| TL;DR: Finding exposed files leaves businesses with decisions about what to keep, remove, or restrict. Teleskope’s Kosmo AI assistant investigates those files, recommends actions, and prepares reports for security staff and the people responsible for the data. It suggests which problems deserve attention first. It cannot change company systems itself, but it prepares the work so people can review and approve what happens next. |
A company finds years of employee records, personal details and all, in a shared folder. Some belong to former employees, while others are still needed. And almost anyone can open that folder, which means a single stolen login could expose all of it.
The security team can spot the problem quickly. Fixing it is another matter, because that takes a conversation. HR has to confirm which records still need to be kept. The company also has to decide who should have access.
Until those decisions are made, the files stay where they are.
That’s where Teleskope’s AI assistant, Kosmo, steps in. It investigates exposed data and suggests what the security team should do next. However, acting on those suggestions could cut off access to files employees still need.
So where should the software stop and a person take over?
AI Makes Forgotten Files Easier to Find
A file can sit unnoticed for years without being properly protected. Perhaps an old project folder still has broad access. Perhaps someone changed departments but kept their previous permissions.
You see, those gaps could go unnoticed for years. Generative AI makes them easier to spot because employees can ask an assistant to find information across files they already have access to.
Microsoft warns that it can quickly surface content that is obsolete or open to too many people. In other words, an employee who would never dig through an old folder can now ask an assistant and see what’s inside.
Security provider Varonis found widespread exposure in the business IT environments it studied. Its State of Data Security research looked at 1,000 business IT environments and nearly 10 billion files. It found that 99% of the organizations had sensitive data that AI could potentially uncover. Some 88% also had accounts that stayed enabled after people stopped using them. It’s worth noting that those numbers describe exposure in the environments studied, not confirmed breaches.
After all, when AI makes information easier to find, companies also need to decide who should be allowed to see it.
More Findings Bring More Decisions
Every exposed file raises a question about who should have access to it. Removing access might protect sensitive data, but it could also disrupt employees who rely on those files to do their jobs.
That’s the challenge Ramp faced. Its security team felt that pressure as the financial software company grew from about 200 employees to more than 1,300. Sensitive financial and personal information moved through collaboration tools such as Slack and Google Drive. Ramp wanted to protect that data without slowing down how its people shared information.
Removing access can protect a file, but the team must first check whether anyone still needs it.
Elizabeth Nammour, Teleskope’s founder and a former Airbnb data security engineer, knows that difficulty firsthand.
“The hardest part of the job was never the fix,” she said when Kosmo launched.
For her, the harder part was deciding which risks needed attention and working with data owners to find the right fix.
Kosmo Prepares the Work Behind the Fix
Teleskope’s platform already finds sensitive data, and under company policies, it can restrict access or remove the information.
Kosmo works as an AI data security assistant, letting security teams investigate problems and plan their next steps by asking questions in plain language. A security employee can ask it about exposed files and see what it recommends doing with each one. It can prepare a briefing for a data owner or suggest a permanent rule to prevent the same problem from recurring.
And it doesn’t always wait for someone to ask. Kosmo can also flag exposed files for the security team to review, helping them identify which problems need attention first.
Nammour called it the “senior analyst I wish I’d had at Airbnb.”
So what does that look like in practice? Beta customers put that analyst to work before launch. According to Teleskope, one customer kept a single Kosmo session running for six days. Its security team reviewed the archive by grouping files according to the decade they were created. This brought old data to light that nobody had reviewed in years.
That’s a different task from responding to new alerts. It means reviewing old files and checking whether the access rules around them still make sense.
Security teams face the same gap after other kinds of findings too. Legion Security’s DragonClaw is designed to help analysts piece together what happened across existing security records and decide what deserves attention next.
The company also says another customer built nine compliance reports in one afternoon from the same set of findings. Previously, each one meant starting from scratch.
The Person Approving the Plan Still Matters
Kosmo can recommend a fix, but only a person can approve it. Teleskope says the assistant has no tool that can make changes in a customer’s systems.
Keeping Kosmo on the recommendation side also limits what can happen if an AI system gets something wrong. HYCU has been looking at the other side of that problem, where agents with permission to change or delete business data need controls around what they are allowed to do.
It can search for sensitive data without giving users access to files they aren’t already allowed to open. Kosmo follows the user’s existing file permissions. The system checks those permissions separately rather than relying on the AI assistant to enforce them.
According to the company, these controls could let employees outside the security team use Kosmo while keeping existing file permissions in place. The model itself can see which files are involved and how they’re labeled, but not the contents of those files.
Of course, controlling access is only one part of the wider picture. Businesses are increasingly looking to data security AI to help teams investigate risks and decide what needs attention. Microsoft’s 2026 Data Security Index found that 82% of surveyed organizations planned to use generative AI for data security work. A year earlier, the figure was 64%.
One energy-sector IT director said their AI systems were “making recommendations for modifications with far more data” than manual work allows.
But here’s the thing: more data can sharpen a recommendation. The person approving it still needs to understand why it fits the business.
That need for review also appears in professional AI tools outside security. Attain IP is designing its patent AI so professionals can inspect and challenge what the system produces before relying on the result.
Data Security is Moving From Detection to Decisions
Data security tools have become better at finding exposed data. Kosmo picks up from there, helping security teams investigate findings and decide what action to take.
Teleskope says Kosmo carries the same numbers from the first finding through to its proposed fixes and reports. That way, security staff can explain both the problem and the plan without double-checking conflicting figures.
As AI makes exposed data easier to find, businesses face more decisions about what to do with it. The tools that stand out will be the ones that help people agree on the next step and approve it.







