Major AI Security Announcements This Week
This week’s AI security news covers critical prompt injection patches from OpenAI, Google, and Anthropic, a CERT-In phishing advisory targeting India’s banking sector, and a NIST AI Risk Management Framework draft update expanding adversarial ML guidance. These announcements affect enterprise deployments, regulated industries, and anyone building or securing AI systems in 2025.
- Key Takeaway 1: Major LLM vendors patched critical prompt injection and data exfiltration flaws this week, affecting enterprise deployments globally.
- Key Takeaway 2: India’s CERT-In issued fresh advisories on AI-powered phishing campaigns targeting the BFSI sector.
- Key Takeaway 3: The US NIST released a draft update to its AI Risk Management Framework, expanding guidance on adversarial machine learning.
- Key Takeaway 4: Demand for professionals who understand both AI and security has jumped sharply, with job postings citing “AI security” skills up 38% year-on-year according to LinkedIn’s 2025 Jobs on the Rise report.
What Are the Major AI Security Announcements This Week?
The biggest AI security announcements this week came from three directions: vendor patches, regulatory guidance, and new research disclosures. Each one matters for a different reason, and together they represent a significant shift in how organisations must think about AI-specific risk.
LLM Prompt Injection and Data Exfiltration Patches
OpenAI, Google DeepMind, and Anthropic all issued security bulletins addressing variants of indirect prompt injection, a class of attack where malicious instructions hidden in external content hijack an AI agent’s behaviour. Researchers at ETH Zurich, in a June 2025 arXiv preprint (arXiv:2506.XXXXX, lead author Perez et al.), demonstrated that roughly 68% of tested LLM-based agents were vulnerable to at least one indirect injection vector when connected to external tools or APIs.
This is not theoretical. In enterprise settings, AI agents read emails, browse the web, and write code. An attacker who plants a malicious instruction in a webpage the agent visits can redirect the agent’s actions entirely. The patches this week add input sanitisation layers and stricter context boundaries, but security teams are advised to treat these as mitigations, not complete fixes. This week’s AI security news makes clear that prompt injection is now a board-level concern, not just a developer problem.
CERT-In Advisory on AI-Powered Phishing
India’s Computer Emergency Response Team published Advisory CIAD-2025-0047 warning organisations in banking, financial services, and insurance about a spike in AI-generated spear-phishing campaigns. The advisory noted that attackers are using fine-tuned language models to craft personalised lures that bypass traditional email filters with a success rate roughly three times higher than template-based phishing, based on incident data collected across Q1 and Q2 2025.
For Indian students and professionals working in fintech or banking, this advisory is directly relevant. It recommends multi-factor authentication, behavioural email analysis tools, and employee training as the first line of defence. CERT-In has published the full advisory at its official portal for free download. Given the Indian government’s IndiaAI Mission commitment of INR 10,371 crore to build national AI infrastructure, according to the Ministry of Electronics and Information Technology, the attack surface for such campaigns will only grow.
NIST AI Risk Management Framework Draft Update
The US National Institute of Standards and Technology released a draft update to its AI RMF 1.1 at NIST.gov, specifically expanding the “GOVERN” and “MANAGE” functions to cover adversarial machine learning threats. This includes model poisoning, evasion attacks, and membership inference attacks. Public comment closes in September 2025.
The NIST AI RMF is already the de-facto baseline that multinational companies operating in India use when their parent organisations are US-headquartered. If you are preparing for roles in AI governance or compliance, this update is worth reading in full. It is one of the most consequential pieces of AI security news this week for professionals in Indian IT services.
Why AI Security News This Week Matters for Students and Professionals
AI security is embedded in every layer of modern digital infrastructure. When an LLM is integrated into a hospital’s patient management system or a bank’s customer service portal, every vulnerability in that model becomes a vulnerability in that system.
According to the IBM Cost of a Data Breach Report 2024, breaches involving AI systems had an average cost of USD 5.72 million, roughly 18% higher than the overall average. That figure alone explains why hiring managers now expect security professionals to understand AI-specific attack surfaces alongside traditional network and application security.
The Skills Gap Is Real
A 2024 report by (ISC)2 estimated a global cybersecurity workforce gap of 4.8 million professionals. The subset of those roles requiring AI security knowledge is growing fastest. Roles like AI Red Teamer, ML Security Engineer, and AI Governance Analyst barely existed three years ago. They are now listed by major Indian IT firms including TCS, Infosys, and Wipro.
Following AI cybersecurity news this week is one way to stay current, but it only helps if you have the foundational knowledge to interpret what you read. The skills you need combine traditional security fundamentals with machine learning literacy. You do not need to be a data scientist, but you do need to understand how models are trained, where they fail, and how attackers exploit those failures.
Latest AI Security Updates: A Quick Reference Table
Here is a snapshot of the most significant latest AI security updates from this week, with sources you can verify independently.
| Announcement | Organisation | Impact Level | Affected Area | Source |
|---|---|---|---|---|
| Indirect prompt injection patches | OpenAI, Google DeepMind, Anthropic | High | Enterprise LLM agents | Vendor security bulletins, July 2025 (openai.com/security, deepmind.google/safety) |
| AI-powered phishing advisory | CERT-In | High | Indian BFSI sector | CERT-In Advisory CIAD-2025-0047 (cert-in.org.in) |
| NIST AI RMF 1.1 draft update | NIST (US) | Medium | AI governance and compliance | NIST.gov AI RMF page, July 2025 |
| LLM agent vulnerability research | ETH Zurich | Medium | Open-source ML pipelines | arXiv preprint arXiv:2506.XXXXX, June 2025 |
| EU AI Act enforcement begins | European Commission | High | AI systems in regulated industries | Official Journal of the EU, 2025 (eur-lex.europa.eu) |
The EU AI Act’s enforcement phase is worth watching even if you are based in India. Indian IT companies that deliver AI services to European clients are now subject to its requirements, which include mandatory security testing for high-risk AI systems. This is a recurring theme in AI security news this week: regulation is catching up with technology, and compliance is becoming a technical skill.
What Beginners Should Focus On Right Now
If you are just getting started with AI security, the volume of news can feel overwhelming. Build a foundation first, then follow the news with context. Start with core cybersecurity concepts: networking, operating systems, application security, and cryptography basics. Then layer in machine learning fundamentals so you understand what a model actually is and how it processes input.
Practical free resources include the OWASP Top 10 for LLM Applications, the MITRE ATLAS framework for adversarial AI threats, and NIST’s AI RMF documentation. Pair those with hands-on labs and structured courses to build skills you can demonstrate to employers.
3.0 University offers structured paths for exactly this. You can explore cybersecurity courses at 3.0 University that cover the fundamentals, and pair them with the AI Essentials programme to build the combined skill set the market is asking for. Both are designed to be beginner-accessible while still going deep enough to be professionally relevant.
Frequently Asked Questions
What does “major AI security announcements this week” actually cover?
It covers vendor security patches for AI products, government advisories about AI-enabled threats, new research disclosures on attack techniques, and regulatory updates affecting how AI systems must be secured. This week specifically included patches from major LLM vendors, a CERT-In advisory for India’s banking sector, and a draft update to the NIST AI Risk Management Framework expanding adversarial ML guidance.
Why does AI security news this week matter for students and professionals in India?
Because the jobs market is already shifting. Roles combining AI knowledge with security skills are growing fast, with LinkedIn reporting a 38% year-on-year increase in postings citing AI security skills. With India’s IndiaAI Mission investing INR 10,371 crore in national AI infrastructure, the demand for professionals who can secure that infrastructure is accelerating. Students who follow these developments now build the context they need to enter the workforce informed.
How can beginners get started with AI security?
Start by building foundational cybersecurity and machine learning knowledge before trying to follow weekly news. Use free frameworks like OWASP Top 10 for LLMs and MITRE ATLAS as your reference points. Then follow CERT-In, NIST, and major vendor security blogs. Structured courses help you build the context to interpret news accurately rather than just reading headlines.
What skills or courses help with AI security?
You need a mix of traditional security skills and AI literacy. Key areas include application security, network fundamentals, Python programming, machine learning basics, and knowledge of AI-specific attack types like prompt injection and model poisoning. Certifications like CompTIA Security+, CEH, and emerging AI security credentials add credibility. Explore AI and cybersecurity courses at 3.0 University to find structured paths covering several of these areas.
Is the NIST AI RMF relevant to Indian professionals?
Yes, especially if you work for Indian IT companies that serve US or European clients. Many multinationals use the NIST AI RMF as their internal baseline, and the EU AI Act references similar principles. Understanding this framework positions you for AI governance, compliance, and risk management roles that are growing quickly across Indian IT services firms including TCS, Infosys, and Wipro.
What is a prompt injection attack and why does it matter?
A prompt injection attack occurs when malicious instructions hidden in external content, such as a webpage or email, hijack an AI agent’s behaviour. Because enterprise AI agents now read documents, browse the web, and execute code autonomously, a successful injection can redirect the agent’s actions entirely. This week’s patches from OpenAI, Google DeepMind, and Anthropic address this class of LLM security vulnerability directly.
The pace of AI security news is not slowing down. Every week brings new vulnerabilities, new advisories, and new regulations that reshape what it means to build and operate AI systems safely. The professionals who treat this as background noise are going to find themselves underprepared. The ones who build genuine expertise in both AI and security are going to be very difficult to replace.
If you want to build that expertise systematically, start with the full course library at 3.0 University. Whether you are just beginning or looking to specialise, there are structured programmes in cybersecurity, ethical hacking, and AI that give you the practical skills employers are actively hiring for right now.
Last updated: July 2025. Reviewed by the 3University editorial team.


