Japanese outlet InnovaTopia reports that Trend Micro’s enterprise brand TrendAI and PwC Consulting have published joint research showing that stored prompt injection attacks succeed across 13 different AI models from Anthropic, OpenAI, Google and DeepSeek. The July 20 article summarizes tests of 2,600 attack prompts in realistic web form and KYC workflows and introduces a new governance metric called AI-CAL.
This article aggregates reporting from 1 news source. The TL;DR is AI-generated from original reporting. Race to AGI's analysis provides editorial context on implications for AGI development.
This research is a clear sign that the industry is finally poking hard at the failure modes of agentic AI, not just models in isolation. TrendAI and PwC essentially demonstrate that if you wire frontier models into real workflows — ticketing systems, KYC flows, databases — stored prompt injection becomes a structural risk, not an edge case that better fine‑tuning will magically fix. Because agents can chain tools with high privileges, a single malicious instruction hidden in user data can trigger cascading data theft.
For the race to AGI, this matters because everyone is quietly converging on autonomous or semi‑autonomous agents as the way to turn raw model intelligence into economic value. If the underlying architecture cannot reliably distinguish “data” from “instructions”, then simply scaling models and bolting on more tools increases systemic cyber risk. The proposed AI‑CAL control assurance levels hint at where things are going: regulators, boards and CISOs will demand auditable, quantitative guarantees about agent behavior before green‑lighting truly autonomous systems.
In competitive terms, labs and platforms that can show strong agent security postures — by design, not just via filters — will gain an edge in enterprise and government markets, which are precisely the customers funding large‑scale deployments today.



