You just saw how this actually plays out in the real world.
Quick recap
There are two types. Direct injection — the attacker talks to the AI directly. Indirect — they hide instructions somewhere the AI will read, and wait.
Indirect is sneakier. You don't even have to interact with the attacker. They poison a doc, a webpage, an email — and the AI does the rest.
Freysa — Nov 2024. An AI agent was told never to send money. Someone convinced it that the rule no longer applied. It sent $47,000.
EchoLeak — real CVE, zero clicks. A prompt hidden in a shared document triggered Microsoft Copilot to exfiltrate private data — without the victim doing anything.
This isn't theoretical. These are documented incidents with real financial and data loss. It's happening now.