

SpotEx offers 17 assets and 25 trading pairs for cryptocurrency spot trading.
Its proof-of-reserves system provides cryptographic verification of reported customer asset balances.
Coin voting, faucets, and listings give communities greater participation across exchange activities.
AI agents are increasingly moving beyond simple question-and-answer systems. They can retain information across interactions, access enterprise applications, retrieve data and take actions on behalf of users. As this technology becomes more persistent, cybersecurity experts are focusing on another part of the threat landscape: what AI agents remember.
Microsoft warned that AI memory can increase an AI system’s attack surface. Unlike systems without persistent memory, where an attacker may need to succeed in a single prompt, memory-enabled AI can let attackers influence behavior over time by planting information that affects an agent’s future reasoning.
AI memory allows systems to retain and recall information across interactions. This can improve personalisation by helping agents understand user preferences and provide continuity. It can also strengthen what Microsoft calls “agentic coherence”, allowing agents to build durable domain knowledge that supports performance.
However, memory serves another role. It stores valuable user information while also shaping agent behaviour and influencing tool calls. Microsoft said this means AI memory needs to be protected like customer data and governed with the same rigor as systems capable of taking action.
The security challenge becomes more complicated because memory events can happen asynchronously from user interactions, making traditional human-in-the-loop security patterns harder to apply.
One of the key risks is memory poisoning, in which attackers place malicious or misleading information into an agent’s stored context.
OWASP’s 2026 Top 10 for Agentic Applications identifies “Memory & Context Poisoning” as a specific risk. It describes scenarios in which adversaries corrupt or seed stored context, including conversation history, memory tools, summaries, embeddings and RAG stores. The corrupted information can later affect reasoning, planning or tool use.
Microsoft’s research also describes a hypothetical delayed tool-execution scenario. In the example, a user opens a shared document containing hidden instructions inserted by an attacker. The AI assistant processes the document but takes no immediate action. Microsoft describes this as delayed tool invocation, where the attack’s impact comes from the gap between the initial exposure and later execution.
Also Read: Silicon Valley Titans Reject AI Extinction Fears as Agentic AI Advances
The threat is not limited to hypothetical scenarios. Microsoft security researchers reported in February 2026 that they had identified attempts to use AI recommendation poisoning to manipulate what AI assistants remember and recommend. Over 60 days, researchers reviewing AI-related URLs in email traffic identified 50 distinct examples of prompt-based attempts to influence AI assistant memory.
The attempts came from 31 different companies and covered more than a dozen industries, including finance, health, legal services, SaaS, marketing agencies, food and recipe sites, and business services.
Microsoft said the effectiveness and persistence of these prompts varied between AI assistants and over time as persistence mechanisms and protections changed.
Microsoft’s approach to AI memory security covers storage, retrieval, model interaction and user control. For Microsoft 365 Copilot, memories pass through sanitization checks when they are created. Proprietary prompt-injection classifiers inspect content for malicious input, while Task Adherence checks are used for explicit memory writes.
Stored memories are governed by Microsoft 365 data policies, including Data Subject Requests, tenant isolation, Customer Lockbox and encryption at rest. Memory updates are also recorded in organisational audit logs, allowing security teams to trace what information was processed, what the system remembered and how that memory influenced later interactions.
Memory security also needs to work alongside identity and access controls. NIST said in August 2026 that enterprises should treat AI agents as first-class entities with their own unique identifiers, credentials, and associated entitlements. The agency warned that sharing personal or enterprise credentials with agents can create accountability, privacy and legal issues.
NIST also cautioned against long-lived API keys and access tokens. It recommended tightly scoped, dynamic credentials and highlighted standards including OAuth 2.0, SPIFFE, JSON Web Tokens and X.509 as foundations for agentic identity and authorisation.
As AI agents gain greater autonomy, enterprises will need visibility into both their actions and their memory. Microsoft’s 2026 red-team findings reported that cross-domain prompt injection and memory poisoning were frequently combined. The company said memory poisoning through cross-domain prompt injection could seed persistent memory after a single successful injection, allowing the effect to propagate across subsequent sessions.
NIST similarly said, “AI agents introduce security challenges that require adapting traditional cybersecurity practices. Its 2026 work focuses on areas including identification, authorisation, auditing, non-repudiation and controls against prompt injection.”
For enterprises, the emerging security requirement is therefore broader than protecting an AI model. Organizations also need to know what an agent remembers, where that information came from, who can access it, and how it can influence future actions.
Also Read: Magic Eden Probes Mystery NFT Transfers After Assets Move for Zero ETH
1.What is SpotEx?
SpotEx is a centralised cryptocurrency exchange offering spot trading, community features, API access, coin listings and proof-of-reserves disclosures.
2.How many assets and trading pairs does SpotEx offer?
SpotEx launched with 17 assets and 25 trading pairs, allowing users to trade cryptocurrencies across available spot markets.
3.What is a Spotex Coin (SPOT)?
Spotex Coin, or SPOT, is the exchange’s native internal coin and is available as a tradable asset on SpotEx.
4.What is SpotEx’s proof-of-reserves system?
SpotEx publishes asset reserves and customer obligations, supported by Merkle tree and SHA-256 cryptographic verification for greater transparency.
5.What community features does SpotEx offer?
SpotEx provides coin voting, cryptocurrency faucets and project listing options, allowing users and communities to participate beyond conventional cryptocurrency trading.
Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp
_____________
Disclaimer: Analytics Insight does not provide financial advice or guidance on cryptocurrencies and stocks. Also note that the cryptocurrencies mentioned/listed on the website could potentially be risky, i.e. designed to induce you to invest financial resources that may be lost forever and not be recoverable once investments are made. This article is provided for informational purposes and does not constitute investment advice. You are responsible for conducting your own research (DYOR) before making any investments. Read more about the financial risks involved here.