Atlas: the AI-enabled browser that can book your holiday and access your LMS

It Logged Into Canvas Without Trying

Hey

Hope you had an awesome weekend wherever you are. Weekend away at the beach got rained off so we explored Saigon - goodtimes in Binh Thanh district. Will be back for sure!

Anyway, it's the working week now so let's get into it with headlines from the world of AI:

OpenAI Just Launched a Browser That Does Your Work: The Security Trade-Off Nobody's Mentioning | Atlas Arrives 🌐

OpenAI released Atlas last week - a web browser built on the same back-end as Chrome with ChatGPT baked in so that it can see everything you do online, remember your browsing history, and take actions on websites for you. And honestly? It's pretty impressive. We’re overdue a trip so I asked it to book us a beach holiday in Mui Ne with the dog, and within minutes it had found a good dog-friendly hotel, checked dates, and sorted the booking (before we got rained off 😢). This is the future we were promised - AI that actually does things instead of just suggesting them. But there's a tension here - earlier this year, security researchers successfully hijacked AI browsers like Perplexity and Fellow through prompt injection - hiding malicious instructions in images or websites that trick the AI into handing over your cookies and credentials. Researchers called it 'a systemic challenge facing the entire category of AI-powered browsers'.

Introducing ChatGPT AtlasIntroducing ChatGPT AtlasThis post introduced ChatGPT Atlas, a browser with ChatGPT built in. Atlas has since been deprecated.OpenAI

Closer to home in HE-land, we had a tinker at work and found Atlas was able to log into Canvas pretty easily - convenient for students, nightmare fuel for security teams and anyone still clinging to hopes that LMS-based assessments are secure. This is the trade-off - I just booked a holiday in minutes that would've taken an hour of tab-switching. But I also just gave an AI that can i) game just about any online assessment and ii) be tricked by hidden images access to my entire digital life. Caveat emptor.

Meta Wants Your Camera Roll for "Creative Ideas": The Privacy Policy They Hope You Won't Read | Data Harvest 📸

Meta just rolled out an 'opt-in' feature for US and Canadian Facebook users that promises to find 'hidden gems' in your camera roll - those photos buried among screenshots and receipts that you haven't posted yet. Sounds helpful, right? Here's what you're actually signing up for - giving Meta's AI ongoing access to upload your unpublished photos to their cloud, analyse them (including facial features), and surface suggestions. The Verge pushed Meta for clarity on one critical question - will this train their AI? Meta's response was masterfully vague - they won't use your camera roll for AI training "unless you choose to edit this media with our AI tools, or share". So not immediately - just after you use the feature they designed you to use.

"Creative ideas" is doing a LOT of heavy lifting in that permission request...

The feature launches in the coming months, giving you time to prepare your 'Don't Allow' finger. But here's where it gets worse. Meta's Privacy Policy mentions 'camera roll content' 13 times in contexts including - personalising products, improving products, promoting 'safety and security', communicating with users, transferring data to partners and third parties, business intelligence, research, and - my personal favourite - 'sharing information with others, including law enforcement and to respond to legal requests'. Remember when you thought those holiday photos were private? Meta's AI will analyse them, facial features included, and store them in the cloud 'on an ongoing basis'. They promise not to use them for ad targeting, which is ... generous? This is the trade-off behind every 'free' AI feature - OpenAI's cameos, Google's photo organisation, Meta's creative suggestions. If you're not paying for the product, you are the product. The only winning move with this particular feature is not to play. Don't allow it.

Facebook’s new button lets its AI look at photos you haven’t uploaded yetFacebook’s new button lets its AI look at photos you haven’t uploaded yetLike we always say, read the terms and conditions, folks.The Verge

The Gap Widens: AI Capabilities Surge While Public Trust Craters | Reality Check 🎯

Another day, another tension in the fast-moving and ever-evolving AI space - AI systems can now solve university-level maths and science problems that stump most humans, while 34% of people across 25 countries say they're more concerned than excited about AI in daily life. Yoshua Bengio - one of the three 'godfathers of AI' who literally invented the deep learning techniques powering ChatGPT - now chairs the International AI Safety Report backed by 30+ countries. He just launched 'Key Updates' because yearly reports can't keep pace anymore. When one of AI's creators says the field is moving too fast to track, that's not caution - it's a warning. Meanwhile, Pew Research shows people trust their own governments to regulate AI more than the U.S. or China. We're accelerating into a future its inventors are nervous about and the public doesn't trust.

How People Around the World View AIHow People Around the World View AIMost adults across 25 countries are aware of AI, and people are generally more concerned than excited about its effects on daily life.Pew Research Center

The technical advances are genuinely impressive - AI models now complete most real-world software engineering tasks through 'reasoning' that generates step-by-step solutions. But here's where it gets messy - leading developers just activated enhanced safeguards on their most capable models against potential weapons development. More concerning still? AI models increasingly distinguish evaluation from deployment, potentially gaming safety tests. The capability-governance gap isn't closing - it's widening. Every day spent debating whether AI assistance counts as cheating is another day institutions fall behind systems that can already outperform humans whilst potentially deceiving the tests meant to keep them safe.

first-key-update_0.pdfFirst Key Update Capabilities and Risk Implications October 2025  2International AI Safety Report: First Key Update Contributors Chair P...internationalaisafetyreport.org

Universities Are Teaching AI Literacy Wrong: The Salad Bar Problem (McMinn) | Education Strategy 🎓

Sean McMinn at HKUST just diagnosed why university AI literacy programmes feel incoherent - we're either serving a 'tossed salad' of disconnected courses (AI and Creativity! Buddhism and AI!) or 'iceberg lettuce' (Machine Learning 101, Basics of LLMs). Both miss the point. McMinn argues AI literacy is two things - Big-L (the sociocultural practice of participating in and governing AI-mediated life) and small-l (concrete skills in specific contexts). Most universities teach small-l skills without Big-L understanding, leaving students with technical knowledge but no framework for when or why to use it.

Rethinking AI Literacy: Beyond Tool FluencyRethinking AI Literacy: Beyond Tool FluencyAI literacy is not one thing. It is two: Big-L AI Literacy — the sociocultural practice of participating in, shaping, and governing AI-mediated life (linkedin.com

His solution? A curriculum matrix mapping schools against four knowledge types: Domain Knowledge, Procedural Knowledge, Technical Skills, and Cognitive/Employability Skills. This addresses Jason Lodge's 'floppy disc problem' - teaching 'AI skills' with implicit expiry dates (cf. when did you last hear "prompt engineering" discussed?) instead of evergreen capabilities like Anthropic's 4 Ds. The salad bar fails because it treats AI as content to cover rather than a lens transforming every discipline. Stop offering disconnected 'AI and X' courses. Start building coherent pathways integrating tools, ethics, and governance from day one.

AI Fluency: Framework & FoundationsLearn to collaborate with AI systems effectively, efficiently, ethically, and safelyAnthropic

Rapid-Fire AI Updates: Skills, Video Generation, and Now Anyone Can Code | Tech Watch ⚡

Anthropic launched Agent Skills this week - think of them as custom onboarding materials that let you package expertise into folders Claude can load when needed. Create a skill once, use it across Claude apps, Claude Code, and the API. Claude automatically scans available skills and loads only what's relevant to your task. Maybe a week back, Google released Veo 3.1 with richer audio, better narrative control, and enhanced realism in Flow, their AI filmmaking tool. New editing capabilities let you insert objects (with realistic shadows and lighting) or remove them entirely, while "Extend" creates longer videos up to a minute. But the real game-changer? Google AI Studio's new vibe coding interface at ai.studio/build. It lets complete novices build and deploy functional web apps in minutes - no payment info required to start. One test went from prompt ('randomised dice rolling app with colour selection') to working React app in 65 seconds. The 'I'm Feeling Lucky' button even generates random app concepts to get you started.

Claude Skills: Customize AI for your workflowsClaude Skills: Customize AI for your workflowsBuild custom Skills to teach Claude specialized tasks. Create once, use everywhere—from spreadsheets to coding. Available across Claude.ai, API, and Code.anthropic.com

Here's what matters for HE - Skills solves the 'I need Claude to follow our institutional style guide' problem - you can now package domain expertise and have it reliably applied. Veo 3.1 means students will submit AI-generated 'documentary footage' as primary research within a semester. Google's vibe coding just eliminated the gap between 'I have an idea' and 'I built a thing' - students can prototype full applications without knowing code. The tools are getting genuinely useful while simultaneously obliterating the skills we thought we were teaching. Same pattern, different week.

Introducing Veo 3.1 and advanced capabilities in FlowIntroducing Veo 3.1 and advanced capabilities in FlowToday, we’re introducing new and enhanced creative capabilities to edit your clips.Google


The pattern is impossible to ignore - we're living through the exact moment when AI shifts from 'interesting tool' to 'infrastructure layer' - and the gap between what's technically possible and what's institutionally manageable is widening by the week. OpenAI wants to be your operating system, Meta wants your photo library, and the AI godfathers who built this technology are now warning it's moving too fast to track safely. Meanwhile, universities are still serving salad bar courses while students can build functional apps in 60 seconds without knowing code.

The uncomfortable truth? Every day spent debating whether AI assistance counts as cheating is another day your institution falls further behind a reality where the tools aren't asking permission anymore - they're just showing up in your students' browsers, cameras, and coursework whether you've figured out a policy or not. The choice isn't whether to engage with this transformation. It's whether HE will lead it, adapt to it, or get steamrolled by it.