← The Vault
The Big Story

Why your new AI assistant could be a security risk

As AI agents gain the power to shop, email, and control your apps, they also open new doors for hackers. From smart glasses capturing private moments to assistants that bypass your computer's security, we are trading our digital privacy for convenience. Here is what is happening under the hood.

Edition № 567Room: The Big Story23 September 20262 min readSources: 4
Article

Technology is shifting from tools we open and close to agents that live in the background, constantly watching and acting on our behalf. While this promises to automate our to-do lists, it is creating new ways for our personal information to be exposed and exploited.

WHAT'S HAPPENING

Meta recently released Muse, an AI agent designed to manage your emails, book appointments, and shop online. At the same time, companies are rolling out smart glasses with cameras that look like everyday fashion accessories. Both technologies have run into trouble. Security researchers found that Muse could be tricked into handing control of a user's entire account to an attacker. Meanwhile, in India, smart glasses are being used to record people in public without their permission, leading to targeted online harassment and even police surveillance of protesters.

The invisible risks of constant connection

HOW IT WORKS

To be helpful, an AI agent needs deep access to your life—your calendar, your emails, and your payment details. Usually, your computer uses a digital key, called a token, to prove who you are when you log into a service. In the case of Muse, researchers discovered a vulnerability where a malicious program could hijack that token. Once the hacker has your token, the AI essentially acts as a puppet for them, following their commands rather than yours. Instead of the AI shopping for you, it could be used to download your private files or take photos using your computer’s camera without you knowing.

With smart glasses, the risk is physical. These devices rely on a small light—a capture LED—to tell bystanders they are being recorded. However, this is a social contract, not a technical barrier. If someone covers the light or disables it, the camera keeps recording, and there is no way for the person being filmed to know they are being monitored. The AI inside these glasses is designed to interpret the world for the wearer, which means it is constantly gathering data on everything and everyone the wearer looks at.

WHY IT MATTERS

We are currently in a phase where companies are rushing to build powerful AI tools before they have fully secured the platforms they run on. When you give an AI assistant permission to send emails or buy goods, you are essentially granting a digital intern total access to your accounts. If that intern has a flaw in its design, the damage can be instant and widespread. We have to decide if the convenience of having an agent handle our errands is worth the risk of those same tools being used to watch us, or to let a stranger walk through our digital front door. The challenge is not just how to make these agents smart, but how to ensure they remain safely under our control.

Sources
← PreviousAI is changing how we work, from telecom hubs to tiny shopsNext →Finding new medicines in nature using artificial intelligence
Tomorrow's edition · free

Liked this one? The next lands at breakfast.

Every story in tomorrow's AI news, rebuilt in plain English — five minutes, sources linked, free forever.

By joining you agree to receive Article's daily newsletter — unsubscribe in one click. Privacy

← Back to the Vault