“Autonomous agents significantly expand the attack surface for prompt injection,” says Natalie Shapira, a security researcher at Northeastern University, who studies AI agents. “The challenge is the chain of permissions and actions that connects the model to multiple applications and services.”