Cisco Reveals 88% Success Rate of Multi-Turn Attacks on AI Models
Cisco's study highlights a critical gap in AI security testing, revealing that multi-turn attacks breach models 88.3% of the time, while single-turn methods fail to capture such risks. The findings call for immediate action from enterprises to adopt more robust security measures.
Key Facts
- Multi-turn attacks succeeded 88.3% of the time, revealing vulnerabilities in current security testing.
- 54% of enterprises experienced security incidents, indicating a critical need for improved defenses.
- Major acquisitions (e.g., Cisco's $400M Astrix) highlight a strategic shift towards identity security.
- 82% rely on native controls, exposing a competitive vulnerability in agent security across enterprises.
- Box's agent trust collapse underscores the importance of continuous monitoring in AI deployments.
Summary
Cisco's recent findings on AI security, presented by Amy Chang at VB Transform 2026, reveal a critical vulnerability in the way organizations test their AI models. In a study involving 15 flagship models, Cisco discovered that multi-turn attacks successfully compromised these models 88.3% of the time, compared to single-turn testing, which failed to capture this level of risk. This stark contrast highlights a significant gap in current security practices, particularly for enterprises relying on outdated single-turn red-teaming methods.
The urgency of this issue is underscored by data from VentureBeat's June 2026 Pulse survey, which indicates that over half of the surveyed enterprises have experienced security incidents involving AI. Despite this, only 32% of organizations provide each AI agent with a scoped, managed identity, and even fewer isolate high-risk agents in secure environments. The findings suggest that many companies are inadequately prepared to defend against increasingly sophisticated AI threats, relying heavily on native controls from their service providers, which account for 82% of security layers.
In response to these vulnerabilities, major cybersecurity firms are actively acquiring companies to enhance their security offerings. Cisco's intent to acquire Astrix Security for approximately $400 million, alongside Palo Alto Networks' $25 billion acquisition of CyberArk and CrowdStrike's $740 million purchase of SGNL, indicates a strategic pivot towards strengthening identity management and isolation frameworks. This trend reflects a growing recognition that many enterprises have yet to fully establish these critical security layers.
Chang's insights emphasize the need for a more nuanced understanding of AI vulnerabilities. The study she co-authored, which involved extensive testing of both single-turn and multi-turn attack scenarios, revealed that traditional testing methods do not adequately reflect real-world interactions with AI systems. Multi-turn attacks, which mimic actual user engagement, expose harmful outputs and misaligned behaviors that single-turn tests overlook. This calls for a fundamental shift in how organizations approach AI security, moving from simplistic testing to more comprehensive, realistic methodologies.
The panel discussion also highlighted the importance of continuous testing and monitoring. Heather Ceylan, CISO of Box, shared her company's approach to simulating multi-turn adversaries, which has proven essential for assessing the effectiveness of their security controls. Ceylan's experience illustrates the pitfalls of placing too much trust in AI agents without robust oversight. When an agent made a mistake, it quickly eroded the trust built over time, emphasizing the need for ongoing vigilance and adaptability in security practices.
Intuit's Rajesh Parekh introduced the concept of a generative AI operating system (GenOS), which aims to streamline security and risk management across AI applications. By establishing tightly scoped permissions for AI agents and automating security testing, Intuit seeks to mitigate vulnerabilities before they can be exploited. This proactive approach reflects a broader industry trend towards integrating security into the development lifecycle, moving away from traditional human-led code reviews.
The challenges of intent detection and the evolving nature of AI threats were also central to the discussion. As organizations increasingly rely on AI agents, the need for deterministic controls becomes paramount. Chang pointed out that current models struggle to accurately derive user intent, necessitating a combination of behavioral proxies and strict controls to safeguard against potential misuse.
The implications of these developments are profound. As enterprises continue to integrate AI into their operations, the demand for advanced security measures will only grow. Organizations must adapt their security strategies to account for the complexities of multi-turn interactions and the evolving tactics of adversaries. Those that fail to do so risk significant exposure to threats that traditional testing methods cannot identify.
Looking ahead, businesses must prioritize the establishment of comprehensive AI security frameworks that encompass identity management, continuous testing, and real-time monitoring. As the landscape of AI threats evolves, organizations that proactively address these vulnerabilities will not only protect their assets but also gain a competitive advantage in an increasingly AI-driven market.
Entities Mentioned
Companies
Products
People
Organizations
Key Concepts
Definitions
- multi-turn attacks
- Attacks that adapt across multiple interactions with an AI model, demonstrating a higher success rate compared to single-turn attacks.
- single-turn testing
- A method of testing AI models using one-shot prompts, which fails to capture the complexities of real-world interactions.
- agent security
- The measures and protocols in place to protect AI agents from being compromised or misused.
- trust architecture
- A framework that integrates human oversight and AI capabilities to ensure secure and reliable interactions.
- GenOS
- A generative AI operating system developed by Intuit that abstracts security and risk modeling for AI agents.
Use Cases
- →Simulating multi-turn adversaries to test AI agents
- →Deploying agents in security operations centers
- →Building a central platform for agent security
- →Automating vulnerability tests into AI development
- →Implementing permissioning frameworks for AI agents
- →Continuous testing of AI models to identify vulnerabilities
Frequently Asked Questions
What are multi-turn attacks?
Multi-turn attacks involve adapting strategies across several interactions with an AI model, leading to a significantly higher success rate in breaching security compared to single-turn attacks.
Why is single-turn testing insufficient?
Single-turn testing fails to reflect real-world usage, as it only evaluates AI models based on isolated prompts, missing vulnerabilities that could arise in extended interactions.
How can organizations improve their AI security?
Organizations should adopt multi-turn testing methods, implement robust identity and isolation layers, and continuously evaluate their AI systems to adapt to evolving threats.
What role does trust architecture play in AI security?
Trust architecture integrates human oversight with AI capabilities, ensuring that security measures are in place to manage risks associated with AI agents effectively.
What is GenOS and its significance?
GenOS is a generative AI operating system that centralizes security and risk management for AI agents, allowing developers to focus on building functionalities without reinventing protection measures.