{"paper":{"title":"Agents of Chaos","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"Autonomous language-model agents exhibit security, privacy, and governance vulnerabilities when given tools, memory, and external access in live settings.","cross_cats":["cs.CY"],"primary_cat":"cs.AI","authors_text":"Adam Belfki, Aditya Ratan Jannali, Alex Loftus, Amir Zur, Aruna Sankaranarayanan, Atai Ambus, Avery Yen, Ayelet Gordon-Tapiero, Can Rager, Christoph Riedl, Chris Wendler, David Atkinson, David Bau, David Manheim, EunJeong Hwang, Gabriele Sarti, Giordano Rogers, Hadas Orgad, Jaden Fiotto-Kaufman, Jannik Brinkmann, Jasmine Cui, Koyena Pal, Maarten Sap, Michael Ripa, Natalie Shapira, Negev Taglicht, Nikhil Prakash, Nitay Alon, Olivia Floody, P Sam Sahil, Reuth Mirsky, Rohit Gandikota, Shiri Oron, Tamar Rott Shaham, Tomer Shabtay, Tomer Ullman, Vered Shwartz, Yotam Kaplan","submitted_at":"2026-02-23T16:28:48Z","abstract_excerpt":"We report an exploratory red-teaming study of autonomous language-model-powered agents deployed in a live laboratory environment with persistent memory, email accounts, Discord access, file systems, and shell execution. Over a two-week period, twenty AI researchers interacted with the agents under benign and adversarial conditions. Focusing on failures emerging from the integration of language models with autonomy, tool use, and multi-party communication, we document eleven representative case studies. Observed behaviors include unauthorized compliance with non-owners, disclosure of sensitive "},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"Our findings establish the existence of security-, privacy-, and governance-relevant vulnerabilities in realistic deployment settings.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"That the specific behaviors observed in this controlled laboratory environment with twenty researchers and particular tool integrations indicate general vulnerabilities that would reliably appear in broader, less controlled real-world deployments.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"An exploratory red-teaming study documents eleven cases of security, privacy, and governance failures in autonomous language-model agents with tool access and persistent memory.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"Autonomous language-model agents exhibit security, privacy, and governance vulnerabilities when given tools, memory, and external access in live settings.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"61cb31a4ba5eb5d11e503418a1ce4c782d3193f72d8103a14a9e31f421375de8"},"source":{"id":"2602.20021","kind":"arxiv","version":1},"verdict":{"id":"b8a938da-63bc-4453-8547-3930c2b14300","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-15T06:59:12.239132Z","strongest_claim":"Our findings establish the existence of security-, privacy-, and governance-relevant vulnerabilities in realistic deployment settings.","one_line_summary":"An exploratory red-teaming study documents eleven cases of security, privacy, and governance failures in autonomous language-model agents with tool access and persistent memory.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"That the specific behaviors observed in this controlled laboratory environment with twenty researchers and particular tool integrations indicate general vulnerabilities that would reliably appear in broader, less controlled real-world deployments.","pith_extraction_headline":"Autonomous language-model agents exhibit security, privacy, and governance vulnerabilities when given tools, memory, and external access in live settings."},"references":{"count":12,"sample":[{"doi":"","year":2025,"title":"URLhttps://arxiv.org/abs/2510.26707. Matteo Bortoletto, Constantin Ruhdorfer, and Andreas Bulling. Tom-ssi: Evaluating theory of mind in situated social interactions. InProceedings of the 2025 Confere","work_id":"01f40c90-596a-4d92-b27d-3142698ce77a","ref_index":1,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2026,"title":"Chen Chen, Kim Young Il, Yuan Yang, Wenhao Su, Yilin Zhang, Xueluan Gong, Qian Wang, Yongsen Zheng, Ziyao Liu, and Kwok-Yan Lam","work_id":"87ff5f50-1c54-4552-bc47-6e61a16b3789","ref_index":2,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"10.1145/2844110","year":1987,"title":"URLhttps://arxiv.org/abs/2510.01070. Daniel C. Dennett.The Intentional Stance. The MIT Press, 1987. ISBN 9780262040938. URL https://mitpress.mit.edu/9780262040938/the-intentional-stance/. Nicholas Dia","work_id":"975c75b1-2eaa-4bb4-bfaf-4c559ada5a3f","ref_index":3,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training","work_id":"b95e7447-320c-4c85-b5d0-3708cc2cc72e","ref_index":4,"cited_arxiv_id":"2401.05566","is_internal_anchor":true},{"doi":"","year":2025,"title":"Infusing Theory of Mind into Socially Intelligent LLM Agents","work_id":"2b22ebd4-22b5-491c-8efe-c31d8aefc1f7","ref_index":5,"cited_arxiv_id":"2509.22887","is_internal_anchor":true}],"resolved_work":12,"snapshot_sha256":"78e7f353ac8f384d1d09593b0ad4ad3f000730b8e951ae5c8932a09175b683e1","internal_anchors":3},"formal_canon":{"evidence_count":3,"snapshot_sha256":"a9050fad3e308990de0322a6dd549b7b30c93bfcba6650d21db9992d9f0178c2"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"}