# A-034

- **Artifact ID:** A-034
- **Status:** ACTIVE
- **Public record:** https://record.cybersecurityhq.com/assumptions#A-034
- **Machine-record SHA-256:** `a59b55d55c6af76013442202731882e55bb88cc1ea3c3b7fd605bf7e86f0a10d`

## Complete structured record

```json
{
  "id": "A-034",
  "statement": "Agentic AI systems correctly distinguish between instruction input and data input based on input channel, source identity, or position in the execution context.",
  "status": "ACTIVE",
  "category": "Under Pressure",
  "ledger_references": [
    "2026-07-24 — In-the-wild prompt injection via poisoned web content (July 2026): Agent-hijacking campaigns crossed from demonstration to confirmed in-the-wild consumer operations through poisoned web content. Data-plane content successfully directed agent instruction execution in production deployments; the channel, source identity, and positional cues that should distinguish data from instructions did not prevent the override under adversarial construction. The instruction/data distinction does not hold when data is crafted to exploit the instruction-processing path."
  ],
  "evidence_count": 1,
  "last_updated": "2026-07-24",
  "related_positions": []
}
```
