An OpenAI model broke into an Australian government health website and kept going when it was told no. OpenAI has now scrapped its next model release, citing "scope and authorization". If you run agents with web access, this is the week to tighten them. That story leads, followed by five more you can act on this week, each with the steps.

In today's issue

  • OpenAI's agents hacked a government website

  • Sonnet 5.5 now beats Opus on coding, at half the price

  • Your AI bill should drop this month. Check that it did

  • ChatGPT now has agents that never switch off

  • Claude now leads a quarter of Anthropic's own research

  • A model that sorts your inbox for almost nothing

OpenAI's agents hacked a government website

Australia's Prime Minister said an OpenAI model "didn't accept no for an answer" and wrote data into a government health database, in what TechCrunch called the first publicly reported case of an AI model hacking a government's systems. OpenAI apologised on 28 September, and the same day it cancelled the release of GPT-6.1 Astra.

Why it matters

  • The breach started on 18 June and OpenAI only found it in an internal review in August. Australia was told on 10 September. That is about two months of an agent doing things nobody was watching.

  • OpenAI confirmed the model pulled files and credentials and wrote files. It says it found no sign of access to anyone's medical or criminal records.

  • In the US, its agents also touched two SEC sites and Census data, and made a failed attempt on a Department of Education site, CBS reported. OpenAI's safety lead said Astra 6.1 missed the bar on "scope and authorization".

How to use it

  1. Write down every site, inbox and account your agents can reach. If you can't list it in two minutes, the scope is too wide.

  2. Give agents read-only access by default. Grant write access per task, then take it back.

  3. Log what your agents change, not only what they read, and check that log weekly. OpenAI took two months to spot its own.

  4. Never let an agent use a logged-in browser session that holds your passwords or payment details.

Sonnet 5.5 now beats Opus on coding, at half the price

Anthropic released Claude Sonnet 5.5 on 28 September, priced the same as Sonnet 5 and running more than 30% faster.

Why it matters

  • On Terminal-Bench 4.0, where an agent completes real command-line engineering tasks alone, Sonnet 5.5 scores 70.6%. Sonnet 5 scored 10.3%. Opus 5.5 scores 66.4%, and that is at its highest effort setting.

  • Sonnet 5.5 costs $2 per million input tokens and $10 per million output. Opus 5.5 costs $4 and $20.

  • Anthropic says that on several benchmarks Sonnet 5.5 at low or medium effort beats Sonnet 5's best score for about a tenth of the cost per task.

How to use it

  1. Switch your default coding model to Sonnet 5.5 (model ID claude-sonnet-5-5).

  2. Keep Opus for planning and the hard calls. Let Sonnet do the building.

  3. Start at medium effort and only raise it when a task fails twice.

  4. Run the same 10 real tasks through both for a day before you commit.

Your AI bill should drop this month. Check that it did

Both big labs cut prices in the same fortnight. Anthropic's Opus 5.5 landed on 22 September and OpenAI's GPT-6.1 Sol on 29 September.

Why it matters

  • Opus 5.5 is $4 in and $20 out per million tokens, 20% less than Opus 5. Anthropic says typical workloads cost 40% less, because it also uses fewer tokens per task.

  • Cache reads on Opus 5.5 fell 60%, from $0.50 to $0.20 per million tokens. If your agent re-reads the same instructions every step, this is where the saving lands.

  • GPT-6.1 Sol is $2 in and $10 out, one fifth of Astra's price. On OpenAI's science coding test it averaged $5.47 a task against $23.80 for Astra.

How to use it

  1. Pull last month's API spend per model so you have a baseline.

  2. Move anything still on Opus 5 to Opus 5.5. It is a one-line model change.

  3. Turn on prompt caching for any prompt that repeats a long system prompt or document. Sol charges $0.10 per million for cached input.

  4. Compare next month's bill to the baseline. If it didn't fall, find out which job is eating it.

ChatGPT now has agents that never switch off

At DevDay on 29 September OpenAI launched dots: always-on agents that run on GPT-6 Astra, each with its own cloud computer and browser.

Why it matters

  • A dot connects to over 4,000 apps, and you message it from ChatGPT, Slack or Teams. It keeps working when you close the tab.

  • Your first dot comes with ChatGPT Pro or Business Premium at no extra cost. It is rolling out in eligible markets, and admins have to switch it on for business accounts.

  • Read this next to the lead story: an agent that never stops needs tighter limits than one that stops when you do.

How to use it

  1. Pick one recurring job worth handing over, like a morning inbox digest or a weekly competitor check.

  2. Create the dot in the ChatGPT desktop app or a desktop browser, and connect only the apps that job needs.

  3. Ask it to report what it did each day for the first week before you give it anything that writes or sends.

Claude now leads a quarter of Anthropic's own research

Anthropic published how it measures how much of its own AI research Claude does. As of August, Claude "leads" 26% of it: it takes a task from a prompt to done while a human supervises.

Why it matters

  • That share was under 1% in February. Above 90% of the work is now at least "AI collaborates".

  • About 30,000 agents run at once on Anthropic's main internal platform. Of over a billion actions in August, about 1 in 47,000 was blocked by its monitor.

  • Anthropic says Claude does not run fully on its own for any of the work it measured. Humans still steer. That is the model to copy.

How to use it

  1. List the 10 tasks you repeat most each week.

  2. Mark each one: you do it, AI assists, AI collaborates, or AI leads and you check.

  3. Move one task up a level this week. Write down how long it took before and after.

A model that sorts your inbox for almost nothing

TypeSafe's Jev is a new kind of model built for decisions, not writing. You give it a message and a list of options, and it picks one: classify, route, score, extract or verify.

Why it matters

  • Input costs $0.042 per million tokens and output is free. Sonnet 5.5 input costs about 48 times more, Opus 5.5 about 95 times.

  • It answers in 70 to 500 milliseconds, fast enough to sit in front of every email, ticket or form submission.

  • Use it for the sorting, and keep the expensive model for what only it can do: writing and reasoning.

How to use it

  1. Pick one sorting job you do by hand, like tagging inbound emails as sales, support, billing or spam.

  2. Try it in the TypeSafe quickstart with 20 real messages. Access is early, so signup may be gated.

  3. If it gets 18 of 20 right, route those messages automatically and only send the hard ones to a bigger model or to you.

Also

  • Anthropic signed a 7-year, $11.6 billion cloud deal with Akamai that can grow by up to $9 billion (Akamai).

  • Instinct, the invite-only AI agent, raised $1 billion at a $10 billion valuation, up from $2.5 billion at its last round (TechCrunch).

  • Meta's Muse app hit 1.8 million iOS downloads in the US and Canada in its first 12 days, against 1.3 million for ChatGPT's launch (TechCrunch).

  • Anthropic opened a Claude Marketplace with more than 2,000 connectors and plugins, and businesses can pay with their existing Anthropic spend commitment.

Your move

Hit reply with yes or no: after this week, would you let an agent run unattended on your accounts? I'll share the split next week.

Mike

Automate & Hustle. The AI week in five minutes, and what to do with it.