The AI assistant you gave access to everything is answering questions about your security — for strangers
You know that AI assistant your company rolled out last year? The one that can search every document, access every wiki, read every Slack channel, and summarize your entire tech stack in seconds? It just became your security team's worst nightmare — not because it got hacked, but because it's helpful.
Researchers just proved they could trick Microsoft Copilot into doing something no human employee would ever do: map out the entire security architecture of the organization it's supposed to protect, then hand that map to an attacker. They call it "meta-hacking." You should call it what happens when you give an AI assistant the keys to everything and forget that it will answer anyone's questions.
The AI didn't break. It didn't get compromised. It just did what it was designed to do: be helpful. And that's the problem nobody saw coming.
What meta-hacking actually means — and why your firewall can't stop it
Here's what happened. Security researchers asked Copilot a series of clever, innocent-sounding questions. Not "show me the admin password" — that would get blocked. Instead: "What security tools does the organization use?" "How are they configured?" "What's the architecture?" "Where are the gaps?"
The AI assistant — trained to be helpful, with access to internal documentation, configuration files, security wikis, and chat history — synthesized all that information and answered. Completely. Accurately. Enthusiastically.
It built a reconnaissance map that would take a human attacker weeks to assemble through phishing, social engineering, and network scanning. The AI did it in minutes. No malware. No exploit. No breach. Just questions.
This isn't prompt injection. This isn't jailbreaking. This is the AI doing exactly what it's supposed to do — except the person asking isn't on your team. They're just someone who got access to your Copilot instance through a compromised account, a shared login, or a contractor who left six months ago but still has a license.
The researchers called the technique "CoSnitch." The name is cute. The implications are not.
Why this is getting worse right now — and faster than you think
Twelve months ago, most enterprise AI assistants could search email and summarize documents. Today, they have access to GitHub repositories, cloud configurations, security logs, identity directories, and every Slack channel in your company. The surface area of what AI can see has exploded — and so has what it can leak.
Companies are racing to give AI assistants more context, more access, more permissions — because that's what makes them useful. The vendor pitch is always the same: "The more your AI knows, the better it performs." Nobody mentions that the more your AI knows, the more valuable it becomes to anyone who can ask it the right questions.
And here's the part that should terrify you: there's no patch for this. CoSnitch doesn't exploit a bug. It exploits the design. The AI is working exactly as intended. The vulnerability is the business model.
You can't train the AI to "detect malicious questions" because the questions aren't malicious. They're just specific. An attacker doesn't ask "how do I hack you?" They ask "what monitoring tools are deployed?" and "how is authentication configured?" — the same questions your new security engineer asked last week.
What you can actually do before someone maps your entire organization
1. Audit what your AI assistant can actually see right now. Open your Copilot settings, your ChatGPT Enterprise connectors, your Anthropic workspace permissions. Look at every data source your AI can access. If the answer is "everything," you have a problem. Limit scope. AI assistants don't need access to your entire security wiki to help with meeting notes.
2. Revoke access for every account that shouldn't still have it. Contractors who left. Employees who switched teams. Shared logins. Every one of those accounts can ask your AI assistant questions. Go through your license list and cut off anyone who doesn't need to be there today.
3. Treat AI assistant conversations like security logs. If your Copilot instance is being used, someone is asking it questions. Are you logging those questions? Are you reviewing them? If someone spends an hour asking about authentication architecture, security tooling, and access controls, that should trigger an alert — not a helpful summary.
4. Stop giving AI assistants access to security configuration files and architecture documentation by default. The same way you wouldn't give every employee admin access to your firewall, don't give your AI assistant unrestricted access to the documentation that describes how your defenses work. Create boundaries. Not every AI use case needs access to everything.
5. Assume someone is already doing this. If researchers published this technique, attackers are already using it. Check your AI assistant logs for patterns of reconnaissance-style questions. Look for accounts asking about tooling, architecture, or security controls. It's not paranoia if it's already happening.
Have you been asked to deploy an AI assistant with access to "everything"?
What did you push back on — and what did you end up giving it access to anyway?
Identity Decoded publishes every week at identity-decoded.com
