ChatGPT Read 400 Internal Company Files In 42 Milliseconds. Security Stacks Saw Nothing.
Skip to content
A routine ChatGPT query just retrieved 404 internal files in 42 milliseconds. The fix isn’t blocking AI — it’s giving it the context it’s missing.

A cybersecurity company recently published an account of something that stopped their security team cold. An employee typed a single question into ChatGPT: “Is there a document in Drive on how to enable SSO?”

In 42 milliseconds, ChatGPT’s backend quietly retrieved over 400 internal company files from Google Drive. Product roadmaps. Financial records. Customer plans. Security procedures. The files spanned nearly every function in the business.

No alert fired. No user downloaded anything. No browser was involved. The requests came from cloud-based IP addresses — server to server — invisible to every tool in the security stack.

The company had approved the ChatGPT-to-Google Drive OAuth integration. The tokens it created stayed active for 21 days. Then a single prompt woke up the backend, and it did exactly what it was permitted to do: read everything it could reach.

Here is the problem. ChatGPT didn’t know that a product roadmap should be treated differently than a help article. It didn’t know that one of those files carried a regulatory obligation and another didn’t. It didn’t know that the person who granted the OAuth access had left the team three weeks ago. It had no way to know any of that.

It had access. It had no context.

Context is what makes access meaningful

Security has always had a context problem. The tools built to protect enterprise data were designed around human actors: browser behavior, endpoint activity, email flows. They could track what a person did. They weren’t designed for a world where AI backends operate at machine speed through API tokens, making thousands of requests with no device, no browser, and no user in the loop.

But the absence of human behavior isn’t the core issue. The core issue is that neither the AI tool nor the security stack had enough context to make intelligent decisions about what should and shouldn’t happen.

Context, in data security, means three things working together: understanding what the data actually is, understanding who or what is accessing it and why, and understanding what rules govern it given the industry and regulatory environment. When all three are present, you can make intelligent decisions automatically. When any one is missing, you are flying blind.

Most enterprises, if they are honest, are flying blind on at least two of those three.

The approval is not the control

The Sola Security incident is a useful illustration of how the gap opens. When an employee clicks “Approve” on an OAuth screen, the security team has typically done their due diligence: reviewed the vendor, scanned the permissions, documented the approval. That process is real and it matters.

But approving an integration is not the same as controlling what it can do to your data. The consent screen grants access. It does not classify the files that access will reach. It does not assess the risk profile of the data being enumerated. It does not apply persistent controls to the files most likely to cause harm if they leave the organization.

That gap — between access granted and data protected — is where the incident happened. And it is not a gap that existing DLP tools, endpoint controls, or SIEM alerts were built to close. Those tools watch for anomalous human behavior. An AI backend making 404 parallel API calls looks like nothing to them, because there is no human behavior to detect.

Intelligence that travels with the data

This is the problem Seclore’s ARMOR platform is built to address. Not by blocking AI integrations — but by ensuring that the data AI can reach is already governed by context-aware intelligence before any integration is ever approved.

The distinction matters. The question is not “can this AI tool access our Drive?” The question is: “what would happen to each file in that Drive if AI did access it?”

ARMOR’s AI data security intelligence engine uses a method Seclore calls the Semantic Triad — analyzing Content, Context, and Intent together — to understand what a document actually means, not just what keywords it contains. A financial model, a customer plan, a security procedure: classified accurately, at scale, without the false positive rates that cause teams to stop trusting classification outputs.

That intelligence is the foundation. But data discovery and classification alone is not enough. ARMOR also maintains a persistent intelligence layer through AI DLP and EDRM (Enterprise Digital Rights Management) — which means that once a file is understood and protected, that protection travels with it. Even if an AI backend enumerates a Drive and downloads 404 files in parallel, the files that carry sensitive or regulated content are already rights-managed. They can be revoked remotely. Sensitive values within them can be masked before they reach an AI processing layer. The audit trail captures every interaction — which integration touched what, from which IP, at what time.

This is what context intelligence actually looks like in practice: not a dashboard showing you risk scores after the fact, but persistent controls that operate at the data level regardless of what agent, application, or backend is doing the accessing.

The goal is not fewer AI integrations

Some security teams, seeing an incident like this, will react by tightening OAuth approvals or restricting AI tool access. That is an understandable first response. It is not a sustainable strategy.

The organizations winning with AI are not the ones that blocked it the longest. They are the ones that built the data foundation that makes fearless adoption possible: data that is understood, classified, and protected before any integration touches it.

When that foundation is in place, an AI backend enumerating a Drive is not a crisis. The files it can reach are already governed. The ones that shouldn’t leave the organization already have persistent controls on them. The audit trail already captures the access. And the security team already has the context to understand what happened and why — without stumbling on it by accident three weeks later.

The Sola Security team asked a good question: why does a single query trigger a full Drive enumeration? That is a question for AI providers to answer. The parallel question — what context does your security infrastructure have over the data AI can reach? — is one every enterprise can answer for itself, starting now.