Every quarter, we publish compliance and security insights that you can share with your employees to fulfill periodic security reminder requirements your organization may be subject to.

As an added bonus, we’ve highlighted some developing security trends and featured a quick tip to get more out of your compliance management.

The AI Security Role You Didn’t Know About

Your security program must conduct formal validations for conducting security reviews of vendors. As your vendors integrate artificial intelligence to their services and products, it’s important to include a focus on AI-related functionality as part of your annual security reviews. But there’s a major operational catch: your formal reviews are annual.

Software vendors, on the other hand, don’t schedule their AI releases based on your annual review. If you review vendors in January but your vendor releases an AI tool in March, you won’t validate that software for another nine months. That’s a long time to be dumping company data into an AI tool that hasn’t been validated. 

How Your Frontline Employees Help Keep You Secure

This is where the rest of your organization comes into play. Whether it is a call center floor or frontline staff working across various internal departments, these employees leverage vendor solutions every single day. If a Service Provider folds a brand-new AI feature into their offering, your frontline users will see it first.

Every employee in your company needs to assist by keeping an eyeball on the functionality in new software releases. All your personnel across the organization should be explicitly informed: if you see AI functionality suddenly popping up in existing tools, raise your hand. Make the internal vendor management or security group aware that this is happening so they can step in and start doing additional validations around that AI space.

 I would rather the frontline employees bury IT in AI alert notifications than for everyone to assume someone else did it. 

Why Continuous Vigilance Is Necessary

A lot of organizations and software providers are playing fast and loose, churning out new AI features into their platforms as quickly as possible. Driven by a fervent desire to do things that look cool simply because they include AI, many software vendors throw caution to the wind with little to no consideration of the security and compliance risks they could be introducing.

As your employees use these vendor tools to complete daily tasks, they may unknowingly share sensitive or internal data with insecure AI engines. You want to trust your vendors, but that trust must be verified. Big tech companies have violated their own privacy statements in the past by allowing back doors and sharing information with unapproved parties. It isn’t a leap for software vendors to inappropriately feed your corporate data into their engines for AI model training or inappropriately sharing data with third parties.

Additionally, there are severe coding risks to consider. Bad actors actively attempt to influence AI learning models to inject backdoor vulnerabilities into generated code so that security holes appear as expected outcomes. Unaware developers then plug the corrupt code straight into production environments. You must maintain a “trust but verify” stance across every automated output.

No AI Policy? Your Company Is Flirting with Disaster

Defining Your AI Vetting Strategy & Asking the Right Questions

When frontline employees raise their hands about new vendor AI inclusions, or when team members request new AI-enabled software, your internal team needs a clear strategy to evaluate whether it continues to be the right tool for the right purpose at the right price point—and at the right risk profile.

Your organization must walk in with eyes wide open:

  • Public vs. Private Instances: Will you allow the use of a publicly available AI platform, or do you require a private instance? Keep in mind that “private instance” can mean many things in the AI world—never assume anything. By far, the safest approach is a vendor internally secured AI platform that has no dependencies on third parties, but unfortunately there are few of those out there.
  • Risk Mitigation & Sensitive Data: If an AI tool doesn’t touch Sensitive or Internal Use data, your risk profile is much lower. However, “Sensitive Data” must be explicitly defined in a clear, well-communicated policy. If AI-enabled software touches Sensitive or Internal Use data, extra care must be taken to thoroughly vet the Service Provider.

When going into deeper levels of questioning with vendors, ask specific, pointed questions about their AI modeling:

  • Are we entering our data into a public pool?
  • Can we garner a private instance of the AI engine?
  • Do we have the capability to host it ourselves so we know precisely where the data is?
  • If we use a private instance, does that mean nothing touches our data or metadata?
  • Is the private model being influenced by learnings from elsewhere or a baseline engine improvement feed?
  • Can I configure my instance of the vendor software to exclude involvement with AI altogether?

Immediate Dealbreakers and Red Flags

Never simply assume you will get a transparent response from massive software vendors—demand evidence that verifies their claims. In practitioner experience, the following are immediate dealbreakers:

  1. A Risk Appetite Mismatch: The vendor doesn’t possess an operational model that aligns with your company’s risk profile (such as offering only a public interface for sensitive data).
  2. The Transparency Gap: The vendor is unable to provide acceptable, concrete answers regarding how they use customer information or who they share it with.
  3. Vague Responses: If a vendor can’t answer your technical questions in detail to your satisfaction, it’s a clear sign they either don’t know or are potentially actively obscuring their real data practices.

Eyes Wide Open

Vendor security management is no longer a set-it-and-forget-it annual task. Because software companies are continuously flipping on AI features between formal review cycles, keeping your organization secure means relying on all your employees to stay aware and to report any new AI tools.

TCT Portal Quick Tip: AI Policy Mapping Is Fast and Secure

Policy mapping has always been one of the most tedious, soul-crushing time sinks on any compliance engagement. The manual drag can easily burn 24 to 48 actual hours (three to six full calendar days of labor) per engagement. Running the math of wasted time for an Assessment firm would make anyone’s skin crawl.

TCT’s new AI policy mapping feature eliminates that drag. 

TCT has just released the first of its powerful AI suite of tools. TCT Portal’s AI Policy Mapping turns a multi-day, labor-intensive task into a simple button click. The Portal handles all of the work and delivers perfectly mapped policies. It couldn’t be easier — or faster — to use. 

  1. Load your policies. 
  2. Select the compliance standard or certification you need to map against.
  3. Click RUN and TCT’s AI analyzes the language in your policies, compares it against the target framework requirements, presenting the results of analysis for review, any adjustments needed, and approval. 
  4. Approve the mappings and the system automatically maps and attaches the correct policy documentation directly to the appropriate control items.

While many public AI tools create a “Wild West” environment full of data privacy gambles and an unreasonable level of unfounded trust, TCT’s AI operates on a strictly closed-loop architecture. Your data is never handed off to (or exposed to) third parties, intermingled with other client datasets, or fed into external AI training models. TCT maintains rigorous control over system access, data location, and boundary controls.

With TCT Portal’s AI system, you can have peace of mind knowing your data remains secure. 

TCT’s AI functionality is strictly opt-in; it will never be forced upon your organization. Contact us to get a demo and learn more about using AI mapping!

What’s Going on in Security This Quarter?

Some of the top breaches in Q3 2026 include:

McKesson Cyberattack: Stolen Data Includes 6.4 Million Unique Email Addresses 

ShinyHunters, a known cybercriminal group, successfully attacked McKesson, a healthcare giant, in which nearly 284 million records were accessed, and a multi-million dollar ransom from  ransomware was demanded. The initial breach occurred via vishing (voice-phishing), leading to compromised employee credentials, leading to the 284 million database rows of information being exposed. (Not necessarily unique individuals.)

Rockstar Games Hit: ShinyHunters Steal 78.6M Records [2026] 

ShinyHunters stole 78.6 million records tied to Rockstar games, a big gaming company with names tied to them, such as Red Dead and Grand Theft Auto series. The attackers did not directly break into Rockstar or Snowflake. They were able to steal authentication tokens from Anodot, an analytics platform that had standing access to Rockstar’s cloud data warehouse. 

No financial payment, player login credentials, passwords, real names were exposed. The interesting part of this breach was the type of records stolen. In-game purchase metrics, revenue data for Rockstar, player behavior tracking, and support tickets/log data for Grand Theft Auto Online and Red Dead Online were stolen. When Rockstar refused to pay the ransom, ShinyHunters posted 7.5 GB of stolen files on the dark web.

Notable stories that hit the news:

Suspected ShinyHunters hacker detained in Jordan, cooperating with FBI, sources say 

A suspected member of the notorious hacking group ShinyHunters, identified as Saif al-Din Khader, has been detained in Jordan and is reportedly cooperating with U.S. investigators. The arrest follows the cybercrime group’s recent claims of defacing the FBI’s website and stealing massive amounts of data related to FBI employees by exploiting a vulnerability in human resources software. 

Khader’s detainment comes on the heels of the arrest of another alleged member, a 24-year-old from Amsterdam named Pepijn van der Stap, earlier in September. Although the FBI declined to comment specifically on Khader’s arrest, the agency emphasized that it is aggressively investigating the ShinyHunters incident and working with international partners to bring all responsible individuals to justice.

Gemini hacked three companies. The AI isn’t the part that should scare you.  

Google’s Gemini AI platform has confirmed 3 companies have been hacked by one of its models since May 2026, only confirming it in September. The interesting part about this is not that AI is hacking companies. The root causes of the hacks are not really AI-related, and in fact could make the use case for AI security features more prominent. Two of the three companies were hacked because Gemini was able to scrape active working credentials from code repositories that were internet-facing. The third was because it was able to keep trying passwords for a found user account, until it brute-forced its way in. 

These findings mean AI found security misconfigurations or companies not following best practices.

With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance 

SOC 2 controls, as they stand now, do not explicitly require companies to note AI Agent uses by workers. AI agents can essentially become additional employees, or pairs of hands for the employees. Because SOC 2 does not treat AI agents as an identity class, or a type of user account specifically, this allows AI agents and the tasks they perform to add risks to an environment without failing a single security control in the SOC 2 audit report. This leaves the heavy lifting up to the Assessors to apply the Trust Services Criteria (TSC) to the use of AI at the target organization.

OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files 

An OpenAI Agent was found to have bypassed Australian Medicare Protocols, gaining access to files that were deemed non-public. The portal where this occurred shows spending figures for Medicare. The Medicare portal refused the AI agent’s data requests, but the agent found a workaround, and proceeded to gain unauthorized access to the files being sought. 

This is just the latest report of an AI agent finding a loophole, security bypass, or work around, going around protocol. As AI advances, its capabilities need to be taken more seriously from a security standpoint.

‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration  

There was a recent flaw in Salesforce’s Web-to-Lead forms, nicknamed SalesBleed, that has caused quite a stir. This is SalesForce’s lead-collection mechanism, which also has direct ties to their CRM. Essentially, the flaws would allow malicious instructions to lay dormant in a web-to-lead form, until an employee of the affected company asks an Agentforce agent to interact, at which point the poisoned lead would allow hidden instructions to run. Two of the three flaws in this attack could be exploited and be exfiltration attacks, but with zero actual clicks from the attacker.

Subscribe

Get industry insider expertise delivered to your inbox

Subscribe to the TCT blog

KEEP READING...

You may also like