Someone on your team wired AI into the company Google Drive last week. You would not know unless you asked.
It took four clicks. They wanted the assistant to stop asking them to paste documents in one by one, so they connected it — to the shared drive, or the Outlook mailbox, or the CRM — and now it just knows. The reports write themselves against real numbers. The follow-up emails quote the actual thread. It is genuinely faster, and that is exactly why nobody stopped to read the permission screen.
The productivity is real. So is what the AI can now see.
The productivity is real. That is why it spreads.
This is not a rollout anyone approved. It is happening from the bottom up, one person at a time, because the tools finally make it trivial.
Two things changed at once. Assistants like ChatGPT, Gemini and Copilot added connectors — one-click links into Gmail, Drive, Outlook, SharePoint and the big CRMs. And underneath them, an open standard called MCP (Model Context Protocol) turned “plug this AI into that system” from a custom integration project into something a single employee can switch on before lunch.
Read the first two numbers together. Most AI use at work is already unofficial, and a real slice of what flows through it is data the company would never knowingly put on the open internet. The tools did not create that instinct to share; they removed the last bit of friction that used to hold it back.
A connector inherits the person, not the file
Here is the part most people clicking “Allow” do not register.
A connector does not grant the AI access to a document. It grants the AI the access of the account that authorised it. Whatever that person can open — every folder they have ever been added to, the finance sheet from two roles ago that nobody revoked, the shared mailbox, the customer list — the assistant can now read on their behalf, and pull into a prompt, and send onward.
A connector does not hand the AI a file. It hands the AI everything the person who switched it on could already open.
Nobody checked what that was.
Permission scoping is the whole game, and it is exactly the screen everyone clicks past. “Read all your files” and “read the one folder you need” are two different grants that look almost identical in the moment. MCP makes the plumbing standard and safe; it does not decide what a given employee should be allowed to connect, or teach them to notice the difference. That judgement sits with the person, and right now the person has had no training on it.
The gap is not the tool. It is who clicks allow.
It is tempting to make this an IT problem — block the connectors, write a policy, be done. That fails for the same reason banning personal phones failed: the productivity is too good, so people route around the ban, and the use goes dark instead of going away.
And the stakes are no longer just reputational. Malaysia’s amended Personal Data Protection Act now carries mandatory breach notification — a company has roughly 72 hours to report a personal-data breach to the Commissioner once it becomes aware of one, alongside new obligations to appoint a data protection officer. A sales rep who connected an AI to a mailbox full of customer records has quietly widened the surface that clock is measured against, and did it with no idea they were making a governance decision.
The exposure is not created by the model. It is created by a capable, well-meaning employee granting broad access they do not understand, to solve a real problem nobody gave them a safe way to solve.
Capability is the only control that scales
You cannot put a lawyer behind every “Allow” button. What scales is the same thing that always scales with a new technology: people who understand what they are doing.
An employee who knows what a connector actually grants, how to scope it to the folder they need instead of the whole drive, what data an AI reads once MCP is on, and where the company’s own line sits — that person is worth more than any blocklist, because they make the right call in the thousand small moments a policy never reaches. That is a training outcome, not a policy document.
It is also, concretely, what SkillTrainer’s AI Productivity Power-Up course now teaches: alongside prompting and context engineering, a dedicated lesson on AI connectors and MCP — what plugging AI into Gmail, Drive, Outlook or a CRM actually exposes, how permission scoping works, and how to get the productivity without handing over the building. It treats governance as a skill the person carries, not a gate IT stands at.
Give people the training before the access
The companies that get this right are not the ones with the strictest AI policy. They are the ones where the people wiring AI into real systems understand what they are wiring — so the productivity lands and the data stays where it should.
The order matters. Access without capability is the exposure. Capability first, then access, and the same connectors that keep you up at night become the reason your team is faster than your competitor’s. For most Malaysian employers the training itself is already funded: courses delivered through an HRD Corp registered provider are claimable against the levy you are paying anyway.
If your people are already connecting AI to company data — and they are — the useful move is to make sure they know what that means. SkillTrainer’s AI Training is built to give a whole team that literacy, connectors and scoping included, before the next four-click decision gets made for you.
Sources
Model Context Protocol — the open standard for connecting AI assistants to tools and data
SkillTrainer AI — AI Productivity Power-Up, now covering AI connectors, permission scoping and MCP