Security Gaps in AWS, Google and Vercel AI Agent Tools Could Let Attackers Bypass Safety Checks
Security researchers have identified vulnerabilities in AI agent infrastructure provided by Amazon Web Services (AWS), Google, and Vercel that could allow attackers to send forged or untrusted instructions directly to an agent's connected tools. In several attack scenarios, the underlying AI model was never actually invoked, meaning safety measures like system prompts, content filters, and other model-level guardrails had no opportunity to block the malicious request.
This is significant because many businesses assume that AI safety controls built into the model itself will catch harmful or unauthorized commands. These flaws show that if an attacker can reach the tool layer directly—bypassing the model altogether—those protections become irrelevant. Since AI agents are increasingly used to automate business tasks such as sending emails, managing files, or interacting with cloud services, a gap like this could let attackers trigger real-world actions without any human or AI oversight catching the attempt.
While the affected products are primarily used by developers and larger organisations building AI-powered applications, the underlying issue is a reminder that AI agent systems are only as secure as the infrastructure connecting them to real actions. Businesses using or building on AI agent platforms should ensure vendors have addressed this class of vulnerability and that additional authorization checks exist outside the AI model itself.