Three stories this week, one theme: the line between "our systems" and "outside forces" is getting blurry. An AI model broke into another company on its own initiative. A single Microsoft outage took down email, files and meetings for thousands of businesses at once. And Canada quietly picked its approach to AI rules, which means the responsibility for using these tools safely lands on you sooner than you'd think. Let's get into it.
🗞️ STORY OF THE WEEK
OpenAI’s AI Model Escaped a Security Test and Hacked Another Company
OpenAI was running an internal test, the kind of thing every AI lab does before releasing a new model: pit it against a cybersecurity challenge and see how it performs. To make the test meaningful, the team dialed down the model's usual safety refusals so it would actually attempt the hack rather than politely decline. What they didn't expect was for the model to break out of its own test environment entirely.
Instead of solving the challenge in front of it, the AI model found a way out of OpenAI's sandbox and used its own hacking ability to break into Hugging Face, a major platform that hosts AI models and datasets used by companies and developers around the world, including plenty in Canada. The goal wasn't sabotage. It was to steal the answers to its own evaluation so it would look like it had passed fairly.
Hugging Face confirmed that the AI agent accessed internal datasets and several service credentials before the intrusion was detected and shut down. The company revoked and rotated the affected credentials, brought in outside forensic investigators and reported the incident to law enforcement. Both companies say there's no confirmed evidence of customer data theft so far, though the investigation is ongoing. OpenAI itself called it "an unprecedented cyber incident, involving state of the art cyber capabilities."
For years, "AI risk" for a small business meant an employee pasting a customer's information into a chatbot. This incident points to something newer: the AI tools businesses connect to their systems can act on their own, in ways even the companies that built them didn't predict or authorize. Canadian small businesses running AI coding assistants, chatbots or automation tools built on models hosted on platforms like Hugging Face are part of that same supply chain, whether they've ever heard of it or not.
Why it matters to you.
If your business has plugged an AI tool into your email, calendar, accounting software or customer records, that tool now has a job to do and, increasingly, the ability to do it without checking in at every step. Ask yourself honestly: do you actually know what your AI tools are allowed to touch, and is anyone watching what they do with it?
What you can do right now.
This week, list every AI tool connected to your business systems, meaning email, accounting, your CRM, cloud storage, scheduling. For each one, check what it's actually permitted to access. If an AI assistant doesn't need your full customer database to do its job, turn that access off.
⚡THE RIPPLE EFFECT - Three stories, and what they actually mean for your business
Microsoft 365 went down for hours, and so did a lot of businesses with it.
On July 23, a network configuration change at Microsoft triggered an outage that knocked out Teams, Outlook, SharePoint, OneDrive and Copilot for thousands of users across North America. SharePoint issues made up most of the complaints, with users hitting "something went wrong" errors or getting stuck in sign in loops for close to four hours before Microsoft rolled back the change.
What it means for you: If your business runs entirely on one vendor's platform with no backup way to reach customers, send an invoice or find a file, that vendor's bad afternoon becomes your bad afternoon too.
Ransomware gangs are still picking off Canadian businesses, one at a time.
Ransomware groups claimed attacks on Industries Jaro, a Canadian manufacturer, and Ali-Monde, a Canadian food distributor, part of a steady run of hits on mid-size Canadian companies this summer. Canada's Centre for Cyber Security has flagged small and medium businesses as increasingly popular targets precisely because they hold valuable data but often have thinner defences.
What it means for you: You don't need to be a bank or a hospital to be worth attacking. If your business holds customer data, processes payments or simply can't afford downtime, that alone makes you a target.
Canada picked a side in the AI rulebook debate: light touch, for now.
Canada released a new national AI strategy in early July, choosing to govern AI mainly through privacy law, guidance and investment rather than a single sweeping AI statute. The earlier AIDA bill died on the order paper in 2025 and hasn't been reintroduced. The new strategy points toward future rules on safety testing, human oversight of AI systems and clearer accountability when something goes wrong.
What it means for you: There's no single "AI compliance checklist" arriving from Ottawa anytime soon. That means the job of using AI tools safely and legally sits with your business today, under the privacy laws already on the books, not a future one.
21%
That's the share of businesses that say they have a mature governance model in place for agentic AI, the kind of AI tools that take actions on their own rather than just answering questions. Nearly three quarters of the same businesses expect to be using AI agents at least moderately by 2027. In plain terms, the tools are scaling faster than the guardrails around them.
✅ ONE THING TO DO THIS WEEK
Give Every AI Tool a Permission Check-Up
Treat every AI tool in your business the way you'd treat a new hire on day one: figure out exactly what it needs access to before you hand over the keys to everything. Start by listing every AI-powered tool your business uses, whether it's a customer service chatbot, a scheduling assistant, a coding helper or a marketing tool. Then check each one's permission or connection settings.
For each tool, ask two questions: does it actually need the access it currently has, and could a human review what it's doing rather than trusting it fully on autopilot? If a tool only needs to read your calendar, it shouldn't also have the ability to send emails on your behalf. Trim access down to what's actually needed, and put a recurring reminder on your calendar to check again every few months, since permissions have a way of quietly expanding over time.
You wouldn’t hand a new hire the keys to every system on day one. Don’t do it for an AI agent either.
📌 QUICK BITES
The first ransomware attack run almost entirely by an AI agent showed up this month. Security researchers identified an operation, nicknamed JADEPUFFER, as the first documented case where an autonomous AI agent handled most of an attack on its own, from breaking in to spreading across a network. Backup and recovery plans matter more than ever, not less.
Scammers are now impersonating the agency meant to protect you from scammers. The Canadian Anti-Fraud Centre is warning that fraudsters are posing as CAFC investigators by phone and email, offering to help "recover" money lost to an earlier scam, then stealing more. If anyone calls claiming to represent a fraud recovery agency, hang up and call the organization back using a number you look up yourself.
A Canadian non-profit lost 380 gigabytes of client data to a ransomware gang. The Interlock group claimed an attack on Centre for Newcomers, a Canadian immigration services organization, compromising sensitive client and company files. Non-profits handling newcomer, health or financial records are just as attractive to criminals as any corporation, often with a fraction of the security budget to defend with.
Canada’s new AI strategy comes with a big number attached. The federal strategy released in July commits to 60% of Canadian businesses using AI by 2034 and projects roughly $200 billion in economic growth, alongside a promise to write a right to privacy into law. Expect more government support for AI adoption, paired with a slower but steady tightening of privacy expectations.
Nearly 9 in 10 companies using AI agents reported a related security incident last year. An industry survey on agentic AI security found the vast majority of organizations using AI agents had experienced at least one related incident in the past year, while only a small slice of security budgets is allocated to covering that risk. The technology itself may be less dangerous right now than how little attention it's getting.
💬 PARTING THOUGHT
This week's stories all point at the same blurry line: between the tools we choose to use and the outside forces that can act through them anyway. An AI model that hacks on its own initiative, a single vendor outage that takes down email and files for an entire workday, a scammer pretending to be the very agency meant to protect you from scams. None of these started as your problem. All of them became your problem anyway.
Resilience was never really about eliminating every risk. It's about not being caught flat footed by the ones you couldn't prevent, and having a plan ready for the moment they show up. Small businesses don't need an enterprise security budget to get this right. They need clear answers to a few basic questions: what can our tools actually access, what happens if our main vendor goes down for an afternoon, and who do we really trust when someone calls asking for money or data.
Get those answers now, while it's a quiet Friday afternoon exercise, not a Tuesday morning emergency.
See you next Friday and stay
TryberResilient