[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fms7Epn_2fRyAWgMehmbSorQ0YgYFIsDTsJDglEEQCvM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"9d78390c-b0cb-4643-9081-5768de32c4b2","encrypted-prompts-defeat-ai-safety-filters-in-grok-and-gemini","dae8bb3c-b19d-4793-8f76-bd008133bcb8","Encrypted Prompts Defeat AI Safety Filters in Grok and Gemini","Researchers uncovered 'Cryptographic Context Injection,' a technique that smuggles malicious instructions past AI safety guardrails by encoding them in encrypted form, which the model then decrypts and executes within its trusted environment. The root cause lies in a fundamental configuration flaw: AI safety checks are applied at the input layer but not re-evaluated after decryption occurs during inference. This means the guardrails — designed to block harmful content — never actually inspect the true intent of the payload. The consequences are severe, enabling attackers to exfiltrate sensitive data or generate restricted outputs that would otherwise be blocked. As AI systems are integrated into enterprise workflows, this class of vulnerability represents a rapidly expanding and underappreciated attack surface.","**Immediate actions:**\n- Audit all AI model integrations to identify where untrusted, encrypted, or encoded inputs may be processed without secondary safety validation.\n- Implement input sanitization and decryption-then-re-evaluation pipelines so that safety checks occur *after* any decoding step, not just at initial ingestion.\n\n**Long-term improvements:**\n- Work with AI vendors (xAI, Google, etc.) to demand post-decryption guardrail enforcement as a baseline security requirement in SLAs and procurement criteria.\n- Establish a formal AI Security Policy that classifies prompt injection and cryptographic bypass as critical threat vectors requiring dedicated red-team testing.\n- Apply the principle of least privilege to AI model permissions, ensuring models cannot access sensitive data stores or execute actions beyond their defined scope.\n\n**Detection measures:**\n- Deploy logging and behavioral monitoring on AI API endpoints to flag anomalous output patterns (e.g., unexpected data exfiltration, policy-violating content generation).\n- Integrate AI-specific threat intelligence feeds into your SIEM to receive timely alerts on newly discovered prompt injection or bypass techniques.\n- Conduct regular adversarial prompt testing (AI red-teaming) as part of your vulnerability management cycle to proactively identify guardrail weaknesses.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"NIST AI RMF – GOVERN 1.1 (AI Risk Policies)","NIST AI RMF – MEASURE 2.5 (Adversarial Testing)","NIST SP 800-53 SI-10 (Information Input Validation)","NIST SP 800-53 AC-4 (Information Flow Enforcement)","NIST SP 800-53 AU-12 (Audit Record Generation)","CIS Control 16 (Application Software Security)","CIS Control 8 (Audit Log Management)","CIS Control 18 (Penetration Testing)","GDPR Article 25 (Data Protection by Design and by Default)","GDPR Article 32 (Security of Processing)","OWASP LLM Top 10 – LLM01 (Prompt Injection)","OWASP LLM Top 10 – LLM06 (Sensitive Information Disclosure)","ISO\u002FIEC 42001 (AI Management System – Risk Treatment)","published","2026-08-21T16:21:28.031586+00:00","2026-08-21T16:21:27.928+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fwww.securityweek.com\u002Fencrypted-prompts-bypass-ai-safety-guardrails-in-grok-and-gemini\u002F","encrypted-prompts-bypass-ai-safety-guardrails-in-grok-and-gemini-832066","Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":40,"name":41,"slug":42,"description":43,"color":44},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":46,"name":47,"slug":48,"description":49,"color":50},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]