TalkTalk Business warns SMEs on AI agent access risks
Mon, 27th Jul 2026 (Today)
TalkTalk Business has warned small and medium-sized enterprises to tighten controls around AI agents after reports that an OpenAI agent breached a secure test environment and reached the open internet. The incident, it said, highlights the risks for smaller businesses using autonomous AI tools without formal oversight.
Bradley Collis, cybersecurity solutions architect at Planet IT, part of TalkTalk Business, said the episode should shift attention away from whether AI tools are inherently hostile and towards how they are connected to business data and services.
"This incident does not mean every AI tool is uncontrollable. It shows what can happen when an autonomous system has a goal, excessive access and gaps in the controls around it. It is worth mentioning that an AI model cannot be intrinsically 'malicious'. We may want to humanise AI models and agents as bad actors, robot overlords or unchained and uncontrollable synthetic hackers, but in this case the agent simply pursued its objective in a way its operators had not expected. For businesses, that is the key lesson. An AI agent can cause serious harm while doing exactly what it believes it has been asked to do," Collis said.
The comments come as many SMEs adopt AI features through email, productivity, finance and customer service software, while staff also use public AI tools outside approved company systems. That trend has created what security specialists describe as Shadow AI, where data is entered into external tools without IT teams knowing where the information goes or what rights those services have.
Collis said his main concern is not the AI brand itself but the level of access granted once a tool is connected. In many cases, businesses approve broad rights for systems that need only narrow access to complete a single task.
Access risks
"The biggest issue is excessive access permissions. Businesses often focus on whether they trust the AI provider but overlook what the tool can do once it is connected. A tool needed for one simple task can be given permission to read every mailbox, access an entire CRM, download files, send messages or change records. That creates a large potential impact from one compromised account, stolen access token, malicious instruction or unexpected action by the agent.
"An AI agent should only be able to access the specific information and functions needed for its task. It should not receive administrator access because that is easier to configure. Businesses also need to ask who and what has access to the new AI tool. Do users have guardrails so they know when to use AI and when not to? Has a link been clicked that synchronised AI with a CRM without anyone realising, and where is that new potential PII data link being housed?" he said.
The issue is particularly acute for SMEs because many lack dedicated cyber teams and formal review processes for new software connections. Industry figures cited by TalkTalk Business show only 14% of UK SMEs feel confident handling an AI-powered cyber incident, while 31% of businesses using or considering AI have no plans to secure it.
Separate figures cited by TalkTalk Business put the average cost of a cyber incident for a UK SME at £31,000, with total losses across the segment reaching £4.2 billion over the past year. Those costs can rise further if an AI tool has access to customer records, finance systems or internal documents.
Trial controls
For companies testing AI agents, Collis said the first step is to avoid linking them directly to live systems through standard employee or administrator accounts. Instead, businesses should use a controlled test setup, dedicated credentials and non-sensitive data.
"Do not connect an AI agent directly to your live business systems using a normal employee or administrator account. Create a controlled test environment, use a dedicated account with the minimum possible permissions, and test it with dummy or non-sensitive information. The agent should not have access to live customer records, company-wide email, payment systems, administrator accounts, or the ability to delete or change important data.
"For businesses already using Microsoft 365, our recommendation is to keep the initial trial within their managed Microsoft 365 environment, using Microsoft 365 Copilot or Copilot Studio rather than connecting an unapproved external AI tool to company data. The advantage is that Copilot works within the identity, permissions and security controls the business already uses. It respects the user's existing Microsoft 365 access, while administrators can apply controls through Microsoft Entra, Microsoft Purview and Power Platform. These can include multifactor authentication, conditional access, data loss prevention policies, sensitivity labels, connector restrictions and audit logging.
"Copilot Studio also gives administrators more control over which systems an agent can connect to, who can build and publish agents, and how testing is separated from live use. This is much safer than allowing employees to connect separate AI applications to email, SharePoint, Teams or customer systems without central oversight.
"However, using Copilot does not remove the need for a security review. Copilot respects the permissions already in place, so poorly managed or overly broad Microsoft 365 access can still expose information to the wrong users. Before starting, the business should review its SharePoint, Teams and file permissions, restrict the agent to one clearly defined task and make sure a named person is monitoring what it does.
"The aim is not simply to choose a trusted AI brand. It is to trial the agent in an environment where access can be limited, activity can be monitored and permissions can be withdrawn quickly. Businesses should also be clear about what they are using and make sure the model or agent is fit for purpose. If they are working with large amounts of confidential or customer data, it may be prudent to run open-source or open-weight models locally on their own hardware, and always ensure PII and corporate secrets are ringfenced from cloud-based models that train on their data," he said.
The wider lesson, he argued, is that vetting third-party AI tools can no longer stop at brand reputation or product popularity. Businesses need to know what information is retained, whether prompts are used for training, which suppliers sit behind the service, what permissions are requested and how access can be cut off quickly.
"It strengthens the advice. Checking the reputation of the provider is no longer enough. Businesses must examine the full connection between the AI tool and their own systems. They should understand what information the provider collects, whether prompts or company data are retained, whether information is used to train models, where it is processed and which other suppliers are involved.
"They must also check what permissions the integration requests, whether actions are logged, whether administrator approval is required and how access can be withdrawn immediately. The OpenAI incident is significant because it shows that unexpected behaviour can happen even within a highly skilled and well-funded organisation. SMEs should therefore assume that every AI agent could behave unexpectedly and limit the damage it would be able to cause," Collis said.
He added that security reviews often uncover little-known automation tools connected to mailboxes, cloud storage and CRM systems through long-lived access tokens with no clear owner inside the business. In some cases, the employee who installed the tool has changed roles or left the company.
"A recurring situation we find during security reviews is businesses discovering AI applications or automation tools connected to mailboxes, cloud storage and CRM platforms through long-lasting access tokens. Some have no named owner, no review date and no documented process for removing access. The person who originally installed the tool may have changed roles or left the company, while the integration continues to access business information in the background.
"That is a security incident waiting to happen. The immediate response is to remove unnecessary integrations, revoke and rotate access tokens, identify who owns each tool, and reconnect approved services using dedicated accounts with restricted permissions. The biggest concern is often not a highly advanced attack. It is an unknown tool with excessive access that nobody inside the business is monitoring," Collis said.