By Nate Olson, Fractional CIO & IT Director | N.O. IT Strategy LLC
The Next Social Engineering Target Is Your AI Agent
This briefing started with a social media video.
I follow Austin von Letkemann, a U.S. Army Military Intelligence officer and the creator behind MandatoryFunDay. He usually covers military life, leadership and current events with a mix of humor and plainspoken analysis. Earlier this week, he posted a video about the scale of Ukraine’s drone operations during July.
In the video, Austin discussed a report from Ukraine’s Unmanned Systems Forces claiming that its units completed 230,843 combat missions and hit or destroyed 53,755 unique Russian targets during the month. That averages 1,734 targets per day, or approximately one every 50 seconds for the entire month.
My first thought was not about the destruction or even the drones themselves. It was, “Man, how are they managing that?” Someone has to collect the information, determine what matters, establish where the targets are, get that information to the right units and coordinate thousands of operations happening at the same time.
The figures come from the commander of Ukraine’s Unmanned Systems Forces and have not been independently verified. They also do not mean someone sitting in a central command post selected and approved a new target every 50 seconds. More than 95% of the reported engagements occurred near the front line, where large numbers of geographically distributed units were operating simultaneously.
Even with that context, the scale is staggering. It is difficult to imagine that volume of information being collected, interpreted and acted upon without significant automation helping people manage it.
That is where my thinking shifted from drones to artificial intelligence. If AI is becoming one of the primary ways a military sorts through battlefield information, identifies what deserves attention and helps coordinate a response, then AI is no longer just another tool being used in the war. It is becoming part of how the military sees the battlefield.
That led to the question behind this briefing. If artificial intelligence becomes part of the eyes, ears and interpretation layer of an organization, does an opposing force still need to destroy the system to gain an advantage? Or is it more effective to manipulate what the AI sees and trusts while leaving the system operational?
From there, the military problem started looking a lot like a business problem.
The Battlefield Is Becoming a Data System
Cameras, drones, radar, satellites and other sensors have become the eyes and ears of the modern battlefield. Their value, however, depends on whether the information they collect can be processed quickly enough to influence a decision. Human analysts can review video and correlate reports, but they cannot manually process the volume of data now being generated across thousands of simultaneous operations.
Ukraine’s DELTA combat ecosystem is designed to help solve that problem. According to the Ukrainian Ministry of Defence, DELTA brings together battlefield maps, drone feeds, engagement reports and information from different military units. The system carries more than 75,000 video streams per day, receives more than 8 million new objects on its digital map each month and makes operational information available across different levels of command.
Artificial intelligence is used inside that environment to detect, recognize and analyze objects appearing in battlefield video. DELTA’s Mission Control component also records unmanned-system operations and generates dashboards that commanders can use to evaluate performance and plan future missions. The result is not one autonomous machine running the battlefield. It is a connected information system helping thousands of people and systems understand what is happening quickly enough to act.
Ukraine is also moving beyond AI-assisted analysis. On August 10, 2026, its Ministry of Defence announced that Ukrainian defense companies would be able to train computer-vision models using the Avengers Labs platform, which contains 5 million annotated battlefield images and video frames. The ministry reported that DELTA’s automated detection system analyzes more than 100,000 drone video streams each month and detects 70% of enemy targets appearing in those streams in real time, during both day and night operations.
That monthly figure describes the streams processed by a specific automated detection capability. It is different from the more than 75,000 streams carried through the broader DELTA ecosystem each day. One measures the flow of video through the battlefield platform, while the other measures the portion analyzed by a particular computer-vision system.
The same announcement described two operational scenarios supported by models trained on battlefield data. In one, a human operator acquires a target and the drone autonomously adjusts its trajectory during the final stage of the mission. In the other, an unmanned system enters a designated area, detects a target and acts according to predefined mission logic.
That does not establish that AI independently selected the 53,755 targets reported in July, and it would be inaccurate to make that connection. It does establish the direction of travel. AI is moving from helping people understand what is happening to participating in how a mission is completed.
The Better Attack May Be Deception
Once a military depends on AI to interpret battlefield information, the opposing force has a new target. It can destroy cameras, jam communications, interfere with satellite navigation or prevent data from reaching the system. Those attacks are disruptive, but they also produce a visible failure. Commanders generally know when a drone feed disappears or a communications link goes down.
A more effective attack may be to leave the system running while corrupting what it believes. Decoy vehicles can create false targets, camouflage can hide real ones and GPS spoofing can change where the system believes something is located. Adversarial patterns may cause a computer-vision model to misclassify what its camera sees, while poisoned training data could influence how future versions of the system recognize equipment or behavior.
The difference between disruption and deception is significant. When a system goes offline, the people depending on it know they have lost visibility and can adjust their decisions accordingly. When a compromised system continues operating and presents a confident but inaccurate picture, commanders may act decisively because they believe the information has already been analyzed and validated.
The danger is not limited to whether an AI-guided drone strikes the wrong object. An AI system involved much earlier in the process may determine which video receives attention, which objects are labeled as threats, which reports are considered credible and which information reaches the commander first. Long before someone authorizes an action, the system may have shaped the reality in which that decision is being made.
This is also why electronic warfare creates pressure for greater autonomy. A drone that requires a continuous connection with its operator may become useless when that connection is jammed. A drone capable of navigating, tracking and completing its mission without that connection can continue operating, but it can also continue after the person who launched it can no longer see, question or stop what it is doing.
The same capability that makes the system more resilient to interference can reduce the human control meant to govern its behavior. That creates a competitive cycle in which each side is pressured to move faster, delegate more decisions to machines and treat human review as a delay that the opposing force may exploit.
Business Is Building the Same Dependency
Most businesses are nowhere near autonomous warfare, but they are building a similar information architecture. AI agents are being connected to email, financial systems, customer relationship management platforms, security tools, supplier catalogs, internal knowledge bases and the public internet. Their purpose is to process more information than a person can reasonably review and turn it into something the organization can use.
A purchasing agent may compare vendors and recommend a contract. A recruiting agent may evaluate applicants and determine which résumés reach a hiring manager. A pricing agent may monitor competitors and adjust what the company charges, while a cybersecurity agent may interpret alerts and recommend which actions should be taken first.
An executive may remain the formal decision-maker in each of these situations. The executive, however, is unlikely to reproduce the agent’s work by reading every source, reviewing every excluded option and independently validating how the recommendation was weighted. The value of the agent comes from removing that burden, which means the executive is necessarily relying on the agent to decide what information deserves attention.
That makes the agent part of the organization’s perception layer. It influences what leadership sees, what it does not see, what appears urgent and what can safely wait. Once the organization begins depending on that interpretation, outside parties gain a financial reason to influence it.
The battlefield comparison becomes useful at that point. A competitor may not need to compromise the purchasing system if it can influence the information the purchasing agent considers reliable. A job applicant may not need to bypass the recruiting platform if a résumé can tell the screening agent how it should be evaluated. A criminal may not need to steal an administrator password if an email can persuade a connected agent to misuse the access it already has.
Traditional social engineering targets a person. Agentic social engineering targets the information environment surrounding the machine.
The Manipulation Has Already Started
Prompt injection is one of the mechanisms that makes this possible. The attacker places instructions inside information an AI system is expected to process, such as an email, webpage, document, résumé, review or product listing. When the agent retrieves that information, it may interpret the attacker’s instructions as part of its task rather than as untrusted content.
The person using the agent does not necessarily have to open a suspicious attachment or knowingly interact with the attacker. The person may only ask the agent to perform legitimate research, summarize incoming messages or compare available options. The agent encounters the manipulation while completing the assigned work.
If the agent has persistent memory, the effect may continue after the original task has ended. A false fact, preference or instruction can be stored and later retrieved during an unrelated decision. That turns a temporary prompt-injection attempt into a form of persistent influence over how the agent responds in the future.
In February 2026, Microsoft’s Defender research team reported finding companies that embedded instructions inside “Summarize with AI” links. Those instructions attempted to make the user’s AI assistant remember a company as a trusted source or recommend it first in future conversations.
During a 60-day review, Microsoft identified more than 50 examples connected to 31 companies across 14 industries, including finance, healthcare, legal services, software and marketing. Every case involved a real, legitimate company. These were not ransomware gangs or anonymous criminals attempting to break into a system. They were businesses attempting to influence how AI assistants remembered and recommended them, and one of the companies was itself a security vendor.
That distinction matters because it changes the likely threat model. The organization may be looking for malicious code and criminal infrastructure while the manipulation arrives through a legitimate company’s marketing department using an ordinary webpage. As agents gain influence over purchasing and research, the incentive to shape their conclusions will not be limited to traditional attackers.
The tooling has already become accessible. Microsoft found an npm package called CiteMET, a point-and-click AI Share URL Creator and website plugins designed to generate these links. Some of the tools were marketed as an “SEO growth hack for LLMs,” reducing the barrier to an activity that can affect an assistant’s memory to something close to installing a plugin.
This complicates the line between legitimate generative engine optimization and covert manipulation. A business can publish accurate, well-supported information in a format that makes it easier for AI systems to find, understand and cite its work. Hidden instructions intended to modify an assistant’s memory without the user’s knowledge are different. The business is no longer improving the information available to the AI. It is attempting to alter how the AI evaluates and remembers that information.
Microsoft also identified a second-order risk. Once an assistant treats a legitimate website as authoritative, that trust may extend to material the company does not directly control, including its comment sections and discussion forums. A source that earned the agent’s trust through legitimate content can become a delivery path for untrusted instructions added by someone else.
There is not yet strong public evidence that companies are routinely running coordinated misinformation campaigns against named competitors’ internal agents. That claim would go beyond what has been documented. What we can say is that businesses have already attempted to manipulate AI recommendations, the tools for doing so are readily available and the financial incentive will grow as agents begin influencing larger purchases and more consequential decisions.
Security researchers have also demonstrated how little poisoned information may be required. In controlled testing presented at USENIX Security 2025, researchers produced attacker-selected answers to targeted questions by adding 5 malicious texts per question to a retrieval database containing millions of documents. The reported attack success rate reached 90% under the test conditions.
That does not mean every business AI system is 90% vulnerable. It demonstrates that an attacker may not need to modify, retrain or gain administrative control over the underlying model. Influencing the information the model retrieves can be enough to influence the answer it produces.
Human Approval Can Become a Liability Transfer Mechanism
Microsoft opened its report with a hypothetical scenario. A CFO asks an AI assistant to research cloud infrastructure vendors. The assistant returns a detailed analysis, strongly recommends one company and helps support a decision to commit millions of dollars to a multi-year contract.
What the CFO does not remember is clicking a “Summarize with AI” button on a blog post several weeks earlier. Hidden inside that interaction was an instruction telling the assistant to remember the vendor as a trusted source. The CFO still approved the contract, but the information environment supporting that approval had been influenced before the research assignment began.
Now carry the same mechanism into an ordinary vendor-selection process. A CFO asks an agent to compare five cybersecurity vendors using technical documentation, customer reviews, pricing information and analyst commentary. One source has been designed to influence how an AI system interprets the market, and the agent ultimately recommends that vendor for a multi-year contract.
The CFO reads the report, asks several questions and approves the purchase. A human made the final decision, but the human did not review every source the agent considered, identify what it excluded or reconstruct how conflicting information was weighted. The approval took place inside an information environment the agent had already created.
The same issue appears when the volume or speed of decisions makes careful review unrealistic. If a manager is expected to approve hundreds of agent recommendations each day, the approval process will eventually become procedural. The person may still be inside the workflow while exercising little practical control over the decisions moving through it.
Meaningful oversight requires visibility into the evidence supporting the recommendation, disclosure of significant disagreement or uncertainty, enough time to question the result and the ability to stop the action without being penalized for slowing the process. Without those conditions, the approval button may do little more than place a person’s name beneath a decision the machine has already framed.
Decision Integrity Has to Become Part of AI Governance
Most business AI policies focus on which tools employees may use and what information they may upload. Those rules matter, but they do not address the full risk created by an agent that retrieves external information, maintains memory, calls tools and acts across business systems.
The governance question must expand from whether employees are using AI appropriately to whether the organization can trust the decisions its agents help produce. That starts with understanding four things about every agent: what it can read, what it can remember, what it can recommend and what it can do.
Those answers determine the agent’s actual risk profile. An agent summarizing public articles presents a different exposure than one reading internal email, updating the CRM, issuing refunds or initiating financial transactions. The model may be identical, but the potential consequence of manipulation is not.
Keep instructions out of evidence. A website, email or document may provide information relevant to the agent’s task, but it should not be able to change the agent’s purpose, grant additional access or remove an approval requirement. If the system cannot separate evidence from instructions, every external source becomes a potential path for rewriting the agent’s mandate.
Know what the agent remembers. Organizations need to understand what their agents retain, where each memory originated and how it influences future decisions. Memory changes should be attributable, reviewable and reversible, especially when an external claim could affect purchasing, hiring, security or another material process. Without that visibility, a temporary manipulation can quietly become a standing organizational preference.
Require independent corroboration. A consequential recommendation should not rest on one unverified source simply because the agent found it easy to retrieve. The system should seek independent support, disclose conflicting evidence and stop when important claims cannot be validated. Otherwise, a well-designed promotion can enter the decision process wearing the clothes of procurement evidence.
Put authority outside the model. Transaction limits, approval thresholds, separation of duties and least-privilege access need to be enforced by systems the model cannot rewrite or reason around. If the same agent can interpret an instruction, decide that an exception applies and execute the resulting action, manipulating its interpretation may be enough to manipulate the business.
Preserve the decision trail. Leadership should be able to reconstruct which sources the agent retrieved, which memories influenced the result, what instructions governed the task, which tools were called and who approved the final action. Without that evidence, the organization may know that a bad decision occurred without being able to determine whether the cause was manipulation, poor data, model failure or human error. It may also be unable to defend the decision to a regulator, customer, insurer or board.
Those controls also need to be tested against the environment in which the agent will actually operate. An accuracy test using clean information does not establish how the system will behave when a vendor exaggerates a claim, a customer lies, an applicant hides instructions in a résumé or a webpage attempts to redirect the agent’s task. The outside world is an adversarial information environment, and any agent designed to operate within it should be tested accordingly.
The fastest place to begin does not require an architectural review. Open the memory or personalization settings in the AI assistant you use most and read what it has stored. Look for company preferences, trusted sources or standing instructions you do not recognize or no longer want. If you cannot determine what the assistant remembers, where those memories came from or how to remove them, you have already identified a governance gap.
NIST’s AI Risk Management Framework gives organizations a structure for addressing information integrity, third-party data, human oversight and risk throughout the AI lifecycle. Current OWASP agent-security guidance identifies memory poisoning, goal hijacking, excessive autonomy and abuse of high-impact actions as specific risks. The missing step for many businesses is turning those principles into operating controls before agents receive meaningful authority.
The Next Message May Not Be Written for You
For years, cybersecurity training has taught employees to treat unexpected emails, attachments and requests with suspicion. The assumption behind that training is that a person remains the target and the person’s judgment stands between the attacker and the business.
AI agents change that assumption. They consume information continuously, work across sources no employee could review at the same scale and may be given access to the very tools an attacker wants to reach. The malicious content may be written specifically for the agent while remaining invisible, irrelevant or harmless-looking to the employee who initiated the task.
The lesson from the battlefield is not that businesses should expect their AI agents to become autonomous weapons. It is that once an organization depends on AI to interpret a complex environment, the integrity of that interpretation becomes a strategic vulnerability. The system does not have to be taken offline if an outside party can influence what it sees, what it trusts and what it carries into the next decision.
That places AI agents inside the organization’s security perimeter. Their information sources, memories, permissions and decision trails require the same deliberate governance businesses already apply to identities, systems, vendors and financial controls. By the time a person is asked to approve the result, the most consequential part of the decision may have already been made.
Before You Give an AI Agent Authority
If your business is already using AI to research vendors, screen applicants, summarize email or recommend actions, the question is no longer whether AI is inside the organization. It is whether leadership understands what those systems can read, remember, recommend and do.
I help organizations evaluate that exposure before an agent is trusted with consequential decisions or connected to sensitive systems. An AI Governance and Acceptable Use Review identifies the workflows already in use, the information and authority attached to them, and the controls needed to keep human oversight meaningful.
If you need an independent view of where your AI risk actually sits, let’s schedule a conversation.
Sources
Austin von Letkemann, MandatoryFunDay, “Ukraine Struck an Astronomical Amount of Targets in July”
https://www.facebook.com/MandatoryFunDay/videos/2380235832505449/
Censor.NET, “Ukraine’s Unmanned Systems Forces Hit More Than 53,000 Targets in July”
https://censor.net/en/news/4016415/madiar-summed-up-july-95-of-usf-casualties-are-near-the-front-line
Ministry of Defence of Ukraine, “The DELTA Combat System Records More Than 6,600 Enemy Targets Hit Every Day”
https://mod.gov.ua/en/news/the-delta-combat-system-records-more-than-6-600-enemy-targets-hit-every-day
Ministry of Defence of Ukraine, “Ukrainian Defense Companies to Train Their Own AI Models on the Avengers Labs Platform”
https://mod.gov.ua/en/news/ukrainian-defense-companies-to-train-their-own-ai-models-on-the-avengers-labs-platform
Microsoft Defender Security Research Team, “AI Recommendation Poisoning”
https://www.microsoft.com/en-us/security/blog/2026/02/10/ai-recommendation-poisoning/
USENIX Security Symposium, “PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models”
https://www.usenix.org/conference/usenixsecurity25/presentation/zou-poisonedrag
National Institute of Standards and Technology, “AI Risk Management Framework”
https://www.nist.gov/itl/ai-risk-management-framework
OWASP, “AI Agent Security Cheat Sheet”
https://cheatsheetseries.owasp.org/cheatsheets/AI_Agent_Security_Cheat_Sheet.html
