What Happened
Mandiant’s testing found prompt injection remains a primary attack vector in enterprise AI deployments, alongside weak file permissions and poor access controls. The report also highlighted an AI agent that generated a large cloud bill during testing, showing how agentic systems can create direct financial risk.
Why It Matters
According to Mandiant’s testing, prompt injection remains a primary attack vector in enterprise AI deployments, and one AI agent during testing was able to autonomously generate a roughly $50,000 cloud bill, demonstrating that agentic systems can directly trigger significant financial impact when insufficiently constrained. The report also notes contributing weaknesses such as poor file permissions and access controls, which increase the blast radius of misbehaving or compromised agents. From RealGround’s perspective, this illustrates the need for robust guardrails on AI agents, strict budget and resource limits, and secure business logic design to prevent uncontrolled actions. Continuous adversarial testing of agent behavior and hardening of permissions can substantially reduce both security and financial risk from AI agent abuse.
RealGround Analysis
This signal maps to AI agent abuse. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://www.helpnetsecurity.com/2026/09/16/google-mandiant-enterprise-ai-security-risks-report/
