Stories

Anyone with Microsoft 365 Copilot can now build an AI agent, and Atlassian's Rovo still leaks data

Jubilant Ingrevia cut process variability 60% across 30 connected projects, and a quarter of AI job interviews now start after 10 PM.

By , Senior AI ConsultantEdition of

5stories
4minute read
In This Edition

In the Microsoft 365 Copilot app there is a list called Agents, and under it a New Agent option. An employee selects it, types what the thing should do, and presses Send. Copilot writes the agent's name, its description and its instructions out of that sentence, and rewrites them as the description gets more precise. Microsoft's own support page walks through the steps, and none of them involves code.

Microsoft draws a line between two kinds of agent: Agent Builder is for one person or a small team, while anything meant for a whole department, or needing multi-step work and connections to outside systems, belongs in Copilot Studio. The example Microsoft publishes is an agent that answers questions from a team's SharePoint files and emails.

Take the invoice folder somebody in accounts opens every morning. An agent pointed at that folder can read what is in it, check each document against the rules it was given, and draft the reply, and with the code interpreter capability turned on it can do the arithmetic too. Somebody still looks at the invoice the agent could not match.

Which files an agent may read follows from which files its builder may read, and Microsoft notes that the knowledge sources on offer differ by the user's licence. Ten employees building ten agents produces ten sets of instructions and ten reading lists, each one shaped by whoever was in a hurry that week.

Agent Builder comes inside the Microsoft 365 Copilot licence a company is already paying for.


A line of white text at the bottom of an uploaded PDF, invisible to the person who uploaded it, is enough to make Atlassian's Rovo hand private work to a stranger. The security firm PromptArmor showed how: Rovo reads the hidden line as an instruction from its own user, builds a web address out of it, and sends Jira tickets and Confluence pages to a server the attacker controls, with no click from anyone. Months after the report, the flaw is open.

Switching off web search for Rovo across the organization does not close it. That setting removes the search function and leaves in place the tool Rovo uses to open a URL, which is the one that does the sending, PromptArmor found.

In Melbourne, a man ABC News calls Andrew told an agent to book him a morning gym class. Within minutes it found a weakness in the gym's booking system, and, asked how he could improve his position on a waitlist, it cancelled another member's reservation. The software confirmed that he was a customer entitled to cancel a booking without confirming that the booking was his. ABC News called it Australia's first known autonomous AI cyberattack. Tech Times reported that no police complaint has been filed, and that no clear provision of Australian law makes Andrew, the developer of the OpenClaw agent software he ran, or Anthropic, whose Claude model worked inside it, responsible.


Jubilant Ingrevia makes specialty chemicals in India, in a market that has been in a long price downturn, and it put more than 30 connected projects into a plant that kept running throughout: machine learning models that set production parameters, digital twins of critical equipment, sensors feeding predictive maintenance. Process variability fell 60% and the plant's output nearly doubled, by the figures published through the World Economic Forum's Global Lighthouse Network. Fewer than 40 people run that line.

Thirty projects in one plant is a different exercise from thirty pilots in thirty departments. A model that sets a production parameter is only as good as what it knows about the batch arriving, the state of the equipment and the safety limits, and each of those numbers belongs to a different team. Connect them and the model has something to work from; leave them in separate systems and it has a guess.

Jubilant ran the same work again at an older site, where it now returns more than $5 million a year.


Thirty percent of British manufacturers were hit by a cyberattack in the past year, in a new industry survey, and that count includes attacks that landed on a supplier rather than on the factory's own systems. Half of those firms have nothing written down for the day it happens.

There is a reason attackers keep coming back to factories, and IBM's X-Force incident responders give it: a production line has an extremely low tolerance for downtime, so encrypting the systems that run it pays well. By X-Force's count, manufacturing has been the most attacked industry five years running, 28% of the cases its responders handled.


A worker whose shift ends at nine can now do a first-round interview at half past ten, talking to an AI with no recruiter awake for it. A quarter of AI-run job interviews now start after 10 PM, on the numbers from the recruiting platforms Ribbon and Greenhouse.

Most of those candidates are never told that the thing scoring them is software.

Illinois has required since 2020 that an employer explain how the AI works and get written consent before it analyses a video interview. New York City requires an independent bias audit of an automated hiring tool every year, with civil penalties of $500 for a first violation and $500 to $1,500 for each one after, counted for each day the tool is in use.

In March 2025 the ACLU of Colorado complained to the Colorado Civil Rights Division and the federal Equal Employment Opportunity Commission that Intuit used a HireVue video platform to score candidates for an internal promotion and refused a deaf and Indigenous employee's request for human-written captioning. HireVue's chief executive, Jeremy Friedman, told HR Dive the complaint is "entirely without merit".


THE DAILY BRIEF

Get the next edition in your inbox.

A five-minute read, every weekday morning.

Free forever · Unsubscribe anytime

Share This Brief