Definition
A design flaw where an AI-powered workflow can be tricked into performing high-privilege actions by an unauthenticated input — without ever manipulating or 'jailbreaking' the AI model itself. It exploits how the workflow assigns trust and authority, not the model's judgment.
Why it matters
Because the attack bypasses the model entirely, defenses built to catch manipulated prompts or malicious instructions simply don't apply, leaving a governance gap that boards need new controls to close.