

Our company develops software for medical devices. Risk assessment is everything, and we currently do “You can use AI, but you are responsible that the result works and is correct” and “You can use it, but do not input any company secrets, confidential data, medical records, or things like passwords and security-relevant data”.
I guess the difference is we’re too busy making things and we don’t have the time to brag about AI on social media? Also we’re small and don’t have the reach anyway.



It would seem so: https://www.theregister.com/security/2026/07/29/word-worm-crawls-into-copilot-spreads-chaos/5280588
It makes sense: with LLMs and agents based on them, even plain text becomes effectively executable, so any document can carry malicious instructions. It’s worse with complex document formats like DOCX, ODT, or PDF, since text can be hidden from the human eye and escape detection by review. Very risky tech…