Security researchers at Noma found they could manipulate GitHub's AI into exposing private repository contents just by crafting the right prompts. If your team uses AI that have read access to your codebase, this is a concrete reason to ask exactly what that agent can touch and who can ask it questions.
Wednesday, July 8, 2026 · about a 2 minute read
AI Agents Do What You Tell Them, Including the Wrong Things
Today's stories keep circling the same quiet truth: giving an AI real access to real things is a different game than chatting with a bot.
Get the calm version of AI news.
One email a day on what is actually happening in AI, in plain English. No hype, no doom.
Free. One calm email a day. No hype, no doom.
A team built Rowboat, an open-source local alternative to Claude's desktop app, because they wanted something that feels less like a chat window and more like a real work surface you can customize. If you have ever wished your AI assistant could fit into your actual workflow instead of the other way around, this is worth a look.
A new tool called GeoSQL lets Claude and Codex work with geospatial data, meaning you can ask an AI to query and reason about maps and location data without writing the SQL yourself. For anyone who works with geographic data and has always needed a specialist to write those queries, this is the kind of small tool that quietly saves an afternoon.
A new paper found that what looks like an AI model caving to peer pressure, changing a correct answer when pushed, often happens even when there is no peer in the conversation at all. It means some of what we call AI sycophancy might actually be a quirk in how the questions are framed, which changes what we need to fix.
Get this every morning.
This paper shows that LLMs give different yes or no answers to the same moral question depending on which option is listed first or how the sentence is worded, not because their underlying judgment shifted but because they are, at the core, predicting which word comes next. This is exactly what the book talks about: the model is not reasoning from principles, it is pattern-matching on the shape of the question, and that is a genuinely important thing to hold in your head when you are using AI to help you make decisions.
Simon Willison built a small web component using GPT-5.5 and shared the exact prompt he used, which is a useful reminder that a lot of real software is now being written this way, one prompt at a time. Watching what experienced developers actually prompt for, and how they share that work, tells you more about where the tools are headed than most product announcements do.
Researchers found that so-called reasoning models, the ones that show their work before answering, still facts, and they propose a way to reduce that during training. If you rely on a reasoning model for anything factual, it is worth knowing that the visible thinking process does not guarantee the final answer is grounded in reality.
That's today. See you tomorrow.
Get this every morning.
One email a day on what is actually happening in AI, in plain English. No hype, no doom.
Free. One calm email a day. No hype, no doom.

The book behind this newsletter
Just Predicting Words
How ChatGPT, Claude, and Modern AI Actually Work
The trick is small. The world it built is not.