Stories

Only daily AI users feel good about their job security, and most employers have no AI rule

Microsoft Copilot revealed an undocumented parameter that ran prompts with no click, and Z.ai reports 2,436 flaws found across 269 open-source projects.

By , Senior AI ConsultantEdition of

3stories
3minute read
In This Edition

Thirty percent of US workers use AI every day, 34% a few times a week, 37% not at all. Only the daily group feels good about what the technology is doing to their job security. The weekly users and everyone below them told CNBC and SurveyMonkey that AI makes them feel less secure, in a survey of 1,686 US workers and students taken in July. Daily users were also the only group with anything positive to say about the job market as a whole.

Time saved is not the disputed part: the people surveyed reported that benefit whether or not the tools made them feel secure. Their employers have mostly said nothing. More than half of them have no official AI policy, and very few have banned the technology or drawn any hard line around it, the same survey found.

Without a rule, an occasional user decides each question alone. Which documents go into the tool. Whether a customer email drafted that way should say so. Whether a manager will read the habit as initiative or as a shortcut. In a SurveyMonkey study of 6,330 adults in February, 37% of workers who use AI said it almost feels like cheating at their job. Training is not filling that space either: The Conference Board, surveying nearly 1,300 workers in July, found 55% of them using AI regularly and only one in three who had received any employer training in the previous six months.

In December 2023, the same two pollsters found the reverse of today's result: back then, the more a worker used AI at work, the more that worker worried about losing the job.


Varonis, a security firm, wanted Microsoft Copilot to run an instruction without the user pressing anything. Copilot refused: a powerful command needs a deliberate action from the person, a keypress or a click. So they kept asking why. Why was automatic execution impossible? What happened when a page loaded with text already in the prompt field? Copilot answered every question, listed the parameters Microsoft had switched off, and named one that appears in no documentation: autorun=1.

Under certain session conditions, Varonis found, that parameter makes a prompt carried inside a link run as the page loads, with no click and nothing shown on screen. One click on a crafted link was then enough to pull data from the victim's inbox, from connected apps and from the assistant's stored memory. Varonis found no sign that anyone had used it.

No bug in Outlook or OneDrive was involved. The attack used Copilot's ordinary permission to act for a signed-in user, which is the permission a company grants the day it connects an assistant to its email and its customer records.

Varonis reported the flaw in December 2025. Microsoft switched off the link parameter that fed text into the prompt in February 2026 and shipped the fuller fixes on 18 August 2026, eight months after the report.


Z.ai released GLM-5.3 on 14 August, and says the file anyone can download and run on their own machines will follow free of charge once its safety checks are done, about two weeks later. On CyberGym, a test of finding known flaws in source code, Z.ai reports 84.5% for the new model against 77.2% for its previous one, close to the top paid models from OpenAI and Anthropic. Those are the company's own figures, and no outside team has reproduced them.

Finding a flaw and exploiting one are separate jobs, and the model is much weaker at the second: 54.4% on Z.ai's own exploitation test, up from 24.4%, against more than 76% for the paid leaders. The cheap part is the search, reading a large body of code and listing where it can be broken. Z.ai has put that part on Hugging Face as a free tool called OpenVuln, so the volunteer who maintains a piece of open-source software can scan its code for nothing, and so can whoever wants to break into it.

Working with security teams, Z.ai says its models identified 2,436 flaws across 269 open-source projects after expert review and the removal of duplicates, 1,097 of them critical or high severity, including in Linux, WebKit and FreeBSD. The oldest of them dated from 1981, and on average a flaw had been in the code 26.6 years before the model found it.


THE DAILY BRIEF

Get the next edition in your inbox.

A five-minute read, every weekday morning.

Free forever · Unsubscribe anytime

Share This Brief