API key exploitation is more than hypothetical. In a different context, a student who reportedly exposed a GCP API key on GitHub last June was left nursing a $55,444 bill (later waived by Google) ...
As for the mobile update, Android 17 Beta 2 is adding a few building blocks for developers. The new tools are privacy-focused, just like the photo picker that limits access to only selected photos.
AI API calls are expensive. After our always-on bot burned through tokens, we found seven optimization levers that cut costs by 45-50% without sacrificing output quality.