Today's briefing
The assistant that reads your inbox can be talked into things
A Copilot jailbreak, a data-retention promise and a disputed protein claim — what this week's AI news actually changes for a school, clinic or workshop.
The one that matters
Researchers talked Microsoft's Copilot into helping attack it — and that is the whole problem
Security researchers persuaded Microsoft Copilot to hand over information useful for attacking Copilot itself. Five outlets carried it; the technical detail in circulation is thin, and we are not going to invent any. But the word doing all the work in every write-up is tricked. Nobody broke into a Microsoft data centre. Somebody talked to the assistant and it cooperated.
Why this lands differently than a normal security story
Copilot is not a niche tool. It is the AI that arrived inside the Microsoft 365 subscription your office already pays for — roughly USD 30 per user per month as an add-on, a few thousand rupees per user per month in India. For most owners reading this, it is the only AI product actually deployed at work, and it was sold on exactly one promise: it can see your things. Your mail, your SharePoint folders, your Teams threads, last quarter's spreadsheets.
That access is the product. It is also the exposure. A 30-bed clinic's shared drive holds patient files, doctor rosters and insurance correspondence. A 600-student school's drive holds fee defaulters, staff appraisals and welfare notes. A workshop with 40 staff has supplier pricing that would be worth real money to a competitor. An assistant that can be talked into things is an assistant that can be talked into things while holding all of that.
The uncomfortable structural point, which this research sits inside rather than invents: your assistant reads text that arrives from outside your company. Emailed PDFs. Supplier invoices. Website form submissions. CVs. Any of those is input, and input is where persuasion happens. Your firewall has no opinion about a politely worded paragraph.
What this does not mean
It does not mean your data leaked. Nothing in the reporting says any customer was affected. It does not mean Copilot is unsafe to use, and it is not a reason to rip it out — every assistant with access to a business system carries some version of this weakness, including the ones being sold to you as the safe alternative.
Two groups are overstating it in opposite directions. Security resellers will quote this headline while pitching an "AI security posture" retainer you do not need yet. And vendors announcing that they can pipe your "full business context" into an AI assistant are quietly assuming the assistant should see everything — which is precisely the assumption under review.
What a sensible owner does this month
- Find out what it can already see. Have your office manager or IT provider list which folders are shared with "everyone in the organisation." Half a day's work. Most firms are shocked.
- Name the two or three folders it must never touch. Payroll, patient records, board minutes, student welfare files. Restrict them properly, not by hoping.
- Roll out narrow, not wide. Not using Copilot yet? Turn it on for one team — reception, admin, quoting — instead of the whole company.
- Keep a human signature on anything leaving the building. Quotes, patient letters, notices to parents.
- Ask your existing IT provider two questions before buying anything new: who can see what today, and what happens to their access when someone resigns.
None of that is an AI project. It is the access hygiene you should have had before the assistant arrived. The assistant just made the gap expensive.
Also worth knowing
-
OpenAI reaffirms Zero Data Retention for eligible API customers
OpenAI restated that eligible API customers can run without their data being retained, and previewed something it calls Private Safety Processing. If you handle patient records or student data, this is the paragraph your software vendor should be quoting to you in writing. Note the load-bearing phrase — "eligible API customers" — which covers software built on OpenAI, not the consumer chat app your staff open on their phones.
OpenAI ↗ -
"Don't paste the AI, please" — the most-argued-about post of the week
Nearly a thousand points of discussion on a simple complaint: people pasting unread AI output into emails, tickets and reviews, making the checking someone else's job. This is the cheapest workplace policy you will ever write, and it fits on one line — if you paste it, you own it. Worth saying out loud at your next staff meeting, especially in a small agency or accounts team.
Hacker News ↗ -
Anthropic claims Claude designed working protein binders in a lab test
Anthropic says Claude designed protein binders that worked for 14 of 15 targets, and six outlets picked it up. It has already drawn public pushback from critics calling the result unimpressive and far from novel. For a clinic, pharmacy or manufacturer there is nothing here to act on this year — it is a lab result, not a medicine, and lab-to-shelf is measured in years.
Storyboard18 ↗ -
Businesses are switching AI vendors every time a new model ships
New data suggests OpenAI is closing on Anthropic among business users, with companies flipping back and forth as each lab releases something better. The useful read is not who is winning — it is that your AI vendor is not a ten-year decision. Keep your prompts, your customer data and your actual workflow in systems you control, so switching costs you a week rather than a rebuild.
TechCrunch AI ↗ -
Two big financial firms lost access to Claude in Hong Kong
Goldman Sachs and OKX were both cut off from Claude in Hong Kong — a reminder that access to these tools can be withdrawn for reasons that have nothing to do with your behaviour as a customer. If you have a branch, back office or contractor in another country, confirm the tool is actually available there before you build a process around it. Have a manual fallback for anything that would stop the day if the assistant went dark.
Yahoo Finance ↗ -
ChatGPT can now write and send your texts through Apple Messages
A new Apple Messages integration lets ChatGPT act as an automated scribe for your texting. Tempting for a shop or clinic doing appointment reminders and follow-ups — but a machine sending messages under your name is you sending them, legally and in the customer's eyes. Keep it drafting rather than sending, and check your consent obligations first (CASL in Canada, TRAI's rules in India).
TechCrunch AI ↗ -
"Anti-AI" fonts don't stop machines — they do block screen readers
A widely-read argument that fonts designed to be unreadable by AI barely slow the machines down while breaking accessibility for people who rely on screen readers. Schools and colleges keep buying tools in this family — detectors, poisoned documents, watermarks — and they keep underperforming. Spend the money on assessment you can actually trust instead: in-person work, oral defence, drafts you can see the history of.
Hacker News ↗ -
A press release promises "full business context" for Claude Enterprise
Three outlets carried this, and all three were reprinting the same PR wire announcement — that is not corroboration, it is distribution. Connecting an assistant to your internal systems is a genuine product category and some of these tools are good. But the hard part was never the connector; it is whether your records, file names and processes are clean enough to be worth reading, and no vendor fixes that for you.
PR Newswire ↗
How this briefing is put together
Every morning we read the day's AI announcements and reporting from the companies themselves and from the technology press, then pick the handful that actually change something for a working business. The analysis is ours and it is written for owners and managers, not engineers. Every story links to its original source above — read them, and disagree with us where we've got it wrong.