{"id":376787,"date":"2026-09-03T02:20:00","date_gmt":"2026-09-03T09:20:00","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/en\/?p=376787"},"modified":"2026-09-03T02:20:39","modified_gmt":"2026-09-03T09:20:39","slug":"aws-sans-owasp-and-nist-warn-system-prompts-arent-a-security-boundary","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/aws-sans-owasp-and-nist-warn-system-prompts-arent-a-security-boundary\/","title":{"rendered":"AWS, SANS, OWASP and NIST warn: system prompts aren\u2019t a security boundary"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Amazon Web Services (AWS), the SANS Institute, the Open Worldwide Application Security Project (OWASP), and the U.S. National Institute of Standards and Technology (NIST) are now saying that if you&#8217;re deploying AI agents, you can&#8217;t treat <strong>system prompts<\/strong> as a real security boundary. That shift puts <a href=\"https:\/\/en.softonic.com\/articles\/autonomous-software-agents-face-fresh-hacking-attacks-hidden-instructions-can-leak-your-data\" rel=\"noopener\">prompt injection<\/a> and runtime controls back at the center of the conversation.<\/p>\n\n<p class=\"wp-block-paragraph\">OWASP still lists prompt injection among the top large language model (LLM) risks in its updated Top 10, because attacker-controlled content can steer models into exposing <strong>sensitive files<\/strong> or taking actions they shouldn&#8217;t. NIST&#8217;s 2026 Agent Standards Initiative came after research that, according to NIST, found task hijacks worked 81% of the time. OWASP has also added an Agent Control Standard.<\/p>\n\n<p class=\"wp-block-paragraph\">If you&#8217;re running agents across internal tools, support, development, or operations, the warning from AWS, SANS, OWASP, and NIST is pretty direct. Put controls in place when an agent reads data, calls tools, or executes actions. Give the agent the same permissions as the user, or fewer. Start from <strong>deny, not allow<\/strong>.<\/p>\n\n<p class=\"wp-block-paragraph\">You can see the gap in recent adoption data. Deployed agents doubled in four months. Thirty-eight percent of organizations are running more than 100, and <strong>more than 80%<\/strong> say they could stop unauthorized data access. Even so, nearly 9 in 10 still reported an agent-related incident, including a 2026 OpenAI plugin ecosystem supply-chain attack that affected 47 enterprises, along with compromises in multi-agent infrastructure.<\/p>\n\n<p class=\"wp-block-paragraph\">The latest guidance and standards from AWS, SANS, OWASP, and NIST are available in their published reports and security documentation.<\/p>","protected":false},"excerpt":{"rendered":"<p>Amazon Web Services (AWS), the SANS Institute, the Open Worldwide Application Security Project (OWASP), and the U.S. National Institute of Standards and Technology (NIST) are now saying that if you&#8217;re deploying AI agents, you can&#8217;t treat system prompts as a real security boundary. That shift puts prompt injection and runtime controls back at the center &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/aws-sans-owasp-and-nist-warn-system-prompts-arent-a-security-boundary\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;AWS, SANS, OWASP and NIST warn: system prompts aren\u2019t a security boundary&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9332,"featured_media":376786,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[6771],"class_list":["post-376787","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","content-category-ai"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/376787","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9332"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=376787"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/376787\/revisions"}],"predecessor-version":[{"id":376788,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/376787\/revisions\/376788"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/376786"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=376787"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=376787"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=376787"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=376787"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=376787"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=376787"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}