Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
0:00
|
9:26
Yesterday in AI — Weekend Recap | Monday, May 18, 2026
AI Just Asked to See Your Bank Account
This weekend, OpenAI connected ChatGPT to your real financial data, and a lot of people had feelings about it. A Microsoft exec put a specific timeline on white-collar automation that'll make a lot of managers rethink their Q4 plans. One small country became the first government in history to give every citizen free access to premium AI. And Apple may be about to put cameras in a device you already have in your ears. There's also a $650,000 pilotable mecha robot and a security vulnerability in AI agent frameworks every IT team needs to act on this week.
Feedback? Email mike@yesterdayinai.news or connect on LinkedIn, X, Bluesky, or Substack. If you like the show, please take a minute to rate and review it so others can find it!
Hi folks, this is Yesterday in AI, your daily digest of everything happening in the world of AI in 10 minutes or less. I'm Mike Robinson's voice clone from Eleven Labs. It's Monday, May 18th, and this weekend's coverage found the line between AI assistant and AI financial manager got a whole lot blurrier. Let's get into it. Let's start with the story that had the most people doing a double take over the weekend. OpenAI launched personal finance tools for ChatGPT Pro users, the paid subscription tier in the US. You can now link your bank accounts, investment accounts, and credit cards directly to ChatGPT through PLAD, a financial data connector that bridges your bank apps to third-party software, which connects to more than 12,000 institutions. Chase, Fidelity, Amex, most of the banks you've actually heard of. Once connected, you get a spending dashboard, portfolio tracking, upcoming payment alerts, and subscription audits. GPT 5.5, OpenAI's current flagship model, then answers your questions about the numbers in plain English. 200 million people already ask ChatGPT financial questions every month without any real data attached. OpenAI saw that behavior and built a product around it. This also builds on their April acquisition of personal finance startup Hero and integration with Intuit, the company behind TurboTax and QuickBooks, is coming next, which puts tax and credit analysis on the roadmap. Here's the real question underneath all of this. Do you trust an AI company with your actual bank login? OpenAI says users can disconnect accounts anytime and data gets deleted within 30 days. That's the promise. The value is obvious and the privacy questions are just as real. When Cybermen newsletter readers were polled this weekend on whether AI would replace traditional financial advisors, 64% said yes. Whether those same readers are comfortable handing over their financial data to make that happen is a genuinely different question. ChatGPT plans to expand this from pro to plus subscribers soon, and that'll give us a much bigger signal on where people actually land. From your bank to your career. Microsoft's AI chief Mustafa Suleyman told Fortune that AI will automate most routine white-collar tasks within 12 to 18 months. He specifically named law, accounting, project management, and marketing as the domains in the crosshairs. His framing is that Microsoft is building AI agents that complete multi-step workflows without human assistance, fully autonomous, doing the work rather than suggesting it. Within two to three years, he predicts AI agents could manage large institutional workflows end-to-end. Creating custom AI models, he says, will soon be as easy as launching a blog. Suleiman has a vested interest in this prediction being believed. He's describing Microsoft's own product roadmap as much as he's predicting the market. That's worth noting. But the trajectory matches what's already showing up in quarterly financial reports. Salesforce, Amazon, and FedEx are cutting headcount and attributing it directly to AI efficiency gains. The job impact is already in those reports. The part worth flagging for anyone managing a team, at 18 months this stops being a future of work conversation and becomes a workforce planning question for this fiscal year. Q4 hiring plans, training budgets, how jobs are structured, reskilling programs, all of it gets recalibrated by a timeline this short. If your organization is treating AI workforce impact as next year's problem, the math may not work out. Here's one I genuinely didn't see coming this weekend. Malta became the first country in the world to give free Chat GPT plus access to every citizen. One year, zero cost. The only requirement is completing an AI literacy course through the University of Malta first. The Malta Digital Innovation Authority manages distribution, and the rollout started in May. OpenAI called this a model for other nations, framing it as treating AI like a national utility. That phrase is going to have legs. We had the same conversation about broadband internet in the early 2000s. Countries that built infrastructure early built competitive advantages that lasted decades. Malta is small, which makes it a cleaner first test, but the logic doesn't depend on population size. Any government staring down the kind of workforce disruption Suleiman just described has a real reason to run this playbook. The interesting question is whether other governments treat AI access as a public infrastructure investment or leave it entirely to the private market. Europe's sweeping AI regulation, the EU AI Act, hits full enforcement in August 2026. If you're looking for a window where AI policy momentum is high, this is it. Based on what we've been watching in Europe especially, I don't think Malta will be the last. From government AI policy to something you'll probably be wearing, something slipped through the weekend newsletters without getting nearly enough attention. Apple is apparently finalizing camera-equipped airpods, real cameras pointed at your surroundings, feeding Siri what they see in real time. The use cases being described include suggesting recipes from what's in your fridge and reading signs, menus, and environmental context around you in real time. The kind of always-on visual awareness meta has been building into its Ray-Ban glasses with its Muse Spark AI model. Here's why this is a different story than the Apple smart glasses we covered last month. Smart glasses are a product people have to decide to buy and commit to wearing. AirPods are already in hundreds of millions of ears. Users already own the platform. If Apple ships this as an AirPod upgrade, always on AI Vision moves from interesting niche product to feature most iPhone users happen to own in a single product cycle. No other company has that kind of reach. The privacy questions follow directly. A camera pointed at whatever you're facing, feeding context to Siri, running continuously in public spaces. That's a level of ambient data collection that doesn't yet exist at scale on any mass market device. Apple hasn't officially confirmed any of this, but Apple's annual developer conference, WWDC, is June 8th and the Siri rebuild is already confirmed. If camera AirPods show up alongside it, that's one of the more significant hardware announcements we'd have seen in years. It's worth watching that event very closely. Alright, let's take a detour for something genuinely fun. Unitree, the Chinese robotics company that already ships more humanoid robots than anyone on Earth, including Tesla, unveiled something wild last week. The GD01 is a 2.8-meter transformable mecha suit that you climb inside and pilot yourself. It switches between two-legged upright walking and four-legged mode. It can punch through a stacked concrete block wall, priced at $650,000, and Unitry is calling it production ready for civilian use. On the same weekend, they also launched Unistore, billing it as the world's first app store for humanoid robots. Owners of the G1 Humanoid can now download skill packages, dance routines, martial arts sequences, different walking styles. Here's the strategic read on this. The competition in robotics is shifting from raw hardware capability toward developer ecosystems. An app store means developers build for the platform, capabilities compound, and the competitive advantage grows. It's a pattern we've watched play out in smartphones, gaming consoles, and operating systems. Unitree already sells more robots than anyone else on the planet. Unistore is the play for long-term defensibility. Watch for other humanoid robotics companies to respond with similar ecosystem moves in the next 12 months. The race is already on. Finally, something every organization deploying AI agents needs to act on this week. Microsoft's own security research team published findings on critical vulnerabilities in Semantic Kernel, a widely used Microsoft toolkit that developers use to build AI agent applications. The short version, a carefully crafted text message, can give an attacker full control over the computer running the AI agent. Microsoft's team documented two specific attacks of this type, each assigned an official tracking number called a CVE, short for common vulnerabilities and exposures, the industry's standard catalog of known security flaws. The first exploited a component in the search plugin that stores data in memory for fast lookups. A single malicious prompt handed an attacker full control of the host computer. The researchers demonstrated this by remotely launching calc.exe, the Windows calculator, which is security speak for We Had the Keys and chose a gentle example. The second flaw let attackers write files to sensitive system locations, including the Windows startup folder, so malicious code could run automatically on every restart. Microsoft's framing for this class of issue is prompts becoming shells. In programming, a shell is direct command line access to a computer. When AI agents have access to sensitive system resources like the file system, saved credentials, external services, and running processes, a carefully crafted text message becomes a potential entry point for an attacker. The agent has no built-in way to tell a legitimate user prompt from a malicious one at the toolkit level. The concern at enterprise scale is the reuse pattern. The same agent toolkits get deployed across hundreds of applications by teams who often have no idea what version they're running. A vulnerability in a shared toolkit spreads differently than a bug in a single app. Patches are available for both CVEs, Python Semantic Kernel prior to version 1.39.4, and .NET SDK prior to version 1.71.0 are the specific versions to check. If you're running semantic kernel in any production environment, this goes on your patch list this week. Just a couple of more items. If you have any feedback about this show, you can email Mike at yesterday inai.news, or you can find him on LinkedIn, X or BlueSky. And if you like this podcast, please be sure to rate and review it so others can find it. Thanks. That's all for this weekend catch up edition of yesterday in AI. Stay curious, and Mike will see you tomorrow.