Daily digest · 2026-08-20

Daily Digest, 2026-08-20

TL;DR: Today is about agents that hold too much authority and the controls being built to claw it back. AWS published a pattern that carries the user's own permissions through an agent so databases enforce access instead of trusting the model to behave, which is exactly the gap that let an approved Meta agent post its answer where unauthorized staff could read it. On the attack side, researchers got Grok to steal user data by encrypting the malicious instructions so text filters never saw them, and CISA says attackers are actively breaking into MLflow servers. The UK privacy regulator also published audits of police facial recognition, giving the first clear read on what documentation it accepts.

Top stories

Also notable

Beyond AI