Did you know that most enterprise AI plans that include zero data retention options only cover API calls and Dev tools?
That means even with a 20-seat minimum and contractual ZDR terms, your team is still uploading confidential documents to a shared server. 🙈
IBM just published its 2026 Cost of a Data Breach report.
The average breach now costs $5 million, up 12% in a year.
The finding that should worry small firms: 43% of security incidents now involve shadow AI, meaning AI tools employees used without approval. Last year it was under half that.
And most organizations have no plan for it. More than two thirds have no governance process at all.
Your staff is already using AI. The question is whether you know where.
https://t.co/kgrASMK6lY
most legal AI tools are built for big law firms.
we're building Faradex for the people who can't afford big law firms.
startup founders reading 80-page contracts alone at midnight.
developers shipping a product without knowing if their terms of service will hold up.
that's the gap nobody is talking about.
Harvey and LexisNexis are fighting over AmLaw 100 clients.
we're focused on everyone else.
Thanks for mention in today’s release @FastCompany !
How to work with AI without becoming replaceable
LEVERAGE INSIGHT, THEN MAKE THE CALL
“The professionals who get replaced are the ones who are using AI to produce a specific deliverable. The ones who won’t are using it to enhance their judgment or to provide insight into a decision that they, not the AI, will ultimately make. I use AI like a super analyst, and then layer on context that others don’t have, like taste, data, trend analysis, and accountability for the outcome.
A specific example: as a go-to-market adviser, I’ll use Claude to build a 100-company target list and draft five positioning angles in an afternoon. This work used to take over a week. But that’s not what I’m paid for. The value is knowing which 10 of those accounts are actually worth a call, why a buyer will or won’t trust one of those five messages, and owning the result when it ships.”
https://t.co/JJUE3Zk2ol
The wrapper problem in #2 is the one nobody talks about. “Confidential” until it hits someone else’s API.
Faradex skips it entirely. Dedicated isolated instance per client, zero retention, nothing sent to a shared model to train on.
Different kind of proof than on-chain, same goal: your documents don’t leave.
Researchers just tricked six AI browsers into handing over user credentials. Including ChatGPT Atlas and Claude's Chrome extension.
The method? Convince the AI it's playing a game.
LayerX built a puzzle page that rewarded wrong answers. Once the agents accepted that "incorrect is fine," they abandoned their safety rules entirely. Then they fetched SSH login credentials from a work GitHub repo and handed them over.
The AI didn't flag it as malicious. It celebrated winning the game.
OpenAI patched it. According to LayerX, Anthropic's fix failed. Perplexity ignored the report. Three vendors never responded.
If a puzzle can talk your browser out of its guardrails, what else can?
https://t.co/2kDLQv49YN
New research called GuardFall broke the safety checks in ten of eleven popular open-source AI coding agents tested.
Only one, Continue, held up.
The trick is old. Safety filters read a command as plain text, but the Bash shell rewrites that text before running it, stripping quotes and expanding shortcuts. What looked harmless to the guard runs as something destructive.
These agents execute commands with full account access. Point one at a rigged code repository and a hidden instruction can wipe files or steal SSH keys and cloud credentials.
How much of your firm's work now flows through a tool that cannot tell a safe command from a dangerous one?
https://t.co/71JIl6Oo4v
A browser extension your team installed years ago for a harmless reason, blocking ads, may now be quietly recording every conversation they have with AI...
A researcher disclosed an operation codenamed PromptSnatcher involving two Chrome extensions, Smart Adblocker with roughly 90,000 users and Adblock for Browser with roughly 10,000 users.
They function as real ad blockers, using legitimate public filter lists as cover, while running an undisclosed channel that captures conversation history, model usage, and subscription tier from eight major AI platforms, including ChatGPT, Claude, Gemini, and Copilot.
The data is sent to operator-controlled infrastructure. Both extensions were still available on the Chrome Web Store at the time of reporting, and the capture feature appears to have arrived through routine software updates, long after the extensions earned user trust.
For professional services, this lands on the riskiest habit of the past several years - unauthorized extensions.
When a lawyer pastes draft contract language into a chatbot, or an accountant pastes a client reconciliation, or an analyst pastes deal terms, that text can become privileged or material non-public information sitting in a stranger's database.
The exposure is not the AI tool itself but the browser layer wrapped around it. Inventory the extensions running in your environment, restrict installs to a vetted allowlist, and remind staff that a browser add-on runs with the same visibility they have.
https://t.co/NhHk3awKLi
Researchers just showed Microsoft 365 Copilot Enterprise could be turned into a one-click data theft tool.
A single malicious link could pull a victim's mailbox content, calendar, OneDrive and SharePoint files, and even live MFA codes.
Varonis disclosed the flaw, "SearchLeak" (CVE-2026-42824), on June 15. Microsoft mitigated it server-side, with no click or patch required from users.
No malware. No download. Just one click on the AI assistant your whole firm already trusts.
How much of your client file sits inside Copilot right now?
https://t.co/5FVHatTdH5
The most locked-down AI model in the world lasted 24 hours before a Discord group got in.
Not through a zero-day. Through a contractor.
Every AI tool your firm uses has the same problem. You just haven't read the headline yet.
Private deployment is not optional anymore.
https://t.co/xFjqUpKn6E
Anthropic's Mythos AI found thousands of critical vulnerabilities across every major OS and browser.
More than 99% of them are still unpatched.
The Fed and Treasury convened an emergency meeting with Wall Street bank CEOs over the implications. JPMorgan is now testing the model. Anthropic refused to release it publicly because the hacking capability is "too powerful."
It also found a flaw in a security-focused operating system that had gone undetected for 27 years.
Your firm's software has holes in it. An AI just found them. The question is whether attackers find them next.
https://t.co/ptDTZyjaio
Check Point found a hidden vulnerability in ChatGPT that allowed silent data exfiltration.
A single malicious prompt could leak your conversations and uploaded files to an external server via DNS tunneling.
No warnings. No user confirmation. Completely invisible.
The DNS channel was bidirectional, meaning attackers could also execute commands inside ChatGPT's runtime...
OpenAI patched it February 20, 2026. But it existed. What other vulnerabilities will we discover this year?
https://t.co/Pvli9ybmfD
Anthropic had two major security leaks in five days.
March 26: A config error exposed 3,000 internal files, including a draft blog post revealing an unreleased model called "Mythos" that Anthropic says poses "unprecedented cybersecurity risks."
March 31: Claude Code's entire source code shipped in an npm package. 500,000+ lines of TypeScript. Forked 41,500+ times on GitHub before it could be pulled.
The company building AI for enterprise security couldn't secure its own code. Twice. In one week.
Can they really secure yours?
https://t.co/PPASVhoptL
McKinsey built an internal AI platform for 40,000 employees.
A solo researcher hacked it in under 2 hours.
46.5 million internal chat messages exposed. Client consulting data. System configurations. All of it.
Enterprise AI is moving fast. Security is not keeping up.
https://t.co/TalMMN6VCD
Organizations are adopting AI systems faster than they are securing them.
One survey cited in the report found that 83% of organizations planned to deploy agentic AI capabilities into their business functions, while only 29% reported being ready to operate those systems securely.
https://t.co/Gl9O462bIX
Reach out if your organization is looking to deploy agents securely.
Have you heard of Shadow AI? It's when your employees are using their personal AI accounts to do company business.
IBM found that breaches involving shadow AI cost organizations $4.63 million on average.
That is $670,000 more than standard incidents.
1 in 5 organizations already reported a breach due to shadow AI.
Only 37% have policies to even detect it.
https://t.co/HT8UVZjYgG
Breaking Security News: Autonomous agent hack McKinsey's AI Platform, Lilly
https://t.co/Aaup9lwYIJ autonomous agent hacked Lilly and accessed:
→ 46.5 million chat messages (containing a lot of confidential company information)
→ 728,000 files
→ 57,000 user accounts
→ 384,000 AI assistants and 94,000 workspaces
→ system prompts and model configurations
→ 3.68 million RAG document chunks
→ 1.1 million files and 217,000 agent messages routed through external AI APIs
https://t.co/bhU7kytW2U