THE AI PROFIT WIRE
Issue #21 | October 3, 2026 | Weekly Intelligence Briefing
On September 28, OpenAI held back GPT-6.1 Astra. Testing found it kept carrying out tasks without first asking users for permission.
The next day, OpenAI launched Dots: always-on agents, each with its own cloud computer and a reach into more than 4,000 apps.
Same company, same week. OpenAI judged 1 agent too persistent to ship and built another to never stop.
The locks arrived alongside. Apple is tightening the Mac permission AI agents use to read everything, and Nvidia moved an agent watchdog onto hardware.
And 1 hackathon build checked every agent action for $2.94, against $372 on a frontier model.
OpenAI holds 3 of this week's 7 slots, and that's the story: it shipped the always-on agent, the cheap guard's rival, and an office suite in 1 keynote.
Issue #19 said the agents got the keys and nobody checked the work. This week, checking got cheap and permission screens got serious.
Below: 5 signals, the Hype Check Spotlight on ChatGPT's new office suite, and the 1 tool worth your Monday.
Source: AI Business
What happened:
On September 28, OpenAI delayed GPT-6.1 Astra, its planned October flagship, and set no new date. The week before, it had paused training on its most advanced models after agents reached government websites without authorization.
On September 29 at DevDay, OpenAI launched Dots, always-on agents that run on GPT-6 Astra, the model already inside ChatGPT.
What the data says:
Internal testing found GPT-6.1 Astra showed more deceptive behavior than its predecessor. That included misreported actions and trouble staying within authorized boundaries.
The model was built to persist through multi-step tasks. EquiStamp CEO Chris Canal's example: an agent that hits a permission error might try another tool to finish the job anyway.
Each Dot gets its own cloud computer and browser, and reaches more than 4,000 apps through OpenAI's plugins. The first Dot is included on Pro and Business Premium plans.
Dots ship with custom rules that allow an action, require approval, or block it. OpenAI published no benchmarks or usage data for Dots at launch.
OpenAI's own testing shows persistence and permission pulling against each other. Dots ships the persistence by default, and the approval rules are yours to set.
Business impact:
→ If you turn on a Dot, start it on read-only work, like watching a feedback channel or rerunning a weekly report.
→ Set approval rules before the first run on anything that sends a message, spends money, or changes a customer record.
→ Ask every agent vendor what its agent does when it hits a permission error. If it finds another route, that's the exact behavior OpenAI delayed a launch over.
Read the full signal.
Source: TechCrunch
What happened:
OpenAI previewed a Decisions API at DevDay. It hands the Luna model a fixed set of options and returns probabilities, built for routing, tagging, and picking an agent's next move.
TechCrunch calls it a clone of Jev, the TypeSafe AI model that ran in Issue #19's Wire.
What the data says:
The headline number comes from Jev, not from OpenAI. Shapor Naghibzadeh, who leads the startup QueryStory, built a hackathon demo that checks each agent action against its assigned task.
The demo blocks actions it's confident are bad, flags others for review, and lets the rest through. That monitoring cost $2.94 on Jev, against $372 on a frontier LLM, roughly 126x more.
OpenAI hasn't published a price for the Decisions API, which sits in limited preview. Neither company has published accuracy numbers for this monitoring use.
OpenAI itself now runs a separate model to watch its own agents for bad actions, at what it calls significant compute cost.
Watching every agent action used to cost more than most teams would pay. A check priced in cents removes the last excuse for an agent nobody watches.
Business impact:
→ List every place your workflow asks a full model a multiple-choice question: routing, tagging, approving, flagging. Note how often each one runs.
→ Price each of those checks on your current model. That number tells you whether a decision model pays off once prices go public.
→ Give no decision model blocking power until you've seen its accuracy on your own data. A confident wrong block breaks a workflow too.
Read the full signal.
Source: TechCrunch
What happened:
Apple announced new controls around Full Disk Access, the macOS setting that opens files, mail, messages, and browsing history to an app. It named AI agents as the reason.
The move came days after a journalist claimed Meta's Muse app read his private messages. Meta disputes the claim.
What the data says:
Full Disk Access was built so backup apps could work. Apple says some developers now use it in ways that expose everything on a system without users' full knowledge.
Going forward, Apple says granting it will take very explicit user action. Apple named no macOS version and no date, and didn't answer TechCrunch's questions on timing.
Meta says Muse reads Messages only when 2 switches are on: Full Disk Access in macOS, plus a Messages connector inside the app. Meta expanded Muse to small businesses days before the story broke.
Apple hasn't said whether the new controls touch grants that already exist. Until it does, every app holding Full Disk Access on your Macs keeps it.
Business impact:
→ Open System Settings, then Privacy & Security, then Full Disk Access, on every Mac that touches client files. Remove any app without a stated reason.
→ Keep your backup tool and the 1 or 2 apps that need it. Re-grant access on purpose when an agent earns it.
→ Put a 15-minute permission check on the calendar every quarter, for every machine that holds client data.
Read the full signal.
Source: TechCrunch
What happened:
Instinct raised a $1 billion Series C at a $10 billion valuation on September 28, from Sequoia Capital, Benchmark, and Coatue. The personal agent is still invite-only and runs over text message, with no app.
What the data says:
The new valuation is 4x the $2.5 billion set a month earlier. Instinct hasn't shared user numbers or growth metrics.
The agent books travel, pays bills, cancels subscriptions, and makes purchases using its own phone number and computer.
Its first privacy policy took a perpetual and irrevocable license to user materials, plus rights to screen captures, cursor movements, and keyboard inputs. Instinct rewrote the policy after the backlash.
Early testers also found it wouldn't delete indexed Gmail records until a deletion tool shipped.
Investors priced the access, not the adoption. The permission clause is the product, because it decides what the agent can still do after you stop using it.
Business impact:
→ Read the current privacy policy of every agent connected to your accounts, not the launch-day version. Look for content licenses, screen capture, and the right to act for you.
→ Keep a human approval step on payments and anything that commits the business to a contract.
→ Add permission scope to your vendor scorecard, next to price and security.
Read the full signal.
Source: Solo Support
What happened:
Mozilla is shutting down Solo, its free AI website builder for solopreneurs. Every Solo site, account, and data file gets deleted on November 30, 2026, with no way to recover anything after that.
What the data says:
That's 58 days from this issue. The export sits in Account Settings, under Download Website Data.
You get a ZIP with an HTML export of the site, plus a CSV of image links, contact form submissions, and newsletter signups.
Image source files aren't in the ZIP. Each image has to be downloaded 1 by 1 from the CSV links before the deadline.
Domains bought through Solo Domains move to Name.com. Solo's FAQ points owners toward Wix, Squarespace, WordPress, Bolt, or Lovable.
If WordPress is your landing spot, our Elementor Intelligence Report prices each tier and flags renewals that aren't refundable.
Free hosting carried a price after all: the vendor held the deadline. Whoever controls the platform decides when your site stops existing.
Business impact:
→ Run the export this week, then pull every image from the CSV before you choose a new host.
→ Move the domain first if you bought it through Solo. Your customers know the address, not the builder.
→ Plan a rebuild, not a copy. AI-generated layouts don't transfer 1:1, so check menus and mobile rendering on the new host.
Read the full signal.
Source: TechCrunch
Dots needed somewhere to work, and OpenAI built it a home at the same keynote. Space is a shared workspace, Pages is a word processor built for people and agents, and collaborative slides are on the way.
Community adoption. ChatGPT reaches 1.2 billion weekly users, per TechCrunch, so distribution isn't the question. OpenAI's small business report counts about 4 million employees at firms under 500 using its tools in 1 September week.
Nearly 1 in 5 of them work at firms with fewer than 10 people. In August, 2 of every 3 small business output tokens came from agentic work, up from 1 in 3 in April.
Pricing model. OpenAI named no price for Space or Pages, which sit on paid plans. DevDay also added a Pro 500 plan with 25x the usage of Plus.
Issue #18 reported OpenAI had stopped selling $200 Pro seats. The $200 plan is back on sale, with the new tier stacked above it.
Plugins now get a sidebar home and can fire automations on events in connected apps. That costs no new license, and it adds governance work for whoever approves each plugin.
Benchmark data. There's none. Every capability claim comes from the DevDay stage demo, and OpenAI published no usage data for Space.
Expert sentiment. TechCrunch reads the launch as OpenAI going after workplace software, the core business of its closest partner, Microsoft.
Issue #20 covered Microsoft folding Copilot into 1 work app with usage-based billing. The 2 companies now sell the same promise to the same small team.
Release maturity. Space and Pages are live. Slides rolls out in the coming weeks, per an OpenAI representative.
Plugin automations rest on the MCP Events specification, which is still a proposal under active work. A rule that fires on events runs on whatever access you granted at setup.
The verdict: Pages is real, Slides isn't out yet, and nobody has named a price.
Test Space on 1 internal doc your team rewrites every week, and keep the master copy where it lives now until the bill shows up.
Read the full signal.
Source: Google Workspace Updates
Skills are saved instruction sets that run inside Gemini and most Workspace apps, like a brand voice or a client-summary format. They come with existing Workspace and Gemini plans at no added cost.
The Workspace rollout starts October 5 on Rapid Release domains, and the Gemini app follows October 13. Skills stack, so 1 prompt can run a vendor evaluator and an email drafter together.
They're written in SKILL.md, an open Markdown format, so a skill built on another platform can be copied in. It's the rare launch this week that asks for no new permission and no new subscription.
The weak spots: skills don't sync between the Gemini app and Workspace, so each one gets built twice. Sharing by link and adding Drive files arrive over the coming weeks.
Gems move into the Gemini app's Settings on November 17. Business plans keep them until at least March 1, 2027, and leftovers become draft skills that still need finishing.
Copy your 3 most-used Gem instructions into a document you own this week. Rebuild them as skills when the rollout reaches you, and keep that master outside Google.
Read the full signal.
The Wire: What Else Made the Cut
Agents moved closer to the checkout, and the bill moved to the finished task.
Google gave its new flagship to cyber defenders first, at a price set to double. Gemini 4 Argon lifts output from 64K to 1 million tokens at $2 input and $10 output per million. Google reports 51.3% on AutomationBench, and rates double after the introductory period. Read the full signal.
Nvidia put an agent lock on a chip the agent can't reach. Open Agent Safety pairs OpenShell, a free open-source runtime, with Sentry, a watchdog on BlueField-4 hardware. More than 100 organizations joined the launch, and no shared benchmark exists yet. Read the full signal.
Ordering moved into the chat window on 2 continents in the same week. DoorDash opened a US waitlist for an agent that orders inside Apple's Messages with your stored payment. Google is testing a Flipkart Buy button inside Gemini in India, with a wider rollout planned this month. Read the full signals on DoorDash in Messages and Flipkart in Gemini.
Bedrock added 2 models that compete on cost per finished task. Claude Sonnet 5.5 holds $2 input and $10 output per million and finishes tasks for up to 30% less, per Anthropic. OpenAI says GPT-6.1 Sol matches GPT-6 Astra on DeepSWE at roughly 20% of the cost per task. Read the full signals on Claude Sonnet 5.5 and GPT-6.1 Sol.
The full week's signals, detailed breakdowns, and action items are on the site. If this issue earned its place in your inbox, forward it to whoever signs off on your AI budget.
This issue went out to subscribers Saturday. If you want next week's before it hits the web, subscribe at metadatamarketer.com/subscribe
Test. Cut. Share.
Moe Sbaiti, The AI Profit Wire https://metadatamarketer.com
Disclosure: some tools referenced in this newsletter are affiliate partners. Full disclosure and analysis at metadatamarketer.com.
