Security News

ASD Warns Businesses: AI's Biggest Flaw Can't Be Patched, Only Contained

iTnews · 21 Sept 2026
Key Takeaway Small businesses adopting AI tools should limit what those tools can access and do, rather than assuming the AI itself can be made fully secure.

The Australian Signals Directorate (ASD) has released guidance warning that a fundamental security weakness in agentic AI systems has no reliable technical fix. The issue, known as prompt injection, occurs because AI language models process instructions and data in the same stream and cannot reliably tell the difference between the two. This means malicious content fed to an AI agent can be mistaken for a legitimate command.

ASD's guidance introduces the concept of the 'harness', everything surrounding the AI model itself, including connectors, permission systems, and memory stores. Because organisations cannot fix the underlying model, ASD argues the harness is the part they actually control and should focus on securing. The agency notes this harness will likely remain in use across multiple generations of AI models.

This view aligns with the UK's National Cyber Security Centre, which reached a similar conclusion last year, comparing AI models to an inherently 'confusable deputy' rather than a system with a bug that can simply be patched. Both agencies suggest that where the risk is too high, some use cases may simply not be suitable for AI at all.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from iTnews. We link back to every original so you can read it yourself.