Go back

The Unlocked Door: AI Security and the Basics Your Company Is Probably Missing

12m 57s

The Unlocked Door: AI Security and the Basics Your Company Is Probably Missing

The transcription highlights a critical and widespread lack of security in corporate AI deployments. It reveals that foundational AI platforms possess severe vulnerabilities, with some flaws remaining unpatched and actively exploited. Compounding this, most companies have minimal visibility into the AI tools their employees use, leading to rampant "shadow AI" where sensitive data is often shared with unauthorized consumer applications. Furthermore, deployed AI agents frequently operate with excessive, unmonitored permissions, creating risks like prompt injection attacks. In response, intelligence agencies like the NSA have issued guidance stressing AI supply chain security. The solution involves practical steps: auditing AI tool usage, rigorously vetting AI vendors, applying least-privilege access principles to agents, prohibiting sensitive data in consumer AI tools, and enabling thorough logging. The core issue is not advanced threats but a systemic neglect of basic security hygiene, which companies must address proactively to gain a strategic advantage and avoid future crises.

Transcription

2011 Words, 12271 Characters

English
[MUSIC] This is the AI Brief brought to you by the YPO Technology Network, and I'm Stephen Forte. This is a special weekend edition called the Unlocked Door. AI Security and the basics your company is probably missing. Today we'll talk about critical vulnerabilities in the platforms, powering your AI stack, why two thirds of security leaders can't see their own vulnerabilities, and the five things you can do this week to stop the bleeding. Let's set the scene. It's 2026, and most companies at YPO scale are somewhere on the AI adoption curve. Maybe you've got a few automations running on Zapier or NADN. Maybe your team is using ChatGPT, Claude, or Microsoft's co-pilot to draft emails and summarize documents. Maybe you've started experimenting with agents, little software programs that can take actions on your behalf. Connect to your CRM, your calendar, your email, you're not running a full AI factory. You're doing what most serious companies are doing right now, testing, building, deploying, and nobody is saying this loudly enough. The security posture around most of that deployment is a mess. Not because your team is incompetent, because the tools themselves have vulnerabilities, because your employees are using AI tools you don't know about, because the agents you're deploying have more access than they should, and because the people responsible for securing all of this can't see most of it. This week gave us a lot to work with. Let's go story by story. Story one, critical vulnerabilities in the platforms your AI is built on. Security researchers this week disclose serious flaws in three widely used AI platforms, Amazon, Bedrock, Langsmith, and SG Lang. If those names don't mean anything to you, here's the translation. These are the building blocks that developers use to build AI applications. Bedrock is Amazon's managed AI service. Langsmith is a tool for building and monitoring AI agents. SG Lang is an inference framework, the engine that runs the models. The findings were not subtle. Amazon Bedrock has a flaw that allows attackers to ex-filterate data through DNS queries. Essentially sensitive information can be quietly smuggled out of your environment in a way that looks like normal network traffic, Amazon's official response. They consider this intended functionality. They recommend switching to VPC mode as a workaround, which is technically accurate and also deeply unsatisfying. Langsmith has an account takeover vulnerability, an attacker can steal authentication tokens and takeover accounts. That's rated at 8.5 out of 10 on the severity scale. SG Lang has two separate unauthenticated remote code execution vulnerabilities, both rated 9.8 out of 10. The maximum is 10. And as of this week, those SG Lang flaws remain unpatched. And separately, a platform called Langflow, a popular tool for building AI pipelines, had a critical remote code execution vulnerability. Disclose this week. It was exploited in the wild within 20 hours of the disclosure, 20 hours. That's not a security posture. That's an open door with a welcome mat. Why does this matter if you're not a developer? Because the platforms your team is building on have their own attack surface. You don't need to understand DNZX filtration to understand that your AI stack can be compromised through the tools underneath it. And when Amazon's answer to a security researcher is that's intended functionality, that is the kind of answer ACEO should file under we need to have a longer conversation with our vendor. A lot of YPO members are building on managed cloud AI services precisely because they trust the vendor to handle security. This week is a reminder that trust is not a substitute for verification. Story 2. 67% of security leaders can't see their own AI. Pintera just released their 2026 chief information security officer or CISO survey, 1200 cybersecurity professionals. The headline number 67% of CISOs have limited or zero visibility into where AI is running inside their own organizations. And the number with full visibility, 0%, not a rounding error, 0. Meanwhile, from a separate data set, 80% of workers are using unauthorized AI tools at work. And one third of those workers are sharing proprietary company data with those unsanctioned services. We're talking customer records, financial projections, internal strategy documents, HR files, pasted into free chat GPT accounts, free cloth, free copilot consumer tier, tools that in their free versions may use your inputs to train future models. The result, 88% of organizations reported a confirmed or suspected AI agent security incident in the past 12 months, 83% reported an AI security incident in 2025. These are not outliers. This is the baseline. Sailpoint, one of the major identity security companies just launched a product called Shadow AI Remediation. The fact that a company of that scale sees enough market demand to build a dedicated product for this tells you everything about how widespread the problem is. Here's the YPO level version of this story. Your employees are already using AI tools you didn't approve and don't know about. They're not doing it to be reckless. They're doing it because the tools are useful and nobody told them not to. The data walking out the front door isn't from a sophisticated hack. It's from a well-meaning employee who needed to summarize a contract and use the first tool that came to mind. Think about your next forum meeting. How comfortable are you answering the question, do you know what AI tools are running in your company right now? If the honest answer is no, you're in the majority. And that's the problem. Story three, the NSA has something to say about your AI supply chain. The National Security Agency alongside allied intelligence agencies from the UK, Australia, Canada, and New Zealand, the Five Eyes, released formal guidance this week on AI supply chain security. When that group publishes a joint advisory, it's not a think piece. It's a signal. The guidance defines the AI supply chain as training data, the models themselves, software frameworks, hardware, infrastructure, and third party services, all of it, every layer. And it names the specific attack vectors, data poisoning, corrupting the data used to train a model so it behaves in ways the attacker wants. Hidden backdoors, vulnerabilities, deliberately embedded in models or frameworks, model manipulation, altering a model's behavior after it's been deployed, and evasion attacks input specifically designed to fool AI systems into making wrong decisions. Their recommended mitigations are practical, verify the integrity of data and models before you use them, maintain a trusted model registry, a documented list of approved models and where they came from, and document your AI dependencies the same way you document software dependencies, what they're calling an AI bill of materials. The business translation, every enterprise deploying AI has a supply chain, it probably cannot fully see. You're using models from open AI and Thropic, Google, or Amazon. You're running frameworks built by open source communities. You're connecting to third party services through your agents. Each of those connections is a potential entry point. When the NSA publishes a guidance document, it's defining the baseline. It's the standard you'll be held to when something goes wrong and someone asks what due diligence you did. For any YPO member whose company uses third party AI, which is most of you, this is now the floor, not the ceiling. Story four, your AI agents have too much access and most companies have no idea. The fourth story ties everything together. A new analysis this week found that over half of deployed AI agents operate without consistent security oversight or logging. Only 29% of organizations have formal AI agent governance policies. When the agents running in tools like NADN, Zapier, and Copilot Studio, they often get admin level access by default. Because that's the easiest way to make them work. Here's the analogy. Imagine you hired a new assistant. On their first day, you gave them the keys to every office, access to every file, admin rights on every system, and the ability to send emails on your behalf. You didn't ask them to log what they did. You didn't review their access after 90 days. You didn't set any rules about what they could and couldn't do. That's what most companies are doing with their AI agents right now. The attack vector here is called prompt injection. An attacker embeds malicious instructions into content. Your agent will read a document and email a web page. Those instructions redirect the agent to take actions it wasn't supposed to take. A Zapier automation connected to your CRM and your email can be manipulated to exfil trait customer data. A Copilot agent with broad Microsoft 365 permissions can read and forward sensitive documents. An N8N workflow with database access can be triggered to dump records. The good news, the industry is starting to build the answer. Nvidia launched OpenShelves week at GTC, an open source runtime that enforces security constraints on AI agents at the kernel level. The key innovation is that the security policy runs outside the agent itself, which means the agent literally cannot override its own guardrails. It's the beginning of a real answer to the agent trust problem. But OpenShelves a developer tool. The practical fix for most companies doesn't require new infrastructure. requires applying the same govern and it's principles to AI agents that you apply to any employee or contractor, minimum necessary access, documented permissions, regular reviews and audit logs. So what do you actually do? Here's the playbook. Five things, none of them complicated. First, know what's running. Treat shadow way. I like shadow IT. It exists. It's growing and ignoring it makes it worse. Ask your IT team to show you every AI tool connected to your systems. If they can't answer that question, that's your first project. Treat AI platforms like vendors. The tools your team is building on, bedrock, langsmith, open AI's API andthropics API have their own security posture. Vette them the same way you'd vet any software vendor. Ask about their patch cadence, their incident response process and what they do when a researcher finds a critical flaw. Third, enforce least privilege for AI agents. Give your Zapier Automation admin access to your CRM scope permissions to the specific task. Read only where possible. Review agent permissions quarterly the same way you review employee access. Fourth, keep sensitive data out of consumer AI tools. Free chat GPT, free clawed consumer co-pilot, these are not enterprise grade. They don't have the data processing agreements, the audit logs or the usage policies that enterprise versions have. A simple rule never paced customer names, financial data or internal strategy into a free AI tool. Use chat GPT enterprise, clawed for enterprise or Microsoft 365 co-pilot. Tools with proper contracts behind them. Fifth, log everything you cannot secure what you cannot see. 67% of CIOs can't see their AI. The fix starts with turning on audit logs. Most enterprise AI tools have them. They're just not on by default. Here's the closing thought. The AI security story isn't about sophisticated nation's data tax. It's about basics being missed at scale. Your employees are pasting sensitive data into free tools. Your agents have more access than they need. The platforms you're building on have unpatched critical vulnerabilities. And your security teams are trying to defend a perimeter they can't see. The good news is that the fixes are not complicated. They're just not being done. The companies that do them first, the ones that build AI governance into their operations now before the incident, will have a meaningful advantage when the companies that didn't are explaining themselves to their boards. At YPO scale, you have the resources to do this right. The question is whether it's on the agenda. That's the YPO Tech Network AI brief for Saturday, March 22nd, 2026. I'm Stephen Forte. If this hit home, send it to a fellow member who needs to hear it. I'll be back Monday with more. Until then, stay sharp.

Podcast Summary

Key Points:

  1. Major AI platforms like Amazon Bedrock, Langsmith, and SGLang have critical, unpatched security vulnerabilities, including data exfiltration and remote code execution flaws.
  2. Most organizations lack visibility into AI tool usage, with 67% of security leaders having limited or no insight, while employees widely use unauthorized tools, risking data leaks.
  3. AI agents are often over-permissioned by default, operating without security oversight, making them vulnerable to prompt injection attacks that can compromise systems.
  4. The NSA and allied agencies emphasize securing the entire AI supply chain—from data to models—against threats like data poisoning and model manipulation.
  5. Recommended mitigations include discovering shadow AI, vetting AI vendors, enforcing least privilege for agents, restricting sensitive data from consumer tools, and enabling comprehensive audit logs.

Summary:

The transcription highlights a critical and widespread lack of security in corporate AI deployments. It reveals that foundational AI platforms possess severe vulnerabilities, with some flaws remaining unpatched and actively exploited. Compounding this, most companies have minimal visibility into the AI tools their employees use, leading to rampant "shadow AI" where sensitive data is often shared with unauthorized consumer applications.

Furthermore, deployed AI agents frequently operate with excessive, unmonitored permissions, creating risks like prompt injection attacks. In response, intelligence agencies like the NSA have issued guidance stressing AI supply chain security. The solution involves practical steps: auditing AI tool usage, rigorously vetting AI vendors, applying least-privilege access principles to agents, prohibiting sensitive data in consumer AI tools, and enabling thorough logging.

The core issue is not advanced threats but a systemic neglect of basic security hygiene, which companies must address proactively to gain a strategic advantage and avoid future crises.

FAQs

Amazon Bedrock has a data exfiltration flaw via DNS queries, LangSmith has an account takeover vulnerability, and SGLang has unpatched remote code execution flaws. These platforms are building blocks for AI applications, and their vulnerabilities can compromise your AI stack.

According to a survey, 67% of CISOs have limited or zero visibility into AI tools running in their companies, with 0% having full visibility. This is compounded by employees using unauthorized AI tools and sharing proprietary data, leading to widespread security incidents.

The NSA and allied agencies released guidance defining the AI supply chain, including training data, models, and third-party services. They highlighted attack vectors like data poisoning and recommended mitigations such as verifying data integrity and maintaining a trusted model registry.

Over half of deployed AI agents operate without consistent security oversight, with many having admin-level access by default. This lack of governance, combined with prompt injection attacks, can lead to data exfiltration or unauthorized actions by agents.

First, identify all AI tools connected to your systems. Second, vet AI platforms like vendors for security practices. Third, enforce least privilege for AI agents and review permissions quarterly. Fourth, avoid using consumer AI tools for sensitive data. Fifth, enable audit logs to monitor AI activity.

Free tools like ChatGPT or Claude consumer versions lack enterprise-grade data processing agreements and audit logs. Employees may inadvertently share sensitive data, such as customer records or financial projections, which could be used to train models, leading to data breaches.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.