2025 is shaping up to be the year in which AI agents move from theoretical discussion to mass, real-world use in business environments. At the same time, new evidence from the Lakera, group company Check Point Software Technologies, show that cyberattackers immediately recognized this transition and adapted with alarming speed.
According to new analysis from Lakera, which is based on real-world attack activity observed during the fourth quarter of 2025, as soon as artificial intelligence systems began browsing the web, analyzing documents, and interacting with external tools, adversaries evolved their techniques to exploit these very capabilities.
The findings demonstrate that attacks are no longer based on simple or “raw” forms of prompt injection. Instead, attackers are turning to indirect attacks, which are embedded discreetly into documents, web pages, and structured content. These methods require less effort and show significantly higher success rates.
Lakera's research highlights three critical trends that are expected to define the security of AI systems in 2026:
- The leakage system prompts emerges as the main target of attackers, with hypothetical scenarios and disguised prompts proving particularly effective.
- Mechanism bypasses happy safety they are becoming increasingly subtle, often appearing as analysis, evaluation, or role-play rather than overtly malicious requests.
- Specialized attacks on AI agents have already been recorded, including attempts to extract confidential data, insert script-like instructions, and manipulate agents through untrusted external sources.
According to Lakera, the findings offer one of the first and clearest pictures yet of how real-world attackers are responding to the adoption of agentic AI in production environments. AI agents are entering the workplace faster than traditional security models can adapt. The same automation that promises increased productivity is simultaneously, and often silently, expanding the attack surface.
At the same time, the research raises serious questions about how organizations will securely manage the processing of external content, data sources, and documents by AI agents, especially in regulated and sensitive environments. As the Q4 2025 data demonstrates, indirect prompt injection is no longer a theoretical risk, but an already easier and more effective form of attack compared to direct techniques.
Lakera points out that organizations planning to deploy or expand the use of AI agents in 2026 should immediately review trust boundaries, external data import processes, and guardrails to ensure the safe adoption of the technology.
The full report entitled «The Year of the Agent What Recent Attacks Revealed in Q4 (and What It means for 2026) " is available, while more information is presented on the relevant Lakera blog.
More at blog:
https://www.lakera.ai/blog/the-year-of-the-agent-what-recent-attacks-revealed-in-q4-2025-and-what-it-means-for-2026
Although the press releases will range from very select to rare, I said I'd pass...because sometimes the editors hide.


