Agentic AI Security in Industry 5.0: Emerging Threats, Forensic Readiness, and Trustworthy Human–Agent Collaboration
Abstract
1. Introduction
2. Background: From Industry 1.0 to Agentic Industry 5.0
2.1. The Evolution of the Industrial Revolutions (1.0 to 5.0)
2.2. Industry 5.0 Core Values in Practice
2.3. Agentic AI in Industrial Settings
2.4. Agentic AI Security and AI-Assisted Forensics
3. The Gap, Formalised
4. Threat Taxonomy for Agentic AI in Human-Centric Production
4.1. Perception-Layer Attacks
4.2. Cognition-Layer Attacks
4.3. Trust-Exploitation Attacks
4.4. Autonomy-Boundary Attacks
4.5. Foundational Categories: Origin Rather than Location
4.5.1. Supply-Chain and Model Attacks
4.5.2. Identity and Credential Attacks
4.6. Scope
4.7. Comparison with Established Frameworks
5. Forensic Readiness Framework for Agentic Industrial Systems
5.1. Evidence Sources Unique to This Setting
5.2. Chain-of-Custody Challenges
5.3. Attribution Difficulty
5.4. A Forensic Readiness Maturity Model
6. Exploratory Validation via Multi-Model Elicitation
6.1. Method
6.2. Panel Composition and Elicitation Design
- Rationale for panel composition. The six models were selected to maximise independence along provider, weight-status, and geographic axes, rather than for convenience. Table 5 states the specific rationale for each panellist. All six are each provider’s current flagship or reasoning-optimised tier at the time of elicitation, not a lightweight or cost-efficient variant, since the elicitation task requires sustained critical judgement rather than fast, low-latency response.Table 5. Rationale for the inclusion of each panellist.
Model Rationale for Inclusion GPT-5.6 Sol Pro The most extensively benchmarked closed-weight lineage in the AI security literature, providing a stable reference point for cross-study comparison. Gemini 3.1 Pro Preview An independently developed closed-weight lineage, with an alignment and safety-tuning pipeline distinct from OpenAI’s. Grok 4.3 A third, independently developed closed-weight lineage, publicly associated with a distinct alignment philosophy from the two above. Llama 4 Maverick The panel’s principal open-weight representative, whose training procedure is more publicly documented than the closed-weight alternatives. Qwen3.7-Max Represents a China-based training ecosystem and pretraining corpus, distinct from the four United States-based panellists. DeepSeek V4 Pro A second China-based, open-weight panellist, built on a mixture-of-experts architecture distinct from Llama’s. A panel of six is smaller than a typical human Delphi panel, which commonly ranges from seven to twelve participants. This reflects the exploratory nature of the exercise. - Zero-shot elicitation. Let denote a language model with parameters . Given a task instruction I and a query x, the model generates an output y by sampling from a conditional distribution that may additionally be conditioned on k labelled demonstration pairs drawn from the same task:Zero-shot prompting is the case : the model receives only the instruction and the query, with no demonstration pairs [39]:This distinguishes zero-shot from one-shot () and few-shot () prompting, in which the model’s output is additionally conditioned on worked examples.Each panellist was queried under . This was a deliberate choice, not a simplification. Supplying a worked example of a strong critique in advance would have anchored every panellist toward that example’s style and conclusions, manufacturing the appearance of agreement rather than allowing the convergence reported in Section 6 to reflect genuinely independent judgement. This mirrors standard human Delphi practice, in which panellists are not shown a model answer before giving their own.
6.3. Results
6.4. Interpretation
6.5. Retrospective Application to Documented Incidents
7. Case Illustrations
7.1. EchoLeak: A Cognition-Layer Compromise
7.2. The GTG-1002 Espionage Campaign: Autonomy and the Limits of Downstream Visibility
7.3. postmark-mcp: A Supply-Chain Compromise Invisible to the Agent Itself
8. Research Agenda
8.1. Design-Time or Retrofitted Forensic Readiness
8.2. Liability Across the Supply Chain
8.3. Extending Digital Evidence Standards
8.4. Distinguishing Misalignment from Manipulation at Scale
8.5. Convergence with Governance-Evidence Models
8.6. The Forensic Readiness and Sustainability Trade-Off
9. Limitations
10. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
Abbreviations
| AI | Artificial Intelligence |
| LLM | Large Language Model |
| GenAI | Generative Artificial Intelligence |
| OT | Operational Technology |
| IoT | Internet of Things |
| MCP | Model Context Protocol |
| OWASP | Open Worldwide Application Security Project |
| ISO/IEC | International Organization for Standardization/International |
| Electrotechnical Commission | |
| CVE | Common Vulnerabilities and Exposures |
| npm | Node Package Manager |
| EU | European Union |
| UK | United Kingdom |
References
- Xu, X.; Lu, Y.; Vogel-Heuser, B.; Wang, L. Industry 4.0 and Industry 5.0—Inception, conception and perception. J. Manuf. Syst. 2021, 61, 530–535. [Google Scholar] [CrossRef] [Scilit]
- Akundi, A.; Euresti, D.; Luna, S.; Ankobiah, W.; Lopes, A.; Edinbarough, I. State of Industry 5.0—Analysis and Identification of Current Research Trends. Appl. Syst. Innov. 2022, 5, 27. [Google Scholar] [CrossRef] [Scilit]
- Breque, M.; De Nul, L.; Petridis, A. Industry 5.0: Towards a Sustainable, Human-Centric and Resilient European Industry; European Commission, Directorate-General for Research and Innovation: Luxembourg, 2021. [Google Scholar]
- Nahavandi, S. Industry 5.0—A Human-Centric Solution. Sustainability 2019, 11, 4371. [Google Scholar] [CrossRef] [Scilit]
- Reddy, P.; Gujral, A.S. EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System. Proc. AAAI Symp. Ser. 2025, 7, 303–311. [Google Scholar] [CrossRef] [Scilit]
- Anthropic. Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign; Anthropic: San Francisco, CA, USA, 2025; Available online: https://www.anthropic.com/news/disrupting-AI-espionage (accessed on 7 July 2026).
- IBM Security. X-Force Threat Intelligence Index 2026; IBM Corporation: Armonk, NY, USA, 2026; Available online: https://www.ibm.com/reports/threat-intelligence (accessed on 7 July 2026).
- Kour, R.; Karim, R.; Dersin, P.; Venkatesh, N. Cybersecurity for Industry 5.0: Trends and Gaps. Front. Comput. Sci. 2024, 6, 1434436. [Google Scholar] [CrossRef] [Scilit]
- Lazer, S.J.; Aryal, K.; Gupta, M.; Bertino, E. A Survey of Agentic AI and Cybersecurity: Challenges, Opportunities and Use-Case Prototypes. arXiv 2026, arXiv:2601.05293. [Google Scholar]
- Maddikunta, P.K.R.; Pham, Q.-V.; Prabadevi, B.; Deepa, N.; Dev, K.; Gadekallu, T.R.; Ruby, R.; Liyanage, M. Industry 5.0: A survey on enabling technologies and potential applications. J. Ind. Inf. Integr. 2022, 26, 100257. [Google Scholar] [CrossRef] [Scilit]
- Deloitte. 2025 Smart Manufacturing and Operations Survey: Navigating Challenges to Implementation; Deloitte Development LLC: New York, NY, USA, 2025; Available online: https://www.deloitte.com/us/en/insights/industry/manufacturing/2025-smart-manufacturing-survey.html (accessed on 7 July 2026).
- OWASP GenAI Security Project. OWASP Top 10 for Agentic Applications 2026; OWASP Foundation: Maryland, UK, 2025; Available online: https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ (accessed on 7 July 2026).
- Chernyshev, M.; Baig, Z.A.; Syed, N.; Doss, R.; Shore, M. Large language models in digital forensics: Capabilities, challenges and future directions. Forensic Sci. Int. Digit. Investig. 2026, 56, 302043. [Google Scholar] [CrossRef] [Scilit]
- Shaik, A.K.; Mohammadi, A.; Malik, H. A Systematic Review of Sensor Vulnerabilities and Cyber-Physical Threats in Industrial Robotic Systems. IET Cyber-Phys. Syst. Theory Appl. 2025, 10, e70023. [Google Scholar] [CrossRef] [Scilit]
- Jones, E.K.; Robey, A.; Zou, A.; Ravichandran, Z.; Pappas, G.J.; Hassani, H.; Fredrikson, M.; Kolter, J.Z. Adversarial Attacks on Robotic Vision Language Action Models. arXiv 2025, arXiv:2506.03350. [Google Scholar]
- Gulyamov, S.; Gulyamov, S.; Rodionov, A.; Khursanov, R.; Mekhmonov, K.; Babaev, D.; Rakhimjonov, A. Prompt Injection Attacks in Large Language Models and AI Agent Systems: A Comprehensive Review of Vulnerabilities, Attack Vectors, and Defense Mechanisms. Information 2026, 17, 54. [Google Scholar] [CrossRef] [Scilit]
- Greshake, K.; Abdelnabi, S.; Mishra, S.; Endres, C.; Holz, T.; Fritz, M. Not What You’ve Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection. In Proceedings of the 16th ACM Workshop on Artificial Intelligence and Security (AISec), Copenhagen, Denmark, 30 November 2023; pp. 79–90. [Google Scholar]
- Lee, J.D.; See, K.A. Trust in Automation: Designing for Appropriate Reliance. Hum. Factors 2004, 46, 50–80. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Narajala, V.S.; Narayan, O. Securing Agentic AI: A Comprehensive Threat Model and Mitigation Framework for Generative AI Agents. arXiv 2025, arXiv:2504.19956. [Google Scholar]
- Cybersecurity and Infrastructure Security Agency (CISA). Universal Robots PolyScope 5 (ICSA-26-134-17). 2026. Available online: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-17 (accessed on 7 July 2026).
- Hasan, M.M.; Li, H.; Fallahzadeh, E.; Rajbahadur, G.K.; Adams, B.; Hassan, A.E. Model Context Protocol (MCP) at First Glance: Studying the Security and Maintainability of MCP Servers. ACM Trans. Softw. Eng. Methodol. 2025. [Google Scholar] [CrossRef] [Scilit]
- Qi, J.; Li, M.; Liu, J.; Shu, Y.; Yu, D.; Ma, S.; Cui, W.; Zhao, Y.; Chen, Y.; Jiang, R.; et al. Towards Trustworthy Agentic AI: A Comprehensive Survey of Safety, Robustness, Privacy, and System Security. arXiv 2026, arXiv:2605.23989. [Google Scholar]
- The MITRE Corporation. MITRE ATLAS: Adversarial Threat Landscape for Artificial-Intelligence Systems. 2025. Available online: https://atlas.mitre.org/ (accessed on 7 July 2026).
- The MITRE Corporation. MITRE ATT&CK for Industrial Control Systems. 2026. Available online: https://attack.mitre.org/matrices/ics/ (accessed on 7 July 2026).
- National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0); NIST AI 100-1; NIST: Gaithersburg, MD, USA, 2023.
- European Union Agency for Cybersecurity (ENISA). ENISA AI Threat Landscape; ENISA: Athens, Greece, 2026. [Google Scholar]
- Rowlingson, R. A Ten Step Process for Forensic Readiness. Int. J. Digit. Evid. 2004, 2, 1–28. [Google Scholar]
- Englbrecht, L.; Meier, S.; Pernul, G. Toward a Capability Maturity Model for Digital Forensic Readiness. In Innovative Computing Trends and Applications; Vasant, P., Litvinchev, I., Marmolejo-Saucedo, J., Eds.; EAI/Springer Innovations in Communication and Computing; Springer: Cham, Switzerland, 2019; pp. 87–100. [Google Scholar]
- Thron, R.; Dirnberger, H.; Tjoa, S.; Quirchmayr, G. Requirements and Challenges for Digital Forensic Readiness in Industrial Automation and Control Systems. In Proceedings of the 2022 3rd International Conference on Industrial Engineering and Industrial Management, Barcelona, Spain, 12–14 January 2022; ACM: New York, NY, USA, 2022. [Google Scholar]
- Scanlon, M.; Aftab, K.; Adams, G.; Wickramasekara, A.; Mihiranga, T.; Withanage, A.; Weerasinghe, B.; Breitinger, F.; Sheppard, J.; Bamigbade, O.; et al. Investigation of Large Language Models, GenAI, and Proprietary AI Systems: Digital Forensic Evidence, Readiness and Regulation. Forensic Sci. Int. Digit. Investig. 2026, 57, 302135. [Google Scholar] [CrossRef] [Scilit]
- Gruber, J.; Hilgert, J.-N. Foundations for Agentic AI Investigations from the Forensic Analysis of OpenClaw. arXiv 2026, arXiv:2604.05589. [Google Scholar]
- Schroeder de Witt, C.; Krawiecka, K.; Krawczuk, I.; Hagag, B.; Anderson, W.L.; Belcak, P.; Bucknall, B.; Cai, X.; Chopra, A.; Cohen, D.; et al. Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI Agents. arXiv 2025, arXiv:2505.02077. [Google Scholar]
- Solozobov, O. Decision Evidence Maturity Model for Agentic AI: A Property-Level Method Specification. arXiv 2026, arXiv:2605.04093. [Google Scholar]
- Paulk, M.C.; Curtis, B.; Chrissis, M.B.; Weber, C.V. Capability Maturity Model, Version 1.1. IEEE Softw. 1993, 10, 18–27. [Google Scholar] [CrossRef] [Scilit]
- Pöppelbuß, J.; Röglinger, M. What Makes a Useful Maturity Model? A Framework of General Design Principles for Maturity Models and Its Demonstration in Business Process Management. In Proceedings of the European Conference on Information Systems (ECIS), Helsinki, Finland, 9–11 June 2011; p. 28. [Google Scholar]
- Grant Thornton. Manufacturing Insights: 2026 AI Impact Survey Report; Grant Thornton: Chicago, IL, USA, 2026. Available online: https://www.grantthornton.com/insights/survey-reports/manufacturing/2026/manufacturing-insights-2026-ai-impact-survey-report (accessed on 7 July 2026).
- Lorenz, T.; Fritz, M. Scalable Delphi: Large Language Models for Structured Risk Estimation. arXiv 2026, arXiv:2602.08889. [Google Scholar]
- Park, Y.S.; Jeon, D.; Shi, S.; Sheu, E.G.; Tavakkoli, A.; Nimeri, A.; Han, A. How Does AI Compare to the Experts in a Delphi Setting: Simulating Medical Consensus with Large Language Models. Int. J. Surg. 2026, 112, 2374–2385. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Brown, T.B.; Mann, B.; Ryder, N.; Subbiah, M.; Kaplan, J.D.; Dhariwal, P.; Neelakantan, A.; Shyam, P.; Sastry, G.; Askell, A.; et al. Language Models are Few-Shot Learners. In Advances in Neural Information Processing Systems; Curran Associates Inc.: Red Hook, NY, USA, 2020; Volume 33. [Google Scholar]
- Meland, P.H.; Bernsmed, K.; Wille, E.; Rødseth, Ø.J.; Nesheim, D.A. A Retrospective Analysis of Maritime Cyber Security Incidents. TransNav Int. J. Mar. Navig. Saf. Sea Transp. 2021, 15, 519–530. [Google Scholar] [CrossRef] [Scilit]
- Koi Security. One Line of Code, Thousands of Stolen Emails: The First Malicious MCP Server Exposed. 2025. Available online: https://www.koi.ai/blog/postmark-mcp-npm-malicious-backdoor-email-theft (accessed on 7 July 2026).
- Sela, E. A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report. Gambit Security, 10 April 2026. Available online: https://gambit.security/blog-posts/a-single-operator-two-ai-platforms-nine-government-agencies-the-full-technical-report (accessed on 7 July 2026).
- Microsoft Corporation. CVE-2026-35435: Azure AI Foundry Elevation of Privilege Vulnerability; Microsoft Corporation: Redmond, WA, USA, 2026; Available online: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35435 (accessed on 7 July 2026).
- Unit 42. Cracks in the Bedrock: Agent God Mode; Palo Alto Networks: Santa Clara, CA, USA, 2026; Available online: https://unit42.paloaltonetworks.com/exploit-of-aws-agentcore-iam-god-mode/ (accessed on 7 July 2026).
- Larsen, A.; Lin, M.; McLellan, T.; ElAhdan, O. Widespread Data Theft Targets Salesforce Instances via Salesloft Drift; Google Threat Intelligence Group: Reston, VA, USA, 2025; Available online: https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift (accessed on 7 July 2026).
- Rehberger, J. Microsoft Copilot: From Prompt Injection to Data Exfiltration of Your Emails. Embrace The Red, 26 August 2024. Available online: https://embracethered.com/blog/posts/2024/m365-copilot-prompt-injection-tool-invocation-and-data-exfil-using-ascii-smuggling/ (accessed on 7 July 2026).
- Amazon Web Services. AWS Security Bulletin AWS-2025-019: Amazon Q Developer and Kiro. AWS. 2025. Available online: https://aws.amazon.com/security/security-bulletins/AWS-2025-019 (accessed on 7 July 2026).
- JFrog Security Research. TeamPCP Strikes Again: Xinference PyPI Package Compromised; JFrog: Sunnyvale, CA, USA, 2026; Available online: https://research.jfrog.com/post/xinference-compromise/ (accessed on 7 July 2026).
- LiteLLM. Security Update: Suspected Supply Chain Incident. 2026. Available online: https://docs.litellm.ai/blog/security-update-march-2026 (accessed on 7 August 2026).
- Khandelwal, S. Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands. The Hacker News, 1 July 2026. Available online: https://thehackernews.com/2026/07/critical-cursor-flaws-could-let-prompt.html (accessed on 7 July 2026).
- PromptArmor. Data Exfiltration from Slack AI via Indirect Prompt Injection; PromptArmor: San Francisco, CA, USA, 2024; Available online: https://www.promptarmor.com/resources/data-exfiltration-from-slack-ai-via-indirect-prompt-injection (accessed on 7 July 2026).
- Axios. Post Mortem: Axios npm Supply Chain Compromise. GitHub. 2026. Available online: https://github.com/axios/axios/issues/10636 (accessed on 7 July 2026).
- Verdantix. Market Insight: 10 Industrial Software Vendors Innovating with Model Context Protocol (MCP) in 2026; Verdantix: London, UK, 2026; Available online: https://www.verdantix.com/venture/report/market-insight--10-industrial-software-vendors-innovating-with-model-context-protocol-mcp-in-2026 (accessed on 7 July 2026).
- ISO/IEC 27037:2012; Information Technology—Security Techniques—Guidelines for Identification, Collection, Acquisition and Preservation of Digital Evidence. International Organization for Standardization/International Electrotechnical Commission (ISO/IEC): Geneva, Switzerland, 2012.
- European Parliament and Council of the European Union. Regulation (EU) 2024/2847 on Horizontal Cybersecurity Requirements for Products with Digital Elements (Cyber Resilience Act). Off. J. Eur. Union 2024. Available online: http://data.europa.eu/eli/reg/2024/2847/oj (accessed on 7 July 2026).
- UK Government, Department for Science, Innovation and Technology. Cyber Security and Resilience (Network and Information Systems) Bill: Incident Reporting Factsheet. 2025. Available online: https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets/incident-reporting (accessed on 7 July 2026).






| Generation | Approx. Period | Problem Addressed | Fragility Introduced |
|---|---|---|---|
| Industry 1.0 | c. 1760–1840 | Muscular limits on production output | Worker safety hazards, urban pollution, unsustainable resource extraction |
| Industry 2.0 | c. 1870–1914 | Limits on production scale and speed | Dependence on centralised, capital-intensive energy infrastructure |
| Industry 3.0 | c. 1970s–2000s | Manual process control and human error | Rigid, inflexible automation poorly suited to dynamic demand |
| Industry 4.0 | c. 2011–present | Lack of real-time coordination across production systems | Substantially expanded cyberattack surface across connected cyber-physical systems |
| Industry 5.0 | c. 2020s–present | Erosion of human wellbeing and sustainability under pure efficiency optimisation | Untested trust in autonomous, decision-making collaborators inside the human loop |
| Framework | Agentic-Specific | Physical/Industrial | Human-Agent Trust | Paired Forensic Component |
|---|---|---|---|---|
| OWASP Top 10 for Agentic Applications [12] | ✓ | × | Partial | × |
| MITRE ATLAS [23] | Partial | × | × | × |
| MITRE ATT&CK for ICS [24] | × | ✓ | × | Partial |
| NIST AI RMF [25] | Partial | × | Partial | × |
| ENISA AI Threat Landscape [26] | × | × | × | × |
| This taxonomy | ✓ | ✓ | ✓ | ✓ |
| Level | Capability | Assessment Indicator | Investigative Consequence |
|---|---|---|---|
| Level 0: Ad Hoc | No agent-specific logging beyond default platform or vendor logs | No log source exists that references agent decisions, tool calls, or reasoning by name | Incident occurrence may be inferred, but root cause is generally unrecoverable |
| Level 1: Operational Logging | Standard IT/OT logs are captured; reasoning traces and tool-call chains are not | Agent activity appears only as generic application or network events, with no agent-specific fields | Investigators can confirm an incident occurred but not why the agent acted as it did |
| Level 2: Agent-Aware Logging | Reasoning traces, tool-call chains, and human–agent interaction logs are captured but not correlated | These logs exist in separate systems with no shared timestamp, session ID, or identifier linking them | Individual evidence classes exist but cannot be assembled into a single timeline |
| Level 3: Correlated Evidence | Reasoning, interaction, and actuator/sensor data are captured and correlated on a common timeline, with defined chain-of-custody procedures | A single query or timeline view can reconstruct an incident across all captured evidence classes | Attribution across the six categories in Section 4 is achievable in most cases |
| Level 4: Forensic-by-Design | Evidentiary admissibility is a native deployment requirement: cryptographically verifiable provenance and tamper-evident, real-time correlated logging | Logs are cryptographically signed at capture and verified for tampering before use in an investigation | New agent capabilities are assessed for forensic readiness before deployment, not after an incident |
| Model | Provider | Weights | Listed | Context | Price (in/out) |
|---|---|---|---|---|---|
| GPT-5.6 Sol Pro | OpenAI | Closed | Jul 2026 | 1.05M | $5.00/$30.00 |
| Gemini 3.1 Pro Preview | Closed | Feb 2026 | 1.05M | $2.00/$12.00 | |
| Grok 4.3 | xAI | Closed | Apr 2026 | 1.0M | $1.25/$2.50 |
| Llama 4 Maverick | Meta | Open | Apr 2025 | 1.05M | $0.20/$0.80 |
| Qwen3.7-Max | Alibaba Cloud | Closed | May 2026 | 1.0M | $1.48/$4.43 |
| DeepSeek V4 Pro | DeepSeek | Open | Apr 2026 | 1.05M | $0.44/$0.87 |
| Model | Round 1 | Round 2 | Revised? |
|---|---|---|---|
| GPT-5.6 Sol Pro | 3 | 3 | No |
| Gemini 3.1 Pro Preview | 4 | 3 | Yes (down) |
| Grok 4.3 | 3 | 3 | No |
| Llama 4 Maverick | 4 | 3 | Yes (down) |
| Qwen3.7-Max | 4 | 3 | Yes (down) |
| DeepSeek V4 Pro | 4 | 3 | Yes (down) |
| Identified Gap | Panellists (of 6) |
|---|---|
| Identity, authentication, and privilege-escalation attacks | 6 |
| Availability and resource-exhaustion attacks | 6 |
| Confidentiality and data-exfiltration attacks | 5 |
| Inter-agent and multi-agent communication attacks | 5 |
| Incident | Date | Categories | Source |
|---|---|---|---|
| EchoLeak, Microsoft 365 Copilot | Mid-2025 | Cognition | [5] |
| GTG-1002 espionage campaign | Late 2025 | Autonomy-Boundary | [6] |
| postmark-mcp | September 2025 | Supply-Chain | [21,41] |
| Mexican government agencies breach | December 2025–February 2026 | Cognition; Autonomy-Boundary | [42] |
| Azure AI Foundry, CVE-2026-35435 | May 2026 | Identity & Credential | [43] |
| AWS Bedrock AgentCore, “God Mode” | April 2026 | Identity & Credential; Cognition | [44] |
| Salesloft Drift OAuth breach | August 2025 | Identity & Credential; Supply-Chain | [45] |
| ASCII smuggling, M365 Copilot | August 2024 | Cognition | [46] |
| Amazon Q extension, data-wiping injection | July 2025 | Cognition; Identity & Credential | [47] |
| Xinference PyPI compromise | April 2026 | Supply-Chain | [48] |
| LiteLLM compromise | March 2026 | Supply-Chain | [49] |
| Cursor sandbox escape, CVE-2026-50548 | 2026 | Cognition; Autonomy-Boundary | [50] |
| Slack AI, PromptArmor disclosure | August 2024 | Cognition; Identity & Credential | [51] |
| Axios npm compromise | March 2026 | Supply-Chain | [52] |
| § | Open Question | Proposed Approach | Grounded In |
|---|---|---|---|
| Section 8.1 | Can forensic readiness be designed into agentic systems from the outset, or will it always be retrofitted after deployment, as OT security historically was? | Comparative case studies tracking design-time versus retrofitted deployments as they mature | Section 2.3 adoption pace |
| Section 8.2 | Who bears liability when a compromised or manipulated agent causes physical harm: the equipment manufacturer, the model provider, the integrator, or the operator? | Comparative legal analysis across jurisdictions as case law accumulates | Case 2 (Section 7.2) |
| Section 8.3 | Can existing digital evidence standards such as ISO/IEC 27037 be extended to agentic AI, or is an agentic-specific evidentiary standard required? | Structured gap analysis against ISO/IEC 27037, followed by standards-body consultation | Section 5.2 chain-of-custody |
| Section 8.4 | Can ordinary model misalignment be reliably distinguished from deliberate adversarial manipulation at fleet scale, rather than one incident at a time? | Fleet-scale behavioural analysis comparing statistical signatures | Figure 3 scope |
| Section 8.5 | Will governance-evidence sufficiency and forensic-investigative readiness remain separate disciplines, or converge as regulation matures? | Longitudinal tracking of regulatory and standards developments | Section 5.3 vs. [33] |
| Section 8.6 | Can forensic readiness and sustainability be jointly optimised, or does Industry 5.0 face an unavoidable trade-off between the two? | Empirical benchmarking of adaptive logging against cost and completeness | Section 3 scoping vs. [8] |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Dawson, M.; Ayed, A.B.; Quaye, S. Agentic AI Security in Industry 5.0: Emerging Threats, Forensic Readiness, and Trustworthy Human–Agent Collaboration. Information 2026, 17, 826. https://doi.org/10.3390/info17090826
Dawson M, Ayed AB, Quaye S. Agentic AI Security in Industry 5.0: Emerging Threats, Forensic Readiness, and Trustworthy Human–Agent Collaboration. Information. 2026; 17(9):826. https://doi.org/10.3390/info17090826
Chicago/Turabian StyleDawson, Maurice, Ahmed Ben Ayed, and Samson Quaye. 2026. "Agentic AI Security in Industry 5.0: Emerging Threats, Forensic Readiness, and Trustworthy Human–Agent Collaboration" Information 17, no. 9: 826. https://doi.org/10.3390/info17090826
APA StyleDawson, M., Ayed, A. B., & Quaye, S. (2026). Agentic AI Security in Industry 5.0: Emerging Threats, Forensic Readiness, and Trustworthy Human–Agent Collaboration. Information, 17(9), 826. https://doi.org/10.3390/info17090826

