Today's briefing
The AI crime report that should change your payments process
Anthropic's misuse report reads like a spy thriller. The part that matters for a 600-student school is duller, cheaper and fixable this month.
The one that matters
Anthropic says it caught state-linked misuse of its AI — and missed one case for months
What happened, in plain words
Anthropic, the company behind the Claude AI models, published its September report on how people have tried to misuse its systems and what it did about it. Coverage picked out four threads: campaigns linked to Russia and China that the company says it disrupted; attempts it believes were aimed at developing biological weapons, which it says it blocked; governments using the models to help automate intelligence work; and a fourth cybersecurity incident involving an early version of Claude that its own checks initially missed and that only surfaced months after the fact.
Strip away the geopolitics and two plain facts remain for someone running a business. Criminal and state-linked groups now treat commercial AI tools as ordinary cheap labour. And the company selling the tool did not catch everything the first time, on its own admission.
What it actually means for your business
You are not the target of a Russian intelligence operation. The thing that travels from a report like this down to a 600-student school in Pune or a 30-bed clinic outside Winnipeg is fraud economics. The expensive part of a scam was never the bank transfer — it was the writing. Producing a convincing letter in fluent Hindi, Marathi or Canadian-office English, referencing your actual vendor, your actual invoice numbers and your principal's actual turn of phrase, used to require a person with time and language skill. That cost has collapsed. The same automation that makes an AI agent useful for chasing overdue invoices makes it useful for chasing your accounts clerk.
Picture the realistic version: your bursar receives a message that looks like it came from the trustee who signed last term's furniture order, quoting the correct amount, apologising for the rush and giving new bank details. Nothing in that email is technically sophisticated. It is simply well written, well timed, and one of four hundred sent that morning.
The second lesson is about vendors. If the company with the safety team, the internal monitoring and the published policy still found an incident late, then "our AI provider handles security" is not a control you can lean on. It is a statement of intent.
What it does not mean, and who is overstating it
It does not mean AI tools are now unsafe to have in your office. Nothing in this report suggests that using a chatbot to draft parent circulars or summarise supplier quotes puts you at risk.
It does not mean the software committed crimes. Several headlines this week put the agency in the wrong place — people misused a tool, which is a different and older problem than a machine acting on its own.
And it does not mean you need to buy anything. Expect security resellers to arrive over the next few weeks with "AI-powered threat protection" quotes citing exactly this report. Nothing here says your existing antivirus or email filter is obsolete. The gap this story exposes is in your approval process, not your software stack.
What a sensible owner should do this month
- Put a callback rule in writing. Any change to bank details, or any payment above a threshold you choose — say ₹50,000 or CAD $1,000 — gets verified by phoning a number you already had on file, never a number in the message. Cost: nothing.
- Require two people for payments above that threshold. Most accounting software supports this already; you are switching on a setting, not buying a product.
- Turn on multi-factor authentication for email, accounting and payroll. Free, and it still defeats the majority of account takeovers.
- Spend twenty minutes with the staff who move money. One message: urgency plus a change of payment details equals stop and verify. No exceptions for the boss.
- Ask what staff are pasting into free chatbots. Student records, patient notes and salary sheets are the ones that will cost you. Write a one-page rule about what may and may not go in.
That is a few hours of an office manager's time and no capital spend. The headline is about nation-states; the fix on your desk is a phone call before a transfer.
Also worth knowing
-
DeepSeek releases v4.1 Flash, and developers spend the day arguing about it
DeepSeek put out a new fast, low-cost model and it drew heavy developer discussion — beyond the release itself, the detail available is thin, so treat specific claims about it with caution. The pattern is what matters to you: the price of capable AI keeps falling roughly every few months. If a vendor quoted you an AI project budget more than six months ago, ask them to requote before you sign.
Hacker News ↗ -
ChatGPT adds a data agent that builds dashboards from your own company data
OpenAI's new Data agent connects to company data and lets someone build charts and dashboards by describing what they want in plain language. For an owner who currently waits three days for a report from whoever knows Excel best, that is a genuine time saving. Two caveats: it needs a paid business plan, and it is only as good as your data — if your sales sheet has four spellings of the same customer name, fix that first.
OpenAI ↗ -
OpenAI's new voice model can hold a real phone conversation
GPT-Live-1 supports natural back-and-forth speech, custom voices and telephone integration. The obvious use is the clinic or workshop that misses calls at lunchtime — appointment booking, opening hours, order status. This is a developer tool, not an app you download, so budget for someone to build and test it, and keep a human path for anyone who asks for one.
OpenAI ↗ -
OpenAI launches an Agents API for software that works on its own for hours
The Agents API is a managed service for building agents that run long sessions and use tools without someone watching each step. This is the foundation for the "AI that actually does the task" pitch you will hear from software vendors all quarter. Worth knowing it now exists; not worth commissioning until you can name one repetitive process and say exactly what a wrong result would cost you.
OpenAI ↗ -
ChatGPT gets a version aimed at banks, lenders and financial firms
OpenAI packaged financial data and a newer model into a product for research, modelling and client documents. Unless you run a finance business, this is not for you to buy. It is useful as a signal: your bank, broker or accountant will likely get faster at producing analysis, so expect quicker turnarounds and ask for them.
OpenAI ↗ -
An Indian services firm completes its set of Microsoft AI partner badges
Simform announced it now holds Microsoft's full slate of AI cloud designations, including AI Business Solutions. Partner badges measure a vendor's relationship with Microsoft, not whether their work succeeded at a business like yours. If someone leads a pitch with credentials, ask instead for two named clients your size and a fixed-scope paid pilot before any annual commitment.
PR Newswire ↗ -
An Anthropic researcher puts the odds of AI killing everyone above 10%
A researcher at the company gave a personal probability estimate in a television interview, and it travelled across dozens of outlets. It is an opinion about the long run, not a forecast about your next quarter, and it changes nothing about whether you should automate your invoicing. The concrete version of that worry is this week's misuse report — which is why the lead story is the one to act on.
CBS News ↗ -
A lab uses AI coding tools to hunt for new antibiotics in old genomes
A research group is using OpenAI's tools to search genetic data — including from extinct species — for molecules that might work against drug-resistant infections. Nothing here to adopt, and any clinical benefit is years away. It is a clean illustration of what this technology is genuinely good at: searching spaces too large for people to search by hand, which is also the best test for whether your own AI idea is worth funding.
OpenAI ↗
How this briefing is put together
Every morning we read the day's AI announcements and reporting from the companies themselves and from the technology press, then pick the handful that actually change something for a working business. The analysis is ours and it is written for owners and managers, not engineers. Every story links to its original source above — read them, and disagree with us where we've got it wrong.