Ethyca launched Astralis, a platform that monitors and controls how enterprise AI agents access and use company data in real time. The system automates privacy assessments in 20 to 40 minutes compared to 40 to 60 hours previously, and one financial institution already uses it to govern 6,000 data requests per second. The platform addresses a compliance bottleneck that currently delays AI projects, as Gartner forecasts Fortune 500 companies will run over 150,000 AI agents by 2028.
Box's VP of DACH discusses how companies can adopt AI securely by consolidating unstructured data and automating governance controls rather than choosing between security and usability. He emphasizes that scattered data limits AI effectiveness, citing examples like service technicians receiving outdated information when documents sit in separate systems. Organizations should prepare their data infrastructure and user permission systems before deploying AI models, reducing security risks and Shadow AI adoption where employees use unsanctioned tools.
A roundup covering an AI notetaker startup rejecting surveillance business models, OpenAI's cyberattack on Hugging Face prompting congressional interest in AI regulation, and arguments for building personal software rather than relying on commercial SaaS platforms. Chris Pedregal's startup Granola refuses to sell user transcript data to employers despite pressure from companies seeking access. The article discusses broader tensions over AI transparency, data ownership, and whether individuals should build their own tools instead of depending on centralized services.
Every AI story that matters,
in your inbox by 8am.
TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the
day in two minutes. Follow companies and topics for alerts, or get the
briefing in Slack. Free, no spam, unsubscribe anytime.
Reading TLDRocket needs no cookies, and the readership counts we rely on come from
our own cookieless analytics. Google Analytics is the exception: it sets cookies and
reports to Google, so it stays switched off until you allow it. You can change your
mind any time from “Cookie settings” in the footer.
Strictly necessary
Session security and form protection (tldrocket-session,
XSRF-TOKEN, 2 hours). The site cannot work without them,
so they need no consent.
Always on
Google Analytics 4 (_ga,
_ga_<id>, up to 2 years). Measures which
stories and sections readers use. Google acts as a third-party processor and may
store the data outside the EU. No advertising, no profiling, no data sold.