09/30/2026
New this week: an AI assistant handed over an entire filesystem — SSH keys and all — because someone simply asked it to export a file. No hack. No exploit. Just an agent doing exactly what it was told, with none of the judgment a human would apply.
That's the risk category law firms need to start taking seriously: not what AI might say wrong, but what an AI agent is capable of doing when nobody's checking its permissions.
We break down this incident — plus the AWS credential exposure and legal tech's fast pivot toward agent governance tooling — in our latest post. Worth a read before your next AI rollout.
🔗 https://www.cochatechnology.com/ai-agent-security-risks-law-firms/