Weekly edition ·

The AI Act Week and the Industry’s Response to Agents and Bots

The submission of GPAI’s first risk assessment to the AI Office under the AI Act involved 24 national authorities in technical audits and set the pace for the week. Also in the spotlight were OpenAI’s pilot opening up ChatGPT to paid agents with Angi and Wayfair, and Cloudflare’s default blocking of mixed-use AI crawlers.

In this edition

  1. Strategy · High

    OpenAI Launches Paid Agents; Angi and Wayfair Pilot Program

    Labeled pilot launches first native ad channel in ChatGPT: brands operate conversational agents that continue the conversation after an ad click.

    Read full analysis
  2. Security & Risk · High

    Acronis Patches CVE-2026-87886 After Exploitation; 72h Warning

    A privilege escalation flaw in Acronis backup plugins has been exploited in limited attacks, sparking a U.S. government patch mandate.

    Read full analysis
  3. Security & Risk · High

    WSO2 API Manager: critical admin token forgery flaw

    A 9.8 CVSS flaw allows admin token forgery in WSO2 API Manager 4.1 to 4.6; watchTowr's honeypot recorded malicious traffic on September 13.

    Read full analysis
  4. Regulation · High

    AI Act: First Risk Evaluation Deadline Today

    Models exceeding 10^25 FLOPs must submit reports by today; 24 national authorities are conducting technical audits.

    Read full analysis
  5. Strategy · High

    Cloudflare Blocks Mixed Use AI Crawlers by Default

    New default policy applies to free customers and new sites: bots combining search, training, and agents are blocked on any ad-monetized page.

    Read full analysis

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.