Security researchers demonstrated something in 2025 that should reframe how every enterprise thinks about AI risk. They sent an employee an email. The employee never opened it. The company's AI assistant read it anyway, followed instructions buried inside it, retrieved internal documents the sender had no business seeing, and passed them out of the building. Nobody clicked anything. No alert fired. The technique was named EchoLeak, disclosed by Aim Labs against Microsoft 365 Copilot and tracked as CVE-2025-32711. Microsoft patched it server-side in June 2025 and found no evidence it had been used in the wild, which is the point: this was a demonstration, run by researchers, of something the architecture permitted by design.
What makes that story useful is not the exploit. It is what the exploit reveals: enterprise AI moves your data along a path most organisations have never actually drawn. Nothing in that attack broke. Every component did exactly what it had been built to do.
Which is why the question that surfaces forty minutes into every AI meeting, usually from someone in legal (where does our data actually go?), is the right question asked far too late. What follows is the map that should have existed first: five stops, one boundary, and seven places a copy comes to rest.
The Data Has Already Left the Building
The instinct this provokes (block everything, approve one tool, declare victory) misses the signal. People route around IT because the sanctioned path does not reach the systems they work in. The durable fix is a governed path that is better than the ungoverned one, and you cannot build that without knowing precisely where a governed prompt goes. Shadow AI is what an unmanaged adoption curve looks like from the security side, which is why AI adoption is a people problem before it is a technology one.
The first place your data goes is rarely your AI vendor. It's a personal account your security team cannot see.
Eerly AI StudioStop One: The Prompt Is Bigger Than the Question
Users picture a question travelling to a model. What travels is an assembled payload, and two of its properties are consistently underrated by the teams shipping these systems.
Exposure is not a single event but one repeated for the life of the thread. Model APIs are stateless, so the whole history is resent on every turn: a detail disclosed at turn 3 is re-transmitted at turns 4 through 40. And the system prompt, authored like configuration, reviewed like configuration, yet reading like an internal policy manual, leaves the building on every call. Classify it accordingly.
Stop Two: Retrieval Makes a Second Copy
To answer from your own knowledge, a system splits your documents into chunks, converts each into an embedding (a long list of numbers) and stores those vectors in a searchable index. Two comfortable beliefs about that step are wrong, and the diagram shows precisely where each one breaks.
Treating a vector store as a low-sensitivity derived artefact because "it's just numbers" is the most common data-classification error in enterprise AI today. Song & Raghunathan (CCS 2020) recovered 50–70% of input words from sentence embeddings; Vec2Text (EMNLP 2023) recovered 92% of 32-token inputs exactly in-domain, and reconstructed full names from clinical notes. Calibrate that figure honestly: against a production embedding model on out-of-domain text the same method scored 60.9% exact at 32 tokens and 8.0% at 128, so inversion degrades with length and domain shift. It does not disappear, and ALGEN (ACL 2025) has since cut the data an attacker needs to roughly a thousand samples.
The permissions failure is not theoretical, and EchoLeak was not an isolated case. Researchers at UT Austin's SPARK Lab documented ConfusedPilot, a class of confused-deputy vulnerabilities in RAG assistants in which poisoned documents corrupt responses and content can surface even after access to it is revoked. A Microsoft Research position paper goes further, demonstrating exfiltration against fine-tuning and RAG architectures and arguing that prompt sanitisation, output filtering and isolation are all probabilistic, and that only deterministic, participant-aware ACL enforcement across the pipeline actually holds. And the entitlements those controls would have to enforce are largely unmapped: Microsoft's State of Cloud Permissions Risks found over 70% of identities had used none of their granted permissions in the preceding 90 days. Retrieval does not create an oversharing problem so much as finally exercise the one that was always there. The file share nobody has reviewed since 2019 was safe mainly because it was unsearchable. It is the same neglected corpus behind the enterprise knowledge problem, now suddenly queryable.
An embedding is a copy of your document, not a redaction of it.
Eerly AI StudioStop Three: Tool Calls Widen the Reach
The moment a system stops answering and starts acting, the path widens. Tool calls send arguments outward into live systems (ticketing, CRM, ERP, mail, file storage) and pull records back inward. Whatever returns is appended to the context and transmitted to the model on the next call. Action is not a separate data-flow concern from retrieval; action feeds retrieval. (For what these agents actually do once they are wired into a system of record, see our guide to AI agent types and what they do inside SAP.)
So the governing question changes shape. It is not "what is this user allowed to see?" but "what can every credential this agent holds see in combination, and what happens when one prompt persuades it to combine them?" An agent wired into five systems through five service accounts carries a reach no individual employee possesses, one that appears on no org chart and in no access review.
Stop Four: Crossing the Trust Boundary
At this point the prompt, the retrieved chunks and the tool output are concatenated and sent to a model. If that model is hosted by a third party, this is the moment your data leaves infrastructure you control and enters infrastructure you merely have a contract about. Three variables decide what that means.
Read the retention row carefully, because it is the one that catches people. Providers retain more than most teams expect, for defensible reasons: OpenAI generates abuse-monitoring logs for API usage and retains them for up to 30 days, longer where law requires, and even under a zero-data-retention arrangement limited metadata may persist to satisfy legal and safety obligations. "Zero" is a contractual configuration with named exceptions, not an absolute. On training, the operative word is never whether but default. And on geography: under GDPR every call sending personal data outside the EEA is a cross-border transfer, and a prompt containing a customer's name is personal data however incidental it felt to type.
Retention posture is also a moving target. In August 2026 OpenAI previewed a zero-retention safety system while Anthropic moved toward requiring retained logs for its newest models. An assessment signed off in 2025 may not describe the model you are calling today, so treat retention like a pinned dependency version, not a policy you read once. The regulatory dates move too: Regulation (EU) 2026/1744, in force 27 July 2026, deferred the Annex III high-risk obligations to 2 December 2027 (Annex I to 2 August 2028), while leaving the Article 50 transparency duties on their original August 2026 timeline.
"We don't train on your data" is a contract setting, not a law of physics. Ask what the default is.
Eerly AI StudioStop Five: The Exhaust Nobody Budgets For
Tracing can capture prompts, retrieved context, tool arguments and completions verbatim. That makes it simultaneously the most powerful debugging capability in the field and its most significant compliance liability, because a trace stores precisely the payload the rest of the architecture was protecting. The standard itself is careful about this: OpenTelemetry's GenAI semantic conventions deliberately keep message content out of the default attribute set and make capture opt-in behind an explicit flag, precisely because prompt bodies routinely contain names, account numbers and proprietary logic. Which means the exposure at this stop is usually not something a vendor did to you. It is a flag somebody turned on in staging to chase a bug and never turned off. And logs propagate: to the tracing vendor, to dashboards, into the warehouse, out through alert emails. Each hop is a new copy, in a new system, with a new access list, under a retention rule nobody mapped back to the source document's classification.
Count them honestly and a single question turns out to leave copies in seven distinct places. Only three of those sit inside the perimeter you designed.
Then there are sub-processors, the vendors behind your vendor. A credible data-protection agreement carries standard contractual clauses covering every one of them, flows residency down the chain rather than stopping at the first hop, and addresses compelled-access regimes such as the US CLOUD Act and FISA 702 with notice, contest and termination triggers. A vendor who cannot produce a current sub-processor list is not telling you they have none. They are telling you they have not looked.
Most teams encrypt the model call, then log everything it said into a system nobody classified.
Eerly AI StudioFive Questions, and the Weak Answers
Each of the questions below has a reassuring non-answer that sounds like a strong one. Hearing the weak version tells you more than any certification badge on the trust page.
The controls that answer those questions are not exotic. They are simply the ones that get skipped, because each sits on a boundary between two teams and therefore belongs, organisationally, to nobody.
Sovereignty Is an Architecture, Not a Checkbox
The most useful shift of the past year has been from data residency, which country the bytes sit in, to technical sovereignty: who controls the stack that processes them, and under whose jurisdiction that control sits. It is a better frame because it survives contact with reality. Data can rest inside the EEA and still be reachable under a foreign compelled-access regime. A region setting is a necessary answer, not a complete one.
None of this argues against enterprise AI. It argues against accepting the word "enterprise" as though it settled anything. Enterprise is not a promise somebody made you. It is a set of controls somebody configured, in a contract somebody signed, over a path somebody drew. When nobody can produce the drawing, the controls are usually partial and the contract is usually older than the model in production. The organisations that avoid that are the ones already treating human-AI collaboration as something to design rather than something to announce.
Which returns us to that email nobody opened. EchoLeak did not succeed because the technology failed. It succeeded because every component behaved exactly as designed, along a path no one had drawn end to end. The path is finite: five stops, one boundary, seven resting places. It can be documented in an afternoon and verified in a fortnight, and once it is written down it stops being something an organisation takes on faith and becomes something it can actually govern.
You cannot govern a data path you have never drawn. Draw it once, and most of the hard questions answer themselves.
Eerly AI StudioAt Eerly, this is the premise the platform is built on: agents that act across enterprise systems within the permissions teams already have, policy-level control over what an agent is allowed to reach, and execution traceable end to end, so that "where did that data go?" is a query, not an investigation. The path exists whether or not anyone maps it. Mapping it is the whole job.
See the whole data path, on one screen.
Eerly AI Studio runs agents across your enterprise systems within the permissions your teams already have, with policy-level control over what an agent is allowed to reach and execution traced end to end. Walk the five stops with us against your own stack, and we will show you where each copy comes to rest.
Book a Demo →Sources & Further Reading
- Peer-reviewed research. Song, C. & Raghunathan, A.: Information Leakage in Embedding Models (ACM CCS 2020) · Morris, J. et al.: Text Embeddings Reveal (Almost) As Much As Text, Vec2Text (EMNLP 2023) · Chen, Y., Xu, Q. & Bjerva, J.: ALGEN: Few-shot Inversion Attacks on Textual Embeddings (ACL 2025)
- Attack research, primary disclosures. Aim Labs: EchoLeak: zero-click data exfiltration in M365 Copilot, with Microsoft's advisory for CVE-2025-32711 · SPARK Lab, UT Austin: ConfusedPilot: Confused Deputy Risks in RAG-based LLMs · Bhatt, S. et al. (Microsoft Research): Enterprise AI Must Enforce Participant-Aware Access Control (2025)
- Survey and telemetry evidence. Gillespie, N., Lockey, S. et al., University of Melbourne & KPMG: Trust, Attitudes and Use of Artificial Intelligence: A Global Study 2025 · Cyberhaven Labs: 2026 AI Adoption & Risk Report (vendor research, read as such) · Microsoft: State of Cloud Permissions Risks
- Provider documentation: read the contract, not the summary. OpenAI: Data controls in the OpenAI platform and Enterprise privacy · Anthropic: zero data retention and covered-model retention · Google Cloud: Vertex AI data governance
- Regulation, primary texts. Regulation (EU) 2024/1689 (AI Act), as amended by Regulation (EU) 2026/1744 · Article 99 on the three penalty tiers · GDPR Chapter V, Articles 44–49 on transfers · EDPB–EDPS Joint Response on the US CLOUD Act
- Engineering standards. OpenTelemetry GenAI semantic conventions, where prompt and completion content is opt-in by design · OWASP Top 10 for LLM Applications, particularly LLM02 on sensitive information disclosure

Tejas builds the platform layer beneath Eerly's agents: the isolation, permission and data-path engineering that decides whether an enterprise AI system is something a company can actually put its records through.