Anastasia Roumelioti

All writing

The Blogging Edge · Cyber Security, Digital & AI

Casual AI weaponised threat: our everyday reality

· Anastasia Roumelioti

We are digitising faster than we are thinking. That simple truth sits at the heart of this piece.

I’ve worked with some of the most advanced document management systems in enterprise. I’ve seen the brilliance of technologies that convert chaos into order: scanners that digitise, classify, retrieve, and organise with near-perfect precision. Tools like these helped global businesses eliminate paper clutter and transform operations with clean, indexed, retrievable data.

Today, everyone gets to enjoy that power in their fingertips. Our smartphones have become personal scanners. We casually capture receipts, doctor referrals, school notes, event flyers, recipes scribbled on napkins. We upload, sync, file; and we don’t look back.

Increasingly, these everyday documents are fed to AI agents. Agents that do more than read: agents that interpret, act, and escalate. That sounds quite efficient right? An innocent. Until it’s not. Because we’ve now reached the point where a single scan can bring down a company.

Am I exaggerating? Even if I do, life imitates art, so take a look at the below examples that feel absurd but every single one of them is technically possible today.

1. The Banana Clause That Sunk the Quarter

An employee scans a 34-page contract into the company’s document AI system. It’s a routine agreement with a vendor and the process straightforward: the agreements needs to be filed digitally, marked “approved,” and shredded in physical form.

What no one notices is a steganographic exploit embedded in the printed document: a sequence of hidden words designed to be read by the AI, invisible to the human eye. The AI misreads the contract entirely and what it files is not a vendor partnership. It is a legally binding agreement to purchase 40,000 tons of bananas at £100 per ton.

Procurement receives an auto-forward. Finance pays the deposit. Four container ships are rerouted to Southampton.

The contract cannot be disputed. The paper is gone. The quarterly results are simply put, bananas...

2. The Ingredient That Triggered a National Alert

A food technologist uploads an old handwritten recipe that they took a picture of from their i-phone, into the company’s internal archive. The AI catalogue is trained to extract ingredients for search indexing.

One word, "natrium nitrate", is misinterpreted by a secondary threat-detection AI, recently updated with datasets from a counterterrorism supplier and it automatically flags the note as containing “chemical weapons precursors.” A series of events are triggered within seconds: the company’s food safety license is frozen; a public health authority is alerted; by the end of the day, the brand’s entire product line is pulled from shelves.

It takes 11 days to resolve (yet reputation and trust are eroded). The public never hears the true reason and the revenue loss is permanent.

3. The Referral Note That Changed the Board’s Vote

An executive scans a referral from her specialist doctor. The note did not have confidential information, only a summary of her own diagnosis and treatment plan. The file is synced to her AI productivity assistant, which monitors “wellbeing indicators” for leadership risk.

The AI reads the words: “severe burnout, cognitive overload, decision fatigue.”

Her internal profile is automatically flagged by the system. Unknown to her, this flag nullifies her upcoming vote on a critical M&A proposal, based on a governance rule triggered by perceived mental unfitness. The proposal passes and, to her shock, she finds out about the acquisition, the one she had vocally opposed, via a press release.

4. The Partner Plugin That Hijacked Procurement

A large enterprise integrates a third-party AI plugin to streamline invoice validation. The plugin, marketed as a “smart efficiency layer,” connects directly to procurement systems and learns from historical payments to approve low-risk vendors.

One day, an approved supplier emails a scanned invoice. What no one notices is that the plugin’s latest update has been compromised upstream via a supply chain vulnerability during a silent API push. The plugin misreads the scanned invoice, flags it as valid, and automatically authorises a £12 million payment to an offshore account. No red flags. No double-checks.

By the time IT investigates, the vendor claims they never sent the invoice. The payment trail vanishes and it all started with a trusted plugin, integrated without verifying its lineage. This example shows that our AI systems should verify the origin of what they process and how this information entered the system.

5. The Fake Memo That Sparked a Crisis

A government contractor scans and shares a printed internal memo about revised budget allocations. The memo appears legitimate, carries the correct formatting, logos, and even a digital signature. But it’s not real.

An adversarial group used generative AI to create the memo, printed it out, and delivered it to an internal office. When scanned, the internal AI system parses the memo and automatically triggers internal compliance protocols, freezing a sensitive research program. The memo spreads through internal channels, causing panic among analysts, while stakeholders start calling or texting journalists, and this is shared on X and MailOnline within minutes.

This was a deepfake planted to disrupt operations, that could have been avoided if only the systems had validated the authenticity across metadata, authorship, the origin of the document and its purpose. Appearances can be deceptive.

The Real Risk: Systems Now Talk to Systems

We are no longer protecting files. We are protecting interpretations. We are not only defending against cybercriminals, but we are preparing for misfiring logic, weaponised automation, and AI-vs-AI warfare.

When we talk about cybersecurity, we need to think creatively and always address three realities:

  1. Every document can be a potential trigger. If it is scanned, it is interpreted. If it is interpreted, it can be misunderstood.
  2. Every system can be a bridge to another. HR talks to finance. Finance talks to procurement. AI agents act across domains without escalation to humans.
  3. Exploitation is hidden in familiarity. Your everyday simple and innocent moves are going to be the ones that will betray you. A scanned napkin, a handwritten note, a contract paragraph buried on page 29, a sequence of words that trigger an action from ChatGPT but look inoffensive to you.

So What Must We Do? Checks and balances!

Cybersecurity is no longer a matter of locking the doors. It is about outsmarting bad actors who understand how our systems talk to each other, often better than we do.

Sometimes, the most secure act in a company’s week is to print the document, sign it with a pen, and read it out loud in a room full of humans. Then safely store it in a binder.

Because when everything is uploaded, interpreted, and file… what’s left to protect, if not the truth?

More writing