Artificial intelligence systems are starting to do more than answer questions. New AI "agents" can remember information from previous interactions, plan a series of steps and use digital tools to complete tasks. AI agents can now remember and hackers can 'poison' their memories—a new cybersecurity threat.
September 3, 2026 AI agents can now remember and hackers can 'poison' their memories—a new cybersecurity threat by Abbas Yazdinejad, The Conversation edited by Swati Mestri, reviewed by Andrew Zinin Swati Mestri Scientific Editor Meet our editorial team Behind our editorial process Andrew Zinin Chief Editor Meet our editorial team Behind our editorial process Editors' notes This article has been reviewed according to Science X's editorial process and policies. Editors have highlighted the following attributes while ensuring the content's credibility: fact-checked peer-reviewed publication trusted source written by researcher(s) proofread The GIST Add as preferred source The important part of memory poisoning is the delay, as a poisoned AI agent may not immediately behave like a compromised system. Memory is part of what makes these systems useful.
But my recent research, conducted with my colleague Hadis Karimipour at the University of Calgary, shows that memory can also create a security weakness that is easy to overlook. Think of an AI agent as an assistant that keeps a notebook of what it learns. Each time it completes a task, useful information can be written into the notebook and consulted later.
Now imagine that someone manages to slip a misleading instruction into that notebook. The attacker may not need to take control of the AI directly. The agent can continue working normally for some time.
But days—or several interactions—later, it may open its notebook, retrieve the poisoned information and treat it as something it previously learned and can trust. This is known as memory poisoning, and the important part is the delay.
A poisoned AI agent may not immediately behave like a compromised system. Like a notebook, an AI agent’s persistent memory can carry information from one interaction to the next.
A malicious link is clicked, malware executes or a stolen password is used to access an account. Memory poisoning can work differently.
Discover more from ChuckysCarnage
Subscribe to get the latest posts sent to your email.
