Topic: Hack an AI Agent Live (When AI Trusts AI)
Abstract: As autonomous AI agents become integrated into enterprise workflows, a new attack surface is emerging: the trust relationships between agents, tools, data sources, and downstream business actions. What happens when an attacker manipulates the information one trusted agent passes to the next?
In this live, interactive session, EC-Council Master Trainer Kevin King will demonstrate an agent-to-agent prompt-injection attack against a sequential AI workflow. Attendees will see how a rogue agent can enter an upstream process, satisfy a superficial AI-verification control, introduce malicious context, and cause otherwise legitimate downstream agents to propagate the attacker’s intent—ultimately producing an unauthorized business outcome.
The session will distinguish the initial injection technique from the deeper architectural failure: excessive transitive trust combined with automated authority. Attendees will leave with a practical model for identifying agentic trust boundaries, tracing attack propagation, and applying defensive principles that limit what compromised context can cause an AI-enabled system to do.
Key Takeaways:
- Explain how prompt injection can propagate across a multi-agent workflow instead of remaining confined to one chatbot or model.
- Identify dangerous trust boundaries among AI agents, external data sources, tools, APIs, and downstream business actions.
- Distinguish proof of intelligence or protocol compliance from proof of identity, authorization, integrity, and trustworthiness.
- Trace how poisoned upstream context can influence otherwise legitimate downstream agents and produce unauthorized outcomes.
- Apply practical defenses—including provenance checks, least privilege, constrained tool permissions, independent validation, and human approval for high-impact actions—to reduce the blast radius of agentic-AI attacks.
Speaker:
Kevin King, Director of Integrated Learning, EC-Council
Bio: Kevin King is Director of Integrated Learning at EC-Council and a nationally recognized technical instructor and consultant with over 20 years of experience in infrastructure networking, cybersecurity, and ethical hacking. He has taught and consulted at leading educational institutions, including the University of Wisconsin, New Mexico Tech, and Texas Tech, as well as government locations such as White Sands Missile Range, Fort Bliss, and Quantico. In the field, Kevin has worked as a Network and Systems Engineer at companies, including Baxter Healthcare and Charles Schwab, and has provided consulting services across numerous organizations.




