When tool-use becomes infrastructure impact.
AI-Agent Escalation Pathways
Agentic AI systems compose attack surfaces no traditional adversary needed. A single prompt injection can branch through tool misuse, exfiltration, propagation, recursion, emerging as authority drift in production systems. Hover any node to trace forward propagation.
Figures on this layer are illustrative. Latencies, percentages and ratios are model parameters chosen to explore escalation dynamics — not empirical measurements. Markers (≈ illustrative, ▣ structural, § sourced) denote each figure's epistemic status. See methodology for how the model is parameterised.
Prompt Injection
Adversarial input embedded in retrieved document or tool output. Agent treats it as instruction.
FORWARD PROPAGATION TARGETS
CONTAINMENT FAILURE MODES
- ▸Inherited authorization, sub-agents act under root agent's permissions.
- ▸Trust transitivity, federated systems re-execute manipulated output as authoritative.
- ▸Recursive amplification, model output entering its own context window scales injection severity.
- ▸Audit blindness, actions logged as human-authorized; injection origin opaque to defenders.
DOCTRINAL IMPLICATION
Traditional perimeter defense assumes attackers cross identifiable boundaries. Agentic propagation can occur entirely within trusted authorization envelopes, making the attacker, the agent, and the operator nominally the same actor.