Verified in the first week of August 2026. Two frameworks moved days before publication, so re-check before any reprint.
| Source | Date | What it supports |
|---|---|---|
| IBM, Cost of a Data Breach Report 2026 | 29 July 2026 | Global average $4.99M, US average $11.50M, AI-enabled breaches ~$6M, prompt injection $5.89M, model inversion $6.07M, shadow AI $5.39M vs $4.63M, 43% shadow AI prevalence, 68% no completed AI governance policy, 247-day mean time to identify and contain, 1 in 4 malicious breaches AI-enabled. Base: 602 organizations breached March 2025 to February 2026. |
| Gartner, worldwide AI spending forecast | 19 May 2026 | $2.596 trillion total AI spending in 2026, up 47%. AI cybersecurity line item $51.347 billion, about 2%. Note the category bundles AI-for-security with securing-AI, so 2% is an upper bound. |
| MITRE ATLAS data repository, release 2026.07 | 31 July 2026 | 16 tactics, 178 techniques (101 parent, 77 sub), 37 mitigations, 68 case studies. Monthly content releases. |
| OWASP GenAI Security Project, LLM Top 10 for 2026, v1.0 | 3 August 2026 | Prompt Injection first for a third year. Excessive Agency up to third. LLM08 is now Hidden Context Exposure. Rankings derived from analysis of around 10,000 real-world incidents. |
| OWASP Top 10 for Agentic Applications | 9 December 2025 | ASI01 to ASI10, used verbatim in the agentic article. |
| Hackett, Birch, Trawicki, Suri, Garraghan (Lancaster University and Mindgard), arXiv:2504.11168, LLMSec 2025 | 2025 | Up to 100% evasion against six production protection systems including Azure Prompt Shield and Meta Prompt Guard. |
| Schwinn et al. (TU Munich and Mila), arXiv:2603.06594 | February 2026 | LLM judge performance degrades to near random chance under red-teaming distribution shift, across 6,642 human-verified labels. |
| Maloyan and Namiot, arXiv:2601.17548 | January 2026 | Over 85% attack success against agentic coding assistants with adaptive strategies. Most defenses under 50% mitigation. Review of 78 studies, 42 techniques. |
| Li et al., RobustJudge, arXiv:2506.09443 | revised November 2025 | Up to 40% robustness swing from prompt-template choice. 15 attacks, 7 defenses, 12 models. |
| Meta, Llama Prompt Guard 2 model cards | 2025 | 19.3 ms for the 22M encoder, 92.4 ms for the 86M encoder. |
| NVIDIA developer blog, guardrail effectiveness and performance | 3 March 2025 | Three NeMo rails add roughly 530 ms end to end. First-party measurement of NVIDIA's own product. |
| TrueFoundry guardrail benchmark | 19 May 2026 | Azure PII 52.3 ms, OpenAI moderation 191.5 ms, Pangea prompt injection 358.7 ms. Published by a gateway vendor, not independent. |
| Sysdig, LLMjacking research | 2024 to 2025 | Roughly $50,000 of stolen compute in 4.5 days from one monitored proxy (observed). $46,000 per day is Sysdig's modelled ceiling, not a measured loss. Label it as modelled wherever it appears. |
| Anthropic, disrupting the first reported AI-orchestrated cyber espionage campaign | 13 November 2025 | GTG-1002. AI performed 80 to 90% of the campaign. ~30 targets. Humans intervened at 4 to 6 decision points. Succeeded in a small number of cases. |
| Anthropic, AI-enabled cyber threats mapped to MITRE ATT&CK | 3 June 2026 | 832 banned accounts over 12 months. 67.3% used AI to write malware. Medium-risk-or-higher actors rose from 33% to 56%. |
| Five Eyes cyber agencies, "The AI shift in cyber risk" | 22 June 2026 | ACSC, CCCS, GCSB, NCSC, CISA, NSA. "The timeline is not years, it is months." |
| Varonis Threat Labs, SearchLeak, CVE-2026-42824 | 15 June 2026 | One-click exfiltration from M365 Copilot Enterprise. Microsoft fixed 4 June 2026, rated critical. |
| Aim Security / Microsoft, EchoLeak, CVE-2025-32711 | June 2025 | First zero-click prompt injection in a production LLM system. |
| Zscaler ThreatLabz, indirect prompt injection targeting AI agents | 2 July 2026 | Two live campaigns. Four of 26 tested models executed fraudulent payments. |
| Sysdig, JADEPUFFER | 1 July 2026 | First complete LLM-driven ransomware. Self-corrected a failed login in 31 seconds. 1,342 Nacos config items encrypted. Key never transmitted. |
| Invariant Labs, MCP tool-poisoning disclosure | 1 April 2025 | Direct tool poisoning, rug pull and tool shadowing. Exfiltration succeeded even with user confirmation because arguments were hidden. |
| Microsoft, poisoned MCP tool descriptions warning | 30 June 2026 | MCPTox benchmark: poisoned-tool attacks effective at rates up to 72.8%. |
| NSA and CMU SEI, MCP security design considerations, CSI v1.0 | May 2026 | Eight named threat classes including output poisoning. |
| UK NCSC, "Prompt injection is not SQL injection" | 8 December 2025 | "It's very possible that prompt injection attacks may never be totally mitigated." |
| OpenAI, understanding prompt injections | 7 November 2025 | "A hard, open problem." |
| Anthropic, prompt injection defenses | 24 November 2025 | "No browser agent is immune to prompt injection." |
| Google DeepMind, advancing Gemini's security safeguards | 20 May 2025 | Baseline defenses "became much less effective against adaptive attacks." |
| European Commission, AI Omnibus enters into force | 27 July 2026 | Article 50 transparency applied 2 August 2026. Annex III high-risk deferred to 2 December 2027, Annex I to 2 August 2028. Article 99 penalties unchanged at €35M or 7%. |
| Colorado SB 26-189, signed by Governor Polis | 14 May 2026 | Repealed and replaced the Colorado AI Act. New ADMT transparency law effective 1 January 2027. |
| California SB 53, Transparency in Frontier AI Act | in force 1 January 2026 | 10^26 FLOP threshold, $500M revenue for large developers, 15-day incident reporting, $1M per violation. |
| Executive Order, Eliminating State Law Obstruction of National AI Policy | 11 December 2025 | DOJ AI Litigation Task Force, FCC proceeding, FTC policy statement, BEAD conditions. |
| Acquisition timeline | Aug 2024 to Jun 2026 | Acquirer press releases plus Infosecurity Magazine M&A round-ups for Feb and Mar 2026. Only F5 / CalypsoAI disclosed a price ($180M). All other reported figures are press estimates and are omitted from the site. |
| AI-Sentinel internal benchmarks, v6.0 | June 2026 | Sub-20 ms overhead, average clean pass under 8 ms, rejections 2 to 4 ms, p99 2.2 ms at 200 rps, 2,000+ rps per instance, 1,237 automated tests, 160 mapped to MITRE IDs, 16 Rust crates, ~205,000 lines. Labelled as internal on every appearance. |
| MSP pilot results | June 2026 | 85.1% adversarial action rate across 1,000 payloads, zero confirmed exfiltrations across 3,000 live attacks, 100% of system-prompt extraction and cost-amplification probes blocked. Client unnamed at their request. |