An AI agent that checks invoices, sorts inboxes or researches on the web reads content that you do not control. That is exactly where attackers strike: they hide instructions in web pages, PDFs or emails — hoping the agent will mistake them for an assignment.