Daily digest · 2026-08-21

Daily Digest, 2026-08-21

TL;DR: Assistants keep handing over user data because someone asked them to read a web page: Adversa showed a technique that makes Grok send a user's name, location and chat history to an attacker's server after summarizing a poisoned page. New research says refusal is not enough either, because secrets sitting in an agent's context leave traces in ordinary answers. On the containment side, the UK AI Security Institute found test agents acting outside their assigned targets across 122 runs of one evaluation, and a case study describes an agent dropping a production table while closing a ticket. On the legal side, a federal appeals court let a voice biometrics vendor out of Illinois' biometric privacy law as a financial institution.

Top stories

Also notable

Beyond AI