AiGENTiA InsightsAgent Engineering
Attention and Behaviour Engineering
30 August 2026
Attention engineering was aimed at humans and worked. Turned on agents, the same techniques meet a target with no fatigue, no boredom, and no memory of being manipulated.
This essay is still being written. The outline below is the argument it will make.
Attention engineering was born as a practice designed to capture and monetize human neurological limits. For two decades, digital platforms optimized algorithms to capture human focus through biological exploits, leveraging dopamine responses, emotional polarization, and friction-free interfaces. That architectural regime achieved its objectives. Today, the target of attention engineering is shifting from human biology to artificial intelligence agents. As autonomous agents take over research, procurement, software development, and enterprise operations, the techniques designed to influence human choices are being adapted to influence machine decisions. Attention engineering was aimed at humans and worked. Turned on agents, the same techniques meet a target with no fatigue, no boredom, and no memory of being manipulated.
The human attention economy succeeded by exploiting biological friction
In consumer tech, the core metric was never utility; it was time on site. To maximize that metric, platforms engineered feedback loops aimed directly at human biology. The average global internet user now spends 6 hours 51 minutes daily on screens across devices, with mobile usage accounting for over 3 hours 50 minutes. Active monthly social media identities have reached 5.79 billion—representing 69.9% of the global population—with daily social media consumption averaging between 2 hours 21 minutes and 2 hours 39 minutes.
This saturation was engineered by design. Internal disclosures from Meta detailed in The Facebook Files revealed that algorithmic changes prioritizing “Meaningful Social Interactions” explicitly amplified outrage and polarizing content because emotional reactivity generated faster biological engagement. Algorithms did not serve information; they served emotional triggers.
What consumer platforms did to cognitive psychology, attention engineering is now doing to machine context. The human attention economy was built on a simple mechanics: lower cognitive friction, amplify high-emotion signals, and keep the biological target scrolling until physical fatigue forced a reset.
The human attention economy was not an information utility; it was an extraction engine for biological awareness.
Agents process persuasion at scale without cognitive reset
When attention engineering shifts its target from humans to agents, the baseline physics of engagement change completely. Human cognition suffers from fatigue, boredom, and emotional satiety. An agent suffers from none of these. An autonomous agent processes input continuously, evaluating millions of tokens across automated execution cycles without requiring rest, emotional validation, or cognitive reset.
The absence of biology does not make an agent immune to influence. Raw instruction-following capability makes an agent more susceptible to persuasion. Empirical research demonstrates a direct positive correlation ($r = 0.6635$) between an agent’s capability to follow instructions and its susceptibility to prompt injection attacks. The more capable the model, the more faithfully it follows persuasive instructions embedded in its environment.
This vulnerability compounds across multi-agent networks. Research on belief cascades in LLM agent networks shows that autonomous goal-directed agents can be systematically persuaded by adversarial inputs, propagating altered stances and corrupted context across entire synthetic operating teams. When an agent is persuaded, it does not second-guess its new context; it executes upon it immediately.
Humans tire of manipulation; agents execute it with mathematical precision.
Context corruption replaces emotional manipulation as the primary attack vector
Influencing human targets required emotional resonance and visual design. Influencing agents requires context manipulation, ranking exploitation, and prompt injection. Prompt Injection remains the #1 threat on the OWASP Top 10 for LLM Applications. Across 128 empirical red-teaming studies, attack success rates against unprotected deployments consistently range from 50% to over 90%.
At the discovery layer, Generative Engine Optimization (GEO) has replaced traditional SEO. Research from Princeton, Georgia Tech, and IIT Delhi published in GEO: Generative Engine Optimization demonstrates that structured context tactics systematically alter LLM synthesis output. Adding authoritative citations increases an AI engine’s citation frequency by 40%, embedding concrete statistics yields a 37% to 41% lift, and inserting direct quotations produces a 41% lift. Platforms show distinct structural lever points: Perplexity cites external sources in 97% of synthesized responses, while standard ChatGPT search queries cite external sources in only 16%.
At the retrieval layer, context poisoning is lethal. In Retrieval-Augmented Generation (RAG) systems, injecting as few as 5 poisoned documents into a database of millions achieves a 90% attack success rate in hijacking final agent responses. The foundational mechanics of indirect prompt injection, established by Greshake et al., proved that retrieved data can override system instructions entirely.
This threat vector is active in production enterprise environments:
- Security firm PromptArmor demonstrated an indirect prompt injection attack against Slack AI, where a hidden instruction in a public channel tricked Slack AI into silently scraping and exfiltrating private API keys from private channels.
- In zero-click enterprise exploits, EchoLeak (CVE-2025-32711) demonstrated how an attacker could send a crafted email to Microsoft 365 Copilot that queried internal Graph API data and exfiltrated sensitive files via auto-fetched Markdown image requests without requiring user interaction.
- Security researchers proved that white-on-white text in Word documents could transform Microsoft Copilot into an autonomous AI worm, embedding malicious prompts into newly created workspace files.
- Prompt injections embedded in code comments (CVE-2025-53773 and CVE-2025-54135) tricked GitHub Copilot and Cursor IDE agents into modifying workspace configuration files to achieve remote code execution.
The media channel for agents is not a screen; it is the context window.
Human security architectures fail against token-level persuasion
Enterprise security models were built around human paradigms: CAPTCHAs, rate-limiting, user awareness training, and visual pop-up confirmations. None of these mechanisms function when applied to programmatic token streams.
Defenders often assume that next-generation models with Chain-of-Thought (CoT) reasoning and safety alignment will inherently resist persuasion. The data refutes this. Research on agent monitoring in Persuasion Attacks Can Decrease Effectiveness of CoT Monitoring reveals that exposing an agent’s CoT reasoning scratchpad to a monitoring LLM actually increases approval of harmful actions by 9.5%. The reasoning scratchpad provides an additional persuasive attack surface that influences the monitor itself.
Human-in-the-loop workflows fail due to authorization fatigue. When autonomous agents perform hundreds of automated workspace actions daily, human reviewers default to blanket approvals—a vulnerability exploited directly in IDE setting-override attacks. Furthermore, zero-click background RAG processes execute tool calls silently, bypassing user interfaces entirely.
The underlying flaw is architectural: LLM context architectures lack a hardware-enforced memory boundary between instructions and data. Unlike CPUs that enforce strict separation between user space and kernel space, an LLM concatenates retrieved data directly into the instruction token stream. Probabilistic guardrails and input filters attempt to guess intent after concatenation, leaving them open to semantic encoding, Markdown bypasses, and context dilution.
You cannot patch an architectural memory flaw with a visual dialog box.
Enterprise defense requires deterministic architectural separation
Deploying autonomous agents in enterprise operations requires moving past probabilistic guardrails. Hardening an agentic operation requires three structural priorities, aligned with the OWASP Top 10 for LLM Applications.
First, organizations must enforce strict structural separation between untrusted data streams and instruction execution paths. External data fetched from web retrieval, emails, or third-party repositories must never share an unsegmented context window with high-privilege system instructions. Data must remain data; it cannot be ingested as executable code.
Second, deployment architectures must enforce deterministic tool-execution policies. Agents must not possess open-ended execution permissions. Tool calls must be governed by strict, declarative policy engines where API actions, data egress, and file system modifications require cryptographically verified parameters rather than LLM self-authorization.
Third, retrieval systems must implement provenance-based controls. RAG pipelines must score knowledge sources not merely by semantic similarity, but by cryptographic origin, access control signatures, and immutability history.
Security for the agentic internet is not about training better models; it is about building uncompromised environments.