By the Shadow AI Policy team
Almost every AI acceptable use policy answers one question well — which tools may people use? Very few answer the second one: what are those tools allowed to reach?
That second question is where the data actually goes. An approved AI assistant connected to company mail, files and chat can read more in a second than an employee could paste in a week, and it does so without anyone making a decision at the moment it happens. If your policy governs the tool but not the connection, the most consequential grant in the whole arrangement is the one nobody signed off on.
Approving a tool and approving what that tool can reach are two different decisions. Most policies make the first one carefully and the second one by accident.
Section 6 of nearly every AI policy — ours included, until this week — is a list of things employees must not enter into an AI tool: customer data, HR records, source code, contracts. It is good advice and it is worth keeping. But read it literally and notice what it assumes: that data leaves the company because a person typed or uploaded it.
A connected tool breaks that assumption. Once an assistant holds a standing authorization to a mailbox or a document store, the data path no longer runs through the keyboard. The tool fetches what it needs. An employee can follow the paste rule perfectly, all day, every day, and still be sitting on top of an exposure the policy never described.
This is the same category error that made browser extensions a governance gap — a problem we wrote about here — except that connectors are usually granted deliberately, by people who believe they are doing something routine, and are then never looked at again.
On 18 August 2026 Microsoft shipped a server-side fix for a chain of three vulnerabilities in Copilot Personal, disclosed by Varonis Threat Labs under the name CoSnitch and tracked as CVE-2026-24301. The mechanism is worth understanding precisely, because it is a cleaner illustration of the connector problem than anything we could have invented.
An undocumented URL parameter caused a prompt supplied in a link to execute the moment the page loaded, inside the victim's already-authenticated session. That injected prompt could then query the services the user had previously connected, encode what it retrieved, and use the assistant's own ability to fetch a URL to send the results to an endpoint the attacker controlled. Varonis reported the issue to Microsoft in December 2025 and found no evidence of exploitation in the wild.
Three things about that sequence matter for policy:
To be clear about the state of it: this specific flaw is patched, and we have no reason to tell anyone that their Copilot deployment is currently exposed. The reason to care is that the shape of the attack is not specific to Microsoft. Any assistant that can be handed content and also holds standing access to systems has the same two halves. Vendors will keep closing individual instances; the structural risk is the grant.
We changed the free policy template this week rather than writing about a gap we had left open. Two additions, in the two places the gap actually lives.
Approval covers a tool, not everything that tool can reach. Connecting an AI tool to company email, files, calendars, chat, code repositories or any other system — through a connector, plug-in, extension or "sign in with" authorization — now requires separate approval from the policy owner, because it gives that tool standing access to data nobody pasted into it. The personal or free tier of any tool must never be connected to a company account or company data, and limited-tier and prohibited-tier tools must not be connected at all. Grants already made get reviewed on the same cycle as the tier list itself.
Data can leave an AI tool without anyone typing it in. A link, document, web page or message that an AI tool opens on your behalf can contain instructions the tool follows as though you had given them — including instructions to gather whatever the tool can reach and send it somewhere else. So: do not open AI-assistant links that arrive from outside the company, do not point a connected tool at content you do not trust, and if a tool does something you did not ask it to do, stop and report it.
That second clause is deliberately written without the words "prompt injection." An employee does not need the term to follow the rule, and a policy that makes people feel they need a security background to comply is a policy people quietly stop reading.
Shadow AI stopped being only about which tools employees sign up for. The tools your company approved, paid for and rolled out are now the ones with the deepest reach into your systems, and the permission model that gives them that reach is largely invisible to the people who own the policy.
A tier list that names ChatGPT and Copilot but says nothing about what they are plugged into is answering the 2023 version of the question. Governing the connection is the 2026 version, and it is a paragraph of work, not a project.
A connector is any standing grant that lets an AI tool reach another system on the user's behalf — a plug-in, an integration, or a "sign in with Google/Microsoft" authorization that gives the tool ongoing access to mail, files, calendars, chat or code. It needs separate treatment because approving a tool and approving what that tool can reach are two different decisions. A data rule written around what employees type in does not cover data the tool fetches by itself, which is why a paste-only policy can be followed perfectly and still leak.
Yes. Content an AI tool reads can carry instructions the tool then follows as though the user had typed them — a pattern usually called prompt injection. In August 2026 Varonis Threat Labs disclosed CoSnitch (CVE-2026-24301), a chain of three flaws in Microsoft Copilot Personal in which one clicked link auto-executed an attacker's prompt inside the victim's authenticated session, queried the apps that session was already connected to, and posted the results to an attacker-controlled endpoint. Microsoft shipped a server-side fix on 18 August 2026 and Varonis reported no evidence of exploitation in the wild. The mechanism is what matters for policy: no paste occurred, so a paste-only data rule was never broken.
For personal and free tiers, yes — those accounts sit outside your contracts, your logging and your ability to revoke, so they should never hold standing access to company systems. For approved enterprise tools, a ban is usually the wrong call, because connectors are most of why those tools are worth paying for. The workable rule is that a connector is approved separately from the tool, by the same person who owns the approved-tool list, and that grants already made get reviewed on a schedule rather than living forever.
Start with your identity provider rather than with employees. Microsoft Entra ID and Google Workspace both list third-party applications that users have granted OAuth access to, along with the scopes each one holds, and that inventory will usually be longer than anyone expects. Review it for AI tools nobody approved, revoke what is unused or unrecognized, and only then ask teams what they need reinstated. Asking first tends to surface the grants people remember, not the ones that matter.
Tailored to your industry and the AI tools your team uses — including the connector rules above. Free preview, then $149/mo to keep it current as the rules and vendor terms change — or $79 for a one-time snapshot.
Generate my policy kit →Writing policies for several clients? MSPs, IT consultancies and fractional CISOs keep a roster of client kits that refresh monthly, under their own branding. See partner plans →