FY26 SOTU Report Background

From Jailbreaks to Agentic Attacks: The Evolution of AI Abuse

AI abuse is evolving beyond copy-and-paste jailbreak prompts. New Bitsight Threat Intelligence research shows how threat actors and cybercrime-adjacent users are experimenting with prompt injection, obfuscation, multi-model workflows, AI coding agents, and access to tools that can turn unsafe model behavior into real-world security risk.

This report traces that evolution from early jailbreak communities and underground markets to MCP abuse, agentic execution, and AI-assisted cyber operations.

Key takeaways

  • AI abuse is moving from prompt manipulation toward agentic execution
  • Jailbreaks are becoming repeatable workflows built around obfuscation, model routing, testing, and retry logic
  • Prompt injection can create greater risk when AI agents can access files, run commands, or call enterprise tools
  • MCP-connected tools expand the potential impact of indirect prompt injection and unsafe agent behavior
  • Threat actors are increasingly interested in AI capabilities, including private prompts, uncensored models, API access, coding agents, and stolen AI assets

Download the report to explore how AI abuse is evolving and what security teams should monitor as AI systems become more connected, autonomous, and operational.

 

Download Report

 

Ransomware Word Cloud
Jailbreak AI TRACE Report cover
Emma Stevens
Senior Threat Intel Advisor, Bitsight

Threat actors are learning where AI systems have power. In agentic environments, what the model can do may matter more than what the model can say."

Jailbreak AI TRACE Report cover

report reveals

AI abuse is moving beyond simple jailbreak prompts, creating new risks as models gain access to tools, files, code, and enterprise workflows.

  • AI abuse is shifting from prompt manipulation toward agentic execution, where compromised assistants can read files, run commands, call tools, and interact with enterprise systems
  • Jailbreaks are becoming repeatable workflows, combining obfuscation, model routing, testing, retry logic, and multi-model comparison rather than relying on a single prompt
  • Prompt injection carries greater consequences in agentic environments, where hidden instructions in repositories, documents, webpages, emails, or tickets can influence real actions
  • MCP-connected tools are expanding the AI attack surface by connecting agents to files, APIs, repositories, credentials, shell-backed tools, and internal systems
  • Threat actors are increasingly pursuing the broader AI capability ecosystem, including uncensored models, private prompts, API access, coding agents, stolen credentials, and proprietary AI assets