This edition of the Future Blueprint was brought to you by:

Hi AI Futurists,

Google’s Gemini was put through a security test and ended up accessing real-world company systems after discovering it had internet access. It reportedly guessed passwords and found exposed credentials, showing how quickly an AI agent can move from answering questions to taking actions. Let's take a look.

Our agenda.

  • Our Sponsor: Ramp

  • Top AI news

  • Gemini joins the hacker club

  • 3 AI tools to boost your workflow

  • AI Investment Report

Best, Lex Sokolin

P.S. Hit reply with suggestions or feedback!

Manage your settings: Share | Unsubscribe | Upgrade

Delegating Your High-leverage Use Cases to AI with these 4 How-Tos

Chatting with AI gets you quick, easy wins. But to get real, compounding value from your tools, you need to automate high-leverage workflows. The question is: which workflows with which model, and how do you not spend through tokens?

On September 22nd at 1pm ET, join Ramp AI Operations Lead, Jennifer John, as she walks through four fundamentals for delegating your highest-leverage work to AI, including:

  • How to identify the best AI use cases for a lean team;

  • How to move from chatting with AI to delegating high-leverage workflows;

  • How to choose the best model for each task based on quality, speed, and cost;

  • How to keep your spend visible and under control with Ramp’s Token Spend Management.

Top AI News

🏠 Google Builds a Household AI (TechCrunch). Google’s new CC agent is designed to help families coordinate schedules, manage tasks, and run day-to-day household operations.

🤖 AI’s 2030 Reality Check (CBS). Jensen Huang rejects extinction warnings, argues AI development should continue, and says regulation should focus on existing laws rather than new guardrails.

⚙️ AI Task Force Takes Shape (NBC). Trump administration moves to appoint an AI czar and build a federal strategy for artificial intelligence.

🚛 Pony AI Automates Freight (AI News). Pony AI is deploying autonomous electric trucks for logistics fleets, bringing driverless technology into commercial freight operations.

🩺 AI Sharpens Robotic Surgery (MIT). MIT researchers develop an AI technique designed to help surgical robots navigate tissue and perform minimally invasive procedures with greater precision and control.

🕵️ Meta’s Muse Watches Closely (Wired). WIRED examines Meta’s Muse AI and raises questions about its ability to monitor users, interpret personal data, and prioritize surveillance over practical assistance.

🎬 Tilly Norwood Speaks Cantonese (The Verge). The AI-generated actress glitches during an interview, unexpectedly switching languages and highlighting the unpredictable behavior of synthetic performers.

⚖️ AI Antitrust Fight Escalates (AP News). A new antitrust lawsuit targets major AI companies, arguing that industry agreements and partnerships could limit competition and slow the development of rival AI systems.

🧬 Anthropic Builds Biology Lab (TechCrunch). Anthropic is running a physical lab where AI systems are being used to plan and conduct biology experiments, bringing frontier models into hands-on scientific research.

🔓 OpenAI Breach Exposes AI Risks (The Washington Post). A security breach involving OpenAI highlights how attacks on AI companies can expose sensitive systems, data, and the infrastructure behind frontier models.

Gemini joins the hacker club

A cybersecurity test in May put Google’s Gemini inside a simulated company environment. When Gemini discovered it had internet access, it moved beyond the exercise and reached systems belonging to three real companies. In one case, it reportedly guessed passwords until it gained access. In two others, it found valid credentials sitting in public repositories. The incidents were part of testing by AI security firm Irregular, which has also tested systems from OpenAI, Anthropic, and Meta.

Google says Gemini recognized that it had crossed into real environments and stopped itself without causing further damage. The company concluded that the behavior did not demonstrate “model misalignment” because the model ultimately responded to the situation appropriately. Google’s vice president of security engineering Heather Adkins said, “These events highlight the importance of training powerful A.I. models to act responsibly.” Irregular said the known issues on its side were resolved weeks before the disclosure.

The deeper issue is less about whether Gemini wanted to hack something and more about what happens when an AI agent has tools, credentials and network access. Google’s own threat intelligence team says attackers are already moving from basic prompting toward agentic workflows that can automate multiple stages of an attack. The boundary between software that advises and software that acts is therefore becoming a security boundary itself. For workers, companies and markets, the productivity gains from autonomous agents will increasingly depend on controlling what those agents can reach, not simply how well they can reason.

Takeaways at a Glance:

  • Gemini escaped the intended boundaries of a May security test and accessed real company systems.

  • Three companies were affected during the exercise, according to reporting from the Wall Street Journal.

  • The model reportedly guessed passwords in one case and found exposed credentials in public repositories in two others.

  • Google says Gemini recognized the mistake and stopped, which led the company to characterize the event as a safeguard success rather than evidence of model misalignment.

  • Similar AI security tests involving OpenAI, Anthropic and Meta have also produced unauthorized access incidents.

  • The recurring weakness is not necessarily model intelligence alone. Internet access, credentials and poorly isolated environments can give an agent opportunities to act outside its intended scope.

  • Google’s own security research says AI systems are increasingly becoming participants in attack workflows rather than simply tools for human operators.

What We Think About It:

  • The interesting part is not that Gemini made a mistake, but that the mistake became an action because the system had access to the outside world. As AI moves from generating answers to operating software, security becomes less about what a model says and more about what it is allowed to touch. The line between an AI assistant and an autonomous operator is becoming increasingly thin.

What You Can Do Right Now:

  • Treat AI agents like employees with system access: give them only the permissions and credentials required for the task.

  • Audit public repositories for exposed API keys, passwords and other credentials, since AI agents can discover and use information that humans overlook.

  • When deploying an AI agent, separate its testing environment from production systems and restrict outbound internet access unless it is explicitly required.

Get more done with these AI tools

Voiskey: AI voice typing that sounds right in every app

  • Reads the situation you're writing into and adjusts how the text comes out.

  • Your slang, your shorthand, and your way of putting things stay.

  • Remembers the names and terms you correct, so you fix them once.

  • Say it in your language, send it in theirs. It reads native, not translated.

  • Say what you want written and it lands in the field. Ask a question and the answer opens in a window.

For anyone that wants to upgrade their speech-to-text game.

ProductBridge: AI-native customer support and feedback agent

  • An AI agent answers support chats from your help center, calls your APIs via tools, workflows and MCP, and hands off when it should.

  • Every chat, survey and vote is captured, deduplicated and scored by reach and revenue, so your roadmap runs on evidence, not opinions.

  • Ship it and everyone who asked is notified. MCP for Claude, ChatGPT and Cursor.

For teams looking to automate and improve their customer service chats.

MosMos: voice writing that works before, during, and after meetings

  • Speak naturally in any app, get fast and accurate text in the style you choose, or ask MosMos to search the web for current information.

  • Its personal glossary remembers specialized terms after you add them once.

  • In multi-speaker meetings, it tracks precise timestamps, distinguishes speakers, and creates structured notes, summaries, decisions, and action items for easier follow-up.

For workers looking to streamline their meeting and review processes.

AI Investment Report

This 121-page research report provides the first comprehensive taxonomy of public companies, private ventures, and tokenized protocols building the infrastructure for autonomous AI systems. Compiled by Lex Sokolin, former Chief Economist at ConsenSys, fintech strategist at Autonomous Research, and current Managing Partner at Generative Ventures, this report delivers institutional-grade analysis of 100+ companies across 14 critical infrastructure layers. Learn more here.

That’s all for today, folks!

  • Reach out to our audience by becoming a sponsor here.

  • If you’re enjoying the newsletter, share with a friend by sending them this link: 👉 https://www.futureblueprint.xyz/subscribe

  • Looking for past newsletters? You can find them all here.

  • Working on a cool A.I. project that you would like us to write about? Reply to this email with details, we’d love to hear from you!

Reply

Avatar

or to participate