---
title: Poisoning
seo_title: Poisoning — video
description: What happens when a document or memory preserves a dangerous instruction and the system uses it again later.
keywords: RAG poisoning, agent memory, sleeper agents, memory poisoning, LLM backdoors, unlearning
date: '2026-08-06T00:00:00+00:00'
robots: index,follow,max-snippet:-1,max-image-preview:large,max-video-preview:-1
hide:
- toc
- navigation
video_watch_page: true
---


<div class="s5-video-watch" data-s5-video-watch data-video-id="videos-series-seguridad-ia-03-envenenamiento-md">
  <header class="s5-video-watch__header">
    <div class="s5-video-watch__crumbs"><a href="https://5sigmas.com/en/videos/">All videos</a><span>AI security</span><span>0:48</span></div>
    <h1>Poisoning</h1><p>What happens when a document or memory preserves a dangerous instruction and the system uses it again later.</p>
  </header>
  <div class="s5-video-watch__player">
    <video controls crossorigin="anonymous" preload="metadata" poster="/en/series/seguridad-ia/03-envenenamiento.jpg" playsinline data-s5-watch-player><source src="/en/series/seguridad-ia/03-envenenamiento.mp4" type="video/mp4">Your browser does not support the video element.</video>
    <p>Links containing <code>?t=</code> open the video at a specific second.</p>
  </div>
  <section class="s5-video-watch__summary" aria-labelledby="video-summary-title">
    <div class="s5-video-watch__section-head"><span class="s5-eyebrow">Video summary</span><h2 id="video-summary-title">The ideas to retain</h2></div>
    <div class="s5-video-watch__snippet-grid"><article><span>01</span><h2>Storing a datum does not make it true</h2><p>Storing an output in a database does not make it trustworthy. An agent&#x27;s memory should have an origin, date, scope, permissions and an expiration policy. Without those properties, the…</p></article>
<article><span>02</span><h2>Persistent memory is already a measurable attack surface</h2><p>Evidence from 2026 makes it possible to analyze this surface much more directly than the earliest work on backdoors in model weights.</p></article>
<article><span>03</span><h2>Dangerous behavior can also remain hidden in the model</h2><p>The Sleeper Agents study built test models that wrote safe code when the prompt indicated 2023 and vulnerable code when it indicated 2024. The demonstration does not describe a commercial…</p></article></div>
  </section>
  
  
  <aside class="s5-video-watch__source"><div><span class="s5-eyebrow">Context and evidence</span><h2>Continue with the full article</h2><p>The chapter develops the mechanism, primary sources, limitations and connections to the rest of the series.</p></div><a class="s5-video-watch__source-link" href="https://5sigmas.com/en/series/seguridad-ia/03-envenenamiento/">Read the article →</a></aside>
  <section class="s5-video-watch__related" aria-labelledby="related-videos-title"><div class="s5-video-watch__section-head"><span class="s5-eyebrow">Next step</span><h2 id="related-videos-title">Related videos</h2></div><div class="s5-video-watch__related-grid"><article><a href="https://5sigmas.com/en/videos/series/seguridad-ia/05-controles-produccion/"><img src="https://5sigmas.com/en/series/seguridad-ia/05-controles-produccion.jpg" alt="" loading="lazy" width="1280" height="720"><span>AI security · 0:48</span><strong>Production Controls</strong></a></article>
<article><a href="https://5sigmas.com/en/videos/series/seguridad-ia/04-red-teaming/"><img src="https://5sigmas.com/en/series/seguridad-ia/04-red-teaming.jpg" alt="" loading="lazy" width="1280" height="720"><span>AI security · 0:48</span><strong>Red Teaming</strong></a></article>
<article><a href="https://5sigmas.com/en/videos/series/seguridad-ia/02-jailbreaks/"><img src="https://5sigmas.com/en/series/seguridad-ia/02-jailbreaks.jpg" alt="" loading="lazy" width="1280" height="720"><span>AI security · 0:48</span><strong>Jailbreaks</strong></a></article></div></section>
</div>
