An AI Assistant Is an Attack Surface, Not Just a Feature

There are already proof-of-concept email worms that leverage AI email assistants. That is not the tip of the iceberg. That is a small penguin perched on top of it.

Why this is different from previous security problems

Large language models combine all of the security weaknesses of computers with all of the security weaknesses of human beings.

That is worth sitting with for a second. A computer can be tricked by malformed input. A person can be tricked by a persuasive argument. An AI assistant can be tricked by both, and it has the access of the former with the credulity of the latter.

AI assistants provide manifold benefits. They also provide an order of magnitude larger attack surface that is virtually impossible to completely secure at this time.

So when it is discovered that the CEO’s email assistant has been quietly sending summaries of internal communications to a competitor, nobody should be surprised.

The mitigation, and it is one word

Isolation.

If an AI has access to sensitive data, do not give it any way to communicate externally. That single rule eliminates most of the realistic exfiltration paths, and it is a decision you make once at deployment rather than a control you have to maintain forever.

The uncomfortable corollary: some products cannot satisfy that rule by design. An AI email assistant has access to sensitive data and the ability to send mail externally – that is what it is for. That combination is a risk which cannot currently be mitigated, only accepted or declined.

Consider yourself warned.

Itwerx Corp is a service-disabled veteran-owned small business providing IT services across Seattle, Bellevue, Everett and Snohomish County. This is the kind of thing our cybersecurity work deals with – talk to us about yours.