People

Kyle Polley

Kyle Polley is a security executive in the New York technology industry who serves as Chief Information Security Officer at Perplexity, the artificial-intelligence search and browser company [1][2]. Before assuming that title he was described as head of security operations at Perplexity, having previously worked in detection-and-response roles at Robinhood and built the security program at the fintech company Pipe [4]. At Perplexity he has overseen security for the company's three products: the Perplexity answer engine, the agentic web browser Comet, and Perplexity Computer, a tool with file-system and code-execution access, and he has said his team has had to confront the AI-security problems that come with being an early releaser of such agentic tools [3].

A central focus of Polley's public work has been prompt injection, in which untrusted content ingested by a browser agent such as Comet can contain hidden instructions that the underlying language model cannot reliably distinguish from legitimate system or user input [3]. He has catalogued several attack patterns his team observed in the wild, including impersonation of an application's own prompt template, social-engineering language embedded in web pages that mimics phishing tactics aimed at the agent rather than a human, and conditional triggers hidden in content such as calendar events that activate only when the agent performs a specific task [3]. He has also argued that existing open-source prompt-injection benchmarks and classifiers, such as PromptGuard, are unrealistic because they miss attack types seen in production, are fooled by benign "distractor" text like cookie-consent banners, and rely on surface keywords rather than an assessment of intent, with detection accuracy dropping sharply once distractors or non-English language are introduced [3].

In response to these gaps, Polley's team built and open-sourced BrowseSafeBench, an evaluation dataset drawn from and modeled on real-world attacks and classified into a specific taxonomy, along with BrowseSafe, a classifier fine-tuned on that data using a 30-billion-parameter Qwen-based model [3]. He has reported that this classifier reaches roughly a 90.4% F1 score for detecting prompt injection while returning results in subsecond latency, which he contrasts with prompted general-purpose models like GPT-5 and GPT-5 mini that achieve comparable or better accuracy but take two to twenty seconds, a delay he says makes them impractical to deploy in production without user frustration [3]. He has noted that BrowseSafe also departs from binary classifiers by outputting a confidence probability rather than a simple yes-or-no determination [3].

Beyond prompt injection research, Polley has spoken publicly about how organizations should sequence security investment, arguing that detection-and-response capability should precede compliance work because attackers will not wait for a company to obtain certifications such as ISO or SOC 2, and because during an actual breach stakeholders will want to know what happened rather than what certifications were held [4]. He contends that building a genuinely strong security program tends to satisfy compliance requirements as a byproduct, and that treating compliance as the primary driver can lead teams down unproductive paths [4]. On integrating artificial intelligence into security operations, he has said he does not expect AI to replace security staff outright but expects it to absorb repetitive, slow tasks, freeing humans for judgment-driven incident response, and he has released open-source work intended to let security operations teams experiment with AI integration at varying levels of maturity [4].

Insights & ideas

Kyle Polley's core focus is prompt injection as the central security challenge facing AI agents with browser and system access, a problem he explains arises when untrusted website content is ingested into an agent's context and the underlying model cannot reliably distinguish tool output from user input or system prompts [1]. He describes concrete attack patterns his team has observed, including prompt template impersonation, agent-directed social engineering, and conditional triggers hidden in web content or calendar events [1]. He also argues that existing open-source benchmarks and classifiers, including PromptGuard, are unrealistic because models tend to detect injections by keyword matching rather than intent, failing against multilingual attacks or "distractor" content like cookie consent banners that mimic injection language [1].

On security operations more broadly, Polley argues organizations should prioritize detection and response capabilities before compliance, since attackers will not wait for certification and a breach without proper logging leaves a company unable to determine what happened [2]. He holds that a strong security program naturally produces compliance as a byproduct, whereas compliance-driven approaches can lead teams astray [2]. He also sees AI as useful for automating repetitive security operations tasks without replacing human involvement in incident response [2].

Experience

  1. Chief Information Security Officer
    PerplexityJul 2026 to Present
  2. Member of Technical Staff, Security
    PerplexityDec 2024 to Jul 2026
  3. Head of Security, EM of Internal Systems
    PipeJan 2023 to Dec 2024
  4. Lead Security Engineer
    PipeJul 2022 to Dec 2024
  5. Security Engineer
    RobinhoodMar 2020 to Jul 2022
  6. Security Engineer - Data Science & ML
    PatternExJun 2018 to Mar 2020
  7. IT Security and Operations Researcher
    NASA Ames Research CenterJun 2016 to Sep 2017
  8. Code I Support, Intern
    NASA Ames Research CenterAug 2013 to Aug 2015

Education

Media & appearances

This page shows public professional information only, each fact cited. Is this you? Corrections or removal within 24 hours, no questions asked.