Every AI Tool Your Firm Connects Is a Door You Have to Defend

Law firms are connecting AI tools to their systems faster than they're securing them. Recent attacks show why every integration needs the same scrutiny as a new employee with network access.

When your firm adds a new employee, there’s a process. You decide what systems they can access, what files they can see, what they’re allowed to do. Nobody hands a first-day associate the keys to every filing cabinet in the building.

AI tools don’t get that process. They get connected to email, document management, calendars, and client files, usually with whatever permissions the person installing them happens to have. Nobody asks “what’s the minimum access this tool needs?” It gets full access because that’s the fastest way to get it working.

That’s how firms end up with AI tools that can read every document in the system, send emails on behalf of attorneys, and access client data across every matter. Not because someone made a bad decision. Because nobody made a deliberate one.

AI tools are now targets

Two recent attacks show where this is heading.

Sysdig researchers documented what they believe is the first ransomware operation run entirely by an AI agent. They named it JadePuffer. The AI exploited a vulnerability in Langflow, an open-source tool for building AI workflows. From there, it harvested credentials, moved through internal systems, found a production database, and encrypted everything. When a step failed, the AI adjusted its approach and retried within 31 seconds.

The entry point wasn’t a phishing email or a stolen password. It was an AI tool connected to the internet with credentials stored on the same system.

Separately, the Djinn Stealer malware (discovered in late June) specifically searches for AI configuration files on infected machines. It’s looking for the credentials that AI tools use to connect to other services. One compromised workstation with an AI coding assistant can hand an attacker the keys to every system that assistant touches.

Both attacks happened in the past few weeks.

What this looks like in a law firm

Your firm probably has at least one AI tool connected to your systems right now. Copilot reads your email and documents. CoCounsel connects to your document management system. An AI notetaker sits in your meetings and accesses your calendar. Maybe someone installed a browser extension that “summarizes” web pages, and it’s quietly reading everything they view.

Each connection works the same way: the AI tool gets credentials or permissions that let it access your data. Those credentials are stored somewhere, on the user’s machine, in a configuration file, or in a cloud service.

If any of those storage points gets compromised, the attacker doesn’t just get the AI tool. They get everything the AI tool could reach. And because most AI tools get set up with broad permissions to “work better,” that’s usually a lot.

We covered a version of this with SearchLeak: a single vulnerability in Copilot exposed everything the user could access. That was one AI tool with one flaw. Most firms are now running several.

Why AI tools are different from your other software

Your billing system handles billing. Your email client handles email. If either one gets compromised, the damage is limited to what that system does.

AI tools are built to cross those boundaries. Copilot reads your email, your files, your calendar, your Teams chats, and your SharePoint sites. That’s the whole point. A legal AI assistant might connect to your DMS, your email, and your research databases at the same time. An AI notetaker accesses your calendar, joins your calls, and stores transcripts somewhere.

Every one of those connections is a path an attacker could use. And unlike your billing system, which has been around for 20 years and been hardened over time, many of these AI tools were built fast, shipped fast, and haven’t been through the kind of security testing that traditional enterprise software gets.

Questions to ask before connecting any AI tool

You don’t need to configure any of this yourself. But before your firm connects an AI tool to any system, someone should be asking:

What data can this tool actually access? Not what it needs. What it can reach. An AI tool might only need documents from one practice area, but the default configuration gives it the entire document management system.

Where are the credentials stored? If the tool uses API keys or tokens to connect to your systems, are those sitting on individual workstations where malware like Djinn Stealer could find them? Or are they in a managed, secured location?

What’s the blast radius if this tool gets compromised? If an attacker stole this tool’s credentials, what could they access? If the honest answer is “pretty much everything,” that’s worth reconsidering.

Who approved this, and is it written down? Your firm should have a list of every AI tool connected to firm systems: who approved it, what it can access, when it was last reviewed. If that list doesn’t exist, building one is the first step. (If you have an AI acceptable use policy, this should already be part of it.)

When was the last time someone checked? AI tools get connected and forgotten. The permissions granted six months ago may not make sense anymore. Quarterly reviews are the only way to keep the list honest.

Treat every AI connection like a new hire

Each AI tool your firm connects to its systems should get the same scrutiny you’d give a contractor with network access. What can they see? What can they do? What happens if their credentials are stolen?

The firms handling this well aren’t avoiding AI. They’re just asking those questions before they click “connect,” and checking back every few months to make sure the answers still hold.


Artech Solutions helps law firms and professional services firms in the Des Moines metro evaluate AI tools, configure them with appropriate access controls, and keep track of what’s connected to what. If your firm has been adding AI tools without a formal review process, we can help you build one.