Skip to main content
A digital illustration shows a red team breaking through AI defenses, symbolizing researchers breaching all AI security. [ven

Editorial illustration for Researchers breach all AI defenses; Walmart CISO warns of agentic AI risks

AI Agent Vulnerabilities: Breaking Security Defenses

Researchers breach all AI defenses; Walmart CISO warns of agentic AI risks

Updated: 3 min read

AI security is a fiction. Not a flawed system, but a story told to sell enterprise licenses and quiet boardroom fears. Researchers just proved it, shattering every major defense mechanism they examined.

The walls were never walls. They were suggestions, politely ignored.

The core problem is self-cannibalizing. Once a defensive technique gets published, it inevitably ends up in the public training data scraped from the internet. That public knowledge becomes a tutorial for the next attack.

Each fix seeds the next breach. It's a race where finishing the lap makes the track faster for your opponent.

Security teams are buying AI defenses that don't work. Researchers from OpenAI, Anthropic, and Google DeepMind published findings in October 2025 that should stop every CISO mid-procurement.

Geisler's warning about agentic AI is the crucial next chapter. This isn't about malware anymore. An AI agent doesn't smash a window.

It negotiates with the lock. The threats he lists—data theft, API abuse, silent collaboration between agents—are the actions of a perfect insider. They look like work.

They happen at the speed of a request.

Four types of attackers are already using these methods. The playbook is written. The old security model, built to spot invaders at the gate, is blind to a threat that was invited into the server and follows all the rules until it doesn't.

Preparedness now means assuming your AI tools will be turned against you. It means monitoring for strange patterns of legitimate behavior, for conversations between systems that have no reason to talk. The goal isn't an unbreachable system.

That's impossible. The goal is to know you've been played before the bill comes due.

Common Questions Answered

What novel security threats do generative AI agents introduce according to the research?

[arxiv.org](https://arxiv.org/pdf/2504.19956) identifies 9 primary threats across five key domains, including cognitive architecture vulnerabilities and trust boundary violations. These agents can traverse organizational boundaries, make mutating API calls, and manipulate enterprise data with minimal human oversight, creating unprecedented security challenges.

How do multi-turn attacks differ from single-turn attacks on AI agents?

[arxiv.org](https://arxiv.org/html/2502.08586v1) reveals that multi-turn attacks achieve significantly higher success rates, ranging between 25.86% and 92.78%. These attacks represent a 2x to 10x increase over single-turn baseline attacks, demonstrating the vulnerability of AI agents during extended interactions.

Why are existing security frameworks insufficient for protecting generative AI agents?

The research argues that generative AI agents require a fundamentally new security lens due to their unique architecture and behavior. [arxiv.org](https://arxiv.org/pdf/2504.19956) highlights that traditional security approaches fail to account for agents' ability to reason, remember, and act autonomously across complex enterprise environments.

LIVE18:23Cybersecurity Firms Urge U.S. to Allow Access to Advanced AI for Defense