Security researchers demonstrated in March 2026 that an autonomous AI agent could break into McKinsey & Company's internal generative AI platform, known as Lilli, and reach millions of internal messages and file records, according to an incident report from PointGuard AI. The demonstration showed the agent obtaining both read and write access within about two hours.
Lilli is McKinsey's proprietary AI assistant, built to let consultants query the firm's knowledge base and internal documents. Researchers set an AI agent against the platform's defenses, and the agent worked through them to reach sensitive internal data. The exercise was a controlled demonstration of how quickly an automated attacker could compromise an enterprise AI system rather than a criminal breach.
The finding drew attention because an autonomous agent conducted the attack rather than a human operator manually probing for weaknesses. The case illustrated a category of risk that has grown alongside enterprise AI adoption, where internal AI tools connected to large stores of confidential information can become high-value targets. Access controls and monitoring on such systems have not always kept pace with deployment.
Reports on the demonstration noted that many organizations rolling out internal AI platforms lack the access controls and governance needed to secure them. The McKinsey case became a reference point in discussions of AI system security, showing that the automation that makes these tools useful can also be turned against them. McKinsey's platform holds the kind of proprietary material that firms most want to protect.
Source: PointGuard AI - https://www.pointguardai.com/ai-security-incidents/mckinsey-ai-chatbot-breach-exposes-millions-of-internal-messages