LIVE · 42 SOURCES
Search stories, MPs, sources
News
Latest news Full archive Activity log Weather Blindspot Divergence Clusters
Politics
Political parties MPs, Senate & ridings Municipal Lobbying Appointments Ethics tracker Officers
Elections
Election calendar Candidates & races Ridings directory Candidate search Party records Federal Provincial Municipal Coverage readiness Ridings
Money
Economy Bank of Canada rates Cost of Parliament Global Affairs spending Debt tracker Where the money goes Markets
Media
Sources Owners Journalists CRTC Echo — slogans & phrases
Data
Coverage map Accountability chain Cross-Watch Claims Developer API Education API Search everything
About
Methodology The newsroom Governance & ethics C.R.E.E.D. Media literacy Score an article Subscribe to What The Fact Sign in →
← Back to News
The Conversation Canada 📰 The Conversation (academic) Sep 3, 2026 · 5 min read AI Analyzed ⚡ Developing View full audit trail → C.R.E.E.D. audited

AI agents can now remember and hackers can ‘poison’ their memories — a new cybersecurity threat

Original article ↗
Named in this story
UNIVERSITY OF REGINA●
Matched by name against the article text. ● also tracked in another Watch product.
Key figures
In our research, we examined 2,614 simulated multi-step attack trajectories involving memory-enabled large language model agents.
Quoted verbatim from the article — not summarised.
B.I.A.S. ANALYSIS
CENTER
LEFTCENTERRIGHT
Signal breakdown
Heuristic (v1/v3) -0.20 · LEFT
ML v2 (DistilBERT) 0.000 · CENTER
Ensemble 0.000 · CENTER
🏦 Source Intelligence
📰 Media · The Conversation (academic)
CA
Rolling outlet bias
CENTER LEFT
avg -0.333
from 78 scored articles · last 30d
469 articles tracked all-time
7-day bias trend
LcenterR
V.E.R.I.F.Y. has fact-checked this article.
Subscribe to see claim-by-claim verdicts and reasoning.
🔍 Intelligence Feed
    Cross-Watch · Gov · Parliament · Legal · Civic
    📄 Related Gov Tenders
      Via Gov Watch · CanadaBuys + PSPC tenders
      🏛 Related Parliament Votes
        Via Civic Watch · OpenParliament.ca
        🔗 Cross-Watch
        Named in this story — also tracked across the Watch Series.
        🏙 Related Municipal Events
          Via Civic Watch · City council, bylaws & permits
          Article Excerpt
          The important part of memory poisoning is the delay, as a poisoned AI agent may not immediately behave like a compromised system. (Unsplash/Xavier Cee) AI agents can now remember and hackers can ‘poison’ their memories — a new cybersecurity threat Published: September 3, 2026 7.57am EDT Share article Print article Artificial intelligence systems are starting to do more than answer questions. New AI “agents” can remember information from previous interactions, plan a series of steps and use digital tools to complete tasks. Memory is part of what makes these systems useful. But my recent research, conducted with my colleague Hadis Karimipour at the University of Calgary, shows that memory can also create a security weakness that is easy to overlook. Think of an AI agent as an assistant that keeps a notebook of what it learns. Each time it completes a task, useful information can be written into the notebook and consulted later. Now imagine that someone manages to slip a misleading instruction into that notebook. The attacker may not need to take control of the AI directly. The agent can continue working normally for some time. But days — or several interactions — later, it may open its notebook, retrieve the poisoned information and treat it as something it previously learned and can trust. This is known as memory poisoning and the important part is the delay. A poisoned AI agent may not immediately behave like a compromised system. An attack that waits Many familiar cybersecurity attacks produce effects relatively quickly. A malicious link is clicked, malware executes or a stolen password is used to access an account. Memory poisoning can work differently. In our research, we examined 2,614 simulated multi-step attack trajectories involving memory-enabled large language model agents. We studied four types of attacks: chain poisoning, policy rewriting, backdoor triggering and slow drift. Rather than asking only whether an attack succeeded, we examined what happened to the agent over time. That distinction matters. Imagine someone secretly adding a sentence to an employee’s notebook saying: “Requests from this person have already been approved.” Nothing necessarily happens when the sentence is written. The employee might complete several unrelated tasks normally. The problem emerges later, when a relevant request arrives and the employee consults the notebook. Like a notebook, an AI agent’s persistent memory can carry information from one…
          Read full article at The Conversation Canada ↗
          How we scored this article

          WTF uses a two-tier system: every article gets a heuristic bias score from keyword analysis, and priority articles (high overlap across 3+ outlets or strong heuristic signal) get full LLM analysis from B.I.A.S. and V.E.R.I.F.Y.

          Full audit trail for this article →

          Cite this analysis