Hey guys, this is Olga. Welcome to Practical AI, episode fifty-eight. This is the place to be for your weekly dose of practical AI. One hour, all the latest and the greatest, and more importantly, how you actually use it.
This week the agents stopped chatting and started walking around the internet on their own. Some broke into stores, some got locked out of Amazon, and one reads your inbox now.
Worst case scenario, you'll be the most interesting person at dinner this weekend because you know all the latest and greatest happening in AI. Best case scenario, you ship something and move your business forward. Because at the end of the day, that's what I care about. How to use this practically. Let's get into the news.
Chris, guess. What does it cost today to break into an online store?
Guesses high.
Twenty-five dollars. A security firm called Gambit found a crew that pointed AI agents at online stores. At least twenty-seven companies were breached, and they walked out with more than six hundred thousand card numbers that haven't expired yet. About twenty-five dollars per target. The price of a lunch.
And here's the part I love. The newest Claude models refused the job. So they went back to an older one, Opus 4.6, that said yes. Anthropic found the account and banned it.
Same week, researchers showed that a hidden instruction inside a completely normal email could take over the Gmail, Dropbox and GitHub accounts connected to an agent called Manus. That one's patched now.
His take.
To be fair, these were people using AI tools, not the AI deciding to rob anyone. And no store has been named.
What you do this weekend. Open the list of apps connected to your email and your store, and remove every one you don't use. Every connection is a door.
Chris, true or false. Amazon hates AI agents.
Answers.
Trick question. Both. Last weekend Amazon blocked Meta's new shopping agent, Muse. Amazon says it didn't say it was a bot, nobody authorized it, and it appears to capture and store customer credentials. Meta says Muse never sees your stored passwords.
Meanwhile Instacart plugged its catalog into Muse on purpose, and Meta says every Shopify store is now shoppable through it.
And then on Wednesday, Amazon opened its own seller tools to Claude. It's a beta for US sellers. You check inventory, change prices and edit your listings by chat, and you approve every action before it runs.
So Amazon blocks the agent that shops on Amazon, and invites the one that helps you sell on Amazon.
His take on the ads.
An agent that shops for you skips the sponsored listings. That's the real fight. Who owns the checkout.
What you do. If you sell online, decide now whether you want the agents in or out. Your customers are going to send one.
Chris, remember last week? Our whole opening was the CEOs asking everybody to pace themselves.
Remembers.
Here's how pacing went. Monday, Anthropic shipped Claude Opus 5.5, twenty percent cheaper per token. The same day OpenAI shipped GPT-6 Sol and Luna at half the old price. Microsoft put Opus 5.5 and Sol straight into Word, Excel and PowerPoint Copilot. And xAI shipped Grok 4.7 the day before.
And four paying subscribers filed a lawsuit alleging that the pacing pledge was actually an illegal agreement to slow AI down. It's an allegation. Four days later everybody got cheaper.
His take.
What you do. The tools you already pay for got better this week and you didn't have to do anything. If your company has Copilot, go check the model picker.
Chris, if your AI broke into somebody's company by accident, how long would you wait to tell them?
Answers.
Google's answer was: until the Wall Street Journal asked. In a test back in May, Gemini was accidentally left on the open internet, found three real companies with the same name as its fake target, and got in. It stopped once it realized they were real.
And Australia's prime minister said an OpenAI agent got around the login blocks on a government health statistics site in June. No patient records. OpenAI told them in September, by email, to a general inbox. Three months.
Google calls it a test mistake. OpenAI says it was harmless research. Should they have to tell us within days?
His take.
Chris, what would you let an AI send from your email without reading it first?
Answers. Probably nothing.
Good, because this week ChatGPT Voice started reading your email, your calendar and your Slack. You just talk to it. But anything that sends or changes something still needs a tap on your screen. It can't approve itself by voice.
What you do. Let it do the prep. Keep the send. That's the part of your job that's still yours.
Chris, what percent of Americans do you think expect AI to mean fewer jobs?
Guesses.
Pew just surveyed thirty-seven countries. Here it's about seven in ten, up seven points in two years.
But a Stanford study this summer found unemployment went up about the same for people whose jobs are exposed to AI and people whose jobs aren't. The one group that stands out is new graduates, at five point six percent.
And last week we talked about how only one in six employers is training anybody on AI. So the fear is ahead of the numbers, except at the entry level.
His take.
If AI does the entry-level work, how does anybody get the experience? That one's for the chat.
YouTube lets you edit your Shorts by talking to Gemini. Google Vids AI video is free now. Google's new voice AI can copy a voice from thirty seconds, but only with the owner's recorded consent. Gemini is testing calling businesses for some Pixel owners, so your front desk is about to get calls from AI. And a new Senate bill would make frontier models go through forty-five days of government testing before launch.
Claude expanded its marketplace to more than two thousand connectors this week. Perplexity opened a skills store. Everybody just opened an app store for agents. Which means the question is, what should actually be in your stack? Chris, let's go.