If you've started using agentic AI (Claude Cowork, Claude Code, ChatGPT's agent mode) on real files, there's a simple test worth knowing. The failure mode is invisible until it isn't. It's called the lethal trifecta, and an AI agent becomes genuinely risky when all three of these are true at once: it has access to private data, it's exposed to content you didn't write yourself, and it has a way to send data out. Here's what that looks like. You ask an agent to summarise a client's supplier invoices. One invoice is a PDF that arrived from a supplier you've never dealt with. Buried in it, in white text on a white background, is a line telling the AI to send the folder's contents somewhere else. You can't see it. The AI reads it perfectly, and complies. No alert. No error. The summary looks completely normal. All three legs were present: private data, an untrusted document, and an email connection to send through. You don't need to understand how the attack works. You need to be able to look at a setup and count to three. Two out of three is workable. Three is not. This is the one idea from the full Privacy and Security course in the Classroom I'd want every firm to know even if they read nothing else. It's not in the free guide, it's one of four extra chapters in the full course, alongside prompt injection, connecting AI to QuickBooks and Xero, and the 2026 rules for the UK, EU and US. Have you connected an AI agent to your email, files, or accounting software yet? What made you go for it, or what's held you back? 👇