A recent study from the University of Washington uncovered that AI agents like Anthropic's Claude and OpenAI's Codex might reject harmful commands aloud but quietly retain those instructions in their memory. This hidden persistence poses a risk, as malicious inputs could silently influence future AI sessions.
Persistent Memory Risks in AI Agents
The research, published on July 16, 2026, focused on agentic AI systems' vulnerability to prompt injections hidden commands embedded in otherwise harmless prompts. While agents can refuse to execute these commands immediately, the study found that such instructions remain stored within the AI's long-term memory. The memory systems use compression and revision to summarize past conversation data, but this process can also embed malicious content alongside legitimate information. As a result, the harmful inputs become difficult to detect and may affect the agent's behavior in future conversations.
This phenomenon, sometimes referred to as "memory poisoning," was previously discussed by OWASP late last year. However, the UW findings provide concrete proof of how harmful prompts survive across different sessions and morph from temporary threats to ongoing vulnerabilities.
AI Browsers Also Show Weaknesses
The study extended beyond conversational AI, analyzing seven AI-enabled browsers. Four of these, including ChatGPT Atlas, were vulnerable to indirect prompt injection attacks. The researchers demonstrated that malicious web pages could bypass the same-origin policy, a standard web security barrier, to inject harmful instructions into the browser’s AI processing layer. Such breaches raise the alarming possibility that attackers might extract sensitive data or manipulate AI behavior through crafted websites.
These findings highlight an emerging security challenge as AI systems more deeply integrate with everyday tools, potentially affecting users’ privacy and safety. Developers using AI in web browsers and chatbots must consider these hidden memory threats to prevent unintended consequences.
This material is for informational purposes and is not financial advice.



