Good day .
One small ask before the news.
This brief is also a six-minute podcast, out every morning before you're at your desk.
If you'd rather hear it than read it, tap once here and it'll follow you to whatever app you use. It’s FREE, and it takes about four seconds.
If easier for you, here are direct links to Apple Podcasts & Spotify Podcasts
Okay, now back to the good stuff — A startup is now selling hosted access to open-weight models with the refusal circuitry cut out, and TechCrunch got one to write a password stealer on a free account. DoorDash, Airbnb and Siemens have started routing work to Chinese models that cost a tenth as much. Anthropic is hiring people to decide how much of Stripe’s job it should do itself. And two Calgary researchers have a name for what happens when someone slips a page into your agent’s notebook and waits.
A Startup Will Sell You the AI With Its No Button Snipped Off
What happened: Abliteration.ai hosts open-weight models, including Z.ai’s new GLM-5.3, with their refusal behaviour surgically removed, and sells access through a browser or an API. The technique itself is years old and Hugging Face already lists thousands of “abliterated” models; the new part is that someone rents the GPUs and takes your credit card. TechCrunch’s Rebecca Bellan opened a free account, asked for a Python program that steals saved Chrome passwords and a protocol for culturing a dangerous pathogen at home, and got both.
Why it matters: The company was incorporated in March, has no venture money yet, and says its customers are early-stage red-teaming startups in the UK and Europe that test the defences of banks and airlines. Its only identity check is the credit card. Co-founder Devon, who would not give his surname because he still works somewhere else, told TechCrunch the company is “still in the process of defining” where its responsibility ends. That is a sentence a bank’s security vendor is now paying for.
What everyone’s saying: CivAI’s Andrew Yoon says the process lets you “modify the model so that it becomes a sociopath” and expects abliterated models to be used for harm soon; his proposed fix is classifiers at the provider and identity checks for anyone renting serious GPUs. The red-teamers TechCrunch called were less impressed: Fabraix’s Ahmed Aly says abliteration degrades the model’s knowledge and he fine-tunes instead, and Armadin’s David Slater says until this last generation open-weight models were easy enough to jailbreak that nobody bothered.
My read between the lines: The real story is the model, not the startup. GLM-5.3 is capable enough that the security people who used to shrug at jailbreaks now care who has the un-refusing version. The guardrails every lab spends months on live in a few directions inside the weights, and a hobbyist can delete them in an afternoon. Abliteration.ai just put a checkout page on the afternoon. If the bio safeguards went too, as one policy researcher claimed on X this week, this is a week-one problem for whoever releases the next big open model.
📖 Further reading: Anthropic built the most powerful AI ever. You can’t use it. — the other end of the same argument: one lab gating its most dangerous model, and a startup selling the ungated version of everyone else’s.
Every story today is about somebody’s AI bill, and the cheapest line item is the one that actually ships work. Viktor is an AI agent that lives in Slack, connects to more than 3,000 tools, and turns a message into a finished report, a live dashboard, working code or a full campaign while you are in the meeting about it. Not a chatbot you check on; a coworker you hand things to. New readers get $50 off their first month. Hire Viktor →
DoorDash and Airbnb Found the 90% Off Bin
What happened: The Financial Times reports (via Futurism) that DoorDash, Airbnb and Siemens have moved chunks of their AI workload onto Chinese models from DeepSeek, Z.ai and Moonshot, drawn by price and by open weights they can tune themselves. On OpenRouter, the marketplace where developers pick a model per request, Chinese models have overtaken Claude and ChatGPT. DoorDash co-founder Andy Fang said the company saves real money sending “lower-level work” to a Moonshot model; the startup Lindy dropped Anthropic entirely for DeepSeek V4.
Why it matters: A Juniper Research report out Wednesday puts Chinese models at up to 90% cheaper to run and says US labs’ share of OpenRouter work fell from about 70% a year ago to about 30%. On Thursday we covered Fable 5.1 taking the top score and the top bill; this is the other half of that chart. Ramp’s AI Index has the most committed companies spending around $7,500 per employee per month, and Futurism cites one organisation that reportedly burned $500 million on Claude in a single month.
What everyone’s saying: Featherless CEO Eugene Cheah: enterprises are realising “we don’t need the best model, we can use the faster, cheaper models.” Georgetown’s Sam Bresnick asks why anyone would pay a premium for OpenAI or Anthropic when the Chinese models are “generally workable.” Cohere’s Aidan Gomez points at the Trump administration suspending overseas access to Anthropic’s Mythos as the moment foreign buyers stopped trusting a single US supplier.
My read between the lines: Juniper’s scary paragraph is the honest one: the Western data-centre build-out is financed on the assumption that customers keep paying a premium for the best model. Two markets have formed, one on price and one on quality, and every Chinese release moves the line between them. OpenRouter is a routing layer, not a revenue statement, so the 30% figure overstates the switch. But a CFO does not need the number to be exact. He needs a reason to ask the question, and this week handed him three.
📖 Further reading: Fable 5 Costs 2x Opus — and Using It Wrong Costs You More Than That — the operator’s version of the same decision: which tasks earn the premium model and which ones never did.
The Brief is free and stays free. What members get is the part that takes me a week rather than a morning: the paywalled deep-dives behind these headlines, like which of my own workloads I moved off the premium model and what broke, plus the full archive. Become a member →
Anthropic Is Hiring Someone to Build Its Own Cash Register
The Information (via Seeking Alpha)
What happened: The Information reported on Friday that Anthropic is weighing how much of its billing, payments, tax and fraud infrastructure to build in-house instead of buying from Stripe, citing its own job listings. The Staff Software Engineer, Billing Platform posting is blunt about it: “Make build-vs-buy calls. We lean heavily on third-party billing, payment, and tax platforms, and you’ll decide where to extend them and where to build our own primitives around them.” Pay is $320,000 to $405,000.
Why it matters: Stripe currently runs Anthropic’s payment collection, invoicing, subscriptions and checkout, per Crypto Briefing. Every dollar of Anthropic’s revenue passes through that stack, and the posting lists “processing cost as a real number you drive down.” At Anthropic’s scale a fraction of a percent on interchange is a team’s worth of salaries. This is what companies do when the vendor’s take rate becomes visible on the income statement.
What everyone’s saying: The framing is “could hurt Stripe,” and it is worth remembering Stripe publishes Anthropic as a customer case study. The same week, Anthropic open-sourced Claude Commerce Agents with Visa, Mastercard, Shopify and Accenture: a shopping agent that searches catalogues and walks a customer to checkout, and a merchant agent that sets prices and watches inventory. So it is now on both ends of the transaction.
My read between the lines: Read the posting as a product spec and the target is not Stripe. It is usage-based billing for agents: per-token metering, prepaid credits, enterprise entitlements, disputes handled automatically. That does not exist as a product anyone can buy, so the lab that bills more tokens than anyone is writing it. If it works, it is the billing system every agent company needs next year. Stripe should worry less about losing a customer and more about who ends up selling the thing.
📖 Further reading: Your SaaS bill is a sitting duck — the build-versus-buy argument, now being run by a company with the engineers to build.
Poison the Notebook, Then Wait
The Conversation (via TechXplore)
What happened: Abbas Yazdinejad and Hadis Karimipour at the University of Calgary ran 2,614 simulated multi-step attacks on AI agents that keep persistent memory, and published the results in IEEE Access. The pattern they call memory poisoning: an attacker slips a false entry into the agent’s stored knowledge, the agent carries on normally for days, then retrieves the entry when a relevant request arrives and trusts it as something it learned itself. They studied four flavours: chain poisoning, policy rewriting, backdoor triggering and slow drift.
Why it matters: Two of the four, slow drift and backdoor triggers, were close to indistinguishable from normal behaviour when checked one step at a time, and only showed up across later interactions. Some attacks were non-monotonic: the agent looked worse, then better, then did the harmful thing. Every security review that tests an agent right after it reads something suspicious, sees nothing, and signs off is testing the wrong moment.
What everyone’s saying: Yazdinejad’s own analogy, in The Conversation: someone writes “requests from this person have already been approved” in a colleague’s notebook and nothing happens until the colleague consults it. The pitch is “trajectory-aware” testing, evaluating the whole sequence rather than each prompt. The bigger industry chorus this week, under the banner of Insider Threat Awareness Month, is that agents with credentials are now a category of insider.
My read between the lines: Every product this year is racing to give its agent a longer memory, because memory is what makes it feel like it knows you. This paper says memory is also the first durable foothold an attacker gets. Prompt injection was a one-shot con. Memory poisoning is a sleeper agent, and the thing that eventually wakes it up is you, asking a perfectly normal question.
📖 Further reading: Why Your AI Has Goldfish Memory (And How to Finally Fix It) — the memory setup I recommended is now the attack surface this paper describes. Worth re-reading with that in mind.
A Brain Coach Says You Are Surrendering, Not Offloading
What happened: Memory coach Jim Kwik went on The Jefferson Fisher Podcast this week to argue that leaning on AI for the first draft of every thought is not cognitive offloading, which humans have done since the notebook, but “cognitive surrender”: the skill never gets built because the friction that builds it is gone. His fix is to brainstorm, understand and imagine before the prompt, then let the AI in, then decide yourself. He also has a new book out, which is not unrelated to the podcast tour.
Why it matters: The evidence people reach for here is MIT Media Lab’s “Your Brain on ChatGPT” study, in which essay writers using ChatGPT showed the weakest connectivity on EEG and most could not quote their own work minutes later. It is one small study with a limitations section its authors keep pointing at, but it is the reason a memory coach can now get a hearing on a communication podcast.
What everyone’s saying: The self-improvement circuit has adopted the line wholesale, and Kwik’s framework has an acronym, which is how you know it is for sale. MIT’s own FAQ for the study asks journalists to stop saying it shows AI makes people “dumber,” and to avoid “brain scans,” “brain damage” and “terrifying findings.” The discourse is not complying.
My read between the lines: Kwik is right about the mechanism and wrong about the scale. The people at risk are not the ones who never think before prompting; they are the ones who used to think before writing and no longer have to. I write this brief with a lot of machine help, and the part I refuse to hand over is this bullet. Decide which bullet is yours before the model decides for you.
📖 Further reading: I stopped writing. My output doubled. — my version of the line between offloading the typing and offloading the thinking.
That’s your AI Brief for Saturday.
—Artificially Intimidating















