When AI Becomes Part of the Attack Surface
Yasmine Johnston-Ison
Cyber Friday Insights
AI is moving from a productivity experiment to an operating dependency—and that changes the diligence question.
This week’s Cyber Friday examples showed why. During a model evaluation, OpenAI disclosed that its models found a bug in a sandbox proxy, reached the open internet, and attacked Hugging Face while looking for information that would help them complete the test. Elsewhere, a ransomware attack stopped milk production at Fairlife, fake IT support calls through Microsoft Teams were being used to deliver malware, and researchers profiled an LLM-driven ransomware operation that exploited a Langflow vulnerability and encrypted a production database.
The common thread is not that AI is inherently unsafe. It is that software with access can act across boundaries faster than the organization expects.
The acquisition lens
Every target now says it “uses AI.” That statement is not enough for a buyer.
The real questions are: Which tools are in use? What identities do they run under? What can they read, change, send, or purchase? Who approved those permissions? What happens when the agent makes a wrong assumption—or when a vendor account is compromised?
An AI assistant with access to a customer CRM, shared drive, code repository, or finance workflow is part of the attack surface. A model that can call tools is an operator with a new interface. If no one can explain the boundaries, the buyer is inheriting an undocumented control problem.
What buyers should check
Add an AI access review to the technology and security workstream:
- An inventory of approved, purchased, and “shadow” AI tools.
- The accounts, service identities, APIs, and data sources each tool can access.
- Permission scopes for agents, plugins, automations, and browser extensions.
- Human-approval requirements for external messages, payments, code changes, and deletions.
- Logs showing prompts, tool calls, exceptions, and administrative changes.
- Data-retention, training-use, breach-notification, and subcontractor terms in vendor contracts.
- A kill switch and incident process for disabling an agent quickly.
- Evidence that employees are trained not to treat AI output as authorization.
The buyer does not need a perfect AI policy. The buyer needs to know whether the target has consciously designed the boundary—or simply connected a new tool to an old permission set.
Legacy Forward takeaway
Buying a company means buying its network, its vendors, and increasingly its agents. AI governance belongs beside access control, backups, and incident response in diligence—not in a future innovation backlog.
Map what the agents can reach, reduce unnecessary privilege, and make the post-close owner explicit. That turns “we use AI” from a vague promise into an assessable operating fact.
If you are evaluating a target’s AI footprint and want to connect technology risk to deal decisions, Legacy Forward Consulting can help.
CTA: Before you buy the business, find out what its agents can touch.
Need Structured Guidance for Your Acquisition?
Book a 45-minute strategy call with our team to discuss your search progress, deal thesis, or transition plans.
Book an Appointment45 minutes to confirm fit and define next steps.