Microsoft Flags Emerging Agentic AI Security Risks, Urges SBOMs to Track Components
Agentic AI can autonomously break down tasks, invoke tools and access external data, but it also broadens the attack surface for prompt injection, privilege abuse and supply-chain attacks. Microsoft said companies that lack visibility into the plugins, prompt templates and code dependencies used by agents will struggle to trace vulnerabilities and assess the impact of incidents, making software bills of materials, or SBOMs, essential.
Microsoft has updated its Taxonomy of Failure Modes in Agentic AI Systems to version 2.0, adding seven categories of emerging risks, including goal hijacking, visual attacks targeting computer-use agents, or CUAs, and context contamination. It also recommended that companies apply software supply-chain governance practices by creating an SBOM for each AI agent, with a complete record of plugins, prompt templates, model configurations and code dependencies to support continuous audits and incident response.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →