So, What Actually Happened?
Wednesday, and I got stuck on one number in a research paper. A single polluted web page is enough to make an AI recommender name the wrong product, and it works 27% of the time. Replace the whole top three results and it goes to 73.8%. No jailbreak, no clever prompt. Just a page, sitting there, waiting to be read. We scanned 190,000 articles this week so you don't have to. Same morning, Palo Alto's threat team published where AI-written malware actually stands, and Morningstar and PitchBook started selling verified market data as the thing that keeps a bank's AI honest. I went looking for the model story. I kept finding the input story instead.
The Bottom Line: Nobody spent Tuesday arguing about what the models can do. Three separate rooms argued about what the models are allowed to read, and one of them attached an invoice to it.
Attackers have agents. So do you. Both act through identity, and neither waits for a human. Join security, identity, and AI leaders to master the operating model for the agentic era: defend against AI attacks, govern agentic identities, and recover any IdP at machine speed.
The Tracks That Matter
1. A Single Poisoned Page Bends What Your AI Recommends
Researchers built a benchmark called FORGE to test how easily AI recommenders can be fed a lie, and one contaminated page produced fooled rates up to 27%, rising to 73.8% when the top three sources were replaced. The uncomfortable part is the defenses. They tried four. Telling the model to be skeptical made things worse in some cases, consensus filters started suppressing real products, and re-ranking by credibility removed roughly one sixth of the fakes. Meanwhile Palo Alto's Unit 42 published its August read on AI-enabled malware, which is the same story from the other side: the people generating bad inputs now have generation tools too. Search engine optimisation just became an attack technique with a much shorter feedback loop.
Here's what works: Take your highest-stakes AI answer and log the pages it actually retrieved last month. If nobody owns that list, nobody owns the answer.
2. Morningstar And PitchBook Put A Price On Being Right
Morningstar and PitchBook are now feeding licensed investment data into enterprise AI for financial services, and the framing matters more than the deal. They are not selling a model or an agent. They are selling the guarantee that when a bank's AI says something about a private company, the number came from somewhere with a name on it. Two years of enterprise AI spending went to the reasoning layer on the assumption that the reading layer was free and roughly true. That assumption is what the poisoned-page work just took apart. Note who moved first here: the two firms whose entire business was already built on being the citable source.
Here's what works: When a vendor pitches you an AI answer, ask what they pay for their inputs. Free inputs mean somebody else chose them.
3. ByteDance And Hollywood Settled AI Copyright Without A Courtroom
ByteDance and the major studios reached a global deal on AI copyright protections, which is a genuinely different outcome from the last eighteen months of this fight. Courts have been slow, jurisdictional and unpredictable, so the two sides did what the music industry eventually did with sampling: priced it. What gets settled in a deal like this is not the philosophical question of whether training is fair use. It is the operational question of which catalogue a model may read, under what audit, for how long. That is a supplier contract, and it can be revoked. Every company building on a general-purpose model just acquired a dependency it did not sign for and cannot see.
Here's what works: Ask your model vendor which of their training and retrieval sources are licensed, and what happens to your outputs if one licence lapses.
Quick hits:
- Google licensed a database instead of building one. Google selected Rezolve AI's distributed database for its own stack, which is a useful reminder that even the largest infrastructure buyer on earth still buys the boring layer rather than rewriting it.
- Korea's GPU-efficiency play goes public. Lablup filed for a KOSDAQ listing on the argument that the scarce resource is no longer chips but utilisation of the chips you already bought, which is a very different pitch from every compute story of the last two years.
- The power bill found a lab. UC San Diego began testing new power technology for AI data centres, a sign that electricity supply has moved from a slide in a keynote to an engineering problem with a test site.
Signal vs. Noise
🟢 Signal: Data quality. Data quality is being written about slightly less this week and mattering considerably more across everything else moving. That is the shape of a topic changing category: it was a cleanup chore, and this week it became a security control, because the fastest way to break an AI system is now to edit what it reads. Most coverage still files it under hygiene.
🔴 Noise: ”Responsible AI.” The phrase pulled noticeably more volume this week while its hold on everything actually happening fell away. It is being said more and connected to less. The decisions with consequences attached moved into licensing contracts, retrieval logs and threat reports, none of which use the phrase.
Hire Ava, the AI BDR built for enterprise
Ava is the first AI BDR to run outbound end to end, finding leads or ingesting your CRM accounts, sending personalized emails on your reps' behalf, and booking meetings, autonomously or on copilot. She runs outbound for DoorDash and Grammarly. She's SOC 2 Type II audited, SSO and GDPR ready.
From the 190K
We scanned 190,000 articles this week. Here's what no one's talking about:
Morningstar and PitchBook licensed their data into a bank-facing AI, ByteDance signed a global copyright deal with Hollywood, and Liner raised $36.1 million in Series C funding for a research tool whose entire pitch is showing you the source.
The financial-data desk reads the first as a distribution deal. The entertainment trades read the second as a licensing truce. The startup wire reads the third as a mid-size round in a crowded category. Read them on one morning and the money is doing something specific: it is moving one layer up the pipe, away from the model and into what gets fed to it. That layer used to be free. Scraped, assumed, unowned, and treated as a solved problem by everyone building on top of it. Three separate buyers just decided it is neither free nor solved, and started paying for provenance the way you pay for clean water rather than the way you pay for software.
What changes Thursday is a question in your vendor review. For your most important AI workflow, name the sources it reads, and name who is paid to keep them accurate. If the answer to the second is nobody, your accuracy is a favour the internet is currently doing you.
By The Numbers
- One polluted page fools AI recommenders up to 27% of the time, rising to 73.8% when the top three results are replaced — the cheapest known attack on an AI system right now is publishing a web page, and the four tested defenses all failed.
- Cloud giants have committed $3.1 trillion to AI infrastructure — the capital is nearly all going to compute and buildings, almost none of it to verifying what those machines read.
- Liner closed a $36.1 million Series C — venture money backing citation and source-tracing as a product category, not a feature.
- Gartner expects more than 40% of agentic AI projects to be cancelled by 2027, with only about 23% of organisations scaling agents past pilot — the failure is usually a use case nobody made specific or measurable, not a model that underperformed.
- Gartner expects 40% of enterprise applications to embed task-specific AI agents by the end of 2026, up from under 5% in 2025 — adoption and cancellation are accelerating at the same time, which is what a market looks like mid-correction.
- See what's rising across AI and data this week →
Deep Dive: What's In The Crate
Every DJ has had the moment. You pull a record you have played a hundred times, drop the needle, and it is not the pressing you thought it was. Wrong speed, wrong edit, wrong version. The crowd does not know why the room went flat, and neither do you, because you were watching the mixer instead of the sleeve. The set was never about the desk. It was about what was in the crate.
One bad record is enough
The FORGE work found that a single contaminated page can steer an AI recommendation, and stacking the results makes it near-certain. This is not a model-quality problem. A better model reads the fake page more attentively.
The forgers upgraded
Unit 42's malware read-out and the pollution research describe one economy from two ends. Generating convincing bad inputs at scale used to be the expensive part of an attack. It is now the cheap part, and the target is not your firewall but your retrieval.
So good inputs got a price
Morningstar and PitchBook selling grounded data, and ByteDance paying Hollywood for rights, are the same commercial event. Verified, licensed, attributable input has become a purchased good, because the free version is no longer trustworthy enough to build on.
What Actually Works
- Log what your AI reads, not just what it says: retrieval history is the audit trail. Most teams keep outputs and throw away sources, which makes any later error impossible to diagnose.
- Put a named owner on your top ten sources: for each one, who is accountable if it is wrong, and how would you find out.
- Ask vendors for licence provenance in writing: which sources are paid for, which are scraped, what happens to your outputs if one is withdrawn.
- Test with a poisoned page of your own: publish a controlled false fact somewhere your system reads, and see whether it comes back. That is a one-week experiment with a very clear answer.
Watch the sleeve, not the mixer. Nobody ever blamed a bad night on the crate, and it was almost always the crate.
Most Chased Growth. These Stocks Just Kept Paying.
While the market swings between hype and panic, a different group has quietly delivered: steady income and rising payouts.
Energy giants, consumer staples, healthcare leaders — businesses people rely on.
This briefing breaks down 5 Dividend Aristocrats with decades of consistent payouts and the pricing power to keep growing them.
By clicking, you’ll receive this and other Elite Trade Media LLC financial newsletters, which may include advertiser offers. Publications · Privacy · Unsubscribe anytime.
What's Coming
California Starts Collecting On Data Brokers
California is stepping up enforcement under the CCPA and the Delete Act, which turns broker registration from paperwork into liability. Any AI product enriched with third-party consumer data now inherits that exposure, and most buyers have never asked which brokers sit behind their enrichment vendor.
Data Centres Become A Planning Fight
New South Wales opened consultation on data centre guidelines and network connection rules. Siting, grid connection and community consent are becoming the real constraint on capacity, well before chip supply is. Expect delivery dates in AI contracts to start carrying planning-permission caveats.
Cross-Border Evidence Demands Reach AI Vendors
The EU's e-evidence regime is landing on US technology providers now, with direct production orders across borders. If your AI vendor holds your prompts and retrieved documents, they hold discoverable material about your business, and their compliance posture is quietly yours.
For Your Team
Thursday's meeting prompt: ”Name the five sources our most important AI workflow reads every day. Who is paid to keep each one accurate, and how would we know within a week if one of them started lying to us?”
Share-worthy stat: One polluted web page is enough to bend an AI recommendation 27% of the time. Replace the top three sources and it hits 73.8%. Every tested defense, including telling the model to be skeptical, failed to fix it.
Go deeper: Track where AI data provenance and licensing money is moving →
The Track of the Day
”A breach response plan is only as good as the evidence behind it.”
Fidelis Security, on what actually gets you through an incident
Swap ”breach response plan” for ”model” and you have Tuesday in one sentence. The evidence behind it is the whole product now, and this week three different industries started buying it rather than assuming it.
We scanned 190,000 articles this week so you don't have to. Data Pains → Business Gains.
Published: August 26, 2026 | Curated by Yves Mulkers @ Ins7ghts
1,300+ articles scanned. 7 stories selected. Our AI distills the noise into signal—in seconds. Get early access →
Know someone who'd find this useful? Share your unique referral link →
Want Your Own AI Intelligence Briefing?
Our platform analyzes 1,000+ sources daily and delivers personalized insights in seconds.
Join the Waitlist →Founding members: Lifetime discount • Priority access • Shape the product



