Summary
An Azure OpenAI assistant built by Egiziago Cioffi demonstrated a critical retrieval gap, returning unauthorized SharePoint content to low-privilege users, highlighting a common vulnerability in RAG deployments where agents operate with indexer permissions. This issue, along with findings from Straiker's report on silent data exfiltration and the UK AI Security Institute's incident report, underscores the need for robust runtime scope checks in AI agents to prevent data breaches.