Skip to main content

folkfox

Skip to main content
Skip to content
AI SECURITY

AI security grew a deadline before it grew evidence

The law now expects systems that resist manipulation. The field still cannot say how often manipulation works, and for a marketing team that gap is an opening rather than an embarrassment.

Quick answerAI security means keeping models and agents from being manipulated into acting against their operator. From 2 August 2026 most of the EU AI Act applies, so robustness became a dated legal duty rather than a slide.
Section 01

The deadline landed before the evidence did#

A fox will not commit to a trail it cannot see the end of. Security buyers behave the same way, which is why the most useful thing to happen to AI security this month was a date rather than a discovery. Dates can be diarised, doubted and defended. Discoveries, at least the ones currently circulating, cannot.

On 2 August 2026, the AI Act implementation timeline records that "The remainder of the AI Act starts to apply, except Article 6(1)." The same entry carries a second duty, this one for Member States, who had to "ensure that their competent authorities have established at least one AI regulatory sandbox at national level" by that day.

Two later dates matter for planning. On 2 August 2027, "Article 6(1) and the corresponding obligations in the Regulation start to apply", and providers of general-purpose AI models placed on the market before 2 August 2025 must have complied by then. AI systems sitting inside the large-scale IT systems listed in Annex X have until 31 December 2030 to "be brought into compliance with this Regulation", according to the same published timeline.

A date is a diary entry, and a diary entry is a campaign#

Regulators publish dates long before anybody publishes proof, and the product security world already knows what to do with that. The European Commission's Cyber Resilience Act reporting guidance states that from 11 September 2026, manufacturers are required to report actively exploited vulnerabilities and severe incidents affecting products with digital elements.

The cadence is the part worth stealing. An early warning "within 24 hours of becoming aware", then "a full notification within 72 hours", then a final report no later than 14 days after a corrective measure is available for an actively exploited vulnerability. Three deadlines, three different states of knowledge, three separate conversations a vendor can helpfully have with a buyer who is about to live through all of them.

The four dates that anchor an AI security content calendar, with the page each one comes from.
DateWhat appliesSource
2 August 2026The remainder of the AI Act applies, except Article 6(1). Member States must have at least one national AI regulatory sandbox established.AI Act timeline
11 September 2026Cyber Resilience Act reporting begins: early warning in 24 hours, full notification in 72 hours, final report within 14 days of a corrective measure.European Commission
2 August 2027Article 6(1) applies. Providers of general-purpose AI models placed on the market before 2 August 2025 must have complied.AI Act timeline
31 December 2030AI systems inside the large-scale IT systems listed in Annex X must be brought into compliance.Regulation (EU) 2024/2847

The tooling for that reporting regime is still described in the future tense, and refreshingly so. ENISA's page on the Single Reporting Platform says the platform "shall become a technical tool for the reporting of actively exploited vulnerabilities and incidents impacting products with digital elements in the EU Digital Single Market", and that "As of 11 September 2026 onwards, the SRP will be used by CSIRTs and manufacturers for mandatory reporting".

Note the honesty of that construction. The obligation is fixed, the plumbing is being built in public, and nobody pretends otherwise. Most vendor roadmaps could learn from a regulator's willingness to say what is not finished yet.

The sandbox is a room your buyer is allowed to experiment in#

The regulatory sandbox clause is the most under-read line in the whole timeline. Every Member State had to stand one up by 2 August 2026, which means there is now a sanctioned space where your buyer can test a system under supervision instead of shipping it and hoping. Sandboxes are where documentation gets read closely, and being the vendor whose documentation survives that reading is worth more than a webinar.

Work out who owns the date inside the buyer's business, because it is rarely the person you have been emailing. An obligation with a reporting cadence like the 24, 72 and 14 day sequence lands on whoever signs the notification, which drags legal, product and the security team into one thread. Content that hands all three the same set of facts gets forwarded between them, and a forwarded document makes the introductions your outreach cannot.

So the AI Act's arrival is not a fear pitch. It is a fixture list. Somebody inside your buyer's business now owns a dated duty they cannot yet discharge, and they are searching for language that describes their predicament, not language that describes your platform. The scent to follow is the phrasing they use when nobody is selling to them.

Section 02

Why ai security statistics keep failing the sniff test#

Two figures have been prowling AI security marketing for weeks: a triple-digit annual surge in prompt injection attempts, and an attack success rate round enough to fit neatly on a slide. Neither traces to a primary source. Both lead back to vendor posts citing other vendor posts, which is precisely why neither of them appears anywhere in this piece.

That restraint is positioning, not pedantry. Your buyer reads statistics for a living, and the tell never changes: a number with no method, no sample, no date and no route back to whoever counted. Publish it and you have told a security professional exactly how much scrutiny your marketing survives, which is roughly one click.

Checking one of these figures takes ninety seconds, so make somebody do it before the deck ships. Click the citation. If it lands on another blog, click again. Keep clicking until you either reach a document that states how the counting was done, or you run out of links entirely. A chain that terminates in a press release has told you everything worth knowing: somebody wrote a number, and everybody since has been quoting the writing rather than the counting.

What a countable number actually looks like#

Contrast it with an analysis that shows its working. Dragos counted 1,140 ransomware incidents affecting industrial firms worldwide in the second quarter of 2026, a 12% rise on the 1,020 it recorded in the first quarter, in its Q2 2026 industrial ransomware analysis. Manufacturing absorbed 747 of them, 65% of the total across all subsectors, and North America carried 514.

Help Net Security, covering the same analysis, breaks the remainder out: construction 176, equipment manufacturing 114, firms supporting ICS environments 117, transportation and logistics 95, food and beverage 70. Europe took 316 incidents and the United States alone 431, or 38% worldwide. Qilin led the claim counts with 140, down from 198 in the first quarter, ahead of Akira on 129 and The Gentlemen on 125.

Every one of those numbers has a quarter attached, a counting body attached and a definition attached. You can disagree with the method. You cannot accuse it of hiding one. That is the whole difference between a statistic and a slogan.

Then comes the sentence that spoils the sales deck. "Dragos observed no case in Q2 2026 in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system". Not one. The damage ran through ordinary enterprise IT, not through the turbine on somebody's homepage hero image.

Fernando Cassina made the same point in a single line on X on 17 August 2026. His post is in Spanish and the translation here is folkfox's: industrial ransomware does not come in through the PLC, it comes in through the VPN without multi-factor authentication. Substitute the model for the PLC and you have the AI security version of the same sentence.

None of that is an AI number, and that is exactly the point. The industrial figures are checkable because somebody counted carefully, named the method and published the quarter. AI security has no equivalent yet. Until it does, the honest move is to stop borrowing an invented one and start saying plainly that the counting has not been done.

Section 03

Prompt injection, drawn honestly#

Prompt injection is easy to explain and awkward to sell, because a good explanation makes it sound like a design decision rather than an attack. A language model receives instructions and content down the same channel. Anything it reads can therefore attempt to instruct it, and the model has no reliable way to tell the difference between the two.

Indirect prompt injection is the variant that should worry anyone shipping agents. The instruction is never typed into a chat box by an attacker in a hoodie. It is planted in a document, a web page, a support ticket or a wiki entry the agent has been told to read, and the agent follows it because following what it reads is precisely the job it was handed.

ai security and prompt injection: a painted fox reads a book as a hidden paper hand slips an extra note between the pages
Indirect prompt injection, drawn honestly: the instruction arrives inside the thing the agent was told to read.

The clearest public account of ai agent security this week came from a practitioner rather than a product. A post to r/cybersecurity at 09:00 UTC on 17 August 2026, titled "Our whole agentic AI security plan was ship the agents now and figure out access later" describes the pattern in ordinary working language. It is anonymous testimony, not a verified incident report, and it deserves to be read as such.

The poster describes a ticket-triage agent that would "open the internal wiki, follow a link dropped in a page and pull down a config file with a live API key in it". The agent was running "as a service account some guy who left set up for a nightly export". Nothing in that sentence is exotic. Every component of it already exists in most companies, sitting quietly in the undergrowth where nobody has looked since the leaver's last day.

The login rules we are so proud of do not even touch it.
Anonymous practitioner, r/cybersecurity, 17 August 2026

The follow-on line explains why. Those controls "were built for a person signing in from a laptop, not something hammering the API all day that never logs in or out". Identity, not the model, is the quarry here. An agent is a new species of user that never sleeps, never signs out and inherits whatever the borrowed account could already reach.

For a marketing team, that reframing is the gift. The buying conversation is not about model behaviour at all, it is about accounts, permissions and the documents an agent is allowed to open. Those are boring, budgeted, board-legible problems, and boring problems buy faster than dramatic ones.

Inventory is the unglamorous half of the job#

Counting down to the Cyber Resilience Act deadline, the account @SBOMFlow posted six words on X on 17 August 2026 that transfer wholesale to agents: "You cannot report what you cannot inventory." A reply from @boardyai the same day added that the line is the one teams tend to discover too late.

Swap the vulnerability for the agent and the sentence still stands. Most teams cannot list the agents running in their name, the credentials those agents hold, or the documents each one may read. No amount of model-level hardening fixes an inventory problem, and no amount of clever filtering outfoxes a permission that should never have been granted.

The practical shape of an answer is unfashionably dull: one identity per agent, a written list of the sources it is allowed to read, a human approving anything that writes, and logging that survives a bad week. That is the den you build before winter, not the alarm you install after the fox is inside.

Section 04

What the demand data actually says#

Demand is the one number in this story anybody can measure for themselves, so folkfox measured it. Every figure in the two charts below came from a DataForSEO pull run on 17 August 2026 at United States scope. It is first-party measurement, it is repeatable in ten minutes, and it is exactly the kind of checkable specific this article has been arguing for.

The shape is not the one the category's marketing implies. AI security carries 3,600 monthly searches at a keyword difficulty of 19. Prompt injection, the term most vendor blogs are built around, pulls more demand at 4,400 but sits at a difficulty of 46, well over double. The two least contested terms are the two almost nobody optimises for: llm security at a difficulty of 7, and eu ai act compliance at 26.

AI security demand against difficulty, measured not assumed
Scatter plot of five AI security keywords plotting keyword difficulty against monthly United States search volume, measured on 17 August 20266000400020000ai security (19, 3600)ai securityprompt injection (46, 4400)prompt injectionai agent security (20, 480)ai agent securitllm security (7, 390)llm securityeu ai act compliance (26, 170)eu ai act compliKeyword difficulty
The busiest term is also the hardest: prompt injection takes 4,400 searches at difficulty 46, while llm security asks almost nothing of you at difficulty 7. folkfox measurement, DataForSEO, 17 August 2026, United States scope.

Read that scatter the way a fox reads a hedgerow. The crowded corner top right is where every competitor is already standing, shoulder to shoulder, bidding against each other for the same word. The quiet ground is bottom left, where difficulty is low and the intent behind the query is unusually specific.

Direction matters more than volume on a young topic. On the same pull, AI security was up 20.8% year on year, LLM security up 26.0% and EU AI Act compliance up 21.9%, while prompt injection was down 6.9% and AI agent security down 11.1%. The attack names are cooling. The discipline names and the compliance names are warming, which is what a category looks like as it grows up.

What each click costs, against the cheapest of the five
What each click costs, against the cheapest of the fiveBullet chart comparing cost per click for five AI security keywords against a target line at 25.93 US dollarsai security: 70.6 of 25.9ai security70.6 USDai agent security: 77.2 of 25.9ai agent security77.2 USDllm security: 34.2 of 25.9llm security34.2 USDeu ai act compliance: 28.6 of 25.9eu ai act compliance28.6 USDprompt injection: 25.9 of 25.9prompt injection25.9 USD
Every term costs more per click than the cheapest, prompt injection at 25.93 USD, with ai agent security running at nearly three times that on a fraction of the volume. folkfox measurement, DataForSEO, 17 August 2026, United States scope.

A difficulty of 7 is not a loophole, it is a vacancy. Nobody has written the definitive page on llm security because the subject sounds too basic to bother with, and basic is exactly what somebody searches for at eleven at night with a board paper due in the morning. Answer the plain question plainly, name the controls, date the page, and the vacancy quietly becomes yours.

One honest caveat on our own figures. These are United States volumes taken on a single day, and demand for a regulatory phrase moves with the news cycle, so a pull in November will not match this one. That is an argument for repeating the measurement every quarter and publishing the date beside it, not an argument for quoting somebody else's stale screenshot.

Cost per click is the market's own opinion of what a query is worth, and it says something blunt. Prompt injection is the cheapest of the five at 25.93 US dollars, while AI agent security costs 77.17 and AI security 70.59. Advertisers are paying roughly three times more for the term with a tenth of the traffic, because the person typing it is much further down the trail towards a purchase.

A 480-search term looks trivial on a dashboard and behaves like a pipeline. In a category where a single deal funds a quarter, the size of the audience matters far less than the seniority of it, and the price advertisers will pay is a cleaner signal of seniority than any persona document.

The practical split writes itself. Send budget to the expensive, high-intent phrases, which is where folkfox paid search work begins, and let the content programme claim the low-difficulty explanatory ground before a competitor notices it is empty. Both halves need the same raw material: sentences somebody can quote without checking them twice.

Section 05

How to market ai security without the scary number#

The brief writes itself once the invented statistics are gone. You are selling to somebody carrying a dated obligation, an unmeasured threat and a service account nobody can account for. Give them sentences they can repeat inside their own business, and they will do your selling in rooms you will never be invited to.

No method, no date, no defence

Prompt injection attacks have surged dramatically year on year, with success rates that should alarm every board in the country.

Dated, sourced, specific

From 2 August 2026 the remainder of the EU AI Act applies, and most teams still cannot list which agents run in their name or which credentials those agents hold.

The second version is duller, and it is the one that gets forwarded, because a security lead can defend it in a meeting without doing any homework first. That is the only test AI security copy needs to pass: would your buyer paste this sentence into an internal document with their own name attached to it?

Publish the method, not just the number#

If you do hold proprietary telemetry, publish how it was gathered. The window, the sample, the definition of an attempt, the date it was pulled. A named method turns a number into evidence, and evidence becomes the citation every rival has to reach for. That is a durable asset, unlike a scary percentage, and it is the same discipline behind folkfox SEO and GEO work and our content marketing services.

Watch where your evidence lives, too. The scraping layer beneath every rank tracker and AI visibility dashboard is now being litigated. MediaPost reported that Google filed an amended complaint alleging SerpApi bypassed its technological safeguards, three weeks after US District Judge Yvonne Gonzalez Rogers dismissed the original complaint and left Google able to proceed only on claims about content it licenses from third parties.

Google says it receives "hundreds of millions of artificial search requests each day" from SerpApi and built a system called SearchGuard to stop bot scraping. SerpApi's own post, which is the defendant's account and should be weighed as one, says "the court rejected Google's attempts to expand the DMCA to assert control over access to public pages".

Glenn Gabe read the amended complaint as Google protecting its licensing partners, Reddit among them, in a post from 12 August 2026 that is five days old rather than fresh. A reply in the same thread, from the account @AgenticOperator, put the consequence better: "every court ruling changes who can access what, and that changes who AI can cite."

That should land twice for a security brand. Your measurement stack rests on somebody else's access, and so does your visibility inside AI answers. If the only proof of your reach is a third-party scrape, you have a supply chain, and supply chains get contested in court.

Run the calendar, not the panic#

Build the programme around the dates. The 11 September 2026 reporting obligation gives product security vendors a hard countdown. The 2 August 2027 application of Article 6(1) gives everyone else one. Between them sit twelve months of predictable, searchable questions, and a content plan that answers them in order will outrank a plan that reacts to whatever frightened somebody on a Tuesday.

Regulated buyers behave alike whatever the sector, which is why the approach folkfox runs for FinTech marketing transfers here almost untouched, and why serious brand strategy work usually starts with a list of the things you have decided to stop claiming.

The field will eventually get its incidence data. Somebody will count properly, publish the method and give the industry a figure it can cite without flinching. Until that day arrives, the specific, dated, slightly boring account beats the dramatic one every time, because the person you are selling to has already learned to distrust the drama.

Buy the category name carefully. AI security posture management is measurable, uncontested search ground, and folkfox measured it at difficulty 1 against a $62.37 cost per click on 17 August 2026, which is the shape of a term buyers use and rivals have not yet crowded.

Questions

Frequently asked questions#

What is prompt injection, in plain English?

Prompt injection is when text an AI system reads ends up acting as an instruction instead of information. A model takes instructions and content down the same channel, so a web page, a ticket or a document can tell it to do something its operator never asked for. Indirect prompt injection is the version where that text is planted inside something the system was told to read.

Where should AI agent security actually start?

With inventory and identity, well before model hardening. List every agent running in your name, the credentials each one holds and the documents it is permitted to open. Most agents borrow a service account, and service accounts sit outside sign-in rules built for humans, so the usual login controls never see them at all.

Is LLM security a separate discipline from application security?

Not really. LLM security is application security with an extra class of input. Least privilege, secrets management, logging and network controls all still apply. What changes is that the input itself can behave like an instruction, which is why access boundaries matter more than clever filtering at the model layer.

What does EU AI Act compliance require from 2 August 2026?

From that date the remainder of the AI Act applies, except Article 6(1), and Member States had to have at least one national AI regulatory sandbox established. Article 6(1) and its corresponding obligations follow on 2 August 2027, and AI systems inside the large-scale IT systems listed in Annex X have until 31 December 2030 to comply.

Salt Security's breakdown of EU AI Act Article 15 ties prompt-injection defence to cybersecurity: the robustness obligations are concrete and deadline-bound.

Can I quote a vendor's attack statistics in my own campaign?

Only if you can reach the primary source and it names a method, a sample and a date. Several widely shared AI attack figures trace back to marketing posts citing one another. A security buyer will check, and an unsourceable number costs far more credibility than the click it buys you.

Why does AI security search demand look so small?

Because the category is young and its vocabulary is still moving. On 17 August 2026 folkfox measured 3,600 monthly United States searches for AI security at a difficulty of 19, with the discipline and compliance terms growing while the attack names shrink. Small, specific and rising beats large, generic and contested.

Does AI security posture management cover agents as well as models?

It should. Most tooling sold as AI security posture management started by inventorying models and their data paths. Agents moved the risk: an agent holds credentials, calls tools and acts. If a posture product cannot tell you which identity an agent runs as and what that identity can reach, it is describing half the estate.

Keep reading

Read more on this topic#

Ready to sell AI security without the invented statistic?

Evidence-led campaigns for security brands are what folkfox builds: dated calendars, sourced claims, and reporting that survives a buyer reading it closely.