SECURING AGENTIC ARTIFICIAL INTELLIGENCE SYSTEMS: ASSESSING PROMPT INJECTION, MEMORY POISONING, AND AUTONOMOUS TOOL-USE RISKS IN INTELLIGENT APPLICATIONS

Authors

  • Faheem Ahmed Author
  • Dr Hussain Shah Author
  • Nazia Azim Author
  • Faisal Rahman Author

Keywords:

Agentic Artificial Intelligence, Prompt Injection, LLM Security Memory Poisoning, Autonomous AI Agents

Abstract

Artificial Intelligence (AI) has come a long way, and the advent of Agentic Artificial Intelligence systems goes beyond traditional AI offerings, such as reasoning, planning, memory retention, and access to external tools. These are areas that offer important potential for automation and intelligent decision making, but they also bring along with them complex cyber security challenges. Unlike conventional software systems, Agentic AI applications are based on flexible interactions between LLMs, memory modules, external data sources, and autonomous mechanisms for tool usage, which introduces new attack vectors. Some of the most significant emerging risks include unauthorized autonomous tool execution, memory poisoning, and prompt injection attacks, all of which can erode trust in AI systems, data security, and organizational reliability. The goal of this study was to understand the insights of cybersecurity practitioners on Agentic Artificial Intelligence-related security threats. A qualitative, phenomenological study approach was used to explore experts' lived experiences and interpretations of AI security challenges. The data were obtained using semi-structured interviews conducted with 18 professionals such as AI security researchers, cybersecurity experts, machine learning engineers, and software architects. Thematic analysis method by Braun and Clarke was used to analyse the collected data to find any significant pattern and theme. The results pointed to four key themes: (1) Agentic AI is a growing cybersecurity attack vector, (2) prompt injection is a key threat to AI reliability, (3) memory poisoning is a challenge to long-term trust in AI, and (4) autonomous tool usage is a governance and control issue. The participants highlighted the limitations of conventional cybersecurity methods to defend autonomous AI systems, given their adaptive nature, intricate structures, and self-reliant execution. The research emphasises the need for AI-specific security models, least-privilege access control, memory validation, continuous monitoring, and oversight. The study adds to the growing area of AI cybersecurity by offering empirical findings on the experiences of experts and actionable recommendations for securing next-generation autonomous AI applications. The results are relevant to policymakers, organizations, cybersecurity experts, and developers of Agentic AI technologies, as they aim to encourage secure and responsible use of these new technologies. Agents are exploring the possibility of monitoring the user's input and the resulting output.The agents are investigating potential monitoring of the input and output of the AI system.

Downloads

Published

2026-07-31