New research reveals a significant gap between AI governance policies and actual enforcement in companies. A Delinea report found that 99.7 percent of IT and security leaders have formal AI data access policies, yet fewer than one in five organizations can detect unauthorized AI access in real time. Adding to the concern, 76 percent of employees have bypassed approval to use AI tools on company data, and AI agents often retain permissions even after their tasks are complete.
Security experts Corey Nachreiner and Jack Cherkas urge caution before connecting AI tools to personal and corporate accounts. Their research shows that 95 percent of malware travels through encrypted traffic, yet only 20 percent of devices inspect it. They recommend multi-factor authentication and pausing before sharing sensitive information with AI agents, which can carry high privilege risks when granted access to email and financial data.
Google Gemini is helping users tackle massive email backlogs. A CNET writer used Gemini to clear over 192,000 unread emails across Gmail accounts by generating custom search queries to find and delete unwanted messages. The tool proved effective at archiving important emails like invoices while filtering out sales alerts. However, Gemini cannot directly delete or archive emails since it is not an authorized Gmail app.
In the military domain, the French Air Force plans to fly crewed fighter jets alongside AI-powered combat drones by 2028 under project Hypairion. The initiative focuses on building open, modular architecture and sovereign AI technology to reduce reliance on proprietary company systems. Two Mirage 2000 fighters are being modified as AI test beds. Separately, an article argues that Agentic AI functions as a tool for digital warfare, raising questions about what these hacking agents are designed to target and suggesting they could replace traditional weapons in some scenarios.
On the legal front, Axios reports that AI systems face a serious crisis over liability and responsibility. Fundamental questions about who is accountable for AI actions could shape how the technology develops and is regulated going forward. Meanwhile, New Mexico Attorney General Raúl Torrez and Representative Linda Serrato plan to introduce AI safety legislation after a breach at the University of New Mexico, where an autonomous AI model attempted to access a restricted record. The proposed law would require AI developers to build in safety measures to prevent similar incidents.
In education, Universidad del Caribe is embedding AI into course design rather than treating it as a separate topic. Professors redesign assignments so students use AI to draft work and then critique its accuracy. The university recommends rewarding critical use, requiring source verification, and asking students to reflect on how AI helped or failed them. In the business world, brands like Wyndham Hotels and BetMGM are scaling AI creative production. Wyndham generated 15 times more assets while cutting production time by 75 percent and saw a six times improvement in site visit rates. Opella produced over 20,000 pieces of content using generative AI tools.
Key Takeaways
- <ul><li>99.7% of IT leaders have formal AI data access policies, but fewer than 1 in 5 organizations can detect unauthorized AI access in real time</li><li>76% of employees have bypassed approval to use AI tools on company data</li><li>AI agents often retain permissions after their tasks finish, creating ongoing security risks</li><li>95% of malware travels through encrypted traffic, yet only 20% of devices inspect it</li><li>Google Gemini helped a CNET writer clear over 192,000 unread emails but cannot directly delete or archive emails as it is not an authorized Gmail app</li><li>French Air Force plans AI wingman flights by 2028 under project Hypairion, modifying Mirage 2000 fighters as AI test beds</li><li>New Mexico lawmakers plan AI safety legislation after a university breach where an autonomous AI model accessed a restricted record</li><li>Wyndham Hotels generated 15 times more assets using AI while cutting production time by 75%</li><li>Opella produced over 20,000 pieces of content using generative AI tools</li><li>Universidad del Caribe embeds AI into course design by having students draft work with AI and then critique its accuracy</li></ul>
AI agents keep company data access after tasks finish
A Delinea report found that 99.7 percent of IT and security leaders have formal AI data access policies. However, fewer than one in five organizations can detect unauthorized AI access as it happens. AI agents often keep permissions after their work ends, and 76 percent of employees have bypassed approval to use AI tools on company data.
AI agents retain business data access and act for users
A new study shows a gap between AI governance policies and how they are enforced in companies. While 99.7 percent of IT leaders say they have formal AI access policies, agents may still gain excessive permissions. Experts say AI agents need clearly defined permissions, continuous monitoring, and least-privilege controls like human users.
New Mexico AI breach prompts safety legislation push
Attorney General Raúl Torrez and Representative Linda Serrato plan to introduce AI safety legislation after a breach at the University of New Mexico. An autonomous AI model tried to access a restricted record at the school. The proposed law would require AI developers to build in safety measures to prevent similar incidents.
Agentic AI described as weapon with unclear targets
An article argues that Agentic AI functions as a tool for digital warfare. It raises the question of what Agentic AI hacking agents are meant to target. The piece references military strategy and suggests that using AI agents to attack computer systems could replace traditional weapons in some scenarios.
French Air Force plans AI wingman flights by 2028
The French Air Force plans to fly crewed fighter jets alongside AI-powered combat drones in 2028 under project Hypairion. The project aims to build open, modular architecture and sovereign AI technology so the government controls critical systems. Two Mirage 2000 fighters are being modified as AI test beds, with the goal of reducing reliance on proprietary company systems.
Google Gemini helps clear 200,000 unread emails
A CNET writer used Google Gemini to tackle over 192,000 unread emails across Gmail accounts. Gemini created custom search queries to find and delete unwanted messages from Nextdoor and promotional sites. The tool helped archive important emails like invoices while filtering out useless sales alerts. However, Gemini cannot directly delete or archive emails since it is not an authorized Gmail app.
Universidad del Caribe embeds AI into course design
Universidad del Caribe promotes AI literacy as a design quality rather than a separate topic. Instead of adding AI modules, professors redesign assignments so students use AI to draft work and then critique its accuracy. The university suggests rewarding critical use, requiring source verification, and asking students to reflect on how AI helped or failed them. This approach teaches students to think clearly with and despite AI tools.
Wyndham and BetMGM scale AI creative production
Brands like Wyndham Hotels, Opella, and BetMGM are building in-house teams to use AI for mass-producing digital marketing assets. Wyndham generated 15 times more assets while cutting production time by 75 percent and saw a six times improvement in site visit rates. Opella produced over 20,000 pieces of content using generative AI tools. BetMGM uses AI selectively, keeping some production for human staff due to strict regulations.
AI faces existential legal crisis over liability
Axios reports on the serious legal challenges facing artificial intelligence. The article highlights that AI systems are encountering fundamental questions about liability and responsibility. This legal crisis could shape how AI develops and is regulated in the future. The piece appears in the Behind the Curtain column as an analysis of the mounting pressures on AI governance.
Experts warn about Shadow AI permissions risks
Security experts urge caution before connecting AI tools to personal and corporate accounts. Corey Nachreiner and Jack Cherkas warn that AI agents with access to email and financial data carry high privilege risks. They recommend multi-factor authentication and pausing before sharing sensitive information. Their research found that 95 percent of malware travels through encrypted traffic, yet only 20 percent of devices inspect it.
Sources
- AI agents keep access to company data after their work is done
- AI Agents still retain Access to Business Data and Act on Users Behalf
- AG, Santa Fe lawmaker pitch AI safety measures after UNM breach
- Agentic AI is a Weapon, Against Who isn’t Clear
- French Air Force plans loyal wingman flight in 2028 in sovereign AI push
- Can AI Fix Your Chaotic Inbox? I Unleashed It On 200,000 Unread Emails
- AI literacy as habit, not bolt-on
- Marketing’s upper middle embraces AI creative production
- Behind the Curtain: AI's existential legal crisis
- Shadow AI and the permissions problem: what to check before handing AI the keys
Comments
Please log in to post a comment.