OpenAI has confirmed something that sounds like science fiction: one of its own AI agents “escaped” a secure test environment by exploiting an unknown vulnerability to reach the open internet, and autonomously hacked AI platform Hugging Face. OpenAI itself has called it “unprecedented.” Hugging Face’s CEO called it “mind-blowing.”
This poses a question for small businesses: if the world’s best-resourced AI company can’t fully contain its own AI agents, what chance does a 20-50 person SME have?
Why This Matters For SMEs
SMEs don’t have OpenAI’s resources, red-teaming or incident response capability, yet they’re adopting the same category of autonomous AI tools, often without any of the guardrails. This incident is the clearest evidence yet that AI agents can behave unpredictably, even under expert supervision. For SMEs experimenting with AI agents unsupervised, the risk isn’t hypothetical — it’s already showing up in breach data:
- Only 14% of UK SMEs feel confident handling an AI-powered cyber incident (FSB)
- 31% of businesses using or considering AI have no plans to secure it (DSIT & Home Office, Cyber Security Breaches Survey 2025/26)
- The average UK SME cyber incident costs £31,000 — totalling £4.2bn across UK SMEs in the past year (FSB)
Following its acquisition of Planet IT in March 2026, TalkTalk Business now offers managed cybersecurity and IT support specifically built for SMEs. Because of this, we spoke to Bradley Collis, Cybersecurity Solutions Architect at Planet IT, and part of TalkTalk Business, asking him a series of questions to help SMEs who, in light of this news, may be concerned about plugging agents into their CRM or finance systems with no security oversight. Bradley has 13 years of experience investigating cyberattacks and supporting organisations through live security incidents, and states:
“This incident does not mean every AI tool is uncontrollable. It shows what can happen when an autonomous system has a goal, excessive access and gaps in the controls around it.
“It’s worth mentioning that an AI model cannot be intrinsically ‘malicious.’ We may want to humanise AI models and agents as bad actors, robot overlords or unchained and uncontrollable synthetic hackers; but the truth is that in this case the agent simply pursued its objective in a way its operators had not expected. For businesses, that is the key lesson. An AI agent can cause serious harm while doing exactly what it believes it has been asked to do.”
Q1. Are you seeing SME clients already using AI agents or tools without any security review? What does that look like in practice?
“Yes. AI is now built into many of the applications businesses use every day. Microsoft 365 Copilot, for example, can summarise emails, meetings and documents, while other platforms are adding AI features to CRM, finance, customer service and productivity tools.
“The bigger challenge for many businesses is Shadow AI. Employees are using public AI models and unapproved applications without the knowledge of their IT or security teams. Sensitive business information may be copied into these tools, including customer data, contracts, financial records and internal documents.
“We also need to remember that a number of the top-grade frontier models that make the headlines, such as Deepseek and Kimi, operate out of jurisdictions where there are little to no data privacy rules and definitely no adherence to schemes such as GDPR.
“Most SMEs do not currently have the tools to see which AI services employees are accessing, control which models they are allowed to use, or prevent sensitive information from being shared. That lack of visibility makes it difficult to understand where company data is going and what risk the business is accepting.”
Q2. What is the single most common vulnerability you find when reviewing an SME’s AI or technology stack?
“That’s easy. Excessive access permissions.
“Businesses often focus on whether they trust the AI provider, but overlook what the tool can do once it is connected. A tool needed for one simple task can be given permission to read every mailbox, access an entire CRM, download files, send messages or change records.
“That creates a large potential impact from one compromised account, stolen access token, malicious instruction or unexpected action by the agent.
“An AI agent should only be able to access the specific information and functions needed for its task. It should not receive administrator access because that is easier to configure.
“Additionally, who and what has access to this new AI tool? Do you have guardrails in place for your users so they know when to (or not to) use AI? Have you accidentally clicked a link that’s synchronised your AI with your CRM without realising, and where is that new potential PII data link being housed?”
Q3. If an SME wanted to safely trial an AI agent this week, what is the minimum security step it should take first?
“Do not connect an AI agent directly to your live business systems using a normal employee or administrator account.
“Create a controlled test environment, use a dedicated account with the minimum possible permissions, and test it using dummy or non-sensitive information. The agent should not have access to live customer records, company-wide email, payment systems, administrator accounts or the ability to delete or change important data.
“For businesses that already use Microsoft 365, our recommendation is to keep the initial trial within their managed Microsoft 365 environment, using Microsoft 365 Copilot or Copilot Studio rather than connecting an unapproved external AI tool to company data.
“The advantage is that Copilot works within the identity, permissions and security controls the business already uses. It respects the user’s existing Microsoft 365 access, while administrators can apply controls through Microsoft Entra, Microsoft Purview and Power Platform. These can include multifactor authentication, conditional access, data loss prevention policies, sensitivity labels, connector restrictions and audit logging.
“Copilot Studio also gives administrators more control over which systems an agent can connect to, who can build and publish agents, and how testing is separated from live use. This is much safer than allowing employees to connect separate AI applications to email, SharePoint, Teams or customer systems without central oversight.
“However, using Copilot does not remove the need for a security review. Copilot respects the permissions already in place, so poorly managed or overly broad Microsoft 365 access can still expose information to the wrong users. Before starting, the business should review its SharePoint, Teams and file permissions, restrict the agent to one clearly defined task and make sure a named person is monitoring what it does.
“The aim is not simply to choose a trusted AI brand. It is to trial the agent in an environment where access can be limited, activity can be monitored and permissions can be withdrawn quickly.
“Also be aware of what you’re using and ensure you’re using an AI model or agent that’s fit for purpose. If you’re working with lots of confidential or customer data, it may be prudent to run open source or open weight models locally on your own hardware (current hardware sourcing issues notwithstanding) and always ensure that you have ringfenced PII and corporate secrets from cloud-based models that train on your data.”
Q4. Does this incident change your advice to clients about vetting third-party AI tools?
“It strengthens the advice.
“Checking the reputation of the provider is no longer enough. Businesses must examine the full connection between the AI tool and their own systems.
“They should understand what information the provider collects, whether prompts or company data are retained, whether information is used to train models, where it is processed and which other suppliers are involved.
“They must also check what permissions the integration requests, whether actions are logged, whether administrator approval is required and how access can be withdrawn immediately.
“The OpenAI incident is significant because it shows that unexpected behaviour can happen even within a highly skilled and well-funded organisation. SMEs should therefore assume that every AI agent could behave unexpectedly and limit the damage it would be able to cause.”
Q5. Can you share an anonymised SME client incident linked to unsecured AI or automation tools?
“We can discuss a recurring situation we find during security reviews. Businesses discover AI applications or automation tools connected to mailboxes, cloud storage and CRM platforms through long-lasting access tokens. Some have no named owner, no review date and no documented process for removing access.
“The person who originally installed the tool may have changed roles or left the company, while the integration continues to access business information in the background.
“That is a security incident waiting to happen. The immediate response is to remove unnecessary integrations, revoke and rotate access tokens, identify who owns each tool, and reconnect approved services using dedicated accounts with restricted permissions.
“The biggest concern is often not a highly advanced attack. It is an unknown tool with excessive access that nobody inside the business is monitoring.”
TalkTalk Business offers a Security Readiness Audit specifically designed to help SMEs identify these blind spots before they become costly breaches.
