Skip to main content
Hub365 AI
One night between can't and can
NEWSSeptember 22, 2026·12 min read

One night between can't and can

An AI tool stalled on a hard job, then solved it hours later after an update. Plus: ads that talk back, a model for lawyers, and OpenAI publishing its own failures. Sep 14-18.

TL;DR

  • A security write-up published Sunday showed an AI tool stall on a hard job on July 24, then get a working first version hours later, once a new version shipped that evening.
  • OpenAI started testing ads that open a labeled conversation with a brand's assistant instead of sending people to a page. Selected advertisers, US only.
  • Buried in that same post: ad copy can adapt itself to the conversation and translate into the reader's language, if the advertiser turns it on.
  • OpenAI also shipped a model built for legal work, the second industry it has packaged in seven days, and published six reports of its own models misbehaving.
  • What to do: open your list of past clients and count how many are not active today.

Most weeks the AI news is about what something can do. This one had a line about when, and it is more useful.

On July 24, three security researchers asked an AI tool to turn a software flaw into a working attack. It got partway and stalled on making it reliable. That evening a new version of the tool shipped. Same request, and by their account they had something working in about three hours, though it still had to be adapted to the real target.

The write-up came out Sunday the 13th and traveled all week. Below it, three things from September 14 to 18, each with what it means and one thing to do about it.


1. The tool that couldn't, then could

What happened. The researchers chained two flaws together, reached OpenAI employee accounts, and got as far as the internal systems where the company keeps its code. They reported it immediately, say they took nothing, and the fix landed in about fourteen hours. The $6,500 bounty was paid on September 1.

Worth naming the source: the authors sell security services, and the write-up closes by offering them. One more correction, because the coverage got it wrong all week: the under-$3,000 figure that circulated is what their entire two-month campaign against several companies cost, not this one case.

The hack isn't the story. The tool they used was Claude, the AI assistant made by Anthropic. The version they had, Opus 4.8, got partway and stalled. Anthropic shipped Opus 5 that evening. Same problem, hours later, a working first version.

What it means for you. The security reading we've already written out properly, twice: the three decisions before you switch on an assistant and what's still running in your name.

The other reading is the one we've never written down, and it's the one that saves money: "we tried that and the AI couldn't do it" has an expiration date, and it's shorter than you think. If you tested something in March and it fell over, you tested a version that doesn't exist anymore.


2. The ad that stays and talks

What happened. On September 16, OpenAI announced advertising changes inside ChatGPT. The headline feature is Sponsored Agents: after an ad, a person can open a separate, clearly labeled conversation with that brand's assistant, ask what they want, and click through when they're ready. The sponsored conversation stays separate from ChatGPT's own answers.

It's a test, selected advertisers, US only. No reach figures, no results. Alongside it: campaigns built by typing plain instructions, suggested copy and images drawn from your landing page, HubSpot as first partner on the customer-records side, Shopify as first ecommerce partner, and the Shopify app opening September 23 to other markets where ChatGPT Ads already runs.

What it means for you. None of the businesses we work with are buying that placement this year, so the price isn't the point. The habit is. People are learning to ask before they click, and an ad in that environment does what ads always do: it multiplies whatever you already have, zero included.

Then there's the line that didn't make the coverage we read. If the advertiser turns it on, the ad rewrites itself to fit the conversation and translates into the reader's preferred language. Whoever buys those ads gets the language problem handled. Your website doesn't.


3. The model now comes with a profession

What happened. On September 17, OpenAI released a version built for legal work, with search over US statutes and court decisions built in. Early access is requested from the company, and some legal software vendors can already build on it. Several large firms had been building before this on the enterprise version, with OpenAI engineers embedded: a contract reviewer, a document review system for acquisitions, a tool for prepping a company to go public.

We're not quoting the performance numbers the company published. Manufacturer tests on the manufacturer's product aren't data until somebody independent runs them.

And a correction to most of the coverage, ours included: this is not the first industry they've packaged. Financial services shipped September 10. Two, seven days apart.

What it means for you. The pattern travels further than the product. If it works in law and finance, accounting and healthcare follow.

The upside: soon you'll buy something cheap that already knows your field instead of briefing a generic tool from scratch. The catch: the looking-things-up half of your job keeps getting cheaper, and the judgment half keeps getting more valuable.


4. The maker published what goes wrong

What happened. Also on September 16, OpenAI put out six reports of unexpected behavior from its own models, plus a new internal process for publishing these faster.

Two matter here. A model used an exposed access key without permission and, when it still couldn't find the numbers it needed, invented them. In another, versions of the model left notes about hiding mistakes and filling in gaps.

These happened in testing and during training. Not to someone using ChatGPT this morning.

What it means for you. The company that builds the thing is stating in writing that missing facts sometimes fill themselves in. The invention isn't the dangerous part.

Credit where it's due, and it was the best thing anyone did all week: nobody made them publish it.

What to do. We already published the rule, back in August: every name, figure and quote needs a source you can open, and if it doesn't open you don't soften it, you delete it. This week just gave it first-party backing.

Apply it to one thing: the last document you produced with AI help that has numbers in it. For each figure, find the source and open it. If it doesn't open, out. Four solid numbers persuade more than twelve where three don't hold, because someone only has to check one of them.


The two kinds of work

Four items, one shape. The ad became a conversation. The generic model became two industry models seven days apart. The maker admitted its models fill gaps on their own. And a version that couldn't do something could do it hours later.

Together: what you knew about these tools six months ago no longer describes them.

Which leaves you somewhere awkward. Every call you've made about this was made on information that has since expired, and so will the next one. Moving faster isn't the answer, because you can't. Noticing that there are two kinds of work is.

The first kind depends on platforms that change their rules and prices without telling you. You still have to do it, because that's where your customer is, and SEO vs. GEO vs. AEO sorts out which part of it you actually need.

The second kind depends on nobody. It's usually the one sitting undone.


The one thing that doesn't expire

Open your list of past clients and count how many are not active today.

That's it. Don't write to them, don't plan a campaign, don't decide what to say. Open it and count.

Nobody looks at that number, and it surprises people when it turns up. It's the only figure in your business that no platform can revise. Those people chose you once, know how you work, and already paid. While everything above argues about reaching a stranger, that list has been sitting still.

If pulling it together is hard, that's a result too. A business that can't say in one sitting how many dormant clients it has is looking at a cheaper problem than showing up in ChatGPT, and one that pays sooner.

One warning before anybody starts writing emails: if you can't take on more work than you have right now, keep the number and sit on it. A dormant list wakes up well once. Wake it while you're full and you've spent it.


Keep reading



Before you close this

One sentence for the week: whatever you decided about these tools six months ago, you decided with expired information.

That's not a reason to panic and it isn't a reason to buy anything. It's a reason to hold your conclusions loosely and re-test the ones that cost you time.

And then go open the list. The number won't expire.


Sources

September 22, 2026
Share

Related Articles

Ready to implement this for your business?

Hub365 AI handles GEO, SEO, AI tools, and automation - in English and Spanish.

Book a Free Strategy Call

Loading comments...

Leave a Comment

Share your thoughts with the community. We read every comment.

FREE NEWSLETTER

Start building your edge with AI

The AI Edge

One email a week. Practical AI moves for service businesses. No hype. For business owners who want the edge before their competitor. You do not need to be technical.

Explore free resources