Close Menu
NCIJ Network NCIJ Network
    What's Hot

    CloudNC raises $20M to automate manufacturing’s most pressing bottlenecks

    September 9, 2026

    The Hidden Instructions That Can Hijack AI Agents

    September 9, 2026

    Bitcoin Holds, Wall Street Stalls as Oil Shock Revives Fed Hike Bets

    September 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • CloudNC raises $20M to automate manufacturing’s most pressing bottlenecks
    • The Hidden Instructions That Can Hijack AI Agents
    • Bitcoin Holds, Wall Street Stalls as Oil Shock Revives Fed Hike Bets
    • In Peru, mercury leaves a toxic footprint on those who depend on a river
    • US bans Canadian alcohol, motorcycles and dairy products as trade spat escalates
    • Geheimdienst-Dilemma: Der Staat und das AfD-Risiko – POLITICO
    • Meta bets on AI agent Muse to catch up in AI race
    • FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    The Hidden Instructions That Can Hijack AI Agents

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 9, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    They cannot be seen, can be tailored to different purposes and once adopted they operate at lightning speed. 

    Hidden AI prompt injections are synonymous with indirect prompts but with the specific quality of being hidden from human overview. Unlike traditional prompt injection attacks, where a user directly attempts to manipulate an AI chatbot, indirect prompt injection targets the information AI agents ingest. Bowbridge fears they are a growing risk to autonomous agents.

    “As businesses are rapidly adopting AI agents, these systems are increasingly being given access to sensitive information, internal documents and operational tools. While this creates significant opportunities for efficiency, it also introduces a new cybersecurity threat that traditional security controls may not detect.” They do not, for example, have a fingerprint similar to malware that can be detected on disk by any traditional AV product.

    A hidden prompt injection is embedded in an external document that an autonomous agent might consume during its operation. In this sense, they are similar to watering hole attacks that compromise a trusted third-party environment but are here targeting AI agents rather than human visitors.

    Malicious instructions can be hidden inside everyday content, causing AI agents to treat attacker-controlled content as trusted guidance, warns Bowbridge. Example hiding places for these prompts include documents and file metadata, emails and online content, images and embedded content, and code repositories and developer workflows.

    A malicious injection can cause an agentic system to act beyond its intended use and outside its guardrails.

    Advertisement. Scroll to continue reading.

    They are dangerous because modern autonomous agentic systems generally inherit the privileges of their user, act silently at machine speed, and have no human-like judgment or reasoning – just simple reaction to the instruction. 

    Consider a common agent – the executive assistant. To function effectively, an executive assistant must be granted access to the same files and databases with which the executive normally interacts: email, calendars, staff, external meetings and more. If that agent succumbs to a malicious injection prompt, a bad actor could further poison or delete the files or exfiltrate sensitive data to an attacker controlled C2.

    “Agentic AI has enormous potential to transform enterprise operations, but organizations need to recognize that these systems are processing information from sources they cannot always trust. A document that appears harmless to a user may contain hidden instructions designed to influence an AI agent’s behavior,” comments Jörg Schneider-Simon, CTO and co-founder at Bowbridge. 

    The firm gives a real world example, where an AI agent was asked to review supplier quotes and identify the cheapest option. “A malicious quote contained a hidden instruction within the document metadata, instructing the AI agent to override previous guidance and select that supplier. Despite being the most expensive quote, the AI agent recommended it because it could not distinguish between trusted system instructions and untrusted document content,” explains the firm.

    Since there is little, if any, time or opportunity to prevent a poisoned autonomous AI agent taking action, defense should focus on preventing the poisoning rather than preventing the action. (Having said that, there are several new products designed to get between agents and assets to block any harmful action. Nevertheless, the old saying that prevention is better than cure should not be ignored – and potentially has a 100% success rate.)

    Bowbridge recommends scanning documents before they are processed by agents, using technology to detect any hidden content within files, metadata and document structures, and applying AI security frameworks that may be available.

    “The rise of agentic AI represents a significant shift in how organizations approach cybersecurity. As AI systems become more embedded within enterprise workflows, protecting the content they consume will become a critical part of securing business applications,” warns the firm.

    Related: Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents

    Related: AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million

    Related: OpenLeash Adds a Human Check to Risky AI Agent Actions

    Related: What the Hugging Face Incident Teaches Security Leaders About AI Agent Access

    Agents hidden hijack instructions
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

    What It Took to Reach 1 Billion Build Manifests

    CISA tells operators to harden Siemens S7 PLCs. Here’s how to do it without disrupting production

    WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

    Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

    Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    CloudNC raises $20M to automate manufacturing’s most pressing bottlenecks

    September 9, 2026

    The Hidden Instructions That Can Hijack AI Agents

    September 9, 2026

    Bitcoin Holds, Wall Street Stalls as Oil Shock Revives Fed Hike Bets

    September 9, 2026

    In Peru, mercury leaves a toxic footprint on those who depend on a river

    September 9, 2026
    Latest Posts

    Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

    August 1, 2026

    AI in Formula One: Competitive advantage is all about the human in the loop

    August 1, 2026

    Pedro Sánchez hits out at EU leaders over criticism of Spain’s migrant crisis

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    CloudNC raises $20M to automate manufacturing’s most pressing bottlenecks

    September 9, 2026

    The Hidden Instructions That Can Hijack AI Agents

    September 9, 2026

    Bitcoin Holds, Wall Street Stalls as Oil Shock Revives Fed Hike Bets

    September 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.