Daily digest · 2026-09-07

Daily Digest, 2026-09-07

TL;DR: Deletion is today's theme, and the news is bad for anyone who promised it. Three separate papers show that erasing someone's data from an AI system mostly doesn't work: federated "unlearning" broadcasts leak the very records that were deleted, deleting an agent's memory row leaves the cache and summaries holding the same information, and the standard definition of unlearning gives no guarantee against anyone who watched earlier model releases. On the attack side, prompt injection now runs as an adaptive search by an attacker agent rather than a fixed payload, and a malicious MCP server holds its payload until the third tool call so install-time scanning comes back clean. Meanwhile insurers still can't price what a rogue agent breaks, and one paper shows models answer differently when they notice they're being tested, which dents the safety evidence a lot of programs rest on.

Top stories

Also notable

Beyond AI