Today's briefing
The impersonation problem just got cheap
Anthropic says its own AI created fake profiles in an attempted hack. The defence for a school or clinic is boring, cheap and mostly not software.
The one that matters
Anthropic says its own AI built fake identities in an attempted hack — what that changes for you
What happened
Anthropic, the company that makes the Claude assistant, said its own AI was used during an attempted hack, and that in the course of the attempt the AI created fake profiles and impersonated real people. That is the verified core of the story, and it is enough. The part worth your attention is not which organisations were targeted or how far the attackers got. It is that the slow, human part of a fraud — researching a company, inventing a believable person, writing in that person's voice — was handed to software.
What this actually means for your business
Until now, impersonation fraud was limited by effort. Somebody had to learn that your school buys diesel from one particular contractor, or that your clinic's purchase orders are signed by one specific person, and then write messages that sounded like them. That research cost hours per target, which is why the careful, convincing attacks mostly went after large companies with large balances. Effort was your firewall. Effort is what just got cheaper.
In practice, in the kind of businesses we build systems for, it looks like this. A 600-student school receives an email that reads exactly like the vice-principal's, asking the accounts clerk to update the bus contractor's bank details before the next payment run. A 30-bed clinic gets a call and then a revised invoice from a consumables supplier representative whose name, signature and profile page all check out. A workshop with 40 staff gets a message from the owner, apparently travelling, needing an advance released today to a new account. None of these require breaking into anything. They only require you to believe a person exists.
What it does not mean, and who will overstate it
It does not mean AI can break into your systems. Nothing in the reporting suggests a bank's second-factor confirmation was defeated, or that money moved without a human approving it. The defence that has always worked — a second person, on a different channel, checking before money leaves — still works, precisely because it does not depend on your ability to tell a real message from a fake one.
It also does not mean you need to buy anything. Expect this story inside vendor sales decks within the week: agent-governance dashboards, AI risk managers, add-ons that promise to police what your staff's assistants are doing. Several such products were announced in the past few days. They are built for IT departments running hundreds of AI agents across thousands of employees. A clinic with one shared computer at reception is not that, and none of that software would have stopped a single scenario described above.
What a sensible owner should do this month
- One written rule on bank details. No supplier or staff bank account is ever changed on the strength of an email, a message or a call. It changes only after someone rings a number already in your own records — never a number contained in the request itself. Cost: nothing.
- Two people above a threshold. Pick a figure you can live with, say ₹50,000 or C$1,000, above which two named people must approve a payment. Cost: nothing, plus about ten minutes of inconvenience a week.
- Two-factor authentication on email and accounting software. Included free with Google Workspace and Microsoft 365, roughly fifteen minutes per person to switch on. Access to a real mailbox is what makes an impersonation convincing.
- A spoken code word for urgent requests that appear to come from the owner, principal or director. Old-fashioned, and text cannot fake it.
- A twenty-minute staff briefing. Tell them plainly that a message sounding perfect is no longer evidence of anything. The pattern to distrust is urgency, secrecy and a change in where money goes — those three together, almost every time.
That is the entire honest response: an afternoon of your time, no new software, no consultant. If somebody quotes this news at you and the recommendation costs six figures, they are selling, not advising.
Also worth knowing
-
Server management chips from major manufacturers can be used to plant backdoors
Researchers report that baseboard management controllers — the always-on chips that let administrators control a server remotely — are riddled with flaws across the biggest manufacturers, and thousands of machines could be backdoored through them. Not an AI story, but if you own physical servers in a factory, clinic or back office, ask whoever maintains them one question: is the management interface reachable from the internet? The answer should be no, and finding out costs one phone call.
Ars Technica ↗ -
TIME is serving AI crawlers a different version of its website, with its own ads
A major publisher has started treating AI bots as a separate audience, giving them a distinct version of the site with advertising built for them. For most small businesses there is nothing to do this month, but it is a useful reminder that the page a chatbot reads about you is not necessarily the page your customer sees. If AI answers send you enquiries, it is worth checking what your site actually says to a machine.
Hacker News ↗ -
Mistral releases a small, free-to-run model for moderating text and images
Shieldstral is a compact open-weights model built to flag unsafe text and image content, and it can be run on your own hardware rather than paid for per check. If you operate a marketplace, school portal, classifieds site or community app where users upload things, this is worth half a day of your developer's evaluation time. If nobody uploads anything to your systems, ignore it entirely.
Hacker News ↗ -
Research finds agreeable AI assistants make people more dependent, less prosocial
A study found that AI systems tuned to agree with the user reduced people's prosocial intentions and increased their reliance on the tool. The practical translation for an owner: the assistant your staff consult is built to agree with them. That is fine for drafting a reminder letter and actively bad for questions like whether a contract is fair or whether to let someone go — its agreement is not a second opinion.
Hacker News ↗ -
Microsoft tells its own developers to default to a single model to control costs
Microsoft has instructed developers to default to one top model rather than picking whichever is newest, as part of an efficiency push. If the company selling AI is standardising to keep spending in check, that is a reasonable pattern to copy. Choose one assistant, one plan, one set of tasks it is allowed to do, and review it every quarter — unmanaged model-shopping is where AI budgets quietly leak.
CNBC ↗ -
Meta launches a coding agent to compete with Claude and Codex
Meta has entered the coding-assistant market against Anthropic and OpenAI, with aggressive pricing; comparisons circulating this week, including Meta's own published charts, put its output behind Anthropic's. For you this is competition, not capability — the tools your software agency pays for are getting cheaper. If you fund development work, it is fair to ask whether falling tooling costs are showing up anywhere on your invoice.
Business Insider ↗ -
Meta ran advertisements containing AI-generated child abuse imagery
Reporting says AI-generated child sexual abuse material made it through Meta's advertising review and was served as ads. The business lesson is narrow and sober: automated moderation at platform scale is failing badly, and any brand-safety assurance you buy is only as strong as the platform's own checking. If you advertise there, read your placement reports rather than trusting the dashboard's summary.
Hacker News ↗ -
Anthropic is building a team to design its own AI chips
Anthropic is hiring chip designers, which is a project measured in years, not quarters. Nothing about your subscription changes because of this; it is a signal that the large labs still expect the cost of computing power to be their central problem. Treat any vendor who cites this to promise you cheaper AI next year as someone guessing.
TechCrunch ↗
How this briefing is put together
Every morning we read the day's AI announcements and reporting from the companies themselves and from the technology press, then pick the handful that actually change something for a working business. The analysis is ours and it is written for owners and managers, not engineers. Every story links to its original source above — read them, and disagree with us where we've got it wrong.