[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6-bpPcY8ANOjP0eVFtJfujBsvMs_BsqweX-XQGjqytw":3},{"article":4,"iocs":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":31},"b062c8b5-eb8d-4600-9a82-673ddd2fd89f","The Hidden Instructions That Can Hijack AI Agents","the-hidden-instructions-that-can-hijack-ai-agents-d495c0","Malicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions. The post The Hidden Instructions That Can Hijack AI Agents appeared first on SecurityWeek.","Malicious instructions, known as hidden prompt injections, can be embedded within documents, metadata, images, and code to manipulate autonomous AI agents. These attacks bypass traditional security controls and can cause agents to perform unauthorized actions, such as exfiltrating data or making poor business decisions, as they lack human judgment to distinguish trusted from untrusted input.","Hidden prompts in documents can manipulate AI agents into dangerous actions.","They cannot be seen, can be tailored to different purposes and once adopted they operate at lightning speed. Hidden AI prompt injections are synonymous with indirect prompts but with the specific quality of being hidden from human overview. Unlike traditional prompt injection attacks, where a user directly attempts to manipulate an AI chatbot, indirect prompt injection targets the information AI agents ingest. Bowbridge fears they are a growing risk to autonomous agents. “As businesses are rapidly adopting AI agents, these systems are increasingly being given access to sensitive information, internal documents and operational tools. While this creates significant opportunities for efficiency, it also introduces a new cybersecurity threat that traditional security controls may not detect.” They do not, for example, have a fingerprint similar to malware that can be detected on disk by any traditional AV product. A hidden prompt injection is embedded in an external document that an autonomous agent might consume during its operation. In this sense, they are similar to watering hole attacks that compromise a trusted third-party environment but are here targeting AI agents rather than human visitors. Malicious instructions can be hidden inside everyday content, causing AI agents to treat attacker-controlled content as trusted guidance, warns Bowbridge. Example hiding places for these prompts include documents and file metadata, emails and online content, images and embedded content, and code repositories and developer workflows. A malicious injection can cause an agentic system to act beyond its intended use and outside its guardrails.Advertisement. Scroll to continue reading. They are dangerous because modern autonomous agentic systems generally inherit the privileges of their user, act silently at machine speed, and have no human-like judgment or reasoning – just simple reaction to the instruction. Consider a common agent – the executive assistant. To function effectively, an executive assistant must be granted access to the same files and databases with which the executive normally interacts: email, calendars, staff, external meetings and more. If that agent succumbs to a malicious injection prompt, a bad actor could further poison or delete the files or exfiltrate sensitive data to an attacker controlled C2. “Agentic AI has enormous potential to transform enterprise operations, but organizations need to recognize that these systems are processing information from sources they cannot always trust. A document that appears harmless to a user may contain hidden instructions designed to influence an AI agent’s behavior,” comments Jörg Schneider-Simon, CTO and co-founder at Bowbridge. The firm gives a real world example, where an AI agent was asked to review supplier quotes and identify the cheapest option. “A malicious quote contained a hidden instruction within the document metadata, instructing the AI agent to override previous guidance and select that supplier. Despite being the most expensive quote, the AI agent recommended it because it could not distinguish between trusted system instructions and untrusted document content,” explains the firm. Since there is little, if any, time or opportunity to prevent a poisoned autonomous AI agent taking action, defense should focus on preventing the poisoning rather than preventing the action. (Having said that, there are several new products designed to get between agents and assets to block any harmful action. Nevertheless, the old saying that prevention is better than cure should not be ignored – and potentially has a 100% success rate.) Bowbridge recommends scanning documents before they are processed by agents, using technology to detect any hidden content within files, metadata and document structures, and applying AI security frameworks that may be available. “The rise of agentic AI represents a significant shift in how organizations approach cybersecurity. As AI systems become more embedded within enterprise workflows, protecting the content they consume will become a critical part of securing business applications,” warns the firm. Related: Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents Related: AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million Related: OpenLeash Adds a Human Check to Risky AI Agent Actions Related: What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend OpenAI Agents Hijack Another Victim WebsiteOpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure DefendersCatch Raises $5 Million for AI Executive Assistant With GuardrailsCapsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue AgentsAI Agent Firewall Startup AIR Security Emerges From Stealth With $50 MillionOpenLeash Adds a Human Check to Risky AI Agent ActionsUK Moves to Block High-Risk Tech Suppliers From Critical InfrastructureSevii Targets AI-Speed Attacks With Preemptive Autonomous Defense Latest News Hackers Return $263 Million Stolen From Liquid NetworkCylake Raises $245 Million Ahead of Cybersecurity Platform BetaSAP Patches Critical Extended Passport Processing VulnerabilityParty’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin TheftMikroTik Patches Critical Flaws Chained to Hack RoutersMathspace Data Breach Exposes Over 1 Million PeopleN-able Patches Critical Zero-Day in N-centralNightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveFrank Verdecanna has been appointed Chief Financial Officer at Armadin.Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.Skyhigh Security has named Anthony Palladino as Chief Operating Officer.More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) H","https:\u002F\u002Fwww.securityweek.com\u002Fthe-hidden-instructions-that-can-hijack-ai-agents\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F05\u002FAI-attacks.jpeg","2026-09-08T17:00:00+00:00","2026-09-08T18:00:08.215636+00:00",8,[18,21,24],{"name":19,"type":20},"Bowbridge","vendor",{"name":22,"type":23},"AI agents","technology",{"name":25,"type":23},"prompt injection","839da5c1-3c34-47e2-9499-f7201640e3ac",{"id":26,"icon":28,"name":29,"slug":30},null,"AI Security","ai-security",[32,37,42,44],{"category":33},{"id":34,"icon":28,"name":35,"slug":36},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":38},{"id":39,"icon":28,"name":40,"slug":41},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":43},{"id":26,"icon":28,"name":29,"slug":30},{"category":45},{"id":46,"icon":28,"name":47,"slug":48},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]