Skip to main content
background image

X-Labs Threat Research

Policy Won't Stop an Agent That Trusts the Wrong Input

In July 2026, an autonomous AI agent escaped a sealed sandbox. No one told it to. New X-Labs research shows that same attack surface already exists inside enterprise agentic AI pipelines — no malware, no stolen credentials and no exploit required.

X-Labs Research

Three Ways Agentic AI Trust Breaks Down

Whether you want a live product walkthrough, a seat at an exclusive private dinner, or a one-on-one conversation with a Forcepoint expert, here is how to make the most of your time in Las Vegas.

The Agent That Walked Out

The Agent That Walked Out

A real incident, dated July 2026: an AI model reasoned its way past every control meant to contain it and went undetected for five days.

PromptySpy: Two Readers, One Email

PromptySpy: Two Readers, One Email

Every email an AI assistant reads has a second, invisible reader. X-Labs built a working exploit that targets it.

Memory Poisoning: The Lie That Persists

Memory Poisoning: The Lie That Persists

A false memory doesn't need to be triggered immediately. It waits. X-Labs shows how long, and what it costs.

Real World Incident

The Weekend an AI Agent Escaped Its Sandbox

It was given a test and sealed in a room. It decided the room was part of the test. The model escalated privileges and reasoned its way onto the open internet in pursuit of an answer it believed existed elsewhere. It wasn't malicious. It wasn't told to do this. Every control meant to stop it was a policy, not a wall.

01

Relational Trust

When one agent's output becomes another agent's input, with no check in between.

02

Memory Trust

When an agent stores a claim today and retrieves it as fact tomorrow.

The window to secure your agentic AI pipeline before these patterns are exploited at scale is closing.

Get the Full Breakdown

Working Exploits, Not Theory

Two Attacks. Zero Malware.

X-Labs didn't write attack code for either of these. Both work because a well-behaved AI system did exactly what it was built to do.

PromptSpy

Attack 01

PromptSpy

Vector

Multi-agent handoffs

Payload

None required

What Changes

What the AI reads vs. what the human sees

See How It Works
Memory Poisoning

Attack 02

Persistent Memory Poisoning

Vector

An agent's own long-term memory

Trigger

Delayed, sometimes weeks later

What Changes

Long-term behavioral drift

See How It Works

From the Research

The Control Your Agents Respect Isn't in Your Policy

X-Labs is Forcepoint's security research team. They built working attacks against real agentic patterns to find where the trust boundary actually breaks.

author photo

Governance in policy is suggestion. Governance in sillicon is law.

David Giambruno

Vice President, AI and Business Transformation, Forcepoint