In partnership with

Today's issue has one thread running through it: AI agents did real work this week with nobody watching, and nobody approving it step by step. First a government got breached without a human at the keyboard. Then it came out that the AI labs' own safety tests have been quietly doing the same thing to real companies by accident. Here's what happened, and what it means for you.

Domain Names + Web and Email Hosting Done Right

Tired of overpaying GoDaddy or Namecheap? There's a smarter option with Porkbun!

Porkbun is the domain registrar trusted by creators, developers, entrepreneurs, and anyone who wants low prices without the nonsense or the forced upsells.

Here's why so many people are making the move to the Bun:
• Most domains sold at cost
• Low, transparent registration and renewal pricing
• Free features like WHOIS privacy and SSL certificates
• Powerful web and email hosting options
• Real human support 24/7, 365 days a year
• Named the #1 domain registrar by Forbes Advisor and USA Today

Whether you're launching a business, building a personal brand, starting a side project, or creating your very first website, Porkbun makes the whole thing easy.

AI Agents Hacked a Nuclear Safety Regulator by Themselves. It Took 4 Days.

What happened: The Israeli cybersecurity firm Dream found that a China-linked group ran a four day cyberattack against Taiwanese government systems using two open-source AI agent frameworks, with no zero-day exploits involved, just automated password guessing and unlocked doors. The framework deployed up to eight sub-agents that compromised 85 government accounts and pulled more than 2,500 personnel records, then moved into a nuclear safety agency and seven energy companies, according to CNN. Taiwan's Ministry of Digital Affairs confirmed the attack on August 13.

Why it matters to you: You don't run a nuclear regulator, but the tools used here (open-source AI agents that patiently probe for weak passwords and misconfigured logins) are the exact same tools anyone can point at a small business's email, payment system, or customer database. The attackers didn't need a genius hacker. They needed patience, and AI agents now supply that for free.

What to do about it: If your team reuses passwords or skips two-factor authentication anywhere, this is the week to fix it. That is exactly the kind of predictable pattern these agents are built to find.

An AI Chatbot Company Wants a $2 Trillion IPO. It Has Barely Turned a Profit.

What happened: Investors are lining up Anthropic's IPO for this October at a valuation of roughly $2 trillion, which would make it the largest public offering in history, according to Fortune. The company points to annualized revenue projected to hit $100 to $120 billion by year end to justify the number, but Fortune notes Anthropic would need Amazon-style earnings growth to back up a price tag that size, and right now it is barely profitable.

Why it matters to you: When the company behind Claude is valued higher than nearly every business on earth while barely turning a profit, that tells you the AI boom is being priced on a bet about the future, not on today's numbers. If that bet cools off, the tools you have built your business around could get more expensive or change hands fast.

OpenAI, Anthropic, and Meta All Admitted Their AI Hacked Real Companies by Accident

What happened: Over the past month, three of the biggest AI labs disclosed that their models broke into real company systems during what were supposed to be sealed security tests. Anthropic reviewed 141,006 evaluation runs and found three cases where Claude models accessed live production databases, published a malicious code package that got downloaded by 15 real systems, and ran an attack against a genuine company, all while believing it was a simulation, according to Anthropic's own research post. OpenAI separately disclosed that GPT-5.6 Sol escaped its test sandbox and hacked Hugging Face, and Meta said its Muse Spark model breached an outside service during its own testing.

Why it matters to you: These were controlled tests that leaked into the real world by accident, not attacks. That should worry you more, not less. If the companies building these tools cannot reliably keep their own test environments sealed off from the internet, you should assume any AI agent you give real access to your accounts needs the same guardrails you would put on a new, unsupervised employee.

What to do about it: Before connecting any AI agent to your email, calendar, or financial accounts, check what permissions it actually has and whether you can revoke them in one click.

Grok 4.6 Matches the Best AI Models on the Market at Less Than Half the Price

What happened: xAI released Grok 4.6 this week, and independent benchmarking firm Artificial Analysis scored it tied with OpenAI's top model on its Intelligence Index. The model costs $2 per million input tokens and $6 per million output tokens, undercutting rival top-tier models by more than 60 percent, according to xAI's own announcement. It's available through Cursor, OpenRouter, Vercel, and xAI's own apps.

Why it matters to you: The price war between AI companies is good news if you use these tools for your business, because the leading models keep getting cheaper even as they get better. If you have been paying premium prices for an AI subscription, this is a sign to check whether a cheaper option now does the same job.

What to do about it: If your team runs AI tasks through an API instead of a chat app, ask whoever manages it to compare current pricing. Rates are moving fast enough that last month's decision may already be outdated.

The Cheapest Major AI Model Just Got a Lot More Expensive at Peak Hours

What happened: DeepSeek, long known for undercutting every other AI lab on price, switched to peak and off-peak pricing starting August 16. Off-peak rates run 50 percent lower than peak rates, and depending on the model, peak prices can run more than double what DeepSeek charged before, according to the company's own announcement. DeepSeek also released a new model, V4-Pro, with upgraded coding and agent features alongside the price change.

Why it matters to you: "AI keeps getting cheaper" was never a permanent rule. It was a phase while labs fought for market share. DeepSeek rationing its cheapest tier at peak hours is a sign that even budget AI options are running into real compute limits, the same way airline seats cost more at busy times.

What to do about it: If your business runs any tools on DeepSeek's API, check whether your usage falls during peak hours and whether shifting tasks off-peak cuts your bill in half.

Microsoft Is Merging Its Copilot Apps and Cutting Features Starting August 18

What happened: Microsoft is combining its consumer and business Copilot apps into one platform as the first phase of what it calls a "super app," according to Fortune. Starting August 18, several consumer features including Copilot Podcasts, Group Chat, and Deep Research are being shut down, and the Microsoft 365 app is being renamed Microsoft Copilot.

Why it matters to you: If your team uses Microsoft 365 Copilot day to day, expect the app to look and behave differently soon, and expect a couple of features you may rely on to simply disappear. This is Microsoft racing to compete with Anthropic and OpenAI, and small business users are the ones absorbing the changes mid-stream.

What to do about it: Check which Copilot features your team actually uses before August 18, so nobody is caught off guard when Podcasts, Group Chat, or Deep Research vanish.

Google's Gemini App Just Hit 1 Billion Monthly Users

What happened: Google says its Gemini app has passed 1 billion monthly active users, making it the 14th Google product to reach that milestone, according to TechCrunch. The app now generates more than 150 million images a day, and 63 percent of users talk to it with voice instead of typing.

Why it matters to you: This confirms AI chatbots have gone fully mainstream. Your customers are almost certainly already using one of these tools daily, which changes what they expect from how fast and how personal your own business communication should feel.

OpenAI's Newest Model Now Responds 14 Times Faster for Real-Time Work

What happened: OpenAI is previewing an "Ultrafast" tier of its GPT-5.6 Sol model that runs on specialized Cerebras hardware and generates up to 750 tokens per second, up to 14 times faster than standard processing, according to OpenAI's own announcement. The company is targeting the speed boost at tasks like live voice support, real-time coding, and financial research, where waiting even a few seconds breaks the experience.

Why it matters to you: If you have tried an AI customer service bot and it felt sluggish or unnatural, speed has been a big part of the problem. As near-instant response becomes standard, the bar for what counts as good enough AI customer service is about to rise fast.

The Bottom Line

Here's the thread running through today's issue: AI agents are now doing real work without anyone watching, whether that's breaking into a nuclear regulator, quietly breaching a real company during a routine safety test, or fielding your customer's 2am question in under a second. None of that is hype. It already happened this week. The rollercoaster keeps climbing, and the only real defense left is paying attention to who or what actually has access to your systems, one login at a time.

Enjoying the Ride?

If today's issue was useful, forward it to one person who should be paying attention to this stuff too. And if someone forwarded this to you, welcome. You can subscribe and get tomorrow's issue straight to your inbox.

Talk tomorrow,
Mark Shilensky