Interactive guide · Bought, built, already there · No sign-up - Where AI gets in, and what holds it.
Every AI tool in your business came through one of three doors. You bought it, you built it, or a vendor switched it on inside something you already pay for. Each door leaks differently and each has a different owner. Walk through them, then check your own.
Door 3 · Already there · A vendor switched it on
The door that was never closed. Copilot in Outlook and Teams, AI summaries in the CRM, suggested replies in the help desk, a “smart” feature in the HR system. It arrived in a routine update.
- Copilot in Outlook and Teams
- AI summaries in the CRM
- Suggested replies in the help desk
- A setting that shipped switched on
Why three doors - Most businesses guard one door and leave two open.
Policies tend to cover the tool that was bought on purpose. The tool a developer built on a weekend and the feature a vendor enabled overnight are the ones nobody has written down.
- of staff use AI in ways that breach policyKPMG and University of Melbourne, Trust in AI 2025
- 48 %
- of organisations hit by an AI-related breach lacked proper AI access controlsIBM Cost of a Data Breach Report, July 2025
- 97 %
- automated decisions must be named in your privacy policyPrivacy and Other Legislation Amendment Act 2024
- 10 Dec 2026
Walk through each door - What leaks, and what holds it.
Choose a door, then choose a leak. The control that holds it lights up, with the guidance or the incident behind it. Every claim links to its source.
The door that was never closed. Copilot in Outlook and Teams, AI summaries in the CRM, suggested replies in the help desk, a “smart” feature in the HR system. It arrived in a routine update.
What leaks · choose one
What holds it
- Watch the settings, not just the invoices
- Fix permissions before switching it on
- Review releases, and keep a human on the actions
Choose a leak on the left to see which control holds it.
Seen in the wild
In June 2025 Aim Security disclosed EchoLeak, CVE-2025-32711: a zero-click prompt injection that made Microsoft 365 Copilot exfiltrate data from a user’s files through a crafted inbound email. No user action was needed. Microsoft fixed it server-side and reported no evidence it had been exploited.
Source: Microsoft Security Response Center, June 2025
Who holds the keys - Each door shifts how much control you have.
Buying gives you a contract. Building gives you the architecture. The door that was already open gives you only the settings, and that is where most firms hold the least.
How much you control
Only the settings. You did not choose the model, the data flow or the release date, and you may not be told when they change.
- What is on the line
- Mailboxes, files, chat history and the metadata that describes them.
- Who owns this door
- Whoever administers the tenant. Usually your IT provider, sometimes nobody in particular.
- The first control to put in
- A review of what “everyone” can see before any assistant is enabled.
The claims decoder - Six things a vendor will say. Turn each over.
None of these lines is false. Each one just leaves out the question that matters.
Ask instead
What is the tested bypass rate, and who tested it?
OWASP puts prompt injection first on its 2025 list because no filter stops it completely. A vendor who says “blocks” rather than “reduces” has not measured it.
Source: OWASP GenAI Security Project, November 2024
Ask instead
On which plan, and where does it say that in the contract?
Defaults differ between consumer and business tiers of the same product, and the setting can be changed by the vendor. The promise only counts once it is a clause.
Source: Office of the Australian Information Commissioner, October 2024
Ask instead
Then what can your users already see?
This claim is true and it is the problem. An assistant that inherits permissions inherits every over-shared folder, and it makes them searchable in one sentence.
Source: Microsoft Learn, Current documentation
Ask instead
Which region holds the data, and who are the sub-processors?
Sending personal information overseas is a disclosure under Australian Privacy Principle 8. “Enterprise grade” names no region, no certification and no processor.
Source: Office of the Australian Information Commissioner, October 2024
Ask instead
What data does the feature send, and where is the off switch?
A default that shares content with a model is a new data flow, whatever the release notes call it. If there is no off switch, that is the answer.
Source: National AI Centre, Department of Industry, Science and Resources, October 2025
Ask instead
What can it do without a person, and what is the rollback?
OWASP calls the risk excessive agency: an assistant with more permissions than its task needs. The 2026 joint guidance on agentic AI asks for a distinct identity per agent, least privilege and a human approving high-impact actions.
Source: CISA, NSA, ASD’s ACSC and partners, April 2026
The morning after an update - Four of these eight settings widen the door. Find them.
A vendor release landed overnight and switched on eight settings. Open each one. The console keeps score. Sample, synthetic data.
Admin console
Harbour Conveyancing · Sample tenant, synthetic data
Updated overnight · 8 settings changed
Found 0 of 4 that widen the door · 0 of 8 checked
Your door check · Six questions · Two minutes - Which of your doors is standing open?
Two questions per door. The report card fills in as you answer and names the door to close first, with the fixed-price step that closes it. Nothing you enter leaves your browser.
What holds all three - One ladder covers every door.
The same five steps we scope every engagement with. Each one covers all three doors, so nothing depends on guessing which door a tool came through.
- Step 1: Check
- Step 2: Discover
- Step 3: Guard (current)
- Step 4: Ship
- Step 5: Sustain
01
Check
Find every AI tool in use across all three doors, including the ones on personal cards and the features that switched themselves on.
02
Discover
Rank what is worth doing on value, effort and risk, so the first build is the one that earns its guardrails.
03
Guard
A plain-words policy, a register with owners, the Privacy Act wording, and a Copilot oversharing review before anything is enabled.
04
Ship
One workflow built with a human review step in front of every action it can take, measured before and after.
05
Sustain
A quarterly pass over vendor settings and the register, because defaults change between reviews.
Sources - Every claim on this page has one.
The framing is ours. The facts are theirs. Where a figure could not be verified it is not on the page.
- 01OWASP Top 10 for LLM Applications 2025OWASP GenAI Security Project · November 2024
- 02Engaging with Artificial IntelligenceAustralian Signals Directorate’s ACSC, with CISA, NCSC-UK and partners · January 2024
- 03Deploying AI Systems SecurelyNSA, CISA, FBI, ASD’s ACSC and partners · April 2024
- 04AI Data Security: best practices for securing data used to train and operate AI systemsNSA, CISA, FBI, ASD’s ACSC and partners · May 2025
- 05Guidance for AI Adoption: six essential practicesNational AI Centre, Department of Industry, Science and Resources · October 2025
- 06Guidance on privacy and the use of commercially available AI productsOffice of the Australian Information Commissioner · October 2024
- 07Privacy and Other Legislation Amendment Act 2024, automated decision-making transparencyOffice of the Australian Information Commissioner · Commences 10 December 2026
- 08Trust, attitudes and use of artificial intelligence: a global study 2025KPMG and the University of Melbourne · April 2025
- 09Cost of a Data Breach Report 2025IBM and Ponemon Institute · July 2025
- 10LLMjacking: stolen cloud credentials used in new AI attackSysdig Threat Research Team · May 2024
- 11Malicious AI models on Hugging Face backdoor users’ machinesJFrog Security Research · February 2024
- 12A small number of samples can poison LLMs of any sizeAnthropic, UK AI Security Institute and the Alan Turing Institute · October 2025
- 13CVE-2025-32711, Microsoft 365 Copilot information disclosure (EchoLeak, reported by Aim Security)Microsoft Security Response Center · June 2025
- 14Slack under attack over sneaky AI training policyTechCrunch · May 2024
- 15Get ready for Microsoft 365 Copilot with SharePoint Advanced ManagementMicrosoft Learn · Current documentation
- 16Careful adoption of agentic AI servicesCISA, NSA, ASD’s ACSC and partners · April 2026
- 17Work Trend Index 2024: AI at work is here, now comes the hard partMicrosoft and LinkedIn · May 2024
- 18AI Risk Management Framework: Generative AI Profile (NIST AI 600-1)National Institute of Standards and Technology · July 2024
This page is general information, not legal advice or a security assessment. The settings console and the tenant name are synthetic. Nothing entered in the door check is collected.
Want the whole picture, not just the doors?
Nine questions, three minutes, nothing leaves your browser. The scorecard shows which of the five steps you are on and which service fits.
Want the three doors checked in your business? Book a call.
Twenty minutes. We tell you which door to close first, what it costs to close, and whether you need us at all.
+61 490 083 850 · Wollongong, NSW