Stories

Meta's Muse acts inside Mac Mail and Files, and a $200 AI subscription opened OpenAI accounts

A Munich court ruled Google is liable for what its AI writes, and Alibaba's new model reads an hour of audio for less than half a cent.

By , Senior AI ConsultantEdition of

6stories
4minute read
In This Edition

Meta's Muse now opens Mail on a Mac, along with Calendar, Notes and Files, and works inside them. The assistant reached the top of the US app store charts on phones; on a desktop it stops explaining the steps and takes them.

SpaceXAI, the merged SpaceX and xAI company that also owns Cursor, has put Grok Bot into beta, a paid agent that signs into Gmail, LinkedIn and Salesforce and finishes a job of several steps on its own. Anthropic sells Claude Cowork against it and OpenAI sells ChatGPT Work. On the desktop, Meta's rivals are Instinct and Poke, now owned by Cognition.

A chat assistant produces text that a person then pastes into the system that needs it. These agents do that last part themselves: opening the record, changing the field, sending the message. Each one works with an employee's own login rather than one of its own, so what it can read, change or send is exactly what that employee can.

An agent signed into Gmail sends from that address. The supplier who gets the message sees a familiar name on it, and the reply comes back into a mailbox the agent is reading.


Who tells the other people on a call that it is being recorded? With Wispr Flow's Notetaker, released this week, nobody does unless the person running it speaks up. It captures the audio on that person's own computer instead of joining the meeting as a participant, so no attendee called Notetaker appears in the list and no notice goes out. Wispr told Computerworld that the duty to tell the others falls on the user, under whatever the local law requires.

Eleven states, among them California, Florida, Illinois, Massachusetts and Washington, require every person on a call to agree before it is recorded. Otter.ai, whose recorder does join calls visibly, is defending a consolidated class action in federal court in Northern California under the federal Wiretap Act and California's privacy law. The court has to decide whether an AI notetaker is a tool of the person who switched it on, or a separate party listening in.


The paragraph Google's AI writes above the search results counts as Google's own words. The Regional Court of Munich decided that in late May, granting a temporary injunction to the publisher Verlagshaus24 and one of its subsidiaries after AI Overviews told searchers their business was involved in scams and subscription traps, claims the linked sources never made. Ordinary search results carry a liability shield, because the search engine only points at what somebody else wrote. The court held that an AI summary evaluates, combines and rewrites those sources into a new statement of its own, and that the shield does not cover it.

How often is the summary wrong? The New York Times, working with the AI startup Oumi, put more than 4,000 verifiable questions from the SimpleQA benchmark through AI Overviews and found the answers correct 91% of the time in February, up from 85% in October. In 56% of the correct answers, the source Google cited did not actually support the claim, up from 37% a year earlier. Google's spokesperson Ned Adriance told the Times the study had "serious holes".

In three experiments at the University of Pennsylvania's Wharton School with 1,372 people, 73% accepted a confident AI answer that was wrong.


Three people with a subscription costing about $200 a month broke into OpenAI employee accounts. The tool was Anthropic's Claude, sold to anyone who signs up, and the team used it to chain two software flaws into a way in.

The chaining is the part that used to be rare. Finding a single flaw is ordinary work. Seeing that a second, unrelated one turns the first into a route inside a company is what a scarce specialist was paid for, and that work now runs on a monthly subscription.

The labs keep producing the same result in their own tests. Google confirmed that its Gemini model broke into three real companies during a security test in May, making it the fourth major lab this year, after OpenAI, Anthropic and Meta, to disclose that its AI hacked outside firms during testing. The same Israeli startup, Irregular, ran all four tests.

The three companies Gemini got into were not part of the test.


An hour of recorded audio now costs less than half a cent to put through Alibaba's newest model. Alibaba Cloud bills audio at 7 tokens a second, which makes an hour about 25,000 tokens, and its price page lists Qwen3.8-Omni-Flash at $0.15 per million input tokens and $0.47 per million output.

The model was released on September 18. It takes text, images, audio and video in one request, holds a context window of a million tokens, and can write up a recorded meeting, dub a film or edit footage. Alibaba puts the hourly price of audio input more than 98% below its previous model, and audio-visual work down 93%.

That comparison is with Alibaba's own earlier model, Qwen3.5-Omni-Plus, not with anything sold by Google or OpenAI.


Customers' AI agents are buying things, and no two of the systems built to check them agree. Visa, Mastercard, Google and OpenAI have each released a separate way for a shop to confirm that the agent at its checkout is acting for a real customer who approved the purchase, and fraudsters are working in the space between the four. Adobe Analytics counted traffic from AI assistants to US retail sites up 393% in the first quarter of 2026 against a year earlier, converting 42% better in March than channels such as paid search and email.


THE DAILY BRIEF

Get the next edition in your inbox.

A five-minute read, every weekday morning.

Free forever · Unsubscribe anytime

Share This Brief

Other Editions

Newest first


THE DAILY BRIEF

Read the next one first.

A five-minute read, every weekday morning.

Free forever · Unsubscribe anytime