Skip to content
by InfinyAI ES

IA en un minutoNewsSecurity

Security

Check Point launches a feature to protect AI agents from booby-trapped documents

IA en un minuto newsroom · Editor: Jon Elgezabal

In 30 seconds

PromptGuardX, Check Point's new feature, scans every PDF for buried commands before an AI agent or copilot gets to read its contents. The tool exposes concealed layers, invisible text and character tricks, and flags the passage that set it off along with a confidence level. It sits inside Threat Emulation, and Check Point admits that more defenses are still required.

Check Point Software, the cybersecurity company, introduced PromptGuardX on Tuesday, October 6, a feature that checks PDF files for hidden instructions before their content reaches an AI model, a copilot or an agent.

The problem it targets is indirect prompt injection (prompts are the instructions an AI receives): someone hides commands inside a PDF, an email or a website and waits for an AI system to read it. A person sees a normal document, but the AI processes text extracted from the file's underlying structure, where there may be invisible text, concealed layers or manipulated Unicode characters. According to Check Point, the file may contain no malware at all and still carry an instruction meant for the agent.

In its demonstration, a normal-looking invoice contains a hidden instruction. When an AI system is asked to summarize the document, the instruction attempts to make it launch the computer's calculator, a safe stand-in for running a command. The invoice contains no executable and exploits no PDF vulnerability, so the action depends on an AI system reading the instruction, following it and having access to the right tool. In a company, Check Point explains, a similar instruction could attempt to retrieve supplier records, send information elsewhere, change payment details or invoke a tool unrelated to the user's request.

PromptGuardX analyzes each PDF in four stages. It extracts the text an AI system would receive, including hidden text, and normalizes characters to undo common disguise techniques. It locates suspicious regions, such as text that impersonates system instructions or asks the AI to ignore previous instructions. It analyzes the context with a fine-tuned classifier that tells apart text that discusses an instruction from text that attempts to issue one. And it produces a verdict with a confidence score and the specific text that triggered it.

It is integrated into Threat Emulation, the Check Point system that inspects files for malware, malicious URLs and suspicious behavior, and it is available in supported deployments across Quantum, Harmony Email & Collaboration and Threat Emulation-enabled gateways. The announcement gives no price. Check Point itself acknowledges that no single control eliminates this kind of attack and that other protections are still needed, such as prompt inspection, runtime monitoring, least-privilege access and action-level enforcement.

According to its AI Security Report 2026, detections of longer malicious prompt payloads increased approximately fivefold between March and May 2026, approaching 1% of observed prompts in May.

Why it matters · analysis and opinion

Until now, checking a file meant asking whether it carried malware. With agents that read invoices and other documents on their own, the question becomes whether the text is trying to give them orders, and a cybersecurity vendor building that into its file inspection shows the risk has already left the lab. That said, for now it analyzes PDFs and works inside Check Point's own products, so it does not replace the basics. Anyone who already lets an AI assistant read outside documents and then act can start today with three things: give it minimal permissions, require a person to confirm payments or data transfers, and keep document reading separate from the tools that carry out actions. The filter sits in front of the agent, but the damage depends on what the agent is allowed to do.

Official source: Check Point · Written with the help of AI: how we make the news

Is your website up to scratch? We will audit it for free

AI in your inbox, every day or every Friday

The stories that matter, each one in a minute. With the source for every one.

Choose one or both:

You will get an email to confirm your subscription: until you click its link, you will not receive anything. You can unsubscribe from any email.