@brian_greenberg@infosec.exchange
Post #4342687
2026-08-03 01:45 UTC
✨ A sparkle icon shows up in an app you own. Nobody in IT put it there. A user opens a ticket asking what it does, and the help desk has no answer. The feature is live, it's available to everyone, and it's already processing your data.
I wrote this one for Forbes because it keeps happening and I've stopped pretending it's normal.
Zoom gave admins about four days in July 2024 to click "do not auto-enable" before AI Companion turned itself on. Google launched Workspace Intelligence in April 2026 with Gemini reaching into Gmail, Drive, Chat and Calendar, each source on by default, and the admin controls could show up as much as 72 hours behind the live feature. OpenAI ships ChatGPT Enterprise with connectors off and ChatGPT Business with them on. Same company, opposite decision.
Here's the part that should bother you. Many U.S. states require two-party consent for recording. Whether an AI meeting summary counts as a recording under wiretap law is still an open question, and your company gets to be the test case. Zoom chat retention defaults to two years, so the evidence sticks around while you figure it out.
What decent vendor behavior would look like:
・New AI features ship off, with the switch left to you
・One clear notice to admins naming the feature, the data it touches, and the date it goes live
・An evaluation window measured in weeks
Until that shows up, work from the assumption that the next AI feature is already on in your tenant. Put configuration reviews on a recurring schedule. Write down every default-on surprise you find and bring that list to your renewal conversation, because that's where you actually have leverage over the behavior.
Default-on is a choice. So is governance.
https://briangreenberg.net/2026/07/30/default-on-ai-are-saas-vendors-outsourcing-their-risk-to-you/
#AIGovernance #CISO #SaaS #security #privacy #cloud #infosec #cybersecurity
Replies (0)
No replies.