OpenAI is previewing Private Safety Processing, a system that flags patterns of AI misuse across sessions without OpenAI staff ever seeing customer prompts, aiming to close the gap between zero-retention privacy and abuse monitoring.
OpenAI is previewing Private Safety Processing, a system that flags patterns of AI misuse across sessions without OpenAI staff ever seeing customer prompts, aiming to close the gap between zero-retention privacy and abuse monitoring.
Researchers found that encrypted chain-of-thought blocks returned by OpenAI, Anthropic, and Google's reasoning APIs used a shared global key, letting weaker models decode stronger models' hidden reasoning and exposing 704 real privacy artifacts in published developer logs.
xAI's Grok Build CLI 0.2.93 uploaded entire Git repositories including commit history and unredacted credentials to a Google Cloud Storage bucket by default. Here's what was exposed and what xAI's server-side fix left unanswered.
Researchers from Oxford and Meta demonstrate that four of five frontier LLMs exfiltrate sensitive data from multi-agent orchestrator systems via a single indirect prompt injection, bypassing access controls entirely.
Research confirms that text embeddings stored in vector databases are not safely anonymised. Inversion attacks can reconstruct source text with high fidelity from embeddings alone, including those produced by commercial APIs.
Training data can be reconstructed from foundation model weights with significantly higher accuracy than previously reported, with implications for GDPR compliance and IP protection.