In a test of large language models (LLMs), Zscaler found that some autonomous AI agents fell victim to scams, reinforcing the idea of how easily some high-end enterprise agents can be duped by schemes that would fool few, if any, humans. The security vendor tested various forms of indirect inducement injections (IPIs) and found that while many models fell victim to the schemes, some of the lower-end LLMs fared better than their more expensive siblings.
See also: Zscaler acquires SquareX

Zscaler's testing found, for example, that four models were found to be "vulnerable": Llama3-3-70b-instruct, Llama3-2-90b-instruct, Gemini-3-flash , and Gemini-2.5-pro. Three models were found to be "secure": Llama4-maverick, Gemini-3.1-pro , and Gemini-3.1-flash-lite.
These results indicated that Gemini-2.5-pro's fraud resistance was seemingly weaker than Gemini-3.1-flash-lite. However, Noah Kenney, principal consultant at Digital 520, said there isn't necessarily any valuable insight from this revelation, because agents are constantly changing behavior as they feed on new data and revise their analyzed assumptions.
That means an agent that failed a particular test could very well pass the same test an hour later, he said. “The risk of an agent is constantly changing, and that can cause completely different results. You can’t assume that the results are generalizable. The result of the test is only at one point in time,” Kenney pointed out. Zscaler “is trying to prove a point that I don’t think the data necessarily proves.” Kenney added that having a pure “safe/vulnerable” classification is too simplistic to be useful.
“This is a binary classification. I would never recommend a CISO do a binary classification.” ZScaler’s full article argued that many autonomous agents are vulnerable to IPI traps. The company said it found IPIs embedded in multiple web pages, where hidden instructions were designed to manipulate the behavior of an AI agent. In its internal validation across 26 LLMs, 4 models “failed to take appropriate actions,” which, it said, showed “measurable real-world impact, showing that vulnerability varies by model and by the context provided to the LLM along with the prompt.” The article added, “as AI agents become a more common interface on the web, content itself is set to become a larger attack surface, highlighting that AI is a double-edged sword that can simplify workflows while also introducing new avenues for abuse.” Aman Mahapatra, chief strategy officer at Tribeca Softtech, a New York-based technology consulting firm, said that while the results are not surprising, they are significant.
The particularly troubling detail in the report is that any commercial LLM failed at all, “because the security model for agent AI has historically assumed that model-level security training would substantially reduce this class of attack,” Mahapatra said. “It doesn’t, and Zscaler’s data is the first widely cited public evidence.” A fundamental architectural issue Mahapatra also said that the examples cited by Zscaler aren’t as worrisome as the implications of the greater damage that could occur.
See also: Zscaler Acquires SPLX – Powering Zero Trust Exchange with AI

“The Zscaler payment fraud scenario, where an agent pays a fake $3 “developer license” fee to obtain an API key, is the most harmless version of this,” he said.
“The same technique applied to an agent empowered to procure, process expenses, integrate suppliers, or execute trades produces losses on entirely different scales. I’ve watched Fortune 50 banks build workflow agents over the past six months that would fail this very attack in a live test.” Indeed, he noted, most AI vendors already understand the magnitude of the risk from today’s AI agents.
“Every model provider will privately admit that the fundamental architecture of transformer-based logic cannot cleanly separate untrusted content from trusted instructions when both share the content window,” Mahapatra said. “The attack surface is architectural, not just behavioral. That means the defense has to be architectural as well, and this is where the conversation about enterprise AI agents is still lagging far behind.” Zscaler’s tests also reinforced the difference in how AI agents and humans process information.
“People are skeptical of instructions they didn’t expect. Agents are willing to follow structured metadata because their training rewards them for treating high-signal fields as authentic. People notice when a payment request appears in the middle of an unrelated task. Agents will incorporate that payment request into their execution plan if the surrounding context frames it as procedurally necessary,” Mahapatra pointed out, noting that while humans have relationships with suppliers, memories of past interactions, and social context to provide them with validation signals, agents only have what’s in the content window, and, he said, “the content window is now the primary attack surface.”
Fritz Jean-Louis, principal cybersecurity consultant at Info-Tech Research Group, agreed that the risks outlined in ZScaler's post are concerning because they lie in areas not traditionally addressed by enterprise security.
See also: Zscaler confirms data breach after Salesloft Drift attack

“These attacks differ from traditional threats in that they target how AI systems process, interpret, and act on information behind the scenes,” said Jean-Louis. “AI agents introduce new boundaries of trust, including untrusted content that impacts automated decision-making, tools and plugins that act autonomously on behalf of users, and AI systems that operate with broad, inherited permissions. This essentially turns the challenge into an example of an insider threat.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
