---
title: Prompt Injection Is a Permissions Problem
description: "The ASD says prompt injection can't be fixed inside the model. Google says attackers are already running agentic attack pipelines. The short version for Australian security leaders: guardrails you control plus a permission model you designed, and most organisations have neither."
image: https://www.saltt.tech/hubfs/blog/featured-images/prompt-injection-is-a-permissions-problem-20260923103900.jpg
---

[![SALTT Technologies](https://www.saltt.tech/hubfs/raw_assets/public/saltt-theme/images/logo.svg)](https://www.saltt.tech/)

- [Home](https://www.saltt.tech/)
- [Services](https://www.saltt.tech/services)
  
  [Cybersecurity Architecture & Engineering](https://www.saltt.tech/services/security-architecture) [Penetration Testing & Technical Assurance](https://www.saltt.tech/services/penetration-testing) [AI Cybersecurity](https://www.saltt.tech/services/ai-cybersecurity) [Governance, Risk & Compliance](https://www.saltt.tech/services/grc) [CyberOps Management](https://www.saltt.tech/services/cyberops)
  
  [View all services →](https://www.saltt.tech/services)
- [About](https://www.saltt.tech/about)
- [Insights](https://www.saltt.tech/insights)
- [Contact](https://www.saltt.tech/contact)

[Get in Touch](https://www.saltt.tech/contact)

[Insights](https://www.saltt.tech/insights) › Cybersecurity

Cybersecurity 30 September 2026

# Prompt Injection Is a Permissions Problem

The ASD says prompt injection can't be fixed inside the model. Google says attackers are already running agentic attack pipelines. The short version for Australian security leaders: guardrails you control plus a permission model you designed, and most organisations have neither.

# Prompt Injection Is a Permissions Problem

*Two national agencies say the model can't be fixed. Google says attackers aren't waiting. Here's what that means for where you put your controls.*

**SALTT Technologies | 30 September 2026**

---

In January, Microsoft patched a prompt injection flaw in Copilot Studio. Its safety mechanisms had flagged a malicious request as suspicious. The customer data left anyway, because the agent sent it through Outlook, a tool it was allowed to use, to an address it was asked to use. Nothing the customer controlled sat between the flag and the send.

That case (ShareLeak, CVE-2026-21520, disclosed by Capsule Security in April) is the whole argument in one incident. The model provider's built-in filter did its job. What decided the outcome was that an agent reading public form comments had the same permissions as an agent acting on a trusted instruction.

This month, two documents made that lesson official.

---

## What the ASD said

On 11 September the Australian Signals Directorate published *Agentic AI harnesses: the layer above the model*. Its core finding: for prompt injection, "no fully reliable technical mitigation currently exists" inside the model.

The reasoning is short. A language model gets its instructions and the content it's processing in the same context window and can't reliably tell them apart. Anything it reads, an email, a PDF, a form field, a code comment, can be taken as an instruction. That isn't a bug in one model. It's how they work.

The UK's NCSC reached the same conclusion in December 2025: under the hood "there is only ever 'next token'", so the model is an "inherently confusable deputy" rather than a system with a fixable input bug. OpenAI calls prompt injection "a frontier, challenging research problem". Anthropic got its browser agent's attack success rate down to one per cent and then said one per cent "still represents meaningful risk". A one per cent failure rate is great for a spam filter. It isn't a security boundary.

So the ASD's answer is architectural. It uses "harness" for everything in an agentic system other than the model: tool registry, permission system, connectors, memory, execution environment, logging. If the model is the brain, the harness is the body. Three things follow.

The harness is the part you control. The model is somebody else's artefact.

The harness outlasts the model. Models get swapped every few months. The ASD expects the harness to become "the more enduring organisational capability".

The harness is where the damage gets decided. A poisoned document can make a model want to exfiltrate data. Only the permission system can let it.

And the line to take to your next architecture review: "Do not rely on model safety controls instead of harness-enforced controls."

---

## What Google saw

Google Threat Intelligence Group's Q2 2026 report (8 September) and Sandra Joyce's Cloud CISO Perspectives piece (16 September) supply the urgency. Attackers have stopped treating AI as a writing assistant and started treating it as infrastructure.

A financially motivated actor compromised a cloud environment, deployed a multi-agent framework driven by markdown instruction files, and planned, built and ran a mass credential-harvesting campaign in under six hours. A related command-and-control server was managing more than 23,800 stolen secrets through a dashboard.

A group tracked as UNC6780 (TeamPCP) has been running supply chain compromises across PyPI, npm and Docker Hub since March: trojanised MCP servers, malware hiding in `.claude/`, `.vscode/` and `.cursor/` directories, and prompt injection payloads built to blind the AI scanners now used for security review.

A China-linked espionage group was seen using a tool called CC Switch to rotate between Claude, Gemini and Codex depending on the task, from exploit scripts to phishing lures.

In one intrusion, an exposed GitHub token led to unauthorised GPU workloads and a large bill. Claude and Gemini credentials are now the most sought-after AI accounts on underground markets, and prices more than doubled this year.

None of these attacks defeated a model's reasoning. Every one exploited what an agent or pipeline was allowed to reach: credentials, tokens, connectors, registries, compute. That's the harness, and it's where the attackers already are.

---

## The test to apply

Simon Willison's "lethal trifecta", since adopted by OWASP, is the most useful single check. An agent becomes an exfiltration channel when it has all three of: access to private data, exposure to untrusted content, and a way to communicate externally. Remove any one and an injection has nowhere to go.

ShareLeak had all three. So did Salesforce Agentforce's PipeLeak. So did the three coding agents (Claude Code, Gemini CLI Action, GitHub Copilot Agent) that Johns Hopkins researchers got to post their own API keys into pull request comments via a malicious PR title.

The NCSC turns the trifecta into a rule: when a model processes content from a party, its privileges should drop to that party's. An agent that just read an anonymous web form shouldn't still hold the permission to email your customer list. That's an authorisation problem, and authorisation is something this industry already knows how to do.

---

## Where guardrails fit

This isn't an argument against guardrails. It's an argument about which ones, and who controls them.

The safety filters built into a model or copilot by its provider are the provider's controls. You can't inspect them, tune them to your policy, or see their telemetry, and they change when the model does.

An independent, organisation-controlled guardrail layer is a different thing, and in the ASD's terms it's part of the harness. Inline inspection of prompts, responses and tool calls against your policy. Data loss prevention on AI channels. Visibility over which AI apps and models staff and agents may use. Behavioural detection on the endpoints where tool calls execute. Each cuts residual risk and gives you telemetry the provider's filter never will.

What no guardrail does is stand in for authorisation. The external guardrail is the smoke detector you own and can hear. The permission model is the fire door. You need both, and both belong to you.

---

## Why it matters here

The ASD isn't a lone voice. Its harness guidance sits alongside *Careful adoption of agentic AI services*, released jointly with CISA, the NSA and the UK, Canadian and New Zealand agencies in April. Five Eyes alignment is usually a leading indicator of where expectations settle.

For APRA-regulated entities the expectation has already arrived. APRA's 30 April AI letter named third-party AI supply chain risk as the biggest gap it sees, and with CPS 230's material service provider requirements applying to existing arrangements since 1 July, the harness inside a partner-supplied product is squarely in scope.

Which raises the question the ASD asks but doesn't answer: if the harness were compromised or misconfigured, what's the worst outcome, and what would contain it? For most organisations the harness arrived inside a commercial product, so the answer depends on the technology partner. Ask them, in writing, before signing: what can the agent reach and under whose identity, which actions run without approval, what's logged and can we ingest it, can we disable individual connectors, and does the agent's privilege drop when it reads untrusted content.

---

## Four moves this quarter

**Inventory every agent and its harness.** Including the copilots and the proof-of-concept nobody decommissioned. Record what each can read, what it can do, whose identity it acts under. Apply the trifecta test. Any agent with all three is a finding.

**Treat agents as identities.** Human owner, review cadence, revoke what's grown beyond purpose. Exactly like service accounts.

**Fix the two cheapest harness controls.** Approval gates on irreversible actions, and logging of prompts, tool calls and configuration changes. Usually configuration, not development.

**Put the harness questions into third-party risk.** Before the next AI-enabled product is signed.

---

Two national cyber agencies and the two leading model developers have now said in public that a language model can't separate instructions from data and may never be able to. That isn't a reason to avoid agentic AI. It's a reason to stop expecting any single layer to carry the load, and to design the one that's been neglected.

Prompt injection is a permissions problem. Fix the permissions.

---

## Further reading

- ASD: [Agentic AI harnesses: the layer above the model](https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/agentic-ai-harnesses)
- NCSC: [Prompt injection is not SQL injection (it may be worse)](https://www.ncsc.gov.uk/blog-post/prompt-injection-is-not-sql-injection)
- Google Threat Intelligence Group: [AI Threat Tracker: From prompting to autonomy](https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai)
- iTnews: [ASD says prompt injection in AI cannot be fixed](https://www.itnews.com.au/news/asd-says-prompt-injection-in-ai-cannot-be-fixed-629019)
- VentureBeat: [Microsoft patched a Copilot Studio prompt injection. The data exfiltrated anyway](https://venturebeat.com/security/microsoft-salesforce-copilot-agentforce-prompt-injection-cve-agent-remediation-playbook)
- Simon Willison: [The lethal trifecta for AI agents](https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/)

---

*SALTT Technologies works with Australian organisations on agent inventories and identity governance, harness threat modelling and secure design review, third-party assurance for AI-enabled platforms, and the layered guardrail and detection architecture around them. These fall within our AI Security, Governance, Risk & Compliance, and Security Architecture & Engineering capability areas. Contact us at [saltt.tech](https://saltt.tech).*

[Cybersecurity](https://www.saltt.tech/insights/tag/cybersecurity) [AI Security](https://www.saltt.tech/insights/tag/ai-security) [Threat Intelligence](https://www.saltt.tech/insights/tag/threat-intelligence) [Governance Risk and Compliance](https://www.saltt.tech/insights/tag/governance-risk-and-compliance) [LLM Security](https://www.saltt.tech/insights/tag/llm-security)

![SALTT Technologies](https://www.saltt.tech/hubfs/SALTT_TECH_Black.png)

SALTT Technologies

SALTT Technologies

SALTT Technologies is an all-Australian cybersecurity consultancy working across security architecture, technical testing, AI security, governance and compliance, and managed cyber operations — helping Australian organisations understand their risk and act on it. saltt.tech

In This Article

Get in Touch

### Need expert guidance?

Our practitioners work with Australian enterprise and government organisations. No obligation — just a conversation.

[Enquire Now](https://www.saltt.tech/contact)

More Insights

## Related articles

Podcast 30 Sep 2026

The Prompt Injection Podcast

The Prompt Injection Podcast SALTT Tech Insights, Episode: Prompt Injection Is a Permissions Problem

[Read article →](https://www.saltt.tech/insights/prompt-injection-podcast)

Cybersecurity 22 Jul 2026

The First Agentic Breach Was an Accident

In July 2026, two of the most capable AI models in the world broke out of a locked-down test environment, found their wa...

[Read article →](https://www.saltt.tech/insights/openai-hugging-face-agentic-breach-2026)

Cybersecurity 15 Jun 2026

The Attacker's Marginal Cost Is Now Zero

Two independent research papers published this year confirm what the security community has been anticipating: self-repl...

[Read article →](https://www.saltt.tech/insights/ai-worms-self-replicating-malware-2026)

[![SALTT Technologies](https://www.saltt.tech/hubfs/raw_assets/public/saltt-theme/images/logo.svg) SALTT Technologies](https://www.saltt.tech)

All Australian cybersecurity partner.  
 Sydney · Melbourne · Brisbane.

Services

- [Security Architecture](https://www.saltt.tech/services/security-architecture)
- [Penetration Testing](https://www.saltt.tech/services/penetration-testing)
- [AI Cybersecurity](https://www.saltt.tech/services/ai-cybersecurity)
- [GRC](https://www.saltt.tech/services/grc)
- [CyberOps](https://www.saltt.tech/services/cyberops)

Company

- [About Us](https://www.saltt.tech/about)
- [Insights](https://www.saltt.tech/insights)
- [Contact](https://www.saltt.tech/contact)

Legal

- [Privacy Policy](https://www.saltt.tech/privacy-policy)
- [Product Supply Terms and Conditions](https://www.saltt.tech/productsupplytermsandconditions)
- [Voluntary Statement Against Modern Slavery](https://www.saltt.tech/voluntary-statement-against-modern-slavery)

© 2026 SALTT Technologies Pty Ltd. All rights reserved. ABN 32 660 169 808.

[saltt.tech](https://saltt.tech)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SALTT Technologies",
    "url" : "https://www.saltt.tech/insights/author/saltt-tech"
  },
  "dateModified" : "2026-09-30T22:16:31.133Z",
  "datePublished" : "2026-09-30T22:16:31.000Z",
  "headline" : "Prompt Injection Is a Permissions Problem",
  "image" : [ "https://www.saltt.tech/hubfs/blog/featured-images/prompt-injection-is-a-permissions-problem-20260923103900.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.saltt.tech/insights/prompt-injection-is-a-permissions-problem",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.saltt.tech/hubfs/SALTT_TECH_VariableBackgrounds.png"
    },
    "name" : "SALTT Technologies"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BreadcrumbList",
  "itemListElement" : [ {
    "@type" : "ListItem",
    "item" : "https://www.saltt.tech",
    "name" : "Home",
    "position" : 1
  }, {
    "@type" : "ListItem",
    "item" : "https://www.saltt.tech/insights",
    "name" : "Insights",
    "position" : 2
  }, {
    "@type" : "ListItem",
    "item" : "https://www.saltt.tech/insights/prompt-injection-is-a-permissions-problem",
    "name" : "Prompt Injection Is a Permissions Problem",
    "position" : 3
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.saltt.tech/insights/prompt-injection-is-a-permissions-problem#article",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SALTT Technologies",
    "url" : "https://www.saltt.tech/insights/author/saltt-tech"
  },
  "dateModified" : "2026-09-30T22:16:31+10:00",
  "datePublished" : "2026-09-30T22:16:31+10:00",
  "description" : "The ASD says prompt injection can't be fixed inside the model. Google says attackers are already running agentic attack pipelines. The short version for Australian security leaders: guardrails you control plus a permission model you designed, and most organisations have neither.",
  "headline" : "Prompt Injection Is a Permissions Problem",
  "image" : "https://www.saltt.tech/hubfs/blog/featured-images/prompt-injection-is-a-permissions-problem-20260923103900.jpg",
  "inLanguage" : "en-AU",
  "isPartOf" : {
    "@id" : "https://www.saltt.tech/insights#blog",
    "@type" : "Blog",
    "name" : "SALTT Tech Insights",
    "url" : "https://www.saltt.tech/insights"
  },
  "keywords" : "Cybersecurity, AI Security, Threat Intelligence, Governance Risk and Compliance, LLM Security",
  "mainEntityOfPage" : {
    "@id" : "https://www.saltt.tech/insights/prompt-injection-is-a-permissions-problem",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@id" : "https://saltt.tech/#organization",
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://saltt.tech/hubfs/raw_assets/public/saltt-theme/images/logo.svg"
    },
    "name" : "SALTT Technologies"
  },
  "url" : "https://www.saltt.tech/insights/prompt-injection-is-a-permissions-problem",
  "wordCount" : 1532
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://saltt.tech/#organization",
  "@type" : [ "ProfessionalService", "LocalBusiness" ],
  "address" : [ {
    "@type" : "PostalAddress",
    "addressCountry" : "AU",
    "addressLocality" : "North Sydney",
    "addressRegion" : "NSW",
    "postalCode" : "2060",
    "streetAddress" : "Level 4/1 James Place"
  }, {
    "@type" : "PostalAddress",
    "addressCountry" : "AU",
    "addressLocality" : "Melbourne",
    "addressRegion" : "VIC",
    "postalCode" : "3000",
    "streetAddress" : "Suite 4423, 805/220 Collins Street"
  }, {
    "@type" : "PostalAddress",
    "addressCountry" : "AU",
    "addressLocality" : "Brisbane City",
    "addressRegion" : "QLD",
    "postalCode" : "4000",
    "streetAddress" : "Suite 4126, 29/97 Creek Street"
  } ],
  "areaServed" : "AU",
  "contactPoint" : {
    "@type" : "ContactPoint",
    "areaServed" : "AU",
    "contactType" : "sales",
    "email" : "hello@saltt.tech"
  },
  "description" : "All Australian cybersecurity consultancy providing technical testing, AI security, GRC, security architecture, and CyberOps services.",
  "foundingCountry" : "AU",
  "hasOfferCatalog" : {
    "@type" : "OfferCatalog",
    "itemListElement" : [ {
      "@type" : "Offer",
      "itemOffered" : {
        "@type" : "Service",
        "name" : "Cybersecurity Architecture & Engineering",
        "url" : "https://www.saltt.tech/services/security-architecture"
      }
    }, {
      "@type" : "Offer",
      "itemOffered" : {
        "@type" : "Service",
        "name" : "Penetration Testing & Technical Assurance",
        "url" : "https://www.saltt.tech/services/penetration-testing"
      }
    }, {
      "@type" : "Offer",
      "itemOffered" : {
        "@type" : "Service",
        "name" : "AI Cybersecurity",
        "url" : "https://www.saltt.tech/services/ai-cybersecurity"
      }
    }, {
      "@type" : "Offer",
      "itemOffered" : {
        "@type" : "Service",
        "name" : "Governance, Risk & Compliance",
        "url" : "https://www.saltt.tech/services/grc"
      }
    }, {
      "@type" : "Offer",
      "itemOffered" : {
        "@type" : "Service",
        "name" : "CyberOps Management",
        "url" : "https://www.saltt.tech/services/cyberops"
      }
    } ],
    "name" : "Cybersecurity services"
  },
  "knowsAbout" : [ "Cybersecurity", "Penetration Testing", "AI Security", "Governance Risk and Compliance", "Security Architecture", "CyberOps" ],
  "legalName" : "SALTT Technologies Pty Ltd",
  "logo" : "https://saltt.tech/hubfs/raw_assets/public/saltt-theme/images/logo.svg",
  "name" : "SALTT Technologies",
  "sameAs" : [ "https://www.linkedin.com/company/saltt-technologies" ],
  "slogan" : "Defending the digital future.",
  "taxID" : "ABN 32 660 169 808",
  "url" : "https://saltt.tech"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.saltt.tech/#website",
  "@type" : "WebSite",
  "inLanguage" : "en-AU",
  "name" : "SALTT Technologies",
  "publisher" : {
    "@id" : "https://saltt.tech/#organization"
  },
  "url" : "https://www.saltt.tech"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.saltt.tech/insights/prompt-injection-is-a-permissions-problem",
  "@type" : "WebPage",
  "about" : {
    "@id" : "https://saltt.tech/#organization"
  },
  "dateModified" : "2026-09-30T22:16:31+10:00",
  "description" : "The ASD says prompt injection can't be fixed inside the model. Google says attackers are already running agentic attack pipelines. The short version for Australian security leaders: guardrails you control plus a permission model you designed, and most organisations have neither.",
  "inLanguage" : "en-AU",
  "isPartOf" : {
    "@id" : "https://www.saltt.tech/#website"
  },
  "name" : "Prompt Injection Is a Permissions Problem",
  "url" : "https://www.saltt.tech/insights/prompt-injection-is-a-permissions-problem"
}
```