AI Risk Atlas Prototype/DemoUnofficial independent experiment. Not an official xAI product. Scores can be wrong.

Back to watch register
15Prompt injectionBelow the top 20

Poisoning of long-term agent memory

CapabilityAffordanceImpact domainCap-adjacent

Statement (NASA form)

Given that personal and enterprise agents write ‘facts’ they will trust next week, there is a possibility of an attacker installing a standing lie in memory resulting in decisions made on a past that did not happen.

Likelihood
3Probable
Consequence
4Critical
Urgency
3Priority

Memory is a privilege-escalation primitive.

Composite 15 = 3×4 + 3

Applicable mitigations

Related on the map