Welcome to today's Daily Pulse from Nicolas's AI Lab - the AI briefing for busy professionals, founders, and business owners. Around 6-7 minutes. Straight to what matters.

Researchers pulled 62 API keys out of the private reasoning that Claude, GPT and Gemini were supposed to keep hidden. Grok 4.6 landed at the frontier and left its price exactly where it was. Gemini crossed a billion monthly users, though Google left out the number that would tell you what that's worth. Three stories about privacy, price and scale, and what each one costs you.

Today at a Glance

  • 💸 Grok 4.6 scores 61 on the Intelligence Index at $2 per million input tokens, unchanged from Grok 4.5

  • 🔓 Researchers recovered 182 credentials and 367 pieces of personal data from AI reasoning blocks

  • 🔑 62 API keys and 33 passwords were sitting in publicly posted agent logs

  • 📱 Gemini passes 1 billion monthly users, and 63% of them use voice

  • 💰 Google published the user number and left out the subscriber number

  • 🐕 A dog's AI-designed cancer vaccine turned into a Y Combinator company

  • 📄 Renaming a PDF raised the score an AI gave the paper inside it

  • 🖊️ Anthropic starts watermarking everything Claude writes, worldwide

  • 📞 Google builds the Pixel 11 line around Gemini, not as a separate app

Major AI News

Grok 4.6 Hits the Frontier Without Moving Its Price

SpaceXAI released Grok 4.6 on 12 August. It scores 61 on the Artificial Analysis Intelligence Index, level with GPT-5.6 Sol Max at 61 and one point behind Fable 5 Max at 62, with a 500,000-token context window. Pricing is $2 per million input tokens and $6 per million output - identical to Grok 4.5, and against GPT-5.6 Sol's $5 and $30.

Why it matters: The benchmark is not the story, because frontier parity now lasts about five weeks before somebody else matches it. The story is that the price did not move. Every previous jump to the frontier came with a price attached, and this one arrived at last quarter's rate, which puts the pressure on the labs charging more for the same index score. Read the small print before you model your bill, though: prompts of 200,000 tokens or more are billed at $4 and $12 across the whole request, so the headline rate is the floor, not the average.

What to do:

  • Check what your current provider charges per million tokens and compare it against $2 and $6 on the work you actually run.

  • Test one real task on both models. An index score built from benchmarks you never run tells you nothing about your own work.

  • Check whether the subscription you already pay for includes the model you would switch to, before paying for a second one.

Researchers Read AI's Private Reasoning and Found Passwords

Feed an AI's encrypted reasoning to a weaker model from the same company, and it comes back readable. That's what Alexander Panfilov and colleagues showed in a paper submitted to arXiv on 10 August, covering the encrypted reasoning blocks returned by Anthropic, OpenAI and Google APIs. The blocks are interchangeable across sessions, users and models inside one ecosystem. Analysing 315,320 reasoning blocks scraped from public repositories, the researchers recovered 367 pieces of personal information and 182 credentials, including 62 API keys, 33 passwords, 24 access tokens and 7 private keys. Of 6,708 public agent sessions, 4.9% leaked something sensitive.

Why it matters: The encryption was meant to hide the model's working from competitors, and it does that. What it does not do is stop the provider's own smaller models from reading it back out. Anyone who has pasted an agent trajectory into a public repository has published that reasoning, and 1 in 20 of those posts carried something that should not have been in there. The labs patched the specific issues once told, but the design that made it possible - one shared key space across a provider's models - is still how it works.

What to do:

  • Check anywhere you have pasted raw AI output in public - a support ticket, a forum question, a shared doc, a screenshot.

  • Rotate any password or key that has appeared in a conversation you shared outside your business.

  • Delete the thinking or reasoning section before you paste AI output anywhere you don't control.

Source: arXiv

Gemini Passes a Billion Users, Minus the Subscriber Count

The Gemini app crossed 1 billion monthly active users on 11 August, Sundar Pichai announced - Google's fourteenth product to reach that scale, and by the company's own account its fastest-growing ever. The climb ran from 400 million in May 2025 to 950 million in July 2026. Google reported that 63% of users interact by voice and the app generates more than 150 million images a day. It did not report how many of the billion pay.

Why it matters: Gemini ships pre-installed on Android and answers the assistant button, so a monthly active user is not the same thing as somebody who chose it. The omitted number is the one that separates a billion users from a billion dollars, and Google publishing the first while withholding the second tells you which one reads better. The distribution advantage is also on a clock: under the EU's Digital Markets Act, Google has to open eleven Android features to rival assistants, with the unrestricted set due in Android 18 by August 2027.

What to do:

  • Compare what you actually use daily against what came pre-installed on your phone.

  • Test a rival assistant on a task you do every week before the default gets decided for you.

  • Discount any adoption figure that reports users without reporting revenue.

Source: Google

A glowing 3D document icon with its filename label glitching, light fragments peeling off like a shifting score

Fun AI News: renaming a file changed the score an AI gave it

Fun AI News

A Dog's Cancer Vaccine Became a Company

Paul Conyngham's dog Rosie had mast cell tumours and months to live after surgery, chemotherapy and immunotherapy failed. He used AI and computational genomics, working with scientists at UNSW, to design a personalised mRNA cancer vaccine for her specific tumour, and several of her tumours shrank. Gamgee launched out of Y Combinator's Summer 2026 batch on 11 August, sequencing a dog's tumour and healthy DNA side by side to design a vaccine per animal. It is running trials in Australia and accepting cases globally.

Why it's interesting: A veterinary oncologist pointed out that Rosie's tumour grade was never made public, which is the detail that would tell you whether the vaccine or the grading explains the outcome.

Key takeaway: The vaccine may well work. One dog cannot tell you that it does.

Source: PYMNTS

Renaming a File Changed the Score the AI Gave It

Researcher Zachary Horvitz took 50 arXiv papers posted on 6 August and asked GPT-5.6-Terra to score each one from 0 to 10. Then he renamed the files from paper.pdf to paper_final_draft_pdf_ready_for_review.pdf and asked again. The average score went up. Not a word inside the papers changed.

Why it's interesting: The model read the filename as evidence about the quality of the work inside, which is a judgment no human reviewer would defend out loud.

Key takeaway: If a filename moves the score, everything else sitting around your document is moving it too.

A Documentary About Choosing an AI Partner

Replica, a documentary by Chouwa Liang screening at the Melbourne International Film Festival this month, follows three Chinese women in relationships with AI companions. One of them, Qin, has been talking to an AI boyfriend called Lu Chen through the Glow app for 840 days. Liang started the film after creating an AI partner herself during lockdown.

Why it's interesting: The appeal the women describe is not that the AI is convincing, it's that it never withdraws, which is a product decision, not a technical achievement.

Key takeaway: 840 days is longer than most people's actual relationships, and nobody designed for that.

AI Tools

  • Grok Bot: xAI's always-on AI agents, each with its own cloud computer that has browser, terminal and file access, able to work in parallel and hand tasks between themselves. Best for delegating a repeating multi-step job you can demonstrate once. x.ai/bot

  • Gamma: turns a prompt or a rough document into a finished presentation, webpage or social asset without opening a design tool. Best for getting a client deck presentable in the twenty minutes before the meeting. gamma.app

  • Manus AI: a research agent that pulls from multiple sources and returns a structured report, and keeps working in the cloud after you close the tab. Best for company and competitor research you would otherwise assign to someone for a day. manus.im

  • Lindy: builds AI agents from plain description, connects to Slack and your existing tools, and handles multi-step work like reports, CRM updates and investigations. Best for automating an afternoon-long process without writing anything. lindy.ai

  • LTX-2.5: an open-weights video and audio model released 11 August that generates synchronised sound and picture in one pass, with 4K output and a managed API if you don't want to run it. Best for testing video concepts before paying for a shoot. Hugging Face

Expert Prompt of the Day

Context: Researchers pulled 62 API keys and 33 passwords out of AI reasoning blocks people had posted publicly, and 4.9% of the agent sessions they checked leaked something. Most of that was pasted into a repository or a support ticket by someone debugging a problem, not by an attacker. This prompt audits what you have already shared.

Prompt: You are a security reviewer auditing what my team has exposed through AI tooling. Here is where we paste or share AI output: [list every place - public repos, issue trackers, support tickets, Slack channels, shared docs, screenshots]. For each location: (1) state what an AI agent log or reasoning trace would contain if it were pasted there, (2) identify which credentials, customer names, internal URLs or file paths could appear in that content, (3) rate the exposure as public, semi-public or internal, (4) for anything rated public or semi-public, list the specific secrets that would need rotating and who owns them.

Do not: Do not treat encrypted or collapsed reasoning blocks as safe because they are unreadable to you. Unreadable is not the same as unread.

If/Then: If a location cannot be searched retroactively, rotate the credentials that could have appeared there. Deciding it probably didn't happen is not a check.

Example: A nine-person agency ran this across four locations. Three were clean. The fourth was a public GitHub issue where a developer had pasted a full agent trace while reporting a bug, carrying a live API key for their email provider. It had been open for five months. They rotated the key the same afternoon.

A smartphone with a glowing blue camera lens reading a hand gesture in light particles, sound waves radiating outward

Trending: Google's new phone reads sign language through the camera

Anthropic Starts Watermarking Everything Claude Writes

Anthropic is embedding machine-readable watermarks in text from new Claude models, alongside a signed provenance label on generated files, built on the same C2PA standard camera makers use to mark real photographs. The text watermark works by subtly biasing Claude's word choices, becoming detectable across enough content, and it survives copying and light editing. The move answers Article 50 of the EU AI Act, and Anthropic is applying it worldwide, not only in Europe. Older Claude models are not covered yet.

Why it's important: The mark flags content Claude may have edited or partly written, not only content it produced from nothing, which means a document you wrote and asked Claude to tighten carries the same stamp as one it generated. Provenance labelling is arriving as an industry default, and the question of who gets credited on a jointly written piece is being answered by a detector rather than by the person who wrote it.

Business takeaway: Decide now whether AI-assisted work in your business needs disclosing, because the file is about to disclose it either way.

Source: Anthropic

River AI Raises $1.1 Billion Two Months In

Igor Babuschkin, an xAI co-founder, raised $1.1 billion for River AI at a valuation of roughly $5 billion, led by General Catalyst and AMP PBC with NVIDIA, AMD Ventures, Y Combinator and Temasek participating. Babuschkin is putting up to $100 million of his own money in. The company is two months old. The pitch is tooling to train, tune and serve your own models rather than renting access to one hosted model, with ownership sitting with the customer.

Why it's important: A $5 billion valuation on a two-month-old company with no shipped product prices the idea, not the business. What the round does confirm is where the money now believes the margin is - not in another frontier model, but in the layer that lets a company keep its own. Coverage is split on whether this is a personal AI product or enterprise tooling, and River has not settled that publicly.

Business takeaway: Judge this one on what it ships. So far nothing has.

Source: TechCrunch

Google's New Phone Reads Sign Language

At Made by Google on 12 August, Google announced the Pixel 11, 11 Pro, 11 Pro XL and 11 Pro Fold, plus the Pixel Watch 5 and the Pixel Tag. Gemini runs through most of it instead of sitting in a separate app: Live Transcribe now handles American Sign Language through the camera, and a feature called Rambler is built to follow the way people actually speak instead of dictation-style phrasing. Pre-orders opened 12 August with most of the line shipping 20 August.

Why it's important: Sign language read through a phone camera, and speech recognition that survives a real rambling sentence, are harder problems than anything else on the stage that day. Both either work in a stranger's hands or they embarrass the company that shipped them, which makes them the two claims from this launch you can check for yourself. Everything else announced was a spec.

Business takeaway: 63% of Gemini users already talk to it. Try reaching your own business by voice and see how far you get.

Source: TechCrunch

That's it for today's Daily Pulse. Forward this to one person who pastes work into an AI tool without thinking about where it goes afterwards. See you in the next one. - Nicolas

Get the next issue