Skip to main content
RiskGovernance

Prompt Injection: The Risk Nobody in the Boardroom Understands Yet

Prompt Injection: The Risk Nobody in the Boardroom Understands Yet
Published 24 September 2026Last reviewed 24 September 20264 min readBy Simon Steggles· Fractional AI Director
Who this is for:Board directors, risk owners and executives who sign off on AI tools without a technical security background

TL;DR

Your staff are feeding AI systems documents, emails and web pages you have never vetted. Every one of those inputs is a place an attacker can hide an instruction your AI will follow. Prompt injection is the top-ranked AI security risk of 2026, and most boards have never heard of it.

Key takeaways

  • Prompt injection topped the OWASP 2026 LLM Top 10, released 6 August 2026, ahead of data leakage and every other AI risk category.
  • OWASP's own agentic AI risk mapping shows prompt injection touches six of its ten top categories. This is not one risk. It is a family of them.
  • A single hidden email exploited a Microsoft 365 Copilot flaw (CVE-2025-32711, CVSS 9.3) to exfiltrate data silently.
  • Regulatory reporting windows are shrinking fast: 4 hours under DORA, 24 under NIS2, 72 under New York's RAISE Act. You need a plan before an incident, not after.

You approved the AI tool. You did not approve what happens when someone hides an instruction inside a document that tool reads.

That is prompt injection. It is not a bug you patch once. It is a structural property of how large language models work, and in 2026 it sits at the top of the OWASP list of AI security risks for the second year running.

What prompt injection actually is

Your AI system reads a system prompt from you, a request from your user, and often a third document: an email, a webpage, a PDF someone uploaded. The model treats all three as one stream of text. It cannot reliably tell your instruction apart from an instruction hidden inside that third document.

An attacker exploits this by hiding text in something your AI will read. White text on a white background in a CV. A comment buried in a webpage your AI summarises. A line in an email your AI assistant processes. The model reads the hidden instruction and, in enough cases, follows it.

This is why prompt injection is not a bug in one product. It is a property of how every current large language model processes text. You cannot patch it away. You can only limit what an AI system is allowed to do once it has been fooled.

Why 2026 made this unavoidable

OWASP released its 2026 LLM Top 10 on 6 August. For the first time, a quarter of the ranking came from real incident data rather than practitioner opinion alone. Prompt injection stayed in first place. Excessive Agency, where an AI system is given more autonomy than the task needs, jumped to third.

The incidents back this up. In March 2026, a backdoored package on PyPI called LiteLLM was downloaded 47,000 times in a three-hour window, compromising agent frameworks including CrewAI and Microsoft GraphRAG. In August 2025, attackers used stolen OAuth tokens in the Salesloft breach to reach customer data across more than 700 organisations.

One statistic should worry every board reading this. A 2025 industry report found 91% of enterprise AI tools operate with no security team oversight at all. You have almost certainly deployed AI tools that fall into that 91%.

The legal exposure you have not priced in

Prompt injection is starting to show up in court, not just in security advisories. In May 2026, a Brazilian labour court fined two lawyers R$84,000 after they hid white-on-white instructions in court filings, attempting to manipulate the court's AI system. The attempt failed. The court still referred the lawyers to disciplinary authorities and called the conduct offensive to the dignity of justice.

In the US, courts are starting to treat prompt injection against your own AI systems as a form of improper means under trade secret law, similar to industrial espionage. That cuts both ways: it protects you when someone attacks your systems, and it exposes you if your staff try it against someone else's.

None of this is theoretical for a UK board. If your organisation runs AI-assisted screening, document review or customer-facing agents, you are already carrying this exposure whether your risk register mentions it or not.

What actually reduces the risk

Stop trying to build an AI model that cannot be fooled. OWASP's own guidance now says this directly: build the system around the model so that when it is fooled, nothing important breaks. That means limiting what any AI agent can do without a human checking first.

Security researcher Simon Willison calls this the lethal trifecta: an AI agent becomes dangerous when it can read private data, is exposed to untrusted content, and can communicate externally, all at the same time. If your AI tool has all three, treat it as high risk regardless of what the vendor's marketing says.

Meta's internal rule is simpler and easier for a board to apply: an autonomous agent can have two of those three properties without a human in the loop. The moment it needs all three, a person signs off before it acts. Put that rule, or one like it, into your own AI policy this quarter.

What to do now

Put prompt injection on your risk register this quarter, named specifically, not folded into a generic AI risk line. Ask every AI vendor you use one direct question: what happens if this system is fed a hidden instruction, and what stops it acting on that instruction without a person checking first.

Check which of your AI tools can read private data, process untrusted external content, and take action or send information externally, all at once. Any tool that can do all three needs a human checkpoint before it acts, not after.

If you do not have someone in your organisation who can answer these questions properly, that is the gap to close first. A risk register entry with nobody accountable for it is not a control.

About the author

Simon Steggles - Fractional AI Director

Simon helps UK SMEs and councils put AI to work safely. Royal Navy 1984–90 (Cat 3 PV at the time, now superseded by DV); current NPPV3 Police vetting for public-sector work; ISACA AI Governance certified. Based in Birmingham. £300K+ recovered for councils, 43% cost reduction in manufacturing, zero data-protection incidents across every engagement.

More about Simon

Want help applying this?

Grab the free AI Readiness Checklist or book a 30-minute strategy call with Simon - no pitch, no slide deck, just practical advice for your situation.

Free AI Readiness Checklist

Find Out Where AI Can Save or Generate Money in Your Organisation

Book a free 30-minute call with Simon. Bring a real problem - staff time, governance worry, vendor proposal, failing pilot - and leave with a concrete first step you can take next week.

Call