Could AI Be Creating Security Risks That Traditional Cybersecurity Misses?

Businesses spend a lot of money on locks: firewalls, passwords and two-factor codes. Then all of a sudden an AI assistant gets handed access to the inbox, the shared drive and the customer database, and nobody has to break in anywhere because the newest member of staff was let in on day one.

That gives attackers a different target from the one most security setups were built around. Instead of finding a way in, they can try to manipulate an AI into misusing access it legitimately has, which is something a firewall wasn’t designed to handle.

 

Your New Colleague Comes With A Lot Of Keys

 

Most business software has a defined job: one system handles payroll, another manages customer records and another keeps track of appointments. An AI assistant connected to several business systems can reach customer and employee data, internal documents, databases, business software, outside tools through APIs and the email and calendar of whoever it works for. Some can act as well as retrieve, meaning they can send the email or update the record themselves.

An application being compromised is already a problem for whatever it was connected to. An AI system connected to several parts of a business can be manipulated across those connections, which potentially gives an attacker a route towards information or actions they couldn’t access directly.

The concern isn’t only how many systems an AI can reach – it’s what it can do once it gets there.

 

The Chatbot Is Now Part Of The Target

 

One of the best-known ways of manipulating these systems is prompt injection, where malicious instructions are placed into content an AI is processing and influence what it does. The indirect version is nastier because the instructions can sit inside a webpage, document or email that the AI is asked to process while the person using it never sees them.

The UK’s National Cyber Security Centre (NCSC) warned in December 2025 that prompt injection can’t currently be treated like a conventional vulnerability with a clean fix. AI models can struggle to properly distinguish between instructions and other content, so the NCSC recommends reducing the likelihood and impact of successful attacks instead of assuming a product can block prompt injection altogether.

The model isn’t the only thing that can be misconfigured; an agent can be given overly broad permissions, connected to the wrong tools or allowed to take actions that should require a person to approve them. If the AI follows a malicious instruction, those permissions determine how far the result can travel.

 

 

The Attacker Doesn’t Need To Break In When The AI Is Already Inside

 

Researchers at Aim Security found a vulnerability in Microsoft 365 Copilot in 2025, later named EchoLeak and tracked as CVE-2025-32711. An attacker could send a specially crafted email to someone at the target company, without the recipient needing to open it. When Copilot processed the email while answering an ordinary work question, hidden instructions could cause it to retrieve sensitive information and transmit it through trusted Microsoft services.

Nobody had to steal a password or break through the company’s network in the usual sense. An email from outside the organisation was enough to influence a tool that already had legitimate access to internal information. The attacker wasn’t trying to become an authorised user; they were trying to influence something that already was one.

 

Giving The AI Less Access Limits The Damage

 

OWASP, the Open Worldwide Application Security Project, is a non-profit organisation that publishes security guidance and its Top 10 list for large language model applications puts prompt injection at number one. It also lists excessive agency, which covers AI systems being given too much functionality, permission or freedom to act.

An AI that summarises customer emails doesn’t need permission to delete them, an assistant that drafts replies doesn’t exactly need permission to send them and a system that can search sensitive financial records doesn’t automatically need permission to change those records.

Saying an assistant “has access” to a system tells you very little on its own but whether it can read, send, edit, delete or make a transaction tells you way more about what happens if that access is manipulated.

 

Somebody Has To Read The Logs

 

Security teams already monitor odd logins, strange network traffic, malware and stolen credentials. With AI, they also need to see what the system is actually doing with the permissions it’s been given.

That could include an AI suddenly using a tool outside its normal workflow, following instructions that conflict with its system rules, accessing sensitive files it normally ignores or moving information between connected services in an unusual way.

Individual actions can still look completely normal – reading a document and sending an email are both ordinary tasks for an AI assistant. The warning sign could be the combination: an assistant that normally summarises meeting notes suddenly reads a confidential contract and sends information from it to an unfamiliar address.

Keeping detailed records of those actions gives security teams something concrete to investigate. They can see what the AI accessed, which tool it used, what action followed and where the information went.

 

Existing Security Isn’t Enough On Its Own

 

Businesses don’t need to replace identity management, access controls, endpoint security, network security or data protection because they’re using AI. Those controls still restrict what an attacker or compromised system can reach, and an AI can’t use a database it hasn’t been given permission to access.

What they don’t necessarily account for is an authorised AI being manipulated through the information it processes. An AI can have permission to open an email, search a document or use a tool without every instruction inside that content being trustworthy.

AI-specific testing, monitoring and governance therefore need to sit alongside the controls businesses already use. The connections need protecting, but so does the AI’s ability to act on what it finds through them.

 

Securing What The AI Can Reach And What It Can Be Told

 

An AI doesn’t need to be hacked in the traditional sense to become a security problem. It can have legitimate access to a company’s systems and still be manipulated into using that access in a way nobody intended.

Businesses need to know what an AI can read, which systems it can reach, what those permissions let it do and which actions need a person to approve. Once AI is given access to sensitive business systems, security has to account for the instructions it encounters as well as the person or system that gave it access.

 

Click Here For The Original Source

——————————————————–

..........

.

.