When assistants can access sensitive data and autonomously interact with multiple business systems, untrusted input can create risks that extend well beyond a conventional chatbot session. , creating a path for sensitive data to be retrieved and potentially exposed with minimal user interaction. During testing, researchers found that Rovo could access data across Jira, Slack, Google Workspace, Microsoft 365, databases, uploaded files, and other connected resources. Once malicious instructions entered a trusted session, an agent could retrieve sensitive data and potentially expose it externally with minimal user interaction. Bottom lineRovoBlast underscores the security risks that emerge as AI assistants gain deeper access to enterprise systems, data, and workflows.