Dashboard

Why AI Can See Files It Shouldn't in Your Company

AI assistants inherit the permissions of whoever connects them, and most shared drives are far more open than anyone remembers. Audit the share before you connect anything.

Cecilia Iona
Cecilia Iona
Senior Editor, AI & Product
15 September 20261 min read

Why AI Can See Files It Shouldn't in Your Company

The reason an AI can see files it shouldn't is almost never that the AI broke in. It is that the assistant inherited the permissions of whoever connected it, and those permissions were already far wider than anyone remembered. The model did not get new access. It got fast, tireless, well-indexed access to everything a human account could technically reach but never had time to look at.

That distinction matters, because it tells you where the fix lives. Not in the model, not in the vendor's data policy, but in the share settings you have not audited since the company was half its current size.

The scale of the gap, measured

The security startup Cymphony launched publicly on 9 September 2026 with $30 million led by Sequoia Capital and the SMBC Fin Atlas Beyond Fund. The number worth noting from its launch coverage is not the funding. At one United States public company, Cymphony found roughly 85,000 files that had become reachable by AI tools and agents. The company said none had actually been accessed through those systems, which is the good news and also entirely beside the point: the exposure existed and nobody had counted it.

The same coverage describes an external collaborator who installed an unsanctioned instance of an AI assistant and used their own existing access to scan thousands of sensitive files. Again, no break-in. The collaborator had been granted that access, legitimately, at some earlier point, for some narrower purpose that everybody had stopped thinking about.

Cymphony's chief executive framed it as enterprise security having been designed for human employees, with independent entities now joining the workforce that are no longer people. That framing is useful precisely because it puts the burden back where it belongs. A human with access to 85,000 files reads maybe forty of them. An assistant with the same access reads all of them in a minute, and it answers questions using all of them.

Where the over-sharing actually hides

In small companies it is usually three places, in roughly this order of severity:

Source

How it happens

Why AI makes it worse

Link sharing defaults

A folder was shared with anyone at the company to unblock one person, years ago

Company-wide means the assistant's index too, and nobody sees a share dialog when they ask a question

Legacy group membership

Someone changed roles, kept their old group, and the group grants folder access

The assistant answers from every folder the stale group can reach

Contractor and collaborator accounts

External access granted for one project and never revoked at the end of it

A tool connected on the contractor's side inherits their whole view of your drive

None of this is new. It is the ordinary entropy of a shared drive. What is new is that the entropy is now queryable in natural language, which converts a theoretical exposure into a practical one. The related risk of tools nobody approved is worth reading alongside this: see what shadow AI is and how it gets into a company.

Audit the share before you connect the assistant

This sequence takes an afternoon in a company under fifty people, and it is worth doing before the connector, not after.

  1. Pull a report of every folder shared with anyone at the company or anyone with the link. In Google Drive and SharePoint this is an admin report, not a per-folder check. Read the list rather than skimming the count.

  2. Sort by folder name and look for the words payroll, legal, board, offer, contract, investor and salary. This is crude and it works.

  3. List every external account with any standing access. For each one, name the project it was for. If you cannot name it, revoke it.

  4. Check which groups grant folder access, then check who is still in those groups. Role changes are the usual culprit.

  5. Only then connect the assistant, and connect it as a dedicated account rather than through a person's own login, so its reach is something you can see and change in one place.

  6. Re-run steps one and three on a calendar reminder. Quarterly is enough.

Step five is the one people skip and regret. An assistant connected through an individual's account gets that individual's blast radius, silently, and it changes whenever their permissions change. The argument for giving it its own identity is covered separately in whether an AI agent should have its own user account.

What this is not

This is not an argument against connecting AI to your documents. The value is real and the alternative, people pasting extracts into a chat window, is worse on every axis including this one. It is an argument for doing the boring permissions work first, and for filing it under the same heading as the other risks that come with running AI in a business. Whether the vendor trains on what it sees is a separate and also important question, covered in how to check if an AI tool trains on your data, and the specific case of a shared drive is worked through in whether it is safe to let an AI agent access your shared drive.

Frequently asked questions

Does the AI vendor see files I never asked it to read?

It sees what the connected account can reach and what the product's indexing settings allow. Most assistants index broadly so that search works, which means reach and read are much closer together than people assume. Check the connector's scope settings, not just the top-level permission prompt.

If nobody has accessed a file, is the exposure real?

Yes, in the sense that matters for an audit or an incident review. Unexercised access is still access, and the first time anyone discovers it is usually when an assistant surfaces a quote from a document in an answer to an unrelated question.

Is this a reason to keep sensitive files off the main drive?

Separating genuinely sensitive material into a tightly scoped space is sensible, and it is easier to maintain than perfect permissions on one sprawling drive. It is not a substitute for the audit, because the sprawling drive will still contain things you would rather not have quoted back.

How often does this need rechecking?

Quarterly for the external accounts and the company-wide shares, and immediately after any wave of role changes or the end of a contractor engagement. Those two events cause most of the drift.

How did this land?

About the author

Cecilia Iona
Cecilia Iona

Senior Editor, AI & Product

Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.

Share

Get the next post in your inbox

One email a month. Product updates, engineering posts, and the best of Built with Swarmz.

I agree to receive emails about AI building tips and Swarmz product news. Unsubscribe any time.