The Automation Nobody Reviewed: How AI-Built Workflows Are Quietly Leaking Enterprise Data
A developer asked an AI to speed up a document approval process. It worked perfectly and exposed sensitive HR files to hundreds of colleagues. This is happening across businesses right now.

Key points
- A security analyst at a large company found sensitive HR documents copied into a Microsoft Teams channel visible to hundreds of employees, caused not by a hacker but by an AI-generated workflow.
- Microsoft 365 tools such as Power Automate, software that automatically moves files and data between apps, are increasingly being built with AI assistants that produce code nobody fully reviews.
- AI-generated automation frequently requests far broader access to company systems than the task requires, creating hidden pathways an attacker could exploit if an account is later stolen.
- These automated workflows bypass normal code review, so security teams often don't know they exist.
A developer at a large company wanted to speed up paperwork. They asked an AI assistant to write an automated workflow inside Microsoft Power Automate, a tool that connects Microsoft 365 apps. The workflow ran perfectly. Documents moved. Approvals got faster.
It also silently copied sensitive HR files into a Teams channel that hundreds of employees could read. First reported by Dark Reading, the incident involved no outside hacker, no stolen password. Just code that worked as written, and nobody had checked what it could actually see.
How did the automation cause a data leak?
AI coding assistants lower the barrier for anyone to build powerful automation in minutes. The trouble is that code they produce is optimised to complete the task, not to limit what data it touches.
When an AI writes a script that pulls files from SharePoint, Microsoft's file-storage system, and posts them to Teams, it tends to request broad access to the whole company's file storage rather than narrow access to one folder. Security inherits a wide-open door.
If that automation's account is later stolen through phishing, where criminals use fake emails to trick staff into handing over passwords, an attacker could reach far more data than the workflow ever needed. We reported a close cousin of this problem on 28 May 2026, when a visibility study found most corporate AI exposure traces back to a thin slice of heavy users, invisible to security teams. The pattern here is the same: broad access accumulating quietly, below the radar.
Data exposure doesn't always look dramatic. A Power Automate flow distributing monthly reports could quietly forward payroll records or legal documents to the wrong channel for weeks, because it looks exactly like normal business activity.
Compliance teams face the same trap. An AI-written query used to gather documents for a legal case, a process called eDiscovery, can accidentally collect privileged communications or miss critical files, adding legal liability on top of the technical problem.
Should you worry?
The speed is the real shift. Building this kind of automation once required specialist knowledge and took days. AI compresses that to minutes, and security teams reviewing automation aren't keeping pace with the rate employees are creating it. The old assumption that only experienced developers build production workflows is no longer valid.
Banning AI assistants isn't a realistic answer. Treating AI-generated code as finished, approved code is equally wrong. It's a draft that needs human review before it touches production systems.
Practical steps are straightforward: inventory every automated workflow running across your Microsoft 365 environment, enforce least-privilege access so each workflow gets permission to touch only what it needs, and monitor for unusual file movement or new external-sharing activity.
The bigger watch item is the audit gap, not any single workflow. Most organisations govern applications, cloud infrastructure and identities with reasonable rigour. The automation layer connecting all of them often has none. That's where the next significant enterprise breach is quietly being set up, one helpful AI-written script at a time.



