Brief

OpenAI Warns Prompt Injection Threat Persists

OpenAI acknowledges prompt injection attacks cannot be fully eliminated and is using automated AI attackers to harden its Atlas agentic browser against threats.

By Marcus Lee • 1 min read Published: Updated:

OpenAI said prompt injection attacks remain an unresolved security risk for AI agents, even as it rolls out stronger protections for its ChatGPT Atlas browser. In a blog post, the company said that prompt injections, which hide malicious instructions inside web pages or emails, are unlikely to ever be fully eliminated as AI agents gain autonomy and web access.

Atlas, launched in October, allows ChatGPT to browse and act on users’ behalf, expanding what OpenAI described as its security threat surface. Researchers quickly demonstrated that indirect prompt injections could manipulate AI-powered browsers, a challenge also flagged by the U.K.’s National Cyber Security Centre and browser developers including Brave.

To counter the threat, OpenAI said it is relying on layered defenses and rapid patch cycles, including an automated attacker trained with reinforcement learning to simulate hacker behavior. The system tests attacks in simulation, studies how AI agents respond, and iterates to uncover vulnerabilities before they are exploited in real-world settings.

OpenAI said the approach has surfaced novel attack strategies not identified through human red teaming. The company also recommends limiting agent access, requiring user confirmations, and narrowing task instructions to reduce exposure, acknowledging that agentic browsers still involve significant security trade-offs.

Disclaimer: AIstify is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and insights on artificial intelligence, emerging technologies, automation, and related industries. NuvexMedia LLC invests in and collaborates with companies across the AI, technology, software, and digital innovation sectors. These relationships do not influence AIstify’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2026 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.

AI & Machine Learning, Consumer Tech, News