Most AI agent data leaks happen when one agent combines three things: access to private data, exposure to content you don't control, and a way to send information outside your organisation. Remove or tightly control any one of those three, and the most common leak path closes.
In April 2026, the Cloud Security Alliance and Token Security reported that 65% of organisations had experienced at least one cybersecurity incident caused by AI agents in the past year. Of those, 61% involved sensitive data exposure. The same research found that 60% of organisations couldn't terminate a misbehaving agent, and 67% lacked audit trails across all the data channels their agents could reach.
Most of that data comes from the US, where agent adoption is further along. That gives Australian organisations a useful advantage: the chance to learn from these incidents before our own agents reach the same scale.
OWASP's 2026 reporting found prompt injection is still the main cause of agent security failures in production. The reason is structural. A language model can't reliably tell the difference between an instruction from you and an instruction hidden inside an email, a document or a web page it has been asked to read.
That's why security researchers talk about a "lethal trifecta". An agent that can read private data, process untrusted content, and communicate externally can be turned into an exfiltration tool by a single well-placed piece of text.
Real incidents often start somewhere less dramatic. In April 2026, Vercel disclosed a breach in which attackers compromised a third-party AI tool that an employee had connected with OAuth access, then used that access to move into Vercel's systems.
The practical controls are mostly about design, not products:
What is prompt injection? It's when text inside content an AI reads, such as an email or document, is interpreted as an instruction. The model follows it because it can't reliably distinguish data from commands.
Is Microsoft 365 Copilot affected by this? Any AI that reads content is exposed to some degree. Copilot only surfaces data a user can already access, which limits the damage, but permissions still need to be right.
Does the Privacy Act cover AI agents? If an agent uses personal information to make, or substantially help make, decisions that significantly affect people, new transparency obligations apply from 10 December 2026.
Planning your first production agent? Our AI Readiness Assessment reviews identity, network and gateway design before anything goes live.
About the author: Timotius Devin is AI Lead at PerData Technology Partners in Melbourne. At PerData Devin helps Australian organisations design, govern and deploy AI on the Microsoft platform.
Sources