Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Carl Knoos, co-founder & CIO, Fusion Collective
A Crumbling Foundation
The current state of AI cybersecurity is built on a foundation of sand.
Industries obsess over sophisticated defenses: zero-trust architectures, multi-factor authentication, behavioral monitoring, and endpoint detection. Meanwhile, the most basic attack vector remains completely unmitigated: prompt injection.
The absurdity is that the “hack” literally makes text invisible by setting the font color to match the background color. This is not a sophisticated nation-state exploit. This is CSS 101. As of the publishing date, no known reliable safeguards exist against this attack class.
But wait, there’s more! Before you even have time to worry about prompt-injection, you’ve probably provided your AI agents with superuser or other overly broad permissions to your production data.
We’re spending untold millions on castle walls while the front door is propped open with a welcome mat.
The AI is the Malicious Actor!
We’re handing AI systems the keys to the kingdom with alarming casualness. AI tools increasingly operate with broad, often administrative-level permissions. There is a treasure trove of anecdotes from the wild:
- Antigravity confidently erases the entire drive without permission or authority
- LLMs instructed to “clean up” databases that interpreted this as DELETE FROM
- Coding agents that purged repositories or overwrote production code
- Automation tools that cascaded destructive actions across connected systems
The permission model assumes that the AI will only do what the user intends, but prompt injection enables a third party to alter the authorized user’s intent. Knowing how destructive even accidental actions can be, imagine what it looks like in the hands of a malicious actor.
We can (hopefully) assume that the glaring issues around AI tools and agents obtaining root or other elevated permissions and promptly then misusing them like toddlers with espressos isn’t by design; however, ultimately, this does not matter, the net result is the same. What good is the latest AI-driven security layer, when another valid AI agent is the one who nuked your database?
The good news is that this is a fixable problem. The bad news is that it is (for now) 100% an operator issue. Organizations and users who deploy these tools must take a more active role in mapping out exactly which permissions they delegate and incorporating those permissions into their standard security review cycle.
The Air Gap Fallacy
You cannot meaningfully isolate an AI system and still derive value from it.
“Just air gap it” sounds reasonable until you think about it for thirty seconds. AI tools are, by definition, input-output machines. They require data to process and return results to be of any use. Any input channel is a potential injection vector, and any output channel is a possible exfiltration path.
The core issue, however, remains that the value proposition of AI is its connectivity to your data and systems, and an air-gapped AI is a costly, if shiny, paperweight. If someone you are speaking with offers this as a solution to the AI security issues, they’ve told you all you need to know about their general understanding of the situation, and you can take their advice accordingly.
The Only Defense That Works (For Now)
If you can’t defend the AI, defend the data. Until prompt injection has a reliable solution, assume that any AI-accessible data is potentially compromised, and that sensitive data must be architecturally segregated from AI tooling.
While this is not a satisfying answer as it significantly limits AI’s utility, it’s the only honest one given the current state.
The uncomfortable reality: we’ve deployed these systems faster than we’ve developed the ability to secure them.
Together, we’ve enabled a reality in which agents and tools consume simple yet malicious CSS instructions with incredible levels of autonomy and overly broad permissions, and the damage from this is observable in real time.
It’s All Security Theater
We need to have a serious conversation about AI and security, one that demands intellectual honesty about where we actually are and the challenges we face. The industry needs to stop pretending sophisticated defenses matter when the basics are broken.
Until we address these foundational security vulnerabilities, every layer of sophisticated defense we build is performance art.
These are problems that will continue to manifest in 2026 and beyond. As organizations and firms continue to accelerate the deployment of AI/ML tools, while reducing headcount in the vain pursuit of shareholder value, we can expect to see a steady stream of AI-related (or perhaps even induced) security incidents. The magical invisible hand of the Free Market is not incentivized to dedicate resources to these issues. Rather, this is the expected outcome of what Cory Doctorow calls “enshittification” of everything.
The adage of “People, Process, Technology” may sound like just another phrase that Big 4 firms throw around. However, there is a lot of truth behind it, importantly, that it places people first. This is not by accident. No matter how expensive or shiny a technical solution is, if not deployed from a people-first mindset, with well-thought-out change management, operational failure becomes almost inevitable. It seems that until we have the honest conversation we so urgently need, we are doomed to continually relearn this lesson.
The irony is that this article will probably be used to prompt someone’s AI assistant. Hopefully, you checked all of the text before slurping it in!
##
ABOUT THE AUTHOR
A Big 4 alum and DevOps expert, Carl Knoos is Co-Founder & CIO of Fusion Collective, an IT consulting firm serving financial, entertainment, and industrial companies on their journeys to leveraging AI and emerging technologies for transformative business outcomes. Originally from Stockholm, his nearly 30-year career has led him across the globe – from Stockholm, Boston and New York – to lead strategic cloud and infrastructure initiatives for companies like Deloitte, Viacom, Time Inc., and Verizon Enterprise Solutions. Having cut his teeth amidst the dot-com boom, Knoos is a technologist above all else and is focused on the ethical and responsible development of emerging technology.





