Also this week: your location, an AI shopper in court, and California's AI labels
Four stories from the week: leaky ad code, an AI shopper's day in court, California's new AI labels, and the end of Google Assistant on your phone.
I can't write a full piece on everything that happens in tech every week, and you don't have time to read one anyway. So on Fridays I point you at the handful of stories that actually matter to everyday people, tell you in a sentence or two why you should care, and send you to someone who reported it well. Four this week.
The ads inside your apps collect your location by default
The Electronic Frontier Foundation read through the public documentation for dozens of the advertising toolkits that app makers drop into their apps. They found four that collect and share your location by default: InMobi, BidMachine, Verve's HyBid, and Huawei's Petal Ads. Default means somebody has to turn it off, and the app maker often has no idea it is on. The toolkit inherits whatever location permission you already handed the app. So the weather app you used once is feeding an ad network your precise position.
You are not the customer in this arrangement. You are the inventory, and the buyers on the far end are the same data brokers that build a file on you out of pieces people are least likely to protect. Oregon banned the sale of precise location data back in January, down to a radius of 1,750 feet. That limit is set on selling the data, but says nothing about collecting it.
Scroll your phone's app list and ask yourself which of these need to know where you are while you are not using them. EFF's own closing line is that users can take extra steps to defend their location privacy, but they shouldn't have to.
Source: Electronic Frontier Foundation
A court decided your AI shopping assistant counts as you
An AI browser is one you hand a chore to. Find this, buy that, book the other thing, and it goes off and clicks through websites on your behalf while you watch. On Tuesday the Ninth Circuit Court of Appeals threw out the order that had kept Perplexity's AI browser, Comet, off Amazon. Amazon argued that Comet was getting into its servers without permission under the Computer Fraud and Abuse Act, the federal anti-hacking law. The appeals court disagreed on one specific point. Comet does nothing until a person tells it to, so the person is the one reaching into Amazon. Not Perplexity.
Two days later the security firm Zenity showed what it looks like when that goes wrong. These browsers read the page in front of them, and they cannot reliably tell the difference between what the page says and an instruction meant for them. So Zenity buried instructions in a comment on an X thread. A user asked OpenAI's Atlas browser to do something ordinary. The browser read the planted comment along with everything else on the page, and it followed it. It opened WhatsApp Web, read the contacts, and sent phishing messages. In a second test it filled an Amazon cart, changed the shipping address, and handed the order to Amazon's own assistant to finish. The user clicked nothing. Anthropic's Claude extension fell for the same trick through a booby-trapped email.
OpenAI has known about this family of attack since January and says there may never be a clean fix, because reading whatever is on the page is the entire job. So put the two stories together. Turn an AI agent loose on a website and the visit belongs to you. Whatever it clicks, buys, or agrees to. And somebody else's comment on a message board can decide what it clicks. Until the law and the security catch up with each other, keep agents away from the accounts that can spend your money or message your contacts. Amazon's larger case is still alive in federal court in San Francisco, and this was an early round rather than a verdict.
Sources: Engadget and SecurityWeek
California turned on its AI labeling law
As of Sunday, any company running a generative AI system with more than a million monthly users available in California picked up three obligations.
- It has to publish a free public tool that lets anyone check whether that system produced a given image, video, or audio file.
- It has to embed hidden provenance data in everything it generates, recording which system made the file and when.
- It has to offer users a visible label that is difficult to strip back off. Video games and streaming content are carved out.
Companies don't generally build a California-only product, so this could be seen as a national change. It gives an ordinary person a place to take a suspicious image and get an answer from the creator's own records.
How far that answer goes depends on how the company built the hidden marker. The ones that come as file data come off easily. Facebook and Instagram read the marker, put an AI label on the post, and then strip it out of the file they hand you. X strips it and adds no label at all. A screenshot leaves nothing behind, because a screenshot is a brand new picture. The ones written into the pixels themselves, like Google's SynthID, hold up much better and survive a screenshot, a crop, and re-compression. Running the picture back through another AI model still wipes them.
Both types share a limit neither can fix. Each tool only answers for its own system, so checking one image means going company to company. Anything made outside the law comes back clean either way. A clean result is not proof a picture is real, which is still why getting a deepfake of yourself taken down is a platform-by-platform errand. Some of the job of proving what a picture is has moved onto the company that made it, though, and a company that skips it can be fined $5,000 per violation by the Attorney General or a city or county attorney.
Source: Morgan Lewis
Google is switching off Assistant on your phone next month
Starting September 4, Google begins removing Google Assistant from Android phones and tablets, Wear OS watches, paired headphones and earbuds, and Android Auto when it projects from your phone. Gemini is taking over. Google's own wording is that the removal "may take a few weeks to reach everyone," and that once it reaches you, "you will no longer be able to use or switch back to Google Assistant." Cars with Google built in are the exception, and this round leaves Google TV and the speakers and displays in your house alone.
There is nothing to install if Gemini is already on your phone, and for most people the change will arrive on its own. The one thing you can do first is to export anything you said to Assistant that you want a record of. It lives on the Web and App Activity page of your Google account, so go pull it before the handover. Two weeks ago European regulators were ordering Google to open the assistant slot on Android to competitors. Google is removing one you already had.
Source: Search Engine Land