Two years ago, AI security was mostly about preventing chatbots from writing bad poetry or circumventing safety filters. Today, we are trying to stop autonomous agents from exfiltrating our corporate data. The attack surface has shifted so quickly that the controls we built in 2024 look almost quaint.

With the week wrapping up, I want to step back and look at how the AI security beat has evolved over the last 24 months, and why the stakes are completely different now.

2024: The Chatbot Era and Direct Injection

If you look back to October 2024, our primary concern was direct prompt injection. Attackers were focused on finding clever ways to bypass alignment guardrails. The risk was mostly reputation damage—a model saying something offensive, generating bad code, or giving bad advice.

Security teams treated LLMs like untrusted input forms. We tried to bolt on input validation and prompt scanning to catch the jailbreaks. The AI was a walled-off oracle; you asked it a question, and it gave you an answer. It could not take action on your behalf, so the blast radius of a successful attack was relatively small.

2025: The Integration Era and Indirect Injection

By late 2025, everything changed. We moved past isolated chatbots and started integrating AI directly into our workflows. Suddenly, models had access to our documents, our emails, and our codebases through Retrieval-Augmented Generation (RAG).

The threat shifted to indirect prompt injection. Attackers realized they did not need to interact with the model directly. Instead, they could hide malicious instructions inside a document or a webpage that the AI would eventually read.[2] If a user’s AI assistant summarized a manipulated document, the agent effectively became a vector for the attacker.[2]

We saw adversaries embed hidden instructions in phishing emails specifically designed to confuse AI-based triage systems.[2] The risk moved from content generation to data exposure. The model was no longer just answering questions; it was summarizing sensitive internal data, and attackers were finding ways to trick the model into leaking that data back to them.

2026: Agentic Sprawl and Excessive Agency

Which brings us to today. The new 2026 OWASP Top 10 for LLM Applications tells the story clearly: “Excessive Agency” jumped from number six in 2025 to number three today.[1]

We are no longer just dealing with systems that retrieve data. We are deploying agentic AI systems that plan, reason, and execute actions across enterprise infrastructure without continuous human oversight.[3] These agents have persistent memory, they hold credentials, and they make API calls to other systems.[1][3]

Prompt injection remains the number one risk on the OWASP list, but the consequences of a successful injection are entirely different.[1] When an attacker hijacks an agent’s goals today, they are not just getting a bad response. They are hijacking the agent’s permissions. They can abuse tool calls, poison the agent’s memory, or trigger unauthorized data exfiltration.[3]

We are finding out that traditional application security controls miss these new attack vectors entirely.[3] You cannot just scan a prompt for bad words when the attacker’s payload is a hidden instruction in a PDF that tricks an agent into sending an email to an external domain.

Securing the Machine Identity

The shift from 2024 to 2026 is a shift from securing an application to securing an identity. When you give an AI the ability to act on your behalf, it becomes a machine identity. It needs least-privilege access, runtime monitoring, and strict boundaries on what actions it can take without human approval.

The AI security conversation is no longer a niche topic for machine learning researchers. It is an identity and access management problem, and it is landing right on the practitioner’s desk.

Sources

[1] https://www.paloaltonetworks.com/blog/security-operations/owasp-top-10-data-security-2026 — What the 2026 OWASP Top 10 Tells Us About the Growing Role of Data Security [2] https://www.crowdstrike.com/en-us/cybersecurity-101/artificial-intelligence/ai-monitoring — CrowdStrike: AI Monitoring: Key Concepts and Best Practices [3] https://www.paloaltonetworks.com/cyberpedia/agentic-ai-security-solutions — Agentic AI Security Solutions: Top 7 Platforms Compared