We Know AI Agents Create Cybersecurity Risk
With AI everywhere and news stories about AI agents “escaping” their confines and roaming the internet, it is easy to fear creating a situation where AI agents at your nonprofit could create a serious vulnerability without you even knowing it. Agentic AI or AI agents are becoming more common in the workplace, and many AI tools will prompt users to create an automation or agent to complete a task. What do you need to know before taking that step?
If you have been exploring AI tools and thinking about creating AI agents, you might be holding back until you know more. And with good reason – there is something called the lethal AI trifecta that nonprofits need to watch out for.
This is when AI has three things:
- autonomous exfiltration ability: the power to act on its own, like creating files, accessing systems, or sending emails,
- access to sensitive information like emails or donor data,
- access to untrusted content.
This can result in your AI agent taking actions you can’t control and can’t secure, or even committing actions on behalf of nefarious actors. These actions can range from inviting attackers into your systems to sending scam emails with company email addresses. How can you prevent this?
A Quick Note on Names
Every AI company uses different terms for their agent tools, and those names change often as the technology evolves. You might see “Copilot agents,” “Claude Code,” “ChatGPT Workspace Agents,” “Gemini Enterprise,” or others. New names appear almost every few months. Whatever a tool calls itself, ask the same question: does this agent have autonomous ability to act, access to sensitive information, and access to content from outside your organization? If it has more than two of those at once, you’ve got a lethal trifecta risk, no matter what the product is named.
AI Agent Lethal Trifecta and Prevention Measures
Your AI agent should never have access to more than two aspects of the lethal trifecta at the same time. You can prevent your AI from having access to one or more of the three points of the trifecta by being careful at creation.
Autonomous Exfiltration Ability
A great place to start is by not allowing your AI agent’s autonomous exfiltration ability. To simplify, do not let your AI agent access or create files without asking your permission every time. This is an excellent security gate for many reasons.
By not letting your agent autonomously create or edit files you ensure all of its work is reviewed by a human, and also prevent it from making potentially costly mistakes that you learn about after the fact.
This safeguard also keeps malicious actors from accessing a key attack vector and goes a long way towards improving your cybersecurity.
Access to Sensitive Information
Another good step to take is to carefully monitor what content your AI agent can access. You already know that your AI tools have access to everything you have permission to see. That’s why it’s a good idea to prep your file permissions for AI tools.
In addition, it may seem useful to create an AI agent to help manage your inbox and calendar. An AI agent may feel less invasive than a human assistant and less interested in your private emails. However, think about how many emails you receive that include a link – to a calendar invite, a document, a website. If your AI agent can read those emails and act on what it finds, clicking a malicious link in a phishing email could hand an attacker a foothold in your systems, or let them send messages that look like they’re coming from you.
Another example: an AI agent set up to help draft donor thank-you notes would need access to your donor database, which likely includes giving history, contact information, and sometimes even payment details. That’s exactly the kind of information you don’t want exposed if the agent is compromised through one of the other two risks in the lethal trifecta.
Access to Untrusted Content
“Untrusted content” often enters quietly. If you ask your AI agent to search the web, read reviews, or check a website for you, it’s now looking at content written by strangers, which could include hidden instructions designed to manipulate it. The fix isn’t to avoid this kind of task altogether, it’s to make sure that when your agent is looking at the open internet, it doesn’t also have the ability to act on your systems or see your sensitive information at the same time.
By limiting your AI agent to trusted sources, you minimize the chances of a bad actor reaching it in the first place. For instance, an AI agent that can read user reviews or public comments of unknown origin or intent should not also have access to sensitive systems like your donor database or email.
In much the same way, if you use an AI chatbot on your website, it should be kept separate from any secure systems, since that AI is receiving unfiltered input from anyone who visits your site. That can include people who may be testing it for weaknesses or attempting prompt injection, where hidden instructions are slipped into what looks like an ordinary message.
Always remember if your AI has access to two parts of the trifecta to not give it access to the third. Doing so decreases the risk of your AI being turned against you.
Is Your IT Partner Meeting the Moment?
As your organization navigates challenges, you deserve a support team that is as committed to your mission as you are.
Would you like to see how our human-centered approach can stabilize your IT environment? If you have questions about how to align your technology with your mission, we are here to help.
Community IT has been serving nonprofits exclusively for 25 years. We offer Managed IT support services designed for organizations that want a partner, not just a provider. For a fixed monthly fee, we provide the proactive planning and ongoing IT strategy you need to ensure your technology is always an asset and opportunity, not a liability.
We think your IT partner should be able to explain everything clearly, without talking down to you or using unnecessary lingo. If you’re ready to gain peace of mind and clarity about your IT roadmap in our challenging environment, let’s talk.
As advocates for using technology to work smarter, we’re practicing what we recommend. This article was drafted with the assistance of AI, but the content was reviewed, edited, and finalized by a human editor to ensure accuracy and relevance.
Photo by Oscar Brouchot on Unsplash