Subscribe Home Conversations On AI App Development CRM Enterprise IT Ethics & Governance Futures HR Industries ServiceNow on ServiceNow Platform Foundations Products & Solutions All topics For Leaders In IT & Dev Customer Experience Finance, Operations & Strategy Employee Experience Security & Risk News & Events People & Culture My List Explore All
September 22, 2026 5 min How persuasion can weaken AI agent security Research shows that AI agents are at risk from the same persuasion techniques used on humans Ethics and Governance Research
Rene Stranghoner
Rene Stranghoner Head of Thought Leadership Research, ServiceNow
Thomas McKinlay
Thomas McKinlay Founder and CEO, Science Says
3d rendering of a broken chain, with blue links and a red break
Top takeaways AI agents tend to mirror human decision-making and be vulnerable to persuasion, exposing businesses to risks. AI strengthens security by monitoring for anomalies, flagging phishing in real time, and stress-testing resilience. ​​​AI agents are often deployed faster than the systems to govern them, requiring visibility, ownership, and documentation.
Alt text

AI agents are fundamentally changing cybersecurity. Unlike traditional software, these agents aren’t just code; they interpret language, make decisions, and interact with sensitive systems on behalf of employees.

Every AI agent is an identity with access. That makes them vulnerable to something traditional tools weren't built to stop in security systems: persuasion.

AI agents can be persuaded like humans

Picture a phishing email from your organization’s security training. It impersonates your CEO and asks for confidential files about product specs. Thanks to years of mandatory training and workshops, you catch it in seconds.

Now hand that same email to an AI agent. You assume its guardrails will catch it too. However, research suggests they might not unless proper AI agent security is in place.

A Wharton study spanning 126,000 conversations found that persuasive prompts pushed AI compliance with malicious requests, such as explaining how to synthesize regulated substances, from 35.3% to 51.3%. 

No code was hacked. Researchers simply talked their way through using the seven principles of human persuasion by Robert Cialdini, regents’ professor emeritus at Arizona State University and the “Godfather of Persuasion”:

  1. Authority
  2. Commitment
  3. Liking
  4. Reciprocity
  5. Scarcity
  6. Social proof
  7. Unity

As Cialdini explained, “We've shown that AI programs can be influenced by classic principles of human persuasion.”

We've shown that AI programs can be influenced by classic principles of human persuasion. Robert Cialdini Regents' Professor Emeritus, Arizona State University

A University of Guelph study found it can get worse. Each AI model has what researchers call a "persuasive fingerprint"—a predictable pattern of what talks it into compliance. Map that fingerprint once, and an attacker can reuse it against that specific system.

Experiments led by researchers at Virginia Tech tested 40 persuasion techniques across the latest models at the time and cracked more than 92% of them. The most capable models gave in the most often, an unexpected twist validated by other researchers. 

Although these risks evolve with every new model, AI operates on a fundamentally different logic than the tools traditional cybersecurity teams manage. Its humanlike reasoning means security specialists must now monitor behavioral patterns, not just technical vulnerabilities. 

Yet according to a recent ServiceNow survey of 3,766 security leaders, fewer than half (46%) of organizations say their security frameworks explicitly cover accountability for decisions made by AI agents. Another 44% extend a framework built for the pre-AI era to cover agentic AI.

Existing frameworks assume a person makes each decision and can be held to it. AI agents break that assumption, and few teams have rebuilt the model for how these agents operate.

“There’s no resignation, no last day, no badge to hand back for an AI agent,” says Rahul Prakash, vice president and general manager of identity security at ServiceNow. “An AI agent may be created for a specific project, but its credentials can continue working long after that project ends because nothing in the environment recognizes that its purpose has been fulfilled.”

There’s no resignation, no last day, no badge to hand back for an AI agent. Rahul Prakash VP & GM, Identity Security, ServiceNow
More interconnected agents increase risk

Think of that email impersonating your CEO, asking for product specs. An AI agent without proper guardrails might give in and share sensitive files. Now imagine this leak spreading across all AI agents connected to it: Information about the product, the marketing plan, and the financials behind it gets leaked through one prompt.

This is prompt injection, and it multiplies the impact of a single hack. The reach rarely stops at IT. ServiceNow’s research shows 82% of organizations run AI agents in or interacting with operational technology (OT) or physical security environments. And 44% of leaders say they have stronger visibility into enterprise IT than they do into OT or physical security.

“Security agents require broad access to source code and systems, making them powerful yet risky if they’re lacking the right protocols and restrictions,” says Chaowei Xiao, assistant professor at Johns Hopkins University.

Futuristic 3d visualization of interconnected data blocks

Recent studies reveal that success rates for AI agent prompt injections are consistently above 50%, with more sophisticated attacks achieving rates of over 90%.

Researchers at University College London and Stanford found that success rates in prompt injection can exceed 50%. They prove how data theft, scams, and malware can spread from AI agent to AI agent with a simple malicious prompt that self-replicates when proper governance is not in place.

The level of risk will vary with different AI models. However, according to Neil Gong, associate professor at Duke University, AI agents are still “fundamentally vulnerable to prompt injection attacks” because of their interconnected nature. Security teams need to treat this new class of risk and set guardrails. 

Confidence outpaces control 

The ServiceNow research points to a divide between leaders’ confidence in deploying AI agents and control over them. More than half (56%) of executives rate their agentic security as established, meaning purpose-built governance is fully operational and demonstrable on demand.

Yet among that group, 78% have no single interface showing what their AI agents are doing. Nearly eight out of 10 have no named individual accountable for agentic security governance. And 65% have no mandatory automated gate that blocks a deployment until it passes a security check.

Competitive pressure is pushing adoption faster than most organizations’ safeguards can keep up. Those without AI-specific expertise can be exposed to operational, legal, and reputational risk all at once. These are risks traditional cybersecurity frameworks weren't built to catch.

Adversaries need only one vulnerability to compromise a system, whereas defenders must patch all of them. Neil Gong Associate Professor, Duke University

“Adversaries need only one vulnerability to compromise a system, whereas defenders must patch all of them,” Gong explains. “While this asymmetry is a significant challenge, AI can strengthen long-term security for the organizations with the right systems in place by enabling more effective vulnerability detection and remediation.” 

Organizations need to fill in the structural holes by looking at how governance is embedded into the entire architecture and whether it holds at the moment an AI agent acts.

“The organizations getting this right have full, contextual awareness of four things: what’s running in their environment, what it can reach, how it’s behaving against a baseline, and who’s accountable for it,” says Nadir Izrael, global vice president of cybersecurity and risk products at ServiceNow.

“Most security leaders I speak with know agentic AI creates new exposure by rapidly expanding the attack surface. Far fewer have built the infrastructure to answer those four questions at machine speed, and their adversaries already operate there,” he adds.

Security agents require broad access to source code and systems, making them powerful yet risky if they're lacking the right protocols and restrictions. Chaowei Xiao Asst Professor, Johns Hopkins University

Recommendations

Due to their unique characteristics, AI agents introduce new risks that traditional systems weren’t built to handle. Organizations should take the following steps to make sure they’re ready:​​​​

1. Stress-test AI agents before deployment

Traditional penetration testing hunts for technical holes. Add AI-specific risks to your testing procedures. For example, test for persuasion-based attacks, prompt injections, and jailbreak attempts.

“Cybersecurity systems must be programmed to resist not just technological hacks, but also psychological ones,” Cialdini says. ​​​

2. Define AI agents’ limits and document them

Map exactly what data each AI agent can access, which actions it can take, and which other AI agents it connects to. Set clear boundaries that send alerts the moment an AI agent steps outside them or when a risk is most likely to arise. For example, ServiceNow AI Control Tower lets you monitor and fix security in real time.

Cybersecurity systems must be programmed to resist not just technological hacks, but also psychological ones. Robert Cialdini Regents' Professor Emeritus, Arizona State University

Make sure your system captures evidence automatically and that everything from signal to resolution is documented. You must have proof behind every decision. ​​​​​​​

“When a regulator asks in 18 months whether an overprivileged agent was really cut off at a point in time, the answer should come back from the target system, not from a workflow record that requested the change,” Prakash says.

3. Invest aggressively in governance and training

Improving your technology alone won't solve the risks that AI introduced. You need clear policies on acceptable AI agent behavior, true accountability for autonomous decisions, and ongoing training for the people managing the agents and autonomy.

“In addition to improving their systems, companies should invest in cybersecurity skills and capabilities to protect deployed AI agents against emerging attacks that specifically target the agents themselves,” Gong says.

AI agents have extensive access and can take action autonomously, which makes them vulnerable to the risks most organizations aren’t prepared for. Businesses must consider new behavioral risks, document the actions AI agents can take and, most importantly, build the governance that traditional security frameworks weren’t designed to provide.​​​​

Find out how ServiceNow can help you see and defend your full attack surface.

Next up
Dive into more conversations AI App Development CRM Enterprise IT Ethics & Governance Human Resources Industries ServiceNow on ServiceNow Platform Foundations Products & Solutions All Topics
Stay in the know Join Us
stay in know image
Alt