As businesses and governments tie more of their operations to AI systems, they become increasingly vulnerable to attacks that exploit the inherent blind spots of AI systems. The most common of these are prompt injection attacks, wherein attackers find a way to give an AI system malicious instructions. Microsoft found that some companies were including "summarize with AI" buttons on their websites that contained hidden instructions. More directly malicious attacks can be equally effortless. OpenAI claimed last year that fully defending against prompt injection attacks in AI browsers may not be possible.