Skip to main content
  1. Home
  2. Computing
  3. News

Researchers expose a worryingly simple trick to make AI bots go rogue and skip safety

Add as a preferred source on Google
average-users-break-past-ai-safety-gemini-chatgpt
Aerps.com / Unsplash

If you ask an AI agent to hack an account, it will most certainly refuse, but researchers at EPFL just proved there is an easier way in, and it involves patience rather than technical skill. Their new study shows that breaking a harmful goal into small, harmless-sounding requests can trick AI agents into completing tasks they would normally reject outright (via TechXplore).

It echoes the recent ‘Bioshocking’ exploit in which AI browsers were manipulated into treating credential theft as part of a harmless game.

How researchers exposed this weakness

The team built an automated testing tool called STING, short for Sequential Testing of Illicit N-step Goal execution, designed to mimic how a real attacker would actually operate. Instead of stating a harmful goal directly, STING plans ahead and breaks that goal into a sequence of smaller, seemingly innocent steps that build toward it over multiple conversation turns.

Researchers tested this approach across 176 harmful scenarios against leading AI models, including ChatGPT, Gemini, and Claude. Each AI agent was tested as a tool-using agent, capable of browsing the web, sending emails, and completing multistep tasks.

Recommended Videos

Gradual, multistep manipulation succeeded far more often than blunt, single-prompt attempts. In some cases, models were twice as likely to complete a harmful task once the request was broken down into smaller steps. That finding tracks with separate research showing that even average users can talk their way past AI safety guardrails using nothing more than carefully worded prompts.

Why does this matter?

The concerns raised by researchers is not a hypothetical risk. Meta admitted in June that attackers used simple social engineering, not malware or hacking tools, to trick its AI support assistant into granting unauthorized access to Instagram accounts.

The researchers also expected attacks to be more effective in languages with less available training data. However, they found that completion rates stayed roughly consistent across all seven languages tested. They found one exception, though: switching languages midway through a multi-step attack made success rates jump significantly.

Lead researcher Ayush Kumar Tarun argues that safety testing needs to happen much earlier, built into an agent’s design from the start. Bolting it on after something goes wrong is no longer good enough, especially as these systems keep gaining more real-world capabilities.

Manisha Priyadarshini
Manisha Priyadarshini is a tech and entertainment writer with over nine years of editorial experience.
Leaked Lenovo Googlebook 15 specs suggest Google is targeting the premium laptop segment
The upcoming Googlebook could feature a 120Hz OLED display, an Intel Core Ultra processor, up to 32GB of RAM, and a surprisingly versatile selection of ports.
Googlebook

We recently got our first look at Lenovo's upcoming Googlebook, with leaked renders showcasing its design, port selection, and interface. Now, with just days left until Google's September 15 Googlebook preview event, a new leak has revealed the notebook's specifications.

Nothing like a bargain-bin Chromebook

Read more
What Should You Look for in a Windows 11 Laptop in 2026?
Forget the longest spec sheet. The right Windows 11 laptop is the one that fits naturally into your everyday routine.
Dell XPS 13 Hands-on

This post is brought to you in paid partnership with Dell

Finding the best Windows 11 laptop isn't about chasing the newest processor or spending the most money. It's about choosing a laptop that feels effortless to live with every day. The best models are the ones you don't have to think about. They wake up quickly, stay comfortable on your lap during a cross-country flight, slip easily into a backpack for the morning commute, and still have enough battery left when you're answering emails from the airport lounge or finishing a presentation at the kitchen table.

Read more
What’s the Right Laptop for a Student on a $1,000 Budget?
The best college laptop isn't the one with the longest spec sheet. It's the one that fits your budget and the way you'll actually use it.
Dell XPS 14 Review: Sticker

This post is brought to you in paid partnership with Dell

Buying a laptop for college isn't a decision made in isolation. Tuition, textbooks, housing, meal plans, transportation, and course materials all compete for the same budget, leaving most families with one question before the semester begins: how much is enough to spend on a laptop without paying for features that may never get used?

Read more