Read The Day

AIagent securityStory 01

Nine of 15 agent approval designs were forgeable

What changedResearchers tested 15 ways for an AI agent to ask for confirmation and found that nine could be forged. Their core lesson is simple: approval evidence cannot live in the same place an agent or hostile page is allowed to rewrite.

Diagram and evaluation results for agent confirmation attacks and defenses

The useful part

Why it matters

A visible approved message is not a security boundary if the agent or hostile content can write the same surface; approval evidence needs an isolated trusted channel.

Keep in mind

Good to know

This is a controlled study, not proof that every similar-looking product is exploitable. The useful finding is the trust boundary: moving evidence off an attacker-writable channel cut attack success from 97% to zero in one tested setting.

Evidence

Primary source

Agent security researchers

Read the complete 23 September 2026 edition