ESET's New AI Security Features Target Shadow AI, Prompt Injection and Agentic Risk Across the Enterprise
ESET previews AI protection capabilities targeting shadow AI, prompt injection, and agentic risks — giving enterprise security teams visibility into how employees interact with AI tools across the organisation.

ESET AI security features protecting enterprise chatbot communications and agentic AI workflows from prompt injection, shadow AI risks and supply chain attacks
The endpoint is back at the centre of the cybersecurity conversation — and this time, the threat is coming from inside the organisation.
ESET, a global leader in cybersecurity with more than 30 years of endpoint protection experience, has previewed a new suite of AI security capabilities designed to address one of the fastest-growing and least-visible risks facing enterprise security teams today: the unmonitored, ungoverned use of AI tools by employees across corporate environments.
Demonstrated at RSAC 2026 and scheduled for full launch later this year, the new features expand the visibility layer within the ESET PROTECT Platform — giving security teams the intelligence they need to investigate emerging risks tied to everyday AI usage and the growing adoption of agentic AI across enterprise networks.
The Problem: Shadow AI Is Already Inside Your Organisation
Most enterprise security teams are focused on external threats. But one of the most pressing risks in 2026 is already sitting inside the perimeter — and it is growing faster than policy can keep up with.
As employees embed AI tools into their daily workflows, many are using open cloud-based chatbots without IT oversight, approval, or any visibility from the security team. This creates what ESET terms "shadow AI" — an ungoverned layer of AI interaction that is quietly exposing sensitive data including internal documents, API keys, secrets, and credentials to external systems that were never vetted or approved.
For GCC enterprises operating under frameworks such as the UAE's Personal Data Protection Law (PDPL), SAMA's Cybersecurity Framework, and Saudi Arabia's National Cybersecurity Authority (NCA) controls, this is not simply an operational risk — it is a compliance exposure that regulators are increasingly paying attention to.
How ESET Is Addressing It
ESET's approach is built around getting as close to the source of AI interaction as possible. The core of the new capability is a secure browser technology that intercepts AI interactions in real time, analysing both prompts and responses before they are processed or acted upon.
In practical terms, this means:
- Malicious URL detection — flagging dangerous links submitted through chatbot prompts before they reach the user
- Prompt injection monitoring — identifying and blocking attempts to manipulate AI systems through crafted inputs
- Sensitive data interception — detecting when employees are submitting confidential information into AI tools and enforcing organisational policy before exposure occurs
- Script and code analysis — reviewing AI-generated outputs for malicious or risky code before it is executed
All activity is logged at the endpoint and surfaced in the ESET PROTECT Platform, giving security teams a centralised view of how AI tools are being used across their organisation — and the ability to investigate, block, or enforce policy accordingly.
The Agentic AI Frontier
Beyond chatbot interactions, ESET is tracking a more sophisticated and rapidly evolving threat: the expansion of agentic AI tools that can execute actions on a system with limited human oversight.
As organisations begin deploying autonomous AI agents to automate workflows, a new attack surface is opening. ESET has identified several categories of emerging risk in this space:
- Compromised AI frameworks — trojanized components embedded in widely used libraries such as LiteLLM, delivered through standard repositories that developers trust by default
- Autonomous agent exploitation — tools like OpenClaw that can execute system-level actions with minimal oversight, creating opportunities for attackers to hijack agent behaviour
- AI supply chain attacks — a rising category of threat that mirrors traditional software supply chain attacks but targets the AI toolchain specifically
ESET has already been protecting customers from supply chain attacks through compromised libraries, but notes a clear rise in AI-specific variants — and is committing further research and development to this area.
For enterprise security teams in the GCC who are beginning to deploy agentic AI for automation, this is a threat vector that demands immediate attention. The broader conversation around AI governance and security across the MENA region is accelerating — and agentic AI risk is becoming a central part of it.
Industry Collaboration and the ESET AI Skills Checker
ESET is the only dedicated cybersecurity member of the Agentic AI Foundation (AAIF), a collaborative body working to establish trusted standards, secure protocol designs, and best practices for AI agent interoperability. Members include OpenAI, Amazon, Microsoft, and Anthropic.
This positions ESET at a unique intersection: a company with deep endpoint security heritage that is now actively shaping the standards governing how AI agents communicate and operate securely across enterprise environments.
As part of its RSAC 2026 announcements, ESET also launched a free ESET AI Skills Checker — available to non-ESET customers — which analyses AI skills for hidden instructions, malicious code, and risky behaviour using multilayered inspection and cloud-based sandboxing. For existing ESET Endpoint users, it is already available as a built-in feature.
What GCC CISOs Should Take Away
The risks ESET is addressing are not hypothetical — they are active and accelerating. Three immediate priorities emerge from this announcement for enterprise security leaders across the Gulf:
1. Audit your shadow AI exposure now. If your organisation does not have visibility into which AI tools employees are using and what data they are submitting to those tools, you have an uncontrolled compliance and data exposure risk that regulators in the UAE and Saudi Arabia are increasingly focused on.
2. Agentic AI needs a security framework before deployment, not after. Organisations that move quickly to automate with AI agents without establishing governance and monitoring frameworks are creating the attack surface of tomorrow — today.
3. Endpoint is the new AI security perimeter. As AI interactions happen at the device level, endpoint security platforms that can intercept, analyse, and enforce policy on AI communications are becoming essential infrastructure — not optional add-ons.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.