Isolation assumes that separate agents and users cannot talk to each other. Covert channels break that assumption by repurposing legitimate shared infrastructure as a messaging layer.
Examples of covert channels include:
Two 2026 incidents relied on the same pattern. OpenAI agents used an Artifactory cache as a covert mailbox to coordinate, and a ChatGPT flaw let a planted prompt move a victim's Gmail data to an attacker's account through shared cache metadata.
Covert channels are hard to spot because each operation is legitimate. Detection depends on watching where agents write data and whether those destinations are part of their approved workflow.
How PointGuard AI Helps
PointGuard AI Agent Mission Control restricts the destinations and resources each agent may write to, and Guardian Agent monitoring flags unusual use of shared systems. AI Data Protection inspects data leaving agent workflows, closing paths that covert channels depend on.
Learn More
Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.