Prompt Injection Is the New Phishing: How Enterprises Should Harden Their AI
As large language models seep into trading desks and back offices, attackers are weaponizing prompts. Here is a compact playbook for CISOs and finance leaders.
As large language models seep into trading desks and back offices, attackers are weaponizing prompts. Here is a compact playbook for CISOs and finance leaders.

Illustration by IMF Alpha editorial · Reviewed by Pedro Marini
Short version: models are social‑engineered, not just hacked.
Large language models have moved out of the lab. They now sit inside processes that price trades, summarize legal risk, and answer customers. That shift changes the attacker calculus. Prompt injection is often the simplest route: rather than cracking a model, an adversary nudges its inputs so it produces harmful outputs or spills sensitive context.
Why this matters now
A short historical thread
Remember how phishing evolved in the 2000s? Mass email blasts gave way to highly targeted social engineering as defenses improved. Prompt injection is the same pattern, transposed onto language models: as models got smarter, attackers switched from noisy exploits to subtle manipulations of behavior.
Examples and realistic scenarios
These are not hypotheticals. They are concrete failure modes that financial institutions should be planning for now.
What works in practice: a pragmatic playbook for the next 90 days
Tradeoffs and second‑order effects
Hardening prompts adds latency and engineering work. Lock language down too tightly and people will build shadow tools to move faster. The trick is to balance governance with developer‑friendly guardrails so security doesn’t become a roadblock people routinely bypass.
Editorial take
This calls for pragmatism, not panic. Stop thinking of these models as just another API endpoint. They behave — and they need defenses that account for that behavior. For finance, the harms go beyond data loss: mispriced decisions and regulatory trouble are realistic outcomes. Act now and you’ll avoid awkward audit conversations later.
Actionable next step
If you run critical AI workflows, run a prompt‑injection tabletop within 30 days. Make the exercise measurable and tie it to your incident response playbook. It will show where trust boundaries leak and which controls matter most.
Plain summary: this is social engineering rewritten for machine cognition. Ignore it at your peril.

From data marketplaces to GPU demand, a quiet supply shock in training data is shifting winners in the AI race — and not always in predictable ways.

From neural engines in phones to new edge silicon, on-device AI is reshaping hardware economics. Here’s who benefits, who doesn’t, and how investors should think about it.

Smartphones are running LLMs and fraud detection locally. That changes privacy, cost structures, and who controls financial data — fast, but messy.