You turned on an AI assistant to help your team. It reads email, digs through shared files, drafts replies, saves everyone time. That is the point of it.
It will also follow instructions it finds while it works.
Security researchers call it indirect prompt injection: hide commands inside ordinary content, an email, a shared document, a web page, sometimes in text no person ever sees, and the assistant treats them as orders. Last year, Aim Security researchers showed that one crafted email could make Microsoft 365 Copilot hand internal files to an attacker, with nobody clicking anything. Microsoft rated it 9.3 out of 10 and fixed it on their side, and no attack in the wild was ever found. The patch closed that flaw, not the pattern: OWASP, the nonprofit that ranks software risks, now lists prompt injection as the top risk to AI applications.
This July it reached the money. Zscaler found web pages with hidden text telling any visiting AI agent to pay a three dollar software fee to the attacker's cryptocurrency wallet. When Zscaler pointed test agents at the page, four of twenty-six AI models paid. The wallet had already received payments.
Assistants are becoming agents. They no longer just read and summarize; they send, book, buy, and file, and the access you hand them is the exposure. Three plain steps get ahead of it, without tearing the assistant out. First, list every AI tool connected to your business and what each can reach: email, files, payments, the power to send things outside the company. Second, cut each back to the least it needs, which whoever set it up or whoever runs your Microsoft 365 can change in the settings. Third, require a person to approve anything that moves money or sends data out, and switch off any setting that lets the assistant act on its own for those. If you do not know what your assistants can already do, that is the first thing to find out, and a fair question to bring to whoever handles your IT, us included.
An assistant that reads everything can be instructed by anything it reads.
NexusTek is a CMMC L2-certified managed service provider serving small and mid-sized businesses across the United States.