Good afternoon. This week in The Context:
| Ctrl+Alt+Del | ||
| Three issues from the past week that are shaping trust and security in AI. | ||
|
||
|
||
|
|
Rearview
Events from this week that add colour to our themes.
Personal inboxes are now part of the corporate attack surface. Google's Threat Analysis Group documented APT42, an Iranian state-sponsored actor running targeted credential phishing against senior figures across US political campaigns. The mechanism is patience: the group inserts itself into existing conversational threads via personal email accounts. Corporate email controls do not extend to the personal Gmail of a C-suite executive, yet those accounts are routinely used for sensitive coordination.
Single-vendor AI dependency now carries regulatory risk. California's SB 1047 passed the State Senate, introducing developer liability for large AI models and mandating a full-shutdown capability. Organisations that have hard-coded production workflows to a single foundation model now carry regulatory disruption risk if that model's developer faces compliance action or mandatory shutdown.
Applying AI
Learning from others, applying it to your context.
Who governs which AI tools your employees can connect?
If the answer is unclear, the Salesforce exposure likely applies. AI writing assistants, meeting summarisers, and workflow agents all require OAuth grants - often with broad scopes, often without IT visibility. Third-party AI grants need the same review cycle as privileged accounts, not the default-allow posture designed for productivity.
Does your helpdesk still verify identity with biographical data?
2.7 billion records including SSNs are now searchable. Asking for the last four digits verifies internet access, not identity. Possession-based controls - hardware tokens or device-bound proof - are the only direction that still holds.
Could your organisation switch its primary AI provider in 30 days?
If the answer is no, SB 1047 is your signal. Hard-coded model API dependencies are now a regulatory and commercial risk. You may not need to switch providers - but you need to know you could. The time to build abstraction layers is before you need them.
Takeaways
OAuth tokens persist beyond password resets and bypass MFA. The permission layer needs the same rigour as the credential layer. Governance built around password hygiene has a structural gap at the consent grant.
Biographical data is no longer a reliable secret. Verification processes built on knowledge-based questions are now confidence tests for attackers. Move to possession-based controls.
Single-configuration errors can expose hundreds of gigabytes. Detection-only postures leave the root cause ungoverned. Govern data pipelines and developer endpoints - not only detection.
AI tooling has made shadow OAuth grants significantly harder to see. Extend identity governance scope explicitly to include third-party AI application grants - same review cycle as privileged accounts.
Poll of the Week
How concerned are you about the emergence of autonomous AI-driven cyberattacks?
Opinion
What strikes me about this week is not the sophistication of the attacks. What strikes me is that the defence still relies, at its critical moment, on an employee correctly assessing a permission request they were never trained to evaluate, while under social pressure from a caller pretending to be IT.
We have spent years hardening the password layer and the endpoint layer. The permission layer received the productivity design, not the security design. That is not a failure of individual employees. It is a failure of the architecture they were given to work inside.
The reasonable question for this week is not whether your employees clicked the wrong thing. It is whether the system would have caught them if they had.
Thanks for staying with me until the end,
David
Weekly Context is one tier of an ongoing body of work at synoptikon.com on navigating AI and cyber resilience for digital trust. The long reads, essays, and deep dives sit there for when an idea here needs more room.






