Securing AI agents: prompt injection, shadow AI and the AI Act
An AI agent reads content it does not control and acts with real rights. The risks specific to agents, shadow AI, the guardrails to put in place before production, and what the AI Act asks for.
Securing an AI agent means deciding in advance what it can see, what it can do and who approves its sensitive actions, then checking it continuously. An agent is not like other software: it reads content it does not control, it acts with real rights, and a well-crafted piece of text can be enough to hijack it.
This article covers the risks specific to agents, shadow AI, the guardrails to put in place before production, and what the AI Act asks for. For what an agent is, see our article on agentic AI.
The risks specific to agents
Prompt injection. It tops the list of language model risks published by OWASP, in both its 2025 and 2026 editions. It is direct when someone types an instruction that hijacks the model, and indirect when the model reads outside content (a web page, an email, a document, a tool’s output) that hides instructions. For an agent, the second is the more dangerous: a booby-trapped email can ask it to forward documents, and it has the rights to do so.
Unwanted actions. An agent with more rights than its task needs can go further than intended: delete instead of archive, send instead of prepare.
Data leaks. An agent can pass information to an outside service, or show a user data they are not allowed to see.
In December 2025, OWASP published a list dedicated to agentic applications. It adds, among others, agent goal hijacking, tool misuse, identity and privilege abuse, memory poisoning, and cascading failures when several agents are chained together.
Shadow AI: AI used without a frame
Shadow AI means the AI tools employees use without the company’s approval. It is common: according to Microsoft and LinkedIn’s Work Trend Index (May 2024), 75% of knowledge workers already used AI at work, and 78% of those users brought their own tools. In France, an Ifop survey for Talan (March 2025) found that only 9% of employees said their company had rolled out generative AI tools on their computers.
The cost is measurable: in its 2025 Cost of a Data Breach report (July 2025), IBM says one organisation in five suffered a breach linked to shadow AI, with an average extra cost of 670,000 dollars.
A ban alone is not enough, since the uses already exist. What works: map the uses, offer an approved tool, and set written rules. The French data protection authority (CNIL) recommends framing the use of generative AI with an internal policy or charter, and the French cybersecurity agency (ANSSI) says sensitive data must never go into public online AI tools.
The guardrails to put in place before production
- An inventory: for each agent, the data it touches and the actions it can trigger.
- Its own identity and least-privilege rights, reviewed regularly, as ANSSI recommends for the rights of AI tools on business applications.
- No automatic critical action: ANSSI asked for this in its 2024 guide on generative AI, and CERT-FR stated in April 2026 that human approval must be mandatory whenever a system command or an action with side effects is considered.
- Outside content treated as untrusted: an email or web page the agent reads must not be able to trigger an action on its own.
- Attack testing before production: we try to hijack the agent with booby-trapped content, as an attacker would.
- Logs, alerts and an emergency stop: every action is logged, and the agent can be suspended at any time.
- A sandbox first: the agent proves itself on dummy data, in an isolated environment.
Our offer AI agents under control puts these guardrails in place in your tools, and the page Agentic AI under your control shows how we build them in from the design stage.
What the AI Act asks for, and from when
The AI Act does not create a separate category for agents: an agent is an AI system, subject to the rules that match its use. It mainly distinguishes two roles. The provider develops a system and places it on the market under its own name; the deployer uses it under its own authority. A company that uses an agent for its own processes is usually a deployer.
- Since 2 February 2025: the banned uses, and the obligation to take measures to support the AI literacy of the people who use it (eased by the 2026 omnibus regulation).
- Since 2 August 2026: most other rules, including transparency. A person dealing with an agent must know they are talking to an AI.
- From 2 December 2027: high-risk systems in the areas the regulation lists (such as employment and access to essential services), then 2 August 2028 for those built into products. These dates come from Regulation (EU) 2026/1744, in force since 27 July 2026.
A well-framed agent (inventory, limited rights, human approval, logs) makes these obligations easier to meet, but does not replace that work: the level of risk depends on the use, and has to be assessed case by case. The glossary sums up the timeline.
Who decides: management, security, business teams
- Management sets the authorised uses and the level of risk accepted.
- The IT department and the CISO approve the tools before any rollout, as CERT-FR recommends.
- Business teams own the processes handed to agents and the human approvals.
- The data protection officer follows personal data: the CNIL published an exploratory note on agentic AI and personal data in July 2026.
Frequently asked questions
What is prompt injection?
An attack that slips instructions into what an AI model reads, to make it do something other than what is expected. It can come from the user or, for an agent, from a document, an email or a web page it consults.
What is shadow AI?
Employees using AI tools without the company’s approval, often with personal accounts. The main risk is data leaking to services the company does not control.
Does the AI Act apply to our agents?
Yes, as it does to any AI system, with obligations that depend on the use: transparency towards people, AI literacy for teams, and stronger obligations if the use is classed as high-risk.
Should every action of an agent be approved?
No, only those that commit the company: sending, paying, deleting, changing a system. Reading, searching and preparing can stay automatic, provided they are logged.
Sources
Facts and figures checked on 3 October 2026.
- OWASP, Top 10 for LLM Applications, 2026 edition, August 2026.
- OWASP, Top 10 for Agentic Applications, 9 December 2025.
- ANSSI, security recommendations for a generative AI system, 29 April 2024 (in French).
- CERT-FR, bulletin CERTFR-2026-ACT-016, 13 April 2026 (in French).
- Microsoft and LinkedIn, 2024 Work Trend Index, 8 May 2024.
- IBM, Cost of a Data Breach Report 2025, 30 July 2025.
- Ifop for Talan, the French and generative AI, wave 3, fieldwork March 2025 (in French).
- European Commission, regulatory framework for AI (AI Act).
- AI Act Service Desk, Article 50 (transparency).
- CNIL, Q&A on using a generative AI system, 18 July 2024 (in French).
- CNIL and CIANum, note on agentic AI and personal data, 20 July 2026 (in French).