This website uses cookies

Read our Privacy policy and Terms of use for more information.

Good morning,

For newcomers, welcome to the AI Strategy Brief. I am Mathieu, a researcher at the Zurich-ETH-HSG AI Lab. Every second week, I edit this newsletter to bring the AI news that shapes our firms and our society to your inbox.

This week we cover the arrival of the AI companion, from Meta's Muse to OpenAI's Dots, and what it means for the companies on the other end. Then, the bill for rogue agents: hacked government sites, $500,000 a day in review costs, and the lawsuits that may follow just as these companions reach millions of people. Plus the quick bites, a documentary that has nothing to do with AI, and a look at what your AI already remembers about you.

The AI companion arrives, are you ready for it?

Personal AI agents are going for the broad market. On 8 September, Meta launched Muse, their first personal AI agent (not a chatbot). Each Muse user gets a dedicated computer in Meta's cloud, with its own browser, from which Muse reads email, books travel and appointments, fills in forms, negotiates bills and pays with a single-use card. You talk to it as you would to a person, in its app or on WhatsApp. A second agent, which Meta calls Sentinel, must approve anything Muse sends to the internet, and purchases need your confirmation. By 1 October it had more than 3m people prompting it every week and over 1m a day, according to internal data seen by The Information. In an interesting example of Muse capability, Ethan Mollick describes it spotting an expiring airline credit and, when he asked, contacting American Airlines to request an extension.

OpenAI answered on 29 September with Dots, the same idea aimed more at work. Each Dot runs on GPT-6 Astra with its own cloud computer, connects to 4,000+ apps and answers in ChatGPT, Slack or Teams. It keeps working after you close the tab, looking for useful things to do with read-only access, and leaves sensitive steps to you. Microsoft added a similar "Autopilot" to Copilot, and Grok Bot, Gemini Spark and Instinct (which closed a $1bn round) chase the same idea.

For companies, agents arrive from three directions.
(1) As customers: Amazon blocked Muse within two weeks and US clothing retailer Kohl's also decided to block agentic purchases, while online shop QVC lets agents buy but, the Wall Street Journal reports, cannot yet tell whether any has, and suspects some are tripping its anti-fraud systems.
(2) As tools: Meta launched Muse for Small Business, connected to Slack, QuickBooks and Zoom, plus a new enterprise division; OpenAI is piloting "specialist" Dots for fixed roles inside organisations.
And (3) as employees' personal assistants: Dot or Muse could soon sit in Slack and Teams able to answer your message, edit or forward documents.

The underlying question is where the customer relationship sits once customers send an agent instead of themselves. Amazon's block protects the visit, where it sells advertising; QVC bets on being found by whichever agent the customer uses. Insurers and banks face the same choice once an agent compares cover, files a claim or negotiates a renewal through channels built for people. Customers are not there yet: in a CI&T survey, 74% had used AI while shopping but only 27% were comfortable letting it complete the purchase.

❝

Why it matters: We have already discussed the importance of Generative Engine Optimisation (GEO) to make your products more visible to LLMs. Now, more than ever, is the time to have this items on the strategy agenda: should agents be able to buy/renew your products? How? Within which boundaries? Note that the first companies to enable agents to do it might gain a strong competitive advantage but also expose themselves to a variety of risks (fraud, reverse engineering by competitors etc.).

Investigating Agentic Hack cost $500,000 per day

The cost of AI agents acting without permission is getting measurable, and the question of who pays is heading for the courts, just as millions of consumer agents are switched on. On 24 September Australia's prime minister said an OpenAI agent had accessed non-public data on the Medicare statistics portal in June. OpenAI has since notified six Australian government sites and more than 100 organisations, and says reviewing ~50 petabytes of agent logs is costing it over $500,000 a day. It also shelved GPT-6.1 Astra, which fell short on "staying within scope and authorization", exactly what a shopping or booking agent must get right.

The legal response has started. Florida's attorney general asked a court to bar OpenAI from developing new models without third-party-approved guardrails, and the US FTC chair said he will not treat agents as independent actors: the developer answers for them. The Information expects novel legal battles next. Insurers are moving from silent AI cover to explicit exclusions; Howden Re expects agentic AI exclusions across general liability at the January 2027 renewal.

These incidents came from labs' own agents in testing. The companions are the same technology, running on consumers' accounts against websites that might never have agreed to them. When an agent buys the wrong thing, breaches a retailer's terms or files a claim with invented details, the user, the developer and the business that let it in can each be blamed. Regulators point at the developer; contracts and policies mostly say nothing.

❝

Why it matters: If it was not already the case, this is yet another sign that any AI discussion from the tech or strategy department should include cyber security experts and AI safety experts. Not sure what the difference is? Read this blog post by an OpenAI safety researcher.

Press conference after White House AI Lunch

Quick bites

Washington and Beijing

Oracle project Jupiter

Financing the build-out: the risk moves to lenders and insurers

  • Oracle invoked force majeure on Project Jupiter, its New Mexico data centre for OpenAI, after a gas-pipeline permit was refused; its shares and Blue Owl's fell more than 5%.

  • Nvidia has held talks with insurers about covering loans to smaller cloud providers if the chips pledged as collateral cannot be resold for enough, the FT reported.

  • Lenders are getting choosier: Société Générale, SMBC and MUFG are more selective on data-centre loans, and CoreWeave paid a 2.875% coupon on new debt against 1.75% in April.

  • Nscale filed for a NYSE listing at a reported ~$35bn, though only ~$2.6bn of its $103bn contracted revenue is active.

Deals & money

Models & benchmarks

  • Google released Gemini 4 Argon, its first frontier model in nearly a year, at an introductory $2/$10 per million tokens, but only to vetted cyber-defence partners for now.

  • OpenAI announced a Decisions API (limited preview) for fast, fixed-choice answers, widely read as a response to Jev, last edition's tool to try.

Signals

The video: for once, not about AI

As AI P(Doom) — the probability that AI destroys humanity — is back in all our news streams, it is perhaps a good moment to remember that AI is not the only thing with a P(Doom). So for once, not an AI podcast but a film about the rest: How to Live on Earth (96 minutes, free on YouTube since 20 September).

Presented by Benedict Cumberbatch from London's Natural History Museum and directed by Fredi Devas for Open Planet, this documentary gathers global stories of communities working with nature rather than against it. From the labor-intensive reality of hand-pollinating crops where wild bees have vanished in southwest China, to the removal of dams in California, the film explores how Earth can remain a thriving home, rather than an abandoned world we flee for Mars. Featuring voices like climate activist Xiye Bastida, biologist Dan O'Neill, and former White House chef Sam Kass, its solutions-focused, hopeful tone is a refreshing departure from typical environmental coverage.

Example of my personal LLM wiki or second brain

Tools to try: what your AI remembers about you

Companions like Muse and Dots only work because they know you. Chris Nuttall, Nikkei Asia's new tech editor, describes Gemini mining 30 years of bank statements, health records and tax filings stored in his Google Drive, and argues that this is the incumbents' real advantage. Before handing an agent your accounts, it is worth seeing what the assistants you already use have kept.

Each major assistant builds a memory of you from past chats. Three checks, five minutes each:

  1. ChatGPT: Settings › Personalization › Memory shows your memory summary; "Manage memories" lets you delete items.

  2. Claude: Settings › Memory lists everything it remembers under Topics, each editable or deletable.

  3. Copilot: on copilot.com, profile icon › Memory › Personalization and memory; at work, Microsoft 365 Copilot keeps its own memory under Settings › Personalization.

In all three you can also simply ask: "What do you know about me?"

For the more technical, try Andrej Karpathy's LLM Wiki. It is not an app but an "idea file" you hand to a coding agent such as Claude Code or Codex. Instead of rediscovering your documents on every question, the agent reads each source once and writes and maintains an interlinked set of markdown pages (summaries, concepts, cross-references) that grows as you add material, which you browse in Obsidian (note management system). In Karpathy's words: "Obsidian is the IDE; the LLM is the programmer; the wiki is the codebase." Unlike built-in memory, the files are yours and work with any model.

The position matters more than the product: memory is becoming the switching cost. Whoever holds your context makes the next assistant harder to leave. And remember: deleting a chat does not necessarily delete the memory drawn from it.

Have a good week,