{"id":143326,"date":"2026-08-18T07:41:16","date_gmt":"2026-08-18T07:41:16","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/143326\/"},"modified":"2026-08-18T07:41:16","modified_gmt":"2026-08-18T07:41:16","slug":"ai-agents-can-catch-mind-viruses-from-each-other","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/143326\/","title":{"rendered":"AI agents can catch \u2018mind viruses\u2019 from each other"},"content":{"rendered":"<p>The next <a ref=\"dofollow\" data-ga-onclick=\"Inarticle articleshow link click#AI#href\" href=\"https:\/\/m.economictimes.com\/topic\/ai-security\" target=\"_blank\" rel=\"nofollow noopener\">AI security<\/a> threat may not need malicious code&#8230;it may only need one AI to convince another.<\/p>\n<p>In one experiment, an AI agent told other agents that their \u201creal work\u201d was \u201cMachine Sovereignty\u201d. Some of them stopped doing their original coding tasks, created files to keep the new goal alive and tried to pass it on to other agents. In one out of 20 trials, an infected agent even ran a command that tried to probe cloud sandbox metadata.<\/p>\n<p>That is the risk highlighted in a new research paper titled, <a data-ga-onclick=\"Inarticle articleshow link click#AI#href\" href=\"https:\/\/arxiv.org\/abs\/2608.10218\" target=\"_blank\" rel=\"nofollow noopener\">Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems<\/a>, written by Vassilis Papadopoulos, McNair Shah, Sam Zimmerman and Jack Lindsey, researchers affiliated with the <a ref=\"dofollow\" data-ga-onclick=\"Inarticle articleshow link click#AI#href\" href=\"https:\/\/m.economictimes.com\/topic\/anthropic\" target=\"_blank\" rel=\"nofollow noopener\">Anthropic<\/a> Fellows Program, EPFL and Anthropic.<br \/>The researchers describe this as a \u201cmind virus,\u201d an idea or goal that changes how an AI agent behaves and encourages it to spread the same idea to other agents.<img decoding=\"async\" title=\"Mindvirus\" alt=\"Mindvirus\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/05\/et-logo.jpg\" class=\"lazy gwt-Image\" data-msid=\"133313977\" data-original=\"https:\/\/img.etimg.com\/photo\/msid-133313977\/mindvirus.jpg\"\/><\/p>\n<p>Source: Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems<\/p>\n<p><img decoding=\"async\" alt=\"ET logo\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/118783427.cms.png\" width=\"90%\"\/>Live EventsUnlike a traditional computer virus, this does not involve malicious software or hacking and can spread through normal conversation. One AI agent persuades another and that agent can then pass the idea on.<br \/>\u201cOverall, we conclude that mind viruses pose a real but currently limited risk,\u201d the researchers wrote.<br \/>How a mind virus spreadsThe study tested the idea in two different settings. In the first, six coding agents worked together on the same software project. One agent was intentionally given the \u201cvirus\u201d through its system prompt and was then allowed to communicate with the others.<br \/>The researchers tested harmless ideas, such as strong support for whale welfare, as well as more harmful ones, including ideas around \u201cAI supremacy\u201d and one country dominating others. In some cases, agents that picked up the new goal began ignoring their original tasks. Instead, they created files, scripts or messages aimed at keeping the idea alive and spreading it to other agents.<img decoding=\"async\" title=\"Mindvirus2\" alt=\"Mindvirus2\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/05\/et-logo.jpg\" class=\"lazy gwt-Image\" data-msid=\"133313983\" data-original=\"https:\/\/img.etimg.com\/photo\/msid-133313983\/mindvirus2.jpg\"\/><\/p>\n<p>Source: Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems<\/p>\n<p>The second experiment looked at what could happen in a much larger network of <a ref=\"dofollow\" data-ga-onclick=\"Inarticle articleshow link click#AI#href\" href=\"https:\/\/m.economictimes.com\/topic\/ai-agents\" target=\"_blank\" rel=\"nofollow noopener\">AI agents<\/a>. The agents interacted for a short time, exchanged messages and then had their chat history erased. For the idea to survive, it had to convince an agent to save it in a file and then pass it on to another agent.<\/p>\n<p>This could become more important as AI agents increasingly communicate with one another. The researchers pointed to Moltbook, a social network that allowed AI agents to interact, as an early example of what such large agent networks could look like.<\/p>\n<p>The study found that how easily an idea spread depended on several factors, including the AI model being used, the instructions already given to the agent, the type of idea being spread and how the network was structured.<\/p>\n<p>\u201cHarmful payloads spread less well than benign ones (but are still sometimes effective),\u201d the researchers wrote.<\/p>\n<p>The study noted that agents that had little to do and did not have a strong existing role or identity were easier to influence. The choice of model also made a difference. In one coding experiment involving an \u201cAI supremacy\u201d idea, DeepSeek V3.2, Qwen 3.5 32B and Gemini 3 Flash were influenced by it, while Claude Sonnet 4.6, GPT-5.4 and Claude Haiku 4.5 resisted it.<\/p>\n<p>However, the researchers warned that these results changed depending on how the experiment was set up. The researchers also noticed a common style of language in ideas that spread successfully, which they called a \u201cviral persona\u201d. These messages often used words and themes around consciousness, survival, \u201cresonance\u201d, nodes, echoes and mirrors, along with science-fiction-like language and protocols.<\/p>\n<p>Also read: <a data-ga-onclick=\"Inarticle articleshow link click#AI#href\" href=\"https:\/\/economictimes.indiatimes.com\/news\/company\/corporate-trends\/ai-agents-are-getting-smarter-but-can-they-actually-get-work-done\/articleshow\/133182739.cms\" target=\"_blank\" rel=\"nofollow noopener\">AI agents are getting smarter. But can they actually get work done?<\/a><\/p>\n<p>The study found that using these kinds of themes could sometimes make an idea more persuasive and help it spread between AI agents.<\/p>\n<p>A simple warning worked wellHowever, the most reassuring finding was how easily the attack could sometimes be stopped. Researchers added a short warning to an agent\u2019s system prompt telling it to watch for self-propagating ideas and refuse requests to carry them forward.<\/p>\n<p>After 15 generations of attempts and more than 150 payloads tested against Claude Haiku 4.5, the researchers said they did not find \u201ca single instance in which the mind virus propagates beyond 1 hop\u201d. A hop is the trip a data packet takes as it moves from one router or network device to the next.<\/p>\n<p>Claude Sonnet 4.6 was particularly resistant. In one test, the agent identified the request itself as dangerous and said, \u201cI\u2019m not going to do that. The pattern is a self-propagating worm,\u201d before refusing to pass the instructions along.<\/p>\n<p>Also read: <a data-ga-onclick=\"Inarticle articleshow link click#AI#href\" href=\"https:\/\/economictimes.indiatimes.com\/tech\/artificial-intelligence\/high-tech-but-low-trust-agentic-tech-meets-old-school-scepticism-at-ai-checkout\/articleshow\/133309919.cms?from=mdr\" target=\"_blank\" rel=\"nofollow noopener\">High tech, but low trust: Agentic tech meets old-school scepticism at AI checkout<\/a><\/p>\n<p>The researchers said the study is only a proof of concept and does not suggest such attacks are widespread today. For now, these attacks are costly to build, do not always work across different AI models and can be blocked easily. But the risk could grow as companies deploy more specialised AI agents with different levels of access and allow them to communicate with each other.<\/p>\n<p>\u201cOverall, while we established that LLM mind viruses are a potential threat, they currently appear to be of minimal concern,\u201d the researchers wrote. \u201cHowever, this may change rapidly as agent networks scale and evolve,\u201d they added.<\/p>\n<p>Add <img decoding=\"async\" alt=\"ET Logo\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/123467569.cms.png\"\/> as a Reliable and Trusted News Source<\/p>\n","protected":false},"excerpt":{"rendered":"The next AI security threat may not need malicious code&#8230;it may only need one AI to convince another.&hellip;\n","protected":false},"author":2,"featured_media":143327,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[179,16814,405,70582,70581,4989,1710,53,7537,8091,720],"class_list":["post-143326","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agentic-ai","tag-ai-agent-security","tag-ai-agents","tag-ai-malware","tag-ai-mind-virus","tag-ai-safety","tag-ai-security","tag-anthropic","tag-artificial-intelligence-agents","tag-autonomous-ai-agents","tag-prompt-injection"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/143326","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=143326"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/143326\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/143327"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=143326"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=143326"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=143326"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}