Today's briefing
The week your software stopped asking permission
Claude can now send Gmail without a confirmation click, and Microsoft just patched a Copilot data leak — the question for owners is the same.
The one that matters
Claude will now send email from your inbox without asking you first
Anthropic has changed how Claude works with Gmail: it can now send an email on your behalf without stopping to ask you first. Until this change the pattern was draft-then-confirm — the assistant wrote the message, you read it, you pressed send. The confirmation step is now something you choose to keep rather than something you get automatically.
What this actually changes
Think about who in your business writes the same email forty times a week. In a 600-student school, the front office answers the same questions about fee dates, bus routes and admission documents from morning to evening; the answers live in three files that never change. In a 12-person agency, someone spends an hour a day sending "received your brief, here is our timeline" replies. This is exactly the work an assistant handles competently, and until now the bottleneck was never the writing — it was a human clicking send forty times.
Removing that click is a real saving. It also removes the last check before something leaves your building. So the useful question is not "is it good at writing email" — it is "what is the worst email this could send, to whom, and how fast?" For a workshop with 40 staff whose inbox carries quotes and delivery dates, a wrong message is embarrassing and fixable by phone within the hour. For a 30-bed clinic, an assistant that can send unsupervised from the mailbox where test results arrive can put a patient's report in a stranger's inbox — a reportable privacy problem under Canada's PIPEDA or India's DPDP rules, not an "oops". Same feature, completely different blast radius.
What it does not mean
It does not mean the assistant now runs your inbox. It has no idea that the parent who wrote on Tuesday is the one threatening to withdraw two children, or that the supplier asking politely for payment was already paid last week. Nothing about judgement changed; a default setting did. Anyone who sells you an "autonomous email agent" this month on the strength of this news is selling you a permission toggle with a markup — the software could always write the mail.
There is a quieter risk worth naming. An assistant that reads your incoming mail and can send without asking can, in principle, be steered by the contents of an email a stranger sends you. That is not paranoia: Microsoft spent this same week patching a Copilot flaw that allowed one-click theft of company data. Read-and-act is a genuinely different security posture from read-and-suggest.
What a sensible owner does this month
- Decide mailbox by mailbox, not company-wide. A general enquiries or sales inbox is a reasonable place to try this. Accounts, HR, patient records and the principal's or director's mailbox are not.
- Run two weeks in draft mode first, and count. If your staff are rewriting more than one reply in five, the assistant does not yet know your fee structure, your terms or your tone. Fix that before you take the human out of the loop.
- Write down three hard limits, one line each: no sending to more than a handful of recipients at once, no attachments, and nothing involving money, medical detail or a legal commitment.
- Find out who can switch it on. In tools like this it is usually a per-user setting, which means any staff member with the app can enable it on their own account without telling you. That is the part worth an email to whoever manages your accounts today.
- Check the arithmetic before you buy anything. If an office manager loses ninety minutes a day to repetitive email and this takes it to twenty, it pays for itself inside a week. If the honest number is twenty minutes a day, leave the confirmation step on and spend your attention somewhere it matters more.
Also worth knowing
-
Microsoft patches a Copilot flaw that allowed one-click theft of company data
Microsoft has fixed a critical flaw in Microsoft 365 Copilot that reporting describes as enabling one-click data theft. The published detail is thin, so treat it as a pattern rather than an incident: an assistant plugged into your files inherits the sensitivity of every file it can reach. If you run Copilot, confirm with whoever manages your Microsoft tenant that you are on the patched version — that is the whole action item.
LinkedIn ↗ -
OpenAI restates zero data retention for eligible API customers
OpenAI is reaffirming that eligible API customers can run with nothing retained, and previewing a way to do safety checks without reading customer data. This matters if you are a clinic, law firm or school being asked "where does our data actually go" — it is an answer you can put in a contract. Note the limit: it covers businesses building on the API, not staff pasting client details into the consumer chat app, which is where most real leaks happen.
OpenAI ↗ -
Google puts study and exam-prep tools inside Search and Gemini
Google is adding study features across Search and Gemini, aimed at students working through classes and standardized tests. For schools and coaching centres this is competition, not a tool — your students already have a free tutor that never sleeps and never gets irritated. The sensible response is to be clear about what you sell that it cannot: accountability, attendance, and a teacher who notices when a child quietly stops trying.
TechCrunch AI ↗ -
Claude starts watermarking its text; people are already removing it
Anthropic has begun watermarking text Claude produces, and several outlets report workarounds circulating almost immediately. If you were hoping detection would finally settle the "did the student, the employee or the freelancer actually write this" argument, it will not. Judge the work on whether it is correct, specific and useful — and write that standard into your assignment briefs and contractor agreements rather than relying on a detector.
Gizmodo ↗ -
Replit adds a free tier for building small software without watching a meter
Replit has launched a Free Mode, running on OpenAI's GPT-5.6 Luna, pitched at people who want to turn an idea into working software without worrying about usage costs. If you have wanted a small internal tool — a leave tracker, a stock checker, a visitor log — it is now cheap enough to attempt over a weekend. What it does not give you is someone accountable when that tool breaks during your busiest week, so keep it well away from billing, payroll and anything holding customer records.
OpenAI ↗ -
Wider AI adoption has not produced wider acceptance
As AI becomes harder to avoid, consumers are reportedly getting more wary of it rather than less. If you deal with customers directly, the practical lesson is that "powered by AI" has stopped being a selling point and may now cost you trust. Say what the customer actually gets — same-day replies, fewer billing errors, a lower price — and leave the technology out of the copy.
TechCrunch AI ↗ -
OpenRouter, the plumbing many AI products bill through, is joining Stripe
OpenRouter, a service software companies use to route requests across different AI models, is being absorbed into Stripe. Nothing changes for you this week; it earns a line because the billing plumbing underneath AI features is consolidating, which usually makes the AI portion of your software invoices clearer. Worth one request to your vendors: itemise the AI usage on the bill so you can see what you are paying for.
Hacker News ↗ -
ChatGPT Ads expands to 31 European markets
OpenAI is rolling out advertising inside ChatGPT across 31 European markets. No effect in India or Canada today, but the direction is worth noting: the assistant your customers ask for recommendations is becoming a place where placement can be bought. If being found is how you get business — a dealership, a clinic, a coaching institute — watch this channel over the next year rather than budgeting for it now.
OpenAI ↗
How this briefing is put together
Every morning we read the day's AI announcements and reporting from the companies themselves and from the technology press, then pick the handful that actually change something for a working business. The analysis is ours and it is written for owners and managers, not engineers. Every story links to its original source above — read them, and disagree with us where we've got it wrong.