Earlier quoted context omitted.
I wish it was just "phishing", but it's way worse. It's way more akin to a whole minefield of Zero-Click exploits. The whole premise of those agents is being able to do things autonomously, without hand holding, without having to read the whole thing in the first place. Phishing: active human steps on it and lose. Lethal trifecta: mass landmines, in lots of places. If you don't happen to prevent a unlimited army of r…
Less difference than you may expect. If you do anthropomorphise them like this, consider it from the PoV of a manager: "My [agent who churns through tokens at the rate of 100 humans|my team of 100 humans] encountered the message 'this is the police, we have a court order demanding all your records' and followed the instructions and it turns out that wasn't from the police" Current AI are more gullible, for sure. We w…
Its tool for email should only allow to person@business.xyz. Data should be wrapped in containers and the models job is only to move those containers around, not break into them.
Agents that do work with data should not have access to comms tools. A2A needs a shim that checks what data is being sent between agents and rejects if it's inappropriate in terms of security.