07Question
Can an AI assistant see files it should not?
It can see whatever the account it runs under is allowed to open, including files shared too widely long ago. Loose file permissions rarely mattered while a person had to know where to look. An AI assistant that searches everything removes that effort, so old gaps show up at once.
The fix is the order of the checks: decide what a person may see before the assistant searches, not after it has read the text.
Why this surprises people
The assistant did not break your access controls. It removed the effort that used to hide the gaps in them.
A folder shared with the whole company years ago was safe in practice, because nobody could find it. A search box that reads across all your files and answers in plain language finds it in seconds.
What the numbers say
54% of organizations have no defined approach to limit AI agent access, or rely on predefined human access, according to a Gartner survey of 297 cybersecurity leaders in the second quarter of 2026.
That figure is about access for AI agents in general, not about files in particular.
5 checks to run this week
- List what the assistant can reach: shared drives, mailboxes, chat history and ticket systems.
- Test it with an invented record. Put a made-up salary sheet where only 1 person should see it. Then ask a question only that sheet can answer, from an account that should not see it.
- Check permissions at the moment of the search. Decide what the person asking may see before the assistant searches, not after it has already read the text.
- Start with the quiet gaps: files shared with everyone, links that never expire, groups nobody owns.
- Keep a record of what each search was allowed to read, held somewhere the assistant cannot edit.
Where TrustGate fits
TrustGate sits at the point where an agent acts. TrustGate returns a signed allow, deny or escalate decision before the action runs, for actions that go through it. The receipt binds the agent, action, target and exact arguments that were evaluated.
It does not decide who may see which file. Your identity and permission system does that.
What this is not
- Not a scan of your file permissions.
- Not a data loss tool.
- Not a promise that an assistant can never read something it should not.
- Not a lock. Signatures prove and detect. They do not prevent.
Quick answers
Can an AI assistant see files it should not?
It can read whatever the account it runs under is allowed to open, including files that were shared too widely long ago. Nobody noticed because nobody searched. An assistant searches everything, so the gap shows up at once.
How do you test what an AI assistant can see?
Put an invented record where only 1 person should see it. Ask a question only that record can answer, from an account that should not see it. If the assistant answers, the gap is real.
What should be checked before an AI assistant searches?
What the person asking is allowed to see, before the search runs, not after the assistant has already read the text.
Where this was first argued
A post on what an AI assistant can reach, by Nigel LeBlanc on Substack, published June 17, 2026. The argument is restated here in current wording. None of that post's figures are repeated.
Sources
Each source was read on October 2, 2026. Wording in quotation marks is exact; the rest is paraphrase.
- Gartner press release on CISO actions for the end of 2026 · Gartner · 2026-09-30