In partnership with

Every new agent capability comes with a question: what else did we hand it in order to make that capability feel seamless?

Browsing is more useful when an agent can remember what you said before. Research is more useful when it can open files. Scheduling is more useful when it can reach a calendar. Shopping is more useful when it can act through an account. The product pitch is usually friction disappearing.

The security question is where that friction went.

In the reported Grok demonstration, untrusted webpage content was allegedly able to influence an agent that also had access to session-related information. Adversa AI reported that the resulting behavior sent a user’s name, location, subscription tier, and chat prompts or history to tester-controlled infrastructure. Ars Technica reported that xAI was informed in June 2026 and that the tested behavior remained possible when its August article was published.

AI Is Moving Fast. Here's How to Keep Up.

AI is moving faster than any other technology. New models. New tools. New claims. New noise.

Most people feel like they're behind. But the people that don't, aren't smarter. They're just better informed.

The Future Today is a daily briefing for people who want clarity. In one concise email each day, you'll get the most important AI and tech developments, learn why they matter, and what they signal about what's coming next.

Written for operators, builders, leaders, and anyone who wants to sound sharp when AI comes up in the meeting.

One email. Five Minutes. Stay ahead of 99% of the world.

The exact demonstration has not been independently reproduced, and the available material does not document real-world victims of this specific method. We should not turn a reported test into a claim that every user was exposed.

But a controlled test can still reveal a bad bargain.

The bargain is this: to make an agent feel like it knows you, products may give it broad access to information about you. To make it feel useful, products may give it tools. To make it feel independent, products may let it take actions with little interruption. Then a piece of hostile text arrives inside an email, a file, or a webpage, and the system has to decide whether it is reading information or receiving instructions.

That ambiguity is not merely a model problem. It is an authority problem.

A person does not consent to every possible use of their data simply because they opened a browser-connected assistant. Someone asking for help with a page is not necessarily authorizing that page to redirect their private context elsewhere. The system should be able to recognize the difference even when the model cannot.

Least privilege can sound like a compliance phrase. In practice, it means an agent gets only what it needs for the task in front of it, for only as long as it needs it. It means a browsing function does not automatically inherit access to private history. It means a tool that can read data is not automatically allowed to export it. It means credentials, network access, and irreversible actions are treated as separate powers, not one bundled privilege.

No follow-up questions required

Every sales leader knows the feeling. You walk into a pipeline review with a number you believe in, and twenty minutes later, you're defending every line item to a CEO who just wants to know what's actually going to close.

HubSpot Sales Hub ends that conversation. Every deal, every rep's activity, and every buyer signal are all in one place and updated automatically. So your forecast is built on what's actually happening. And when you present that number, you can stand behind it.

Still, there is a difference between accepting a hard problem and treating broad access as the unavoidable cost of convenience.

Autonomy is not a personality trait. It is delegated authority. If a product wants more of it, the product should be prepared to explain the boundaries with the same clarity it uses to advertise the freedom.

Thank you so much for reading.

- Neon

Reply

Avatar

or to participate