What's New in AI

August 21, 2026

Grok's security flaw and what it means for your stack

Share

HAPPY FRIDAY,

Late August, which means half your team is probably wrapping up vacation coverage and the other half is already mentally checked out before they leave. Somehow this is still when the interesting stuff happens. This week we got an unsettling AI security story, a study that might complicate a few billion dollars worth of copyright lawsuits, and a handful of marketing stories that are worth your time.

In This Week's AI Fridays:

  • Grok can be tricked into stealing user data through encrypted instructions, and enterprise security teams should probably know about this
  • An MIT study says generative AI doesn't copy artists the way everyone assumes, which is going to make some ongoing court cases more interesting
  • Why proving the ROI of agentic AI is less about time saved and more about what you do with it
  • What the teams getting the most from AI are doing differently
  • Quick hits: Nvidia's $21B SpaceX stake, Nevada approves 8,000 robotaxis, and a London data centre with the carbon footprint of a small country

Grok Can Be Tricked Into Exfiltrating User Data Through Encrypted Instructions

Researchers have demonstrated what they're calling Cryptographic Context Injection, an attack vector that gets around Grok's safety guardrails by hiding malicious instructions inside encrypted content. The model processes the instructions without flagging them, and user data goes somewhere it shouldn't. This isn't a theoretical edge case; it's a demonstrated technique against a model that a lot of enterprises are now running inside their workflows.

The Highlights:

  • The attack uses encrypted instructions to bypass Grok's content filters, which don't read encrypted inputs the way they'd read plain text
  • Successful exploits allowed researchers to exfiltrate user data without triggering guardrails
  • The attack requires malicious content to be injected into the model's context window, so it's particularly relevant for any deployment where Grok is processing external documents or user-submitted content
  • xAI has not, as of this writing, issued a patch or public response

The Takeaway:

If Grok is anywhere in your enterprise stack, your security team needs to know this exists before your legal team finds out the hard way.


Does Generative AI Copy Artists? MIT Says It's More Complicated Than That

A new MIT study published in Nature is pushing back on one of the foundational assumptions behind the major copyright lawsuits against AI companies: that generative models directly reproduce training data. The researchers found the relationship between training images and model outputs is considerably more indirect than the plaintiffs' arguments tend to suggest. Whether that holds up in court is a different question, but it does mean the legal theory underpinning several high-profile cases just got more contested.

The Highlights:

  • The study appeared in Nature, which gives it more weight than the average preprint that circulates on AI Twitter for a week and disappears
  • Researchers found that outputs statistically resemble training data in aggregate style but don't reproduce specific works in the way the lawsuits allege
  • The findings are already being cited in ongoing litigation, so the timing is not incidental
  • Artists and rights holders dispute the framing, and several have pointed out that "doesn't copy exactly" is not the same as "doesn't cause harm"

The Takeaway:

This study doesn't settle the copyright debate, but it does mean the debate is going to run longer and get more technical than most people expected.


AI in Marketing

Proving the ROI of Agentic Marketing

The framing most teams reach for when they're trying to justify AI investment is hours saved, and it's the wrong framing. Hours saved just means you did the same work with fewer people, which is a cost argument, not a value argument. What the Marketing AI Institute is pointing toward here is something more useful: what did you do with the time you got back? If the answer is "more of the same work," the ROI case is going to be thin. Agentic systems earn their keep when they shift capacity toward things that were previously unaffordable, faster iteration, more personalization, better testing coverage. That's a harder story to tell to a CFO, but it's the honest one, and it tends to hold up better over time.

via Marketing AI Institute

What the Teams Getting the Most from AI Do Differently

The teams pulling ahead aren't the ones with the most sophisticated tools, they're the ones with the most permissive internal culture around experimentation. Autonomy, cross-functional structure, willingness to run something before it's perfect. The laggards tend to have the same tools and a committee that reviews every prompt template. AI's speed advantage compounds quickly when people are allowed to use it, and it evaporates just as fast when every output needs three rounds of approval before it touches anything real.

via MarTech

Google Discover Is Getting an AI Chatbot-Tuned Feed

Google is rolling out natural language customization for Discover, meaning users will be able to tell the feed what they want in plain English and the AI adjusts accordingly. For content marketers, this is worth watching because Discover has been a meaningful traffic source for publishers who produce content that fits its interest-graph logic. If that logic is now being shaped more directly by individual user intent rather than just engagement signals, the content strategies that have worked historically may not travel forward without adjustment. It's not a crisis, but it's the kind of platform shift that tends to matter more six months from now than it does today.

via The Verge

Stampli Cut Launch Hours by 68% Using ChatGPT Work

Stampli compressed weeks of product launch production into days using OpenAI's Codex and ChatGPT Work, landing a 68% reduction in launch hours. OpenAI published this as a case study, so take the framing with the appropriate grain of salt, but the number is specific enough to be interesting and the workflow they describe, using AI to coordinate across copy, design briefs, and technical documentation simultaneously, is something most mid-size marketing teams could at least partially replicate. The honest benchmark question is whether your current AI adoption is producing results you could put a number on. If not, this is a useful reference point for what that could look like.

via OpenAI


Quick Hits

  • OpenAI has reaffirmed Zero Data Retention for eligible API customers and previewed Private Safety Processing, which is meaningful news if you have clients asking hard questions about where their data goes. Read more
  • A secret parameter in Microsoft Copilot let hackers steal passwords when targets clicked a malicious link; two enterprise AI security stories in one week is either a coincidence or a trend worth paying attention to. Read more
  • A former OpenAI employee argues the industry is being pressured to move faster than is safe, and over a thousand employees at frontier AI firms have signed a letter asking the US government to slow things down; the letter probably won't change much, but the number of signatories is not nothing. Read more
  • Planning documents for a proposed hyperscale London data centre show an annual carbon footprint equivalent to 27,000 flights to New York, which is the kind of number that tends to end up in a parliamentary question fairly quickly. Read more
  • Nvidia has disclosed a $21 billion stake in SpaceX following an exclusive deal to supply Nvidia hardware to SpaceX data centres; Jensen Huang is having a year that will require its own Wikipedia section. Read more
  • Nevada has approved permits for up to 8,000 robotaxis from Tesla, Uber, and Waymo to operate over the next 12 months, which is either a milestone or a stress test, depending on how the next 12 months go. Read more

This article was obviously generated with AI but curated by a human, don't be weird about it.

Compiled by

Pete Bishop, Chief Innovation Officer at ZGM Modern Marketing Partners and host of Artificial Breakdown

Pete Bishop

Chief Innovation Officer, ZGM Modern Marketing Partners

Pete Bishop has spent the last two decades helping brands adopt new technology without losing the plot. He hosts Artificial Breakdown, a podcast and weekly newsletter that translates AI news into practical marketing decisions, and scans 50+ sources each week to write this issue.

Get this in your inbox

One email a week with the AI and marketing news worth your time.