Back to News
Market Impact: 0.22

Security researchers tricked LLMs into giving them cocaine recipes by abusing role models for prompt injection

Artificial IntelligenceCybersecurity & Data PrivacyRegulation & LegislationTechnology & InnovationMarket Technicals & FlowsInvestor Sentiment & Positioning

Researchers argue LLMs cannot reliably distinguish authorized vs. unauthorized inputs, meaning prompt injection will likely remain an ongoing threat absent a new security model. They report an attack (“CoT Forgery”) raising jailbreaking success from near 0% to ~60% on tested models and note human red-teamers can reach close to 100% on benchmarks, suggesting safety scores may overstate real-world resilience. While this is primarily academic, it raises near-term risk around LLM deployment and reinforces persistent whack-a-mole security expectations for the sector.

Analysis

This reads as a validation event for the AI security stack, not a new risk to the core LLM train. The market mechanism is a slower enterprise rollout of agentic features: every material workflow that can be hijacked by untrusted text implies more review, more middleware, and more identity/data controls, which raises deployment friction and lowers near-term attach rates for AI copilots embedded in productivity and workflow software.

The second-order winner set is the security layer: vendors selling model governance, DLP, identity, and content filtering should see a longer budget tail as CIOs move from "demoable" to "auditable" AI. The loser set is pure-play AI application vendors whose valuation assumes fast autonomous-agent adoption; this thesis is more about multiple compression from delayed monetization than an immediate revenue hit. Over 1-3 months, expect this to show up in procurement language, not earnings; over 6-18 months it becomes a durable line item in enterprise AI budgets.

Contrarian view: the consensus may be overreacting to the model-level flaw and underappreciating compensating controls. Most enterprises will not abandon AI; they will sandbox it, limit tools, and route sensitive actions through deterministic layers, which blunts the headline risk. The trade only works if the market is still capitalizing full autonomy into adoption curves—if not, this is more of a rotation signal than a bearish call on AI spend.

What would falsify the thesis is evidence that major cloud/enterprise vendors are shipping robust agent isolation and policy enforcement at scale, or that AI feature adoption continues accelerating despite formal security review. If security budgets do not expand in the next two quarters, the "AI safety tax" is not being passed through, and the short case on AI application multiples weakens materially.

More News