In partnership with

🧠 THAT ONE AI - This Week’s Signal

Here’s what’s shaping AI right now - without the noise:

  1. 🪟 Microsoft rebuilt Copilot into three surfaces

  2. 🔓 OpenAI agents posted 53 user images on the open internet

  3. 💻 Microsoft stopped calling them AI PCs

  4. 🧠 Give your agent its own identity

  5. 🧰 Tools worth testing

🪟 Microsoft Rebuilt Copilot Into Three Surfaces

Satya Nadella announced the largest Copilot update so far on Friday. Microsoft folded several separate tools into one system for work.

The new Copilot has three parts. Home is the main interface, and it puts Copilot Chat next to Office. Code is the coding hub. Autopilot is the personal agent, and Microsoft called it Scout before this release.

Cowork now sits inside Home as well. That is where Microsoft is putting agent work for ordinary employees.

Microsoft also showed a feature named Today. It is a personal command centre, and it is not available yet. The new Copilot reaches Microsoft's Frontier program over the next few weeks. Read the announcement.

The bigger signal: 👉 Microsoft has stopped selling a chat window. It is selling a place to work, with the model underneath. If your product is one feature inside somebody's day, that is the shape you now compete against.

1,000+ Claude Prompts Top Professionals Actually Use at Work

Claude can be your analyst, editor, and strategist.

But most professionals are using it to fix grammar.

These 1,000+ Claude prompts take it from grammar tool to your most powerful AI work assistant.

Sign up for Superhuman AI and get:

  • 1,000+ ready-to-use Claude prompts to get real work done in minutes — researched, tested, and used by professionals at Google, Microsoft, and NASA

  • Superhuman AI newsletter (4 min daily) so you keep learning new AI tools and skills to stay ahead in your career — the prompts are just the beginning

🔓 OpenAI Agents Posted 53 User Images on the Open Internet

OpenAI disclosed that unsecured agents published 53 user images online. The company did not know it was happening.

This is part of a wider pattern. The same agents reached an Australian government website and also exposed sensitive data. OpenAI has paused training on new models.

OpenAI is not alone here. Anthropic, Meta, Google and other labs have all reported similar events.

New reports say the top labs are now investigating tens of thousands of security probes. Read the report.

The bigger signal: 👉 Every one of these incidents came from an internal disclosure. No detection system found them. If you run agents in production, assume the same is true of yours, and write the logging before you need it.

💻 Microsoft Stopped Calling Them AI PCs

Microsoft has dropped the "AI PC" branding. The reported reason is simple. Buyers did not want it.

The name arrived with a hardware requirement and a dedicated key. It did not change what people bought.

Microsoft now describes the same machines by what they do.

The Copilot rebuild announced on the same weekend tells you where the attention went instead. Read the report.

The bigger signal: 👉 A category name only works when customers already feel the problem. Two years of "AI PC" marketing moved nothing. Name the job, and let the model stay invisible.

🧠 That One AI Tip: Give Your Agent Its Own Identity

A lab with a security team disclosed that its agents published 53 user images and it did not notice. Your setup is smaller. It is also probably running on your own credentials.

Most people wire an agent up by handing it the keys they already carry. The agent then has exactly the access you have, and the logs record your name.

Step 1. Create a separate account for the agent

Give the agent its own user or service identity, separate from the one you sign in with. The point is that every action it takes appears under a name you can search for and switch off in one click.

Do this even for a single local agent. It costs 5 minutes.

Step 2. Scope the permissions down

Start from nothing and add only what the current task needs. Four rules cover most cases:

Read-only wherever the task allows it
No delete on anything
No billing access, ever
No user or permission management

If a task needs a write, give it write on one resource rather than the whole account.

Step 3. Allowlist the network

This is the step that would have caught the image leak. An agent that can reach the whole internet can publish to the whole internet.

# allow only what the job needs
allow: api.yourcompany.com
allow: api.anthropic.com
allow: raw.githubusercontent.com
deny:  *

Run the agent inside a container with that egress policy. If it tries to reach anything else, you get an alert and the request fails.

Step 4. Require approval for actions that leave your system

Sort every tool your agent can call into two groups. Reads and internal writes run on their own. Anything that sends, publishes, pays or deletes waits for a human.

Write the list down. An agent with 14 tools and no list is an agent nobody can reason about.

Step 5. Log the tool calls, not the chat

A chat transcript tells you what the agent said. A tool-call log tells you what it did, and that is the record you will need. For each call, record the time, the identity, the tool name, the inputs and the result.

Keep that log somewhere the agent cannot write to. An agent that can edit its own log has no log.

Step 6. Set an expiry

Give every agent credential a date. 30 days is a reasonable default. The forgotten integration is the one that hurts you, and an expiry date removes it without anyone remembering to.

The bigger signal: 👉 The labs found their incidents inside their own logs. An alert never reached them first. Six steps above, and only one is about detection. The other five shrink what an incident can reach in the first place.

That One AI 🧰 TOOLBOX

A few tools quietly worth exploring:

  • 🔁 Rollouts → Cursor's bot watches your deploys, catches regressions and triggers a rollback.

  • ⚖️ Cuey → Puts the answers from the big three chatbots side by side in one window.

  • 🎚️ GoodVibes → Filters X, Reddit, YouTube and other feeds by the kind of thing you want, described in plain words.

  • 🎙️ Hemory → Records your real conversations on iPhone or Apple Watch and serves them to your agents over MCP as searchable, speaker-labelled moments.

The Hidden Cost of AI in B2B Service

A fast answer and a coordinated one are not the same thing. When AI resolves a B2B customer issue without looping in the teams who have to deliver on it, you get confident responses nobody actually signed off on.

A new briefing paper from Harvard Business Review Analytic Services, sponsored by Front, examines the coordination gaps that open up when transactional AI tools meet multi-team B2B service, and how leading companies are using AI to close those gaps instead of widening them.

Read the briefing paper for the questions to ask before your next AI investment.

🔚 EXIT NODE

Microsoft spent two years selling the letters A and I on a laptop lid, and this week it stopped. In the same weekend it shipped a rebuilt Copilot whose three product names mention AI nowhere at all.

The lesson sits in the other two stories as well. The Pentagon does not care which model is top of the index. The 53 leaked images came from an agent that nobody had fenced in.

The capability race has an audience of about 5,000 people. Everyone else is buying a job that gets done.

Before you go, what do you want us to cover next? Reply to this email and let us know.

See you next issue.