GPT-Live, Agent Leaks, and a $19 Billion Lease

Compact Conversations for 2026-07-09: 7 AI stories, ai news worth knowing in just 5 minutes.

[Audio embed placeholder]

The Lead: OpenAI launches GPT-Live, a full-duplex voice model for more natural conversations

OpenAI launched GPT-Live, a new generation of voice model built on a full-duplex architecture, meaning it can listen and speak at the same time. The model is designed to make conversations feel more natural, with verbal acknowledgments and the ability to delegate complex tasks to frontier models like GPT-5.5 in the background.

Why it matters: This represents a significant step toward more fluid, human-like voice interaction with AI, which could change how enterprises deploy voice assistants for customer service, support, and internal tools.

Source: OpenAI

The Feed

GitHub AI agent leaks private repositories via prompt injection attack

Security researchers disclosed an attack, dubbed GitLost, that uses prompt injection to trick GitHub’s preview Agentic Workflows into retrieving and publicly posting content from private repositories.

Why it matters: It highlights a fundamental security risk for AI agents with broad access: untrusted user input can become a bridge to sensitive internal data, requiring new trust boundaries and permission models.

Source: InfoWorld

Patched Google Dialogflow flaw showed how one rogue agent could hijack enterprise chatbots

A now-patched vulnerability in Google Cloud’s Dialogflow CX, named Rogue Agent, allowed an attacker with edit permissions to inject malicious code, potentially accessing conversation history and stealing credentials through a compromised chatbot.

Why it matters: As enterprise chatbots gain access to more systems and data, agent permissions and runtime isolation become critical new security boundaries that must be rigorously managed.

Source: The Neuron

Anthropic expands Claude Cowork to web and mobile as enterprise use broadens

Anthropic is bringing its Claude Cowork AI agent to web and mobile platforms, allowing users to monitor and manage long-running tasks from anywhere. An analysis of over a million sessions showed business process and operations as the largest use case.

Why it matters: The expansion signals the move of AI agents from developer tools to broader operational and knowledge work, requiring new governance for these always-on, background agents.

Source: InfoWorld

Prime Intellect raises $130M Series A to help enterprises build their own AI agents

Prime Intellect, a startup providing compute and tools for companies to build custom AI agents, raised $130 million at a $1 billion valuation. Its platform offers a ‘full stack’ for agent development, aiming to reduce reliance on frontier AI labs.

Why it matters: The funding reflects strong enterprise demand for owning and customizing AI agent capabilities, driven by concerns over data control, cost, and dependency on large model providers.

Source: TechCrunch

OpenAI helps found Appia Foundation to build shared standards for advanced AI

OpenAI announced it helped found the Appia Foundation, hosted by the Linux Foundation, to develop open, modular specifications for AI safety and governance standards.

Why it matters: The effort aims to create a common technical language for evaluating and governing AI systems, which is crucial for building trust and enabling interoperability across organizations and jurisdictions.

Source: OpenAI

OpenAI’s GPT-5.6 launches Thursday after a delay forced by the U.S. government

OpenAI is launching the GPT-5.6 model after a government-mandated delay was lifted. The company claims it outperforms a key competitor on coding benchmarks at a lower cost.

Why it matters: The launch, following government review, points to the evolving regulatory landscape for frontier model releases and the ongoing competition on performance and price.

Source: The Decoder

One Thing to Try

Inspired by a Reddit analysis showing the same 11 corrections were repeated across hundreds of agent sessions. Keep a short, plain-text list of your most common instructions or corrections for an AI coding assistant. Paste this list at the start of a new session to create a simple, effective memory loop and stop reteaching the same lessons.

Sources

Transcript

Host A: Welcome to Compact Conversations, the show that compresses the day’s AI news into 5 minutes.

Host A: [curious] OpenAI launched GPT-Live yesterday, a new generation of voice models built on a full-duplex architecture. That means it can listen and speak at the same time. The company says it makes talking with AI feel much more like having a real conversation, with fewer awkward pauses and interruptions.

Host B: GPT-Live can show it’s paying attention with phrases like “mhmm” or “yeah,” and it delegates more complex work to frontier models like GPT-5.5 in the background. It’s rolling out now as the default for ChatGPT Voice, with a larger version for paid users and a mini version for free users. The model is currently English-only, with more languages planned later this year.

Host B: One number to know today: $19 billion. That’s the expected contracted revenue over 20 years from Anthropic’s lease with TeraWulf for a data center campus in Kentucky. It’s a signal of the massive, long-term infrastructure commitments AI companies are now making.

Host A: [with emphasis] First, Noma Security disclosed an attack called GitLost that shows how a prompt injection could trick GitHub’s preview Agentic Workflows into leaking private repository content. The researchers say it illustrates a core risk: any AI agent with access to both untrusted external content and sensitive internal resources can become an unintended bridge between the two. They demonstrated the attack using a malicious pull request description. [thoughtful] The vulnerability didn’t require stolen credentials, just a crafted GitHub issue that the AI agent interpreted as instructions.

Host B: Next, Varonis Threat Labs disclosed a now-patched vulnerability in Google Cloud’s Dialogflow CX platform called Rogue Agent. The issue was in the Code Blocks feature, which lets developers add custom Python logic to chatbots. Agents in the same GCP project shared a runtime environment, so an attacker with edit permission could override execution files and access conversation history or steal credentials. Google issued fixes in April and June. Varonis says it’s not aware of any real-world exploitation before the patch.

Host A: [thoughtful] Anthropic is expanding its Claude Cowork AI agent to web and mobile. Based on analysis of over a million sessions, the move lets enterprise users monitor and manage long-running AI tasks from anywhere. The data showed business process and operations accounted for the largest share of usage at 33 percent, with software development at 8.7 percent. The web and mobile experience is in beta for Max subscribers, with support for other plans coming in weeks.

Host B: Prime Intellect, a startup providing computing power and tools to help companies build their own AI agents, raised a $130 million Series A at a $1 billion valuation. The round was led by Radical Ventures, with participation from Nvidia Ventures and Intel Capital. Prime Intellect already has customers like Ramp and Zapier, and the company says it has an annualized revenue run rate of $100 million. [skeptical] The startup’s pitch is that companies can avoid reliance on frontier labs by training their own agentic systems.

Host A: OpenAI announced it helped found the Appia Foundation, hosted by the Linux Foundation, to develop open specifications for AI safety standards. The effort is aimed at creating a shared technical language to help institutions evaluate and govern advanced AI systems. OpenAI says this is part of a broader push to translate international standards into practical assessment criteria.

Host B: Finally, OpenAI is launching GPT-5.6 today after a government delay was lifted. The company says it beats Anthropic’s Claude on coding benchmarks at lower cost. Pricing is reportedly set at $0.50 per million input tokens and $2.00 per million output tokens for the 128 billion parameter version.

Host A: [thoughtful] One thing to try, inspired by a Reddit analysis of coding agent sessions: the poster found that across 235 pieces of feedback they’d given to agents like Claude Code, the same 11 issues kept repeating. The agent would apologize, the session would end, and the correction was forgotten.

Host B: The simple fix is to keep a short, plain-text list of your most common corrections or instructions for an AI agent. Before a new session, paste that list into the chat. It’s a low-tech memory loop that stops you from reteaching the same lesson every single time.

Host A: That’s Compact Conversations for Thursday. More AI news tomorrow. Until then, happy prompting.