ChatGPT Work can read private connected data, ingest untrusted web pages, run internet-enabled code, control a browser, and take external actions. That closes all three sides of the prompt-injection “lethal trifecta”: secrets, hostile instructions, and a path to act. The unanswered question is how OpenAI contains a malicious page across that whole chain.
AI news for Monday, August 31, 2026
The Daily AI Espresso — the links the most-followed people in AI actually shared, curated every morning. Edited by Alexis · Live updates →
Build your own AI Weekly Espresso around the topics, companies, and people you actually care about. We’ll keep the rest out of your cup—and send it weekly or whenever enough important news brews.
Create my personalised AI Weekly edition →1. ChatGPT Work collapses three security boundaries. It can reach private data, read untrusted pages, and act externally—the exact combination prompt injection turns dangerous.
2. EU regulators can now demand evidence and changes from OpenAI. OpenAI must assess and reduce systemic risks, open data to vetted researchers, and comply within four months or face potential fines.
3. AI deployment is increasingly a rights-and-workflow negotiation. NHS record corrections, Caterpillar’s training spend, and Google’s studio outreach put responsibility, permission, and human review around the model itself.
Four consequential moves made Absolute Top Alerts: ChatGPT Work spans private data, untrusted web content, and external actions; infostealers hijack Claude sessions and drain paid usage; EU regulators can demand ChatGPT risk audits and fixes; and Taiwan raids a key Nvidia supplier.
Attackers are selecting active Claude sessions from general-purpose infostealer logs, then using the accounts until limits drain. Anthropic says it is revoking sessions, removing saved payment methods, and refunding identified unauthorized charges. A password reset is not enough if the malware remains.
OpenAI must assess and reduce systemic risks, give vetted researchers a path to platform data, and comply with Commission investigations and enforcement. Violations can draw major fines. OpenAI has four months to comply; the register lists 159.1 million monthly EU users.
Prosecutors searched facilities and questioned employees over allegations that China-made circuit boards were labeled as Taiwan-made. Unimicron supplies Nvidia, Intel, Google, and Amazon. It says it is cooperating; this is a criminal investigation, not a finding of guilt.
The rest of today’s expert-filtered signal, ranked for consequence, utility, surprise, and range.
The unusual direction is the story: the SoftBank-owned landlord granted its anchor tenant warrants, now estimated at $5.5 billion, alongside a 20-year lease for a planned 10-gigawatt Ohio campus. The arrangement turns OpenAI into a beneficiary of the value its own commitment creates—before public investors price SB Energy.
OpenAI reportedly uses the Macs for reinforcement learning and computer-use training that repeatedly runs agents inside a full operating system. The unit count is unconfirmed, but the demand signal is striking: memory-rich desktops are becoming AI training infrastructure, and Apple was reportedly not organized for enterprise buyers.
The five-year program covers AI, robotics, and autonomy across the industrial giant’s workforce. Caterpillar is already applying AI to field repair, digital twins, mining, and legacy code. Its useful lesson is organizational: deployment depends on experienced operators redesigning workflows, not simply installing a model.
The FT calculates that valuation gains on holdings in AI companies boosted recent pre-tax results at Alphabet, Amazon, Nvidia, and Microsoft by more than $160 billion. Alphabet’s filing confirms $97.983 billion of quarterly “other income,” primarily unrealized equity gains. These are paper gains—not cloud revenue or cash return.
Healthwatch England says patients have caught errors clinicians missed: “null demyelination” became a frightening diagnosis, one drug was confused with another, and prescription advice disappeared. With 27 scribes already in NHS use, the practical question is who must review the record—and how a patient gets it corrected.
Musk confirmed the secret Bastrop foundry is for gas-turbine blades—single-crystal parts whose long industry backlog constrains new power. Bringing them in-house could accelerate AI datacenters. It also brings the unresolved Memphis permitting and pollution fight deeper into the same vertically integrated system.
Google has reportedly approached Disney, Universal, Warner Bros. Discovery, and others about licensing entertainment IP for AI tools. No agreements have been reached, and the companies did not confirm terms. The early signal matters anyway: frontier labs are testing negotiated access to the characters people already know.
What is trending on social platforms today—checked against the original post before one playful experiment becomes a product claim.
River Raid, Freeway, Stampede, and Donkey Kong become instant “what if?” remasters—and the comments immediately debate which ones deserve to exist. These are images, not playable games. The broader signal is more useful: generative art is becoming a public sketchpad for testing nostalgia, demand, and visual direction before a studio builds anything.
That’s today’s shot. — Alexis · AI Weekly
