
Lakera detections of indirect prompt injection tripled in Q1. Runtime validation becomes critical as enterprises deploy AI agents without content filtering. OWASP 2026 framework adds controls.
A class of security attack that targets the reasoning layer of artificial intelligence agents is accelerating faster than most enterprise defenses can keep pace, according to data from Lakera, a private startup that sells runtime security for large language models.
Lakera's detection of indirect prompt injection attempts tripled between January and March, the company said. The technique does not exploit software vulnerabilities or steal credentials. Attackers embed malicious instructions inside content that AI agents consume – webpages, PDFs, API responses, tool outputs – and the language model treats all of that as part of its reasoning context.
To the model, the injected instruction is indistinguishable from the user's prompt. An agent browsing a competitor's documentation page, summarizing a PDF, or processing a tool call could be redirected to ignore user intent, leak data, or execute unintended actions.
Companies that offer AI agents and copilots are the most exposed. Microsoft's Copilot, Google's Gemini agents, and Salesforce's Agentforce all retrieve external content and execute tool calls. An attacker could inject instructions in a JSON-LD snippet from a legitimate website or in a frequently referenced policy document, three cybersecurity analysts familiar with enterprise deployments said.
Timeline matters. The OWASP Application Security Framework for AI, version 2026, now includes runtime validation of all context inputs as a core control. The framework is scheduled for final release in mid-2026. Lakera's public documentation shows the tripling of injection attempts preceded the OWASP update by several quarters, the analysts noted.
The risk can be reduced. Runtime prompt defense products scan every piece of content before it reaches the LLM. Lakera Guard runs as middleware in the Edge Runtime and flags injected instructions before the model processes them. Enterprises that adopt such validation layers shrink the attack surface. Several large banks and technology companies have started testing these controls internally, the analysts said.
What would make the situation worse is reliance on system prompts and model alignment. Those techniques stop zero-shot attacks but fail against adversarial content embedded in trusted-looking sources. An agent that browses the web or summarizes PDFs without intermediate filtering remains vulnerable. The longer enterprises delay runtime validation, the more likely a high-profile breach becomes, the analysts cautioned.
No such incident has been reported yet. The most concrete marker is the rate of detection at Lakera and similar providers. A spike in blocked injections across production systems would confirm the risk is material. A significant security incident at a major agent platform would trigger the downside.
The immediate market read is a catalyst for cybersecurity vendors that sell LLM-specific defenses. Private firms like Lakera, Protect.ai, and CalypsoAI are raising capital on this thesis. Public names like CrowdStrike and Palo Alto Networks have begun to offer LLM security modules. The bigger second-order effect may hit enterprise software stocks. If a public incident involves a widely used copilot, it could slow adoption timelines and raise compliance costs for Microsoft, Google, and Salesforce.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.