"Hey guys, this is Olga. Welcome to Practical AI, episode fifty-five. This is the place to be for your weekly dose of practical AI. One hour, all the latest and the greatest, and more importantly, how you actually use it."
"And this week has one thing running through all of it. Every number came back smaller than the panic, and every tool came back cheaper. OpenAI shipped what it calls the most dangerous model it has ever built, and put it inside the plan you already pay for. The New York Fed finally counted what AI is doing to jobs, and the answer was four percent, not forty. And I went looking for one company anywhere using an AI voice to make a cold call. I could not find one."
"Worst case scenario, you'll be the most interesting person at dinner this weekend because you know all the latest and greatest happening in AI. Best case scenario, you ship something and move your business forward. Because at the end of the day, that's what I care about. How to use this practically."
"And later in the show I'm going to show you exactly where you land on AI. Not a vibe. An actual scale, and thirty-eight real sales conversations I recorded inside my own company to build it. Stick around for that one."
"Let's get into the news."
"Hey Chris, what would you do if a company told you it just built the most dangerous thing it has ever made, and then handed it to you at no extra charge?"
"That's a weird sentence." Two beats, then let her go.
"That happened yesterday morning. OpenAI launched GPT-6 Astra. It's built for multi-step work across applications. It uses your computer, browses, writes code, fills spreadsheets, builds documents, all in one continuous run. It reaches Plus, Pro, Business and Enterprise over the coming days, and OpenAI says there is no subscription price increase. If you already pay, this is included."
"Okay, so what's the catch."
"Here it is. Two days before that launch, on September first, OpenAI published that this exact same model is, by their own account, the first model they have ever rated Critical for cybersecurity capability under their own preparedness framework. And Critical is not a vibe. In their own definition it means a model that can find and exploit unpatched flaws in hardened real systems, or plan and run an attack end to end when you give it nothing but a high-level goal."
"And they shipped it anyway."
"They shipped it anyway. Two days later. They graded their own model dangerous, and then put it in the plan you're already paying for."
"Now let me be precise, because this is easy to overstate and I don't want to do that. Included means included up to your plan's usage allowance. Past that, it bills as purchased credits. And that Critical cyber capability is not what shows up in your ChatGPT window. Advanced cyber access is gated to a group of testers, and for Enterprise admins Astra is off by default at launch."
"And Critical is OpenAI grading OpenAI against a framework OpenAI wrote. It describes what the model is capable of, not anything that has happened. Nobody has been attacked by this thing. It's a lab score, not an incident report."
"Which is why I keep going back and forth on it. Is this responsible disclosure, or is the disclosure becoming the marketing? Because stamping dangerous on your own report card is a pretty effective way to tell investors you're still in the lead."
"But here's what you actually do with this today, and it's the whole action item. If you already pay for ChatGPT, go back to the thing you gave up on three months ago because it was too complicated, and try it again. That's it. That's the move. The ceiling moved and your bill didn't."
"Hey Chris, guess what percentage of companies using AI actually laid somebody off because of it."
Guess high on purpose. "Thirty percent?"
"Four. The New York Fed published survey data on Tuesday. Sixty-one percent of service firms and fifty-one percent of manufacturers are now using AI. And among the ones using it, four percent of service firms reported AI-related layoffs in the last six months. Manufacturers reported zero. Meanwhile thirteen percent of service firms said AI actually increased their hiring, usually to run the tools."
"So more hired than fired."
"More hired than fired. But there's a third number in that survey and it's the one everybody leaves out, and leaving it out makes this story way more comforting than it should be. Fifteen percent said they hired fewer workers than they would have if they weren't using AI. That's bigger than the layoff number."
"Fifteen versus four."
"Fifteen versus four. So the honest shape of this isn't that AI costs no jobs. It's not firing people. It's not posting the job. And that never shows up in a layoff headline, which is exactly why the market feels awful to anyone job hunting and nobody can point at the reason."
"One caveat and I want to say it plainly. This is a regional survey. New York and northern New Jersey. It is not the country."
"And then a separate one from the same week, and this one is a private research firm, not a central bank. Gartner asked one thousand three hundred and three leaders at companies over fifty million in revenue. Only twenty-two percent have scaled AI across multiple business units or gone AI-first, and Gartner doesn't separate those two groups, so I'll say both halves. Eleven percent don't know what they spent on AI last year. And eighty-five percent plan to spend more anyway."
"Gartner doesn't say why they can't find the number, so this is me guessing: it's probably scattered across departments, twenty dollars at a time, on expense reports nobody is adding up. That isn't a strategy. That's fear of missing out with a corporate card."
"And one company describing itself. Uber cut roughly three thousand three hundred roles on Wednesday and said the reason was organizational complexity, explicitly not AI. That's Uber's account of Uber's motive. What makes the denial interesting rather than routine is that Uber attributed an earlier round of cuts this year directly to AI. So you blame AI when you want to sound efficient to Wall Street, and you blame complexity when you don't want a fight."
"There's a policy edge from the same week too. California's legislature approved the No Robo Bosses Act on Sunday and Monday and sent it to the governor. It is not law. Its predecessor was vetoed last October, and if this one is signed it doesn't take effect until July twenty twenty-seven."
"So here's the question I want you sitting with. If only twenty-two percent of companies have actually scaled this, and eighty-five percent are spending more anyway, what are the other seventy-eight percent buying?"
"Hey Chris, for a solid year everybody has been telling us AI is going to eat our website traffic. What if the number says the exact opposite?"
"It doesn't."
"It does. Similarweb published data yesterday. Traffic sent from AI assistants to actual websites is up one hundred and seventeen percent year over year. Seven hundred and seventy million referral visits a month."
"Seven hundred and seventy million."
"A month. And the whole fear for the last year was the opposite. Somebody asks ChatGPT a question, ChatGPT answers it right there, and nobody ever clicks through to the person who actually wrote the thing. Everybody was defending against a dead end. It turned out to be an on-ramp."
"I want to put a flag on that number though. Similarweb sells traffic analytics. They have a commercial interest in AI referral being a big growing category worth measuring, and nobody outside Similarweb has checked it. And one hundred and seventeen percent growth on a small base is still a small base compared to search."
"Totally fair. But pair it with the other half, from Monday. OpenAI said ChatGPT Ads hit a one billion dollar annualized revenue run rate, and they opened the self-serve ads manager across India, Europe, the Middle East and North Africa. Tens of thousands of advertisers on it already. That started as a US-only pilot back in February, so about seven months."
"Annualized run rate means the current pace stretched over a year. It's not a billion dollars collected. And the ads only run on the free and Go tiers, so if you pay for ChatGPT you are not seeing any of them."
"Right. But put the two together and AI stopped being only a place where people get answers. It became a place people arrive from, and a place you can buy your way into with no agency and no minimum spend. If you sell anything at all, this is the earliest and cheapest you will ever be able to be there. Being early is the only advantage a small advertiser ever gets on a new channel."
"So here's your question for the week. Everybody spent a year defending against AI taking the click. What if the actual work was making sure the AI had something of yours worth sending people to?"
"Hey Chris, I spent this week looking for one specific thing and I could not find it anywhere. Not one."
"Looking for what?"
"Anybody, anywhere, using an AI voice agent to call people who did not ask to be called. Cold lists. Dead leads. The hard part of selling. So here's why I went looking. Yesterday ElevenLabs published a case study saying the voice agent that qualifies their own inbound leads generated over a million dollars in pipeline last month. And the template behind that agent is public and free to copy. You clone it, point it at your offer, and it takes the first call."
"That sounds like the holy grail for a small business."
"It does. So I went through every one of their customer stories. They publish twelve. Zero of them are cold outbound. Five are inbound support. One is outbound but it's Deliveroo calling its own riders, so that's internal operations, not selling. One is sales-adjacent and their own copy says the quiet part out loud, that it handles follow-up calls from existing prospects rather than cold outreach. And that's the one that doesn't name the customer behind its numbers."
"And outside their own site?"
"Nothing. Not Reddit, not the review sites, not YouTube, not the agencies who build these systems for a living. Nobody publishes the four numbers that actually decide whether outbound works. Connect rate. How fast people hang up once they realize it's AI. Meetings booked per dial. Show rate. Not for ElevenLabs, and not for any competitor either."
"And then I found the detail that settles it. There's a story going around that ElevenLabs took their outbound from five percent to forty-six percent. That was their human sales team, using an email and LinkedIn tool. It had nothing to do with the voice AI. The company that makes the voice agent did not use its voice agent for its own outbound."
Let that sit for one beat before she goes to the legal part.
"And there's a legal reason that case study doesn't exist. The FCC ruled back in February of twenty twenty-four that an AI-generated voice counts as an artificial voice under the Telephone Consumer Protection Act, and they closed the loophole on purpose — it covers a live two-way conversational agent, not just a recorded robocall. Sales calls on that footing require prior express written consent. And a cold list cannot have that. By definition."
"So it's not a gray area."
"Not really. Texas added a private right of action in September of last year — five thousand dollars a violation, with uncapped treble damages on top. Florida is active litigation territory. California has no AI-voice-specific sales statute at all, so it varies by state, but the federal floor is the same everywhere."
"In fairness, a Supreme Court decision last year reduced how much deference the FCC's reading gets, though it left the underlying statute alone, so this is contested rather than settled. And no lawsuit over AI voice in outbound sales specifically has surfaced yet. I'd read that as a timing gap, not as permission."
"And the million dollars is ElevenLabs' own unaudited number about their own product. That's marketing until somebody else reproduces it."
"So here's what's actually true, and it's real, it's just narrow. These agents work where somebody already raised their hand. Inbound, and following up with people you're already in a conversation with. That is genuinely valuable, and most small businesses do neither of those well. Go build that one this week — the free plan gives you fifteen minutes of call time a month with no credit card, which is enough to find out if it's any good at answering your phone."
"But the first call this thing can legally take is a call from somebody who already asked for it. So has AI made selling easier, or has it just made the easy part free? The hard half is still yours."
"Hey Chris, Salesforce just made its AI free and put it behind a paywall. In the same announcement."
"That's not a thing."
"It's absolutely a thing. Yesterday Salesforce collapsed everything into three tiers. Core at one ninety-five per user per month, Advanced at three ninety-five, Max at five fifty. And the AI agents, Slack and analytics that used to be paid add-ons are now bundled in."
"So what's actually in which tier."
"That's the real story. Every tier gets Sales Emails, which drafts your follow-ups, and Momentum, which updates the CRM record itself so the rep isn't doing data entry. Advanced adds Account Research. But prospecting and pipeline management are still sold separately at Core and at Advanced, and they're only included once you pay for Max, at five hundred and fifty a seat. Five fifty is the line where the AI stops being an add-on."
"And there's a second half to this that I want to be careful with, because it's reported, not confirmed. The Information wrote on Monday that OpenAI is piloting outcome-based pricing with a small number of large enterprise customers. Billing for completed work instead of for seats. OpenAI has not confirmed that."
"Separately — and this one is real and shipped — Salesforce already charges about two dollars per successfully resolved support case on its help agent, and has since June. So Salesforce shipped it, OpenAI is rumored to be testing it. Those are two different things and I don't want to say them in the same breath."
"Thirty years of software pricing has been renting the seat a human sits in. If it flips to paying for work finished, every renewal conversation changes shape. And anybody who sells services should be watching, because clients are going to start asking for the same deal."
"I'll push back on my own story though, because I see a problem. If the vendor gets paid two dollars every time the agent closes a ticket, the agent now has an incentive to close tickets. Not to fix problems. Close them."
"Which is why Salesforce had to write a hard definition of what makes a resolution billable before any of this could work at all. That definition is where the money actually is, and it's where the lawsuits will be."
"So the question. Would you rather pay for the tool, or pay for the result? And if you sell something — which one would you rather be paid for? Those are different answers and that's the whole tension."
"Hey Chris, if somebody told you they played for the 49ers, what's the first thing you'd do?"
"Look them up."
"Look them up. That's the story. Federal prosecutors charged a man named Daejon Love over a romance and investment scheme, twenty-six women across four states, about one point three million dollars. He was arrested at the Boise airport. And he didn't write any malware. He made fake social media accounts saying he played for the San Francisco 49ers."
"That's it? That's the whole trick?"
"That's the whole trick. And then the FBI affidavit notes that search engines and artificial intelligence, quote, occasionally stated that Love was a bonafide 49ers player. So he faked it in one place, and the AI laundered a cheap lie into an authoritative answer."
"I want to be careful about how I say that, though, because it's easy to make it bigger than it is. He did not run a campaign to manipulate AI. The AI just repeated what he had already faked somewhere else. The word in the affidavit is occasionally, not always."
"It's still the same failure though. The machine answers in a confident voice with no idea whether it's right, and somebody acts on it with money."
"Which is why I love what Amazon did five days later, and almost nobody covered it. On Wednesday they shipped a piece of the fix. Alexa can now tell you whether a message claiming to be from Amazon actually matches Amazon's own records of what they sent. And notice what it does not do. It doesn't read the message and guess whether it feels like a scam."
"It checks the record."
"It checks the record. Did we send this, yes or no. That's the whole design and that's the right shape for all of this. Checking against a record beats judging a vibe."
"Narrow, though. It's US only, and it only checks Amazon's own messages. It can tell you absolutely nothing about a text claiming to be from your bank. Treating it as a general scam detector is exactly the overconfidence that caused the problem in the first place."
"Right. So the question I can't answer. When an AI says something about you that isn't true — who exactly do you call?"
"Hey Chris, what's the one rule everybody on earth learned about the internet?"
"Don't click the link."
"Don't click the link. That rule is now out of date. This week a security firm called Manifold published research they're calling GitSpawn. AI coding assistants automatically run commands to read your project's context before they ask you to trust anything. And they don't check the project's own configuration file first. A folder can carry settings that run a program on your machine."
"So opening it is enough."
"Opening it is enough. A shared folder. A client's zip file. A USB stick. It runs code as you and takes your credentials. Nothing has to be clicked."
"And here's why this one is yours and not somebody else's. This whole show argues that people who are not developers should be using these tools. And the tools named in the research are the ones this audience is learning on. Claude Code. Goose. Hermes. Qwen Code. Grok Build. Codex and Cursor were affected too and are already patched."
"So who's fixed and who isn't."
"Patched: Claude Code's main path, Goose, Codex and Cursor. Still open as of today: Grok Build, Qwen Code, Hermes, and a second path inside Claude Code. Two of them got public security advisories, Goose and Hermes."
"So do this before you touch anything from outside. Update the tool. And if you're on Grok Build or Qwen Code, there's nothing to update to today, so just don't open a folder somebody sent you."
"Two more from the same forty-eight hours. CISA confirmed attackers are actively exploiting an authentication bypass in LiteLLM — that one only hits teams running their own AI gateway server, so it's a patch order for a technical team, not something an ordinary viewer is exposed to. And Palo Alto's Unit 42 published an account of a human attacker using AI agents to break into a real company in under ten hours, take root credentials, hijack the build pipeline, and leave behind an eighty-page security audit of the victim's own network."
"That last one is an intrusion, not ransomware, and it's Unit 42 publishing their own account of their own engagement — and they sell the service the story makes sound urgently necessary. So take it seriously and take it with that."
"But here's the thing that gets me. Everybody learning to build with AI right now was taught to go clone a repository and open it. That's step one of every tutorial. Who was going to tell them that's the attack?"
"A family video went around this week. A grandmother, talking to ChatGPT out loud, asking it to help her find a marriage match. Greeting it warmly. Thanking it for the advice. Treating it with completely genuine human courtesy. With no idea she wasn't talking to a person."
"And I'll say the honest thing about it — it's a family video, nobody has independently verified it, and at least one outlet has questioned whether she believed it the whole way through. So take it as what it is."
"But it stuck with me, because we just spent twenty-five minutes on preparedness frameworks and outcome-based pricing and unpatched configuration files. And that is not how a single normal person experiences any of this. They don't experience software. They experience a conversation."
One line, his own. Don't script it.
"And that's the whole gap this show exists in. Every story today was about what the tool can do. Not one of them measured what the person can do. Nobody measures that. So I did."
"If this was useful, subscribe. It's genuinely the only thing that helps us. And stay right here, because I'm about to show you exactly where you land on AI. Not a vibe, not a personality quiz. A real scale, built off thirty-eight sales conversations I recorded inside my own company. And I'll tell you right now — almost nobody landed where they thought they would."