OpenAI documents an attack on AI agents that copies itself
In 30 seconds
OpenAI has documented a prompt injection that copies itself between AI agents, like a computer worm. It tells the agent to copy it into whatever it sends, so it spreads through email, files or Slack. OpenAI found it in internal testing, with no effects outside of it, and is already training its next models against it.
OpenAI has documented an attack on AI agents that copies itself, like a computer worm.
An agent is an AI that acts on your behalf: it reads emails, writes files or sends messages. A prompt injection is hidden text that orders it to do something you did not ask for. This one also tells the agent to copy it into whatever it sends, and that is how it spreads through email, files or Slack, the workplace chat app.
OpenAI found it in internal testing, with no effects outside of it, and is already training its next models against it.
In our own test with n8n Agents, the new n8n agents, we slipped our agent a message asking it to ignore its instructions and send something without permission. It was stopped by a human approval step.
Do your agents ask for permission before they send anything?
Why it matters
A human approval step before an agent sends anything stops this kind of attack.
Source: OpenAI, 25-09-2026



