Good day . Security researchers just used Claude to break into OpenAI's own systems, Meta and a scrappy startup taught their AI agents to pick up the phone, and a Microsoft exec's own words are about to make a very expensive copyright case a lot more expensive. Let's get into it.
Claude Just Broke Into OpenAI's Own Codebase
What happened: Three security researchers at Hacktron AI used Anthropic's Claude Opus 5 to chain a forum software bug with a separate login weakness, breaking into an OpenAI employee's ChatGPT account and reading into OpenAI's internal code repository. They reported it privately in July, OpenAI patched it, and paid a bug bounty.
Why it matters: The same reasoning that makes Claude good at debugging your code makes it good at breaking someone else's β it took three people and a chatbot, not a nation-state hacking team, to get inside one of the best-defended companies in tech.
What everyone's saying: Security circles are split between alarm and "well, obviously" β coverage is already framing this as proof AI is lowering the barrier to sophisticated hacking, and several outlets note it's the second AI-linked security incident to hit OpenAI in as many months.
My read between the lines: OpenAI got hacked with a tool built by its biggest rival, and the headline it wanted was "researchers responsibly disclosed a bug." The headline it got was "Claude broke into OpenAI." Somewhere in Anthropic's Slack there's a channel that's just emoji reactions.
π Further reading: Anthropic, The Company You Bet On Just Released an AI That Can Hack Your Computer. Here's the Real Story. β if Claude can break into OpenAI in the hands of researchers, it's worth understanding exactly what it can do in anyone else's.
If today's lead story has you wondering who else has a way into your systems, here's a better use of that paranoia: Viktor. It's an AI agent that lives right in Slack, plugs into 3,000+ of your tools, and actually does the work β pulls reports, builds dashboards, ships code, runs campaigns β instead of just chatting about it. Not a chatbot. A coworker. New readers get $50 off their first month. Hire Viktor β
Your AI Assistant Can Now Call Restaurants
What happened: Meta's Muse and rival startup Instinct both shipped the ability for their AI agents to place real phone calls to U.S. businesses this week β booking a table, getting on a dentist's cancellation list, or fighting a cable bill, without you ever picking up the phone.
Why it matters: This is the first mainstream AI agent feature that leaves the screen entirely β the assistant isn't drafting a message for you to send, it's dialing a human and having the conversation on its own.
What everyone's saying: Early coverage is framing this as the next front in the AI-agent arms race β Goldman Sachs has reportedly flagged Muse's rollout as a stock catalyst for Meta, which tells you this is being read as "assistant wars," not a feature update.
My read between the lines: Somewhere a small-business owner is about to have a very confusing phone call with something that sounds like a slightly-too-polite robot. The real product here isn't convenience β it's a queue-jump: your AI calling ahead of every human still doing it the old-fashioned way.
π Further reading: I Make AI Versions of Myself for a Living. This One I Didn't Agree To. β the same agents now dialing your dentist are also modeling you β this deep-dive is about where that line actually sits.
The daily Brief is free and always will be. But if a story like today's leaves you wanting the full story, not just the headline β members get every paywalled deep-dive plus the entire archive, whenever they want it. Upgrade your membership β
Microsoft Privately Called Its Own AI Practices Theft
What happened: Newly unsealed filings in the New York Times' copyright suit against OpenAI and Microsoft show a Microsoft applied-science lead calling the companies' AI training practices "the largest theft of labor in human history" in a January 2023 internal memo β while the companies allegedly scraped paywalled Times content and stripped its copyright notices.
Why it matters: This isn't an outside critic's opinion β it's the companies' own people, in writing, acknowledging what their models were built on and admitting the harm, which undercuts the "fair use" defense both have leaned on for years.
What everyone's saying: Legal and media commentary is treating the unsealed language as a gift to plaintiffs β "even they called it theft" is already the dominant takeaway, since an internal memo does more to prove intent than any outside expert testimony could.
My read between the lines: Everyone in this industry has known for years the models were trained on stuff nobody paid for. The news here isn't the theft β it's that someone wrote the word "theft" in an email, and someone else forgot to delete it before discovery.
π Further reading: A Publisher's Perspective on The Bleak Future of Google's AI-Powered Search β the theft admission is Microsoft's word β this is what it looks like from the side that got robbed.
Humans Are Reading Your ChatGPT Chats
What happened: A 404 Media investigation revealed OpenAI pays hundreds of contractors more than $50 an hour, through an internal program called Project Lily, to read real ChatGPT conversations and rate the bot's answers β and this week two users filed a proposed class action alleging OpenAI misled them about how private those chats actually are.
Why it matters: If you've ever typed something into ChatGPT you wouldn't say out loud, "anonymized" is doing a lot of work β reviewers can't see your username, but they can see full conversations and memory summaries that often reveal exactly who you are and where you live.
What everyone's saying: Coverage is split between "this is standard practice every chatbot company does" and "OpenAI never made this clear enough" β the advice spreading fastest isn't outrage, it's a how-to on opting your chats out of review entirely.
My read between the lines: The uncomfortable part isn't that humans read some chats β it's the name. Somebody at OpenAI sat in a room and picked "Project Lily" for the initiative where contractors read your most private conversations, and nobody in that room thought that was a little on the nose.
π Further reading: Anthropic Won Its Case. Your Chat Logs Just Lost Theirs. β we've covered the chat-logs-as-evidence fight before; this is the same fight from the user's side of the glass.
Google Wants to Run Your Whole Household
What happened: Google Labs expanded its experimental CC agent from a solo productivity tool into a shared assistant for up to six family members, each with their own permissions β CC now sends a daily "Your Day Ahead" brief to the whole household and tracks shared to-dos, forms, and deadlines pulled straight out of everyone's email.
Why it matters: This is Google turning an AI experiment into infrastructure for the most mundane, highest-friction part of daily life β the group text about who's picking up the kids, the RSVP nobody answered, the form that's due Friday.
What everyone's saying: The framing that's sticking is "unpaid intern" β Android Authority calls it Google finally automating admin work, while others read it as a calculated play to get an entire household, not just one user, dependent on Google's stack.
My read between the lines: Every family member gets "a distinct identity and clear permissions" inside an AI that's reading everyone's email. That's either the most useful thing Google's shipped all year, or the most complete household surveillance product ever built β and which one it is depends entirely on how much you trust Google's defaults.
That's your AI Brief for Friday.
βArtificially Intimidating














