Quiz 17 Question 2 of 7

A security architect is reviewing a proposed Copilot Studio computer-use agent that will automate data entry into a legacy desktop application that has no API. The agent will take screenshots, interpret UI elements, and click/type to perform data entry on behalf of users. The architect raises three concerns: (1) the agent could be manipulated by content displayed on-screen to perform unintended actions, (2) the agent runs under a service account with broad permissions, and (3) audit logs only capture the agent's intent, not its actual screen actions. Which concern correctly identifies a recognized security risk specific to computer-use AI agents?

Select an answer to reveal the explanation.

Motivation