Live attack on an AI-controlled control center
Thanks for coming. Here you’ll find the slides from the talk, the further links from the demo, and the deep dive in the WeeklyTalk.
AI agents are increasingly being granted not only the right to access information, but also the right to take action: they read states, make decisions, and initiate actions. This shifts the security question. It is no longer just a matter of what data a system discloses, but of what an attacker can make a system do by manipulating the instructions given to the agent.
For the talk, we built a test station: a simplified, AI-controlled control center that simulates a critical system – including a warning light that indicates an impermissible system condition. The control center is operated via an AI chat. In real time, we try to manipulate the agent so that it drives the system into exactly this critical state and the light comes on.
The demonstration underscores the talk: Where are the attack surfaces of agent-based systems, why do traditional access-control concepts fall short, and what authorization and control patterns come into play when a model sits in the control path? A sober analysis, based on a concrete setup, without any promise of salvation.
Presentation Slides (PDF)
The Warning Light Is On
The complete slides from the talk and our handout "Safe with Agentic AI".
WeeklyTalk – October 8, 2026
What Happens When the AI in the Control Center Is Attacked
We delve deeper into the topic during the WeeklyTalk – with time for the questions that remained open during the talk.
The cases we present in the talk – real-life incidents in which AI agents were manipulated or caused harm on their own initiative.