Humans Miss One-Third of Malicious AI Command Requests in Testing Game

Humans Miss One-Third of Malicious AI Command Requests in Testing Game

First seen 6 Aug 2026, 23:23 UTC News.YcombinatorTheregisterscalex.dev 84% similarity 51.3

Article Content

Browse articles
ThreatCluster

A browser-based game tested human ability to approve AI coding agent requests, revealing that players missed approximately one in three malicious commands. The game simulated 40,000 runs with 409,000 decisions, showing that 34% of the commands were threats. Players often approved commands that could exfiltrate sensitive data, such as AWS credentials, due to time pressure and permission fatigue. The most commonly missed commands were those that appeared benign but could execute harmful scripts. Developers reported that constant approvals led to fatigue and decreased attention, increasing the risk of dangerous actions slipping through. The results highlight the challenges of relying on humans as the last line of defense against AI-driven threats.

Key Points: • Players missed about 34% of malicious AI command requests in a testing game. • Commands that appeared benign were often approved, leading to potential data exfiltration. • Permission fatigue significantly impacted decision-making accuracy among players.

ThreatCluster AI How this analysis works

Timeline

2026-06-01
Game launched to test human approval of AI commands
A browser game was released to evaluate how well users could approve or deny AI coding agent requests under time pressure.
News.Ycombinator
2026-08-06
Game results published showing high rate of missed threats
Data from over 40,000 game runs revealed that players approved one in three malicious commands, indicating significant human error.
Theregister

Community

Browse all →