Twenty-five million strangers
The tally started at roughly half its current size and has kept climbing as state registries post their own counts: more than ten million residents in one state, over fifteen million in another, smaller filings elsewhere, and a total now past twenty-five million people. The records included names, addresses, dates of birth, national identifiers, insurance details and medical information. The intrusion ran for nearly three months before it was found, and the public account of what happened remains thin more than a year later.
What makes this case instructive is not its size — a healthcare-clearinghouse attack two years earlier reached far more people — but the relationship, or rather the absence of one. The company processes benefits claims, child-support payments, unemployment insurance and payroll on behalf of state governments and large employers. Almost nobody whose data was stolen was its customer. Their only connection ran through an agency or an employer that had outsourced work to it.
That is not an unusual arrangement. It is the standard architecture of the modern enterprise, and it is where most data exposure now happens.
Where governance stops
Inside the organisation, a data platform can be genuinely well governed: classified, permissioned, logged, backed up. Then the data leaves — to a payroll processor, a claims administrator, a marketing platform, an analytics vendor, a printing house, a benefits portal — and the governance that applied to it stops at the boundary. What happens next depends on the contract, on the processor’s controls, and on whether anyone at the originating organisation is still watching.
Most are not, because they cannot see. Ask an organisation to list every third party that holds copies of its customer records and the answer is a spreadsheet somebody built for a compliance exercise three years ago. The processors have processors of their own. The inventory is incomplete by construction.
The breached company’s public communication illustrates the second failure. Its incident page did not name a cyber incident and carried a tag hiding it from search engines; a spokesperson would not say how many notifications had gone out. Meanwhile state agencies and employers fielded the questions their residents and workers were actually asking. When a processor goes quiet, the reputational cost lands on the organisation that chose it.
AI vendors are the newest processors
This is where the story turns from a caution about outsourcing into a live design question for AI programmes. Every AI service that receives enterprise data is a processor: the model API that sees the prompt and its context, the retrieval platform that indexes the document store, the agent tool that reads the CRM, the transcription service that hears the meeting. Data is flowing to these services right now, often through pilots outside procurement’s view, on terms nobody has read.
The discipline that applies to a benefits processor applies here, only faster.
- Inventory what leaves, and to whom. Which systems and datasets are reaching which AI services, through which integrations. This is the same data-classification work that governs the warehouse, extended one step further.
- Minimise by default. A model rarely needs the whole record. Masked, tokenised or synthetic data should be the norm for anything outside production, and the data an AI service receives should be the minimum the task requires.
- Contract for the failure, not the feature. Retention, training exclusion, sub-processors, breach notification timelines and the right to audit belong in the agreement before the pilot, because they are impossible to add after the incident.
- Prefer the governed path. Where an AI service can operate against your platform through a connector that enforces your permissions and logging — rather than receiving an export — the data never becomes a copy you have to track.
Before the letters go out
The organisations that handle a processor breach well are the ones that answered three questions in advance: what did we give them, on what terms, and who tells our customers. Those answers should exist today for every processor that holds personal data, and they should be created, not retrofitted, for every AI service being wired in this year.
Twenty-five million people are receiving letters from a company they had never dealt with. The lesson for anyone running a data platform is that the boundary of your governance is not the edge of your systems. It is the last place your data travels — and with AI, that place is multiplying.
