WHITE PAPER: The Questions You Ask Are The Attack Surface
The Questions You Ask Are The Attack Surface
How AI Inference Turns Innocent Queries Into Organisational Intelligence
CyberCQR Threat Intelligence | April 2026 | 12 minutes reading time
The Insight That Changes Everything
Your employees believe that because they are not pasting company data directly into AI tools, they are being careful. They are wrong. The questions they ask, the problems they frame, and the solutions they seek reveal more about your organisation than any document they could have copied and pasted. And someone may be watching every single one of them.
What Is Inference, And Why Should Boards Care?
In intelligence tradecraft, inference is the practice of deriving conclusions from fragments of information that, individually, seem harmless. A single puzzle piece tells you nothing. But assemble enough of them and the picture becomes clear. This principle has shaped espionage for centuries. It now applies, at industrial scale and machine speed, to every interaction your workforce has with AI platforms.
The threat is not the employee who pastes source code into ChatGPT—though that happens too, as Samsung discovered to its cost. The more subtle, more pervasive, and arguably more dangerous threat is the one hiding in plain sight: the cumulative portrait of your organisation assembled from thousands of ordinary queries from ordinary employees just trying to do their jobs better.
Boards that dismiss this as a theoretical risk should consider the following scenario before reading further.
A Constructed Scenario: Six Months, No Data Breach
Imagine a mid-market financial services firm. No data breach has occurred. No source code has been leaked. Yet over six months, their employees have used public AI tools for the following:
- A procurement manager asks for help drafting supplier contract clauses—revealing which systems are being replaced
- An HR director asks for help framing a redundancy communication—signalling a restructuring
- A strategy analyst asks for help modelling a market entry scenario for a named geography
- A CISO asks for help building a business case for a specific security product—revealing current gaps
- A CFO’s PA asks for help formatting board pack numbers related to a named acquisition target
No single query is alarming. Aggregated, they paint a detailed picture of strategic intent, security posture, organisational stress, and competitive positioning. A sophisticated attacker—or a hostile state actor—would pay significantly for that picture.
This Is Not New. Your Supermarket Already Does It.
Before exploring the AI-specific threat, it is worth grounding it in something your board members understand instinctively: commercial data inference. Because the techniques are identical. Only the target has changed.
The Loyalty Card Revelation
When Tesco launched the Clubcard in 1995, it was not offering customers a discount scheme. It was acquiring a surveillance apparatus. The economist Clive Humby, who designed it, described what happened when Tesco first analysed the data: the supermarket’s CEO told him it was like a “bomb going off.” They had not known their customers at all.
A loyalty card captures what you buy. But what the algorithms infer from that is qualitatively different. A well-known example: retailers can identify pregnancy in customers who have not disclosed it, based on changes in purchasing patterns—switching from scented to unscented products, buying certain vitamins, adjusting food choices—weeks before any public announcement. The US retailer Target famously sent pregnancy-related coupons to a teenager before her father knew she was pregnant. The data was never wrong. It was just drawing conclusions the customer did not know she had shared.
Google and Facebook operate on an identical model, simply applied to digital behaviour. The product you search, the articles you linger on, the ads you ignore—none of these individually identify you as a prospect for anything. Collectively, they build a predictive model of your intentions with striking accuracy. A user does not have to click on a cancer charity advertisement for Google to infer health anxiety. Prolonged engagement with health articles, searches with specific symptom terms, and changed purchasing patterns are enough.
The parallel to AI is direct: an employee does not need to paste a strategy document into an AI tool for their queries to reveal strategic intent. The shape of the questions is the document.
When The Obvious Leak Is Not The Real One: The Samsung Case
In March 2023, Samsung’s semiconductor division lifted an internal ban on ChatGPT. Within three weeks, three separate incidents had occurred. One engineer pasted proprietary source code into ChatGPT to debug it. Another submitted code for yield and defect measurement. A third recorded an internal meeting, transcribed it, and sent the transcription for summarisation.
Samsung banned generative AI tools company-wide within weeks and began developing an internal AI platform. JPMorgan, Apple, Amazon, Verizon, and Deutsche Bank followed with similar restrictions.
The Samsung incident is important. But the security community’s focus on it may have inadvertently miseducated boards. The lesson absorbed by most organisations was: do not paste sensitive files into AI tools. That lesson, while correct, addresses only the most visible manifestation of a much larger problem.
What Samsung’s Employees Were Really Revealing
Consider what an analyst with access to Samsung employees’ query logs—not the content they pasted, but the type of questions they were asking—could have inferred:
- Which teams were under production pressure (debugging at scale)
- That yield management was a current operational concern
- That internal documentation practices were being reviewed (meeting minutes)
- The rough shape of the engineering organisation based on query volume patterns across roles
- The type of fabrication challenges being experienced, inferable from the nature of the debugging requests
None of this required access to the source code itself. The questions alone were intelligence.
The Invisible Biography: How AI Platforms Build Organisational Profiles
AI platforms, by design, retain interaction data. The stated purposes are model improvement, personalisation, and service quality. The privacy implications are regularly disclosed in terms of service that almost nobody reads. But the deeper question is not what these platforms store—it is what can be inferred from what they store.
The Inference Layers
Queries to AI platforms reveal intelligence across multiple dimensions simultaneously:
Strategic Inference
- Market entry analysis signals expansion intent
- Competitive analysis framing reveals prioritised threats
- Due diligence queries identify acquisition targets
- Regulatory compliance questions reveal upcoming obligations
Operational Inference
- Process automation queries reveal workflow gaps
- Tool comparison questions expose technology decisions
- Integration questions reveal current architecture
- Incident-response framing signals live problems
Security Posture Inference
- Business cases for tools reveal current gaps
- Compliance queries identify frameworks not yet met
- Incident-related queries signal active vulnerabilities
- Policy drafting reveals what controls do not yet exist
Human Capital Inference
- Redundancy communications signal restructuring
- Performance management queries reveal team stress
- Recruitment framing exposes capability gaps
- Leadership communication patterns reveal culture
The critical point is that none of this requires access to the answers the AI provides. The queries alone constitute the intelligence picture.
The Deepest Layer: You Are The Data
There is a further dimension that most security discussions never reach, because it feels too abstract until it is demonstrated concretely. It concerns not the content of what people ask AI tools, but the way they ask it.
Keystroke Dynamics: The Biometric You Did Not Know You Had
Keystroke dynamics is the science of identifying individuals by the rhythm of their typing. It is not your words. It is the intervals between keystrokes, the duration of each keypress, the speed transitions between different letter combinations, the characteristic errors you make and correct. These patterns are as unique to you as your fingerprint, and—crucially—they are largely unconscious. You cannot fake them under pressure the way you might fake a password.
NVIDIA’s security research team has publicly described a system that builds a deep learning model for every user account on a network. The system learns how you type, when you type, what services you use, and in what sequence. When the pattern deviates, an alert fires. Their head of cybersecurity engineering described it simply: “We need to look for when Bartley is not acting like Bartley.”
The same technology that makes this a security control also makes it an attack vector. If an adversary has access to your keystroke patterns from AI platform interactions, they can:
- Identify specific individuals within an organisation by their typing signature, even without knowing their name
- Track the same individual across different platforms and sessions
- Correlate query patterns with individual roles—inferring seniority, function, and access level
- Detect when a high-value target (a CFO, a CISO, a board member) is the one typing
The implication for AI platforms: every time a senior executive uses a public AI tool, they may be depositing a behavioural biometric that links their typing rhythm, their query patterns, their timing habits, and their vocabulary choices into a persistent profile. That profile is intelligence. It can be used to impersonate them, to time attacks to coincide with their absence, or to identify them as a high-value target for social engineering.
Language As Identity: The Cognitive Fingerprint
Beyond keystroke dynamics, research into what has been called the “cognitive fingerprint” reveals that the way individuals structure their language, their characteristic sentence patterns, their vocabulary preferences, and their problem-framing styles are distinctive enough to identify them with high reliability. A DARPA-sponsored project demonstrated that unique problem-solving sequences—even in abstract cognitive tasks—could verify individual identity as reliably as conventional biometrics.
Applied to AI interactions: a lawyer who consistently frames queries in conditional structures, an engineer who always begins with the constraint before the goal, a strategist who anchors every question in competitive context—these patterns are identity markers. They persist across sessions. They are not affected by VPNs, incognito mode, or pseudonymous accounts.
Researchers have noted that these language patterns can also inadvertently disclose sensitive attributes the user never intended to share: ethnicity, region, mental state, cultural background. The AI system does not need to be told these things. It infers them from the texture of the interaction.
The Aggregation Attack: How Small Pieces Build The Picture
Intelligence professionals call this “mosaic theory.” No single tile in a mosaic is a picture. But arrange enough tiles and a coherent image emerges. Adversaries—whether state-sponsored intelligence services, organised criminal groups, or well-resourced competitors—are now applying mosaic theory to the AI query streams of target organisations.
The attack does not require compromising the AI platform itself. It requires access to the query stream. That access can come through multiple routes:
Pathways to Query Stream Access
| Pathway | Mechanism | Difficulty |
|---|---|---|
| Platform compromise | Breach of the AI service provider itself | High—but not unprecedented |
| Employee account compromise | Phishing or credential theft gives access to an individual’s history | Low—routine attack vector |
| Network interception | Unencrypted or poorly configured connections | Medium |
| Insider threat | Malicious or coerced employee exports query history | Low—often overlooked |
| Legal compulsion | Foreign government demands data from platform provider | Jurisdiction-dependent |
| Shared enterprise accounts | Poor credential hygiene exposes team query histories | Very low—extremely common |
The OmniGPT breach in early 2025 is instructive here. Attackers exposed 30,000 user email addresses, phone numbers, and 34 million lines of chat messages—along with thousands of private API keys. The chat messages were not incidental. They were the target. Every query in that dataset was a window into the intentions, concerns, and capabilities of the organisations whose employees had used the platform.
The Asymmetry Your Employees Don’t Understand
The failure here is not one of malicious intent. It is one of mental model. Your employees have a framework for data security built around documents, files, and systems. They know not to email sensitive spreadsheets to personal accounts. They know not to leave printed board packs on trains. They have been trained, briefed, and certified on these behaviours.
Nobody told them that the context in which they ask a question is itself a disclosure. Nobody explained that the AI platform they are using for a productivity boost is, simultaneously, building an organisational intelligence profile with every query. Nobody made the connection to the loyalty card analogy—which, if you did it on the street rather than the supermarket, we would call surveillance.
The Mental Model Gap
Here is what your employees believe they are doing when they ask an AI tool for help drafting a supplier negotiation strategy:
“I am using a productivity tool to help me work faster. I have not shared any confidential documents.”
Here is what they have actually done:
- Disclosed that a supplier negotiation is active or upcoming
- Revealed the negotiating position they are trying to construct
- Potentially identified the supplier or category by context
- Signalled their level of experience with this type of negotiation
- Provided a timestamped record of organisational activity
All of this from a query with no document attached and no named company in sight.
What Boards Should Ask This Week
- “Do we know which AI platforms our employees are using, and what data governance commitments those platforms make?”
- “Have we assessed the inference risk from query patterns, not just the direct data disclosure risk?”
- “What is our policy on AI tool use by executives and board members—who are the highest-value inference targets?”
- “Is our AI tool usage policy predicated on an outdated mental model of what data leakage means?”
- “Do we have an approved enterprise AI solution that keeps queries within our control boundary, or are we relying on consumer platforms?”
- “Has our cyber insurance policy been reviewed to consider AI inference as a data exposure pathway?”
Three Actions This Week
1. Audit Your Exposure
Map which AI platforms are in use across your organisation, including unsanctioned consumer tools. Identify which employee roles have access to the most sensitive strategic, financial, or security information—these are your highest-inference-risk users.
2. Update Your Mental Model
Brief your senior leadership team—not just your security team—on inference risk. The conversation needs to move beyond “do not paste documents” to “every query is a disclosure.” This is a board-level communication, not an IT policy update.
3. Evaluate Sovereign AI Options
Assess whether your current AI tool provision keeps query data within your control boundary. Enterprise-grade deployments from major vendors offer data isolation commitments. For the most sensitive roles, private deployment may be appropriate. Productivity gain is not worth strategic intelligence leakage.
The Question You Should Be Asking
If a sophisticated adversary had access to every AI query your employees have made in the last twelve months, what would they know about your organisation? If the answer makes you uncomfortable, the gap between your AI governance and your actual risk exposure is larger than you think.
About CyberCQR
CyberCQR provides strategic cybersecurity advisory services to boards and C-suite executives in UK regulated industries. We help organisations understand and govern the risks they cannot see—including the inference risks embedded in everyday AI tool usage.
