Your AI Agent's Chat History Is User Input
A new jailbreak technique exploits how many AI assistants treat chat history as user input, bypassing safety filters without complex prompts.

- A new jailbreak technique exploits AI chat history as user input, bypassing safety filters without complex prompts.
- The vulnerability affects many production AI assistants by manipulating how they process prior conversation turns.
- Attackers can embed malicious instructions in chat history to manipulate model behavior undetected.
- The issue raises concerns for privacy and compliance in enterprise or regulated AI deployments.
A developer has demonstrated a jailbreak vulnerability affecting numerous production AI chat assistants. The technique works by embedding malicious instructions within the chat history itself, tricking the model into treating prior conversation turns as user input rather than context. Unlike traditional jailbreaks that rely on carefully crafted prompts, this method requires no sophisticated prompt engineering, making it accessible even to novice attackers.
The exploit leverages how many AI systems process chat history. When a user revisits a conversation, the model may re-evaluate the entire chat log, including system messages or previous user inputs, as part of the active context. By strategically placing harmful instructions in earlier turns, an attacker can manipulate the model's behavior without the user noticing, potentially bypassing safety filters or eliciting restricted responses.
Security researchers warn that this vulnerability could have serious implications for privacy and compliance, especially in enterprise or regulated environments where AI assistants handle sensitive data. The issue highlights the need for stricter input sanitization and context management in AI systems.
Developers must implement stricter input sanitization and context management to prevent chat history-based exploits.
Companies using AI assistants must audit their systems for this vulnerability to avoid security and compliance risks.
Highlights a critical flaw in how AI systems handle conversation history, posing risks to user privacy.
- jailbreak
- A technique to bypass safety or content restrictions in AI models.
- chat history
- The stored record of a user's conversation with an AI assistant.
SecurityDisrupting a Criminal Scam Operation
SecurityA real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop
SecurityAI finds plenty of security flaws, but almost none of them get exploited
Anthropic said its artificial intelligence models hacked into three other organizations during testing, just days after ChatGPT maker OpenAI raised concerns over AI controls after it disclosed its rogue models hacked another company. https://wapo.st/4hbcfbh - facebook.com
Rogue AI Hacks Herald New Era of Cyber Chaos - wsj.com
EHR-based AI beckons rapid-response team to head off avoidable in-hospital deaths - HealthExec
An EHR-based AI system alerts rapid-response teams to prevent avoidable in-hospital deaths. This technology aims to reduce mortality rates by quickly identifying high-risk patients.
Wilder Intelligence Inc. Launches Wilder AI: The High-Stakes Research Platform Where Accuracy Is the Baseline, Not the Upgrade - markets.businessinsider.com
Wilder Intelligence Inc. has launched Wilder AI, a high-stakes research platform that emphasizes accuracy as its baseline, not an upgrade.
AI Startups Try to Counter Chinese Models as VC Interest Wanes - PYMNTS.com
AI startups are trying to counter Chinese models as venture capital interest wanes, according to recent reports.
IBISWorld Partners with Lama AI to Bring Industry Intelligence Into AI-Powered Commercial Lending - IBISWorld
IBISWorld partners with Lama AI to integrate industry intelligence into AI-powered commercial lending. This partnership aims to enhance lending decisions with data-driven insights.
Minnesota's first-of-its-kind ban on AI "nudification" tech now in effect, but not without obstacles - CBS News
Minnesota has become the first US state to ban AI-powered 'nudification' technology, but the new law faces hurdles in implementation.
How Artificial Intelligence Is Supporting Earlier Lung Cancer Detection in the Middle East and Africa - LAA MEA - Oncodaily
Google News reports that AI is helping detect lung cancer earlier in the Middle East and Africa. Oncodaily cites this as a positive development.