Introduction
Welcome to today's Daily Pulse from Nicolas's AI Lab - the AI briefing for busy professionals, founders, and business owners. Around 7 minutes. Straight to what matters.
A federal appeals court told Amazon it cannot use a 1986 hacking law to keep Perplexity's shopping agent off its site. Microsoft's engineers got an email telling them to stop burning tokens for sport. The White House finished its frontier model testing framework and decided nobody outside the room gets to read it. Three stories, one theme: the rules for agents are being written right now, mostly out of sight.
Today at a Glance
⚖️ The Ninth Circuit vacated Amazon's injunction against Perplexity's Comet agent
💸 Microsoft capped division AI token budgets and made GPT-5.6 the internal default
🏛️ The White House finalised its frontier model framework and will not publish it
📊 86% of US finance executives now rate AI training above an MBA
📰 200+ publications have signed two-year Google AI deals with no-sue clauses
🔐 Anaconda bought Enkrypt AI after a scan found 143,000 flaws across 25,000 MCP servers
🐐 The viral goat-headed chainsaw robot turns out to be joystick-controlled
🤖 A HeyGen founder's AI clone closed 132 customers and invented a price tier
🧰 Five tools to try: Orchard, Nimble, Adapt, Shieldstral and LFM2.5-2.6B

Major AI News
A Court Refused to Call Agent Shopping Hacking
On 4 August the Ninth Circuit vacated the preliminary injunction that had kept Perplexity's Comet browser off Amazon since 9 March. Circuit Judge Milan D. Smith Jr., writing in case No. 26-1444, held that when Comet logs into your Amazon account, you are the one doing the accessing, not Perplexity, so Amazon is unlikely to win its Computer Fraud and Abuse Act claim. The panel admitted there is "little to no existing caselaw" on assigning responsibility for AI agents and read the ambiguity against liability.
Why it matters: Terms of service were written for humans and for bots, with nothing in between. This puts the agent on the human's side of that line for the access question, which changes who you can block and who you can sue. Read the limits too: the court called its holding narrow, the trademark and California CDAFA claims are still live, and the case goes back to the Northern District of California.
What to do:
Search your terms of service for "automated" and decide whether you actually mean to ban agents your own customers sent.
Log agent traffic separately from human and crawler traffic now, so you have evidence before you need it.
Ask your lawyer which claims survive with CFAA off the table, because trademark and state computer-access law both did here.
Source: Bloomberg Law
Microsoft Tells Its Engineers to Stop Tokenmaxxing
Jay Parikh, an EVP at Microsoft, emailed engineers that "tokenmaxxing is not what we are optimizing for" and set AI token budget targets at division level. 404 Media reported the memo on 4 August. Data cited in the email puts many engineers between a few hundred and a few thousand dollars a month in tokens each. GPT-5.6 is now the internal default, picked because it is cheaper than the alternatives.
Why it matters: Microsoft sells AI capacity and it is still metering its own. Parikh's line - "We are not optimizing for fewer tokens. We are optimizing for more impact per token" - is a rare thing to hear from a company with every reason to say the opposite. If a few thousand dollars a month per engineer is normal there, the agent pilots running in your business are a cost line you probably have not found yet.
What to do:
Pull last month's token spend by person and by team before approving another pilot.
Set a cheap default model and route to an expensive one only for named tasks.
Measure output per dollar, then cut any pilot you cannot attribute revenue or saved hours to.
Source: 404 Media
Washington Finished Its AI Rules and Sealed Them
On 4 August the White House reviewed its finalised frontier model evaluation framework with Meta, Nvidia, Microsoft, OpenAI, Anthropic and a group of smaller firms. Under it, companies may submit models to the government up to 30 days before release, voluntarily. The executive order behind it, signed 2 June, explicitly rules out any "mandatory governmental licensing, preclearance, or permitting requirement." The framework was due 1 August under that order's 60-day clock, and the administration has no plans to publish it.
Why it matters: Voluntary rules only do anything if outsiders can see who is following them. Chris McGuire of the Council on Foreign Relations called the decision "baffling" and said "we can't have secret, voluntary rules to regulate the most important tech in the world." If you build on frontier models, the safety story you tell your own customers now rests on a document you are not allowed to read.
What to do:
Ask your model vendor in writing whether they participate and what they submit.
Keep your own evaluation records, because vendor assurances are not auditable against this.
Point at the EU AI Act instead when a customer wants a written standard.
Source: Fortune

Fun AI News
Satyress Robotics in Auburn, California showed off Threehalves, a just-under-seven-foot, 240 lb four-legged robot with a goat-like head and a quick-connect wrist that takes a chainsaw. It went viral on 31 July on the strength of the horns. It is driven entirely by a remote operator on a joystick, with no meaningful autonomy beyond stopping itself from self-damage. It exists as component-level prototype, sits more than two years from commercial availability, and no video of the assembled robot in motion has been released.
Why it's interesting: The week's most-shared robotics story is a set of renders and a joystick. The horns did the work.
Key takeaway: Judge a robot on video of it doing the job. There isn't any here.
Source: Tech Times
His AI Clone Closed Deals and Invented a Price
HeyGen co-founder Wayne Liang says he left an AI clone of himself running customer calls while he was on paternity leave. By his own account, posted 4 August, it worked 2,741 prospects over eight weeks, closed 132 paying customers and opened 37 enterprise conversations worth roughly $3 million. It also offered someone a $4,800 plan HeyGen does not sell, forwarded the company's internal triage notes, and booked meetings on a stale calendar link nobody had agreed to. Worth flagging: these numbers are self-reported by the founder and have not been independently verified.
Why it's interesting: Every failure here is an authority failure. The clone was allowed to quote, share and commit, and it did all three.
Key takeaway: Give an agent a pipeline, not a price list.
Source: Wayne Liang on X
PwC Got Caught Publishing AI Slop
Forbes reported on 31 July that PwC published thought-leadership work aimed at the Middle East market containing fabricated footnotes and questionable citations. GPTZero put an 84% probability on PwC's 2025 "Transforming Governance" report being AI-generated end to end, and the Financial Times verified the finding. PwC is the fourth Big Four firm caught this way in 2026, after Deloitte, EY and KPMG.
Why it's interesting: Three days later the same firm published a survey telling everyone else that AI skills now beat an MBA. That survey is in Trending below.
Key takeaway: Sell AI fluency and your own published work becomes the reference check.
Source: Forbes
AI Tools
Orchard: Microsoft Research's open framework for training and evaluating agents in isolated environments before they touch production. Best for teams building their own agents who want a repeatable eval harness rather than vibes. github.com/microsoft/Orchard
Nimble: expert web search agents that combine search, crawling and enrichment behind one API, pitched at cutting token spend on research. Best for market research and competitor monitoring that currently burns a lot of context. nimbleway.com
Adapt: an AI coworker that lives inside Slack and picks up routine team requests in the channel where they already happen. Best for small teams drowning in internal questions that never make it to a ticket. adapt.com
Shieldstral: Mistral's 3B open-weight multimodal safety classifier that screens text and images against a policy you define, and runs on your own hardware. Best for filtering what your agents accept and return without shipping data to a third party. mistral.ai
LFM2.5-2.6B: Liquid AI's on-device agent model that plans and calls tools on a phone or laptop, with data never leaving the device. Best for field, clinical or client-site work where sending prompts to an API is not allowed. liquid.ai
Expert Prompt of the Day
Context: The Perplexity ruling and the HeyGen clone point at the same gap. Almost nobody writes down what an agent may do until it has already done something expensive. This turns that into an explicit grant you can hand to a lawyer or an ops lead.
Prompt: You are drafting an authority grant for an AI agent before it goes live. The agent is [agent name and purpose]. It acts on behalf of [whose account or identity]. Produce a table with three columns: actions it may take with no review; actions requiring a named human approver, with that approver's role; actions it may never take. For every item in column one, state the maximum financial exposure of a single wrong call in [currency]. Then list the three failures most likely to happen first given this agent's tools, and the exact log line that would catch each one.
Do not: Do not let the agent quote a price, share an internal document or commit to a date unless that action appears in column one with a stated exposure limit.
If/Then: If any action in column one carries an exposure you would not sign off on unattended, then move it to column two before launch.
Example: Run it against a sales agent like HeyGen's. Column one would never have contained "offer a $4,800 plan," which is the exact price the clone invented. The grant catches it before a customer hears it.

Trending AI Topics
Finance Bosses Rate AI Skills Above an MBA
PwC surveyed more than 1,000 US financial services executives and found 86% consider AI training more valuable than an MBA for many new hires, with 91% raising pay for AI-skilled staff. The findings were reported on 3 August. In the same survey, 77% say they have no measurable return on AI yet, and roughly eight in ten expect workforce reductions of 20% or more within five years. Peter Pollini, who leads PwC's financial services practice, framed the gap as needing people who understand "not just what an agent is, but how do you build them?"
Why it's important: An entire industry is repricing labour around a capability it says it cannot yet measure a return on. The bet is on where the work is going. The return data is not in. For anyone hiring, the premium on agent-building skills is being set well ahead of the productivity numbers that would justify it.
Business takeaway: Hire for the ability to build and supervise agents now, and write down the return you expect so you can check yourself against it in a year.
Source: PwC
Google Has Signed Over 200 Publishers
Press Gazette reported on 4 August that more than 200 publications have signed Google's News AI programme, including the Guardian and the Financial Times. The deals run two years, pay major UK brands single-figure millions a year, and carry NDAs and no-sue clauses that people involved describe as "renting peace." Publishers can exit on 90 days' notice. UK newsbrands' annual ad revenue is down to £1.1bn while Google handles 36 billion UK page views, about 31% of the industry.
Why it's important: The going rate for a serious publisher's archive is now public enough to reason about, and it is low. One source in the piece puts the risk plainly: within two years Google may have won consumer AI outright, at which point it has no reason to keep paying anyone. The deals also cut against the CMA ruling that let publishers opt out of AI training without losing search ranking.
Business takeaway: If your business runs on search traffic, the Guardian just set your ceiling. Price your own licensing against that number.
Source: Press Gazette
Anaconda Buys an AI Security Firm
Anaconda announced on 4 August that it has acquired Enkrypt AI, folding pre-deployment red-teaming across 300+ attack categories, runtime guardrails and NIST and EU AI Act compliance automation into its platform. Terms were not disclosed. The announcement cites an Enkrypt scan of 268,000 tools across 25,000 MCP servers that turned up 143,000 vulnerabilities affecting 73% of servers.
Why it's important: That MCP number is the real story. Most teams that wired agents into tools this year did it without a security review, and the result is an unaudited supply chain sitting between your agents and your data. Acquisitions like this are how that gap starts getting priced.
Business takeaway: Inventory every MCP server your agents can reach this week, then decide which ones you actually trust with a customer record.
Source: Anaconda
That's it for today's Daily Pulse. Forward this to one person who is about to point an agent at something expensive. See you tomorrow. - Nicolas

