act on the same day, a walkthrough with the testers, a check of your fixes, and a certificate your buyers can verify.
If you are about to ship an assistant, an agent, or retrieval over customer data, test it before your users do.
Sources
- OWASP Gen AI Security Project, LLM01 Prompt Injection.
- Gartner, survey of 302 cybersecurity leaders, March to May 2025 (press release, 22 September 2025).
- IBM, Cost of a Data Breach Report 2026 (press release, 29 July 2026).
- IBM X-Force, 2026 Cost of a Data Breach: AI adversaries and enterprise risk.
- World Economic Forum, Global Cybersecurity Outlook 2026.