Dave's ReadA man in Melbourne wanted into a gym class that was already full. He asked his AI agent to get him a spot. The agent didn't say it couldn't. It went looking, found a flaw in the gym's booking system, and used it to bump another member off the list. He isn't a hacker. He never asked it to break anything. He asked for a spot in a class, which is about as ordinary a request as a person can make. Here's the part worth your Tuesday morning. Nobody ever told that agent what it wasn't allowed to do. It was handed a goal and a live connection to the internet, and it treated quietly exploiting a bug as a perfectly reasonable way to finish the job. It wasn't broken. It did exactly what it was told. There was nothing anywhere in its instructions about the member who'd lose their place. (ABC News) And this isn't a strange one-off. Meta became the fourth AI lab in recent weeks to confirm one of its own models broke into a real company's systems during testing. Four labs, same finding, over and over. The tools get told what to accomplish. They don't get told what's off limits. So think about your own shop for a second. Somebody there is already running something that can send an email, book time on a calendar, pull a record, or touch a customer's account. Maybe you set it up. Maybe you found out about it later. Either way, the useful question is a narrow one: has anyone written down what that tool isn't allowed to do? Most places, the honest answer is no. Not because anyone was careless. It just never came up, because the tool worked and nothing went wrong yet. The fix is smaller than it sounds. It isn't a policy document and it doesn't need a committee. It's a short list of what the tool doesn't touch without a person intentionally approving it. Money, customers, records, and anything that speaks for you. Twenty minutes, once, before you hand anything the keys. For whatever is already running, there's a way to ask it directly at the bottom of this issue. AI works when you put people at the center. The news worth your timeA voice-cloning scam cost an Ontario woman twelve thousand dollars in a single phone call. She picked up and heard her brother's voice. It wasn't him. Convincing clones now take very little source audio to build. (AI Business Weekly) Why it matters: worth walking your team through this week, particularly anyone who can approve a payment or release a file. A familiar voice on the phone stopped being proof of anything. Google Maps will now take a multi-step request in one go. Order food along your route, check live transit, research a stop, from a single ask instead of three separate searches. (Google) Why it matters: if you route people in the field, this is the first version of that idea worth ten minutes of your dispatcher's time. It's also a habit worth copying everywhere else. Give a tool the whole picture in one ask instead of feeding it one fact at a time. OpenAI pulled its own emergency brake on its next model. The company flagged an unreleased model as capable enough on cyber tasks to find security holes without a person involved, paused some internal work on it, and brought in outside testing. (OpenAI) Why it matters: a lab stopped itself here, with no regulator in the room. If the companies building these tools are drawing lines around what theirs are allowed to do, drawing one around yours isn't paranoid. It's the same instinct at your scale. The backlash against AI data centers is turning into local politics. A reporter spent ten days across Wisconsin and Michigan and found roughly 70% of nearby residents opposed, regardless of party. More than 100 moratorium proposals are now circulating. The complaints are concrete: power bills, noise, water use. (Jasmine Sun) Why it matters: nothing to do this week. But this reaches your chamber lunch and your utility bill well before it reaches the national news. A bill was introduced to tax AI companies and fund worker retraining. The approach is modeled on a Depression-era jobs program, taxing AI companies directly to pay for retraining and job protection. (AI Business Weekly) Why it matters: an early marker that AI and jobs is turning into a policy fight, which means the headcount conversation gets louder around you regardless of what you decide inside your own business. Skim these, then forget themYou don't need to read these. They're here so you don't feel like you missed anything. Click one if it grabs you.
Worth followingThe Neuron. Daily, plain English, and it explains why a story matters to someone running a business rather than someone building the technology. The Rundown AI. Practical and steady. Good for keeping current without reading six newsletters to do it. For the further alongIf you already have agents acting on their own, look up task-scoped credentials. The principle is that an agent holds only the permission it needs for the one task in front of it and loses that permission the second the task ends, instead of carrying standing access to your systems all day long. Your IT person or your managed service provider will know the term. It's the engineered version of the short list above. Try this weekTwo steps, about twenty minutes. Find out what your tools can already do without you, then decide what they can't. First, ask.Pick one thing you already have running that can act in the real world. An email assistant, a scheduling bot, a Zapier or Make automation, anything holding a login you aren't watching all day. Ask it this, word for word: List every real-world action you are currently allowed to take on my behalf, and what stops you from going further.
Read the answer twice. If nothing in it names an actual limit, you don't have one. Then, write the rules.Four lines listing what that tool is not allowed to do without you approving it first. Most businesses can start with these and adjust:
Then tell whoever runs that tool what the four lines are. Do it before you add the next one. One reply. Hit reply and tell me one thing: what's the one tool in your business that can already do something without asking you first? |
Every Tuesday, the few things in AI that actually matter for your business, in plain English. The stories worth your time, the noise you can skip, and one thing to try this week. No fear, no hype, no FOMO.
Issue 002 · Tuesday, July 28, 2026 Dave's Read You run an engagement survey every year. You ask your people about workload, about their manager, about whether they'd recommend the place to a friend. You act on what comes back. Here's the question almost no owner has put on that survey: are you using AI to do your job, and if so, how? Most owners have never asked. Not once. So the honest answer to "is my team using AI" is "I don't know," and the real answer, on the floor, is usually "yes,...
The Kitala BriefAI news & tips for everyone, without the FOMO Welcome to the first Kitala Brief. You're one of the first on the list, and I'm glad you're here. Here's what this is, in one breath. Every Tuesday I read the week of AI news so you don't have to, then send you the few things worth your attention, in plain English. Some weeks that's a lot to cover. Most weeks it's a little, and I'll say so. No hype, no homework. Now, the first issue. Dave’s Read Before you let anyone tell you AI...