Amazon Web Services (AWS), the SANS Institute, the Open Worldwide Application Security Project (OWASP), and the U.S. National Institute of Standards and Technology (NIST) are now saying that if you’re deploying AI agents, you can’t treat system prompts as a real security boundary. That shift puts prompt injection and runtime controls back at the center of the conversation.
OWASP still lists prompt injection among the top large language model (LLM) risks in its updated Top 10, because attacker-controlled content can steer models into exposing sensitive files or taking actions they shouldn’t. NIST’s 2026 Agent Standards Initiative came after research that, according to NIST, found task hijacks worked 81% of the time. OWASP has also added an Agent Control Standard.
If you’re running agents across internal tools, support, development, or operations, the warning from AWS, SANS, OWASP, and NIST is pretty direct. Put controls in place when an agent reads data, calls tools, or executes actions. Give the agent the same permissions as the user, or fewer. Start from deny, not allow.
You can see the gap in recent adoption data. Deployed agents doubled in four months. Thirty-eight percent of organizations are running more than 100, and more than 80% say they could stop unauthorized data access. Even so, nearly 9 in 10 still reported an agent-related incident, including a 2026 OpenAI plugin ecosystem supply-chain attack that affected 47 enterprises, along with compromises in multi-agent infrastructure.
The latest guidance and standards from AWS, SANS, OWASP, and NIST are available in their published reports and security documentation.
Author: Anthony John Padilla
{
"social": {
"email": "content.reviewer90@ext.softonic.com",
"facebook": "",
"twitter": "",
"linkedin": ""
},
"ja-JP": "",
"de-DE": "Anthony Padilla ist ein auf den Philippinen ansässiger Schriftsteller mit Erfahrung in redaktionellen, digitalen und markenorientierten Inhalten. Seine Arbeit konzentriert sich darauf, komplexe Ideen in klare, verständliche Texte umzuwandeln.",
"en-US": "Anthony Padilla is a Philippines-based writer with experience across editorial, digital, and brand-focused content. His work centers on translating complex ideas into clear, accessible copy, with a strong emphasis on structure, accuracy, and user-focused communication. He has contributed to long-form articles, product and platform copy, and marketing-led editorial pieces.",
"es-ES": "Anthony Padilla es un escritor con base en Filipinas con experiencia en contenido editorial, digital y enfocado en marca. Su trabajo se centra en traducir ideas complejas en textos claros y accesibles.",
"fr-FR": "Anthony Padilla est un écrivain basé aux Philippines ayant de l'expérience dans le contenu éditorial, numérique et axé sur la marque. Son travail consiste à traduire des idées complexes en textes clairs et accessibles.",
"it-IT": "Anthony Padilla è uno scrittore con base nelle Filippine con esperienza in contenuti editoriali, digitali e focalizzati sul brand. Il suo lavoro si concentra sulla traduzione di idee complesse in testi chiari e accessibili.",
"nl-NL": "Anthony Padilla is een schrijver gevestigd op de Filipijnen met ervaring in redactionele, digitale en merkgerichte content. Zijn werk richt zich op het vertalen van complexe ideeën naar helder, begrijpelijke teksten.",
"pl-PL": "Anthony Padilla to pisarz mieszkający na Filipinach z doświadczeniem w tworzeniu treści redakcyjnych, cyfrowych i skoncentrowanych na marce. Jego prace skupiają się na przekształcaniu skomplikowanych idei w jasne, zrozumiałe teksty.",
"pt-BR": "Anthony Padilla é um escritor baseado nas Filipinas com experiência em conteúdo editorial, digital e focado em marca. Seu trabalho se concentra em traduzir ideias complexas em textos claros e acessíveis."
}
View all posts by Anthony John Padilla