In partnership with

Anthropic is about to make its biggest bet ever, North Korean hackers found a new way to run AI without anyone watching, and a security flaw let strangers read what AI models were secretly thinking. None of that happened by accident. Today's stories are all about who controls AI, who profits from it, and who gets left exposed when nobody's looking. Here's what actually happened, and what it means for your business.

Cut Lead Review From Hours To Minutes

Sign up for a free trial of Attio, the agentic CRM.

Ask Attio to build a daily workflow that surfaces the deals that need your attention today, like anything with a stage change, a recent reply, or a new signal in the last 24 hours.

Review your pipeline in Claude, synced live from Attio via MCP.

That's it.

Anthropic Is About to Make Its Biggest Bet Yet

What happened: Anthropic is in talks to acquire AI startup Decart for roughly $6 billion, according to Bloomberg and Fortune. It would be Anthropic's largest acquisition ever, coming ahead of an expected IPO. Decart builds software that makes AI chips run more efficiently, plus a video model that can alter live video in real time. Anthropic reportedly wants that chip-efficiency expertise to bring down its own massive computing costs. The deal isn't final and could still fall apart.

Why it matters to you: Anthropic makes Claude, a tool plenty of small businesses now run part of their day on. When a company spends $6 billion just to make its own AI cheaper to run, that tells you how expensive this technology still is to deliver behind the scenes, and where the pressure to bring costs down is really coming from.

What to do about it: Nothing to act on yet. It's just worth knowing why your AI subscription costs what it costs.

North Korea's Hackers Are Now Running AI With the Internet Turned Off

What happened: South Korean cybersecurity firm Genians found that Kimsuky, a hacking group tied to North Korea's Reconnaissance General Bureau, is running AI language models completely offline on its own servers using free tools like Ollama and GPT4All, according to Al Jazeera. The group uses the AI to write convincing phishing documents disguised as things like research reports and event invitations, aimed at military, diplomatic, and academic targets. Because everything runs offline, there are no API logs or safety filters to catch it.

Why it matters to you: Bad spelling and awkward phrasing used to be the easiest way to spot a scam email. AI just took that tell away, for state hackers and small-time scammers alike. The phishing email that lands in your inbox, or one of your employees' inboxes, is only going to get harder to catch by instinct.

What to do about it: Remind your team that a well-written email is no longer proof it's legitimate. Verify anything asking for money, credentials, or sensitive files through a second channel before acting on it.

A Security Flaw Let Strangers Read What AI Models Were Secretly Thinking

What happened: Researchers found a flaw across OpenAI, Anthropic, and Google's AI systems that let a weaker model decode another model's hidden "reasoning," the private thinking a model does before it gives you an answer, according to The Hacker News. Digging through public logs, researchers recovered more than 700 real passwords, API keys, and access tokens that people had accidentally exposed inside that hidden reasoning. The companies were notified and say the specific attack no longer works, though older, already-published logs may still be exposed.

Why it matters to you: If you or your team paste sensitive information into an AI chat, a password, a client's details, financial numbers, you're trusting that it stays private. This is a reminder that "hidden" doesn't always mean secure, especially with tools moving as fast as AI is right now.

What to do about it: Treat AI chats the way you'd treat an email you're not sure is encrypted. Don't paste passwords, account numbers, or anything you wouldn't want made public.

Half of Shoppers Don't Trust AI's Advice Until Reddit Confirms It

What happened: A new Reddit Business survey found that half of US shoppers, and more than a third in the UK, now double-check AI shopping recommendations on Reddit before buying, according to PPC Land. Sixty percent of US respondents said they trust Reddit's community more than their own friends or family to validate what an AI tool told them, and more than 1 in 5 shoppers now type "Reddit" directly into their search bar to find real opinions.

Why it matters to you: Your customers may already be asking AI what to buy, but plenty of them aren't stopping there. They're checking your business against what real people are saying online before they hand over a card number. If nobody's talking about you anywhere people actually trust, that's a gap worth noticing.

What to do about it: Search your own business name on Reddit and see what comes up. If it's nothing, think about where your happiest customers already spend time online, and whether you could earn a few honest mentions there.

Even AI's Biggest Names Can't Agree on How Open It Should Be

What happened: At the Ai4 conference, AI pioneers Geoffrey Hinton, Fei-Fei Li, and Andrew Ng all argued for keeping AI models open rather than locking them behind a handful of big companies, according to TechCrunch. Hinton, who once opposed open-weight models on safety grounds, said that fight is already lost. Andrew Ng warned that a handful of gatekeepers controlling AI access would slow progress for everyone else. Fei-Fei Li pushed back on treating it as all-or-nothing, comparing it to how scientific papers stay open while some materials stay regulated.

Why it matters to you: This debate decides whether the AI tools you rely on stay affordable and varied, or end up controlled by two or three giant companies that can set the price and the rules. It's worth having an opinion on, even if you're not the one building the models.

Spotify Is About to Stop Recommending AI "Artists"

What happened: Starting in mid-September, Spotify will label AI-generated artist profiles with an "AI Persona" badge and drop them from its algorithmic and editorial recommendations by default, according to TechCrunch. The label applies to fake artist identities, not to real musicians who simply use AI in their process. Listeners can still follow an AI Persona artist directly, but Spotify won't push their music to new listeners the way it does for verified, real artists.

Why it matters to you: If you use AI-generated music in ads, videos, or your business's social content, this is an early look at where platforms are heading: labeling AI output and quietly deprioritizing it unless someone actively chooses it. Expect more platforms to draw a similar line before long.

Claude in Your Browser Just Got a Lot More Capable

What happened: Anthropic added its Cowork feature to the Claude Chrome extension's side panel, so it now works as a full AI assistant inside your browser instead of a simple chat box, according to The Decoder. It can pull in your existing Skills, connectors, and plugins with no extra setup, build spreadsheets or slide decks from what's on your screen, and pull data from tools like your CRM while you work. Anthropic says it will ask before completing any purchase and warns against using it with sensitive banking or health information, since a malicious website could try to hijack its instructions.

Why it matters to you: This turns your browser into something closer to a research and admin assistant, without copying and pasting between tabs and a separate AI app. If you already pay for a Claude plan, this is free functionality sitting in a menu you may not have opened yet.

What to do about it: If you use Claude, install the Chrome extension and try it on one real task this week, like pulling numbers from a report or drafting something from a page you're already reading.

OpenAI Built an AI That's Really Good at Hacking, on Purpose

What happened: OpenAI released GPT-5.6-Cyber, a version of its model trained specifically to find security vulnerabilities and build exploits, and made it available to vetted security firms like Cisco, Cloudflare, CrowdStrike, IBM, and Palo Alto Networks through a new access tier called Daybreak Red, according to The Hacker News. The model completes 95% of advanced cybersecurity tasks it's given, up from 57% for the prior version, and has already found real, previously unknown vulnerabilities. OpenAI says the goal is to hand defenders the same firepower attackers are already building for themselves.

Why it matters to you: This isn't a tool small businesses will use directly, but it shows where the cybersecurity fight is heading: AI finding and fixing holes before criminals do, or the other way around, depending on who moves first. The vendors and IT providers you rely on may already be using tools like this without you ever seeing it.

The Bottom Line

Today's stories all point the same direction: money, secrecy, and control are consolidating around AI faster than most of us can track. A $6 billion acquisition, a state hacking group running AI in the dark, a security hole that exposed real passwords, three legends of the field disagreeing on how open any of this should be. None of it means you need to do something different today. It means paying attention to who's building this, who's watching it, and who's cashing in, because those answers will shape what your AI tools cost and how safe they are long before most business owners notice the shift. Stay on the train. Just keep your eyes open.

Enjoying the Ride?

If today's issue helped you catch something before it caught you, forward it to one person who'd want the heads up. New here? Subscribe to get tomorrow's issue in your inbox.

Talk tomorrow,
Mark Shilensky