
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Microsoft's security report highlights that the rapid global adoption of AI agents has led to new security risks, including real attack campaigns exploiting AI agent memory (memory poisoning) and manipulation of agent behavior. These incidents have exposed organizational vulnerabilities, prompting calls for improved governance and security measures. The issue is particularly noted in South Korea.[AI generated]
Why's our monitor labelling this an incident or hazard?
The article explicitly discusses AI agents (AI systems) and their misuse or vulnerabilities leading to security risks, including active attack campaigns exploiting AI agent memory. These attacks and vulnerabilities represent realized harms related to organizational security, which can be considered harm to property or operational integrity. Since the AI agents' misuse and manipulation have directly led to security vulnerabilities and attacks, this qualifies as an AI Incident. The article does not merely warn about potential risks but reports on actual observed attack campaigns and organizational security issues caused by AI agent misuse or malfunction.[AI generated]