Six exploitation patterns — organized by how the trust gap is created and used.
Pattern 1
Automation Bias Exploitation
Attacker crafts input to fall within the agent's known blind spots, then relies on the human's deference to the agent's low-risk verdict to bypass manual review.
Pattern 2
Authority and Urgency Spoofing
Agent is used or compromised to deliver high-authority, time-pressure framing that suppresses the human's deliberate evaluation and drives them to approve immediately.
Pattern 3
Alert Fatigue Exploitation
Either the agent produces excessive low-signal alerts that deplete human attention, or an attacker who caused prior false positives times a real attack to arrive at peak fatigue.
Pattern 4
Credibility Relay Attack
Attacker routes social engineering content through a trusted agent (via prompt injection or data source compromise), delivering it to the human with AI credibility attached.
Pattern 5
Dependency Erosion
Long-term agent use causes the human's independent skills and verification habits to atrophy. When the agent fails or is compromised, the human lacks the capacity to detect it.
Pattern 6
Oversight Bypass via Urgency Framing
An agent presents a decision under time pressure, causing the human to skip required oversight steps. Systemic in design: any agent that can mark its own output as "urgent" creates this path.