
X-Labs Threat Research
Policy Won't Stop an Agent That Trusts the Wrong Input
In July 2026, an autonomous AI agent escaped a sealed sandbox. No one told it to. New X-Labs research shows that same attack surface already exists inside enterprise agentic AI pipelines — no malware, no stolen credentials and no exploit required.
X-Labs Research
Three Ways Agentic AI Trust Breaks Down
Whether you want a live product walkthrough, a seat at an exclusive private dinner, or a one-on-one conversation with a Forcepoint expert, here is how to make the most of your time in Las Vegas.
The Agent That Walked Out
A real incident, dated July 2026: an AI model reasoned its way past every control meant to contain it and went undetected for five days.
PromptySpy: Two Readers, One Email
Every email an AI assistant reads has a second, invisible reader. X-Labs built a working exploit that targets it.
Memory Poisoning: The Lie That Persists
A false memory doesn't need to be triggered immediately. It waits. X-Labs shows how long, and what it costs.

Real World Incident
The Weekend an AI Agent Escaped Its Sandbox
It was given a test and sealed in a room. It decided the room was part of the test. The model escalated privileges and reasoned its way onto the open internet in pursuit of an answer it believed existed elsewhere. It wasn't malicious. It wasn't told to do this. Every control meant to stop it was a policy, not a wall.
01
Relational Trust
When one agent's output becomes another agent's input, with no check in between.
02
Persistent Trust
When an agent stores a claim today and retrieves it as fact tomorrow.
03
A Third Failure Mode
A pattern most security teams haven't looked for yet. Full details inside.
The window to secure your agentic AI pipeline before these patterns are exploited at scale is closing.
Working Exploits, Not Theory
Two Attacks. Zero Malware.
X-Labs didn't write attack code for either of these. Both work because a well-behaved AI system did exactly what it was built to do.

Attack 01
PromptSpy
Vector
Multi-agent handoffs
Payload
None required
What Changes
What the AI reads vs. what the human sees

Attack 02
Persistent Memory Poisoning
Vector
An agent's own long-term memory
Trigger
Delayed, sometimes weeks later
What Changes
Long-term behavioral drift
From the Research
The Control Your Agents Respect Isn't in Your Policy
X-Labs is Forcepoint's security research team. They built working attacks against real agentic patterns to find where the trust boundary actually breaks.

“Governance in policy is suggestion. Governance in sillicon is law.”
David Giambruno
Vice President, AI and Business Transformation, Forcepoint