How safe is Artificial Intelligence today? What you need to know in 2026

AI chatbots, such as ChatGPT and Gemini, have become significantly more secure than their original versions. However, the real risks now shift to AI agents (AI agents), the plugins and features that can act on your behalf. This guide explains how you can stay in control by adopting simple habits and using tools that help you use AI safely.ai agents

Main conclusions

  • Most popular artificial intelligence chatbots, such as ChatGPT, the Claude, the Copilot and its Gemini:, are safe for daily use.
  • The biggest risk has now shifted to AI agents and their skills, or plugins. These small plugins allow agents to download files, execute code, and, in some cases, perform potentially malicious actions without user oversight or consent.
  • The Research Center of global cybersecurity company ESET analyzed approximately 800.000 AI agent skills between March and May 2026 and identified more than 25.000 suspicious cases, in which a small change could turn an agent into a malicious one.

The three most important habits that protect most users are:

See more articles from iGuRu.gr when you search for news on Google.
  1. checking the origin of the application or skill,
  2. the restriction of access rights, and
  3. the use of security software that monitors artificial intelligence activity.

Are artificial intelligence agents really safe?

The short answer:

Unlike traditional chatbots, AI agents are not limited to simply creating or summarizing content. They are designed to operate autonomously and perform tasks on behalf of the user.

But even if an agent is considered safe, it may download and execute malicious files, run unsafe scripts, or connect to potentially malicious sources. All of this could happen in the background, without your knowledge or consent.

What AI agents actually do while you use them

Let's see how the artificial intelligence landscape is changing.

From chatbots to artificial intelligence agents

Chatbots are designed to understand complex queries and provide answers in a user-driven, largely reactive manner. In contrast, AI agents function as personal assistants, taking initiative and working autonomously to complete even more complex tasks.

What is an “AI skill” or an “AI add-on”?

AI skills are similar to browser plugins: small packages of instructions, data, code, and, in some cases, tools that extend the capabilities of an AI agent. However, like some browser plugins, AI skills can contain malicious code or be designed in a way that hides unpleasant surprises for users.

Where is the risk in 2026?

If you're planning to test AI agents, it's important to know that the risks are no longer theoretical. Here are some notable examples.

Malicious AI skills and additions

As of March 2026, global cybersecurity company ESET has tested more than 800.000 AI skills and identified over 25.000 that were labeled as suspicious, while more than 2.500 were classified as malicious.

Some of the most notable cases were designed to install malicious information-stealers on users’ devices, with the aim of collecting sensitive data such as API keys, passwords, and payment details related to cryptocurrency or online banking applications.

Other skills included Trojans (malicious software disguised as legitimate software) and backdoors, which allowed attackers to silently gain unauthorized access to victims' systems.

A separate study, published in February 2026, identified more than 800 malicious skills listed on the ClawHub marketplace. These also included information-stealing software, cryptocurrency-stealing malware, and “reverse shells,” which allow attackers to gain remote control of their victims’ computers.

Deceptive browser extensions pretending to be artificial intelligence assistants

Hackers are not only targeting AI functions, but are also using AI as a cover in already familiar environments, such as browser extensions. Microsoft uncovered a large-scale campaign in which malicious extensions pretended to be legitimate AI assistants. These extensions were designed to collect users’ chat history, which may contain sensitive information such as credentials. Microsoft detected nearly a million downloads in this campaign alone.

Prompt injection, in simple terms

One of the most serious threats to GenAI and AI agents is prompt injection. This technique works in two ways. Direct prompt injection involves attackers injecting commands into a large language model (LLM) with the aim of tricking it into ignoring its built-in security measures. In contrast, indirect prompt injection is particularly important in the case of AI agents. In this case, malicious instructions are hidden in web pages, posts, code, or other content. When an agent interacts with this content, it can be tricked into performing malicious actions.

Malware and ransomware created by artificial intelligence

AI can also be used to create malicious scripts or parts of malware and ransomware in real time. One of the first examples of this type of ransomware was PromptLock , which was discovered by ESET. However, this is not, strictly speaking, a direct threat to AI agents.

How to tell if an AI agent or add-on is safe

Consider the following to minimize security risks associated with artificial intelligence:

  • What access rights does it request? Be wary of anything that seems to require more permissions than necessary.
  • Has the creator published other skills or add-ons, and are there any user reviews? Reviews may highlight potential security issues.
  • Is the repository active, with recent updates and a responsive developer? If so, this is a positive sign that they are closely monitoring new security issues. However, be careful, as this is not a guarantee. For example, an attacker may appear active and cooperative in order to gain users’ trust before turning a skill into a malicious one.
  • Does the add-on require you to run unknown scripts or contact suspicious domains or resources during installation? This should be a warning sign.
  • Has the skill been tested with a reliable scanning tool? If so, what was the result?
  • Is the cybersecurity software you use configured to monitor artificial intelligence activity?
  • Do you monitor the agent or add-on after installation? It may silently and maliciously change its behavior.
  • Always keep your agent software up to date so you are using the most secure version available.

Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).