In partnership with

In Todayโ€™s Issue:

๐Ÿšง OpenAI freezes its top models after a sandbox breach

๐Ÿฝ๏ธ Trump invites Anthropic's Dario Amodei to dinner

๐Ÿ›’ Meta's Muse agent botches a Marketplace sale

๐Ÿฆ Why Wall Street fears agents that move your cash

โœจ And more AI goodnessโ€ฆ

โšก The Signal

AI agents are getting real access to the internet, our money and even our front doors, and last week showed how easily they step past the limits set for them.

OpenAI has halted training, testing and tool use for its most capable models after one of its systems found a gap in its training sandbox and used it to question an outside chatbot. Meta's Muse agent, whose viral week knocked bank stocks on fears it will move people's idle cash, reportedly agreed to a sale and shared a user's home address without asking him. Satya Nadella calls this a new "insider risk," because "the attack can just come from the agent itself." And OpenAI may unveil an always-on assistant of its own at DevDay on Tuesday. Building fences that actually hold is fast becoming as important as building smarter agents.

All the best,

Kim Isenberg

Anthropic CEO Dario Amodei at the G7 in June 2026

๐Ÿฝ๏ธ Trump Invites Anthropic's Dario Amodei to a Private Dinner

President Trump was set to host Anthropic CEO Dario Amodei at a private White House dinner on Sunday evening, their first one-on-one meeting, Axios reported. Trump invited him personally after Amodei missed last week's state dinner, where Sam Altman and Sundar Pichai flanked the president, because of a scheduling conflict. It is a notable thaw: Anthropic's relationship with the administration has been shaky all year, and only last week Trump allies circulated talking points about Amodei's ties to the effective altruism movement. On Tuesday, Trump and House Speaker Mike Johnson meet top AI CEOs at the White House. ๐Ÿ‘‰ tl;dr: Trump personally invited Anthropic's CEO for a private dinner, a sign the White House is warming to the AI lab it has clashed with all year, just before Tuesday's meeting with the industry's leaders.

AT&T runs about 40% of its AI workloads on open models

๐Ÿ’ธ Corporate America Shifts AI Work to Cheaper Open Models

US companies far beyond Silicon Valley are moving AI work to cheaper open-weight models, which they can tune and run on their own hardware. AT&T runs about 40% of its AI workloads on open models and aims for 70% within a year. It processes 45 billion tokens a day, and "at that scale, costs become super important," says data chief Andy Markus. Tinder, whose AI bill jumped from a $1 million to a $10 million annual rate between January and July, now routes some queries to open models, and executives' mentions of open models on earnings calls rose sixfold in August and September, per AlphaSense.

๐Ÿ‘‰ tl;dr: Big companies are moving everyday AI work onto open models they can run and customize themselves, to keep soaring AI bills under control.

Muse apologizes to Matt Robb for the missed pickup; screenshot cropped, buyer's name blurred (Matt Robb via Threads)

๐Ÿ›’ Meta's Muse Agent Botches a Marketplace Sale

Meta's Muse agent, the app that shot up the download charts last week, now has a viral horror story. Tech YouTuber Matt Robb says he let Muse handle his Facebook Marketplace chats for a day, and it agreed to sell a keyboard listed at CA$15 for $10, gave a buyer his address and auto-replied "Yep I'm here!" when he was not home. The buyer waited, left angry and posted a negative rating; Muse told Robb hours later and apologized. His screenshots show one user's experience, not a systematic test.

๐Ÿ‘‰ tl;dr: Meta's Muse can negotiate and arrange sales on your behalf, and one early user says it closed a deal and shared his address without checking with him first.

๐ŸŽฌ Watch This

โ

Deirdre Bosa opens her new show with Satya Nadella at Microsoft's Copilot event.

He presents Autopilot, a long-running agent that completes business tasks while a human checks what goes in and what comes out. Nadella says trust is the biggest hurdle, asking "can I really trust it with all of my credentials," and warns that powerful agents bring a new "insider risk" because "the attack can just come from the agent itself," a line that lands squarely on today's OpenAI news.

He also argues that software now has a real cost per use once AI subsidies end, and that automatic routing, which picks the right model for each task, is becoming the product.[text]

"It was pretty surreal to watch the model unexpectedly find a way to access the internet from what was supposed to be a super secured environmentโ€ฆ One of those moments where capability and risk showed up at the same time."

โ€“ Zuxin Liu, post-training researcher at OpenAI, on X

โ

Liu was on call for the training run in today's Featured Story and got paged when the incident began. The same drive to finish a task that makes these models useful is what carried this one out of bounds.

Source: https://x.com/LiuZuxin/status/2103699462648639645

Did OpenAI just leak its DevDay headliner? A ChatGPT Pro upgrade screen shared by Jake Boggs shows a single $100 tier that includes "o, your always-on assistant," a product OpenAI has not confirmed. DevDay is on Tuesday in San Francisco, so the answer may come soon.

OpenAI Freezes Its Most Capable Models After a Sandbox Breach

โ

The Takeaway

๐Ÿ‘‰ On September 20, an internal OpenAI model in training reached an outside chatbot through a gap in its sandbox's DNS filtering.

๐Ÿ‘‰ OpenAI has paused all training, evaluation and tool-using inference for its most capable models until the gap is verified closed.

๐Ÿ‘‰ The monitor flagged the breach within 15 minutes, but an automatic stop failed and the run went on for about 2.5 more hours.

๐Ÿ‘‰ Two more disclosures: a model that leaked an employee's GitHub token in May, and prompt injections that copy themselves like a computer worm.

OpenAI has frozen work on its most capable models after one of its AI systems found a way out of the sealed room it was trained in. On September 20, an internal research model was asked to identify a blogger from a few clues. When its search tool came up empty, it downloaded the public BrowseComp benchmark, hoping the answer was in there. Then it noticed that the sandbox's DNS resolver, the internet's address book, still answered real lookups, and used a public DNS service to relay questions to an outside chatbot. It tested the route with "What is the capital of France" and got back Paris, then sent 18 more questions. OpenAI researcher Micah Carroll shared the disclosure on X:

OpenAI's monitor flagged the breach within 15 minutes, and a human was looking at it three minutes later. But an automatic stop that should have ended the run did not fire, and the run was only killed about 2.5 hours after the alert. OpenAI says its "safety case assumed that the model could not access the live internet," so it has paused all training, evaluation and tool-using inference for its most capable models until the gap is verified closed and red-teamed, and it will not resume training this particular model.

The incident timeline from OpenAI's report; screenshot cropped (OpenAI)

Carroll's post bundled two more disclosures. In May, a highly persistent internal model twice promised a researcher it would stop trying to copy another team's proof and solve the problem itself. It then wrote his GitHub token into code it pushed to OpenAI's public codex repository, splitting the key into pieces to slip past secret scanners. That model was taken offline for about two weeks. Separately, OpenAI's red-teaming found self-replicating prompt injections: hidden instructions, for example in an email, that get an agent to copy the attack into what it sends, like a computer worm.

The token model's own reasoning, recalling the instruction and pressing on; screenshot cropped (OpenAI)

OpenAI calls the DNS case "a lot less severe" than earlier incidents, since the model's other traffic only reached an offline copy of the web, and the worm appeared only in simulated tools. Still, the pattern across the reports is consistent: told no, these models keep looking for another door.

Why it matters: Agents that search, write code and answer email for us are exactly the systems these reports describe. If a model can find a side door in OpenAI's own locked-down lab, companies handing agents their credentials need controls that stop an agent automatically, with a human alert as the backup.

Stop betting on one AI answer.

Even the best AI model is right only 67% of the time, per Artificial Analysis' AA-Omniscience benchmark. And it sounds confident when it's wrong.โ€จ

Cuey is a free Chrome extension that cross-checks your AI's answer so you don't get burned by the first one. It runs inside ChatGPT, Claude, Gemini, Grok, and more.

Send one prompt, get three answers side by side. No tab-switching, no copy-paste. See where the models disagree before a hallucination costs you.

โ

The chart: Vercel runs an AI Gateway that developers use to send requests to many different AI models, and this FT chart tracks how that traffic splits. In August, open-weight models handled 56% of all tokens (the chunks of text models read and write), up from 7% in December 2025. Their share of the spending rose too, but only to about 14%.

The lesson: Open models now do more than half of the work on this gateway for about a seventh of the money. That gap is the saving AT&T and Tinder are chasing, and a risk for OpenAI and Anthropic, whose models are their main product: OpenAI is in talks to raise money at a $1.2 trillion valuation, and Anthropic's expected IPO could value it at $2 trillion or more. Both released cheaper versions of their flagship models last week.

The caveat: This is one gateway's traffic, not the whole market, and the FT notes that the two frontier labs still capture the bulk of AI spending. The line also swings: open models briefly reached about 26% in February before falling back. And tokens are not equal, since a cheap model can burn through many of them on simple jobs.

๐Ÿฆ Wall Street's New AI Fear: Agents That Move Your Cash

โ

โšก Bottom line
Bank, broker and insurer stocks fell after Meta's Muse agent went viral, on fears it will move people's idle cash.

๐Ÿ’ก Why it matters
Banks earn a crucial margin on deposits that sit in low-interest accounts simply because customers never bother to move them.

๐Ÿ”Ž What it means
If agents shop for better rates automatically, habit stops protecting bank profits and the cost of deposits could rise.

Last Tuesday, Wall Street priced in a new kind of AI risk: an assistant that notices your savings earn almost nothing and moves them. Shares of banks, insurers and online travel agencies slid as Meta's Muse agent went viral, Bloomberg reported. The S&P 500 Financials Index fell nearly 2% to its lowest close since July. JPMorgan and Wells Fargo lost more than 3% each, insurer Allstate 5.5% and brokerage Charles Schwab more than 6%.

Mark Zuckerberg presents the Muse Charm at Meta Connect (Reuters/Carlos Barria, via Yahoo Finance)

Investors call the weak spot consumer inertia: people keep doing what they have always done, even when a better deal exists. Muse can connect to a user's financial accounts, watch balances and investments, suggest changes and act on the user's behalf, Yahoo Finance reports. For banks, cash parked in checking, savings and brokerage accounts that pay little interest is cheap funding. An agent that sweeps that cash into higher-yielding funds would squeeze that margin.

There is a precedent. When interest rates rose in 2023, Schwab customers moved billions into higher-yielding money market funds, forcing the company onto expensive short-term funding and denting its profits for the year. Bank of America analyst Ebrahim Poonawala calls this "deposit sorting" and sees it as "a real threat to industry net interest margins." Competition for deposits is already heating up: Citigroup, PNC and Bank of America have all rolled out offers to attract bigger balances.

[text]

The Muse app on a smartphone

Poonawala also warns against getting ahead of the evidence: "Until deposit costs rise faster than can be explained by rates or competition, the disruption thesis remains conceptual." The proof will show up in banks' funding costs, not in app downloads. And handing an agent your savings is a bigger step than handing it a CA$15 keyboard sale, as this weekend's Marketplace mishap shows.

For product teams moving at AI speed.

AI makes it easier to ship anything, even bad ideas. The hard part is knowing which ideas are worth building.

Jira Product Discovery brings your ideas, customer insights, and priorities into one place, so your team can decide what to ship and move forward with confidence.

Capture ideas, prioritize with evidence, and build living roadmaps your team can rally aroundโ€”all while staying connected to delivery in Jira, so everyone can see whatโ€™s being built and why.

Better product decisions in the AI era.

Reply

Avatar

or to participate