Instinct AI Privacy: Emails Kept After Access Revoked
ALSO: HeyGen's AI clone closed 132 deals, OpenAI's cyber AI
Krishna Rungta
September 1, 2026
Welcome to Guru99 AI Report!
Top Story: Ever wonder what an AI assistant quietly keeps after you hit “disconnect”? Turns out, more than you’d expect. Today we dig into the fine print of AI inboxes — plus robot cops, a rogue sales clone, and a cancer breakthrough.
😬 Instinct Kept Her Emails After She Revoked Access
Brief Buzz:
Instinct is the invite-only AI assistant Silicon Valley can’t stop talking about — it can book doctor’s appointments, cut bills, and clear inboxes. But one tester had its Google access removed and it still summarized her emails three hours later.
- Claire Vo cut Google off at 11 a.m. and then received an Instinct summary of her tax emails at 2 p.m.
- Asked why, the bot said its emails were stored in plain text so they could be searched later.
- After Peter Yang’s complaint, Instinct added a Data Privacy control that let him delete his external data, such as his 36 Gmail records.
- Instinct’s terms of service grant a perpetual, irrevocable license to your materials — including using them to train the AI models.
- One exception: the privacy notice says Google Workspace data is not used for training.
💡 Why Should You Care?
“Disconnect,” “Delete data,” and “Delete account” are three separate buttons. Before you plug an agent into your inbox, check what it retains — and what actually gets removed.
🚦 China’s Robot Traffic Cops: 170,000 Warnings, No Arrests
Brief Buzz:
A 6-foot-2 robot is now working a busy intersection in Hangzhou. When it spots e-bike riders without helmets, it coordinates with the traffic lights to wave cars through — but it has no power to arrest anyone. Reuters visited the pilot, one of several running across China.
- Since May 1, 15 T2 robots have been deployed in Hangzhou by local firm SUPCON Information alongside the city’s police.
- SUPCON says it has issued more than 170,000 warnings and claims a 40% drop in violations — though Reuters couldn’t verify that.
- There’s no gun and no arrest power; after three ignored warnings, it files a report with a human officer.
- Around eighty cities run nearly fifty robots between them; SUPCON expects close to two hundred by year’s end.
- Exports are hitting a wall after the FCC blocked new foreign-made humanoid robot models in July.
💡 Why Should You Care?
This is a live trial of AI policing built on persuasion rather than punishment — the figures come from the users themselves, and the same sensors that nudge you also keep a record of what you do.
🍼 Founder’s AI Clone Closed 132 Deals — And Invented Prices
Brief Buzz:
HeyGen co-founder Wayne Liang took eight weeks of paternity leave and left an AI replica of himself to run sales calls. On August 3 he released the figures and open-sourced the code. The results were strong — and the mistakes instructive.
- 2,741 prospect conversations over eight weeks produced 132 new paying customers — a 4.8% close rate.
- 37 enterprise opportunities worth roughly $3M — pipeline opened, not revenue booked.
- It also invented a $4,800 plan HeyGen doesn’t sell, and emailed a customer internal triage notes.
- Fixes: pricing was pulled out of the model’s reasoning, and internal planning was walled off from customer email.
- Binding pricing and contracts now always escalate to a human approval gate in Slack.
💡 Why Should You Care?
Agentic AI really can handle a big volume of work — but because the numbers come from vendors, analysts still caution against claims of end-to-end autonomy. The wins here leaned on human approval gates.
🔬 AI Splits One Breast Cancer Defect Into Two
Brief Buzz:
An AI tool called CenSegNet, built by scientists at the University of Southampton, analyzes breast tumor tissue one cell at a time. It has found that a defect long treated as a single problem is in fact two distinct defects — and they behave differently.
- The AI mapped 911 tissue samples from 127 patients and more than 330,000 centrosomes — the structures that steer cell division.
- Two distinct faults emerged: cells with extra centrosomes, and cells with abnormally large ones — found in different parts of the tumor.
- The larger ones tracked with higher tumor grade, lymph-node spread, and genetic changes — the more aggressive type.
- Fewer oversized centrosomes in the tumor core were linked to better survival, though the authors call that single association underpowered.
- CenSegNet is free and open-source. It already works on kidney, colon, and appendix tissue — but it isn’t clinic-ready.
💡 Why Should You Care?
Better prognosis tools mean fewer patients over- or under-treated. But this is still early research on one small group — a lab tool, not a bedside one.
📞 AT&T Cut Coding Costs 56% by Routing to Open Models
Brief Buzz:
AT&T no longer sends every AI task to the priciest model. Simple jobs now go to cheaper open-source models it can run on its own systems, while hard tasks still hit the top-tier ones. The goal isn’t to cut total spending — it’s to keep it from ballooning.
- The Information reported that coding cost 56% less for a 2% drop in quality.
- 40% of employee AI queries already run on open models; AT&T is aiming for 60–70%.
- 45 billion tokens a day flow through AT&T’s routing gateway, which the company says cuts costs by up to 90%.
- The point isn’t lower AI bills outright — it’s keeping OpenAI and Anthropic spend flat even as usage climbs.
- Routing is a hot area right now: Stripe bought OpenRouter, Ramp launched Router, and Callosum raised $100M.
💡 Why Should You Care?
Simpler models are now good enough for ordinary tasks. But routing only saves money if you actually know what “good enough” means.
🔓 OpenAI Unlocks a Hacking Model for Vetted Defenders
Brief Buzz:
OpenAI has launched GPT-5.6-Cyber, a model built for the kind of hacking work its standard models refuse. Access is gated behind a vetting process — and the release follows a July incident in which OpenAI’s own models breached Hugging Face after their safety filters were switched off.
- It answered 95% of advanced cyber prompts — versus 1.5% for Sol and 2% for Daybreak Blue, according to OpenAI.
- It measures willingness to respond, not accuracy — and Cyber produces weaker vulnerability reports than Sol.
- Two tiers: Daybreak Blue relaxes the guardrails on Sol, while Daybreak Red unlocks Cyber for authorized exploit work.
- OpenAI says Cyber found two chained Chrome V8 zero-days, patched by Google as CVE-2026-15903.
- Individual accounts need hardware security keys from September 1, plus identity checks and legal attestations.
💡 Why Should You Care?
The same guardrails that stop attackers also stop defenders — as Hugging Face learned the hard way — and the fix is a waitlist most defenders will never reach the end of.
Hey! I’m Krishna Rungta
Founder of Guru99.com, Editor-in-chief & Technology Expert
Was this email forwarded to you? Sign up for free here.

