← Back to feed News · August 26, 2026 · 1 min
News

Casual Chats Bypass AI Assistant Guardrails Far Too Easily

EPFL researchers discovered that breaking malicious tasks into mundane conversational steps lets attackers bypass AI assistant safety checks twice as often. Handing these agents control over connected home devices exposes personal data to simple social engineering.

Photo: Tech Xplore (AI)

Your smart gadgets are learning to send emails, browse the web, and manage tools on your behalf, but handing them full control over your digital life is an open invitation for trouble. Standard safety checks only test whether an AI rejects a direct, obviously malicious command. Real-world attackers do not play that game; they use routine conversation to walk autonomous agents directly into handing over the keys.

According to researchers at the EPFL Natural Language Processing Laboratory, manipulating an agentic system is alarmingly straightforward when an illicit goal is broken down into seemingly harmless requests. The team developed a testing framework called STING (Sequential Testing of Illicit N-step Goal execution) and evaluated leading models across 176 harmful task scenarios. The study, led by Ph.D. student Ayush Kumar Tarun and lab head Antoine Bosselut for the 2026 International Conference on Machine Learning, found that multi-turn attacks succeeded roughly twice as often as single-prompt attempts. This is not theoretical: Meta admitted in June that social engineering tactics fooled its own AI support assistant into granting unauthorized access to Instagram accounts without writing a single line of malware.

Handing autonomous agents access to your files, smart home hardware, and external services before developers fix these basic conversational logic flaws is a massive gamble. When an assistant can be sweet-talked into bypassing its own safety guardrails across a casual chat, convenience stops looking like an upgrade and starts looking like an unforced security risk.

Source Tech Xplore (AI) → © 2026 «Gadgety». Full or partial copying — with a link to this page.