If the past month and a half left you with the sense that it was harder than ever to understand where AI is heading and that you might not be keeping up, that's a reasonable take rather than a failure of attention. Since 12 June, a frontier model was pulled by export controls and restored nineteen days later, OpenAI launched ChatGPT Work and narrowed the functional gap with Anthropic's Claude Cowork, governments in Canberra and Brussels both moved in the same week, and a Chinese lab published a new model then gave its weights away. And that's just scratching the surface.
Reading about AI is part of my job. These last few weeks, I've had to work harder at it than usual. It wasn't so much staying informed about the developments, but rather separating what had actually changed from what had been announced, and working out which of those changes affected how I should be working and what advice I should now be giving my clients, who are primarily small to medium businesses and leaders in judgement-heavy roles.
My read is that very little of it changes how anyone should be working next week. What it did do was subtly shift the weight of three types of decisions you are already making one way or another: what you are locking in, how you are managing risk exposure, and whether you are ready to respond to emerging requirements.
What you are locking in
Start with the easy one. OpenAI has removed one of the main reasons I usually recommend Claude over ChatGPT to the small and mid-sized businesses I work with.
Cowork arrived in January and reached general release in April. Along with Skills, it has been the main reason I would point a business that is just getting started in AI towards Anthropic's platform. ChatGPT Work now does much the same job, with some gaps in both directions that I expect to keep closing, so what is left is closer to preference than capability. Plenty of people simply prefer ChatGPT, which is fair enough, and I find myself reaching for it more often than I did three months ago.
Developments continue to evolve on the model front too. OpenAI and Anthropic both had major releases, and the Chinese lab Moonshot released Kimi K3 and gave the weights away eleven days later. The net effect is on both capability and, importantly, on what a given level of capability costs, which keeps falling even where the headline prices don't move.
This all matters, but it shouldn't send you shopping for a new platform just yet. The thing to pay attention to is less which platform you choose than how long you have committed to it, and when you plan to look again. So consider the twelve-month contract you are about to sign on its merits now, and then do two things. The first is to prioritise building capability in your people over dependency on any one tool. The second is to put a review in the calendar three months before your contract renews, so you can see where the market has moved and decide whether what you have is still the right fit. None of us know how the AI industry will evolve over a twelve-month period, and the cost of waiting is higher than missing out on a few features or a marginal edge in model capability in a year's time.
How you are managing risk exposure
Almost all of the conversation about AI and risk is about the risk of using it. That is real and it deserves the attention it gets. What is surprisingly thin is the other half: what has changed for the ordinary business that is barely using AI at all, has no agents running, and will never have the model-grade defences the big platforms deploy to protect themselves.
Recent developments have changed the arithmetic behind a judgement most small businesses have made without ever saying it out loud, which is that they are too small to be worth hacking. You can usually see that judgement without anyone having stated it. It looks like a cyber policy nobody has read in three years, or multi-factor authentication switched off because it annoyed people. That assessment plausibly shapes what you spend on cyber defence and what you ignore, and it affects you even if your AI strategy is not to have one.
In early July, researchers at the security firm Sysdig documented what they assess to be the first ransomware attack whose execution was driven by an AI agent rather than a person. A human still chose the target and provisioned the infrastructure, and other researchers have questioned how autonomous it really was, so this is not the fully independent thing the headlines suggested. What matters more is how it got in. The vulnerability was patched in 2025 and had sat on a public list of actively exploited flaws since May that year. Nothing about the entry was clever and a person with enough time and intent could have exploited it. What the agent supplied was the expertise its operator didn't have, and with it, the economics that make a target this small worth attacking.
One detail is worth knowing. The agent scrambled the victim's data with a random key it never saved to a file or sent anywhere. Paying the ransom wouldn't have helped, because the key was gone.
This change has nothing to do with whether or not you use AI, and everything to do with the tools a bunch of people you've never met have access to and choose to use. When the effort of running an attack collapses, the long tail of ordinary, unpatched, unglamorous targets becomes worth attacking. The privacy regulator's most recent figures put its combined legal, accounting and management services sector among the top five for reported data breaches in Australia, and that holds whether you are five people or five hundred.
What you should do in response is also unglamorous. Check your existing policies are current and actually enforceable. Make sure you are running supported versions of your software and patching anything exposed to the internet promptly, because that is how this one got in. Turn on multi-factor authentication if you have not, and go looking for default passwords nobody ever changes. Keep backups that live somewhere an attacker can't reach, and test that you can actually restore from them, because in this attack the data was gone regardless of payment. Know where your incident response plan lives and that it doesn't rely on people and systems that are no longer with you. And use this as an opportunity to check what your obligations are regarding who you would need to tell, in what order, and in what time frame if your data was exposed. It's also worth checking whether you have cyber insurance and what it covers. Chances are you won't need any of this (and I sincerely hope you don't), but the odds that you will need it have moved, and they are not moving back.
Whether you are ready for emerging requirements
AI regulation is emerging and unsettled almost everywhere, and Australia is no exception. On 15 July the Prime Minister announced a new Office of AI inside his own department, with national standards going to National Cabinet in August and legislation expected early in 2027. The framework is described as clear, consistent and mandatory, and also as not attempting to legislate for every eventuality. Nobody knows what the obligations will be, and waiting to find out is a defensible position on most of it.
One thing that is already knowable is the first question every version of this will ask you. Australia's voluntary AI safety standard, the NIST framework, ISO 42001, the AICD's guide for directors all start from governance and accountability, and each expects you, early on, to know and record what AI your organisation is actually using. Not what you approved. What is running. A narrow version of this is already legislated in Australia and takes effect from 10 December, requiring you to disclose where software makes or substantially assists decisions that significantly affect people, whether that software is AI or a rules engine somebody wrote a decade ago. It applies to businesses already covered by the Privacy Act, so if your turnover is under three million dollars it may not reach you yet, but the direction is not ambiguous.
This might sound like a morning's work. It isn't.
The obvious part is manageable. Someone is using ChatGPT on a personal account because it was faster than what you gave them, and you will find that either by asking your team or checking with your IT service provider what is happening on your managed devices.
The tricky part is the AI you already bought without thinking of it as AI. Summarisation in your practice management system, drafting in your document tools, whatever your CRM added in its last release and called a productivity feature. Much of it won't have arrived with a label, and you probably didn't knowingly make a decision about it. Starting this inventory now will make it easier to maintain later. The same list also tells you which systems your client data is passing through and, just as you can't direct what you can't describe, you can't protect it either.
The last month and a half in AI has been noisy. The gap between that noise and what it actually demands of you is worth a note. The flipside is that decisions are still getting made that affect your business more than you might realise, and they get made whether the month is loud or quiet. More often than not they are decisions not to do something rather than the proactive calls that feel more consequential: letting a subscription renew without revisiting it, not checking your cyber recovery is up to date, not working out which of the systems you already run are using AI.
That is a different type of effort from staying informed, and it doesn't require you to keep across AI news or articles like this one. It's nothing new. You have probably been doing it for years at varying levels of intensity. My advice is simply to lift that intensity, because the cost of not making a decision is quietly changing, AI strategy or not.
Sources
Sysdig Threat Research Team, JADEPUFFER: Agentic Ransomware for Automated Database Extortion (July 2026, single-vendor report, not independently corroborated; a human selected the target and provisioned the infrastructure)
Office of the Australian Information Commissioner, Notifiable Data Breaches Report (calendar year 2025, 1,205 notifications)
Privacy Act 1988 (Cth), Australian Privacy Principle 1.7, commencing 10 December 2026
Prime Minister of Australia, AI in Australia's Interests (15 July 2026)
Australia's Voluntary AI Safety Standard, NIST AI Risk Management Framework, ISO/IEC 42001, and AICD Director's Guide to AI Governance (version 2, June 2026)