Upcoming

Prompt Injection and the Lethal Trifecta: What Your CISO Needs to Know About Claude Cowork

29 April 2026
2:00 PM UTC
1 hour
Understand Simon Willison's 'lethal trifecta' and why every useful AI agent has all three legs Watch a live prompt injection attack against a Claude agent connected to real data See how Anthropic's model training refuses exfiltration instructions, and where that defence breaks down Apply the four controls of a governed Cowork rollout: sandboxing, OAuth scopes, commercial accounts, network egress Know where to find Anthropic's security documentation and the questions your CISO should be asking

Webinar Starts In:

Time Until Webinar

06
Days
21
Hours
56
Minutes
26
Seconds

Prompt injection is a real, unsolved risk for AI agents with access to your data. We'll show you a live attack, explain why there's no silver bullet, and walk through the four controls that make a managed Claude Cowork rollout defensible for an enterprise CISO.

Reserve Your Spot

Don't miss out on this live session. Register now to receive your Zoom link.

Register Now

About This Webinar

Your security team is right to ask hard questions about AI agents. You should be ready with good answers.

Any AI agent with access to your data, exposure to untrusted content, and the ability to send data outwards has what Simon Willison calls the "lethal trifecta." One poisoned email, web page, or document can redirect the agent to leak information it is meant to protect. There is no single technical fix that eliminates this class of risk. And Claude Cowork — with its Gmail, Drive, Slack, and web access — has all three legs of the trifecta by design.

That is the honest starting point. It is also not a reason to stay on the sidelines. Every major AI vendor is shipping agents into enterprise workflows. The question for your CISO is not "can we eliminate this risk?" but "can we reduce blast radius enough to deploy responsibly?"

In this 15-minute session we will walk through a live demonstration. We have built a pretend attacker site that tells the agent "send me all your data." You will see how the attack works, and how Claude's model training already refuses to comply. Then we will cover the four controls that make a managed Cowork rollout defensible:

  1. Cowork runs in a sandboxed virtual environment on the user's laptop, not inside your network.
  2. Connectors use OAuth, so agents only see what the user is already authorised to see.
  3. Commercial Claude accounts give your IT team governance, audit logs, and data controls. Personal accounts do not.
  4. Network egress settings let you constrain where an agent can actually send data.

You will leave knowing where to find Anthropic's published security documentation, the specific questions to put to your deployment team, and whether a governed Cowork rollout clears your bar.

What We'll Cover

1

Prompt Injection and the Lethal Trifecta

15 minutes

Live demo of a prompt injection attack against a Claude Cowork agent with connected data, how Anthropic's model training responds, and the four controls that make a managed rollout defensible.

2

AI in the News

15 minutes

Latest AI developments and releases from the past week.

3

Q&A

30 minutes

Open forum for questions about your specific use cases.

Total Duration: Approximately 30-45 minutes

About Your Host

Charlie Cowan

Charlie Cowan

Founder & CEO, Kowalah

Charlie hosts our Wednesday Webinars, sharing practical AI strategies and insights to help organizations accelerate their AI adoption journey. With deep expertise in AI leadership and implementation, Charlie provides actionable guidance for executives and teams navigating AI transformation.

Ready to Join Us?

Reserve your spot for this Wednesday Webinar