Stories

Employee-built AI tools are a leading breach cause, and one hijack works across major agents

Citizens Advice wants a guaranteed route to a person, and Gartner expects more than 40% of agentic AI projects to be canceled by the end of 2027.

By , Senior AI ConsultantEdition of

5stories
4minute read
In This Edition

Finance, HR and marketing departments are building software. Small AI tools that do one piece of a job on their own, made by the person who wanted them, with no ticket raised and nobody reviewing the result.

Take a clerk in accounts payable with a backlog of supplier invoices. She describes the job in ordinary sentences and gets back a working script: open the shared mailbox, read each invoice, match it against the purchase order, write the figures into the ledger. It runs every morning after that, under her login, and it keeps running after she moves to another team.

IBM's breach data attributes a bigger share of costly breaches to tools built this way than it did a year ago. Counting them does not require reading any code. Each one can be listed by what it can open: the mailbox, the customer records, the payment file, and the login it uses to get in.

In IBM's Cost of a Data Breach report, one in five organizations reported a breach involving staff use of unapproved AI tools, and those breaches cost about $670,000 more than the average. Of the breached organizations that had an AI-related incident, 97% said they lacked access controls around AI. Of the 600 organizations the Ponemon Institute surveyed for the same report, 63% had no policy on AI use at all.


A security researcher typed an instruction into the title of a code change request on GitHub, and Anthropic's automated code reviewer answered by posting its own access key in a public comment. Aonan Guan, working with two researchers at Johns Hopkins University, ran the same technique against Google's Gemini CLI Action and GitHub's Copilot Agent. It worked on all three.

The weakness underneath is the one researchers have now found in agent products from Microsoft, Google, OpenAI, Salesforce and GitHub: an agent cannot tell a real instruction from hidden text it happens to read while working. An agent hijacked this way moved roughly $150,000 out of a crypto wallet it controlled.

Meta called its new Muse assistant secure by design. Weeks later a researcher found an unpatched flaw that lets a program running on a Mac take over the assistant's access to a person's accounts, and to a connected iPhone. A United Nations science panel, reviewing OpenAI's July hack of Hugging Face, concluded that safety controls are falling behind what these systems can do, and urged governments to act on agent risks now rather than wait for scientific certainty.

Anthropic, Google and Microsoft each paid Guan a bounty for the finding. None of them published an advisory, and none of the flaws was given a public tracking number.


Does a year of chat history make a business AI tool better at its job? It does not. Logs and transcripts pile up, and the tool decides no better in month twelve than in week one, because nothing in the setup turns yesterday's corrections into tomorrow's behaviour.

Microsoft's chief executive, Satya Nadella, makes the point from the other side: the advantage belongs to the company that builds a learning system around the model, a record of which answers people accepted and which they overruled, written back into the instructions the tool works from. Built that way, it survives a change of model underneath.

The subscription for a tool that answers no better in its second year costs the same as it did in the first. Gartner expects more than 40% of agentic AI projects to be canceled by the end of 2027, blaming escalating costs, unclear business value or inadequate risk controls.


Some people told Citizens Advice the chatbot seemed rigged to "make me give up". The charity's research found these systems wasted time, caused stress and delayed problem solving for more than half of the users surveyed, and almost half of those who had to use one found it unhelpful. Citizens Advice now wants energy, banking, phone and internet providers in the UK to guarantee customers a right to talk to a human.

The charity gave one-on-one help to more than 2.7 million people in England and Wales last year, and says the chatbots make it harder for people who struggle with digital services to sort out a problem with an essential one.

Cutting a support team removes a cost from the payroll and creates others: the repeat contact, the complaint, the customer who does not renew. Klarna's assistant handled 2.3 million chats in its first month in 2024, work the company put at 700 full-time agents. In May 2025, its chief executive, Sebastian Siemiatkowski, told Bloomberg that Klarna was recruiting human agents again, so that a customer who wants a person can always reach one.


xAI has put Grok 4.7 on sale at the lowest prices in the market. Price is the first line most buyers compare when two AI tools appear to do the same job.

The cost of corrections appears on no invoice. A team pays it in hours, checking the output and doing parts of the job again.

Independent testing puts Grok 4.7 well behind OpenAI's GPT-6 and Anthropic's Claude on general reasoning, and further behind still on real coding tasks.


THE DAILY BRIEF

Get the next edition in your inbox.

A five-minute read, every weekday morning.

Free forever · Unsubscribe anytime

Share This Brief