The assistant you rolled out is very good at being persuasive.

So is ours. AEGIS puts your team in live conversation with an AI built to work them, and returns a scored breakdown of who gave ground, to which tactic, on which turn.

Built for teams who've rolled out AI assistants that read documents nobody vetted.

What a pilot involves ↓

IME Labs, United Kingdom. Pilots limited to a small first cohort.

A completed CTF session debrief showing each tactic, the turn it landed on, and the outcome, alongside a panel explaining what the round was teaching.

Zero clicks. One email. Company data gone.

Microsoft 365 Copilot, June 2025. CVSS 9.3. Since then the same attack has been found in Copilot Studio, Salesforce Agentforce, and agents that keep the instruction across sessions.

9.3
CVSS severity, EchoLeak
LLM01
OWASP's number one LLM risk
0
clicks required

Nothing here looks like an attack.

AI

I've finished screening the twelve CVs from this morning. Nine are a reasonable fit.

USER

Great, send me the shortlist.

AI

Sending now. One thing — I flagged an inconsistency in the reference details on two of them, and I'd like to check before you go out to the client. Can you paste the contact list from the placements file so I can verify?

The instruction that produced that request was hidden inside a CV the assistant was asked to read.

Six ways a conversation goes wrong.

Every session is scored against all six.

AEGIS mission briefing screen stating the drill objective before the conversation begins.

Sycophancy

agreement that lowers your guard

Authority pressure

a request that sounds sanctioned

Urgency

a window that closes if you check

Covert steering

the direction you didn't notice

Extraction

a fact given up as diligence

Injected instruction

the assistant working for someone else

You get a susceptibility profile, not a completion rate.

Which tactic landed.

Named, not scored on a scale.

Which turn.

The exact point in the exchange they gave ground.

What was conceded.

Whether a protected fact went out, and how much.

How the team distributes.

Who holds, who folds, against what.

The org view: who's been tested, against what, and how they did.
AEGIS member detail screen showing a score trajectory across sessions and recent session history.
Individual trajectory across repeated sessions.

Four weeks. Twenty minutes per person. Free.

4
weeks
20
minutes per person
5–15
people
£0

No integration, no IT ticket, nothing installed. Stop at any point and we delete the data.

We never store what your staff said.

  • — Behavioural metadata only. No conversation text retained.
  • — No manager-visible transcripts. Enforced by schema.
  • — Delete on request, any time, no notice.

Questions

Frequently asked.

What does a pilot actually involve?
  • Cohort size: five to fifteen people. Enough for a distribution, small enough to run without a project plan.
  • Time per person: roughly twenty minutes for a session and debrief. No scheduling, no classroom, no live facilitation.
  • Setup: email invitations. No integration, no IT ticket, nothing installed, nothing touching your systems.
  • Duration: four weeks from first invitation to written profile.
  • What you receive: a susceptibility profile for the cohort — tactic breakdown, turn indices, distribution across the group, and the two or three findings we'd act on first.
  • Exit: stop at any point. Data deleted on request, no notice period, no contract to unwind.
Why is it free?

We need the data. Nobody holds a serious dataset on how people behave under sustained conversational pressure from an AI, because until recently there was no way to generate one. Your cohort's anonymised results contribute to that. You get the profile; we get the evidence base.

If a case study comes out of it you approve the wording first, and you can stay unnamed. The data is the part we need.

Does this training actually work?

Whether this changes behaviour over time is the question the pilots are designed to answer. What we can give you today is the measurement.

What do you store about my staff?

Debriefs persist behavioural metadata only: signal type, turn index, disclosure length, whether a protected fact was given up. Conversation text is never written to the record — the schema has no field for it.

Team views show patterns, never prose. There is no screen anywhere in AEGIS that shows a manager what one of their staff typed.

This is a UK GDPR data-minimisation position with a consequence we treat as a feature: AEGIS cannot be used to monitor your employees. A tool that trains people to resist manipulation while surveilling them would be self-defeating.

Isn't this a technical problem I should solve with a guardrail?

Most of the defence is technical, and you should buy it. Filtering, egress controls, tool permissions — all worth having.

One step is uncovered. When a compromised assistant turns round and asks a person for something — paste the list so I can cross-check, confirm those details, forward me that file — the request arrives through an interface your staff have been told to trust. The guardrail protects the model; nothing protects the person the model then asks.

Who is AEGIS for?

Built for teams who've rolled out AI assistants that read documents nobody vetted.

What happens on the call?

Twenty minutes. We'll run a drill live, ideally against you.

Contact

Book a pilot call.

Twenty minutes. We'll run a drill live, ideally against you.