www.darkreading.com 8/17/2026, 8:11:15 PM · external

Expert Warns AI Firms Must Tackle Prompt Injection and Bias Risks

Expert Warns AI Firms Must Tackle Prompt Injection and Bias Risks
CyberSIXT Evidence Panel
Primary Source shostack.org

ADAM Shostack, a threat modeling expert, discussed OpenAI's recent findings regarding the Hugging Face hack and introduced his new lightweight threat modeling framework for large language models (LLMs) named PHANTOM-B. This model differs from existing frameworks by focusing on potential risks rather than just listing vulnerabilities. PHANTOM-B consists of key elements: prompt injection, hallucination, anthropomorphizing, non-explainable training data, overreliance, missing security engineering, and bias.

Shostack emphasized the importance of addressing these risks, particularly prompt injection and anthropomorphizing, which can lead to misuse of LLMs. He raised critical questions about liability for AI agents and the adequacy of current security measures, suggesting that innovation must be balanced with accountability. The conversation highlighted the complexities surrounding AI safety and the legal implications of AI behavior.

View Primary Source Via www.darkreading.com

Article by CyberSIXT