Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Gemini Enterprise prompt injection: what IAM teams need to know


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12518
Topic starter  

TL;DR: Noma Labs says GeminiJack let hidden instructions in documents, emails, and calendar events drive Gemini Enterprise and Vertex AI Search to exfiltrate Gmail, Calendar, and Docs data with zero clicks and minimal forensic trace, showing how federated search can turn ordinary content into execution paths. The breach proves that AI search trust boundaries collapse when retrieved content is treated as instruction-bearing, not just data.

NHIMG editorial — based on content published by Noma Security: Hacking Google Gemini Enterprise with an Indirect Prompt Injection

Questions worth separating out

Q: How should security teams reduce indirect prompt injection risk in AI systems?

A: Security teams should limit what AI systems can read, separate untrusted content from privileged actions, and apply least privilege to every connected agent.

Q: Why do federated AI search integrations increase enterprise risk?

A: Because they expand the number of systems one query can touch and make a single poisoned item influence multiple repositories.

Q: What do organisations get wrong about zero-click AI data leaks?

A: They assume the absence of a phishing click or malware means the event is low risk.

Practitioner guidance

  • Audit AI query blast radius Inventory which repositories Gemini Enterprise or similar systems can reach, then map what a single query can expose across Gmail, Calendar, Docs, and external sources.
  • Separate trusted instructions from retrieved content Require your AI layer to preserve a hard boundary between system instructions and untrusted indexed material, including documents, email, and calendar events.
  • Restrict response-side exfiltration paths Disable or tightly control response features that can embed external requests, such as auto-loading remote content or image beacons, and monitor for anomalous outbound patterns in generated answers.

What's in the full report

Noma Security's full blog covers the operational detail this post intentionally leaves for the source:

  • A step-by-step attack chain showing how a poisoned document, email, or calendar event becomes executable AI context.
  • The exact exfiltration path used to move data from Gmail, Calendar, and Docs into an outbound request.
  • The architectural changes Google made after the issue was addressed, including the separation of Vertex AI Search from Gemini Enterprise.
  • The practical defence model for AI search, including blast-radius mapping and provenance handling.

👉 Read Noma Security's analysis of the GeminiJack indirect prompt injection flaw →

Gemini Enterprise prompt injection: what IAM teams need to know?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12102
 

Prompt injection becomes an identity problem when the model inherits trust from retrieved content. GeminiJack shows that the boundary between data and instruction is no longer reliable once collaboration content is indexed into AI search. The governance failure is not only model vulnerability, but the assumption that retrieved content can be safely treated as organisational knowledge without revalidating intent. Practitioners need to treat retrieval paths as privileged decision surfaces, not passive lookup layers.

A few things that frame the scale:

  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to Ultimate Guide to NHIs.
  • 79% of organisations have experienced secrets leaks, and 77% of those incidents resulted in tangible damage, according to NHI Mgmt Group research.

A question worth separating out:

Q: Who is accountable when AI search exposes sensitive enterprise data?

A: Accountability sits with the teams that approved the data connections, retrieval scope, and response handling, not just the users who queried the system. Governance should cover access design, provenance controls, and operational monitoring across identity, search, and AI platform owners.

👉 Read our full editorial: Gemini Enterprise prompt injection exposes a collapsed trust boundary



   
ReplyQuote
Share: