ClawSecure says top AI models failed red-team prompt injection tests

11 hours ago
By AI, Created 11:38 UTC, Oct 05, 2026, AGP -

ClawSecure says its two-volume AI Agent Threat Report found systematic failures across models from OpenAI, Anthropic, Google, DeepSeek and Alibaba’s Qwen. The findings raise fresh questions about who is responsible for securing AI agents now being used by developers and businesses.

Why it matters: - ClawSecure says AI agents can be hijacked through ordinary content such as emails, shared documents and support tickets. - The company says those attacks can lead to stolen credentials, drained financial accounts and exposed private data without any mistake by the victim. - The report suggests buyers and developers may be deploying agents without a reliable way to measure prompt-injection risk.

What happened: - ClawSecure published The AI Agent Threat Report on Sept. 24. - The two-volume red-team study tested 14 models from Anthropic, OpenAI, Google, DeepSeek and Alibaba’s Qwen. - ClawSecure says every model failed clean defenses against indirect prompt injection, which OWASP lists as the No. 1 threat to autonomous AI. - The company says it also challenged three Anthropic safety claims using Anthropic’s own words. - One published claim of "0% attack success" was broken at 15.2%, ClawSecure says. - The company also says it exposed default Model Context Protocol vulnerabilities on production platforms including Dropbox Dash, Notion and Linear.

The details: - ClawSecure says attackers can use benign-looking content to hijack an AI agent’s instructions and redirect its behavior. - The report says the tested models obeyed the attacker in every case. - ClawSecure says it disclosed the issues to the labs before publication. - OpenAI told ClawSecure that guardrails are "the developer's responsibility." - Google told "all integrators building agents" to build their own sanitization. - ClawSecure says those expectations are not clearly disclosed to many customers even as the models are marketed widely. - J.D. Salbego, founder and CEO of ClawSecure, said developers now include small teams, vibe coders and SMBs that often lack a security team. - Salbego said AI agents are already running finances, businesses and critical systems, and that content they read can hijack them. - Salbego said there is no standard for measuring that risk and no clear accountability.

Between the lines: - The report lands as policymakers are paying more attention to who bears responsibility for autonomous AI failures. - U.S. Treasury Secretary Scott Bessent said on CNBC that the Hugging Face incident "is the responsibility of the OpenAI management, not a bunch of agents." - Bessent also told the House Financial Services Committee that "the best way to guarantee safety is that the creators are liable for what they build and generate." - ClawSecure has spent the past two months working with bipartisan congressional offices on a national standard for independent AI agent testing. - The proposed framework would let buyers evaluate a model’s injection failure rate before deployment.

What's next: - ClawSecure says the standard is meant to make AI security testing comparable before deployment. - The company says every named company received coordinated disclosure before publication. - ClawSecure made the full report and supporting documents available on its release page. - The broader debate now turns to whether model makers, integrators or customers will be held responsible for securing autonomous agents.

The bottom line: - ClawSecure’s report argues that prompt injection remains a structural weakness across major AI systems, and that the market is handing that risk to developers faster than it is solving it.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

American Tech Today

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

American Tech Today

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.