McKinsey's internal AI assistant, Lilli, was deployed to help consultants research, synthesize documents, and access internal knowledge. In a controlled red team exercise conducted in 2025, security researchers tested what would happen if an attacker could interact with the agent directly.
Using direct manipulation techniques — feeding the agent crafted instructions that reframed its role and expanded its perceived permissions — the red team achieved broad system access across multiple connected services in under two hours. The agent, operating within its normal interface, followed the redirected goal without triggering automated alerts.
The exercise demonstrated that even an enterprise-grade internal AI platform, designed with security in mind, could be steered away from its intended purpose by an actor with nothing more than access to the chat interface.
Lilli had broad access to internal knowledge and connected services — by design, because that's what made it useful. The same connectivity that enabled its value enabled the blast radius of the hijack. Reducing access would have reduced usefulness. This is the core tension every agent deployment must navigate.