A failure mode where an AI system, unable to distinguish trusted instructions from untrusted retrieved data, acts on an instruction hidden inside content it was only supposed to read.
The mechanism behind the real, documented Copilot Studio and Agentforce exfiltration incidents this domain's own defenses are built against.
https://venturebeat.com/security/microsoft-salesforce-copilot-agentforce-prompt-injection-cve-agent-remediation-playbook