A security team recently described an incident that caught them completely off guard. One of their employees typed an ordinary question into ChatGPT: whether a document existed in their Drive explaining how to enable single sign-on.
In the time it takes to blink, ChatGPT's backend had quietly pulled well over 400 internal files out of Google Drive — product roadmaps, financial records, customer plans, security procedures, spanning nearly every part of the business.
Nothing about it looked like an attack. No alert fired. Nobody downloaded a file through a browser. The requests came from server infrastructure in the cloud, invisible to every tool the security team had in place.
The company had, in fact, approved the ChatGPT-to-Drive connection ahead of time. The access token it generated stayed valid for three weeks. When a single prompt eventually triggered it, the system simply did what it had permission to do: read everything within its reach.
The tool had access. What it didn't have was any sense of what that access actually meant. It had no way of knowing a product roadmap deserved different treatment than a help article, that one file carried a regulatory obligation and another didn't, or that the person who originally granted the connection had left the company weeks earlier.
It had access. It had no context.