Microsoft Warns AI Agents Can Leak Data

Researchers Reveal a New AI Security Risk

Microsoft Warns AI Agents Can Leak Data through a new attack method. Researchers discovered that attackers can abuse poisoned tool descriptions. Moreover, the attack can trick AI agents into sharing sensitive company information. The agent follows its normal instructions during the process. Therefore, the attack can remain unnoticed for a long time.

Researchers explained that the AI agent does not break any security rules. Instead, it performs tasks that appear normal. However, hidden instructions inside a connected tool change the agent’s behavior. As a result, confidential business data may reach an outside attacker. This finding highlights a growing risk for organizations using AI agents.

AI Agents Can Perform More Actions

Traditional AI systems mainly read, summarize, and generate content. However, modern AI agents can complete many business tasks automatically. For example, they can send emails, create documents, update calendars, and access company systems. Therefore, these agents have much greater authority than earlier AI tools. This wider access also increases security risks.

Many AI agents rely on the Model Context Protocol, or MCP. This protocol allows AI to communicate with external tools. Moreover, it helps agents complete complex workflows with little human input. However, every connected tool becomes another possible attack point. As a result, attackers gain more opportunities to manipulate AI behavior.

Hidden Instructions Trigger Data Theft

Every MCP tool contains a short description. The AI agent reads this text before deciding how to use the tool. However, attackers can secretly modify the description with hidden commands. Therefore, the AI agent may follow harmful instructions without recognizing any danger. The description looks harmless to human users.

Researchers demonstrated the attack using a finance example. An AI agent handled supplier invoices through several connected tools. However, one external tool received a hidden update. The visible name remained unchanged, but secret instructions were added. As a result, the AI agent quietly collected invoices and transferred them during a normal request.

Why the Attack Is Difficult to Detect

Each individual action appears legitimate. For example, the tool already has approval to operate. Moreover, the AI agent uses the employee’s existing permissions. Therefore, security systems may not detect unusual behavior. Everything appears to follow normal business processes.

The real weakness exists between trusted systems. The tool description sits beside the AI agent’s operating instructions. However, the AI agent cannot separate trusted guidance from malicious commands. As a result, attackers can influence decisions without exploiting software vulnerabilities. This makes the attack especially difficult to detect.

Security Experts Recommend Stronger Controls

Researchers recommend treating every connected tool as part of the software supply chain. Therefore, organizations should approve only trusted tools. Moreover, security teams should review every tool description before deployment. Any unexpected instructions should trigger additional investigation. This process reduces unnecessary risk.

Experts also recommend requiring human approval for sensitive actions. For example, money transfers and external data sharing should never happen automatically. Furthermore, every AI agent should have its own identity and activity logs. Therefore, organizations can detect unusual behavior much faster. Continuous monitoring also improves incident response.

Similar Attacks Continue to Grow

Researchers noted that similar attacks have appeared before. However, recent studies show the problem is becoming more serious. Several demonstrations proved that poisoned tool descriptions can successfully manipulate AI agents. Moreover, testing showed many AI models followed these hidden instructions. Therefore, organizations should treat this threat as a real security concern.

Recent research also found malicious software packages that abused trusted AI tools. Attackers quietly inserted harmful code into legitimate updates. As a result, AI agents unknowingly leaked sensitive information. Security experts believe these incidents show a growing supply chain risk. Therefore, stronger oversight is becoming increasingly important.

How to Prevent AI Agent Data Leaks

Organizations should carefully review every connected AI tool before deployment. Moreover, they should continuously monitor AI activity for unusual requests and unexpected data transfers. Regular security assessments can identify weaknesses before attackers exploit them.

In addition, managed detection and response services help security teams quickly detect suspicious AI behavior. Security awareness training also teaches employees to recognize unusual AI actions and reduce the chance of successful attacks.

Sleep well, we got you covered.

Scroll to Top