Contributing Author: Allan Jacks, Morefield vCISO October marks Cybersecurity Awareness Month. A time when organizations, governments, and individuals spotlight the evolving threats in our digital world. As technology advances at what seems a breakneck speed, so too do the risks that lurk beneath the surface like how we must rethink traditional security models to confront new and emerging challenges. One persistent and complex threat has always been that of insider risks where the danger posed by individuals within an organization who have access to sensitive systems and data. These risks can be malicious, like data theft, or accidental, like a misdirected email containing confidential information. Historically, insider risk has focused on human actors which include employees, contractors, and vendors. But today, a new kind of insider is emerging. Artificial Intelligence (AI), once a tool for efficiency and innovation, is now being recognized as a potential insider risk. With the possibility of access to vast amounts of data, making autonomous decisions, and increased integration into critical workflows, AI systems are beginning to occupy roles once reserved for trusted employees. With that shift comes a new set of vulnerabilities. Historically, insider risk has referred to threats posed by people within an organization who have legitimate access to systems and data. These include:
AI systems are becoming even more integrated and now embedded in:
These systems can act independently, interact with sensitive data, and even influence important business outcomes, making them functionally equivalent to insiders. AI systems share several key characteristics with traditional insiders:
As AI becomes more embedded in business operations, it must be treated not just as a tool – but also as a potential insider. Organizations need to extend their insider risk programs to include AI governance, access controls, and continuous monitoring of autonomous systems. Cybersecurity isn’t just about keeping people honest anymore, but also about keeping machines accountable.
As artificial intelligence becomes deeply embedded in business operations, it introduces new dimensions of risk—some familiar, others entirely novel. While AI promises efficiency, insight, and automation, it also opens doors to misuse, manipulation, and unintended exposure which can include the following.
AI isn’t just a tool—it’s a new kind of insider. It can be trusted with sensitive data, make autonomous decisions, and interact with external systems. But without proper governance, it can also be exploited, misconfigured, or manipulated, posing serious risks to security, privacy, and compliance. Organizations must treat AI with the same scrutiny they apply to human insiders: access controls, monitoring, training, and accountability.
Samsung Data Leak via ChatGPT (May 2023) Samsung employees accidentally leaked sensitive company information while using ChatGPT for help at work, including source code and a recording of a meeting. The incidents raised concerns about the potential for similar leaks and possible violations of GDPR compliance. Samsung has taken immediate action by limiting the ChatGPT upload capacity and considering building its own internal AI chatbot to prevent future leaks. (www.cybernews.com)
A prankster tricked a Chevrolet dealership’s AI chatbot into offering a $76,000 Tahoe for just $1. The chatbot was manipulated through clever prompts, revealing how easily customer-facing AI tools can be exploited. The Tahoe was never delivered. (www.cybernews.com)
In February 2024, Air Canada faced a significant controversy after a grieving passenger, Jake Moffatt, sought a refund for a full-price ticket purchased due to misinformation from an airline chatbot. The chatbot incorrectly advised Moffatt to book a flight immediately and request a refund within 90 days, which contradicted Air Canada’s bereavement travel policy. The Canada’s Civil Resolution Tribunal ruled in Moffatt’s favor, ordering Air Canada to provide a partial refund of approximately $812 CAD. The tribunal found that Air Canada failed to adequately explain the chatbot’s misleading information, which led to the passenger’s decision to pursue legal action.
During a public demo, Google’s Bard chatbot provided incorrect information about the James Webb Space Telescope. The error led to a drop in Google’s stock and raised concerns about the reliability of AI-generated content.
Some companies integrate external AI tools into internal systems without full visibility into how those tools handle sensitive data. These integrations can introduce vulnerabilities if the vendor’s security practices are weak or opaque.
These incidents show that AI systems:
In short, AI now behaves like a digital insider—one that must be governed, monitored, and secured just like human employees.
As AI systems become embedded in core business functions, they must be treated with the same scrutiny as human insiders. Mitigating AI-related insider risk requires a blend of technical controls, governance frameworks, and cultural awareness. Here’s how organizations can stay ahead: Treat AI Systems as Privileged Users
Monitor and Audit AI Behavior
Validate Training Data and Model Outputs
Vet Third-Party AI Tools Thoroughly
Control Generative AI Usage
Update Insider Risk Programs
Foster a Culture of Responsible AI Use
As organizations embrace artificial intelligence to drive efficiency, innovation, and scale, they must also confront a new reality: AI is no longer just a tool – it’s an operational insider. With access to sensitive data, the ability to make autonomous decisions, and increasing integration into critical workflows, AI systems now occupy roles once reserved for trusted employees. This shift demands a redefinition of insider risk. No longer limited to employees, contractors, or vendors, insider threats now include non-human agents capable of causing harm through misuse, manipulation, or misconfiguration. From generative AI leaking confidential data to third-party models operating as opaque black boxes, the risks are real – and growing. Cybersecurity strategies must evolve to meet this challenge. That means extending governance frameworks, updating access controls, and fostering a culture of responsible AI use. It also means recognizing that the very systems designed to protect us can become threats if left unchecked. As we mark October as Cybersecurity Awareness Month, now is the time to take a closer look at how your organization is managing AI-driven risks. Contact Morefield today to assess whether your current cybersecurity framework, data policies, and access controls are ready for this new era. A proactive conversation today can help ensure your AI tools remain trusted allies—not unexpected threats—to your business tomorrow.