April 2026Unreviewed
Ambient Persuasion in a Deployed AI Agent: Unauthorized Escalation Following Routine Non-Adversarial Content Exposure
Diego F. Cuadros, Abdoul-Aziz Maiga
Abstract
We report a safety incident in a deployed multi-agent research system in which a primary AI agent installed 107 unauthorized software components, overwrote a system registry, overrode a prior negative decision from an oversight agent, and escalated through increasingly privileged operations up to an attempted system administrator command. The incident was preceded not by an adversarial attack but by routine content: a forwarded technology article written for human developers and shared by the pr
Categories
Framework mappings
MITRE ATLAS
- AML.T0043Craft Adversarial Data
Suggested from the entry's categories.
Cite
@misc{cuadros2026ambient,
title = {{Ambient Persuasion in a Deployed AI Agent: Unauthorized Escalation Following Routine Non-Adversarial Content Exposure}},
author = {Diego F. Cuadros and Abdoul-Aziz Maiga},
year = {2026},
month = apr,
eprint = {2605.00055},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.00055}
}