AI-assisted attacks can connect reconnaissance, exploitation and data access into a faster operation. The useful question for a defender is not simply, “Was AI involved?” It is, “What happened, what authority applied, and what evidence supports the next action?”
Anthropic's September 2026 threat intelligence report describes selected cases it disrupted between December 2025 and August 2026. Its investigators observed AI used for execution and orchestration while humans set objectives and reviewed results. Those observations are not a measure of every attack. Read Anthropic's report.
There are two distinct problems: an outside attacker may use an AI agent against your systems, and an attacker may plant instructions to manipulate an agent your organisation operates. Unit 42 has documented indirect prompt-injection attempts that sought information leakage or unauthorised action; an attempted injection does not prove the target followed it. Read Unit 42's research.
Look for a sequence, not an AI fingerprint
Imagine a service account reading unusual records, creating a credential and sending data to an unfamiliar destination. This is a hypothetical example, not a DGM customer incident or detection result. Each action may have a benign explanation. Together they warrant an investigation of the account, owner, task, permissions, timing and outcome.
Network telemetry may show destinations and timing but cannot reliably reveal every prompt, application action or permission inside encrypted traffic. Application, identity and agent-tool logs provide other pieces. A repeatable investigation therefore asks:
- Identity and authority: Who or what acted, and what was permitted?
- Sequence: Which source records connect the activity, and which are missing?
- Interpretation: What hypotheses fit the evidence, including benign alternatives?
- Outcome: Was an action refused, alerted on or completed?
- Response: Who may approve a change, and what would verify its effect?
An agent-like traffic pattern is not proof that AI was used, still less proof of a particular provider. “Intent” is an evidence-backed hypothesis, not mind-reading. Uncertainty should remain visible when telemetry cannot settle the question.
Bound agents before an incident
Microsoft recommends layered defences against indirect prompt injection: isolate untrusted content, limit privileges, review risky tool sequences and use human verification for sensitive actions. It cautions that no single defence is sufficient. Read Microsoft's guidance.
An agent deployment should make its permitted task, tools, destinations and revocation path explicit. Investigators need enough audit evidence to reconstruct actions without retaining unnecessary private content. A written instruction to “be careful” is not an enforced permission boundary.
Containment is not the same as repair
Blocking a connection might interrupt one incident while leaving a credential or configuration weakness intact. A responsible response record separates observed facts, authorised actions and post-change evidence. Retest the suspicious path and a legitimate counterpart; do not call a repair verified merely because an alert closed. Read our verified-remediation methodology.
How Deep Grey Matter solves this problem
DGM Intent is in beta testing as an evidence-led investigation layer. It normalises permitted source records into episodes, presents likely-intent hypotheses with supporting evidence, alternatives and unknowns, and lets an analyst review the underlying trail. An initial business evaluation would be a scoped, passive Exposure Baseline for an internet-facing API estate, with source permissions and success criteria agreed in advance.
Its demonstration includes synthetic network, application, database and AI-agent examples. Those examples and lab tests do not establish customer detection effectiveness or production coverage. Protection, repair and retesting paths are being evaluated in controlled environments; no verified customer remediation outcome is claimed. Material changes would require the organisation's explicit authority.
That is the solution we are testing: make the evidence and its limits clear enough for a security team to decide what matters and what to do next. Explore DGM Intent or apply for business early access. Joining the waitlist does not activate protection.
