Editorial

Prompt Injection 101:

What It Is and How to Stay Ahead

Wednesday, September 09, 2026 | 5 MINS

Every AI agent your company deploys will follow instructions, that's the point. 


What it can't do is reliably tell whose instructions those are: yours, or an attacker's, hidden inside an email, a shared document, or a webpage it was just asked to read. Join Javvad Malik, Lead CISO Advisor at KnowBe4, and Jack Chapman, SVP Threat Intelligence at KnowBe4, for a walk through both attack paths, direct and indirect prompt injection, and what changes when you start treating your AI agent like a new colleague instead of a piece of software.

What you'll learn:

  • What indirect prompt injection actually is, and why it's fundamentally different from phishing a human
  • How attackers are hiding instructions in the everyday content your AI agent reads on your behalf
  • Real-world prompt injection incidents from 2025-2026, not research papers, but production system
  • Three "what if" scenarios to get you thinking about your own environment
  • Why the controls that protect people from phishing don't automatically transfer to AI agents, and what to put in place instead

WEBINAR


Reshape how you think about AI agent security

Join this webinar from KnowBe4 on 17 September

REGISTER

Also in this section