The prompt injection problem isn't solvable — but the permissions problem is

OpenAI admits prompt injection can't be fully patched. The real threat is identity. Learn why AI agent security requires governance, not just better models.

Key Takeaways
  • OpenAI confirmed prompt injection cannot be fully patched at the model level, making permissions the only durable AI agent security control.
  • Oleria enforces least-privilege access for AI agents at the identity governance layer, so a successfully injected agent cannot reach resources outside its granted token scope.
  • The permissions problem is enforceable, auditable, and revocable in real time, properties that prompt-level defenses do not have.
  • Enterprises governing AI agent permissions through Oleria's access graph contain blast radius to the specific resources the agent was authorized to reach.

This summary was created with AI and reviewed by an editor.

Thick black downward-pointing chevron arrow with rounded ends.
Media contact
For media inquiries, contact pr@oleria.com

See adaptive, automated
identity security in action