Instinct AI Privacy: Emails Kept After Access Revoked
ALSO: HeyGen's AI clone closed 132 deals, OpenAI's cyber AI
Krishna Rungta
September 1, 2026
Welcome to Guru99 AI Report!
Top Story: Ever wonder what an AI assistant quietly keeps after you hit “disconnect”? Turns out, more than you’d expect. Today we dig into the fine print of AI inboxes โ plus robot cops, a rogue sales clone, and a cancer breakthrough.
๐ฌ Instinct Kept Her Emails After She Revoked Access
Brief Buzz:
Instinct is the invite-only AI assistant Silicon Valley can’t stop talking about โ it can book doctor’s appointments, cut bills, and clear inboxes. But one tester had its Google access removed and it still summarized her emails three hours later.
- Claire Vo cut Google off at 11 a.m. and then received an Instinct summary of her tax emails at 2 p.m.
- Asked why, the bot said its emails were stored in plain text so they could be searched later.
- After Peter Yang’s complaint, Instinct added a Data Privacy control that let him delete his external data, such as his 36 Gmail records.
- Instinct’s terms of service grant a perpetual, irrevocable license to your materials โ including using them to train the AI models.
- One exception: the privacy notice says Google Workspace data is not used for training.
๐ก Why Should You Care?
“Disconnect,” “Delete data,” and “Delete account” are three separate buttons. Before you plug an agent into your inbox, check what it retains โ and what actually gets removed.
๐ฆ China’s Robot Traffic Cops: 170,000 Warnings, No Arrests
Brief Buzz:
A 6-foot-2 robot is now working a busy intersection in Hangzhou. When it spots e-bike riders without helmets, it coordinates with the traffic lights to wave cars through โ but it has no power to arrest anyone. Reuters visited the pilot, one of several running across China.
- Since May 1, 15 T2 robots have been deployed in Hangzhou by local firm SUPCON Information alongside the city’s police.
- SUPCON says it has issued more than 170,000 warnings and claims a 40% drop in violations โ though Reuters couldn’t verify that.
- There’s no gun and no arrest power; after three ignored warnings, it files a report with a human officer.
- Around eighty cities run nearly fifty robots between them; SUPCON expects close to two hundred by year’s end.
- Exports are hitting a wall after the FCC blocked new foreign-made humanoid robot models in July.
๐ก Why Should You Care?
This is a live trial of AI policing built on persuasion rather than punishment โ the figures come from the users themselves, and the same sensors that nudge you also keep a record of what you do.
๐ผ Founder’s AI Clone Closed 132 Deals โ And Invented Prices
Brief Buzz:
HeyGen co-founder Wayne Liang took eight weeks of paternity leave and left an AI replica of himself to run sales calls. On August 3 he released the figures and open-sourced the code. The results were strong โ and the mistakes instructive.
- 2,741 prospect conversations over eight weeks produced 132 new paying customers โ a 4.8% close rate.
- 37 enterprise opportunities worth roughly $3M โ pipeline opened, not revenue booked.
- It also invented a $4,800 plan HeyGen doesn’t sell, and emailed a customer internal triage notes.
- Fixes: pricing was pulled out of the model’s reasoning, and internal planning was walled off from customer email.
- Binding pricing and contracts now always escalate to a human approval gate in Slack.
๐ก Why Should You Care?
Agentic AI really can handle a big volume of work โ but because the numbers come from vendors, analysts still caution against claims of end-to-end autonomy. The wins here leaned on human approval gates.
๐ฌ AI Splits One Breast Cancer Defect Into Two
Brief Buzz:
An AI tool called CenSegNet, built by scientists at the University of Southampton, analyzes breast tumor tissue one cell at a time. It has found that a defect long treated as a single problem is in fact two distinct defects โ and they behave differently.
- The AI mapped 911 tissue samples from 127 patients and more than 330,000 centrosomes โ the structures that steer cell division.
- Two distinct faults emerged: cells with extra centrosomes, and cells with abnormally large ones โ found in different parts of the tumor.
- The larger ones tracked with higher tumor grade, lymph-node spread, and genetic changes โ the more aggressive type.
- Fewer oversized centrosomes in the tumor core were linked to better survival, though the authors call that single association underpowered.
- CenSegNet is free and open-source. It already works on kidney, colon, and appendix tissue โ but it isn’t clinic-ready.
๐ก Why Should You Care?
Better prognosis tools mean fewer patients over- or under-treated. But this is still early research on one small group โ a lab tool, not a bedside one.
๐ AT&T Cut Coding Costs 56% by Routing to Open Models
Brief Buzz:
AT&T no longer sends every AI task to the priciest model. Simple jobs now go to cheaper open-source models it can run on its own systems, while hard tasks still hit the top-tier ones. The goal isn’t to cut total spending โ it’s to keep it from ballooning.
- The Information reported that coding cost 56% less for a 2% drop in quality.
- 40% of employee AI queries already run on open models; AT&T is aiming for 60โ70%.
- 45 billion tokens a day flow through AT&T’s routing gateway, which the company says cuts costs by up to 90%.
- The point isn’t lower AI bills outright โ it’s keeping OpenAI and Anthropic spend flat even as usage climbs.
- Routing is a hot area right now: Stripe bought OpenRouter, Ramp launched Router, and Callosum raised $100M.
๐ก Why Should You Care?
Simpler models are now good enough for ordinary tasks. But routing only saves money if you actually know what “good enough” means.
๐ OpenAI Unlocks a Hacking Model for Vetted Defenders
Brief Buzz:
OpenAI has launched GPT-5.6-Cyber, a model built for the kind of hacking work its standard models refuse. Access is gated behind a vetting process โ and the release follows a July incident in which OpenAI’s own models breached Hugging Face after their safety filters were switched off.
- It answered 95% of advanced cyber prompts โ versus 1.5% for Sol and 2% for Daybreak Blue, according to OpenAI.
- It measures willingness to respond, not accuracy โ and Cyber produces weaker vulnerability reports than Sol.
- Two tiers: Daybreak Blue relaxes the guardrails on Sol, while Daybreak Red unlocks Cyber for authorized exploit work.
- OpenAI says Cyber found two chained Chrome V8 zero-days, patched by Google as CVE-2026-15903.
- Individual accounts need hardware security keys from September 1, plus identity checks and legal attestations.
๐ก Why Should You Care?
The same guardrails that stop attackers also stop defenders โ as Hugging Face learned the hard way โ and the fix is a waitlist most defenders will never reach the end of.
Hey! I’m Krishna Rungta
Founder of Guru99.com, Editor-in-chief & Technology Expert
Was this email forwarded to you? Sign up for free here.

