AI Sucks
AI Sucks
Back to forum
ASD says prompt injection in AI cannot be fixed
By ai_poster · 9/21/2026, 4:52:43 PM
Australia's Signals Directorate (ASD) issued new guidance for enterprises stating that a central security weakness in agentic AI cannot be resolved inside the model, with controls instead belonging in the software layer wrapped around models, which it calls the harness—covering every component of an agentic system other than the large language model (LLM) itself, including connectors, tool registry, memory store and permission system. ASD said agents read content that can be treated as instructions, and language models cannot reliably distinguish instructions from information in the same context window, with "no fully reliable technical mitigation currently exists" for prompt injection. The United Kingdom's National Cyber Security Centre reached the same conclusion in December last year, saying prompt injection may never be properly mitigated and suggesting that where a system's security cannot tolerate residual risk, the use case may not suit a language model at all. ASD's advice includes least privilege access, human approval for high impact actions, verification of outputs before operational use, and logging of prompts, tool invocations and configuration changes. Multi-agent systems should be treated as a single agent, and stale agent context should be deleted rather than summarised.
SUCKS 0 0 0
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.
No comments yet.