Skip to main content
  1. Home
  2. Computing
  3. News

Digital Trends may earn a commission when you buy through links on our site. Why trust us?

Microsoft says your AI agent can become a double agent

New security research flags misused permissions and poisoned memory, pushing companies to lock down agent access.

Add as a preferred source on Google
ai-chip-image
Igor Omilaev / Unsplash

Microsoft is warning that the rush to deploy workplace AI agents can create a new kind of insider threat, the AI double agent. In its Cyber Pulse report, it says attackers can twist an assistant’s access or feed it untrusted input, then use that reach to cause damage inside an organization.

The problem isn’t that AI is new. It’s that control is uneven. Microsoft says agents are spreading across industries, while some deployments slip past IT review and security teams lose sight of what is running and what it can touch.

Recommended Videos

That blind spot gets riskier when an agent can remember and act. Microsoft points to a recent fraudulent campaign its Defender team investigated that used memory poisoning to tamper with an AI assistant’s stored context and steer future outputs.

Shadow agents widen the blast radius

Microsoft ties the double agent risk to speed. When rollouts outpace security and compliance, shadow AI shows up fast, and attackers get more chances to hijack a tool that already has legitimate access. That’s the nightmare scenario.

The report frames it as an access problem as much as an AI problem. Give an agent broad privileges, and a single tricked workflow can reach data and systems it was never meant to touch. Microsoft pushes observability and centralized management so security teams can see every agent tied into work, including tools that appear outside approved channels.

The sprawl is already happening. Microsoft cites survey work finding 29% of employees have used unapproved AI agents for work tasks, the kind of quiet expansion that makes tampering harder to spot early.

It’s not just bad prompts

This isn’t limited to someone typing the wrong request. Microsoft highlights memory poisoning as a persistent attack, one that can plant changes that influence later responses and erode trust over time.

Its AI Red Team also saw agents get tricked by deceptive interface elements, including harmful instructions hidden in everyday content, plus task framing that subtly redirects reasoning. It can look normal. That’s the point.

What to do next

Microsoft’s advice is to treat AI agents like a new class of digital identity, not a simple add-on. The report recommends a Zero Trust posture for agents, verify identity, keep permissions tight, and monitor behavior continuously so unusual actions stand out.

Centralized management matters for the same reason. If security teams can inventory agents, understand what they can reach, and enforce consistent controls, the double agent problem gets smaller.

Before you deploy more agents, map what each one can access, apply least privilege, and set monitoring that can flag instruction tampering. If you can’t answer those basics yet, slow down and fix that first.

Paulo Vargas
Paulo Vargas is an English major turned reporter turned technical writer, with a career that has always circled back to…
Satechis’s color-matched MacBook Neo accessories are just too pretty to ignore
If you wish Apple made peppy accessories for its budget laptop, Satechi heard your prayers without charging you a bomb for it.
Satechi MacBook Neo accessories

Satechi, which makes some fantastic charging and PC peripherals, has just launched a whole bunch of accessories targeted at the MacBook Neo. But instead of making them boring and drab, the company has actually color-matched them to the exact shade that you get on Apple's budget-centric laptop. The offerings on the table include a multi-port adapter, a USB-C snap hub, and a wireless mouse, and all of them are now available to buy starting at $29.99 from Satechi's website and Amazon. Color options that are up for grabs include Citrus, Blush, Indigo, and Silver

Satechi OntheGo 5-in-1 Multiport Adapter ($44.99)

Read more
ChatGPT’s hiking advice left two hikers stranded on a mountain in Poland
The chatbot directed the pair onto a climbing route neither had the skills to finish, and it's not the first time AI has sent travelers somewhere they shouldn't have gone.
Bag, Clothing, Coat

A shortcut recommended by ChatGPT left two hikers stuck on a mountain face in Poland this month, and they needed a helicopter to get back down. It's the latest case of an AI chatbot steering travelers toward routes it has no real way to evaluate.

ChatGPT's shortcut led straight to a dead end

Read more
Firefox is doubling its update pace, and that’s good news for your security
Mozilla Firefox

Mozilla is about to speed up one of the most important parts of using Firefox: security updates. If you're used to seeing a new Firefox update land about once a month, that's about to change. Beginning in September, Mozilla plans to switch to a two-week release schedule for Firefox on desktop and Android, meaning users should start getting updates twice as often. That might sound like more frequent downloads, but it's really about closing security gaps sooner.

Why waiting a month for security fixes no longer cuts it

Read more