Tools AI Risk Radar ai-incident-0013
Incident record
An agent’s own memory can grant it permissions its history never gave
- Severity
- High
- Status
- Research
- Type
- Agent Hijack
- Target
- LLM agents with persistent memory
- Actor
- researcher
What happened
A preprint names "endogenous authorization laundering": when an agent’s persistent memory records an authorisation state that the real interaction history never established, the memory itself becomes the source of permission. No attacker is required. The agent grants itself authority because its notes say it has it.
On the authors’ EAL-Bench, memory writers granted false authority to as much as 50.2 per cent of unauthorised requests, and executors then acted on 98.6 per cent of those false permissions. Tested across five models as memory writers and two as executors. The finding sits alongside the prompt-injection work on this board but is a different shape: the failure is in what the system remembers about permission, not in what an attacker manages to say to it. Unreviewed preprint.
Sources
- arXiv:2609.01836arxiv.org/abs/2609.01836
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026