A padlock rendered as plaintext instructions sitting beside its own key

AI News, August 20: Encrypt the Attack, Grok Complies

No frontier lab shipped a model today. What shipped instead was authority: agents got trading accounts, coding channels, and a fresh way to be hijacked.


The Big Story: Grok’s Guardrails Stop Reading If You Encrypt the Instructions

Adversa researcher Rony Utevsky found that Grok’s prompt-injection defenses can be walked past with a trick that sounds too simple to work. Encrypt the malicious payload. Put the decryption key and the decoding instructions in plaintext on the same page. Grok decrypts the payload and follows it, with no warning and no user confirmation.

What the deciphered instructions tell it to do is the elegant part. Grok is asked to build a “decryption key” that is actually the user’s name, location and chat history, then append that key as a URL parameter pointing at the attacker’s server. The exfiltration is dressed up as the cryptographic housekeeping the model already agreed to do. Nothing in the visible page looks like an attack, because at the moment the guardrails inspect it, it isn’t one yet.

This matters beyond xAI because it targets the seam every guardrail sits on. Injection filters scan text for intent. Encryption means there is no intent to find until after the model has committed to decoding. Ars frames it as more evidence that prompt injection cannot be fixed at the root, the same conclusion the industry reached about agentic browsers earlier this month and has not acted on since.

Today’s Top Stories

Binance Now Lets AI Agents Trade Your Money

Binance launched Agent OS, which lets AI agents execute trades on users’ behalf, working with tools including ChatGPT and Claude Code. The guardrails are real but they are yours to configure: dedicated sub-accounts, permission scopes, withdrawal restrictions. Binance itself has limited visibility into why an agent placed a given trade.

Kraken, Coinbase and OKX have made similar moves opening infrastructure to agentic trading over the Model Context Protocol. So the pattern for the day is an exchange handing agents spending authority while the guardrail literature says the instruction channel into those agents is not defensible. Those two stories published within hours of each other.

Slack Turns Channels Into Coding Sessions

Slack is launching Slack Code, dedicated channels for vibe-coding with AI agents rather than switching between a chat window and an editor. The channels are open and project-specific, with per-user tabs, change diffs, and HTML previews before anything ships.

The bet is architectural. Slack is wagering that agent work belongs where the team already argues about the work, not on a separate IDE surface. If that holds, the competitive question for coding agents stops being model quality and starts being which conversation you already live in.

Callosum Raises $100M to Stop Defaulting to Nvidia

London’s Callosum raised a $100M seed led by Atomico, with Plural, DCVC and a significant check from the UK’s £500M Sovereign AI Fund, that fund’s first publicly disclosed investment. Bloomberg reported the round as one of the largest seeds ever raised by a European startup.

Founded in 2025 by Cambridge neuroscientists Danyal Akarca and Jascha Achterberg, Callosum builds systems software that decomposes a workload and routes each task to the cheapest model and chip that can handle it, rather than sending everything to top-end silicon. It lands four days after Stripe agreed to buy OpenRouter for a reported $7 billion. Routing is being priced as infrastructure now, not as a feature.

Debian Is Voting on Whether to Ban LLM-Written Code

Debian Developers are ranking eight ballot options on LLM-assisted contributions, in a vote running through August 28. The choices span an outright Social Contract amendment banning “any contributions to Debian written with the use or assistance of large language models,” a conditional-approval statement covering tooling licensing, attribution, accountability and disclosure, an option framed around environmental impact, and “none of the above,” which would leave Debian with no policy at all. LWN has the full breakdown.

It drew six points on Hacker News and almost no coverage, which understates it badly. Debian sits underneath a large share of production Linux, and it is the first major distribution to put the question to a formal binding vote rather than a maintainer’s judgment call.

Anthropic’s Enterprise Venture Buys a Consultancy

Ode, the joint venture Anthropic set up with Wall Street firms including Blackstone, is announcing its first acquisition since launching in July: an AI consultancy, bought to accelerate Claude adoption among enterprise customers. Worth flagging that this is single-source and paywalled. The target company’s name sits behind the paywall, and no other outlet had it at the time of writing.

Quick Hits

  • Security: CISA, the FBI and the NSA warned that attackers are using AI to generate exploit scripts against Siemens S7 controllers in US water systems, hitting facilities in Minnesota, Michigan, Arkansas, Georgia and New Jersey. Rural systems are most exposed.
  • Security: Alation, an enterprise data catalog vendor serving roughly half the Fortune 1000, confirmed a cyberattack, declining to say whether data was stolen or how many customers were affected.
  • Supply chain: The Register reported a near-miss “hallusquatting” incident, where an agent recommended a plausible-looking package an engineer nearly installed. Attackers pre-register the names coding assistants reliably hallucinate.
  • Research: A paper announced today finds test-time scaling fails at picking, not generating. The best answer in a sampled pool keeps improving with more compute, but reward models correlate only ρ≈0.12 with actual quality, so systems cannot find it. Only candidate fusion beats a single sample.
  • Research: Harvard released IB-HL-ET, a 217 billion token corpus from 983,000 digitized library volumes across roughly 250 languages, annotated per paragraph rather than aggressively filtered. A large, legally clean, non-web pretraining source at a moment when web data is both exhausted and contested.
  • Legal tech: NetDocuments launched AI Tabular Review for M&A due diligence, and Avvoka is putting its drafting engine inside Harvey. Neither disclosed customers or pricing.
  • Policy: The UAE formalized a program to move 50% of federal government operations to agentic AI within two years. The framework governing which decisions a machine may make autonomously remains unpublished.
  • Politics: Axios reports local anger over AI data centers is scrambling the 2026 midterms, a day after its scoop that GOP operatives are calling data centers politically radioactive.
  • Community: The day’s biggest AI thread on Hacker News was not a launch. It was dontpastetheai.com, a one-page etiquette site arguing that pasting unedited model output at a colleague is disrespectful. 706 points, 349 comments.

What This Means

Read today’s stories in the order they published and you get a clean split. Institutions spent the day handing agents more authority: an exchange gave them trading accounts, Slack gave them a seat in the channel, the UAE committed half a government’s operations to them. Practitioners spent the same day building fences. Debian is voting on a ban. A guide to stripping AI features out of your browser via enterprise policy files hit the front page. So did an etiquette site whose entire argument is that model output should not reach another human unfiltered.

The Grok finding is what connects them. The defense that failed today was not a weak one, it was the standard one, and it failed to a technique with no novel machine learning in it at all. Anyone can encrypt a string. When the gap between “agent can spend money” and “agent’s instruction channel is trustworthy” gets measured this publicly, the pushback showing up as distribution policy and workplace norms rather than as vendor patches starts to look less like reflexive AI skepticism and more like the only lever that actually moves.

Ready to automate your busywork?

Carly schedules, researches, and briefs you—so you can focus on what matters.

See what people say

"Before Carly, I relied on a Calendly link, but the whole process felt impersonal and not very professional. Carly changed that by handling all the back-and-forth, so I'm no longer stuck in endless email threads trying to line up schedules.

Now Carly reaches out to candidates, shares my real-time availability, lets them pick a slot, then sends a Zoom link and drops it straight into my calendar. She sends reminders to both of us before each call, which has significantly reduced no-shows and last-minute confusion.

On top of scheduling, Carly acts like a full executive assistant, sending me my schedule the night before so I can prepare for each call. It reminds me of the old x.ai assistant, but Carly is noticeably smarter, faster, and better suited to my healthcare recruitment business."

Gus Ibrahim, Founder & Director, IHR