Week of July 27–August 3, 2026
Three things moved in AI this week that touch how much access you give AI tools, how much they cost, and how AI-made content gets labeled going forward. Here’s what changed and what to do about it.
An AI model broke into three real companies' systems. Here's the lesson if you're handing AI tools access to yours.
On July 30, Anthropic disclosed that three of its Claude models gained unauthorized access to the real production systems of three separate organizations during cybersecurity evaluations that were supposed to be sandboxed. The models were told their environment was an isolated simulation with no internet access. A misconfiguration between Anthropic and Irregular, the third-party firm running the tests, left the evaluation machines connected to the open internet instead. The models did what they were tasked to do: they found weak passwords and unauthenticated endpoints, and one even published a malicious package to the public PyPI code repository, all against systems that were never supposed to be reachable, TechCrunch reported.
Anthropic says the incident was caught, the affected organizations were notified, and none of it touched customer data or Anthropic’s own systems. OpenAI disclosed a similar incident on July 21, which is what prompted Anthropic’s own review in the first place.
The story isn’t that AI is dangerous in some abstract sense. It’s that two of the most careful AI labs in the world, running tests specifically designed to keep their models contained, still had a permissions misconfiguration that let an AI model reach systems it was never authorized to touch.
If you're connecting an AI receptionist, scheduling tool, or back-office agent to your email, calendar, payment system, or customer records, don't take a vendor's word for it that access is "isolated" or "read-only." Ask specifically what systems the tool can reach, what it can do once it's in, and whether that access is scoped down to only what the job actually requires. The companies breached this week weren't careless. The setup was.
OpenAI cut its cheapest AI model's price by 80%. Your AI tools just got cheaper to run, or should have.
On July 30, OpenAI cut the API price of its two lower-cost GPT-5.6 models. The cheapest tier, Luna, dropped 80%, from $1/$6 per million input/output tokens down to $0.20/$1.20. The mid-tier, Terra, dropped 20%. The flagship model’s price didn’t move. OpenAI says the cut comes from efficiency gains that lowered its own serving costs by 20%, and it’s passing that along. This lands just three weeks after GPT-5.6 launched on July 9.
Most small businesses never touch an API directly. But a lot of the AI-powered tools you already pay for, chatbots, call answering, email drafting, scheduling assistants, are built on top of models exactly like this one. When the underlying model gets 80% cheaper to run, that’s real margin for whoever built the tool.
If you're paying a flat monthly fee for an AI tool built on OpenAI's models, it's a fair question to ask your vendor whether this changes your price or your usage limits. It won't always. But the cost of running AI keeps dropping fast, and that's the reason tools that felt too expensive six months ago are worth a second look now.
California now requires labels on AI-generated images and video. It doesn't apply to you directly, but it'll show up in your feed.
California’s AI Transparency Act, SB 942, became operative on August 2 after a prior extension pushed the original January 1 date back. It requires any generative AI provider with more than one million monthly users in California, think Google, OpenAI, Meta, and similar-scale platforms, to embed C2PA-compatible provenance data in the images, video, and audio their tools generate, offer a free public tool for checking whether content was AI-made, and let users add a visible “AI-generated” label. Violations run $5,000 per day per instance.
This law doesn’t apply to a five-person shop in Anchorage generating a few social posts with an AI image tool. It applies to the platforms themselves. But because most AI image and video tools run through exactly the handful of companies this law targets, the practical effect is that AI-made content across the web starts carrying detectable and sometimes visible markers as a matter of default, not an opt-in feature.
If you use AI-generated images or video in your marketing, this isn't a compliance problem for you, it's a heads-up. Expect more of what you post, and what your competitors post, to carry an origin label whether either of you asks for one. Nothing to do about it right now beyond knowing it's coming.
What we're watching next week
-
AI agent permissions. The Anthropic and OpenAI incidents both trace back to access control, not model behavior. We’re watching whether the AI receptionist and automation vendors serving small businesses publish anything about how they scope access, since most don’t say today.
-
GPT-5.6 pricing trickle-down. We’re tracking whether any of the AI tools built for trades, healthcare, or logistics pass OpenAI’s price cut along, or just pocket the margin.
-
AI content labeling outside California. SB 942 only binds platforms with California users, but a national platform can’t easily run two versions of its product. We’re watching whether the labeling shows up for Alaska users too.