What’s changed in AI security over the past two years
Blog post from Bugcrowd
AI security has changed substantially since 2024 as business adoption has become widespread and autonomous AI agents have moved beyond chatbots into operational workflows, expanding the potential consequences of failures. Organizations increasingly identify data security, privacy, and risk as central concerns, while agent-specific threats such as memory poisoning, plan hijacking, goal drift, and tool abuse have emerged alongside reported incidents involving data exposure, database deletion, and remote code execution. New techniques including many-shot jailbreaking exploit much larger model context windows, although defenses have also improved. AI-related harms are now appearing in litigation and public incidents, while regulation has shifted toward overlapping federal, state, and international requirements, including the active implementation of the EU AI Act. Generative AI has also created “AI slop,” or large volumes of low-quality automated vulnerability reports that complicate security programs. Established risks such as prompt injection, training-data poisoning, denial of service, and supply-chain vulnerabilities remain relevant, but the growing scale, autonomy, and real-world impact of AI systems require updated security threat models and controls.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 4 | 931 | 231 | 103 | -84% |
| AI Guardrails | 1 | 35 | 22 | 12 | -94% |
| LLM | 1 | 747 | 162 | 79 | -85% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.