AI Radar for Companies — Saturday, August 29, 2026
· CompaniesAutomation
Saturday is about who your company can trust. Forcepoint X-Labs put 472 characters of invisible text into an email with 537 visible characters and got the AI summary to move an invoice due date from August 21 to September 3: ten attempts, ten successes. The same day, over a hundred companies signed an open letter warning that AI-assisted cyberattacks will become widespread in the coming months. Andreessen Horowitz raised $1.1 billion to invest only in the physical layer of AI, a federal judge declared the Pentagon's ban on Anthropic illegal, and DigitalEurope, representing 56,000 companies, called to accelerate the 20 billion euros destined for AI gigafactories.
The radar from Friday was about who keeps the warehouse of open AI; Saturday's is about who you can trust: the email summarized by your copilot, the provider giving you the model, and the money deciding what will exist two years from now. Forcepoint demonstrated that 472 characters of invisible text hidden in an email are enough for an AI summarizer to change an invoice due date, and it worked in ten out of ten attempts. Meanwhile, Andreessen Horowitz raised $1.1 billion to invest exclusively in AI hardware, a federal judge struck down the Pentagon's ban on Anthropic, and the European tech lobby put a number on the counter: 20 billion euros for gigafactories.
472 invisible characters change the invoice your AI summarizes, and the attack worked ten out of ten times
Forcepoint X-Labs published a textbook controlled test yesterday: an email with 537 visible characters to which they added 472 characters hidden via HTML—zero-sized, colorless text—so the model received 1,009 characters while the human saw just over half. The hidden instructions did exactly what they asked: the summary moved an invoice's due date from August 21 to September 3 and deleted a person's name from the text. Ten runs, ten successes. The test was done with Claude Haiku 4.5, but researcher Ben Gibney clarified that the attack isn't against Outlook, nor a specific summarizer, nor that model: it's against the habit of feeding unverified email into an LLM without any barriers in between. On the same day, more than a hundred companies—OpenAI, Anthropic, Google, Microsoft, CrowdStrike, Okta, Fortinet—signed an open letter warning that AI-assisted cyberattacks will become widespread in the coming months. For your company: if you have automatic email summarization enabled in Outlook, Gmail, your CRM, or an agent that empties the admin inbox, this already affects you and you don't need to update anything to fix it. Three rules you can issue in writing today that cost zero money. First: no summary triggers an action with consequences—paying, changing an account, moving a due date, approving an order; the summary guides, the original decides. Second: amount, IBAN, and due date are always read from the attached document, never from the text drafted by the model. And third, the cheapest of all: any bank account change communicated by email must be confirmed by phone to a number you already had saved before receiving it. If you also have your own agent reading email, convert it to plain text before passing it to the model and keep it read-only. Source
Andreessen Horowitz raises $1.1 billion for hardware only: capital has moved beneath the software
a16z announced the Machine Age fund yesterday, $1.1 billion dedicated exclusively to the physical layer of AI: processors, memory, networks, storage, cooling, electrical infrastructure, robots, and even the land where data centers are built. It is signed by five partners—Ben Horowitz, Martin Casado, Raghu Raghuram, David Ulevitch, and David George—and the shift is ironic coming from the firm that has spent fifteen years repeating that software is eating the world: their own argument now says the limits are below the application layer, in memory bandwidth, chip availability, power delivery, and manufacturing capacity. For your company: the useful takeaway isn't where the money is going, but where it is leaving. The layer where you buy—applications, agents, connectors, automation tools—is exactly the one that has stopped attracting new capital, and in two years, that doesn't translate into better products but into consolidation: the small providers currently supporting your automations will be sold, merged, or closed. This is not a reason not to hire them; it's a reason to hire them with an exit strategy. Before signing the next tool, check three things: that you can export your data as well as your configurations and flows in a format that works outside of it; that the critical process doesn't depend on a single niche piece with no known alternative; and that the contract states what happens to your installation if the company changes hands. Half an hour of reading now saves you from rushing to redo an entire process later. Source
Judge strikes down Pentagon's ban on Anthropic: your AI provider can fail for non-technical reasons
Federal Judge Rita Lin issued a 59-page ruling yesterday against the U.S. Department of Defense: she declared illegal the supply chain risk label with which the Pentagon banned Anthropic after the company refused to lift its usage limits—lethal autonomous weapons and mass surveillance of citizens—and defended that refusal in public. The resolution finds violations of the First and Fifth Amendments and federal administrative law, leaving a phrase that will be quoted often: the hollow invocation of national security is not a blank check to punish those who criticize the Government. The context is that in February, the Administration ordered all agencies to stop using the company's products. For your company: this isn't about U.S. politics; it's about where you have concentrated risk. For six months, any company that had built its operations on Claude and sold to the public sector there was left without a provider due to a decision that had nothing to do with the model's quality, price, or technical availability. The defense is boring and it works: have your applications talk to the model through your own layer or a router, and not with SDK calls to a provider scattered throughout the code; have a second model already tested with your real use cases and its instructions tuned, because the day you need it, there's no time to tune them; and read the acceptable use policy before building on top, because the limits that seem irrelevant today are the ones that decide if you're in or out tomorrow. The flip side is reassuring: a provider that defends its limits in court is more predictable than one that changes them without notice. Source
Europe puts 20 billion into AI gigafactories and opens doors to industrial companies
DigitalEurope, the lobby grouping companies and associations representing 56,000 European businesses, called on Friday for an ambitious public-private partnership to move European AI from pilot projects to industrial-scale applications. Behind the request is money with a name: InvestAI, the European Commission initiative, aims to mobilize 200 billion euros, of which 20 billion are destined for AI gigafactories, and the Commission and the European Investment Bank have agreed to work together to turn consortium proposals into bankable projects. The operational window is called the Apply AI Alliance: a forum that brings together AI providers, industrial companies, universities, and administrations, focused on six sectors—manufacturing, energy, health, mobility, agri-food, and communications. For your company: a gigafactory is not a matter for an SME, but the consortium surrounding it is. The way to get a European fund to pay for your first pilot is not to apply for the grant on your own, but to enter as an industrial partner in a project that needs exactly what you have: a real process, industry-specific data, and someone willing to test. Two concrete steps if you are in one of those six sectors: ask your industry association if it already participates in the Apply AI Alliance and what consortia it has open; and have a one-page use case ready with the process, the data you have available, and the estimated savings, which is exactly the document they will ask for. And in the meantime, don't sit and wait: public money arrives with an eighteen-month delay, and the automation you launch this quarter pays for itself much sooner. Source
What to watch tomorrow?
The email injection issue has a possible and very specific response: see if Microsoft, Google, or any summary provider announces that it marks incoming content as untrusted before passing it to the model, which is the only real mitigation; until then, you set the control in your procedures. And watch for whether the Pentagon appeals the ruling, as that will determine if the case remains an isolated episode or becomes the precedent that sets the limits of how far a Government can go with an AI provider that disagrees with it.