In partnership with

7wData Ins7ghts

So, What Actually Happened?

Friday afternoon I went looking for one thing and kept finding the same hole. A security team published a count of AI-built applications sitting on the open internet: 5,000 with no login screen, roughly forty percent of them leaking real data. Fine, I thought, that is a security story. Then the legal press, where three federal courts have now ruled on whether a lawyer's chat with a model stays privileged. We scanned 190,000 articles this week so you don't have to. And Europe's financial rulebook came into full force over AI vendors selling into banks. That happened the same week Harvey went out for $500M at $15.5 billion. Different desks, different vocabulary, same missing thing underneath. Two years in, we are very good at deploying this stuff and still terrible at keeping a list of where we deployed it.

The Bottom Line: Two years of AI got built without a paper trail, and the paper trail is what everybody suddenly wants to see.

How Jennifer Aniston’s LolaVie brand grew sales 40% with CTV ads

For its first CTV campaign, Jennifer Aniston’s DTC haircare brand LolaVie had a few non-negotiables. The campaign had to be simple. It had to demonstrate measurable impact. And it had to be full-funnel.

LolaVie used Roku Ads Manager to test and optimize creatives — reaching millions of potential customers at all stages of their purchase journeys. Roku Ads Manager helped the brand convey LolaVie’s playful voice while helping drive omnichannel sales across both ecommerce and retail touchpoints.

The campaign included an Action Ad overlay that let viewers shop directly from their TVs by clicking OK on their Roku remote. This guided them to the website to buy LolaVie products.

Discover how Roku Ads Manager helped LolaVie drive big sales and customer growth with self-serve TV ads.

The DTC beauty category is crowded. To break through, Jennifer Aniston’s brand LolaVie, worked with Roku Ads Manager to easily set up, test, and optimize CTV ad creatives. The campaign helped drive a big lift in sales and customer growth, helping LolaVie break through in the crowded beauty category.

The Tracks That Matter

1. Five Thousand AI-Built Apps Are Running With No Lock

RedAccess researchers swept Lovable, Replit, Base44 and Netlify and found more than 5,000 AI-generated applications running with virtually no security or authentication. About forty percent of the unprotected ones were exposing sensitive data. These are not prototypes on somebody's laptop. They are live URLs with real databases behind them and identities that reach real records. Replit's CEO responded that public apps being public is expected behaviour, which is true and also beside the point, because the security team does not know the app exists. Forrester put the same finding in one line this quarter: application sprawl is outrunning governance. Zscaler's researchers published their own read on frontier AI and enterprise readiness the same day.

Here's what works: Ask security for a list of every AI app builder your company pays for. The distance between that list and reality is your exposure.

2. Harvey Wants $15.5B While Courts Decide If Legal AI Waives Privilege

Three federal decisions, Heppner, Warner and Morgan, have now tested whether attorney-client privilege and work product survive a lawyer's use of generative AI. The short answer is only with safeguards in place. A platform's terms of service can hand your confidentiality away, and Warner drew a ”tools, not persons” line for deciding when that happens. The capital is not waiting for the case law. Harvey is reportedly raising $500M at $15.5 billion, the biggest bet yet that law firms will run their work through a model. Litigators, meanwhile, have started arguing about preserving AI records in discovery, which makes the chat log evidence.

Here's what works: Read what your AI vendor's terms say about your inputs before the next rollout, not after a judge asks.

3. Europe's Rulebook Reaches The AI Vendors Banks Never Listed

DORA is in full application, so its technology-risk obligations are enforceable rather than aspirational, and the question now landing on frontier-AI companies is whether they count as technology providers to European financial firms. If they do, a bank cannot simply use one. It has to name it in the paperwork a supervisor can ask for, next to every other critical supplier. Most AI pilots in European banks did not start in procurement. They started in a business unit with a corporate card. That gap closes by inspection, not by choice. Regulators are pulling the same direction elsewhere: the EU and California are converging on transparency rules aimed at enterprise deployments.

Here's what works: Pull your third-party technology register and find the AI tools your teams use daily that are missing from it. Add them before somebody else does.

Quick hits:

  • A former bitcoin miner became AI infrastructure. Firmus raised $2 billion at a $10.5 billion valuation with Nvidia and Blackstone-managed funds behind it, which is what happens when stranded power becomes worth more pointed at inference than at coins.
  • Copilot passed twenty million paid seats. Microsoft's assistant reached 20 million paying users, a number worth holding next to those 5,000 unregistered apps: governed AI is easy to count, and counting is not the hard part.
  • Data-centre power got its own venture round. Emerald AI raised $90 million for software that flexes data-centre demand against the grid, a bet that the binding constraint has moved from chips to substations.

Signal vs. Noise

🟢 Signal: enforceable obligations. Actual duties gained real weight across Friday's coverage while the phrase everyone uses lost it. Three federal privilege rulings, DORA in full force, the EU and California converging on transparency. Those are court orders and calendar dates, not intentions. Most coverage still files them under ”AI policy” and misses that the deadlines have already landed.

🔴 Noise: ”AI governance.” The label pulled one of the heaviest volumes of any idea on Friday while its hold on everything else thinned out. It now covers a committee, a vendor category, a policy PDF and a federal ruling. When one phrase means four things, it has stopped naming work and started naming a meeting.

Learn How to Stay Visible in the AI Era

AI is changing how customers discover businesses. If your SEO strategy is built for yesterday's search, your visibility is already slipping. Learn how to optimize your content for today’s AI search results with BELAY’s latest report..

From the 190K

We scanned 190,000 articles this week. Here's what no one's talking about:

A security team counted 5,000 live applications nobody had registered, three federal courts ruled on AI conversations nobody had preserved, and Europe's financial rulebook came into full force over AI vendors nobody had listed.

Each of those lands on a different desk. The security press writes up the exposed apps. The legal press covers the privilege rulings. The financial-regulatory press handles DORA. Read them on the same morning and they stop being three stories. Two years of AI adoption ran faster than anybody's ability to write down what was adopted, and the bill for that arrives as a records request rather than an invoice. That is a different problem from the one most AI budgets were built to solve. There is no model upgrade that produces a list you never kept.

What changes on Monday is unglamorous. Before approving the next capability, find out how many AI systems your company is already running that no register, no ticket and no contract knows about. That number is almost never zero, and it is the number a regulator, a plaintiff or an attacker reaches first.

By The Numbers

Deep Dive: The Setlist Nobody Filed

When I played out in Belgium, the venue had to file a setlist. Every track, every night, sent off so the people who made the music got paid. Nobody in the room ever thought about it. The paperwork was the least interesting thing in the building, right up until it was the only thing anyone could check.

The apps nobody put on the list
An app builder hands a marketing analyst a working application in an afternoon. No repo, no ticket, no scan, no owner. Five thousand of those turned up on the open internet in one sweep, and forty percent of the unprotected ones were handing out real data. They work. That is exactly why nobody escalated them.

The conversations nobody kept
A lawyer pastes a draft into a model at eleven at night. Fast, useful, and depending on the platform's terms, possibly no longer privileged. Three federal courts have taken that question seriously this year, and litigators are now arguing about whether those sessions should have been preserved. The work was real. The record of it was not.

The vendors nobody named
A European bank runs a pilot on a corporate card. Legal never saw it, procurement never logged it, the supervisor's register does not know it exists. DORA is in full application, so that gap is no longer a policy debate. It is a question somebody gets asked, with a date on it.

What Actually Works

  1. Inventory before capability: count what is already running before approving the next tool.
  2. Name the app builders explicitly: your security scope probably says ”software development.” AI app builders are not that, and they fall straight through the wording.
  3. Read the terms for what happens to your inputs: confidentiality lives in the contract, not in the interface.
  4. Give the register an owner: models have owners. The list of models almost never does.

The music was always real. Only the tracks on the sheet ever got paid.

Build a digital marketing strategy that drives better results.

HubSpot Academy's Digital Marketing Certification covers SEO, email, paid ads, social, and AI — in just over 3 hours, at zero cost. Join 200,000+ professionals who have advanced their career with HubSpot Academy. Get started today.

What's Coming

Discovery Requests Start Naming AI Tools

Preserving AI records in litigation is already being argued as a spoliation question, which means the duty to keep a chat log arrives before anyone tells you it has. The first sanctions order over a deleted AI session will be reported as a legal curiosity. It will really be a retention deadline for everybody else.

Transparency Rules Stop Being Regional

The EU and California are converging on AI transparency rules with enterprise deployment in the crosshairs. When two of the largest blocs land on similar disclosure duties, multinationals stop maintaining two answers. Build for the stricter one now, because that is the one you will end up shipping everywhere.

Competition Authorities Join the Queue

Regulators are circling AI as a new frontier for competition enforcement. Nobody has a playbook for model distribution yet, which is precisely why the first cases will set the shape. If one provider carries a load-bearing workflow for you, that dependency is about to interest more people than your CFO.

For Your Team

Monday's meeting prompt: ”How many AI systems are running in this company right now that appear in no register, no ticket and no contract? And who finds that number first: us, a regulator, or somebody outside?”

Share-worthy stat: One sweep found more than 5,000 AI-built applications live on the internet with no authentication, and roughly 40% of the unprotected ones were exposing sensitive data. Every one of them was built by somebody trying to do their job faster.

Go deeper: Track where AI risk and spending are actually moving →

The Track of the Day

”The unit of risk is the running application: a live URL, a database behind it, an identity that reaches real records, and a builder who never filed a ticket.”
Orca Security

Every story above is a version of that last clause.

We scanned 190,000 articles this week so you don't have to. Data Pains → Business Gains.

Published: August 8, 2026 | Curated by Yves Mulkers @ Ins7ghts

1,300+ articles scanned. 7 stories selected. Our AI distills the noise into signal—in seconds. Get early access →

Know someone who'd find this useful? Share your unique referral link →

Want Your Own AI Intelligence Briefing?

Our platform analyzes 1,000+ sources daily and delivers personalized insights in seconds.

Join the Waitlist →

Founding members: Lifetime discount • Priority access • Shape the product