AI · 2h ago
AI support copilot leaks PII via tool results, not model output
A developer's AI support system had three PII leak paths, not one. Intake tokenization missed the return path where CRM tool results enter model context. The eval that passed only watched model output, the least dangerous door.
Meridian48 take
This is a practical warning that AI system security requires auditing all data flows, not just model outputs.
ai-securitypii-leaks