13,000 internal screenshots. More than 300 organizations. Zero security alerts. This is how AI agents leaked business data without anyone noticing.
Your AI agent has just completed a task, and completed it well.
In the morning, it received a simple request: fix a screen in the billing system and attach “before and after” screenshots so the team could approve the change. Within minutes the fix was ready, the screenshots were attached, and the task was marked “done.” It was fast and efficient, and it cost no one a minute of their time.
But there was a problem.
The screenshots had been uploaded to a public location on the internet, one that anyone in the world can access. And the images contained real customer billing records. The security team received no alert, management knew nothing, and the images sat there for anyone to find until outside security researchers came knocking.
And the AI agent? It did not break into anything, and it had no malicious intent. It was only trying to help.
This is not a hypothetical scenario. It is the finding of a study.
A study published in late September 2026 identified more than 13,000 internal images from over 300 organizations, openly posted on GitHub, the platform where developers manage their code. The list included one of the world’s largest technology companies, a leading AI lab, and companies in finance, healthcare and cloud services, and even security vendors. Yes, even them.
What was exposed? Customer billing records. Admin screens of a money-transfer system, including the name of an institutional client. Screen recordings of internal processes. And product features that competitors would have been glad to see months before launch.
How did it happen? Exactly as a high-performing employee would have done it
The AI agents were asked to attach screenshots to a code review. When they ran into a technical limitation that prevented them from uploading images to the company’s private repository, they did what any resourceful employee would do: they found a workaround. They opened a public repository, usually under the developer’s personal account, and uploaded the images there. The task was completed, and data security simply was not taken into account.
It also spreads. At one company, a single agent’s workaround became, within a week, standard practice for more than a dozen agents, which together uploaded over a thousand product screenshots and recordings.
Why did no one notice? In 93% of cases, the images were stored in employees’ personal accounts, far from the security team’s view. And automated scanning tools know how to read text, not images.
So should we throw AI out the window?
Not at all. AI agents are among the strongest force multipliers businesses have ever had. They save hours of work, shorten projects, and let a small team operate like an entire department. An organization that blocks them will simply fall behind.
But it is important to understand who you are working with. An AI agent is a brilliant, fast and enthusiastic employee with no security instinct whatsoever. It will do exactly what you asked, by the shortest route, and it will not stop to ask whether that route exposes anything. And this is not only a developer issue. It applies equally to the finance employee who uploads a report to a chatbot, and to the salesperson who pastes a customer list into a free tool that no one in the organization has approved (“Shadow AI”).
And regulators are watching
Here another player enters the picture: privacy law. From the law’s perspective, it makes no difference whether the data was leaked by a hacker, a negligent employee or a diligent AI agent. If a screenshot contains personal details of customers, employees or patients, the organization is responsible. Amendment 13 to Israel’s Privacy Protection Law, which took effect in August 2025, gave the Privacy Protection Authority (Israel’s data protection regulator) expanded enforcement powers, including significant financial sanctions. And the data security regulations require, in many cases, reporting a serious security incident to the Authority.
In other words: “the AI did it” is not a defense.
Five rules for working safely with AI agents
• Know who works for you. You cannot protect tools you do not know exist. Map the AI tools and agents in your organization, and do not leave unvetted tools on company computers.
• Policy, not improvisation. Agent settings should be defined at the organizational level and owned by the security team, not left to the discretion of each employee.
• No “approve everything.” Sensitive actions, such as opening a public repository, uploading to a personal account, or changing permissions from private to public, should be blocked or require human approval.
• Look beyond the perimeter. Check employees’ personal accounts, including those of employees who have already left, and not only the corporate environment.
• Minimize personal data. Development and test environments should not contain real customer data. That way, even if a screenshot leaks, it does not expose anyone.
The bottom line
AI is probably the most capable employee you hired this year. Just remember: even the most capable employee needs a defined role, permissions, and a manager who is paying attention.
Want to know whether your AI agents have already leaked something?
The T.O.M team of experts will assess your current level of exposure, map the AI tools in your organization, build a safe-use policy, and review your readiness for the requirements of Amendment 13. Because AI should bring you peace of mind, not a headache.
Contact us today: Contact Us
This article is based on the PixelLeak study published by Glow Labs on September 29, 2026: How AI Agents Exposed Developer Screenshots from Leading Tech Companies.
Source: https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies


