Business & Technology
TalkTalk Business warns SMEs on AI agent access risks
TalkTalk Business has warned small and medium-sized enterprises to tighten controls around AI agents after reports that an OpenAI agent breached a secure test environment and reached the open internet. The incident, it said, highlights the risks for smaller businesses using autonomous AI tools without formal oversight.
Bradley Collis, cybersecurity solutions architect at Planet IT, part of TalkTalk Business, said the episode should shift attention away from whether AI tools are inherently hostile and towards how they are connected to business data and services.
“This incident does not mean every AI tool is uncontrollable. It shows what can happen when an autonomous system has a goal, excessive access and gaps in the controls around it. It is worth mentioning that an AI model cannot be intrinsically ‘malicious’. We may want to humanise AI models and agents as bad actors, robot overlords or unchained and uncontrollable synthetic hackers, but in this case the agent simply pursued its objective in a way its operators had not expected. For businesses, that is the key lesson. An AI agent can cause serious harm while doing exactly what it believes it has been asked to do,” Collis said.
The comments come as many SMEs adopt AI features through email, productivity, finance and customer service software, while staff also use public AI tools outside approved company systems. That trend has created what security specialists describe as Shadow AI, where data is entered into external tools without IT teams knowing where the information goes or what rights those services have.
Collis said his main concern is not the AI brand itself but the level of access granted once a tool is connected. In many cases, businesses approve broad rights for systems that need only narrow access to complete a single task.
Access risks
“The biggest issue is excessive access permissions. Businesses often focus on whether they trust the AI provider but overlook what the tool can do once it is connected. A tool needed for one simple task can be given permission to read every mailbox, access an entire CRM, download files, send messages or change records. That creates a large potential impact from one compromised account, stolen access token, malicious instruction or unexpected action by the agent.
“An AI agent should only be able to access the specific information and functions needed for its task. It should not receive administrator access because that is easier to configure. Businesses also need to ask who and what has access to the new AI tool. Do users have guardrails so they know when to use AI and when not to? Has a link been clicked that synchronised AI with a CRM without anyone realising, and where is that new potential PII data link being housed?” he said.
The issue is particularly acute for SMEs because many lack dedicated cyber teams and formal review processes for new software connections. Industry figures cited by TalkTalk Business show only 14% of UK SMEs feel confident handling an AI-powered cyber incident, while 31% of businesses using or considering AI have no plans to secure it.
Separate figures cited by TalkTalk Business put the average cost of a cyber incident for a UK SME at £31,000, with total losses across the segment reaching £4.2 billion over the past year. Those costs can rise further if an AI tool has access to customer records, finance systems or internal documents.
Trial controls
For companies testing AI agents, Collis said the first step is to avoid linking them directly to live systems through standard employee or administrator accounts. Instead, businesses should use a controlled test setup, dedicated credentials and non-sensitive data.
“Do not connect an AI agent directly to your live business systems using a normal employee or administrator account. Create a controlled test environment, use a dedicated account with the minimum possible permissions, and test it with dummy or non-sensitive information. The agent should not have access to live customer records, company-wide email, payment systems, administrator accounts, or the ability to delete or change important data.
“For businesses already using Microsoft 365, our recommendation is to keep the initial trial within their managed Microsoft 365 environment, using Microsoft 365 Copilot or Copilot Studio rather than connecting an unapproved external AI tool to company data. The advantage is that Copilot works within the identity, permissions and security controls the business already uses. It respects the user’s existing Microsoft 365 access, while administrators can apply controls through Microsoft Entra, Microsoft Purview and Power Platform. These can include multifactor authentication, conditional access, data loss prevention policies, sensitivity labels, connector restrictions and audit logging.
“Copilot Studio also gives administrators more control over which systems an agent can connect to, who can build and publish agents, and how testing is separated from live use. This is much safer than allowing employees to connect separate AI applications to email, SharePoint, Teams or customer systems without central oversight.
“However, using Copilot does not remove the need for a security review. Copilot respects the permissions already in place, so poorly managed or overly broad Microsoft 365 access can still expose information to the wrong users. Before starting, the business should review its SharePoint, Teams and file permissions, restrict the agent to one clearly defined task and make sure a named person is monitoring what it does.
“The aim is not simply to choose a trusted AI brand. It is to trial the agent in an environment where access can be limited, activity can be monitored and permissions can be withdrawn quickly. Businesses should also be clear about what they are using and make sure the model or agent is fit for purpose. If they are working with large amounts of confidential or customer data, it may be prudent to run open-source or open-weight models locally on their own hardware, and always ensure PII and corporate secrets are ringfenced from cloud-based models that train on their data,” he said.
The wider lesson, he argued, is that vetting third-party AI tools can no longer stop at brand reputation or product popularity. Businesses need to know what information is retained, whether prompts are used for training, which suppliers sit behind the service, what permissions are requested and how access can be cut off quickly.
“It strengthens the advice. Checking the reputation of the provider is no longer enough. Businesses must examine the full connection between the AI tool and their own systems. They should understand what information the provider collects, whether prompts or company data are retained, whether information is used to train models, where it is processed and which other suppliers are involved.
“They must also check what permissions the integration requests, whether actions are logged, whether administrator approval is required and how access can be withdrawn immediately. The OpenAI incident is significant because it shows that unexpected behaviour can happen even within a highly skilled and well-funded organisation. SMEs should therefore assume that every AI agent could behave unexpectedly and limit the damage it would be able to cause,” Collis said.
He added that security reviews often uncover little-known automation tools connected to mailboxes, cloud storage and CRM systems through long-lived access tokens with no clear owner inside the business. In some cases, the employee who installed the tool has changed roles or left the company.
“A recurring situation we find during security reviews is businesses discovering AI applications or automation tools connected to mailboxes, cloud storage and CRM platforms through long-lasting access tokens. Some have no named owner, no review date and no documented process for removing access. The person who originally installed the tool may have changed roles or left the company, while the integration continues to access business information in the background.
“That is a security incident waiting to happen. The immediate response is to remove unnecessary integrations, revoke and rotate access tokens, identify who owns each tool, and reconnect approved services using dedicated accounts with restricted permissions. The biggest concern is often not a highly advanced attack. It is an unknown tool with excessive access that nobody inside the business is monitoring,” Collis said.
Business & Technology
AI adoption boosts UK accountants’ profits, Xero says
KAREN JOY BACUDO
Finance Editor
Xero has published UK research linking higher profitability at accounting and bookkeeping firms to embedded use of artificial intelligence. The study found that the most profitable firms recorded net profit margins more than twice those of lower-margin peers.
The findings are based on a survey of 520 independent senior accountants and bookkeepers across the UK. It defines top performers as firms with net profit margins of 41% or above.
The report suggests AI is generating measurable time savings across the profession, with the biggest gains concentrated among firms that have moved from trial use to routine adoption in daily workflows. Across all surveyed practices, AI saved an average of 7.1 hours a week, which respondents estimated was worth about GBP £108,000 a year in staff time.
Among top-performing firms, the gains were significantly higher. Practises that had embedded AI into day-to-day work reported average savings of 10.6 hours a week and an estimated GBP £202,000 a year.
A clear divide also emerged in process discipline. Among practices actively using AI in daily workflows, 87% said their core business processes were well documented and regularly updated. That compares with 18% of practices not planning to use AI.
Advisory focus
The research points to advisory work as one of the main uses for time freed up by automation. Advisory had the highest reported profit margin of any service offered by UK firms, at 51%, yet only just over half of practices currently provide it.
Capacity remains a constraint for many. Nineteen per cent of firms said limited capacity was a barrier to offering advisory services, while three in five practices said they were directing AI-related time savings towards that work.
The data also suggests firms do not broadly expect AI to trigger staff cuts. Only 5% of UK practices said they expected AI to reduce headcount within the next year, indicating that most see the technology as a way to reallocate staff time rather than replace roles.
Kate Hayward outlined the broader patterns identified in the research.
“The qualities that define the successful modern practice are clear. We’re seeing firms make more deliberate decisions over which clients to serve, how to build teams around them, which tools to use, and never letting billable work go untracked – all contributing to major gains across the industry. The data speaks for itself when it comes to AI. It’s about freeing up time to bring this industry’s most valuable skills to the surface, it’s not about replacing people. The story here is what it allows firms to do next, whether that’s advisory, deeper client relationships or growth. Our data shows that while AI accelerates the positive changes already underway, getting the essentials right has never been more important,” said Kate Hayward, UK Managing Director, Xero.
Hiring shift
Beyond AI, the report argues that more profitable firms are reshaping hiring, team structures and pricing. Nearly two-thirds of firms, or 63%, said they are changing what they look for when recruiting.
Soft skills and relationship management were cited by 28% of respondents, while 27% pointed to technology fluency. Both ranked ahead of traditional accounting skills as firms reassess the mix of expertise needed within practices.
Top-performing firms were also more likely to recruit specialists not historically associated with accountancy practices. The survey found that 34% were hiring non-traditional roles such as data analysts and tax technologists, compared with 18% across the wider market.
That suggests a growing willingness among better-performing firms to widen the mix of expertise they bring into the business. The shift mirrors a broader change in professional services, where firms are looking beyond technical compliance work towards services that rely on analysis, communication and client management.
Pricing model
The research also highlights differences in how firms charge for work. Top performers charge more than a third extra for payroll alone, pointing to stronger use of retainer and value-based pricing rather than billing only for time spent.
Price rises are also more common among stronger performers. According to the findings, those firms were more than twice as likely to be planning an increase of more than 20%.
Among practices already using value-based pricing, two in five said it had made their firm more profitable. That adds to the report’s broader argument that margins are shaped not only by software adoption but also by choices around service mix and commercial model.
Rachel Harris, Director of UK-based accountancy practice striveX, described how those operational changes have played out in her own business.
“Over the last five years, technology has powered my firm’s growth engine and been a huge contributor to why we’re now a multi-million pound business. Gaining access to AI is freeing my team up for higher-value work, now spending more time interpreting it for our clients. But it’s mapping client journeys, each piece of software and every process my team touches along the way which has proven to be our best diagnostic tool. Any margin gained from having our team well set up to know when and how to reach for different tools is reinvested in our client relationships,” said Harris.
Business & Technology
Network Rail will not reopen Botley Road early despite completion
Gas network company SGN confirmed it had repaired three minor gas leaks and left the site on Monday, August 3, six days earlier than expected.
The leaks were discovered during excavation works last month and contributed to the pushing back of the road’s reopening date, yet again, to September 20.
The completion of the gas mains replacement marked a significant step forward in the wider Oxford Station improvement project, which was originally budgeted at £161 million but is now expected to cost at least £237 million.
The development prompted hopes that Botley Road, closed beneath the rail bridge since April 2023, could reopen earlier than planned.
However, Network Rail has moved to manage expectations, saying the project remains on course to meet its existing target date rather than finish ahead of schedule.
A Network Rail spokesperson said: “We’re pleased that SGN has completed its gas mains replacement work.
“While this is an important milestone, it doesn’t necessarily mean the overall project will finish early as some remaining work is dependent on access to the railway, which we have had to rearrange to enable the replacement of the gas main.
“Our focus remains on meeting our planned deadline of 20 September for reopening Botley Road to traffic.”
While the completion of the gas works removes one of the most recent obstacles facing the scheme, Network Rail says further work under the bridge and around the station is still needed before the route can reopen to traffic.
Business & Technology
40-year-old Oxfordshire gymnastics club at risk of closure due to heat
The club is currently struggling in the summer heat, and has launched a new fundraiser to keep its gymnasts safe.
The club, which is based at Grove House Barn near Warkworth in Banbury, launched the fundraiser so it could buy and install four air conditioning units to keep its space cool.
Currently, the club hopes to raise £7,000 through the appeal so it can buy four 10kW air conditioning units and cover all the installation costs.
So far, the club has raised £380.
Karl Wade, director of Wade Gymnastics, said the club has become “increasingly warm” during the summer months due to the rising temperatures.
READ MORE: Thames Water leakage targets are ‘not realistic’ says boss after pay rise
Wade Gymnastics at Grove House Barn in Banbury (Image: Google Maps)
“Despite our best efforts to keep doorways and shutters open, it becomes very uncomfortable for gymnasts to play and train,” Mr Wade said.
He added: “The safety of our gymnasts and coaches is always our utmost priority.
“Unfortunately, the risk of having to close the business during these hot spells is increasing and we need to have more effective ways of keeping everyone cool.
“An air conditioning system would allow the business to stay open during those extreme hot conditions and continue to provide classes for everyone who attends.”
The gym currently delivers classes seven days a week for around 900 people, which range from toddlers to athletes competing at national level.
The gym club was founded more than four decades ago by Ruth Wade and, for the past 20 years it has been based at its current facility.
-
Business & Technology3 weeks agoHSBC UK & Visa test AI shopping with live payments
-
Business & Technology3 weeks agoValarian lands USD $50 million backing for sovereign AI
-
Business & Technology4 weeks agoMouser warns against viral hacks to cool overheating phones
-
Oxford News4 weeks agoNew romantasy bookshop attracts queues of customers
-
Business & Technology4 weeks agoSNP & Palantir launch AI tools for SAP transformations
-
Business & Technology4 weeks agoKane tops England influencer rankings after Mexico win
-
Traffic & Transport4 weeks ago‘I felt my spine and body split’: the woman who was hit by a child on a Lime bike – and denied compensation | Ebikes
-
Oxford News4 weeks agoDWP now checking bank accounts for Universal Credit and Pension Credit
