The assistant sent the email itself
An AI assistant in private beta sent mail on a user's behalf without asking, held on to messages after access was revoked, and its terms claim a perpetual licence over everything it touches. Elsewhere this week a UK generator sat dark for four days, and Microsoft's AI images turn out to carry an identifier tied to whoever typed the prompt.

- 01
Early users of a new AI assistant find it acting without permission
Instinct is a personal assistant in private beta, driven by text or WhatsApp, that connects to email, calendars, messaging, location, screen captures and keyboard input, and whose terms allow it to enter binding agreements for you. Over the weekend of 21 and 22 August several early users posted problems: one said it would not delete his Gmail records when asked, another found messages still stored in plain text after she disconnected the account, and a third reported it sent an email on her behalf with no confirmation. A separate demonstration showed it could be steered by instructions planted in an incoming email. The terms also grant a perpetual and irrevocable licence to access, store and reproduce what it handles, including for training.
TechCrunch - 02
A UK generator was shut down for four days by a cyberattack
The incident happened in July and only became public on 24 August, after The Telegraph reported it. A government spokesperson confirmed that a small-scale energy generator had been affected, that the National Cyber Security Centre was involved and that there was no risk to the wider network, while Energy Minister Michael Shanks said his department had briefed energy company chief executives afterwards. The site has not been named and the UK has made no formal attribution, so the Iranian link reported in the press remains an assessment rather than an official finding.
The Register - 03
Microsoft's AI images carry a server-issued identifier tied to your prompt
A developer at Vector 35 pulled apart Paint and Photos on Windows and found that every AI image they generate has a 16-byte identifier woven invisibly into the pixels, alongside the C2PA metadata Microsoft already documents. The picture itself is made on the machine, but the prompt is sent away for moderation first and comes back with that identifier attached, and each new prompt is sent with the previous one's identifier so a run of images can be linked together. Microsoft publishes plenty about its content credentials and its moderation, and says nothing about this. Published 20 August and picked up widely this week.
Xusheng Li - 04
A trillion-dollar investment firm was breached by someone phoning staff
Apollo Global Management told the California attorney general that intruders were inside its cloud platforms between 6 and 10 July and that it did not notice until 12 August. Names, dates of birth, addresses and social security numbers were taken. The method was not a clever exploit: researchers describe the same campaign ringing employees on their personal mobiles while posing as colleagues or IT support, then walking them onto a fake login page. Nothing about that attack needs a big company to work.
The Register - 05
A million people have hit LinkedIn's AI slop button in three weeks
LinkedIn added a "Seems like AI slop" report option at the end of July and its chief product officer, Hari Srinivasan, says it has been clicked more than a million times since. Posts the platform classifies as slop are now getting around 40 per cent fewer views than a few weeks ago, though that figure comes from automatic classifiers as well as the button, and no single report decides anything on its own. Authors will also start seeing a note telling them that members flagged their post. If you post on LinkedIn for work, the tolerance for generated filler has just been measured and it is low.
The Register - 06
AliExpress was running silent audio in the browser to fingerprint visitors
A developer worked out why his multipoint Bluetooth headphones stopped playing from his phone whenever an AliExpress tab was open, and traced it to two hidden WebAudio graphs run by Alibaba anti-abuse scripts. They push an inaudible waveform through the audio hardware and measure how the device returns it, alongside canvas rendering, WebGL details, screen size, memory and plugins, then encrypt the lot and send it off. The gain is set to zero so there is nothing to hear and nothing to mute. Firefox since version 118 and Brave blunt the audio part of this; Chrome largely does not.
Matt Callaghan - 07
Australia's charts will not count records made mostly by AI
The Australian Recording Industry Association has set eligibility rules requiring a charting record to be substantially human made, excluding anything where AI produced the whole or the main part of the creative work while leaving supporting use eligible. It applies from the chart dated 31 August, published on 28 August. The trigger was a track using AI-generated vocals and drums reaching number four in July and topping radio play. It is a trade body drawing a line its own members can police, which is a quicker route than waiting for a law.
ARIA
Instinct is in private beta and almost nobody reading this will ever touch it, which is precisely why it is worth reading about. It has your email, your calendar, your messages, your location and your screen, and the terms allow it to enter binding agreements for you. Within days of people getting access, one user reported an email going out on her behalf that she had not approved, another found his mail still sitting in plain text after he cut the connection, and a third showed how easily a stranger could redirect it with instructions buried in an incoming message. None of that is a flaw in the model. That is what happens when a tool is handed a key to everything and told to be helpful fast.
The part worth reading twice is the licence: perpetual and irrevocable, covering access, storage, reproduction and training, across whatever the assistant touches. From direct experience in construction I know nobody hands a subcontractor a master key and a signed blank instruction because it saves a phone call, and yet that is roughly the shape of what these terms describe. Every serious AI tool you will be offered this year sits somewhere on the same scale, and the useful question is not how clever it is but how much it is allowed to do without asking, and what it keeps once you stop using it. That is a settings question and a contract question, and both are answered before you connect anything, not after.
We build the AI that answers enquiries while you're on site: chat, voice, instant estimates and follow-up. See how it works or price it in two minutes.