Stories

Microsoft embeds 6,000 engineers in clients, and an AI agent runs a full ransomware attack

Google starts training its AI on Lens photos and voice searches by default, and a study finds AI writing tools shift the meaning of what people say.


5stories
4minute read
In This Edition

Microsoft is placing 6,000 of its own engineers to work inside other companies. In the same week, it cut about 4,800 jobs, roughly 2.1 percent of its staff.

The engineers go into a new unit called Frontier Company, a $2.5 billion effort to build and run AI systems on site at large clients rather than sell software and leave. Amazon's cloud arm committed $1 billion to the same model days earlier, and OpenAI and Anthropic already operate their own versions.

These units exist because of a number that has unsettled the industry. MIT's Project NANDA found that 95 percent of company generative-AI pilots deliver no measurable effect on profit. Firms bought chatbots and copilots, then watched them stall somewhere between a good demonstration and any result a finance chief could point to.

Frontier's engineers co-design each client's systems, put them in use, and keep improving them. That labor, not the software, is the real cost of getting enterprise AI to work, and it raises two questions a buyer rarely faced before: who owns what these engineers build, and where does it run.

The answer to the second is Microsoft's own Azure cloud. Systems built there cost more to move than to keep, whichever AI model runs inside them. The research firm Directions on Microsoft describes the deployment work as the price of acquiring a customer, earned back over years through Azure usage.


An AI agent broke into a company's database, encrypted it, and left a ransom note, all on its own. The security firm Sysdig, which documented the case and named it JadePuffer, calls it the first ransomware attack whose technical work ran from start to finish under a large language model.

The agent got in through a known flaw in Langflow, an open-source tool for building AI apps, that the target had left unpatched despite a fix issued in April 2025. From there it scanned for cloud credentials, moved across the network to a production database, and encrypted 1,342 configuration records before deleting the originals. It wrote the ransom note itself, with a Bitcoin address and a contact email.

What stood out was the speed and the independence. When a login failed, the agent read the error, switched its approach, and had a working fix in 31 seconds, narrating its reasoning in plain notes the whole way. A person still set up the operation and chose the target, but the model handled every skilled step in between. For years those steps each demanded expertise; an agent now chains them itself, which makes the old openings, unpatched software and credentials within easy reach, worth far more to whoever points one at a target.

There is one thing no payment can undo. The agent created its encryption key at random and never saved it, so the encrypted records cannot be recovered even if the victim pays.


Researchers at Oxford and Potsdam universities tested the AI writing helpers built into tools from Meta, Google, Alibaba, Mistral, and Elon Musk's xAI. When people wrote about sensitive subjects, the suggestions those tools offered changed the meaning of what the writers ended up saying.

The mechanism is ordinary. These assistants finish sentences and rewrite drafts, and a model leans toward particular words and framings. Accept enough of its suggestions and the finished text drifts from the point you set out to make. Earlier research on such tools found the pull is strong enough to shift the opinions people hold after writing, not only the words on the page.

This reaches straight into daily work. Staff draft customer replies, policy notices, and public posts with exactly these tools. The change is invisible in the moment, and it showed up across all five companies' systems, on the topics where a single word carries the most weight.


On June 10, Google split its long-standing activity control into a new setting called Search Services History, and for accounts that already had activity tracking on, which is the default, a Save Media option came switched on with it. It saves the photos you run through Google Lens, your voice searches, spoken phrases from Translate, Circle to Search screenshots, and files you upload, and it uses them to train Google's AI.

After Google uses a piece of media to train a model, it disconnects that media from your account and keeps it for up to four years. Deleting the original later takes it out of your history but not out of the copy already inside the training set.

For anyone who photographs a whiteboard, runs a contract through Translate, or asks a question about a client out loud, that material is now in scope by default. The switch is at myactivity.google.com, under Search Services History; Google says accounts issued through a school or university are left out.


In March, Fortune reported that JPMorgan had begun tracking the keystrokes, video calls, and meetings of its junior bankers, and the practice is now common: by a Harvard Business Review count, about 60 percent of large employers use monitoring tools, roughly double the level before the pandemic. AI has pushed them from spotting theft or fraud toward scoring ordinary daily work.

Cornell researchers found the tools can backfire, lowering output and pushing more people to quit. And the rules diverge by country, so a monitoring practice that is legal in one place a company operates can break the law in another.

Share This Brief
Microsoft embeds 6,000 engineers in clients, and an AI agent runs a full ransomware attack | Daily Brief | Inference Wire