Multi-turn attacks broke AI mo... Note
VentureBeat

Multi-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead warns at VB Transform 2026

Cisco's research reveals that attackers can break through AI models in multi-turn conversations up to 88.3% of the time, significantly outpacing single-turn red-teaming efforts. This finding highlights a critical gap in current enterprise AI security, as evidenced by over half of surveyed companies experiencing AI security incidents or near-misses. Many organizations still lack robust identity management and isolation for their AI agents, relying primarily on provider-native controls. Major security vendors are actively acquiring companies to bolster their capabilities in agent identity and isolation, acknowledging this enterprise deficiency.Amy Chang, a leader in AI threat intelligence, emphasized that understanding how models are susceptible to various attacks is crucial for identifying failure points. Multi-turn attacks realistically mimic how humans interact with AI, uncovering harmful outputs missed by snapshot testing. Cisco advocates for a self-assessing agentic framework to develop and execute attacks, finding that fundamental, basic security principles remain the most effective defense.Box's CISO, Heather Ceylan, echoed the need for multi-turn adversarial simulation, noting that even with strong trust, a single agent mistake can erase accumulated confidence. Box employs layered security with strict permissioning, ephemeral sandboxes, and runtime execution controls to contain risks. Intuit's VP of AI and ML, Rajesh Parekh, discussed their GenOS platform, which centralizes security and risk management for AI agents, providing tightly scoped and auditable task authority.Ceylan predicts the end of traditional human code reviews as agents become proficient in identifying and fixing vulnerabilities, though this is still a future goal. Both Ceylan and Parekh stressed the importance of least privilege access for AI agents to prevent broad overreach. The increasing capabilities and access of AI agents expand the attack surface, necessitating continuous testing and automation of common vulnerability patterns.The complexity of detecting true intent versus probability in AI interactions remains a significant industry challenge. Cisco's research indicates models currently struggle to reliably derive intent, making deterministic controls and behavioral proxies essential. Ultimately, enterprises must continuously test AI agents across full conversations, mimicking attacker methodologies, to avoid critical failures in production.