OpenAI has added prompt-injection results to the GPT-5.6 system card, reporting a low failure rate for attacks delivered directly through chat but higher rates in tests involving AI agents and external content. Average attack success rates reached 3.77% for Sol, 3.32% for Terra and 2.94% for Luna in OpenAI’s indirect tests. Direct attacks fall as agent tests remain harderThe updated GPT-5.6 system card describes direct prompt injection as a user’s attempt to override higher-priority instructions. Recent disclosures show why AI agent permissions need stronger controls. OpenAI’s tests show improved resistance to direct prompt injection, while the indirect results leave agent security dependent on the permissions and controls surrounding the model.