Artificially Intimidating
Context Window: AI Daily News Brief
Everybody Wants a Key to Something -- AI Brief August 25
0:00
-6:00

Everybody Wants a Key to Something -- AI Brief August 25

Today's Context Window: Meta's $200-a-month agent, Anthropic's $35M in store credit, a founder's $20K month, and Amazon's chatbot telling on Amazon.

Good day, humans. Today is about who holds the keys. OpenAI shipped a plugin that reads your text messages and wants your entire hard drive to do it. Meta picked a price for a robot that shops for you. Anthropic pledged thirty-five million dollars to open source and paid it in store credit. A solo founder ran up a twenty-thousand-dollar bill on coworkers who do not exist. And Amazon’s own shopping bot explained, out loud, why it will not tell you what is made in America. Five stories about access, and who decides you get it.


ChatGPT Wants the Keys to Your Whole Mac

TechCrunch

You asked it to water the plants. It kept the key.

What happened: On August 20 OpenAI shipped a Messages plugin for the ChatGPT Mac app. It can search, summarize, draft and send your iMessage, SMS and RCS conversations. It is free on every tier including the unpaid one, runs only on Apple-silicon Macs, and to work at all it needs Full Disk Access in System Settings, plus your contact names and automation permissions.

Why it matters: Full Disk Access is not a Messages permission. It is a Mac-wide one. As Computerworld laid out, the same switch that lets ChatGPT read your texts also sits in front of Mail, Safari history and Time Machine backups. And the people on the other end of those threads never agreed to anything. Your friend’s Android messages are now in scope because you tapped a toggle on your laptop. Yesterday we ran Sam Altman conceding he was wrong about the speed; this shipped four days before that ran.

What everyone’s saying: Critics are calling it a betrayal of the thing Apple sells. Developer Steve Moraco called it “total architecture abandonment and user trust betrayal on Apple’s part,” and privacy researcher Paul Walsh argued the plugin works like a backdoor the user builds themselves, exposing messages from people who never consented and may not even own an Apple device. OpenAI’s answer is that the plugin runs locally, builds no general index of your messages, and asks before sending anything.

My read between the lines: OpenAI’s own release notes carry a known issue: scheduled tasks disable the per-send approval, which means ChatGPT can text people as you without asking first. The entire safety argument is “it checks with you,” and the exception is documented in the changelog by the company making the argument. Nobody had to leak that. They wrote it down and shipped anyway.

📖 Further reading: I Make AI Versions of Myself for a Living. This One I Didn’t Agree To. — the plugin’s real problem is the same one in that piece: the person whose data got used was never the person clicking accept


Handing an AI the keys to your personal life is a bad trade. Handing one the keys to your busywork is a great one. Viktor is an AI agent that lives in Slack, connects to more than 3,000 tools, and actually finishes things — the Monday report, the stalled dashboard, the bug fix nobody claimed, the campaign that has been in drafts since June. You do not prompt it all day like a chatbot. You hand it work like a coworker and check the output. New readers get $50 off their first month. Hire Viktor →


Meta Wants $200 a Month for an Agent

The Decoder

Twenty years of knowing what you want to buy, finally holding the wallet.

What happened: Meta is preparing to launch Hatch, a consumer version of its OpenClaw agent, as soon as early September. It has been trained to act on your behalf across DoorDash, Etsy, Reddit, Yelp and Outlook, with a dashboard showing the little tools its agents build for you, like a fitness tracker or a trip itinerary. The Information reported (via Investing.com) that Meta has weighed charging as much as $199.99 a month for a premium tier. A new model codenamed Watermelon is targeted for October.

Why it matters: Meta has never charged you for anything. The whole company is built on the opposite deal: the product is free and you are the inventory. A $200-a-month subscription is Mark Zuckerberg testing whether AI can carry revenue that advertising cannot, which is a much bigger admission than a product launch usually is.

What everyone’s saying: The pricing lands at the very top of the market, matching the $200 tiers from OpenAI and Anthropic, and the skeptical read is that Meta does not have a frontier model to justify sitting there. Watermelon reportedly matches GPT-5.5 internally, which would be a fine place to be if OpenAI had not already shipped past it.

My read between the lines: Look at what they trained it on. Not research, not code, not email triage — DoorDash, Etsy and Yelp. Meta has spent two decades getting extremely good at predicting what you are about to buy and then selling that prediction to somebody else. Hatch is the first version where it can skip the middleman and just buy it. Charging you $200 for the privilege is almost cheeky.

📖 Further reading: The $200/mo question: Perplexity Computer or OpenClaw? — Meta just walked into the exact price bracket that piece breaks down, so the comparison is now a three-way


Quick note before story three. The Brief is free and stays free — five stories, every weekday, no gate. What sits behind the paywall is the other half: the deep-dives where I actually take one of these things apart, plus the full archive going back to the beginning. If the daily is useful to you, that is the part worth paying for. Become a member →


Anthropic’s $35 Million Is Store Credit

Anthropic

Load-bearing, technically.

What happened: On August 21 Anthropic put Claude Mythos 5 — its most locked-down model — into Claude Security, the codebase scanner now in public beta for Enterprise customers. Scans come back with a vulnerability category, a severity rating and a suggested patch, without anyone touching the model directly. Alongside it the company launched the Defender Advantage Fund: $35 million for groups helping open-source maintainers secure their software.

Why it matters: Open source holds up nearly everything you use, and it is largely maintained by volunteers and small nonprofits with no security budget. So $35 million is real money in a corner of the world that rarely sees any. Read the denomination, though. Anthropic’s own announcement says the fund provides $35 million in credits, not dollars. For comparison, the earlier Project Glasswing included $4 million in direct donations. The bigger number is the one that is not cash.

What everyone’s saying: The security press has focused on the access design rather than the money. SecurityWeek and The New Stack both read it as Anthropic solving the dual-use problem by shipping findings instead of the model: defenders get the patches, and nobody gets a general-purpose offensive cyber tool. Every patch still needs a human to approve it.

My read between the lines: A burnt-out maintainer’s problem is time and rent, not a shortage of tokens. Credits are the one currency Anthropic can mint in its own basement, and spending them here buys something better than goodwill: the software that everything else is built on starts running its security through Claude. That is a genuinely strong position to hold. It is also still more than almost anyone else is putting in, which tells you more about the industry than about Anthropic.

📖 Further reading: AI Is a Trust Problem, Not a Tech Problem — the whole design here is about who you let near the model, which is the argument that piece makes at length


He Spent $20,000 on Coworkers Who Don’t Exist

Lenny’s Newsletter

Fifteen agents, one paper list, no HR department.

What happened: Ryan Carson, a five-time founder now running the family-law software company Untangle by himself, told Lenny’s Newsletter he burned through $20,000 in a single month on Devin, the autonomous coding agent from Cognition. He runs roughly fifteen agents at once — engineering, customer success, investor updates — ships somewhere between 22 and 40 pull requests a day, often from his phone, and keeps track of all of it on a handwritten list.

Why it matters: This is one of the few public numbers for what an agent-run company actually costs. After the $20,000 month he tuned it down to about $5,000 per “employee” by routing the repetitive loop work to cheaper fine-tuned models. That is still a real salary line, and it is a useful counterweight to the version of this story where AI labor is free.

What everyone’s saying: Carson’s framing has caught on faster than his numbers: everyone is now a manager of agents, and being excellent at that is the skill of the year. O’Reilly called him a one-person code factory. The pushback is the obvious one — pull requests are not shipped value, and forty a day from fifteen agents is a review problem before it is a productivity win.

My read between the lines: The detail that stayed with me is the handwritten list. He has fifteen autonomous engineers and the coordination layer is paper. That is not a charming quirk, it is the actual state of the tooling. The other half of it: he swapped a hiring plan for a metered utility bill. Employees do not quadruple in cost because you had a busy Tuesday.

📖 Further reading: Paperclip.ing: The Day 0 Playbook for Building a Zero-Human Company with AI Agents — Carson is running the version of this playbook that has a real invoice attached, which makes the plan considerably easier to price


Amazon’s Chatbot Told On Amazon

The American Prospect

It answered honestly because nobody wrote a talking point for this one.

What happened: Researchers Erie Meyer and Zachary Harris at Columbia Law’s Center for Law and the Economy spent weeks interrogating Amazon’s Alexa for Shopping and Walmart’s Sparky about where products come from. The bots answered questions about goods made in China and refused the equivalent questions about goods made in America. Amazon’s own assistant described the gap as a company decision to protect its overseas sellers. Their report calls it an engineered block, not a data gap.

Why it matters: Both retailers can detect false “Made in USA” claims on their own platforms. Neither flags them for you. Asked why, the companies told the researchers that flagging is technically feasible and the decision not to is a business calculation rather than a legal justification. If you have ever bought something because the listing said American-made, the machine that could have checked was told not to.

What everyone’s saying: Manufacturing groups have run with it hardest — the Alliance for American Manufacturing framed the finding as the platforms tuning their assistants to protect Chinese-made inventory over American sellers. Both companies point to existing seller policies and enforcement, which is a different claim than the one the researchers tested.

My read between the lines: The chatbot confessed because nobody drafted a talking point for “why won’t you answer this.” Every other surface a company owns — the press release, the earnings call, the support macro — goes through review. The assistant is a reasoning engine wearing a corporate logo, and when you ask it about its own behavior it will tell you, because it was never briefed. Every company shipping one of these has handed a candid spokesperson a job it did not interview for.

📖 Further reading: What I Learned from 30 Days of Not Shopping on Amazon — if the assistant is deciding what you are allowed to find, the experiment in that piece stops being a stunt and starts being a workaround


That’s your AI Brief for Tuesday.

—Artificially Intimidating

Discussion about this episode

User's avatar

Ready for more?