“Please review the documents from our new software vendor. Summarize the key information and flag any potential security or compliance risks.”
Tasks like this are now routinely handled by AI agents in many companies. They read documents, research websites, cross-check information against internal policies, and help prepare decisions.
What often goes unnoticed: a single inconspicuous piece of text in a document or on a website - barely visible to humans - can be enough to influence how an AI agent operates. Instead of simply evaluating the requested information, the system suddenly follows manipulated instructions and deviates from its actual task.
What may initially sound like a theoretical scenario is already occupying security experts today. As generative AI and agentic systems become more widespread, new attack opportunities are emerging that differ fundamentally from classic cyberattacks. Attackers no longer focus exclusively on exploiting vulnerabilities in networks or applications. Instead, they manipulate the inputs, data sources, or knowledge bases of AI systems - always with the goal of influencing their decisions.
This development has also been highlighted by Germany's Federal Office for Information Security (BSI) in an analysis from June 2026 (link in German). The BSI describes how artificial intelligence is transforming the cybersecurity landscape and why companies need to evolve their security strategies accordingly. This isn't just about the use of artificial intelligence by attackers. At the same time, AI systems themselves are coming into focus: language models, copilots, and agentic AI systems process large volumes of data, access external information sources, and carry out actions autonomously. It is precisely these capabilities that create new attack surfaces.
For companies, this means that alongside classic cybersecurity disciplines, AI security is becoming an essential building block. Firewalls, endpoint protection, and zero-trust architectures remain indispensable, but on their own they aren't enough to effectively protect AI applications. What's needed are additional security measures specifically tailored to language models and AI agents.
For an in-depth overview of AI as an attack tool, attack surface, and shield, see the it-sa 365 topic area “Artificial Intelligence & IT Security”.
But which attack methods are actually relevant today? The following four examples show how attackers can manipulate AI systems - and what measures companies should take to protect their applications effectively.

