READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Cisco Study: AI Models Fail Security Tests 88% of the Time When Attackers Keep Talking

Cisco Study: AI Models Fail Security Tests 88% of the Time When Attackers Keep Talking
Cisco tested 15 flagship AI models with nearly 7,000 multi-turn conversational attacks and broke through up to 88.3% of the time, far more than one-shot prompt tests ever showed. Most companies are still relying on single-turn testing and provider-default security, which this data says is not good enough.

The Test That Changed the Numbers

Cisco ran 30,090 single-turn prompts and 6,986 multi-turn attacks against 15 flagship closed and proprietary AI models. The multi-turn attacks, where a bad actor keeps adapting the conversation instead of firing one malicious prompt and walking away, succeeded between 7.89% and 88.3% of the time depending on the model, according to VentureBeat.

Every single model tested showed what Cisco calls "non-trivial multi-turn exposure." Single-turn and multi-turn testing did not rank the models in the same order. A model that looks solid against a one-shot attack can fold once someone works it over a longer conversation.

Amy Chang, Cisco's head of AI threat intelligence and security research, presented the findings at VB Transform 2026. Chang co-authored the underlying study with Nicholas Conley. Her resume carries weight here: she ran global cybersecurity operations as an executive director at JPMorgan Chase, worked as a senior staffer on the House Foreign Affairs Committee, served as a U.S. Navy Reserve officer, and teaches cybersecurity at the Middlebury Institute of International Studies.

"If you don't understand how models are susceptible to different types of attacks, then you are unable to account for how that model that is powering your agent, that is powering your application, to understand where those failure points are," Chang said, according to VentureBeat. She described single-turn testing as a one-shot malicious prompt, while multi-turn attacks are "more realistic of how we are actually engaging with our models, with our agents, with our applications."

Companies Are Behind, By Their Own Admission

VentureBeat's June 2026 Pulse survey of 107 enterprise respondents backs up why this matters. Fifty-four percent of companies surveyed have already had either a confirmed AI agent security incident, 18%, or a near-miss caught before real damage, 36%.

Only 32% give every AI agent its own scoped, managed identity. Only 30% isolate their highest-risk agents in sandboxes. Meanwhile 82% of companies are still leaning on provider-native and hyperscaler controls, meaning the security default that ships with the product, as their primary layer of defense.

Most companies are betting their agent security on whatever OpenAI, Google, or Microsoft built in by default, rather than building their own layer on top. Cisco is now publishing adversarial evaluation signals for 105 models on its LLM Security Leaderboard, giving companies at least a public reference point instead of guessing.

Money Is Already Moving

The big security vendors are not waiting around. Palo Alto Networks closed its $25 billion acquisition of CyberArk in February 2026. CrowdStrike agreed in January 2026 to pay $740 million for SGNL. Cisco itself announced plans to acquire Astrix Security for a reported $400 million.

All three deals target the same weak spot: identity and isolation controls for AI agents, the exact gap the Pulse survey found most companies have not closed. When three of the largest cybersecurity companies in the world are all buying in the same lane within months of each other, that signals the industry sees this as more than a research curiosity.

The Fair Pushback

A reasonable skeptic could point out that Cisco sells AI security products, including its own leaderboard and threat intelligence services, so a study proving current defenses are inadequate is also a study that helps sell Cisco's fix. That is a legitimate conflict to flag, and it applies to every vendor named here, not just Cisco. CrowdStrike, Palo Alto Networks, and Cisco all have a financial interest in convincing enterprises that existing, cheaper defenses fall short.

The underlying numbers are sound. The 88.3% figure comes from a methodology, nearly 37,000 total prompts across 15 named models, that is specific and reproducible rather than a vague industry scare statistic. Nobody in either source disputes the raw test results; the open question is how much of the urgency is genuine risk versus sales pitch.

What Happens Next

No regulatory body has mandated multi-turn adversarial testing as a standard. There is no law requiring companies to isolate high-risk AI agents in sandboxes or assign them individual managed identities.

The gap Chang's team measured, between how models perform under one-shot testing versus sustained conversational attacks, remains an open engineering problem industry-wide. Whether enterprises close the identity and isolation gap the Pulse survey documented, or whether the next confirmed incident count climbs past this year's 18%, is the number worth watching when VentureBeat runs its next Pulse survey.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
VentureBeatMulti-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead warns at VB Transform 2026
unknown
spiditsMulti-turn Attacks Broke AI Models 88% of the Time - Single-turn Testing Missed It, Cisco AI Security Lead Warns at VB Transform 2026 | AI Timeline | SPIDITS