06/15/2026
Agentic AI systems can be hijacked by malicious instructions hidden in the content they read, no hacking required, yet existing cybercrime law leaves this threat largely unaddressed.
Examining indirect prompt injection through the lens of the Computer Fraud and Abuse Act, Thej Khanna argues that Congress should expand the CFAA's definition of unauthorized access to cover agent-mediated attacks and establish a negligence-based duty of care for developers who fail to protect against these vulnerabilities.
Read More: https://www.cornellpolicyreview.com/ignore-prior-instructions-how-indirect-prompt-injection-falls-through-the-cracks-of-cybercrime-law/