# The coming AI security crisis (and what to do about it) | Sander Schulhoff Page: https://stenobird.com/podcast/lenny-s-podcast/the-coming-ai-security-crisis-and-what-to-do-about-it-sander-schulhoff Text version: https://stenobird.com/podcast/lenny-s-podcast/the-coming-ai-security-crisis-and-what-to-do-about-it-sander-schulhoff.md Podcast: [Lenny's Podcast: Product | Career | Growth](https://stenobird.com/podcast/lenny-s-podcast) Published: 2025-12-21T13:31:22+00:00 Episode link: https://www.lennysnewsletter.com/p/the-coming-ai-security-crisis Audio file: https://pscrb.fm/rss/p/api.substack.com/feed/podcast/181089452/094510ab33d59878b78644266ad3c67b.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/lenny-s-podcast/episodes/the-coming-ai-security-crisis-and-what-to-do-about-it-sander-schulhoff Duration seconds: 5561 ## Resource Sander Schulhoff is an AI researcher specializing in AI security, prompt injection, and red teaming. He wrote the first comprehensive guide on prompt engineering and ran the first-ever prompt injection competition, working with top AI labs and companies. His dataset is now used by Fortune 500 companies to benchmark their AI systems security, he’s spent more time than anyone alive studying how attackers break AI systems, and what he’s found isn’t reassuring: the guardrails companies are buying don’t actually work, and we’ve been lucky we haven’t seen more harm so far, only because AI agents aren’t capable enough yet to do real damage. We discuss: 1. The difference between jailbreaking and prompt injection attacks on AI systems 2. Why AI guardrails don’t work 3. Why we haven’t seen major AI security incidents yet (but soon will) 4. Why AI browser agents are vulnerable to hidden attacks embedded in webpages 5. The practical steps organizations should take instead of buying ineffective security tools 6. Why solving this requires merging classical cybersecurity expertise with AI knowledge — Brought to you by: Datadog —Now home to Eppo, the leading experimentation and feature flagging platform: https://www.datadoghq.com/lenny Metronome —Monetization infrastructure for modern software companies: https://metronome.com/ GoFundMe Giving Funds —Make year-end giving easy: http://gofundme.com/lenny — Transcript: https://www.lennysnewsletter.com/p/the-coming-ai-security-crisis — My biggest takeaways (for paid newsletter subscribers): https://www.lennysnewsletter.com/i/181089452/my-biggest-takeaways-from-this-conversation — Where to find Sander Schulhoff: • X: https://x.com/sanderschulhoff • LinkedIn: https://www.linkedin.com/in/sander-schulhoff • Website: https://sanderschulhoff.com… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/lenny-s-podcast/episodes/the-coming-ai-security-crisis-and-what-to-do-about-it-sander-schulhoff/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/lenny-s-podcast/the-coming-ai-security-crisis-and-what-to-do-about-it-sander-schulhoff.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.