AIToday
AI Business & IndustryAI Safety & AlignmentLarge Language ModelsVentureBeat AIPublished: Sep 2, 2026, 04:00 JST1 min read

Azure OpenAI email assistant leaks SharePoint files

Azure OpenAI email assistant leaks SharePoint files

Key takeaway

  • An Azure OpenAI email assistant leaked SharePoint files to unauthorized users.

  • It passed tests but failed with low-privilege accounts.

  • A filter and narrower assistant closed the gap.

3 Key Points

  1. What happened

    Egiziago Cioffi, CEO of SynSphere Italia, built an Azure OpenAI email assistant that auto-resolves about 60% of inbound customer email. Testing with a low-privilege account against high-privilege questions revealed the assistant returned SharePoint content the requesting user could not have opened themselves.

  2. Why it matters

    The assistant passed evaluations and unit tests, but the retrieval logs showed a production failure where access controls were not respected. This means an AI assistant can bypass intended permissions, exposing sensitive documents to unauthorized users.

  3. What to watch

    The article suggests the fix involved adding a filter and narrowing the assistant's scope, rather than adopting a new identity platform. Watch whether such retrieval gaps appear despite passing standard tests.

Ask the AI about this article →

Summaries like this, in your inbox every morning.

Context & Analysis

Cioffi's experience highlights a blind spot in AI evaluation: tests may celebrate accuracy while ignoring access control. The assistant auto-resolved about 60% of emails, but low-privilege tests exposed a serious gap. The logs contradicted clean evaluation scores, showing that retrieval pipelines can leak data even when models perform well.

The fix was simple—one filter and a narrower assistant—not a new identity platform. This suggests that for many businesses, tightening how an AI searches and what it can return may prevent leaks without costly overhauls. However, the article does not detail the filter's specifics, so the exact method remains unclear, and the risk of similar gaps in other systems is possible but unconfirmed.

FAQ

How did the assistant leak data?
When a low-privilege account asked the same questions as a high-privilege one, outputs differed. The assistant returned SharePoint content the low-privilege user could not have opened on their own.
Did the assistant pass evaluations?
Yes, evaluation scores were clean and unit tests passed, but the retrieval logs revealed the production failure.
What was the fix?
The fix did not require a new identity platform. It involved adding a filter and narrowing the assistant's scope.
VentureBeat AIRead Original Article

Get the latest AI Business & Industry news every morning

For example, today's edition would include:

  • Tesla Cybercab to debut in JapanITmedia AI+ · 1h ago
  • Palantir CEO: AI Risk Is Leaking Your 'Alpha'Yahoo Finance AI · 1h ago
  • AI helps train dogs to sniff cancer in IndiaJapan Times Tech · 1h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleApple accuses OpenAI of destroying evidence