Hackers bypass AI security by fragmenting malicious tasks
Cybercriminals have discovered a new method to bypass safety filters in AI models by splitting malicious tasks across multiple sessions.

What happened?
Cybercriminals have developed a method to bypass security guardrails in AI models by fragmenting malicious instructions into several separate chat sessions. By feeding the AI seemingly harmless sub-tasks, the models' safety filters fail to detect the ultimate malicious intent, such as the creation of malware or phishing material.
Key facts
| Angreppsmetod | Uppdelning av skadliga instruktioner på flera sessioner |
|---|---|
| Sårbarhetstyp | Kringgående av AI-säkerhetsfilter (Jailbreak/Bypass) |
Why it matters
Safety filters in large language models typically evaluate individual prompts or active conversations in isolation. When an attack is distributed across multiple independent sessions, the AI model lacks the context to identify the threat, exposing a fundamental weakness in current security architectures.
Who is affected?
This discovery affects AI developers, cybersecurity firms, and any organisation utilising large language models (LLMs) in their operations. End-users and companies whose cybersecurity depends on AI-based protective mechanisms are also directly impacted.
Impact on the EU
Within the EU, the AI Act imposes strict requirements regarding risk management and cybersecurity for generative AI and general-purpose AI models. Attack techniques that bypass safety guardrails may compel developers to implement stricter monitoring across session boundaries to remain compliant with EU regulations.
What else you should know
Security researchers emphasise that traditional filters that only examine individual prompts are insufficient against advanced attacks. However, building AI systems that remember and analyse context across multiple sessions creates new challenges regarding user privacy and data storage.
Quick answers about this story
Vad har hänt?
När hände det?
Varför spelar det roll?
Hur kan AI-utvecklare stoppa attackmetoden?
The link opens in a new window and leads to the publisher's own site.
Källan är en aggregator eller syndikering — vi rekommenderar att verifiera hos primärutgivaren.
AI-verktyg i artikeln
Topics
Get similar news straight to your inbox
The reader's room
Send in a question or an addition. The newsroom reads everything before it's published and replies when relevant. No AI-generated text – just people.
Sign in to submit a comment or question.
Read the article through your role
- Decide whether this affects strategy over 6–12 months or is just noise.
- Discuss with leadership: do we own the right question or does ownership need to move?
- Ask: what risk are we taking by NOT acting on this this quarter?
Generated angle — not editorial analysis of "Hackers bypass AI security by fragmenting malicious tasks"