The newest AI models are getting incredibly good. They can read emails and write and run code. Search through company documents. Use tools. Access databases. Make decisions. And in some cases, act on our behalf.
If someone manages to manipulate the information the AI reads, they may be able to manipulate what the AI does.
This is where things like prompt injection, data leakage, excessive permissions and insecure integrations become very serious. AND I KNOW - YOU'LL SAY - BUT MY PERSONAL AGENT SAID IT IS SECURE AND SAVE. I will jsut smile :)
The scary part? You don't always need to hack the AI itself. You can attack the information around it. A document. An email. A website. A customer message. Something the AI trusts. And if the AI has too much access, a small mistake can become a big business problem.
So I think the next stage of AI adoption needs to be less about: "What can AI do annd more about: "What should AI be allowed to do?" Give AI access to what it needs.
Nothing more.
Keep sensitive systems separated. Log what agents do. Require approval for important actions. And never assume that because an AI sounds intelligent, it is secure. The smartest AI in the world can still be tricked. And as AI agents become part of everyday business, AI security will become a business requirement, not just an IT problem.
And the worst thing is - that still no one cares about the thing. they jsut happy they can code, build apps and have a team... be careful
Get an email when Thomas publishes