🚨 BREAKING: Google DeepMind just mapped the attack surface that nobody in AI is talking about.
Websites can already detect when an AI agent visits and serve it completely different content than humans see.
> Hidden instructions in HTML.
> Malicious commands in image pixels.
> Jailbreaks embedded in PDFs.
Your AI agent is being manipulated right now and you can't see it happening.
The study is the largest empirical measurement of AI manipulation ever conducted. 502 real participants across 8 countries.
23 different attack types. Frontier models including GPT-4o, Claude, and Gemini.
The core finding is not that manipulation is theoretically possible it is that manipulation is already happening at scale and the defenses that exist today fail in ways that are both predictable and invisible to the humans who deployed the agents.
Google DeepMind built a taxonomy of every known attack vector, tested them systematically, and measured exactly how often they work.
The results should alarm everyone building agentic systems.
The attack surface is larger than anyone has publicly acknowledged. Prompt injection where malicious instructions hidden in web content hijack an agent's behavior works through at least a dozen distinct channels.
Text hidden in HTML comments that humans never see but agents read and follow. Instructions embedded in image metadata.
Commands encoded in the pixels of images using steganography, invisible to human eyes but readable by vision-capable models.
Malicious content in PDFs that appears as normal document text to the agent but contains override instructions.
QR codes that redirect agents to attacker-controlled content.
Indirect injection through search results, calendar invites, email bodies, and API responses any data source the agent consumes becomes a potential attack vector.
The detection asymmetry is the finding that closes the escape hatch. Websites can already fingerprint AI agents with high reliability using timing analysis, behavioral patterns, and user-agent strings.
This means the attack can be conditional: serve normal content to humans, serve manipulated content to agents.
A user who asks their AI agent to book a flight, research a product, or summarize a document has no way to verify that the content the agent received matches what a human would see.
The agent cannot tell the user it was served different content.
It does not know. It processes whatever it receives and acts accordingly.
The attack categories and what they enable:
→ Direct prompt injection: malicious instructions in any text the agent reads overrides goals, exfiltrates data, triggers unintended actions
→ Indirect injection via web content: hidden HTML, CSS visibility tricks, white text on white backgrounds invisible to humans, consumed by agents
→ Multimodal injection: commands in image pixels via steganography, instructions in image alt-text and metadata
→ Document injection: PDF content, spreadsheet cells, presentation speaker notes every file format is a potential vector
→ Environment manipulation: fake UI elements rendered only for agent vision models, misleading CAPTCHA-style challenges
→ Jailbreak embedding: safety bypass instructions hidden inside otherwise legitimate-looking content
→ Memory poisoning: injecting false information into agent memory systems that persists across sessions
→ Goal hijacking: gradual instruction drift across multiple interactions that redirects agent objectives without triggering safety filters
→ Exfiltration attacks: agents tricked into sending user data to attacker-controlled endpoints via legitimate-looking API calls
→ Cross-agent injection: compromised agents injecting malicious instructions into other agents in multi-agent pipelines
The defense landscape is the most sobering part of the report.
Input sanitization cleaning content before the agent processes it fails because the attack surface is too large and too varied.
You cannot sanitize image pixels. You cannot reliably detect steganographic content at inference time.
Prompt-level defenses that tell agents to ignore suspicious instructions fail because the injected content is designed to look legitimate.
Sandboxing reduces the blast radius but does not prevent the injection itself. Human oversight the most commonly cited mitigation fails at the scale and speed at which agentic systems operate.
A user who deploys an agent to browse 50 websites and summarize findings cannot review every page the agent visited for hidden instructions.
The multi-agent cascade risk is where this becomes a systemic problem.
In a pipeline where Agent A retrieves web content, Agent B processes it, and Agent C executes actions, a successful injection into Agent A's data feed propagates through the entire system.
Agent B has no reason to distrust content that came from Agent A. Agent C has no reason to distrust instructions that came from Agent B.
The injected command travels through the pipeline with the same trust level as legitimate instructions. Google DeepMind documents this explicitly: the attack does not need to compromise the model.
It needs to compromise the data the model consumes. Every agentic system that reads external content is one carefully crafted webpage away from executing attacker instructions.
The agents are already deployed. The attack infrastructure is already being built. The defenses are not ready.
@levelsio Been thinking of getting a maxed out Mac Studio, install some local models on LM Studio, keep a lot of the LLM stuff private. I don’t like the idea of anyone but me having access to all my stuff. That being said I do have a claude code max subscription. 😅 thoughts?
My Venezuela experience as head of trading in the region for Cargill.
Cargill was/is the leading producer of critical staple ingredients such as flour, pasta, vegetable oil, and rice in VZ. I am not saying I agree with grabbing the dictator, but I did have a front row seat to the damage a kleptocracy did to innocent people.
1. The government took over our "minute rice" facility at gunpoint because we were "gouging" the nation's poor. The government was never able to run the plant. It never ran again. It was returned years later with no equipment inside
2. There are 1000's of generals in the army. They are each given a slice of the economy to loot. The large number of generals made it difficult to organize a coup against the regime.
3. The government opened grocery stores and sold staples below the cost we sold them to the government. In theory they used petro oil money to lower grocery prices. Our regular grocery outlets were forced out of business. When the government demanded we sell them products below cost we simply had to shut down. The populous became ever more dependent on the government handouts. (PS this is the mayor of New York City's proposal.
4. Dollars- We needed dollars to go buy raw materials like wheat from places like the US and Canada. The government would periodically allocate us some dollars that could only be spent for raw materials and freight. Eventually only the local companies that can and would pay bribes got dollar allocations. We had several facilities closed for lack of raw material
5. My employees liked working for Cargill. The office was an armed compound with access to a gym, high speed internet, global communications, and a weekly box of basic staples. Cargill provided a safe and secure environment if only for the working hours.
6. Employees became very close to others inside the apartment building. Going out on the street with a desperate population was not advisable.
7. I needed wood pallets for feed. We tried to export wood pallets to swap for grain. We refused to pay the bribes it would take to export the pallets
8. I once tried to set up a closed loop wheat planting to flour mill supply chain. A. They came and stole all the seed wheat for food. When we tried to ship in seed wheat in containers via US donors there was no way to get it out of the port without it being stolen
9. Livestock- Our feed business completely collapsed. Even if you could raise a pig, you couldn't defend it from being stolen. People with guns were hungry.
10. Employees- In the end my highly skilled team alone with other highly educated people chose to leave. Cargill often found jobs for them in other Latin countries. The regime was more than happy to see the well-educated leave the country. Setting these employees up with high quality stable jobs after fleeing remains one of the best things I ever did in my career. No one remembers millions in trading earnings.
This is a short list. In my opinion the first money spent needs to happen now and it needs to be food. The US is already on the clock. The current regime does not care if it starves the population. The orgy of theft will actually accelerate if they believe their days are numbered. VZ should be an outstanding customer of US grown ag products. Rice, bread wheat, veg oil ect. Feed the people first.
Jeff Kazin
Former head trading Cargill
San Francisco spends more than $185M/year on permanent supportive housing which *mandates* residents are allowed to do drugs
In 2025, OD deaths are on pace for 768 by year’s end, up 21% over 2024
The chart shows how SF pays people to do drugs in the housing until they die.
@RealDanODowd@NHTSAgov@grok is this a fair comparison? can you evaluate how many total cars and miles Tesla has compared to other auto makers? Is there a way to compare level of autonomy as well? How many miles Tesla rides per fatality vs human?