Multi-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead warns at VB Transform 2026
Summary
At VB Transform 2026, Cisco's head of AI threat intelligence, Amy Chang, reported that multi-turn attacks successfully breached 15 flagship AI models 88.3% of the time, a stark contrast to single-turn red-teaming. This finding, based on 6,986 multi-turn attacks and 30,090 single-turn prompts, highlights a critical vulnerability missed by conventional testing. A June 2026 VentureBeat survey revealed 54% of 107 enterprises experienced an AI agent security incident or near-miss, with 82% still relying on primary provider-native controls. In response, major security vendors like Palo Alto Networks, CrowdStrike, and Cisco are making significant acquisitions, totaling over \$26 billion, to bolster identity and isolation layers. Industry leaders from Box and Intuit presented strategies, including Box's three-layer security framework (permissioning, sandboxing, runtime control) and Intuit's GenOS platform for centralized AI security, underscoring the necessity for continuous, multi-turn adversarial testing in agentic deployments.
Key takeaway
For MLOps Engineers or AI Security Engineers deploying agentic systems, relying solely on single-turn red-teaming is a critical oversight. You must implement continuous, multi-turn adversarial testing to uncover vulnerabilities that traditional methods miss, as models and permissions drift. Prioritize establishing tightly scoped identities, ephemeral sandboxing, and strict runtime execution controls for your agents. Failing to adopt these advanced security postures will expose your AI deployments to significant risks, potentially leading to production incidents and eroding user trust.
Key insights
Multi-turn attacks expose AI model vulnerabilities far more effectively than single-turn testing, necessitating continuous, adaptive security measures.
Principles
- Single-turn AI security testing is insufficient for agentic systems.
- Agent security requires tightly scoped permissions and isolation.
- Continuous testing is essential due to probabilistic and evolving AI systems.
Method
Cisco's framework involves agents assessing deployment scenarios, developing and executing relevant attacks, then evaluating their own success. Box uses permissioning, ephemeral sandboxing, and runtime execution control.
In practice
- Implement multi-turn adversarial testing for AI agents.
- Assign each AI agent its own scoped, managed identity.
- Isolate high-risk agents in ephemeral sandbox environments.
Topics
- Multi-turn Attacks
- AI Agent Security
- Red Teaming
- Identity Management
- Sandboxing
- Continuous Security Testing
Best for: CTO, VP of Engineering/Data, AI Architect, AI Security Engineer, MLOps Engineer, Director of AI/ML
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by VentureBeat.