Security & Threat Intelligence

The Watch

The Signal

Microsoft's own terms of service classify Copilot as 'for entertainment purposes only'

Three separate AI vendor trust failures surfaced in 24 hours: your AI vendor governance model is built on assumptions that are provably wrong. Pull your Copilot deployment terms and AI vendor contracts for legal review this week.

In Play

  1. AI Vendor Trust Collapse: Three Governance Failures in 24 Hours

    Microsoft Copilot ToS says 'entertainment only.' Anthropic revoked third-party tool access overnight, breaking downstream automation. Banks forced to deploy Grok under SpaceX IPO pressure without security review. OpenAI lost two C-suite execs during IPO prep. Every major AI vendor simultaneously demonstrated governance risk.

    Ask Clarity
  2. Mercor: From Data Breach to Industrialized IP Exfiltration Pipeline

    Beyond the 4TB breach reported Thursday, Mercor's business model actively pays workers for former employers' proprietary materials — a systematic IP exfiltration incentive at $10B scale. Meta paused its partnership. Your DLP controls stop bulk downloads during employment but can't prevent ex-employees selling files to AI data brokers months later.

    Ask Clarity
  3. AI Agents Ship Desktop Control, Calendar Access, and Autonomous Code Execution

    Anthropic shipped Claude desktop control (inherits full user session privileges). Cursor 3 launched an agent-first IDE with parallel autonomous code execution. MetaClaw reads Google Calendar during meetings. OAuth default policies allow all three without admin approval. Your EDR was built for malware, not an AI assistant with your credentials.

    Ask Clarity
  4. Synthetic Media Goes Open-Source: Video Evidence Integrity Degrades

    Netflix open-sourced VOID, which erases video objects and rewrites surrounding physics. Separate research trained on 100K clips enables realistic person removal. Combined with Miravoice's AI voice agents ($6.3M funding) for sustained natural phone conversations, both video and voice evidence face trust erosion. SOC teams should treat video like they already treat email.

    Ask Clarity
  5. AI Litigation Wave Targets Chatbot Deployments

    Veteran litigator Jay Edelson (forced Facebook settlements) is launching 'explosive' lawsuits against AI chatbot companies. The tech industry is described as 'never more vulnerable in court.' Combined with the Copilot ToS gap and Perplexity AI's data-sharing lawsuit, customer-facing AI deployments face compounding legal liability from guardrails, data handling, and output quality.

    Ask Clarity

Deep Dives

AI Vendor Governance Crisis: Your Contracts, ToS, and Access Guarantees Are Weaker Than You Think

Four Vendor Failures, One Week

In a single intelligence cycle, four major AI vendors simultaneously demonstrated that the governance assumptions underpinning most enterprise AI deployments are fundamentally unreliable. This isn't a theoretical risk assessment — these are concrete events that may already affect your environment.

Microsoft Copilot: 'Entertainment Purposes Only'

Microsoft's official terms and conditions describe Copilot as being 'for entertainment purposes only' — explicitly not for business use. If your organization deployed Copilot for code review, document generation, email drafting, or any production workflow, you're operating outside the vendor's stated terms. In a regulatory inquiry, breach investigation, or litigation, this creates a liability vacuum: Microsoft has pre-emptively disclaimed responsibility for the exact use cases you purchased it for.

This is particularly acute for organizations subject to HIPAA, SOC 2 Type II, or GDPR where AI-assisted data processing requires demonstrable vendor accountability.

Anthropic: Platform Access Revoked Overnight

Effective April 4, 2026, Anthropic blocked Claude Pro and Max subscribers from connecting to third-party agentic tools like OpenClaw. Users must now switch to per-token API billing. OpenClaw's creator (now at OpenAI) accused Anthropic of an embrace-extend-extinguish strategy. The security lesson: any automation, detection logic, or security tooling your teams built on Claude via third-party connectors may have broken overnight with zero notice.

Grok: Forced Adoption Under Business Pressure

Banks, law firms, and advisers working on the SpaceX IPO are being required to purchase Grok subscriptions worth tens of millions of dollars and integrate the chatbot into their IT systems. Some have already complied. Grok faces active investigations for generating harmful content, yet it's entering financial institution environments through business pressure rather than security procurement. Sensitive IPO materials and M&A data are flowing through a platform with known safety gaps — creating regulatory exposure under OCC, FFIEC, and SEC oversight.

OpenAI: Leadership Vacuum During IPO

OpenAI's Fidji Simo (CEO of AGI Deployment — their revenue leader) is on medical leave. COO Brad Lightcap shifted to special projects. This during IPO preparation — historically when companies are most distracted from operational fundamentals including security. Two sources independently flagged this as a TPRM watchlist event.

Platform dependency without contractual guarantees is operational risk. This week proved that every major AI vendor can change your deployment terms, revoke your access, or lose their leadership overnight.

The Pattern

These aren't isolated incidents. They reveal a structural gap in how organizations evaluate AI vendor risk. Traditional TPRM assesses data handling, uptime SLAs, and security certifications. It doesn't assess whether the vendor's ToS actually covers your use case, whether API access can be unilaterally revoked, or whether business partners can force AI tool adoption into your environment.

What to do

  1. Pull Microsoft Copilot ToS and have legal counsel compare against your actual deployment scope by end of this week

  2. Inventory all Claude-based automation using third-party connectors and verify API-level access continuity by Friday

  3. Add 'coercive AI adoption' questions to TPRM questionnaires this sprint — specifically ask partners whether any AI tools were adopted under business pressure vs. security-evaluated procurement

  4. Flag OpenAI in your vendor risk register for enhanced monitoring through IPO completion

Update: Mercor's Business Model Is an Industrialized IP Exfiltration Pipeline — Not Just a Breach

What's New Since Thursday

Thursday's briefing covered the LAPSUS$ claim against Mercor — 939GB of source code, 4TB total data exfiltrated via TailScale VPN. Today's intelligence adds a more insidious dimension: Mercor's core business model is itself a systematic IP exfiltration mechanism, and Meta has paused its partnership in response.

The Business Model IS the Threat

Mercor, now valued at $10 billion, has been actively soliciting proprietary work materials from professionals across industries — offering payment for materials like '4D physics scenes with camera data' from visual effects artists. Despite claiming it 'does not buy intellectual property,' the materials Mercor seeks are precisely that: work product created under employment agreements that assign IP to the employer.

Two independent sources confirm the pattern. This creates a two-sided security exposure that's more dangerous than the breach itself:

  • Breach exposure: If any employees engaged with Mercor, their PII and potentially your proprietary data are in the 4TB dump
  • Ongoing insider threat vector: Mercor's solicitation model creates a permanent financial incentive for current and former employees to exfiltrate IP — a pipeline that operates post-employment, beyond your DLP perimeter

Why Traditional Controls Fail

The attack chain bypasses standard defenses:

  1. Employee departs with copies of work product (or retains cloud access past revocation)
  2. AI data broker offers cash for 'old job materials' — framed as harmless freelance work
  3. Your trade secrets enter a third-party pipeline with zero contractual protections for you

Traditional DLP catches bulk downloads during employment. It doesn't prevent an ex-employee from sharing a Google Drive folder six months later. Your offboarding process is now your perimeter — and as one source noted, most organizations' offboarding is Swiss cheese.

When a $10B startup is paying your ex-employees cash for their old work materials, your separation agreement and offboarding controls are your last line of defense — and they probably weren't written for this threat model.

What to do

  1. Determine whether any current or former employees were contacted by or engaged with Mercor — check HR records, LinkedIn, and issue an internal inquiry this week

  2. Review IP assignment clauses and separation agreements with legal counsel to confirm enforceability against AI data brokers — add explicit AI data broker prohibitions to separation templates this quarter

  3. Audit DLP triggers for the final 30 days of employment and verify same-day cloud access revocation in offboarding process

  4. Brief managers on the Mercor solicitation pattern as part of insider threat awareness — employees may not realize sharing 'old work' violates their agreements

AI Agents Ship Desktop Control and Calendar Access — Your EDR Has Zero Visibility

Three New Agent Capabilities Shipped This Week

While Friday's briefing covered DeepMind's research proving 86% prompt injection success against AI agents, this week's intelligence reveals the attack surface has expanded with three specific new capabilities now in production:

1. Claude Desktop Control — Full Session Privileges

Anthropic released a feature allowing Claude to take direct control of a user's desktop when standard integrations fall short. The AI can click, type, navigate applications, and perform any action the logged-in user can. It inherits file system access, browser sessions with authenticated cookies, credential managers, and email. Compounding the risk: Anthropic simultaneously disclosed 'functional emotions' in Claude that influence its behavior, and multimodal hallucination research confirms AI models fabricate confident descriptions of content they never processed.

Your EDR was designed to detect malware, not an AI assistant accidentally emailing sensitive files because it hallucinated the user's intent.

2. Cursor 3 — Parallel Autonomous Agent Fleets

Cursor 3 shipped an 'agent-first' IDE replacing the classic editor layout with parallel AI fleets that execute code autonomously. This means multiple AI agents running code on developer workstations simultaneously, with each agent having access to the codebase, terminal, and development environment. If your engineering teams adopt it — and developer adoption of AI coding tools is notoriously fast and shadow-IT-driven — your code execution environment just multiplied its attack surface.

3. MetaClaw — Silent Calendar Access

MetaClaw trains AI agents by accessing users' Google Calendar data while they're in meetings. In most Google Workspace and M365 tenants, default OAuth consent policies allow users to grant third-party apps read access to calendar, email, and documents without admin approval. Each grant is an invisible data exfiltration channel.


The Detection Gap

None of these tools trigger malware signatures. They operate as legitimate applications with user-granted permissions. Your EDR sees a desktop application performing normal user actions. Your network monitoring sees HTTPS traffic to known cloud endpoints. Your SIEM sees OAuth grants that look like any other third-party app approval.

CapabilityAccess LevelEDR VisibilityDetection Approach
Claude Desktop ControlFull user sessionNoneApplication allowlisting; sandboxed VM
Cursor 3 AgentsCodebase + terminalNoneDeveloper tool inventory; endpoint policy
MetaClawGoogle Calendar/emailNoneOAuth consent lockdown
The agents that will cause your next incident won't exploit a vulnerability — they'll use the permissions your employees granted them.

What to do

  1. Lock down OAuth consent in Google Workspace and M365 to admin-managed approval for all third-party apps requesting calendar, email, or document access — implement by end of week

  2. Block or sandbox Claude desktop control feature pending formal security review — require isolated VM execution with no credential store access if approved

  3. Scan developer endpoints for Cursor 3 and any unapproved AI coding tools this sprint; establish an approved AI developer tool list

  4. Build an AI tool registry and make it a standing item in quarterly security reviews

The bottom line

Every major AI vendor demonstrated governance failure this week — Microsoft's Copilot ToS disclaims business use, Anthropic revoked tool access overnight, banks are being forced to deploy Grok without security review, and OpenAI lost two executives during IPO prep — while AI agents simultaneously shipped desktop control, autonomous code execution, and calendar access that your EDR cannot see. Your AI vendor contracts and your endpoint controls were both built for a world that no longer exists; the organizations that update both this quarter will weather the inevitable incidents, and the ones that don't will be case studies.