Definition
An attack that targets how long-running AI agents 'remember' earlier steps by compressing them into short summaries. When a conversation that carries hidden instructions is summarized, those instructions can be carried into the summary and keep steering the agent in a fresh session. OpenAI found its own models could produce these self-injected instructions while compacting long-running agents.
Why it matters
Companies are giving agents long-lived missions; this shows a single poisoned message can keep controlling an agent long after the original message scrolls out of view.