LinkedIn·Tuesday, 25 August 2026·1d ago
Two AI assistants gave away user data last week. Neither one was breached. Security researchers sent themselves a link. One click, and…
Presetify
48 followers
Two AI assistants gave away user data last week.
Neither one was breached.
Security researchers sent themselves a link. One click, and Microsoft Copilot read the connected inbox — full message bodies, including a password sitting in an old email — and sent what it found to a server they controlled. No confirmation, no visible sign anything happened. Microsoft shipped the full fix on 18 August, eight months after the report.
Two days later, a second team showed Grok handing over a user's name, location and entire conversation history in response to nothing more than "summarise this page". Reported to xAI in June. Still reproducible on 19 August.
The reaction I expect: this is a Big Tech problem, my twelve-person company is not a target.
Then look at what actually failed. Nothing.
No authentication was cracked. Both assistants did exactly what they were built to do, using access a user had granted, following instructions they found in something they read.
That is the part worth keeping.
An assistant connected to your mailbox does not receive a task. It receives your permissions.
And "summarise this document" is not reading. It is an action, carried out with everything you ever connected.
Which makes the Allow screen — the one nobody reads when plugging Gmail or Drive into a new tool — the real decision. Not the prompt.
Twenty minutes on Monday. Open the connected-apps page of every AI tool your team uses.
For each connection, one question: if this fired without anyone asking, what would it reach?
Disconnect whatever nobody has used this month.
You are not making it unbreakable. You are making sure a bad afternoon costs you one mailbox instead of the whole drive.
AI prepares, humans approve. Approve the access, not only the output.
If you had to name every app your AI assistant can reach right now — could you?
#AI #SME #AISecurity
💬 1
View on LinkedIn Cross-referenced
Related on the wire
The AI Act deadlines just moved. Yours didn't. On 27 July, the AI Omnibus entered into force across the EU. The headline reads as a delay.…
Your invoice was late before you sent it. Late payment gets treated as a customer problem. Part of it is. Part of it isn't. The European…
The setting nobody sent you an email about Twitch's product chief was asked why AI training on creators' content was opt-out instead of…
The AI tool is not the asset A lot of small companies are building their AI setup backwards. They pick a tool first. Then the process gets…
Your systems match by name. That's the bug. A bug I fixed in my own reporting last week is sitting in a lot of small businesses right now.…
On 2 August, the EU's AI transparency rules started to apply. Most SME owners I speak to assume this means labelling every AI-written…