Key Highlights
- Prompt injection is becoming an execution risk. Instructions hidden in external content can attempt to activate an AI agent’s tools, APIs and permissions.
- PromptGuardX moves detection into the file layer. Integrated into Check Point Threat Emulation, it analyzes PDF files before their content reaches an LLM or AI agent.
- PromptGuardX extends Check Point’s AI Defense Plane into the file layer. It adds an upstream layer of protection alongside prompt inspection, runtime monitoring, access controls and action-level enforcement.
When Content Becomes a Command
AI agents increasingly read invoices, contracts, emails and enterprise data, then use tools and APIs to complete tasks. That changes the security model: the documents they consume are no longer passive references, but inputs that can influence what the agent decides to do next.
This creates an opportunity for indirect prompt injection: an attacker embeds instructions inside a PDF, email, website or tool result and waits for an AI system to process it.
A user may ask an agent to summarize an invoice, while hidden text inside the document instructs it to retrieve information, invoke a tool or send data elsewhere.
As part of Check Point’s broader AI Defense Plane, PromptGuardX extends protection into the file layer by detecting these instructions before they enter the AI workflow. Integrated into Check Point Threat Emulation, it analyzes PDFs before their content reaches an LLM, copilot or AI agent.
The PDF the User Sees Is Not Necessarily What the AI Reads
This is where traditional file security and AI security begin to overlap: the file may be clean from a malware perspective, yet unsafe for an AI system that treats its contents as instructions.
A user sees a rendered PDF, but an AI application may process text extracted from the file’s underlying structure. Attackers can exploit this gap with invisible text, concealed layers or Unicode manipulation. The result is a file that contains no malware, but still carries an instruction intended for an AI agent.
Check Point’s AI Security Report 2026 found that detections of longer malicious prompt payloads increased approximately fivefold between March and May 2026, approaching 1% of observed prompts in May. The trend reflects the growing risk of content-borne attacks reaching AI systems through the information they process.
Stopping Prompt Injection Before AI Ingestion
Many AI security controls inspect prompts and responses, monitor agents at runtime or validate actions before execution. These remain essential, but by then document content may already have been extracted, chunked, stored or merged with other sources.
PromptGuardX adds an earlier enforcement point, examining suspicious instructions while they are still inside the documents and before they become part of the model’s context.
Rather than waiting for a PDF to become an AI input, PromptGuardX extends Threat Emulation to inspect the file before AI ingestion. This adds an upstream enforcement point within Check Point’s AI Defense Plane, complementing the controls that inspect prompts, monitor agents and validate actions later in the workflow.
How PromptGuardX Works
PromptGuardX analyzes the PDF in four stages.
1. Extract and Normalize
The engine extracts the text a downstream AI system may receive, including content hidden through formatting, positioning or document structure. It then normalizes Unicode to reduce common obfuscation techniques such as zero-width characters, homoglyphs, mixed scripts and bidirectional controls.
2. Locate Suspicious Instructions
A pre-filter identifies regions that require deeper analysis, such as delimiter spoofing, impersonation of system or developer instructions, role reassignment, directions to ignore previous instructions or requests to conceal an action.
3. Analyze Context and Intent
Prompt injection often spans multiple lines, combining a fake delimiter, a claim of authority, an execution condition, a requested action and an instruction not to disclose it.
PromptGuardX divides the text into overlapping windows so these relationships remain visible, then evaluates each window with a dedicated fine-tuned classifier.
The classifier distinguishes between text that discusses an instruction and text that attempts to issue one, analyzing semantics, context and intent rather than keywords alone.
4. Generate an Explainable Verdict
For suspicious content, PromptGuardX produces a confidence score and identifies the specific text windows that triggered the verdict, enabling the Threat Emulation report to show both classification and textual evidence.
The verdict becomes part of the Check Point Threat Emulation file-inspection process, alongside analysis for malware, malicious URLs and suspicious behavior.
PromptGuardX brings AI-targeted intent detection into the existing file-inspection process, adding a new question:
Is this file safe for the AI system that is about to process it?
From a Calculator to an Agentic Workflow
In the PromptGuardX demonstration, a standard-looking invoice contains a hidden instruction. When an AI system is asked to summarize the document, the instruction attempts to make it launch calc.exe.
The calculator is a safe stand-in for command execution. The invoice contains no executable and exploits no PDF vulnerability; the action depends on an AI system reading the instruction, following it and having access to the right tool.
In an enterprise workflow, a similar instruction could attempt to retrieve supplier records, send information externally, change payment details or invoke a tool unrelated to the user’s request.
Whether the attempt succeeds depends on the agent’s permissions and downstream controls. PromptGuardX addresses the attack earlier: before the agent encounters the instruction at all.
File Security Is Now Part of AI Security
No single control eliminates prompt injection. AI systems still require prompt inspection, runtime monitoring, least-privilege access and action-level enforcement. Within Check Point’s AI Defense Plane, PromptGuardX adds another layer of protection at the point where a content-borne attack can begin: inside the file.
As AI agents consume more enterprise documents and receive greater permission to act, determining whether a file is safe can no longer mean checking only for malware. It must also mean identifying instructions intended to manipulate the AI system that reads it.
PromptGuardX is integrated into the Check Point Threat Emulation pipeline, enabling supported deployments across Quantum, Harmony Email & Collaboration and Threat Emulation-enabled gateways to inspect PDFs for prompt-injection attempts before their content reaches an AI system.
As agents increasingly act on enterprise content, the content they consume becomes part of the AI security boundary. Securing that boundary means evaluating not only what agents are asked to do, but also the files and information that shape their decisions.



.png)





