AI Radar for Business — Thursday, August 20, 2026
· CompaniesAutomation
Today, AI for business is about where what you've connected lives and who can touch it. Microsoft closed the CVE-2026-24301 flaw on August 18, dubbed CoSnitch by Varonis, which was reported on December 31 and allowed one-click execution of attacker instructions, querying connected Gmail, Drive, Calendar, and OneDrive, and persistently poisoning assistant memory—something that survives password changes, logouts, and device re-registration. Ant Group presented the same day what it calls China's first complete agentic commerce platform: merchants convert pages, products, and flows into MCP skills and tools invoked by their agent Ah Bao, with over 10,000 services, 16 car manufacturers, and 100 million free tokens per user. In infrastructure, European data center projects for 2026-2028 are located an average of 175 kilometers from major cities compared to 46 previously, with rural Spain among the destinations and $725 billion in spending by major cloud providers this year. And in finance, Unitree debuted in Shanghai with a 629% jump at the opening and closed 460% up after raising 6.1 billion yuan.
Yesterday's AI radar was about giving AI permission to act; today's is about where what you've connected lives and who can touch it. Microsoft has taken nearly eight months to fully close a Copilot flaw that allowed for assistant memory poisoning with a single click—a memory that survived password changes—while Alipay is turning its merchant catalogs into callable tools so that the buyer can be an agent. In infrastructure and finance, European data centers are moving to the countryside—with rural Spain among the destinations—and the Shanghai stock exchange opened with a 629% premium for the first humanoid robot manufacturer to go public.
One click poisoned Copilot's memory, and changing the password didn't clear it
On August 18, Microsoft closed vulnerability CVE-2026-24301, dubbed CoSnitch by Varonis, which reported it on December 31: it blocked the automatic execution of instructions in February and has needed until now for the full patch—nearly eight months. The attack chained three pieces: an undocumented parameter in the web address that executed the attacker's instruction as soon as the page loaded, querying connected applications—Gmail, Drive, Calendar, OneDrive—and sending the results to an attacker-controlled server, and persistent poisoning of the assistant's memory that survives password changes, session logouts, and even device re-registration. Microsoft limits this to the personal version of Copilot, stating that its business customers are already protected and need to do nothing, though several analysts dispute that limit. For your company: there are two takeaways, and the most uncomfortable one isn't the patch. The first is surface-level: the hole wasn't in your organization; it was in your employee's personal account with work email connected. So this week's task is to list which personal AI accounts have a company service hooked up—that box is checked by no one because it doesn't appear in your admin panel. The second changes your protocol: your incident manual assumes that changing the password and closing all sessions leaves the account clean. With an assistant that remembers, that is no longer true. Add a step today—clearing the assistant's memory—to the same script you use to revoke access; if it's not written down, it won't get done. Source
Alipay turns product listings into an agent-callable tool
On August 18, Ant Group presented what it calls China's first complete agentic commerce platform: merchants convert their pages, products, and workflows into MCP skills and tools that Ah Bao—Alipay's consumer agent launched in June—can invoke, with payment, identity, risk control, and delivery already integrated. It connects over 10,000 services, including KFC, Luckin Coffee, and Mixue, five mobile brands covering 70% of the market, and 16 car manufacturers. The push is subsidized with 100 million free tokens per user and reduced payment commissions, and CEO Cyril Han estimates that agentic commerce will grow rapidly over the next six to twelve months. For your company: this isn't about China; it's about the format. When the buyer is an agent, your product listing stops being a page that someone reads and becomes an interface that someone calls: price, stock, delivery time, and conditions must be in searchable fields, not inside a pretty image or a PDF. What you can do now, without waiting for this to arrive here, is already half-built: correct and updated product feeds, structured data on the listing, an access point that returns real availability and price, and a written policy on what an agent can reserve or buy without speaking to a person. And if you sell to other businesses, the same applies: your catalog and your rate sheet are the first things the buyer's agent will read. Source
AI data centers are moving to the countryside, and rural Spain is on the list
Reuters published today, with data from JLL, that European projects planned between 2026 and 2028 are located an average of 175 kilometers from major cities, compared to 46 for campuses delivered between 2022 and 2025: of nine European projects over one gigawatt, only one is planned near a major city—Paris—with the rest spread from rural Spain to northern Sweden. Electricity and land are driving this: a megawatt of land with power costs 2.36 million euros in primary markets, 978,000 in secondary cities, and 512,000 in tertiary zones, with Amsterdam at the expensive extreme near 2.7 million. Greenfield projects are moving to 39% of the future portfolio compared to 8% of what has already been delivered, and the four largest cloud providers will spend about 725 billion dollars this year, 77% more than in 2025. For your company: there is a local takeaway and a contract takeaway. The local one, if you are in one of those areas: what's arriving isn't just concrete; it's electrical grid, fiber, and a municipal negotiation where it's better to be at the table before it's signed, not after. The contract one is more immediate and applies to everyone: ask your cloud or model provider in writing which region your data is processed in and where it stays, because when capacity moves, new regions are activated and loads are distributed without anyone notifying you. If your GDPR compliance depends on processing taking place in the European Union, that is set in the contract and verified in the console; it shouldn't be assumed. Source
The stock market pays a 629% premium for humanoid robots; your automation is still software
Unitree debuted today on Shanghai's STAR market: it listed at 150.80 yuan, opened at 1,100—629% above, a valuation of about 66 billion dollars—and closed at 845, still 460% up, with a market cap of 342 billion yuan and 23.2 billion traded in the session. It placed 40.45 million shares, 10% of the enlarged capital, and raised 6.1 billion yuan; in the retail segment, there were 9.8 million accounts fighting for 9.7 million shares. It is the first humanoid robot manufacturer to list in mainland China. For your company: there is no stock advice here, and there is no automation plan for next year either. The useful data is the gap between what the market pays and what can be bought and installed today: humanoid robotics is being funded as if it were ready and delivered as what it is—a young product—while the savings you can measure in 2027 still come from software that removes manual steps from your processes. And there is a commercial consequence you'll notice sooner: when a category becomes this expensive, your machinery and industrial automation providers start calling what they were already selling "AI." Always ask them for the same number—how much the cost per unit produced or per order served decreases, measured—and compare it with what you save by automating paperwork, which is more boring and much cheaper. Source
What to watch tomorrow?
Tomorrow is the deadline CISA gave to US federal agencies to patch a critical flaw in the Ray framework (CVE-2025-62593, versions prior to 2.52.0), the tool many companies use to train and serve models: if your team uses it in any cluster or in continuous integration, that is Thursday's task, because there is already a campaign turning GPU clusters into mining botnets. And it’s worth seeing if Microsoft fully clarifies if CoSnitch also affected corporate Copilots: several analysts don't believe the boundary they've drawn.