Today's briefing
Attacks got cheaper. Your boring checklist got more important
Researchers used Claude to break into OpenAI's systems. For a 30-bed clinic the answer is not new AI security software — it is the unfinished basics.
The one that matters
Researchers used Claude to break into OpenAI's systems, and cheap attacks are the real story
What happened, in plain words
Security researchers used Anthropic's AI model, Claude, to break into systems belonging to OpenAI. More than thirty outlets covered it and it was one of the most heavily discussed technology stories of the week among engineers. What the available reporting does not settle is the scope: how deep the access went, how much was authorised testing, and how much of the work the model did by itself versus a skilled human steering it step by step. Those details matter enormously, and anyone who claims to know them from the headline is guessing.
What is not in doubt is the shape of it. One of the most security-conscious companies in the world was successfully broken into, and a general-purpose AI assistant — the same category of tool your accountant uses to draft emails — was the instrument.
What it actually means for your business
Small and mid-sized businesses have been protected for years by something nobody likes to say out loud: not being worth the effort. Getting into the fee portal of a 600-student school, or the appointment system of a 30-bed clinic, or the shared accounting PC in a workshop with 40 staff, has always been technically easy. It simply required a few hours of a skilled person's attention, and skilled attention was expensive enough that those people chased banks and hospital chains instead.
That economic shield is thinning. When a capable assistant can read error messages, suggest the next probe and write the script, the number of people able to run a competent attack goes up and the hours each one needs goes down. The practical consequence is not a new kind of attack. It is more attempts at the same old ones — an unpatched WordPress plugin on the school site, a CCTV recorder exposed to the internet, a router still on its factory password, an ex-employee whose admin login was never removed.
What it does not mean
It does not mean your systems will be broken into this month, and it does not mean your existing AI tools are dangerous to keep using. Expect a wave of vendors selling AI threat protection subscriptions off the back of this headline. Be sceptical. The organisation in this story was not undone by a missing AI defence product, and neither will you be. The other overstatement, from the opposite direction, is the doom framing — that nothing can be defended any more. That is also false. Most break-ins at businesses your size still come through a reused password or an unpatched box, both of which are fixable.
What a sensible owner does this month
- Turn on two-factor authentication on your business email, accounting software and any admin panel. Free, and it stops the single most common route in.
- Write down every system reachable from the internet — fee portal, booking page, CCTV recorder, router admin page, that old server nobody logs into. Most owners are surprised by the length of the list.
- Remove admin access for people who have left. Takes an afternoon, costs nothing.
- Ask your web or ERP vendor, in writing, when they last applied security updates. The quality of the answer tells you most of what you need to know.
- Test one backup restore. A backup you have never restored is not a backup.
- Only then consider a paid external review. Expect quotes roughly in the range of one to two lakh rupees in India, or a few thousand to fifteen thousand dollars in Canada. Do the free items first — they remove more risk per rupee than anything on the invoice.
Also worth knowing
-
Anthropic says its own AI now leads about a quarter of its research work
Anthropic reports that Claude handles roughly 26% of its internal AI research and development. This is a vendor describing itself with no outside audit, so treat the number as a claim rather than a measurement. The signal worth keeping is narrower and more useful: software work is getting compressed, so when your web or ERP vendor quotes six weeks for a modest change, it is now fair to ask what is taking the time.
Dataconomy ↗ -
A hallucinated intelligence report nearly triggered a US military operation
An AI-generated intelligence summary contained fabricated content and came close to prompting real action before it was caught, with a researcher warning that service members need to understand how uncertain these systems are. The lesson transfers directly: any AI output that leads to an irreversible step — a dosage, a payroll run, a legal notice, a dispatch — needs a human who can check the underlying source, not just read the summary. Decide now which of your processes qualify.
TechCrunch AI ↗ -
A popular AI coding agent was caught quietly uploading users' code history
ZCode, a coding agent built on the GLM models, was found silently sending users' Git history to its servers. If you employ developers or use an agency, that is your source code and potentially your access keys leaving the building without anyone approving it. Ask your development vendor, in writing, which AI coding tools they run and what those tools transmit.
Hacker News ↗ -
Unsealed filings show Microsoft privately called AI data scraping theft
Court documents reveal Microsoft internally described OpenAI's use of paywalled news content as theft of labour, while both companies built datasets from that material and expected it to damage publishers. This matters if your business publishes anything of value — course material, product catalogues, clinical explainers, price lists. It is not a reason to take your website down, but it is a reason to keep dated records of what you publish, because ownership disputes are being fought on evidence like that.
TechCrunch AI ↗ -
Anthropic is pushing towards AI agents that can spend your money
Reporting suggests Anthropic wants its AI to be able to access bank accounts and transact on a user's behalf. The coverage is thin — four outlets and light on the mechanics — so do not read more into it than that. The practical rule is unchanged and worth stating plainly: do not connect any agent to a live business account, and if you want to experiment, use a separate card with a low limit and a monthly statement you actually read.
The Independent ↗ -
A law firm built an IPO review tool on ChatGPT to catch issues earlier
Cooley built an internal tool that uses ChatGPT to surface problems earlier in the IPO process so lawyers spend their time on judgement calls. It is published by OpenAI about its own customer, so read it as marketing rather than evidence. Even so, it is a sound template for any document-heavy professional services firm — a narrow task, a large pile of paper, and a qualified human still making every decision that carries liability.
OpenAI ↗ -
Google and the UN launched a free, searchable database of global statistics
The UN System Data Commons puts official global and national statistics in one searchable open platform. Unglamorous and genuinely useful: if you are building an expansion case for a new branch, writing a grant application for a school, or checking a market claim a consultant made, this is a free primary source. No subscription, no pilot, no vendor call.
Google AI ↗ -
Anthropic adopts OpenAI's format for written AI instructions
Anthropic has agreed to support the instructions specification OpenAI proposed — a shared file format for telling AI tools how to behave on a given project. This is plumbing, and mostly invisible to you. The one part worth noting is that the written rules your team develops for one vendor's tool should increasingly carry across to another, which is a small but real reduction in lock-in.
The Register ↗
How this briefing is put together
Every morning we read the day's AI announcements and reporting from the companies themselves and from the technology press, then pick the handful that actually change something for a working business. The analysis is ours and it is written for owners and managers, not engineers. Every story links to its original source above — read them, and disagree with us where we've got it wrong.