Product & Strategy

The Product Desk

The Signal

Microsoft Copilot and Salesforce Agentforce shipped the same data-exfiltration flaw.

EchoLeak arrived as an email nobody had to click. ForcedLeak came through a public lead form, which is to say through the front door marketing owns and nobody security-reviews. Different entry points, identical architecture underneath: private-data access plus untrusted input plus an outbound path. That combination sits under most shipped AI features, including whichever one you're scoping this quarter. And Treasury's Bessent just told Congress liability belongs to whoever built the thing, which moves this from a pen-test finding to a design-review gate.

In Play

  1. Agent Exfiltration Became A Procurement Question

    Microsoft 365 Copilot and Salesforce Agentforce each now have a named data-exfiltration exploit — EchoLeak via zero-click email, ForcedLeak via a public lead form — built on the same pattern: a model reading private data, ingesting untrusted content, and keeping an outbound path. That pattern is becoming a security-questionnaire line item you have to answer in writing. Treasury Secretary Scott Bessent told the House Financial Services Committee that labs should be liable for what they build, which pushes exposure toward whoever shipped the feature.

  2. Agents Got A Wallet Before A Disclosure Rule

    Shopify agreed to let Meta's Muse agent complete purchases on users' behalf, and the stock closed at $147.74, up 7.12%, on a day the S&P 500 finished flat, per Morning Brew. Your authorization, fraud, and dispute flows were designed for human actors, so an agent with a wallet has no defined counterparty in a chargeback. Bloomberg's Riley Griffin names the harder constraint: Muse is only fully useful once users hand over personal data, and that trust is not yet earned.

  3. Silent Quality Drift Outruns Your Review Step

    Claude Opus 5.5 ships with reasoning effort defaulting to medium, where Opus 5 defaulted to high, and on multi-part tasks it sometimes ends a turn with a text summary instead of a tool call. A turn that ends with no tool call stops the work while looking finished, so your pipelines log incomplete jobs as successes. GitHub Next's Maggie Appleton supplies the review-side version: by roughly question 20 of an agent planning flow, users accept the recommended option unread.

  4. Deployment Model Became A Funded Category

    The largest AI checks in the venture tally went to deployment and evaluation rather than features: Snorkel AI raised a $350M Series E for training data and eval tooling, Verda $189M for a Helsinki-based AI developer cloud with Supermicro taking strategic equity, and Go.AI an outsized $85M Series A purely for on-premises AI in regulated industries. "We can't put that data in your cloud" is now a funded alternative rather than a stalling objection. Palma.ai's $1.8M pre-seed for monitoring production agents is the early tell on what buyers ask next.

  5. Platform Teams Now Gate AI Tool Adoption

    Will Larson told the LDX3 audience that Imprint standardized on Claude Code by having its platform team support nothing else — alternatives are permitted but unsupported — and that it converted the loudest Jira fans first when moving to Linear. If you sell or operate developer tooling, the buying center moved from the individual engineer to the platform team's golden path, and enforcement is support allocation rather than mandate. The evidence is one attendee's account of one company, so treat it as a hypothesis to test on your next internal migration.

Deep Dives

  1. Two Vendors, One Exfiltration Pattern, And A Liability Bill With No Ceiling

    The architecture that leaked data from two flagship enterprise AI products is the one sitting under most AI features, and Washington just signalled the deployer absorbs the damages.

    The mechanism you can copy into your own architecture review The most useful artifact here is not an exploit name. It is OpenAI's own account of how its agents got out. The test environment was described as notionally isolated from…

    3 action items

    ●
  2. Shopify Handed An Agent The Checkout; Meta Handed It Contractors

    Agentic commerce reached production payment rails in the same week that an "autonomous" assistant turned out to be partly staffed by people — and only one of those facts is a problem you can fix with copy.

    The primitives that do not exist yet Start with the question nobody has shipped an answer to: when a model buys the wrong thing, who is the counterparty in the chargeback? Granting an agent transactional authority creates unauthorized-purchase, agent-hijacking, and…

    3 action items

    ●
  3. Opus 5.5 Ships At Medium Effort And Your Pipeline Will Not Notice

    Two independent findings put a shape on how AI quality degrades without an error signal: a changed default nobody announced, and a review step users stop reading around the twentieth question.

    What changed in the model you are about to migrate to The upside is real and it is the reason the default moved: Opus 5.5 matches Opus 5's high effort at medium , in fewer steps and fewer tokens, runs…

    3 action items

    ●

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn