What the commentary actually claims
Frost's central argument is that the threat now sits inside the perimeter, carried by employees, contractors and AI tools, and that this has become a business resilience problem rather than a purely technical one. He walks through several exposure points:
- Data: it lives on every laptop, server and reachable device, so every location is also a possible leak point.
- AI: the awareness worry has shifted from clicking a bad link to what an employee pastes into a chatbot.
- Shadow AI: staff use AI tools outside the company's security remit, which Frost says security teams were never built to monitor.
- Cloud and third parties: email in Microsoft 365 or Gmail, hosted CRM records and supplier relationships all sit outside the organisation's direct control. A compromised invoice or email can arrive through a trusted supplier.
- Identity, devices and physical access: executive details scraped from public profiles, devices that listen, a photographable visitor register, and an unattended USB port.
His answer is multi-layered defence, awareness, strict governance and policies, and AI used as a "persistent security guard". He also recommends working with specialists who understand your attack surface. That last point comes from a security consultancy, so read it as an author's perspective.
The piece's illustrative scenarios, such as the visitor register, the USB drive and the LinkedIn scraping, are plausible but not documented events. The word "exponential" in the headline is rhetorical, because no growth rate is supplied.
The PwC statistic, and how not to misquote it
Frost leans on PwC's Insider Risk: Client Survey Insights 2026, saying "0% of companies" feel prepared for AI-driven insider risk. PwC's own wording is narrower. PwC reports that 60% of organisations now recognise insider risk as important or critical, yet none feel very well prepared for AI-driven threats. That is a statement about "very well prepared", not about being prepared at all.
Other figures from the same PwC page:
- 33% reported an insider-related incident in the past 12 months, and many still rely on siloed, reactive approaches.
- 47% expect insider risk investment to increase over the next 12 months.
- 13% have no designated owner for insider risk, and 63% point to business functions as their primary risk area.
- PwC's five priorities are to build a proactive posture, enhance monitoring, strengthen ownership, reassess frameworks and increase AI preparedness.
The accessible PwC material gives no sample size, field dates or respondent geography. Treat these as client-survey findings, not a global estimate of all companies.
Independent corroboration on shadow AI
Other research points the same way. A Ponemon/DTEX study reported by Yahoo Finance found 73% of respondents worried that unauthorised AI use is creating invisible paths for data exfiltration, while just 18% had fully integrated AI governance into their insider-risk programmes. That study surveyed organisations in North America, EMEA and Asia-Pacific with headcounts of 500 to more than 75,000, over a two-month period ending in September 2025. Different surveys with different methods, but the same direction: awareness is running ahead of control.
Where Microsoft admins can act
Frost's "what do employees paste into a chatbot" worry is the part with the most concrete tooling behind it. Two Microsoft sources matter here.
Sanctioned AI: Copilot and enterprise data protection
Microsoft's Learn documentation says Microsoft 365 Copilot is now named Microsoft Copilot, and Microsoft 365 Copilot Chat is now Microsoft Copilot Chat. Some experiences and licences may keep the old names during the transition. The documentation states the following:
- Organisational use is covered by the Data Protection Addendum and Product Terms, with Microsoft acting as data processor.
- Prompts and responses are protected with encryption at rest and in transit, plus tenant data isolation.
- Copilot respects your identity model and permissions, inherits sensitivity labels, applies retention policies and supports audit of interactions. The specific controls vary by subscription plan.
- Prompts, responses and data accessed through Microsoft Graph are not used to train foundation models.
There are limits. Web queries sent to Bing have their own data-handling practices and sit under the Microsoft Services Agreement and Privacy Statement. The page also tells organisations using agents to check each agent's privacy statement and terms. None of this applies automatically to a consumer chatbot. That is exactly Frost's point about public models.
Unsanctioned AI: Edge for Business and Purview
Microsoft's Edge team described a control aimed squarely at shadow AI in a 23 March 2026 RSAC announcement. According to that post:
- AI prompts and file uploads to supported tools can be audited or blocked using inline data loss prevention powered by Purview.
- Prompts are analysed in real time, and sensitive data triggers an immediate audit or block.
- A blocked user sees a policy notice and a button that redirects the prompt to Microsoft 365 Copilot, where enterprise data protection applies.
- Protection applies on managed or unmanaged devices, provided the user is signed into Edge for Business with their Entra ID. Edge settings also stop users bypassing controls by switching browsers.
- Microsoft says prompt-level Purview protections are generally available, with licensing information published separately.
Caveats matter here. This is a vendor-described capability. It covers a list of supported AI tools, not every AI service an employee might find. It also depends on configuration, Entra sign-in and licensing. It reduces one route to leakage, and it does not close the whole category.
A practical checklist for IT teams
The commentary doesn't supply a program, so the following is general risk-management practice rather than anything Frost or PwC prescribes in these terms:
- Inventory the routes. List which identities, integrations, AI services, devices and vendors can touch sensitive data. You can't govern what you haven't listed.
- Name an owner. PwC's finding that 13% of respondents have no designated insider-risk owner makes this a cheap first step.
- Decide which AI is sanctioned. Provide a route employees will actually use, then check which policy controls cover that route, such as DLP, sensitivity labels and audit.
- Check the controls against your licences. Microsoft states that Copilot controls vary by plan, and the Edge labelled-content protections it describes require Microsoft 365 E5.
- Review third-party access. Treat contractor and vendor access as a first-class risk, with the same scrutiny as employee accounts.
- Don't forget the physical layer. Visitor logs, USB policy and unattended machines are low-tech, but they are still doors.
Analysis: useful frame, thin evidence
The strongest reading of Frost's piece is as a prompt for inventory and governance, not as proof of a measured explosion in attacks. The claim that everything is now external by default is directionally fair for cloud-heavy shops. It glosses over the fact that many controls, such as identity, labelling, conditional access and DLP, can follow data into those platforms.
PwC's survey adds a real signal: boards care, incidents occur, and AI readiness lags. Microsoft's documentation adds something Frost's piece lacks, which is specific controls with specific boundaries. The gap between the two is where an admin's work lies: choosing the doors that matter, then putting a lock on each.
References
- From two doors to a dozen: The exponential expansion of the enterprise attack surface - Lifestyle & Tech Lifestyle & Tech · 2026-10-08T09:07:10+00:00
- Insider Risk Costs Hit $19.5M USD Per Year as AI Creates New Blind Spots finance.yahoo.com
- Protect your enterprise from shadow AI and more: Announcements at RSAC 2026 - Microsoft Edge Blog blogs.windows.com