Your AI agent’s system prompt is not a security control AWS and SANS Institute experts warn that system prompts are not a security control for AI agents, as they can be bypassed through prompt injection. Gee Rittenhouse, who oversees Security Hub, GuardDuty, and Inspector at AWS, and Eric Johnson, a fellow at the SANS Institute, recommend enforcing user permissions at retrieval time within role-based or attribute-based access systems. An AI agent told in its system prompt to show a user only what that user is cleared to see will hand over more the moment someone talks it into doing so. Gee Rittenhouse, who oversees Security Hub, GuardDuty, and Inspector at AWS, and Eric Johnson, a fellow at the SANS Institute, put the fix one layer down: scope the query to the user’s permissions at retrieval time, inside the role-based or attribute-based access system … More https://www.helpnetsecurity.com/2026/09/03/sans-aws-agentic-ai-security/ The post Your AI agent’s system prompt is not a security control https://www.helpnetsecurity.com/2026/09/03/sans-aws-agentic-ai-security/ appeared first on Help Net Security https://www.helpnetsecurity.com .