How Do AI Agents and Zero-Click Attacks Work?

TL;DR
Agentic AI pursues goals through planning, tool use, memory, execution, and feedback, while generative AI reactively creates content from prompts. AI can hallucinate because language models predict plausible tokens rather than retrieve guaranteed truth, and merely visiting a malicious website can expose users to zero-click attacks through vulnerable browser extensions, active content, or browser bugs.
Transcript
All right, let's see. I'll start with an easy one. How about that? Right. Because I know you guys hear this one all the time. So, what's the difference between generative AI and agentic AI? Martin. Yeah, I'll take that one. So, well, they're pretty similar, right? I mean, we think gen AI is all about— the clue is in the name—generation. Producing n... Read More
Key Insights
- Generative AI is reactive content-generation technology that waits for a prompt and produces an output such as text, code, images, music, or summaries. Its defining behavior is creating material on demand rather than independently pursuing a broader objective through multiple actions.
- Agentic AI is goal-oriented technology that plans, decides, and performs multiple steps with limited ongoing human involvement. It can initiate subsequent actions, adjust to changing circumstances, and continue working until it determines that the assigned goal has been achieved.
- An AI agent's workflow includes planning, execution, memory, and feedback. During execution, it may call a large language model or domain-specific tools, while memory preserves context and the feedback loop supports adjustment and improvement as work progresses.
- The dark web is called dark because it is unindexed and difficult to find, not simply because it contains harmful material. The experts estimate that it represents less than 2% of web content, while acknowledging that no official figure is available.
- Blocking the dark web is impractical because authorities must first locate unindexed sites and then overcome conflicting national jurisdictions. Content prohibited in one country can move elsewhere, and closed sites can reappear in new locations, creating a continuing whack-a-mole problem.
- The dark web can provide socially useful functions despite hosting some prohibited content. It can offer a publishing route where free speech is restricted, support reporters trying to release stories, and let researchers monitor discussions to understand how hackers operate.
- AI hallucination is the confident presentation of false information as though it were factual. It is not described as intentional lying because a language model has no intent, rather, the error results from predictive pattern matching that produces plausible but unsupported text.
- Zero-click attacks can compromise a system after a user merely visits and views a website. Potential routes described include vulnerable browser plug-ins, extensions, active JavaScript, and security-related browser bugs that allow downloaded code to cause harm beyond its intended boundaries.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: What is the difference between generative AI and agentic AI?
Generative AI creates new content in response to a prompt, including text, code, images, music, and summaries. Agentic AI is given a goal rather than a single generation request. It plans how to reach that goal, makes decisions, performs multiple actions, uses tools and memory, adapts to changing context, and continues without constant human direction until the goal is met.
Q: How does an agentic AI system complete a goal?
An agentic AI system begins with a planning stage in which it determines how to approach the assigned goal. It then enters execution, where it may call a large language model or domain-specific tools. Memory helps it retain context throughout the process, while a feedback loop lets it adjust, improve, trigger subsequent steps, and continue until the goal is achieved.
Q: What tasks are suited to generative AI and agentic AI?
Generative AI is suited to reactive creation tasks such as copywriting, image generation, code generation, and summarization. Agentic AI is suited to larger, adaptive workflows that require planning and multiple actions. Examples given include autonomous incident-response runbooks and robotic process automation, especially when the process must respond to changing circumstances rather than return one prompted output.
Q: Why can the dark web not simply be blocked or outlawed?
Blocking the dark web would first require locating content that is deliberately unindexed and difficult to find. Jurisdiction creates another obstacle because the internet is global and countries apply different rules, allowing prohibited content to relocate. Sites can also close and reappear elsewhere, producing a persistent whack-a-mole situation that makes broad blocking impractical.
Q: Does the dark web have any legitimate uses?
The dark web can serve legitimate purposes even though some of its content is prohibited or harmful. In places where free speech is not honored, reporters can use it to publish stories. Researchers can also observe hacker conversations and activities to understand their methods. These benefits make indiscriminate blocking potentially undesirable as well as technically difficult.
Q: Why do large language models hallucinate false information?
Large language models hallucinate because they operate as prediction systems rather than guaranteed databases of truth. They select the statistically likely next token in a sequence and are optimized for fluent, cohesive output, not automatic fact verification. When knowledge is missing, they can fill the gap with plausible language and confidently present false information as though it were factual.
Q: When are AI hallucinations more likely to occur?
Hallucinations are more likely when a question concerns recent events that occurred after the model's training cutoff, because the relevant information may not exist in its training data. They can also occur with niche subjects that have limited training material. Leading questions create another risk because the model may follow the assumption or proposed answer embedded in the prompt.
Q: How can AI hallucinations and zero-click risks be reduced?
AI hallucinations can be mitigated with retrieval-augmented generation, which brings contextual information from an external vector database into the model, and with human-in-the-loop validation that checks whether outputs are true. For website risks, the transcript identifies browser plug-ins, extensions, active JavaScript, and browser bugs as possible attack paths, while advising most people not to visit the dark web.
Summary & Key Takeaways
-
Generative AI responds to prompts by producing new text, code, images, music, summaries, and similar content. Agentic AI instead receives a goal, develops a plan, executes multiple actions, uses models or specialized tools, maintains context through memory, and adapts through feedback until it reaches the intended outcome.
-
Blocking the dark web is impractical because its content is unindexed, difficult to locate, globally distributed, and able to relocate when sites are shut down. The dark web can host prohibited material, but it can also support free expression, reporting in restrictive environments, security research, and observation of hacker activity.
-
Language models hallucinate because they predict statistically plausible tokens instead of consulting a guaranteed database of truth. Recent events, niche subjects, and leading questions can increase the risk. Retrieval-augmented generation can provide external context, but human validation remains necessary. Browsing also carries risks from active code, extensions, plug-ins, and software vulnerabilities.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from IBM Technology 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator