AI threats in the wild: The current state of prompt injections on the web
Posted by Thomas Brunner, Yu-Han Liu, Moni Pande At Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users.
Posted by Thomas Brunner, Yu-Han Liu, Moni Pande At Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the security community, anticipating it as a primary attack vector for adversaries to target and compromise AI agents. To answer these questions and to uncover real-world abuse, we initiated a broad sweep of the public web to monitor for known indirect prompt injection patterns. The threat of indirect prompt injection Unlike a direct injection where a user "jailbreaks" a chatbot, IPI occurs when an AI system processes content—like a website, email, or document—that contains malicious instructions.
Despite this collective focus, a fundamental question remains: to what degree are real-world malicious actors currently operationalizing these attacks?
What changed
Proactive monitoring at Google The landscape of IPI on the web There are many channels through which attackers might try to send prompt injections.
How organizations are responding
Despite this collective focus, a fundamental question remains: to what degree are real-world malicious actors currently operationalizing these attacks?
What to watch next
Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.
What remains unknown
The available reporting does not establish whether the issue is being actively exploited in the wild.