Multi-turn attacks against artificial intelligence models have demonstrated an alarming success rate of 88.3%, according to a recent Cisco study that evaluated 6,986 adversarial conversations across 15 proprietary models. This data, presented at an agentic security panel during VB Transform 2026, reveals that traditional single-turn testing — where a malicious prompt is launched and the response is evaluated — is insufficient to protect production systems. The research compared 30,090 single-turn attacks with 6,986 multi-turn attacks; while the former failed to capture evasive behaviors, the latter exposed vulnerabilities that no simple test detects.
The problem lies in the fact that real interaction with AI agents is conversational. A user or an attacker does not limit themselves to a single prompt; they negotiate, reformulate, insist. Models, by maintaining a long context, can be gradually manipulated to obtain prohibited responses, access sensitive data, or execute unauthorized actions. Cisco, together with Nicholas Conley, demonstrated that security rankings among models change completely when moving from one turn to several: models that seemed secure in a single prompt proved fragile in extended dialogues. This forces a redefinition of how companies approach cybersecurity in their AI-based systems.
For organizations that are deploying intelligent agents — whether in customer service, process automation, or business analytics — the conclusion is clear: simple testing is a false guarantee. According to a VentureBeat survey from June 2026, 54% of companies have already suffered a confirmed security incident related to agents (18%) or a near-miss (36%). Only 32% assign managed and scoped identities to each agent, and barely 30% isolate high-risk agents in sandbox environments. 82% of companies still rely on native cloud vendor controls as the primary security layer, an approach that has proven insufficient against multi-turn attacks.
In response, the industry is reacting with multi-billion dollar acquisitions: Palo Alto Networks closed the purchase of CyberArk for $25 billion, CrowdStrike acquired SGNL for $740 million, and Cisco bought Astrix Security for $400 million, all aimed at reinforcing the identity and isolation layer that most companies have not yet built. The answer is not complex, according to Amy Chang, head of AI threat intelligence and security at Cisco: 'It's still simple: go back to the fundamentals, think about what we are really protecting in our organization.' Her recommendation is to work backwards from real incidents, using frameworks like Cisco's Integrated AI Security and Safety Framework, to identify where defenses failed.
In this context, Q2BSTUDIO, as a software and technology development company, offers solutions that precisely address these challenges. With services in custom software development, Q2BSTUDIO can integrate multi-turn security mechanisms from the design phase, ensuring that the AI agents it builds for its clients are evaluated under realistic attack conditions. Additionally, its expertise in artificial intelligence allows designing systems that not only respond to prompts but incorporate deterministic controls and continuous monitoring to detect deviations in real time.
A practical approach is described by Heather Ceylan, CISO at Box. Her company implements three concentric security layers: restricted permissions (the agent only accesses data that the human user could see), ephemeral environments (each task executes in a temporary sandbox), and execution control (tool calls are limited to those strictly necessary). For destructive actions, human approval is always required. This architecture, combined with continuous multi-turn testing, drastically reduces the attack surface.
At Q2BSTUDIO we understand that security cannot be an afterthought. Therefore, when developing process automation based on agents, we apply principles of least privilege and isolation. Furthermore, our offering in cloud AWS/Azure allows deploying these agents with ephemeral identities and adaptive access policies, while BI / Power BI capabilities help monitor agent behavior through real-time dashboards. The combination of artificial intelligence and business intelligence enables detecting anomalous patterns in conversations that could indicate an ongoing multi-turn attack.
Team training is also crucial. Rajesh Parekh, VP of AI at Intuit, emphasizes that agents have 'skills' that can become vulnerabilities. Therefore, Intuit has created GenOS, an AI operating system that centralizes security, risk, and fraud modeling, preventing each developer from reinventing protections. Q2BSTUDIO offers a similar approach through its consulting and development services, helping companies build internal platforms that abstract agent security and enable automated multi-turn testing.
The key lies in continuity. Ceylan warns that, in her experience, a single agent error can destroy all trust accumulated over months. 'They had to start over,' she recounts. Therefore, constant monitoring, mid-session permission changes, and periodic model reassessment are essential. Models change, adversaries adapt, and single-turn tests do not reflect that dynamic reality.
For companies still relying on vendor-native controls, the panel's message is direct: test the way attackers attack, across full conversations and continuously, or discover in production what simple testing missed. At Q2BSTUDIO we offer precisely that: advanced cybersecurity development, including AI agent pentesting with multi-turn methodologies, to ensure your applications are not vulnerable to the 88% of attacks that simple testing doesn't detect.





