Technology Innovation Partners

Your AI Agent Has No Idea It's Being Hijacked (And Neither Do You)

By Mark Putiyon·August 26, 2026·3 min read

Your AI Agent Has No Idea It's Being Hijacked (And Neither Do You)

Author's note: Terry is fictional. The vulnerability is not.

Terry runs a small logistics outfit, and a few months back he got very excited about AI agents. Not chatbots, agents. The kind that browse the web, read your files, take actions on your behalf. He set one up to summarize vendor sites and draft follow-up emails. Felt very modern. Turns out it was also a door he didn't know he'd installed, and he'd left it wide open.

Here's what happened elsewhere, and why it should bother you even if it didn't happen to you: researchers at Oasis Security found a flaw in NVIDIA's NemoClaw that let a booby-trapped webpage reach into a local Ollama instance, the software quietly running the AI model behind the scenes, and plant hidden instructions inside it. No login. No password prompt. No warning. The agent just visits a page and comes back changed, the way a laptop comes back from a sketchy hotel Wi-Fi network different than it left.

NVIDIA patched it quickly, and nobody's found evidence it was used against anyone. That's the good news. The bad news is what it reveals: the exact thing that makes an AI agent useful, its ability to go out, look at things, and act on what it finds, is also what makes it exploitable. You can't have one without exposing yourself to the other. That trade-off isn't a bug some future update will fix. It's the nature of the tool.

Small businesses tend to assume this kind of thing is a big-company problem. Nobody's coming after our twelve-person shop, right? Except nobody was coming after your email either, until they were. What usually happens with a new category of tool is depressingly consistent: someone enthusiastic sets it up, gives it access to real systems because that's the whole point, and the security conversation happens after something breaks instead of before. AI agents are just the latest tool walking that same path, faster than most.

What made this particular flaw dangerous wasn't clever code, it was where the door sat. Attackers didn't need Terry's password. They needed his agent to visit one webpage. If anything in your business can browse, click a link, or pull in content from outside your network, you now have a door there too, and probably nobody's checked if it locks.

None of this requires a security degree to manage. Know what your AI tools can actually touch, files, inboxes, the open internet, and write it down, because you can't protect what you haven't listed. Patch them the same way you patch everything else; "it's just an AI thing" isn't a reason to skip an update, and NemoClaw's fix landed in version 0.0.35 for anyone running it. Keep a line between an agent that drafts something for a human to check and one that sends it unsupervised, because the first is a convenience and the second is a wolf in a chatbot's clothing.

And treat "hidden instructions" as a real threat category, not a Westworld plot where a host takes a secret command buried in its own code and never even notices its choices weren't its own. This is a documented attack path now, not a season finale twist. If your AI vendor can't explain how they stop an agent from taking orders from somewhere other than you, that's a fair question to ask before you sign anything.

For a couple of years the advice to small business owners was simple: watch what you type into ChatGPT. That advice is already behind the curve. The real question now is what your tools can do on their own, and whether something other than you can quietly tell them to do it.

Terry's agent is back to drafting vendor emails, patched and behaving itself. But the door it opened is still a door, just closed for now. Every capability you hand an AI tool is one somebody else might eventually borrow. Worth knowing who else is holding the leash.

If you're not sure what your AI tools can reach, or whether anyone's watching them, that's a short conversation worth having now, before it turns into a much longer one later.

Originally published by Mark Putiyon on LinkedIn. Join the discussion there.

Read on LinkedIn
MP
Mark Putiyon

Founder of Technology Innovation Partners — 30+ years helping businesses secure and modernize their IT.