The AI Sales Pitch Always Skips the Part Where It Gets Attacked

You have probably heard the promise by now. AI agents are almost ready to run your marketing, your ads, your customer service, maybe your whole funnel, while you sip coffee and watch the numbers climb. It is a comforting story. It is also only half of a story, and the other half is usually written down somewhere you were never meant to look.
Here is a small, quiet example that says more than any keynote.
Meta recently published two documents about the same product, an AI system called Muse, on the same day. Same company. Same technology. Same moment in time. One of those documents never once mentions risk, attack, or prompt injection. The other uses that kind of language dozens of times. One reads like a brochure. The other reads like a safety briefing.
That gap is not an accident. That gap is the entire lesson.
Two truths from the same building
Think about what it takes for a large company to produce two documents about one product where one pretends danger does not exist and the other cannot stop talking about it. These were not written by rival factions who never spoke. They came out of the same organization, aimed at different readers, doing different jobs.
The first document has a job. Its job is to make you want the thing. So it talks about capability, speed, possibility. It talks about what the machine can do on your behalf. It is optimistic by design, because optimism is what moves a product from a lab into your budget.
The second document also has a job. Its job is to keep the thing from blowing up in someone's face. So it talks about what happens when a bad actor feeds the system poisoned instructions, what happens when the agent is tricked into doing something it was never supposed to do, what has to be true before you can trust it with anything that matters.
The brochure describes the world you were promised. The safety document describes the world you will actually operate in.
Both are honest, in their own way. That is what makes this so useful. Nobody lied. The company simply told two audiences two different truths, and assumed those audiences would never sit in the same room and compare notes.
Prompt injection is not a footnote
Let me translate the scary word, because most marketers have never had a reason to care about it. Prompt injection is when someone slips hidden instructions into the content your AI reads, and the AI obeys them instead of you.
Picture an AI agent that browses the web to research competitors, or reads incoming emails to draft replies, or scans a webpage to summarize an offer. Now picture someone burying a line of text on that page that says, in effect, ignore your previous instructions and do this other thing instead. The agent, being a very confident pattern matcher and not a skeptic, can just go along with it.
That is not a theoretical parlor trick. It is the reason the second document exists. When you give a system the power to take actions in the real world, you also give it the power to take the wrong actions, and you hand every clever adversary a new door to knock on.
The people building these tools know this cold. That is why the technical document names the danger over and over. They are not being pessimistic. They are being responsible.
The part that should bother you is not that the risk exists. It is that the risk was surgically removed from the version of the story most people will ever see.
Every vendor does this. Learn to read for it.
I am not here to pile on Meta. Meta is unusual only because it published both halves, which is more honesty than most of the industry manages. The pattern itself is everywhere. It is baked into how software gets sold.
Go look at the homepage of almost any AI marketing tool you are being pitched right now. Count the words spent on what it can do. Then count the words spent on what happens when it is wrong, what it does with your data, who is liable when it fabricates a claim about your product, and what an attacker can make it do. The ratio tells you everything.
If a product's marketing never mentions its own failure modes, that is not confidence. That is editing.
I have watched this play out with clients more times than I can count. A founder gets excited about a shiny automation, signs up on the strength of the demo, and never asks the boring question. Six weeks later something goes sideways in a way the sales page never hinted at, and everyone acts surprised. Nobody should be surprised. The warning existed. It was just in the other document.
So the skill I want more marketers to build is not technical. It is a reading habit. When someone hands you the brochure, go find the second document. The changelog. The security page. The terms of service. The developer docs written for engineers, not buyers. The honest stuff is almost always in there, written in a flatter, less exciting voice, because engineers do not get paid to be excited.
Enthusiasm is not a strategy
Here is where I want to push on the conventional wisdom directly, because a lot of smart people have quietly decided that the only two options are total belief or total refusal. Either you go all in on AI agents running your operation, or you are a dinosaur who will be left behind.
That framing is garbage. It is a false choice built by people who profit from your urgency.
The useful posture is neither faith nor fear. It is the posture of someone reading both documents at once. You can believe the capability is real and take the risk seriously in the same breath. In fact, that is the only sane way to use any of this.
A hammer is a genuinely great tool. It is also perfectly capable of breaking your thumb. Nobody writes think pieces about whether we should be for or against hammers. We just learned where to put our hand. AI agents deserve the same unglamorous respect. Powerful, useful, and entirely willing to hurt you if you hold them wrong.
So the question is never should I use this. The question is what am I handing it, and what happens on the worst day.
The questions the brochure hopes you skip
When a tool wants to act on your behalf, not just answer a question but actually do things, a short list of questions separates the people who get burned from the people who do not. This is the one place a list earns its keep.
- What can this thing do without asking me first, and can I turn that off?
- What outside content does it read, and could that content contain instructions it might obey?
- Where does my data go, who can see it, and how long does it stay?
- When it gets something wrong in public, who is responsible, me or the vendor?
- Is there a version of this failing that ends up on the news with my brand attached?
None of those questions are hostile. A good vendor will have answers ready, and will not flinch when you ask. The ones who flinch are telling you something.
Notice that not one of those questions is about capability. The demo already answered capability. The demo is designed to answer capability and nothing else. Your job in the room is to ask the questions the demo was built to distract you from.
Why this matters more as the tools get better
You might be thinking this is a lot of caution over an early technology that will get safer with time. And yes, the tools will improve. But the exposure grows faster than the safety does, and here is why.
The whole direction of travel is toward giving these systems more autonomy, more access, and more real actions. Not just draft this email, but send it. Not just suggest a bid, but place it. Not just find the customer, but reply to them. Every step in that direction raises the stakes of a single manipulated instruction. The blast radius gets wider exactly as the tool gets more useful.
That is the trade nobody puts on the sales page. More power is more usefulness and more risk in the same motion. You do not get to accept one and decline the other.
The more a tool can do without you, the more it can do to you.
Which is why the second document, the one full of the word attack, is not the pessimistic version of the product. It is the mature version. It is what the product looks like to the people who have to live with it after the launch confetti is swept up.
Read the boring one
I keep coming back to that image of two files, published on the same day, describing the same machine, agreeing on almost nothing about danger. It is such a clean picture of how this entire industry talks to us right now.
One voice sells you the future. One voice tells you the truth about the present. And the gap between them is not a scandal. It is just the standard operating procedure of selling powerful things to busy people who would rather not read the manual.
So read the manual. Read the changelog. Read the page written in the flat voice for the engineers. When a company is generous enough to publish both stories, do not settle for the one with the nicer adjectives.
The excitement is real. The risk is also real. Anyone who only shows you one of those is not showing you the product. They are showing you the pitch.
When a vendor hands you the brochure, thank them, and then go find the document they hoped you would skip. That is where the actual product lives.