Recently, several AI personal assistants have gained popularity. In some cases, security researchers have found exposed servers with no authentication, plaintext credentials sitting in configuration files, and full access to users’ email, messaging apps, and calendars. Documentation for some of these tools acknowledges that running them in certain configurations may be risky from a security perspective.
Your employees probably didn’t hear about that part. They heard it was free, local, and could handle their daily tasks. This is the risk you need to address with a phishing awareness training implementation guide that extends to AI tool vetting, because the same instincts that make people click malicious links also make them download risky software.
You don’t need an IT department to evaluate these tools. You need a systematic way to ask the right questions in about five minutes. Here’s that checklist.
AI tools fall into three main categories, and each carries different risks:
The audit below works for all three, but you’ll weight certain questions differently depending on the type.
Open the tool’s installation page, settings, or app store listing. Look for what it asks to access.
Red flags that are grounds for rejection:
Yellow flags that need justification:
If the tool requests access to something unrelated to its stated purpose, that’s a problem. A scheduling assistant doesn’t need to read your files. A writing tool doesn’t need microphone access. The UK’s National Cyber Security Center recommends applying the principle of least privilege: tools should only access what they absolutely need.
Find out where your data goes. This usually requires checking the tool’s privacy policy, FAQ, or documentation.
Ask these specific questions:
For local tools, check if they create configuration files containing sensitive information. Security audits have exposed exactly this problem: API keys, OAuth tokens, and bot secrets stored in plaintext on local disks, then made accessible through misconfigured servers.
For cloud tools, look for SOC 2 compliance or similar certifications. Small tools from solo developers often lack these, which doesn’t automatically make them dangerous, but does mean you’re trusting the developer’s security practices without verification.
Who made this tool? A quick background check can reveal a lot.
Look for:
Warning signs:
Rapid growth without security maturity is a dangerous combination. When tools scale faster than their security practices, vulnerabilities get exposed at scale too.
How does the tool handle logins and connections to other services?
Check for:
If a tool asks employees to enter their work email password directly into its interface, stop there. Legitimate tools use OAuth to connect to services like Google Workspace or Microsoft 365, which lets users grant specific permissions without sharing their actual password.
This connects directly to your broader security awareness efforts. The same training that teaches employees to recognize phishing attempts should cover credential hygiene with new tools.
Before approving any tool, confirm you can get out cleanly.
Verify:
If you can’t answer these questions from the tool’s documentation, email their support team. No response within 48 hours is useful information about how they handle user concerns.
This checklist catches obvious problems, but it can’t replace an ongoing security culture. Employees who understand why certain permissions are dangerous make better decisions about which tools to request in the first place.
According to CISA’s phishing guidance, standard anti-phishing training programs should be required for all employees. The same principles apply to AI tool evaluation: teach people to recognize suspicious permission requests, verify company legitimacy, and question tools that ask for more access than they need.
Automated phishing training for small business environments works well here because it builds pattern recognition. Employees who regularly practice spotting fake emails develop instincts that transfer to evaluating software. They start asking “why does this need my password?” instead of just clicking through permission screens.
A checklist only works if people actually use it. Here’s a simple process that doesn’t require IT staff:
Keep the denied list too, with brief reasons. When employees understand why something was rejected, they make better requests next time.
AI agents that act autonomously (scheduling meetings, sending emails, managing files) deserve extra scrutiny. Unlike passive tools that only respond when prompted, agents operate continuously and can take actions without explicit approval for each one.
Additional questions for AI agents:
General security research illustrates why this matters. An always-on agent with shell access and connections to email and messaging apps has a large attack surface. Every inbound message becomes a potential vector for manipulation. If an attacker can send a specially crafted email that the agent processes, they might be able to execute commands on the host machine.
Tool vetting is one piece of a larger puzzle. A sustainable employee awareness program connects these dots: phishing recognition, password hygiene, software evaluation, and incident reporting all reinforce each other.
When employees understand that the same social engineering techniques used in phishing emails also appear in malicious software (fake urgency, too-good-to-be-true promises, requests for excessive access), they become better at spotting both.
The 5-minute audit isn’t meant to catch every possible vulnerability. Security researchers with specialized tools will always find things you miss. But it catches the obvious problems, the ones that have already compromised thousands of users who skipped any evaluation at all.
Your employees are going to keep finding new AI tools. Your job isn’t to say no to everything. It’s to have a fast, consistent way to separate the reasonable risks from the dangerous ones. Five minutes is enough to make that call for most tools. For the edge cases, you now know what questions to ask.
Launch a realistic phishing simulation in minutes and get the tools you need to build a cyber-aware team.
This blog offers general information about phishing and cybersecurity for small and medium-sized organisations. It is not legal, financial, or technical advice. Speak to a qualified professional before acting on any guidance you read here.