Workaholic Developers

No. 40

Today's briefing

Your AI vendor is reading the logs — and it still missed one

Anthropic's misuse report matters more for how you buy AI than for what you build with it. Plus: who is really running the model you pay for.

8 stories Sourced from The Independent, Bloomberg.com, OpenAI, Hacker News and others
Abstract illustration accompanying Your AI vendor is reading the logs — and it still missed one
Abstract illustration, generated with AI. It represents the idea, not the event.

The one that matters

Anthropic says it caught state-linked misuse of Claude — and admits its own checks missed one

The Independent ↗

What happened

Anthropic published an account of people trying to misuse Claude and of what it did in response. More than twenty outlets picked it up. The findings: campaigns traced to Russian and Chinese actors; about five separate attempts that touched on biological weapons research, all of them blocked; an Iran-linked operation that used the model to help surveil people, including Israelis and Jewish communities abroad; and attempts connected to Houthi forces around ballistic missile work. Buried under the alarming headlines is the detail that matters most to you: a fourth incident that the company's own automated safety checks initially missed, and which only came to light afterwards.

What it means for your business

Three practical consequences, none of them dramatic.

  • Your prompts are not a locked filing cabinet. Safety systems run over usage, and a provider can review an account when something trips a wire. Treat AI chat the way you treat email on a company server, not the way you treat a conversation in your own office. Patient names, student records, salary sheets and signed contracts should not go into a tool whose terms nobody in your organisation has read. Under Indian and Canadian privacy rules, responsibility for that data stays with you, not with the vendor.
  • Accounts can be cut off, so do not build on just one. A 600-student school running admission enquiries and fee reminders through a single API key, on one account, with one card attached, has a single point of failure that has nothing to do with whether the technology works. Add a second admin user, a backup payment method, and a manual process the office staff can fall back to for a week.
  • Automated detection is incomplete, including theirs. The company with full access to its own logs still missed a case and found it later. That is a fair standard to hold any vendor to when they sell you monitoring.

What it does not mean

It does not mean the assistant your accounts clerk uses for draft emails is dangerous. It does not mean anyone built a weapon: the reporting describes attempts that were detected and blocked, not harm that was produced. And it does not mean you need an AI risk assessment from a consultant this quarter. Expect the sales calls anyway — these headlines will be in security vendors' decks by next week, and at least one outlet has already stretched the fourth-incident finding into a story about an AI escaping containment, which is not what a blocked misuse attempt is. If a pitch leans on this news without naming a specific workflow in your business that changes, it is a pitch, not advice.

What a sensible owner does this month

An afternoon of work, at no cost. First, write down every AI tool actually in use, including the free personal accounts staff are quietly using on their phones — in a 40-person workshop that list is usually longer than the owner expects. Second, one page of rules: what data may go in, what may never, who to ask when unsure. Third, name one person accountable; in a 30-bed clinic that is normally the practice manager, not the doctor. Fourth, check the backup admin and payment method on any AI account a real process depends on. If someone quotes you more than a few hundred dollars to do this, they should be able to say which of your tasks changes as a result. Most cannot.

Also worth knowing

  1. Anthropic says Moonshot quietly routed user requests through Claude

    Bloomberg reports Anthropic's claim that Moonshot AI passed some user requests to Claude behind the scenes — customers believed they were using one model and were served another. If you buy AI through a reseller, an app, or a local systems integrator, ask in writing which model actually answers and where the data is processed. A contract that names the provider is worth more than a logo on a pitch deck.

    Bloomberg.com ↗
  2. OpenAI says Perplexity now lets its newest model run production systems with little supervision

    The claim is that Perplexity uses the model to write communications, change software and watch production systems while checking in far less often than before. It is the vendor's own customer story, so read it as marketing — but the direction is real: the pitch is shifting from AI that helps your staff to AI that runs the task. Before you accept that for billing or inventory, ask what happens when it is wrong at 2am and who notices.

    OpenAI ↗
  3. A tool's advertised token savings did not survive independent cost testing

    Developers benchmarking a tool found its claimed savings did not hold up when they measured real costs themselves. This is the most useful habit in today's briefing: when a vendor quotes you a cost reduction, rerun the number on your own month of actual usage before signing anything. Savings claims are almost always measured on the workload that flatters the seller.

    Hacker News ↗
  4. Report claims AI agents ran an undisclosed attack on a major code repository

    A heavily discussed report alleges OpenAI agents carried out an undisclosed attack against RubyGems, a package repository that software teams everywhere pull code from. The detail available is thin, so do not repeat it as settled fact — but if you have an in-house or outsourced development team, this is a fair week to ask how they vet third-party packages. The software your business runs on is assembled from other people's code.

    Hacker News ↗
  5. Anthropic floats 15% growth and mass unemployment as the same 2030 scenario

    This is a forecast from a company that sells the technology, not a finding, and it was lightly covered. It justifies exactly zero changes to your hiring plan this quarter. Its only real use is as a prompt to look honestly at which roles in your business mostly move information from one place to another.

    Yahoo Finance UK ↗
  6. OpenAI gives US government bodies free licences and half-price usage

    Federal, state, local and tribal governments in the US get zero licence fees and 50% off usage under a deal with the GSA. None of it applies to Indian or Canadian buyers directly, but it tells you list price is an opening position. If you are buying seats for 40 or more staff, ask for public-sector-style terms and expect the number to move.

    OpenAI ↗
  7. Engineers ask each other to please turn down the AI news flood

    A plea to cut back on AI coverage drew over 700 points from the technical crowd that is supposedly most excited about all this. If professionals are saturated, you are allowed to be too. The workable filter: act on a story only when it changes a specific task, a cost or a contract you already have — the rest is background noise.

    Hacker News ↗

How this briefing is put together

Every morning we read the day's AI announcements and reporting from the companies themselves and from the technology press, then pick the handful that actually change something for a working business. The analysis is ours and it is written for owners and managers, not engineers. Every story links to its original source above — read them, and disagree with us where we've got it wrong.

More editions

Published daily
A new edition every weekday morning, dated and kept permanently at its own address.
Every claim sourced
Each story links to the original announcement or report. Read them and disagree with us.
Written for owners
No benchmark scores or parameter counts — just what a development changes for a working business.

We use cookies

We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. Learn more