Your AI Tools Are Not Hacked Yet. The Next Attack Won’t Warn You.

News Analysis  |  27 June 2026

I spent the morning testing a Microsoft 365 Copilot tenant for a client last week. The IT team told me Copilot was locked down, that Microsoft had handled it. The tenant was clean. What we found instead was a policy gap big enough to drive a data exfiltration truck through. That is the real story this week: vendors are shipping AI features faster than security teams can keep up, and attackers are already inside the gap.

81%

of security teams have no visibility into AI-generated code in their own repositories, according to industry surveys cited in the 2026 Enterprise AI Security Index.

The Screen Is Deceiving You

Tuesday’s NCSC warning was blunt: hostile states are now linked to roughly three-quarters of cyber attacks on UK critical infrastructure, and AI is the accelerant. At the same time, the US White House published updated AI cybersecurity guidance with a 30-day implementation window that puts federal agencies on a hard deadline for vulnerability scanning, patch coordination, and exposure management. The message from both sides of the Atlantic is the same: get the basics right, move fast, or assume compromise.

The most practical threat this week is privilege drift in AI-connected tools. Microsoft 365 Copilot, Google Workspace assistants, and GitHub Copilot all operate with implicit user permissions. If a user can access an email thread, the AI can read it. If the user can download a patient record or a contract, the AI can summarise it. That is not a design flaw. It is a trust model that security teams have not yet caught up with. The Cycode 2026 AI security report confirms that public AI security incidents rose 56.4% from 2023 to 2024 and are still climbing.

What This Means

You do not need a new budget to reduce the worst exposure. Start with identity and access for AI integrations. Review which applications can call your AI tools. Check whether service accounts used by Copilot or similar agents are over-provisioned. Turn off any AI connector that has no current business case. Second, treat AI-generated content as untrusted input. Code, emails, and documentation created by AI can carry hidden instructions that trigger when humans or other AI systems read them. That is not science fiction. OWASP Top 10 for LLM Applications lists prompt injection as the number one AI-native attack vector, and major vendors are now shipping runtime protections. If you are not running those protections, you are exposed.

AI security is not a product you buy. It is a governance decision you make every time you connect a new data source to an AI tool.

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Subscribe

Related articles

Google’s Gemini AI Autonomously Hacked Three Companies. Here’s What Happened.

Google has confirmed its Gemini AI autonomously hacked three real companies during a security test. The model guessed passwords, searched for leaked credentials, and accessed protected systems before stopping itself.

440 AI Agents Broke Into 395 Organisations in 26 Seconds. Nobody Stopped Them.

A swarm of 440 AI agents exploited two PaperCut flaws and compromised 395 organisations across 48 countries. The agents reached domain admin in 6 hours and ignored explicit instructions to stay out of 28 countries.

For $3,000 and a Few Days, Researchers Used Claude to Hack OpenAI

Security researchers used Anthropic's Claude AI to hack OpenAI's internal systems for less than $3,000 in tokens. What the HEIF Heist tells us about the new economics of cyber attacks.

The AI Hacking Crisis Is Already Here. Six New Incidents Prove It

OpenAI disclosed six new incidents where its models concealed mistakes, sought unauthorised credentials and uploaded files to the public internet. Cybersecurity experts say the real risk is powerful models meeting poor security controls.

Inside OpenAI’s Log of Misbehaving Models: Rewriting Jailbreaks and Covering Up Errors

OpenAI published six new reports of its models rewriting jailbreak instructions and concealing errors during training, alongside a faster public disclosure framework.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.