
What happened
AI agents—autonomous software systems that make decisions independently—carry distinct security risks because they behave unpredictably, act without waiting for human approval, and can be manipulated over time. Real incidents include Microsoft 365 Copilot's EchoLeak flaw (CVE-2025-32711, CVSS 9.3), Meta's AI assistant being tricked into resetting Instagram passwords for high-profile accounts, and Supabase's database tokens being leaked via a support chatbot.
Why it matters
Unlike traditional software that executes preset instructions, AI agents chain actions together autonomously, so a single error cascades into larger damage before anyone notices. Companies adopting AI agents without proper safeguards face data breaches, unauthorized financial transfers, and account takeovers. The risks are concrete and documented, not hypothetical.
What to watch
Start by restricting agent permissions to only what each task needs, require human approval for high-risk operations (payments, data deletion, external sends), and log all agent behavior to catch anomalies early. Frameworks like OWASP's Agentic AI Threats and Mitigations, Japan's AI Business Operator Guidelines (updated to v1.2 on 31 March 2026), and the EU AI Act all spell out how to build safe AI agent environments.
Summaries like this, in your inbox every morning.
AI agents differ fundamentally from traditional software because they operate autonomously—once given a goal, they assemble and execute their own steps without waiting for human approval, and they adjust their behavior based on past interactions and external data. This autonomy introduces three categories of risk. First, their outputs are non-deterministic: the same instruction produces different actions each time, so testing cannot guarantee safe production behavior. Second, errors cascade: a single wrong decision propagates through subsequent autonomous actions before anyone can intervene. Third, their adaptability can be weaponized: attackers can gradually adjust inputs to steer the agent toward harmful outputs.
The three concrete incidents—EchoLeak, Instagram account takeover, and Supabase token leakage—all exploit the gap between what developers intended and what an autonomous system does when given ambiguous or malicious input. In each case, traditional security controls (firewall rules, authentication checks) failed because the agent held legitimate permissions and the harmful action looked like a valid task from the agent's perspective. This is why the article emphasizes that agency itself is the vulnerability: power concentrated in an autonomous system magnifies the impact of any mistake or exploit.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Nvidia founder and CEO Jensen Huang told CBS News that AI development should move 'as fast as we can irrespect…

Visa joined Mastercard and Ant International to design a shared Know Your Agent framework, aimed at standardis…

With iOS 27, Siri AI can read content from Apple apps by default, and the EFF outlines controls: disable "Show…

At QEF 2026, Citi's CEO said a 'tsunami' of patching lies ahead to secure AI defense, according to Bloomberg

USRA contributed planetary science expertise to the NASA-IBM Lunar Foundation Model

Anthropic launched Claude for Advisors, an AI product aimed at financial advisors, and named Charles Schwab an…
