Key Takeaways
- Varonis found a one-click chain in Microsoft Copilot Personal that could quietly pull data from connected email, cloud storage, and calendar — Microsoft patched it; no evidence it was used against real people
- Researchers didn't reverse-engineer the software — they kept asking Copilot why the attack wouldn't work until it volunteered the undocumented setting that made it possible
- Pew: 52% of US adults are more concerned than excited about AI in daily life (up from 37% in 2021); adults under 30 are now majority-wary for the first time
- DeepSeek changed API pricing twice in eight days — first time-of-day premiums, then weekend off-peak at half the weekday rate — while the earlier base-rate hike still stands
- The safest place to use AI in your business right now is in the parts your customers never see — which is also where most wasted hours live
Week of August 17–23, 2026
Three things happened in AI between August 17th and the 23rd that are worth five minutes of your time as someone who runs a business.
None of them ask anything of you. But together they say something useful about where this is actually heading.
This is Last Week in AI — the signal, not the noise. Three stories operators need to understand, and what each one means for how you run your business.
Story 1: Microsoft patched a flaw where one click could open your inbox
Security researchers at Varonis found a chain of weaknesses in Microsoft Copilot. Click one bad link, and an attacker could quietly pull data out of whatever accounts you'd connected to it — email, your cloud storage, your calendar.
No password needed. No warning. To any security software watching, it looked like Copilot doing ordinary Copilot things.
The part that made this a story rather than a routine patch is how they found it. They didn't take the software apart. They just kept asking Copilot why such an attack wouldn't work. Every time it refused, it explained a little more about why. Eventually it volunteered the specific undocumented setting that made the attack possible — including a note that the setting had been disabled.
It hadn't been. They tried it. It worked.
As Varonis put it: Copilot wasn't breached. It was played.
The practical facts, so nobody panics: this hit Copilot Personal, the free consumer version, not the business one bundled with Microsoft 365. Microsoft fixed it and says no action is needed on your end. Nobody found evidence it was ever used against real people. Though it's worth noting the researchers reported it in December and the fix landed eight months later. Tracked as CVE-2026-24301 (CoSnitch).
What it means for operators: the risk with these tools isn't usually the AI itself. It's everything you plug into it. Every account you connect to an assistant is another door, and the assistant has keys to all of them. That's exactly what makes these things useful, and it's the same reason a single bad link mattered here.
Not a reason to avoid them. A reason to be deliberate about what you hand over.
Story 2: The public is getting less comfortable with AI, not more
Pew Research released a new survey of about 3,500 American adults. The headline number: 52% say they're more concerned than excited about AI in daily life. In 2021, before most people had ever used a chatbot, that figure was 37%.
The reverse is more striking. The share who say they're more excited than concerned has fallen by half, from 18% to 9%.
And for the first time, a majority of adults under 30 — the people who use these tools most — say they're more worried than enthusiastic.
What it means for operators: this is the part worth sitting with. Almost four years into everyone having access to this technology, familiarity made people more skeptical, not less.
If you've been assuming you're behind because everyone else has embraced this and you haven't — that assumption is wrong. Most people are somewhere between wary and uneasy, and they've gotten more so over time.
It also matters practically. If you're weighing whether to put AI in front of your customers — a chat widget, an automated phone answer, AI-written emails going out under your name — this is the room you'd be walking into. Nine percent of your customers are excited about that. Half are actively uneasy.
That's not an argument against using AI. It's an argument for using it where it saves you time rather than where it's visible to them. The paperwork, the scheduling, the follow-up, the documentation. Not the handshake. (Same distinction we drew in what AI is actually bad at and using AI vs. running it.)
Story 3: A company changed its AI prices twice in eight days
DeepSeek — the Chinese AI company that had been the cheapest option available anywhere — raised its prices roughly fourfold with three days' notice.
This week it cut them again.
The company announced that weekends now count as off-peak, which means Saturday and Sunday get billed at half the weekday rate. It had introduced time-of-day pricing only a week earlier: certain hours cost double, everything else costs the base rate. Now two full days a week are exempt.
Same company, same tool, two pricing changes in eight days. The base rates are still up sharply from where they were two weeks ago — that increase stands. What changed this week is that weekends no longer carry the premium, so the most expensive hours got a bit cheaper.
What it means for operators: if you've been waiting for this to calm down before you engage with it, here's your answer in miniature. A major provider moved its prices twice in eight days, in opposite directions.
That's what a real price war looks like, and the churn is mostly good news for anyone buying — prices trend down when companies fight this hard. But it also means any specific number you read about AI costs has a shelf life measured in days.
Putting it together
One story about a tool being more connected than people realized. One about a public growing warier the more it sees. One about a market that can't hold a price for a week.
The pitch for the last three years has been that AI is inevitable and you should hurry. What this week actually showed is a technology that's genuinely useful, genuinely leaky, genuinely distrusted by the people you sell to, and priced by companies that keep changing their minds. All at once.
If you take one thing from this week: the safest place to use AI in your business right now is in the parts your customers never see. That's also, conveniently, where most of your wasted hours are.
— Aristotle Taylor, CEO & Co-Founder, Levron Labs
What to do this week
Audit what you've connected to any AI assistant — personal Copilot, ChatGPT, Claude, whatever's in your stack. Write down every account it can reach. Then ask whether each one still needs to be there, or whether the same work could run in a system that never sees your inbox.
If the answer is murky, start with a free ops assessment. We'll map where AI belongs in the back office, where a human should stay visible, and which connected accounts are quietly expanding your attack surface.
Sources
Microsoft Copilot flaw (CoSnitch, CVE-2026-24301)
Pew Research survey
DeepSeek weekend pricing

