Logiciel Solutions Contact Us
Success Stories Tech News Contact Us
whitepaper

AI Security: What Buyers Should Ask.

Nobody has solved indirect prompt injection, so the question is not whether a vendor blocks it but what the agent can still reach once it has been persuaded. Most security due diligence never gets there. It collects certificates, asks about encryption at rest, and leaves the trust boundary undrawn. These seven themes put the architecture on the table instead, each paired with the fluent reply a well-briefed sales engineer gives when the thing underneath is a filter and a hope.

In depth

Every Vendor Says They Handle Injection. Few Can Draw The Boundary.

01

A block rate is not a security boundary.

Ask architecturally what separates an instruction from retrieved content and the weak answer describes filtering and sanitising every input, with a detection layer and a figure above 99 per cent. The strong answer describes trust zones: a privileged planner that never reads untrusted text, and an unprivileged worker that reads it and cannot act. Classification belongs in the telemetry, and the boundary is the thing that holds when classification is one paraphrase from failure.

In shortClassification belongs in the telemetry, and the bou…
02

The second question is what the agent can do once persuaded.

A vendor who says the agent works within the permissions you grant has told you nothing, because you granted those permissions to a component that reads hostile text all day. What you want is an action catalogue: every action taken without a human, the credential behind each one, which are read-only, and which irreversible actions stop at an approval. Per-action credentials scoped to the narrowest operation mean a compromised read path cannot write, and one integration cannot reach another.

In shortone integration cannot reach another
03

Retrieval fails quietly, which is why it is worth two questions.

Ask whether source-system permissions constrain the candidate set before ranking or drop documents afterwards, then ask for the per-role test that asserts a named document stays unreachable for a named low-privilege user. Post-filtering is a ranking bug waiting for the right query. The cheapest artefact in this whole exercise is a dated test result, and its absence tells you retrieval was never authorised in the first place.

In shortThe cheapest artefact in this whole exercise is a da…
04

Ask who has attacked it, and ask for the findings.

A current attestation shared under NDA is a certificate with nothing behind it, and the useful version is a dated exercise by a named firm against their application layer, scoped to injection, leakage, tool misuse and isolation. Then ask to see severities, what was fixed, what was accepted, and the retest result. A vendor who can hand that over inside the week has already lived through the incident you are trying to avoid buying.

In shortA vendor who can hand that over inside the week has…
The detail

The Three Replies That Should End A Vendor Conversation.

Fluency is not evidence. These three replies arrive in confident, well-rehearsed English, and each one tells you the architecture underneath is thinner than the sentence. Hearing any of them is a reason to stop and ask the follow-up in writing.

Zone · 01

We filter every input

The most common reply, and the one that sounds most like an answer. Filters are a paraphrase, an encoding or a new language away from bypass, and no filter has ever been the thing that bounded damage. Ask what the model can still reach when the filter misses, and listen for whether they have ever measured that.

Zone · 02

It uses your permissions

A deflection dressed as customer control. The agent holds whatever the integration was granted, which is usually one service connection with broad scope, so the answer describes who signed rather than what can be reached. Push until they name the credential behind each tool, its permitted actions, and the irreversible ones that stop at a human.

Zone · 03

Tenant identifiers on every record

Offered as proof of isolation, it is a column in a table enforced by application code that one bug undoes. The separation worth buying is named per store, a namespace, a collection or a dedicated index, enforced below the application layer. Then ask about the cache, including the semantic one, and what happens when two tenants ask the same question.

By the numbers

The figures that make it a board-level conversation.

$5.89M
average cost of a breach that began with prompt injection
$6.07M
average cost of a model inversion incident, the costliest AI incident type recorded
92%
of organisations with an AI-related breach had no access controls on their AI models and data
Inside the report

What you'll take away.

01

Step 1 - Get the architecture diagram with the trust boundary marked

Ask which component sees untrusted content and which one holds credentials. If the answer is the same component, the rest of the due diligence is decoration.

02

Step 2 - Take the action catalogue, not the integration scope

Every action the agent can take unattended, the credential behind it, which are read-only and which are irreversible. Then ask what one compromised session could chain together.

03

Step 3 - Ask for the red team findings, not the attestation letter

Scope, severities, what was fixed, what was accepted and why, and the retest date. OWASP Top 10 for LLM Applications is the minimum scope worth accepting.

04

Step 4 - Put the notification clock into the agreement

A period in hours running from detection rather than confirmation, with interim updates. Add the rule that every tenant on a shared component hears about an injection, whether or not their data moved.

Questions

Frequently asked.

What single question separates a hardened vendor from a confident one?

Ask them to show an injection payload that got through in their own testing and what it reached. A vendor with a real security programme names a bypass, a date, what it touched and what changed. One who says nothing has ever got through is telling you they have not looked.

Is a SOC 2 report or a penetration test attestation enough here?

No, and the gap is scope rather than rigour. Those exercises test the platform: network, access management, infrastructure. They rarely touch indirect injection through retrieved content, tool chaining or cross-tenant retrieval, which is where the expensive AI incidents start. Ask what categories were in scope and whether anyone attempted the corpora.

Should we accept that the model is trained to resist adversarial instructions?

Treat it as a useful property and not as a control. Training reduces the hit rate; it does not bound what happens on the hits that land. The question that matters is what the model can still reach when it obeys the wrong instruction, and that is answered by tool scoping, not by weights.

We are a small buyer. Will a vendor really answer these?

More often than teams expect, and the refusal is itself information. Ask in writing, in these words, and give a deadline. A vendor with the artefacts sends them inside a week under NDA. A vendor without them sends a deck, and you have learned something worth more than the answer would have been.

Who should be in the room when these questions are asked?

Whoever can read an architecture diagram, plus the person who will own the incident. Procurement can send the list, but the follow-up questions are the valuable part and they need someone who knows what a pre-filter is. Budget an hour with the vendor's engineer rather than their account team.

How does this sit with your other AI security resources?

This one points outward at a supplier. Benchmarking AI Security scores the systems you already run, across twenty controls and four domains. The AI Security Report prices what the incidents cost when the questions were never asked. Ask these before signature, score yourself after, and take the costs to the board.

Get the whitepaper

Have it emailed to you.

Drop your details and we'll send AI Security: What Buyers Should Ask straight to your inbox - no spam, unsubscribe anytime.

Download whitepaper
Next step

Put these questions to us before you put them to anyone else.

A fortnight of free trial sprint produces code in your repo, a visible backlog, and an architecture note naming the trust boundary and the scope behind every tool credential. You keep all of it. SECTION 7 - FAQ - 5 to 8 questions

Book a due diligence review