Enterprise Adoption2 min read

The Real Risk When AI Reads Your Internal Documents

June 2, 2026Synthesized from 1 source: AWS

Amazon has released document-level access controls for its enterprise AI assistant, Amazon Q, and the timing reflects a much larger and growing problem: most organizations are deploying AI assistants that can read internal documents without any meaningful controls over who sees what, exposing HR files, financial data, and legal documents to anyone who asks the right question.

There is a specific failure mode that keeps appearing as organizations roll out internal AI assistants. They connect the AI to their document storage, give everyone in the company access, and assume that because the documents were always available internally, the AI reading them is no different. It is different, in one important way: AI makes asking questions effortless and instantaneous, which means employees now retrieve information they would never have bothered searching for manually.

A procurement manager at a retail group would rarely dig through a shared drive looking for executive salary bands. But if the company AI assistant can answer any question in seconds, that same manager might ask it something innocuous, and the answer might pull from documents they were never supposed to see.

This is the oversharing problem. It is not usually malicious. It happens because AI systems, by default, try to answer questions as helpfully as possible using everything they have access to. Research across 22 million real enterprise AI prompts from 2025 found that 22% of files flowing through these systems contain sensitive information, including merger documents, financial projections, and employee records.

Amazon's update to its enterprise AI tool, Amazon Q, addresses this directly. Organizations can now set rules at the individual document or folder level, specifying which employees or teams are allowed to see which files. When someone asks the AI a question, it checks those rules before pulling any document into its answer. Documents without explicit permission are blocked by default. No permission listed means no access, which is the safe direction to fail.

The feature covers two common configurations. One uses a single rules file to manage access across entire folders. The other attaches rules directly to individual documents. The folder-level approach is easier to manage. The document-level approach is more precise and faster to update when someone's role changes.

There is a subtler risk that the feature also addresses. Any employee with access to an organization's document storage could, in theory, create a new AI knowledge base pointing at the same storage without enabling any access controls. Amazon Q now lets administrators restrict which employees can even create knowledge bases against sensitive storage buckets. Without that control, the document-level rules could be bypassed simply by setting up a new AI connection.

This matters beyond Amazon's product. Microsoft Copilot, which is embedded across Word, Outlook, and Teams, has the same underlying challenge. When an employee asks Copilot to summarize recent discussions or find relevant documents, Copilot searches across everything that employee can technically access. Research from 2025 found that in many organizations, files marked as available to the whole organization include content that was never intended to be broadly read. AI assistants expose that problem because they make retrieving that content trivially easy.

The regulatory pressure on this is building fast. Sensitive information disclosure is now the second most common AI security failure category, up from sixth in 2023. The EU AI Act's enforcement for high-risk systems begins in August 2026. GDPR fines can reach 4% of global annual revenue. Organizations with poor AI access controls are not just facing internal embarrassment risks; they are facing auditable compliance failures.

The practical implication for any organization running an internal AI assistant is straightforward. The right question to ask is not whether the AI is useful, it clearly is. The question is whether the AI can surface documents to employees who would not normally have access to them. If the answer is yes, and in most early deployments it is, then access controls at the document level are no longer optional. They are the thing standing between an AI assistant and a compliance problem.

Stay informed

Get AI intelligence like this delivered to your inbox.


You May Also Find Valuable