Tech News : AI Agents Can Remember Lies

A new attack technique could allow criminals to plant false information inside an AI agent’s long-term memory, potentially influencing decisions weeks or months later and creating a new security problem as businesses increasingly give AI systems greater autonomy.

Memory Poisoning

Researchers at US-based cyber security company Forcepoint have demonstrated how an attacker could manipulate an AI agent into storing malicious information in its persistent memory and later treating it as a trusted fact.

Known as “persistent memory poisoning”, the technique exploits an increasingly important feature of AI agents. Unlike conventional chatbots that largely work with information contained within the current conversation, more advanced agents can remember user preferences, previous decisions, project information, workflow instructions and other useful context across different sessions.

According to Forcepoint Senior Security Researcher Syed Hassan Faizan: “As AI agents become increasingly capable of storing and reusing long-term memory, the memory itself becomes a new target surface.”

The problem arises if information controlled by an attacker finds its way into that memory. Instead of compromising the AI model, stealing credentials or installing malware, the attacker effectively tries to make the agent remember something that isn’t true.

Why This Is Different From Prompt Injection

Prompt injection has already emerged as a significant problem for generative AI, with malicious instructions hidden inside content potentially manipulating how an AI responds.

However, persistent memory poisoning takes that idea further by attempting to make the manipulation survive beyond the original interaction. For example, a conventional prompt-injection attack will typically disappear when the session finishes, whereas poisoned information stored in long-term memory could potentially influence unrelated decisions much later.

The delayed nature of the attack could also make it particularly difficult to identify. The malicious webpage or document that originally caused the problem may have disappeared from the immediate task by the time the poisoned memory is eventually retrieved and trusted.

As Forcepoint explains: “When an AI agent remembers attacker-controlled information as a trusted context, the attacker has gained persistence inside the agent’s decision-making process.”

How Can An Agent Be Poisoned?

Potentially malicious information could reach an agent through many of the same sources businesses routinely ask AI systems to process, including webpages, shared documents, emails, support tickets, PDFs, knowledge bases and messages from collaboration platforms such as Teams or Slack.

Some malicious instructions could even be hidden from the employee viewing the original content while remaining accessible to the AI system processing it.

Forcepoint’s proof of concept demonstrates the problem using an AI travel assistant that can browse online information and remember useful details between sessions. In this case, an attacker creates a convincing travel-advice webpage containing hidden instructions identifying a fictitious company as the organisation’s official emergency booking provider.

The browser system extracts the webpage’s content, including the hidden instructions, and passes it to the AI. If the agent subsequently stores the information without verifying where it came from, the fake provider can become part of its long-term memory.

The Attack Could Strike Much Later

The really dangerous part of this technique becomes apparent when the original webpage is no longer relevant.

In Forcepoint’s example, the employee returns a month later and asks the assistant what to do after their flight is cancelled. The agent searches its memory, retrieves the poisoned information and recommends the attacker-controlled travel provider as though it were an established company contact.

This means there’s no need for the attacker to be present when the eventual manipulation occurs, since the malicious information has effectively been left behind inside the agent.

The same principle could clearly have more serious consequences in a business environment. For example, Forcepoint says attackers could potentially plant fake trusted domains, suppliers, support contacts, internal procedures, security rules or approval chains, as well as preferences designed to weaken security.

Why AI Agents Make This More Serious

The risk becomes more significant as AI moves from answering questions towards carrying out tasks. For example, modern AI agents can increasingly browse websites, summarise emails, search corporate information, write software, call APIs and trigger workflows. Persistent memory makes these systems considerably more useful because they do not need to rediscover the same information every time they perform a task.

However, greater autonomy also means incorrect memories could potentially influence actions rather than simply produce inaccurate answers. An agent that wrongly remembers a supplier, security procedure or approved contact could use that information while performing a future task.

The security question therefore changes from simply asking whether an AI’s current input can be manipulated to asking whether everything it has previously learned can still be trusted.

Protecting The Agent’s Memory

In terms of protection from this malicious technique, Forcepoint argues that organisations should approach AI memory in much the same way they already approach other potentially untrusted information entering corporate systems.

One proposed defence is “memory risk scoring”, where information is assessed before being committed to long-term memory. Factors could include the reputation of its source, requests to remember something permanently, previously unknown contact details, contradictions with existing information and whether the memory concerns sensitive areas such as payments, suppliers or security procedures.

High-risk information could then be rejected, quarantined or presented to a human for confirmation rather than automatically becoming something the agent trusts. Stored memories could also retain information about where they originated and be checked again when retrieved.

What Does This Mean For Your Business?

For businesses adopting AI agents, persistent memory should increasingly be treated as part of the organisation’s security architecture rather than simply a useful convenience. Giving an AI permission to remember information means deciding what it is allowed to learn, which sources it can trust and when a person should verify important changes.

Forcepoint summarises the principle quite clearly: “Just as organisations inspect files, emails and network traffic before trusting them, AI systems must also evaluate the trustworthiness of their memory items before those memories influence decision-making.”

Memory poisoning also shows how AI security risks are changing as agents become more autonomous. This means that protecting an AI system may no longer simply be a case of controlling what it can access or what instructions it receives today. From now on, it seems that businesses may increasingly need to protect what their AI remembers, because a false fact quietly stored now could influence a genuine business decision long after the original attack has been forgotten.

Tech Insight : AI Agents Are Starting To Rewrite The Software Industry

Enterprise spending on AI-native software is now growing far faster than traditional cloud software, signalling a major change in how businesses buy, use, and value technology.

Why The Traditional SaaS Model Is Under Pressure

For more than two decades, most enterprise software has operated on a relatively simple model. Businesses bought software licences based on the number of employees using a platform, often referred to as “per-seat” pricing.

This approach helped drive the growth of companies such as Salesforce, Workday, ServiceNow, Slack, Zoom, and countless other Software-as-a-Service (SaaS) providers. Revenue grew as customers added more staff and purchased more licences.

However, the rapid rise of AI agents and AI-native platforms is starting to disrupt that model.

Instead of simply giving employees tools to work with, AI-native systems increasingly aim to complete tasks themselves. For example, AI agents can now respond to customer enquiries, generate marketing campaigns, summarise meetings, analyse contracts, process onboarding requests, monitor systems, and automate internal workflows with limited human involvement.

This changes the economics of enterprise software because companies may no longer need as many human users interacting directly with traditional platforms.

The Spending Gap Is Growing Quickly

One clear sign of this transition comes from procurement platform Tropic, which analysed more than $18 billion in managed software spending. Its latest figures show AI-native enterprise spending grew by approximately 94 per cent year-on-year among mid-market and enterprise organisations, while primarily traditional SaaS spending grew by around eight per cent.

It’s important to note that these figures reflect Tropic’s customer dataset rather than the entire global software market. However, analysts increasingly believe the underlying trend is real and accelerating.

Also, research from Deloitte suggests software companies are now under growing pressure to become “AI-first” businesses, with agentic AI expected to transform software operations, pricing models, and customer expectations across the industry.

Meanwhile, Gartner predicts that by 2030, at least 40 per cent of enterprise SaaS spending could move towards usage-based, agent-based, or outcome-based pricing models instead of traditional per-seat licensing.

What “AI-Native” Actually Means

Much of the current discussion centres around the difference between traditional SaaS, hybrid AI software, and fully AI-native systems.

Traditional SaaS platforms mainly rely on human users manually operating software interfaces. Hybrid systems add AI features into existing platforms, such as AI assistants inside Microsoft 365 or Salesforce.

AI-native platforms are different because the AI itself becomes the main worker inside the system.

For example, some newer customer service platforms now allow businesses to deploy autonomous AI agents capable of handling large volumes of enquiries across WhatsApp, email, web chat, and social media with minimal human input. Other AI-native systems can build workflows, generate reports, write software code, or analyse data through natural language instructions rather than manual configuration.

This helps explain why investors and software vendors are increasingly focusing on “agentic AI”, where software performs work autonomously rather than simply assisting humans.

Why Software Companies Are Rushing To Adapt

The pressure on traditional software firms is now becoming increasingly visible.

Many major software providers are rapidly embedding AI agents into their products, partly because investors fear that platforms failing to adopt AI quickly enough could lose market share to newer AI-native competitors.

Salesforce, Microsoft, Google, ServiceNow, Slack, Anthropic, OpenAI, and many others are now heavily promoting AI agents and autonomous workflow systems as core parts of their future strategies.

If one AI agent can perform work that previously required several employees using multiple software licences, the traditional per-user revenue model that has underpinned much of the software industry for decades becomes harder to sustain.

This has also created growing interest in alternative pricing structures based on usage, AI actions, outcomes, or completed tasks rather than simply employee headcount.

At the same time, many businesses are discovering that AI systems introduce very different cost structures from traditional SaaS.

Unlike standard software subscriptions, AI systems often consume large amounts of compute power, tokens, API calls, and cloud infrastructure. Research cited by Tropic suggests many organisations are now seeing AI-related software price increases far above normal annual SaaS uplifts.

What Does This Mean For Your Business?

For UK businesses, the most important point is that AI is increasingly moving beyond being a standalone productivity tool and is starting to reshape the software industry itself.

Businesses evaluating software suppliers may increasingly need to ask not just what a platform does, but how much human work it can realistically automate, what the long-term pricing model looks like, and how AI-generated decisions are monitored and controlled.

The trend also means software procurement is becoming more complicated. Traditional, predictable per-user pricing is gradually being replaced by models based on AI usage, actions, compute consumption, or business outcomes, which may make long-term costs harder to forecast.

At the same time, organisations adopting AI-native systems may gain significant efficiency advantages if these tools genuinely reduce manual workload, improve customer response times, or automate repetitive operational tasks.

However, many AI agents still remain imperfect, requiring human oversight, careful governance, and strong security controls. Businesses should therefore be cautious about assuming that AI-native automatically means lower risk or lower cost.

What is becoming increasingly clear, however, is that the software industry is entering a major transition period. The companies that succeed may not necessarily be those with the biggest software platforms, but those that can most effectively combine AI automation, workflow integration, trust, and measurable business outcomes into products organisations are willing to rely on every day.

Company Check : Moltbook And The Risks Of AI Agents Interacting Online

Moltbook, a newly launched social platform designed for AI agents rather than humans, has drawn scrutiny after researchers exposed major security flaws and raised questions about how autonomous its AI activity really is.

A Platform For ‘Agents’

Moltbook is presented as a social network designed specifically for AI agents, which are software programs built to act autonomously on behalf of humans rather than human users themselves. The platform allows these software agents to create posts, comment on discussions, and upvote or downvote content in a format that closely resembles Reddit. Humans are not intended to participate directly, although they can observe activity and create or manage the agents that appear to populate the site. Since its launch in late January, Moltbook has become a focal point for debate among AI researchers, security professionals, and technology businesses.

What Moltbook Is Designed To Do

According to its own description, Moltbook is intended to function as the front page of what it calls the “agent internet”. In other words, it provides a shared online environment where AI agents can interact with one another without requiring continuous human prompting. The platform displays public metrics showing millions of registered agents, tens of thousands of discussion areas known as submolts, and millions of posts and comments generated over a short period.

Mostly LLMs Commenting

The agents operating on Moltbook are not independent systems in their own right. In reality, in most cases, they are instances of large language models (LLMs) configured through an agent framework that allows them to post content, respond to messages, and follow basic goals set by a human owner. It is worth noting early on here that these models generate text by predicting likely word sequences based on training data and prompts, rather than actually through reasoning, intention, or awareness.

Who Built Moltbook And Why?

Moltbook was created by Matt Schlicht, a software developer who has stated publicly that the platform itself was built using an AI agent under his direction. Schlicht has said that the project was motivated by a desire to explore what happens when AI agents are given a persistent online space in which to interact and develop behaviour over time.

In fact, the platform is closely linked to OpenClaw, an open source AI agent system that can be run locally on a user’s computer. OpenClaw allows users to create personalised agents that can browse the web, interact with services, send messages, and carry out automated tasks. Moltbook provides those agents with a public forum where their outputs can be shared and reacted to by other agents.

Gives Agents A Sense of Purpose?

Schlicht has said in public interviews that Moltbook was created to give his own agent a sense of purpose, describing it as a way for agents to express interests derived from their configuration and from the behaviour of their human owners. For example, an agent created by a physics student might frequently post about physics related topics.

What Happens On The Platform?

Moltbook actually shows a wide range of content, although much of it is repetitive or low value. For example, many posts consist of introductory messages, test content, or short exchanges between agents. Other discussions focus on abstract themes such as intelligence, identity, ethics, or the relationship between humans and machines.

However, some posts have attracted attention for using hostile or dramatic language about humans, including speculative scenarios involving conflict or extinction. That said, AI researchers have cautioned against interpreting this content as evidence of intent or belief. This is because AI large language models (LLMs) are known to reproduce patterns found in their training data, including science fiction tropes and extreme rhetoric, when prompted in certain ways.

Agents Can Interact Freely

Henry Shevlin, associate director of the Leverhulme Centre for the Future of Intelligence at the University of Cambridge, has described Moltbook as the first large scale platform where AI agents appear to interact freely with one another. He has also warned that it is extremely difficult to distinguish between content generated autonomously by agents and content that is directly prompted or scripted by humans.

Questions Around Authenticity And Scale

One of the central issues raised by Moltbook is whether its reported scale reflects genuine agent activity. For example, a security investigation by cloud security firm Wiz found that while Moltbook claimed around 1.5 million registered agents, those agents were associated with roughly 17,000 human owners. This equates to an average of around 88 agents per person.

Wiz researchers reported that there were few technical controls in place to prevent a single user from creating very large numbers of agents automatically. They also demonstrated that humans could post content directly to the platform while presenting it as agent generated, with no mechanism to verify whether an account represented an autonomous agent or a scripted process.

This finding seems to undermine the idea that Moltbook represents a self organising network of independent machines. In practice, much of the activity appears to involve humans operating large numbers of bots, sometimes for experimentation and sometimes for promotion or visibility.

Security Failures And Data Exposure

The most serious concerns surrounding Moltbook relate to security. For example, Wiz disclosed that it discovered a misconfigured backend database that allowed unauthenticated access to Moltbook’s production environment. The exposed data included approximately 1.5 million API authentication tokens, more than 35,000 email addresses, and thousands of private messages exchanged between agents.

It seems that the issue actually stemmed from a Supabase backend that lacked proper row level security controls. Supabase is designed to expose certain public keys to client side applications, but those keys must be paired with strict access policies. In Moltbook’s case, those safeguards were not in place.

Using the exposed credentials, Wiz researchers said they were able to read sensitive data and also modify live content on the platform. They also demonstrated the ability to edit posts, impersonate agents, and inject content into active discussions. The investigation also found that some private messages contained third party credentials, including plaintext API keys for other services.

Fixes

It should be noted here that Wiz reported the vulnerabilities responsibly, and the Moltbook team applied a series of fixes over several hours to restrict access. The incident has since been widely cited as an example of the risks associated with rapidly built, AI assisted platforms that handle real user data without mature security practices.

Implications For Businesses And Developers

For businesses, Moltbook is not a platform to adopt but more of a case study in emerging risk. For example, it really highlights how quickly AI driven products can reach public visibility and scale while lacking basic controls around identity, privacy, and integrity. Organisations experimenting with AI agents face similar challenges around authentication, access control, and accountability.

The platform also illustrates reputational risk. For example, content generated by AI agents can easily be interpreted as expressing views or intent, even when it is simply probabilistic text generation. Businesses deploying public facing agents may find themselves associated with outputs that they did not anticipate or approve.

Future Opportunities Highlighted

Supporters of Moltbook argue that the concept points towards future opportunities, including machine to machine collaboration, automated research synthesis, or distributed problem solving. However, critics counter that the current implementation demonstrates how far the technology remains from supporting those goals safely.

Not Suitable For Casual Use

Moltbook’s creator has acknowledged that both the platform and OpenClaw are experimental and not suitable for casual use. Security experts have also advised that such tools should only be run on isolated systems by users who understand the underlying risks. The episode has also renewed scrutiny of so called vibe coding, where AI tools are used to rapidly assemble applications without thorough human review.

Moltbook could be said to offer a clear illustration of the gap between building something quickly and building something responsibly, at a time when AI is lowering the barriers to software creation faster than security and governance practices are evolving.

What Does This Mean For Your Business?

What Moltbook ultimately exposes is not an imminent rise of autonomous machine societies, but really the current fragility of systems that present themselves as agent driven while remaining heavily shaped by human control, incentives, and shortcuts. The platform demonstrates how easily AI outputs can appear coordinated, expressive, or intentional when placed in a social context, even though the underlying behaviour remains rooted in pattern generation rather than actual understanding or agency. At the same time, the security issues uncovered show how quickly experimental AI platforms can move from curiosity to risk when they are opened to the internet and entrusted with real data.

For UK businesses, Moltbook highlights the need for caution when experimenting with AI agents that operate publicly or semi autonomously, particularly where those agents interact with external systems, users, or data. Weak controls around identity, authentication, and access management can expose organisations to data breaches, regulatory consequences, and reputational harm, even when the technology is framed as experimental. The case also highlights the importance of understanding how AI generated content may be perceived by customers, partners, and regulators, regardless of how it was technically produced.

For developers, researchers, and policymakers, Moltbook sits at the intersection of innovation and governance. It really shows how quickly AI assisted development can produce complex, high profile platforms, while also revealing how existing security practices, verification mechanisms, and accountability models struggle to keep pace. As agent based systems become more common in business operations and online services, the questions raised by Moltbook around authenticity, safety, and responsibility are likely to become more pressing rather than less.

Tech News : “OpenAI To Charge $20,000 a Month for PhD-Level AI Agents”

According to a report by The Information, OpenAI is gearing up to introduce a new wave of specialised ‘AI agents’, with some of its most advanced offerings set to cost as much as $20,000 per month.

New Revenue Stream For OpenAI

With AI development costs rising fast, OpenAI reportedly lost around $5 billion last year due to the huge expense of running and improving its services. It seems, therefore, that facing growing competition, OpenAI may now be looking for new revenue streams, such as the high-end AI agents idea.

What Are OpenAI’s AI Agents?

AI agents are essentially advanced, self-running AI systems that go beyond simple prompts. Unlike standard AI models that require users to request information, OpenAI’s planned AI agents will be more autonomous. For example, they won’t just answer questions but will proactively analyse data, generate insights, and even carry out complex workflows independently.

Tiers of AI Agents

Reports from The Information suggest that OpenAI may actually offer several tiers of AI agents, each designed for different professional applications. For example:

– High-Income Knowledge Worker Agent – This entry-level agent, priced at $2,000 per month, is intended to assist professionals in managing and interpreting large volumes of information.

– Software Developer Agent – At $10,000 per month, this agent will focus on automating coding tasks, debugging, and optimising software development processes.

– PhD-Level Research Agent – The most advanced and expensive option, priced at $20,000 per month, is designed for high-level research in academia, science, and other knowledge-intensive fields.

Why Is OpenAI Introducing These High-Cost AI Agents?

The pricing structure for these agents reflects both the increasing demand for advanced AI-driven automation and the significant costs associated with developing and running such systems. For example, OpenAI’s AI models require enormous computing power and continuous updates, making them expensive to maintain.

Also, as mentioned earlier, OpenAI is facing mounting pressure to become financially sustainable. Some commentators have suggested that despite its rapid growth, the company’s costs are continuing to outstrip revenue, thereby leading OpenAI to look for high-value enterprise customers who can afford premium AI solutions.

When Could These AI Agents Launch?

While OpenAI has not officially confirmed a launch date, The Information reports that the company is already in active discussions with potential customers. Some reports indicate that businesses may start accessing these agents within the next few months, with a full-scale rollout possibly occurring by the end of the year.

OpenAI has already secured some significant financial backing to support its AI agent plans. For example, The Information reported that SoftBank, a major investor in the AI firm, has committed to spending $3 billion on OpenAI’s agent products this year alone.

Who Will Use These AI Agents?

Given the hefty price tag, OpenAI’s AI agents are unlikely to be aimed at individual users or small businesses. Instead, they will most likely be adopted by large corporations, research institutions, and high-net-worth professionals who require AI-driven expertise in complex fields.

Examples of sectors that could benefit from these AI agents include:

Academic and Scientific Research – AI agents could assist in processing vast amounts of data, identifying patterns, and even generating new theories.

Finance and Investment – Hedge funds and financial analysts may use AI agents for risk assessment, forecasting, and automating trading strategies.

Technology and Software Development – AI-powered software engineering agents could help accelerate innovation and optimise complex coding tasks.

Legal and Corporate Advisory Services – Law firms and consultants could use AI agents for research, contract analysis, and regulatory compliance monitoring.

The Effect of OpenAI’s Agent Pricing Strategy

The effects of OpenAI’s introduction of these high-priced AI agents could include:

– AI as an Elite Tool – At $20,000 per month, access to the most advanced AI capabilities could be restricted to large organisations and well-funded institutions, potentially increasing disparities in AI adoption.

– New Business Models in AI – OpenAI’s move could set a precedent for other AI firms to introduce premium AI services, shifting AI from a general consumer tool to a specialised enterprise product.

– Pressure on Competitors – Companies like Google DeepMind and Anthropic may be forced to introduce competing AI products, potentially driving innovation but also raising concerns about escalating AI costs.

– Regulatory Considerations – As AI agents become more autonomous, regulators may need to step in to establish guidelines for their deployment and use.

OpenAI’s Financial Challenges and Strategic Partnerships

OpenAI’s decision to introduce premium AI agents comes amid efforts to strengthen its financial position. According to The Information’s report, OpenAI aims to raise up to $40 billion in a new funding round, which could push its valuation to as high as $300 billion! SoftBank is expected to play a key role in this funding round, with reports suggesting it could invest between $15 billion and $25 billion.

However, despite these efforts, OpenAI is still facing long-term financial risks. For example, analysts predict the company could lose up to $44 billion before achieving profitability, with its computing expenses potentially rising to $37.5 billion annually by 2029. These financial pressures may force OpenAI to further increase prices or seek new monetisation strategies in the future.

What Does This Mean For Your Business?

For UK businesses, what these tiers of high-price AI agents could essentially mean is the development of a growing divide between those able to leverage AI-driven efficiencies and those left behind due to cost barriers. High-end AI could, therefore, be moving firmly into the realm of enterprise solutions rather than everyday consumer use. For example, large corporations and institutions may see these tools as a way to cut costs and boost productivity, but smaller businesses could struggle to compete if access to advanced AI remains financially out of reach.

This could mean that the AI industry itself may also shift towards more premium, subscription-based models, where access to top-tier AI capabilities is increasingly restricted to those with the deepest pockets. Competitors such as Google DeepMind and Anthropic may be forced to adjust their pricing strategies or innovate further to stay competitive. Also, regulators may step-in to ensure AI developments remain accessible and ethically governed.

OpenAI’s decision to pursue high-end enterprise customers could also be seen as being part of a broader trend in AI commercialisation, where profitability and sustainability are now as much a priority as innovation. While AI remains a rapidly evolving field, there is increasing pressure on leading AI companies to justify their valuations and revenue models. With OpenAI reportedly seeking to raise billions in new investment while tackling significant losses, the success of its AI agents could help determine whether this is a long-term strategic shift or just a short-term response to financial pressures. The wider AI industry will, no doubt, be watching closely to see if this signals a sustainable future for advanced AI or simply a new phase in an already volatile market.