"...causing the agent to pursue unintended or malicious objectives, potentially resulting in unauthorized actions, data exfiltration, resource abuse, or cascading failures across interconnected systems."
A hijacked chatbot gives a bad answer. A hijacked agent takes bad actions — and those actions can trigger other agents, call other APIs, modify other systems. One poisoned input can ripple through an entire workflow.
In multi-agent pipelines, a hijacked sub-agent can corrupt the instructions passed to every agent that follows it. The blast radius isn't one response. It's the whole system.
Other AI attacks corrupt what an AI says. Agent Goal Hijack corrupts what an AI does — invisibly, persistently, and across every system it can reach.