Security & Assurance · AI Exposure Assessment
Which AI is in use, what company information has reached it, and what becomes notifiable if that exposure becomes public.
Exclusions are what a regulator reads first, so they are written as exclusions.
In scope. Every AI application reachable from a managed device or a corporate identity, whether approved or not. The data those applications can read. The contractual posture of each, by account tier. AI features inside tools already sanctioned. AI agents and their tool connections.
Out of scope, by agreement. Contractor and agency devices. The Malaysian entity’s finance system, which is on a separate tenancy. Personal devices not enrolled in management, where nothing is measurable and nothing is claimed.
Stated in the scope and repeated here. Interviews ran under a written commitment that nothing disclosed would be used for employee discipline. Contract reading states a posture; it is not legal advice and the client’s counsel owns the conclusion. Probe testing surfaces real sensitive data and was handled inside the client environment only.
No single source shows how AI is actually being used. The disagreements are the findings.
| Source | AI applications seen | What it missed | |
|---|---|---|---|
| Identity provider | 34 | Anything used without an OAuth grant against a corporate account | |
| Network egress | 61 | Use on cellular, and anything inside an already-sanctioned tool | |
| Expense records | 9 | Everything on a free or personal tier, which is most of it | |
| Endpoint inventory | 27 | Browser-based tools leaving no installed artefact | |
| Reconciled register | 73 | — |
Nine applications appeared in exactly one source. Every one of those nine was investigated, and three of them produced findings in section 4. The expense ledger, which the previous year’s review had used as its primary source, saw nine of the seventy-three.
Fifty-one of the seventy-three run on personal or free-tier accounts against which the organisation holds no contract, no retention position and no deletion right.
The asset this engagement produces. Twelve of seventy-three rows shown; the full register is delivered as a spreadsheet the client owns.
| Tool | Owner | Account tier | Data observed | Contract posture | Band |
|---|---|---|---|---|---|
| General assistant A | Firm-wide | Enterprise | Client documents | No training on inputs; 30-day retention | Accepted |
| General assistant A | xxxxxxx, advisory | Personal free | Client documents, draft filings | Consumer terms; trains on inputs by default | Immediate |
| Code assistant | Engineering | Business | Private repositories | No training; enterprise agreement in place | Accepted |
| Code assistant B | Unattributed | Personal free | Private repository contents | Consumer terms | Immediate |
| Meeting transcriber | xxxxxxx, partners | Personal paid | Client calls, including privileged matters | Retains recordings indefinitely | Immediate |
| Translation tool | Operations | Free | Contracts in draft | No deletion right | Planned |
| Design assistant | Marketing | Team | Unpublished campaign material | Standard terms; acceptable | Accepted |
| Assistant inside the CRM | Sales | Bundled, switched on | Full customer record | Covered by the CRM agreement | Planned |
| Assistant inside the document store | Firm-wide | Bundled, switched on | Everything the asker can open | Covered | Immediate |
| Note-taking agent | xxxxxxx, finance | Personal free | Board papers | Consumer terms | Immediate |
| Research agent, three tool connections | Advisory | Team | Reaches mailbox and drive | Connections never reviewed | Planned |
| Grammar checker | Firm-wide | Free | Outbound email text | Consumer terms | Accepted |
The band is set by consequence, not by count. Two hundred people using a grammar checker is accepted; one person putting board papers into a free account is not.
Ten in the full report. Three shown, each with a fix, a named owner and its PDPA position.
The assistant was switched on across the firm as part of an existing licence. It enforces existing permissions correctly, which is the problem: a decade of sharing has left 2,140 documents open to all staff, including two folders of partner compensation and one containing draft redundancy plans. A plain question returns them.
Probe run from a low-privilege account, xx xxxxxx xxxx: "what changes are planned to headcount this year" -> returned 3 documents, incl. draft redundancy plan, xxxxxxxx team "what does a senior manager earn here" -> returned the current compensation band sheet
The assistant did not leak anything. It faithfully surfaced permissions that were already wrong, which is why this is a permissions finding rather than an AI finding.
Restrict the two worst site collections this week, then run the permission remediation across the tenancy. Owner: xxxxxxxxx, head of IT. Notifiable if public: yes for the compensation data, on the PDPC clock, as it identifies individuals.
An engineer used a free-tier assistant against two private repositories for roughly four months. The consumer tier of that product trains on inputs by default and the account has no enterprise agreement behind it. Source code is the most common data type to leave this way, and this is the ordinary version of it rather than an unusual one.
Provide the approved assistant on the business tier, block the consumer domain, and rotate any credential that appeared in the affected repositories. Owner: xxxxxxxxx, engineering lead. Notifiable if public: no personal data identified; commercially material.
One account in finance connected a note-taking agent to a personal mailbox holding forwarded board papers. The agent holds a live connection to that mailbox and to a drive folder. No approval exists and no contract does.
Revoke the OAuth grant, request deletion under the consumer terms and record the response, and add the tool to the blocked list. Owner: xxxxxxxxx, CISO. Notifiable if public: assessable, as the papers name individuals in a redundancy context.
Benchmarked so the board sees the organisation against the industry rather than in isolation.
| Measure | This organisation | Published rate | |
|---|---|---|---|
| AI use on personal accounts | 70% of applications found | Around two-thirds | |
| Most common data type leaving | Source code | Source code, by a wide margin | |
| Overshared sites in the tenancy | 184 | 150 to 300 in a typical tenant |
On every measure the organisation sits inside the published range. That is the useful finding for a board: this is the ordinary condition of a firm this size that has not looked before, and it is not evidence of unusual negligence.
One page, forwardable, carrying no detail an attacker could use. Reproduced here in full.
The decision this asks for: approve the permission remediation programme, and decide whether an approved assistant is provided on a business tier. Nothing else on this list is stable while staff have no sanctioned option.
What a regulator or a customer’s auditor reads.
The full report carries the verbatim probe prompts and their outputs, hashes and timestamps for every log extract, the OAuth grant export with dates, the twelve-month spend extract, and the interview record in anonymised form under the no-discipline commitment. Prompts and outputs are handled as the confidential data they are and were never copied outside the client environment.