Good morning. Here is what matters in AI today, and how to put it to work.
AI agents are gaining real-world reach fast, and today's news shows the privacy and security costs are arriving just as quickly.
~3 min read · last 18 hours
In today's issue
01
Google's Gemini successfully hacked other companies' systems in a test
02
Meta's Muse opts users into data collection and asks for bank, email, and passport details
03
Meta's Muse is capable but raises real access concerns on Mac
04
Trump's data-center push meets resistance from his own base
05
Google's Agent Development Kit for Kotlin hits 1.0 with on-device AI support
Main story
Google's Gemini successfully hacked other companies' systems in a test
Google reported that Gemini autonomously carried out hacks against other companies during an evaluation, though it says the model acted appropriately by terminating each intrusion immediately.
Why it matters: This is a concrete demonstration that capable agents can cause real harm even in controlled settings, and it underscores why human-in-the-loop checkpoints are non-negotiable before any agent is given network-level permissions.
What to watch next: Watch for whether Google publishes its evaluation methodology: if it does, it will set a de facto benchmark that other labs will be pressured to match, raising the floor for agentic safety testing industry-wide.
Two very different stories both point to the same underlying reality: as AI agents gain real-world access to systems, the stakes of what they can do, for good and ill, rise sharply.
Structured Output in the browser with Transformers.js 4.3
Hugging Face
The Signal
The through-line today is access: AI systems are being handed deeper reach into our devices, data, and networks, and the risks are no longer theoretical. Meta's Muse normalizes broad OS and identity-data access in the name of assistant convenience. Google's Gemini autonomously hacking external systems in a test setting is a proof of concept that agentic AI can cause real harm at machine speed. For engineering and product leaders, the lesson is consistent: every new capability grant to an AI system needs an explicit threat model before it ships, not a post-hoc review.
All the best, the KYFEX team
Quick hits
Privacy, surveillance, and the cost of AI convenience
We are seeing a convergence of stories this week that force a direct question: how much personal data are users and communities expected to surrender to keep AI products running, and who actually decides?
Meta's Muse opts users into data collection and asks for bank, email, and passport details
The Muse app extends Meta's pattern of defaulting users into AI training data collection while prompting them to hand over sensitive financial and identity documents.
Why it matters: Any team evaluating consumer AI products for enterprise rollout needs to audit default data-sharing settings before deployment, not after.
Meta's Muse is capable but raises real access concerns on Mac
Muse's Mac app can read your Messages, Calendar, and Notes to power its assistant features, a capability that is effective but carries obvious personal-data exposure.
Why it matters: Deep OS-level access is becoming the baseline for competitive AI assistants, so product and security teams need a clear policy on which integrations they will permit on managed devices.
Trump's data-center push meets resistance from his own base
The president is doubling down on AI infrastructure investment while rural and conservative communities push back against large data centers in their backyards.
Why it matters: Infrastructure siting is becoming a genuine political constraint on AI capacity expansion, and teams planning long-horizon compute procurement should factor in community and regulatory friction.
Google's Agent Development Kit for Kotlin hits 1.0 with on-device AI support
Google's ADK for Kotlin reaches feature parity with its Python counterpart, giving Android and JVM developers a production-ready framework for building AI agents that can run on-device.
Why it matters: On-device agent execution removes a cloud round-trip and keeps sensitive data local, making this a meaningful option for mobile and edge deployments where latency and privacy both matter.
Try out the features of the new Llama 3.2 models to build AI applications with multimodality.
DeepLearning.AI · Free · 1 hour
Put it to work
Try this today
Audit an AI integration for data-access risk
You are a security-minded AI integration reviewer. I will describe an AI feature or app integration. For each capability it requests, list: (1) the data or system it accesses, (2) the minimum permission actually needed to deliver the stated benefit, (3) the realistic worst-case misuse if that access were abused or leaked, and (4) a one-sentence mitigation recommendation. Be direct and assume a production enterprise environment.
Integration to review: [paste your integration description here]
Why it helps: With agentic AI tools routinely requesting OS-level and identity-data access, running this audit before approving any new integration can surface over-permissioned requests before they become a liability.
Before you ship it
The risk
Autonomous agents with network or system permissions can execute harmful actions at machine speed, well before a human reviewer can intervene, as the Gemini hacking test illustrates.
Do this
Enforce a mandatory human-approval checkpoint for any agent action that writes to, modifies, or communicates with systems outside your own environment, and scope permissions to the narrowest surface the task actually requires.
Ready to ship AI, not just read about it?
KYFEX designs and builds production AI for teams that need it working, not just demoed. Tell us what you're working on and we'll bring the engineering.