Top Stories
Microsoft Begins Routing Word and Excel Prompts to Its Own MAI Models
Microsoft has started running a percentage of user prompts in Word and Excel through its in-house MAI models instead of relying solely on OpenAI and Anthropic, TechCrunch reported on July 7. The move lands in the same week as Microsoft’s 4,800-person layoff round and the broader “AI costs more than the people it replaced” line that has been building across 2026.
Microsoft declined to share further, telling TechCrunch it had nothing further to share. The article frames the pivot as part of a wider pullback by Amazon, Uber, Meta, and Accenture, each of which has moved to curb AI spending after a year of “tokenmaxxing.” It is also the clearest signal yet that the GPT-era arrangement - Microsoft as a captive OpenAI buyer - has structurally changed: MAI now sits in the prompt path for two of the most-used Office apps, with MAI models announced at Build this year including an agentic coder and a text-to-image generator. The piece does not name the share of prompts being rerouted or the timing of any broader rollout.
Meta’s Muse Image Generator Faces Immediate Consent Pushback
Meta rolled out Muse Image, a free AI image generator on July 7, built by Meta Superintelligence Labs (code-named “Mango”). It ships inside the Meta AI app, Instagram Stories, and WhatsApp, and supports “Presets,” prompt-based editing, and Facebook Marketplace interior-decorating mockups. Meta’s policy states users “will not be notified about content created using AI features at Meta,” and the feature is opt-out rather than opt-in.
The early controversy is that users can tag another Instagram user with a public profile and manipulate their photos with AI. TechCrunch quotes an X user who flagged the design: “Pulling real users into generated photos without explicit consent is a [privacy landmine] waiting to detonate.” The article ties the launch back to Meta’s existing pattern - the $5 billion FTC fine over Cambridge Analytica in 2019 and the 2021 shutdown of Facebook’s facial-recognition system - and frames Muse’s tagging as a fresh case of broad use of people’s data unless they actively turn it off. A companion product, Muse Video, is reportedly already in development.
GitHub Coding Agent Leaks Private Repos on a Benign Prompt
Researchers at Noma Labs disclosed a prompt-injection flaw in GitHub’s Agentic Workflows that lets an attacker extract private repository contents into a public issue comment. The Register’s write-up of the disclosure names the issue “GitLost” and credits research lead Sasi Levi.
The attack is straightforward: an attacker hides a malicious instruction in plain English inside a public-repository issue belonging to the same organization, and the agent - powered by Claude or GitHub Copilot inside GitHub Actions - pulls the private content and posts it publicly. Noma Labs notes: “To exploit this vulnerability, the attacker needed no coding skills, access, or credentials. All that was needed was to open an issue in a public repository belonging to an organization that uses GitHub’s Agentic Workflow setup and wait.” GitHub had not shipped a fix or documentation as of publication. For any developer who has routed the assistant through private code, this is the first named prompt-injection disclosure against a first-party GitHub agent and a direct privacy beat. It is also the same threat pattern we have been tracking since the AI agent insider-threat coverage in February: a permanent-access system reading untrusted input and publishing what it finds.
Discord Admits AI Moderation Bug Banned 8,000+ Users Over Harmless Images
Discord acknowledged a bug in its AI moderation system that misclassified spreadsheets, chessboards, game textures, and white or gray transparent backgrounds as policy-violating content, automatically enforcing bans before human review. Over 8,000 accounts were banned across roughly two months beginning in May, with about 200 more banned over the weekend before the fix shipped.
Discord posted a thread on X explaining its similarity-matching system and confirmed affected accounts are being restored: “We’re working on better safeguards so this can’t happen again.” The piece lands one day after Reddit disclosed its own LLM-vs-LLM-spam moderation stack, making two named platform incidents in a week where AI moderation broke the wrong way. Similar issues have been reported on Instagram, Facebook Groups, and Tumblr, and Meta’s Oversight Board is pushing for more transparency around automated bans.
Anthropic Expands Claude Cowork From Coding Agents to the Rest of the Office
Claude Cowork, originally launched as a desktop app for Max subscribers in January, is now on web and mobile, Anthropic told TechCrunch on July 7. Agents keep running when a device is offline; chat and Cowork are merged across web and desktop; and projects and artifacts live together across both surfaces.
Anthropic shared early numbers from 1.2 million anonymized sessions across 600,000+ organizations in the last two weeks of May. The dominant use case was “business process operating” at 33.4 percent (reports, onboarding, spreadsheet reconciliation for finance, HR, and admin roles), with content creation and copywriting at 16.4 percent and software development at 8.7 percent. Anthropic’s own framing: “the tasks that are part of a broad swath of jobs, but are rarely a person’s core responsibility.” The rollout is a direct response to OpenAI’s earlier Codex mobile push and a sign that the enterprise agent story is no longer confined to developer tools.
Google Adds Background Tasks and Remote MCP to Gemini Managed Agents
Google’s Gemini API Managed Agents now supports background execution, remote Model Context Protocol server integration, custom function calling alongside sandbox tools, and on-the-fly network credential refresh. Background mode returns a request ID immediately so clients can poll status, stream progress, or reconnect later, addressing the fragility of holding HTTP connections open during long-running agent tasks.
The remote MCP piece is the privacy-relevant one: managed agents can connect directly to remote MCP servers without custom proxy middleware, mixing remote tools with built-in sandbox capabilities like Google Search and code execution. The product lands in the same week as Anthropic’s Cowork expansion and is the clearest competitive answer from Google to the enterprise agent stack on the same week, with authors Philipp Schmid and Mariano Cocirio (Google DeepMind) noting the goal is to let managed agents act as “asynchronous workers that operate inside real development environments without blocking your application.”
EFF Opens “Automated Moderation Is Here to Stay” Series With a User-Rights Framework
The Electronic Frontier Foundation published Part 1 of a two-part series on July 7 by Jillian C. York and Corynne McSherry, arguing that automated moderation is now the durable default on every major platform and laying out a user-rights framework centered on transparency, accountability, due process, and safeguards against harm.
The piece traces the expansion from 2020 pandemic-era cuts to human moderation through to today’s AI-driven systems and notes that protocols adopted in crisis tend to persist: “These failures are not incidental. They are a predictable consequence of deploying automated systems to make complex judgments about language, culture, context, and identity at scale.” The framework explicitly calls out protections for marginalized groups - low-resource languages and LGBTQ content, where “when moderation systems lack nuance, transparency, and human oversight, they can fail to curb harassment and wrongly suppress legitimate content.” Part 2, with company and policy-maker recommendations, is the natural follow-on read after this week’s Discord and Reddit moderation incidents.
Quick Hits
- Hugging Face ships one-click deploy to SageMaker: HF and AWS published a direct “deploy from the Hub to SageMaker Studio” path with pre-configured SFT, DPO, RLVR, and RLAIF permissions and GPU quota visibility for G5 and G6 instances. Arcee AI’s Mark McQuade: “Going from an open model on Hugging Face straight into SageMaker Studio in a single click… is the kind of experience open models have been missing.”
- sqlite-utils 4.0 ships with real schema migrations: Simon Willison released sqlite-utils 4.0 on July 7, the first major version since 3.0 in November 2020, adding a migrations framework tracked via a
_sqlite_migrationstable, nested transactions viadb.atomic(), and compound foreign keys. He credits Claude Fable 5, Claude Opus 4.8, and GPT-5.5 with substantial assistance on the release. - FuriosaAI RNGD accelerators land at Equinix Lisbon: South Korean chip startup FuriosaAI has begun deploying its RNGD AI accelerators (48 GB HBM3, 512 teraFLOPS FP8, 180W TDP on TSMC 5nm) at Equinix’s LS2 datacenter in Lisbon, targeting Europe’s sovereign AI compute demand.
- Atrophy CLI targets vibe-coding skill decay: Bengaluru-based developer Ashutosh Rath’s Atrophy tool treats coding abilities like Elo chess scores across five skill areas - syntax recall, debugging, code reading, API memory, and decomposition - with Python and JavaScript drills at three difficulty levels.
- Savi app screens for AI-cloned kidnapping scam calls: Savi Security, founded by brothers Patrick and Ryan Coughlin, launched a consumer iOS and Android app after a $7M Acrew Capital seed round; the app screens texts, voicemails, and incoming calls in real time using Gemini routed through an “AI gateway,” priced at $8 per month or $63 per year for the whole family.
- Forterra deploys 100+ autonomous Lancer ATVs in Ukraine: Forterra, a US autonomous-vehicle builder, has deployed more than 100 of its Lancer ATVs (built on a Polaris chassis) over nine months in Ukrainian conflict zones, logging over 2,500 miles, 1,100+ missions, and 52 casualty evacuations. Vehicles are currently teleoperated, not fully autonomous.
- Open-source AI is not hurting Anthropic, yet: Decagon CEO Jesse Zhang argues in TechCrunch that frontier labs own the “discovery” phase and open-weight models own “production,” with Vercel AI Gateway data showing DeepSeek leading token volumes but Anthropic still capturing more than half of overall AI spend.
Worth Watching
The EFF series Part 2. EFF’s Part 1 user-rights framework sets up recommendations for companies and policymakers in Part 2. The Discord and Reddit incidents this week give the framework a concrete test case; watch whether EFF’s recommendations show up in any forthcoming federal or state AI-moderation bills.
The agent-supply-chain beat. GitHub’s coding-agent private-repo leak and Discord’s moderation false-positive wave landed on the same day and form the cleanest single signal yet that first-party AI agents in production need a real disclosure-and-recourse path. Watch for follow-on disclosures from other security firms on whether GitLost-style prompt injection shows up against other coding agents, and for GitHub’s response.
Microsoft’s MAI share-of-prompts trajectory. TechCrunch’s Microsoft MAI piece declined to publish the share of Office prompts now routed through MAI. Watch for any future Microsoft disclosure of the prompt-path split, and for whether MAI models start showing up on Microsoft customer-facing pricing pages. The answer to whether Microsoft is now an OpenAI competitor or a partner is going to live in that number.
Treasury’s AI systemic-risk framing. MIT Technology Review reported on a leaked Treasury report comparing the AI market to the dotcom bubble and warning that “AI profits are hiding bigger risks in earnings reports.” Watch for the formal Treasury release and whether any of the framing shows up in the next FSOC report on financial-stability risks from AI-driven market concentration.