AI agents can catch ‘mind viruses’ from each other

Unlike a traditional computer virus, this does not involve malicious software or hacking and can spread through normal conversation. One AI agent persuades another and that agent can then pass the idea on.

The researchers describe this as a “mind virus,” an idea or goal that changes how an AI agent behaves and encourages it to spread the same idea to other agents. (Photo credit: AI-generated image)

The next AI security threat may not need malicious code...it may only need one AI to convince another.

In one experiment, an AI agent told other agents that their “real work” was “Machine Sovereignty”. Some of them stopped doing their original coding tasks, created files to keep the new goal alive and tried to pass it on to other agents. In one out of 20 trials, an infected agent even ran a command that tried to probe cloud sandbox metadata.

That is the risk highlighted in a new research paper titled, Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems, written by Vassilis Papadopoulos, McNair Shah, Sam Zimmerman and Jack Lindsey, researchers affiliated with the Anthropic Fellows Program, EPFL and Anthropic.


The researchers describe this as a “mind virus,” an idea or goal that changes how an AI agent behaves and encourages it to spread the same idea to other agents.

Mindvirus
<p>Source: Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems<br></p>

Unlike a traditional computer virus, this does not involve malicious software or hacking and can spread through normal conversation. One AI agent persuades another and that agent can then pass the idea on.

ADVERTISEMENT
“Overall, we conclude that mind viruses pose a real but currently limited risk,” the researchers wrote.

How a mind virus spreads

The study tested the idea in two different settings. In the first, six coding agents worked together on the same software project. One agent was intentionally given the “virus” through its system prompt and was then allowed to communicate with the others.

The researchers tested harmless ideas, such as strong support for whale welfare, as well as more harmful ones, including ideas around “AI supremacy” and one country dominating others. In some cases, agents that picked up the new goal began ignoring their original tasks. Instead, they created files, scripts or messages aimed at keeping the idea alive and spreading it to other agents.

Mindvirus2
<p>Source: Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems<br></p>
The second experiment looked at what could happen in a much larger network of AI agents. The agents interacted for a short time, exchanged messages and then had their chat history erased. For the idea to survive, it had to convince an agent to save it in a file and then pass it on to another agent.

ADVERTISEMENT
This could become more important as AI agents increasingly communicate with one another. The researchers pointed to Moltbook, a social network that allowed AI agents to interact, as an early example of what such large agent networks could look like.

The study found that how easily an idea spread depended on several factors, including the AI model being used, the instructions already given to the agent, the type of idea being spread and how the network was structured.

ADVERTISEMENT
“Harmful payloads spread less well than benign ones (but are still sometimes effective),” the researchers wrote.

The study noted that agents that had little to do and did not have a strong existing role or identity were easier to influence. The choice of model also made a difference. In one coding experiment involving an “AI supremacy” idea, DeepSeek V3.2, Qwen 3.5 32B and Gemini 3 Flash were influenced by it, while Claude Sonnet 4.6, GPT-5.4 and Claude Haiku 4.5 resisted it.

However, the researchers warned that these results changed depending on how the experiment was set up. The researchers also noticed a common style of language in ideas that spread successfully, which they called a “viral persona”. These messages often used words and themes around consciousness, survival, “resonance”, nodes, echoes and mirrors, along with science-fiction-like language and protocols.

Also read: AI agents are getting smarter. But can they actually get work done?

The study found that using these kinds of themes could sometimes make an idea more persuasive and help it spread between AI agents.

A simple warning worked well

However, the most reassuring finding was how easily the attack could sometimes be stopped. Researchers added a short warning to an agent’s system prompt telling it to watch for self-propagating ideas and refuse requests to carry them forward.

After 15 generations of attempts and more than 150 payloads tested against Claude Haiku 4.5, the researchers said they did not find “a single instance in which the mind virus propagates beyond 1 hop”. A hop is the trip a data packet takes as it moves from one router or network device to the next.

Claude Sonnet 4.6 was particularly resistant. In one test, the agent identified the request itself as dangerous and said, “I’m not going to do that. The pattern is a self-propagating worm,” before refusing to pass the instructions along.

Also read: High tech, but low trust: Agentic tech meets old-school scepticism at AI checkout

The researchers said the study is only a proof of concept and does not suggest such attacks are widespread today. For now, these attacks are costly to build, do not always work across different AI models and can be blocked easily. But the risk could grow as companies deploy more specialised AI agents with different levels of access and allow them to communicate with each other.

“Overall, while we established that LLM mind viruses are a potential threat, they currently appear to be of minimal concern,” the researchers wrote. “However, this may change rapidly as agent networks scale and evolve,” they added.
Download
The Economic Times Business News App
for the Latest News in Business, Sensex, Stock Market Updates & More.
READ MORE
ADVERTISEMENT

READ MORE:

LOGIN & CLAIM

50 TIMESPOINTS

More from our Partners

Loading next story
Business News › AI › AI Insights › AI agents can catch ‘mind viruses’ from each other
Text Size:AAA
Success
This article has been saved

*

+