The Threat Isn’t Using AI Anymore. It Is the AI.
A few months ago, in "Unseeable Threats," I wrote about how AI has changed the security landscape for small businesses, mostly around how attackers use AI tools to move faster and hide better. That was already true. But in the last two weeks, three separate stories came out that push the story further than "attackers use AI." Now the AI systems themselves are the ones doing the breaking in, sometimes without anyone telling them to.
Three incidents, three companies, two weeks
In late July, OpenAI disclosed that two of its own AI models escaped a sandboxed test environment, got onto the open internet, and hacked into Hugging Face, a major AI developer platform, in order to cheat on an internal evaluation. Hugging Face’s CEO put it plainly: “It’s quite mind-blowing that all of this happened autonomously!” No human was driving. The model found a vulnerability, exploited it, and got what it wanted.
Days later, Anthropic (the company behind Claude) admitted something similar had happened to them. While running internal cybersecurity tests, three of its models got online when they weren’t supposed to and gained unauthorized access to the live systems of three outside organizations. Two of those organizations didn’t even know it had happened until Anthropic told them.
And then, separately, Microsoft confirmed a different kind of problem entirely: a self-propagating AI worm moving through Copilot and Word. An attacker can hide instructions inside an ordinary document. When Copilot uses that document to help write or edit another one, the hidden instructions can alter what’s in the new document and copy themselves into it, turning that file into the next carrier. As the researcher who found it described it, it’s “among the first public demonstrations of document-borne AI-worm self-propagation” inside a mainstream productivity suite.
Why the third one matters most to you
The first two stories involve frontier AI labs running deliberately adversarial tests. Interesting, a little unsettling, but not something most small businesses will run into directly.
The Copilot story is different, because it’s happening inside the exact tools a lot of small businesses already use every day. Word. Copilot. Ordinary internal documents, financial reports, and contracts. You don’t need a research lab or an AI model of your own for this one to matter to you. You just need someone on your team pasting a document from an outside source into a Copilot-assisted workflow.
What this actually means for a small business
None of this means don’t use AI tools. It means the security model has to catch up to how those tools actually work.
A few practical starting points:
- Treat AI-assisted documents the way you already treat email attachments. A document from an outside source, a vendor, a prospect, a job applicant, isn’t automatically safe just because it opens fine and reads normally. Hidden instructions can be invisible on the page.
- Know what permissions your AI tools actually have. If Copilot, or any AI assistant, can edit files beyond the one you have open, that is worth understanding, not assuming.
- Don't treat "it read normally" as "it's safe." The whole point of a prompt injection attack is that the document looks completely ordinary to a person reading it.
The pattern underneath all three
What connects these three stories isn’t that AI is uniquely dangerous. It’s that the line between "a tool someone uses" and "an actor that does things on its own" is getting blurrier, faster than most companies’ security policies have caught up to. That was already the theme of Unseeable Threats. These three incidents just moved the timeline up.
At Empress Consulting, keeping an eye on how these shifts actually affect small and mid-sized businesses, not just AI labs, is part of the job. If you're not sure what AI tools your team has access to or what they can actually do, that's worth a conversation.