
| Key Takeaways
• Cases like EchoLeak showed an agent can be tricked into leaking data through the access it was granted. • Enterprises lack defenses against these agents, with only 40% of organizations having a working kill switch and only 37% of organizations enforcing purpose binding. • Average time from initial access to exfiltration is a mere 29 minutes, and only 5% of CISOs are confident they could contain a compromised agent in time. |
Machine identities vastly outnumber human ones in a modern enterprise. According to Palo Alto Networks, roughly seven in ten of them are now AI agents. Identity governance was built to manage people, but there is a real security gap in how it manages AI agents. This post argues that the control has to live in the file itself, not only in the identity reaching for it.
In 2025, researchers at Aim Labs found a flaw in Microsoft 365 Copilot that needed no click and no mistake from the user. An attacker simply sent an email with hidden text disguised as normal formatting. When Copilot processed that email as part of a routine task, the hidden text told it to search the user’s other emails and files, then send what it found back out.
Copilot had every right to read that data. It was doing its job, just following the wrong instruction from the wrong source. Researchers called this EchoLeak (CVE-2025-32711): an agent tricked into misusing access it was always allowed to have. This post is about that problem. Not an agent that got hacked, but one that worked exactly as designed.