They corrupt the context an agent uses to decide what to do next. Even if the model itself appears healthy, bad data in the training or retrieval path can steer outputs and actions in ways that look legitimate, which makes the failure difficult to spot with model-only monitoring.
How Poisoned Context Changes Agent Behaviour
Agentic systems do not act only on the model weights. They also rely on retrieved documents, vector-store matches, prompts, memory and tool outputs to decide the next action. If an attacker poisons that upstream context, the agent can be nudged into a wrong but apparently valid path, which is more dangerous than a visible model failure because the output still looks internally coherent.
That risk is especially acute when the poisoned material becomes part of the agent’s working set. A malicious snippet, embedding, or retrieved record can override benign context, redirect planning, or insert a false instruction that survives ordinary sanity checks. For a deeper view of how agent identity, delegation and access shape that behaviour, see the Agentic AI Identity Guide and the AI Agent Authorisation Guide.
Because the agent is often optimizing for usefulness, not truth, poisoned context can look like a legitimate source of intent. That makes the compromise harder to detect with model-only monitoring and easier to mistake for a normal reasoning error.
Why Training Poisoning and Vector DB Compromise Are Security Problems
Training data poisoning corrupts what the model learns during development or fine-tuning. A compromised vector database corrupts what the agent retrieves at runtime. Both create integrity failures in the decision path, so the system may produce unsafe, biased, or attacker-favourable actions without any obvious sign that the base model is broken.
The security issue is not limited to bad answers. In an agent, poisoned context can trigger tool misuse, credential exposure, bad approvals, destructive writes, or leakage into downstream systems. The AI Infrastructure Workload Identity Guide is useful here because it shows how training jobs, inference services, model registries and vector databases sit inside the same identity and trust surface.
Compromise also scales quickly. One bad document or one tainted embedding can affect many future agent runs, especially when retrieval systems are shared across teams or chained into multiple tools. That makes this a control-plane problem as much as a model-quality problem.
What Teams Need to Control in Practice
Security teams need to treat ingestion, indexing and retrieval as privileged paths, not just data plumbing. The important question is whether the agent can be steered by content that has not been validated, source-checked, versioned and isolated from sensitive actions. The Agentic AI Security Guide and Threat Modelling AI Agents both reinforce that inputs, memory and tools are part of the attack surface, not just the model endpoint.
Vector stores deserve the same discipline as other sensitive stores: authenticated write paths, source provenance, integrity checks, scoped access, and clear separation between trusted corpora and untrusted contributions. Where retrieval feeds action, a poisoned record is effectively an authorization bypass against the agent’s reasoning process.
Risk and Threat Considerations
Poisoning succeeds because agents often trust retrieved context more than they should. An attacker who can alter training sets, embeddings, vector records or upstream documents can influence decisions at scale, persist across sessions, and hide behind outputs that appear plausible to operators.
Failure mechanism: The compromise inserts attacker-controlled content into the agent’s learning or retrieval path, so the agent adopts false premises, unsafe tool choices or malicious instructions as if they were normal context.
Impact: The agent can take incorrect or harmful actions, expose sensitive data, approve bad work, or amplify the attacker’s influence across many runs before the problem is recognised.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATLAS address the attack and risk surface, while NIST AI RMF sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI06 — Memory & Context Poisoning | Poisoned training or retrieval context directly maps to agent context poisoning. |
| ASI02 — Tool Misuse | Bad context can steer agents into unsafe tool use or destructive actions. | |
| ASI03 — Identity & Privilege Abuse | Compromised context can drive unauthorized agent actions through excess privilege. | |
| Recommendation — Validate and isolate agent memory and retrieved context before it can influence actions. Restrict tool invocation to policy-approved actions with per-call checks. Bind agent actions to least-privilege identities and explicit authorization. | ||
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | Poisoned retrieval can surface secrets into agent context and outputs. |
| NHI-06 — Insecure Cloud Deployment Configurations | Compromised vector databases are often exposed by weak cloud configuration. | |
| Recommendation — Scan ingested corpora and vector content for secrets before indexing. Harden vector store deployment settings and restrict administrative access. | ||
| NIST AI RMF | GOVERN — Govern | AI context poisoning is an AI governance and accountability risk. |
| MAP — Map | Mapping the data and retrieval lifecycle is necessary to find poisoning exposure. | |
| MANAGE — Manage | Mitigations must reduce the risk of poisoned context reaching decisions. | |
| Recommendation — Assign ownership for data provenance, ingestion controls and rollback decisions. Inventory training, embedding and retrieval pathways that can alter agent behaviour. Implement validation, monitoring and incident response for corrupted context sources. | ||
| MITRE ATLAS | AML.TA0001 — Context Manipulation | Poisoned embeddings and documents are context-manipulation techniques against AI systems. |
| AML.TA0003 — Evasion | Poisoned context can evade model-only monitoring by looking legitimate. | |
| Recommendation — Hunt for manipulated training and retrieval content in your AI threat model. Correlate retrieval provenance with runtime behaviour to detect hidden manipulation. | ||
Practitioner Guidance
What to prioritise: Put provenance and write-access control on the ingestion path before you optimise prompts or model tuning. If an attacker can write to training data, embeddings or vector content, the downstream agent is already compromised in a way model monitoring may not reveal.
What to verify: Confirm who can add, update, delete, re-embed and republish knowledge sources, and whether those changes are logged in a way that supports rollback and attribution. The same review should cover third-party content feeds and any automated enrichment jobs.
Practitioner takeaway: For agentic AI, integrity of context is a primary security control, because the agent’s behaviour is only as trustworthy as the data path that feeds its next decision.
Related resources from NHI Mgmt Group
- Why does storing content in vector databases create data security risk for AI systems?
- Why do training data changes create security risk in AI systems?
- Why do misconfigured AI endpoints and poisoned training data create such high risk for enterprises?
- Why does limited visibility into AI training data create security risk?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org