Control over AI
Blog
AI data leakage 7 min read

How AI tools reach files you never uploaded

You do not have to share anything to share something. Once an assistant is connected to your account it works with your permissions, and those reach further than you remember.

Admin mapping what a connected assistant can reach
Quick answer

An assistant connected to your work account does not wait for an upload. It searches with your permissions across whatever sources the integration was granted: your mailbox, your documents, shared folders, your chat history. That is the design, not a bypass, and it is exactly why people want the assistant. The consequence is that risk stops being about what someone shares and becomes about what someone is entitled to. In most organisations that second question has gone unexamined for years, because it had no consequences while searching still took effort.

01

A connected assistant reads sources, it does not wait for uploads

02

It searches with your permissions and therefore breaks none

03

Sharing links persist as standing permissions until revoked

04

Guest accounts and former project members usually keep access

05

The remediation is authorisation work, not AI work

A project lead asks her assistant for an overview of open items with a client. Back comes a tidy list containing two lines from an email thread she was never copied on, and a reference to a document in a team site she joined briefly two years ago.

She uploaded nothing. She shared nothing. She asked one question.

The model is not waiting for a file

Most people picture AI data exposure as a single action: you paste something or you drag something in. That is the mental model from the early chatbot era, when an assistant knew only what you handed it.

Once an assistant is attached to your work account, that picture stops holding. It has access to sources: your mailbox, your calendar, your documents, shared folders, your chat history. Exactly which ones depends on the permissions approved when the integration was set up, which is usually a consent screen somebody clicked through.

So there is no sharing moment. The question "what did I share" no longer has an answer, because the answer is: everything I can reach.

It searches with your permissions

This is the part people find reassuring right up until they think it through.

The assistant breaks no rules. It sees nothing you would not see yourself given an hour of searching. That is precisely why it goes wrong: it does that hour in two seconds, and it does not need to know the right search term.

What surfaces is wherever your permissions run wider than anyone intended:

  • Sharing links that never expire. Somebody shared a folder four years ago with "anyone with the link". The link still works and you were once sent it.
  • Old project memberships. You joined a team site for one question and were never removed.
  • Shared mailboxes. What sits in the team inbox belongs to the team, including what landed there by mistake.
  • Permissions inherited from a migration. Moving between systems, access is routinely widened so that "nobody loses access to their work", and then never narrowed again.

Microsoft 365 shows this most clearly, because so much lives in SharePoint and the integration is deep by default. See what happens when Copilot can reach SharePoint. The pattern is not vendor-specific: it holds for any assistant searching first-party sources.

The tempting objection is that this was always possible, so nothing is new.

Technically true. Practically wrong, for three reasons.

Search works on words. You have to know what something is called. An assistant searches on meaning, so "what was going on with that restructuring" finds the document whatever its filename.

Search returns a list. You still have to open, read and judge. That is enough friction to make people give up. An assistant summarises, delivering the content without the threshold.

And search looks inside one system. An assistant combines mail, documents and chat into one answer, exposing connections that existed in no single system on its own.

Constrain, then remediate

Two tracks worth keeping separate, because they have different owners.

Constrain the integration. Which sources may the assistant touch? Most enterprise assistants make this configurable per source, and starting narrow and widening beats the reverse.

Remediate the permissions. This is the real work and it is not about AI. Expiring sharing links, periodic access reviews, revoking guest accounts, and working through the sites set to "everyone in the organisation". It was always necessary; it has now become measurable.

What becomes obvious after doing this for a while: the assistant is rarely the cause of anything. It is the first party to systematically exercise permissions that were too broad for years. That makes it less of a risk than a detection mechanism, and it explains why the cleanup that should have happened long ago suddenly has a budget.

FAQ

Common questions

Can an AI assistant reach my files without me sharing them?

If the assistant is connected to your work account and has access to those sources, yes. It searches with your permissions. Nothing needs uploading: whatever you could open, it can in principle find and summarise.

Isn't that just a leak?

No, and that makes it harder to address. No rule is broken. The assistant does exactly what it is permitted to do. The problem sits in permissions that already existed and that nobody has reviewed recently.

Which sources are typically involved?

Mailbox and calendar, personal document storage, shared team sites, chat history, and sometimes tickets or a CRM. It varies per assistant, and it is set out in the permissions approved when the integration was connected.

How is this different from ordinary search?

Search returns a list of files you then have to work through. An assistant searches by meaning, combines sources and summarises. You do not need the right search term and you never open the document.

What can we do about it?

Two separate things. Constrain what the assistant may reach through the integration's permissions. And remediate the underlying access: sharing links that never expire, guest accounts nobody revoked, sites left open to the whole organisation.