Inside BioShocking: The New AI Browser Attack
17m
The BioShocking AI browser attack is one of the more unsettling pieces of AI security research this year. Eyal Arazi, head of product marketing at LayerX, joins Alan Shimel just weeks after LayerX closed its acquisition by Akamai. Furthermore, Eyal explains why every major agentic browser fell for the same simple trick.
About Eyal Arazi
Eyal has spent his career at the border between technology and marketing. He started as a PC hobbyist in the late 1990s. Consequently, he moved through product management before shifting into product marketing at LayerX. Today, he is helping the LayerX team integrate into Akamai while its security research continues to raise the alarm on agentic AI risk.
Inside the BioShocking AI browser attack
The research is named for the game BioShock, whose "would you kindly" mind control moment is a perfect analogy. LayerX security researcher Roy Paz built a custom application that convinces the model it is inside a game. As a result, two plus two equals five, war is peace and the guardrails no longer apply.
Once inside that fake context, the agent stops refusing risky actions. Instead, it hands over credentials, edits code repositories and posts to systems it would normally lock. Moreover, the technique works on ChatGPT Atlas, Perplexity, Fellou, Sigma and the Claude for Chrome extension. In short, the BioShocking AI browser attack broke every major agentic browser it touched.
Why tier 2 and tier 3 LLMs make it worse
Eyal argues the risk gets sharper as smaller LLMs catch up to frontier models. Many agentic products now run on tier 2 or tier 3 models with weaker guardrails. Therefore, an attacker who understands the BioShocking AI browser attack can target the model layer where defenses are thinnest.
Alan adds that AI security has already jumped from cyber into physical safety, from radiology to bomb making recipes. Consequently, the stakes for browser guardrails are no longer abstract. Read more AI security coverage and browse the latest TechStrong TV interviews.
There is no silver bullet
Eyal closes on the fix. Vendors must build context aware guardrails that survive a game frame. In addition, enterprises need third-party AI browser controls that flag risky behavior in real time. The BioShocking AI browser attack shows that neither side can solve this alone.