Because those controls answer who the actor is and what it may access, not whether the action still makes sense after the agent’s context changes. Prompt injection exploits the gap between allowed access and appropriate use, so the problem is runtime judgement, not login failure.
Why authentication and authorization do not stop prompt injection
Authentication and authorization prove an actor can log in and what it may reach, but prompt injection targets the agent’s decision layer after access is already granted. The abuse is not “unauthorised login”; it is persuading a trusted system to misuse valid access, so the control failure is about runtime judgement, not credential verification.
That distinction matters because many agent failures begin inside an otherwise legitimate session. If the agent can read mail, retrieve files, call tools, or execute actions on behalf of a user, injected instructions can redirect those permissions without breaking the login boundary.
For a broader control view, IAM and IGA Basics explains why authentication, authorization, provisioning, and entitlement governance solve different parts of the access problem, and why valid access alone does not guarantee safe use.
Why the trust boundary breaks at runtime
Prompt injection succeeds when the agent treats untrusted content as if it were operational guidance. The model may have been authenticated, may be acting within policy, and may still be steered by instructions hidden in web pages, emails, documents, tool output, or retrieved context.
The security boundary is therefore not only “who can enter” but “what the system believes while it is working.” Once the agent merges attacker-controlled text into its working context, authorization checks can be perfectly correct and still be bypassed in practice because the system is making the wrong decision with the right privileges.
This is why agent-specific authorization patterns matter. AI Agent Authorisation Guide shows how task-scoped access, per-action decisions, and human approval gates reduce the harm when an agent’s runtime judgement is manipulated.
The same issue appears in real incidents where prompt injection causes data leakage or tool abuse even though the underlying account is legitimate. EchoLeak (Microsoft 365 Copilot) 2025 and Gemini AI Breach, Google Calendar Prompt Injection both illustrate that context abuse can drive unwanted disclosure through valid session paths.
What changes when the actor is an agent rather than a normal user
An agent is not just another authenticated principal. It often has delegated authority, broad tool reach, and the ability to chain actions faster than a human can supervise them. That makes prompt injection a control problem about delegation depth, not just access presence.
When the agent can read, decide, and act across multiple systems, the blast radius of a single malicious instruction can exceed what standard login controls were designed to contain. The key question becomes whether each action is scoped, attributable, and interruptible, not whether the session was valid at the start.
Agentic AI Security Guide and OWASP Agentic AI Top 10 both frame this as an agent trust and privilege problem, where tool misuse, identity and privilege abuse, and goal hijack must be controlled explicitly.
That is also why valid authentication can coexist with abuse in coding agents and service integrations. Gemini CLI prompt injection flaw 2025 and Sentry MCP Agentjacking 2026 show that a trusted tool channel can be turned into an execution path when the runtime trusts the wrong message.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Prompt injection abuses delegated agent authority and valid privileges. |
| ASI02 — Tool Misuse | Injected instructions often turn trusted tools into unintended execution paths. | |
| Recommendation — Scope agent actions tightly and require fresh authorization for sensitive tool use. Constrain tool invocation and block untrusted content from driving side effects. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Excess access increases the blast radius of injected agent actions. |
| IA-2 — Identification and Authentication (Organizational Users) | Valid login alone does not prevent post-authentication abuse in agent workflows. | |
| Recommendation — Limit every agent to the minimum permissions needed for the current task. Authenticate actors before access, then enforce separate action controls after login. | ||
| OWASP ASVS | V8 — Authorization | Prompt injection bypasses safe-use expectations unless authorization is enforced per action. |
| Recommendation — Require explicit authorization checks before each impactful operation. | ||
Practitioner Guidance
What to prioritise: Treat prompt injection as an authorization-and-context integrity problem. The first control objective is to narrow what the agent can do per action, per tool, and per data source, because broad standing access turns a single injection into a wide compromise.
What to verify: Verify that the agent cannot convert retrieved or user-supplied text directly into privileged side effects without an explicit policy decision or human checkpoint. If a prompt, document, or tool response can trigger writes, sends, deletes, or transfers without a fresh decision, the design is too trusting.
Common mistake: Teams often harden login flows and assume the problem is solved. In practice, the weak point is the action layer, where a valid session is still capable of doing the wrong thing under attacker influence.
What good looks like: Safe systems separate identity proof from action permission and from action meaning. The agent can be authenticated, yet still be unable to perform high-impact operations unless the current task, context, and policy all align.
Practitioner takeaway: Authentication confirms membership; authorization confirms reach; prompt injection attacks the judgement in between. If runtime context can be poisoned, access controls must be paired with action-scoped constraints and explicit trust boundaries.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org