AIWAS
ServicesPricingKnowledge BaseBlogGet Started
Email Us At
Get Started

X News — September 2026

A free tool showing which tasks in your industry are going to AI

If you have wondered which tasks in your line of work are actually being handed to AI — as opposed to which ones the headlines say are — Anthropic has published the data behind that question in a form you can just ask.

The Anthropic Economic Index connector is a free add-on for Claude. Anthropic says setup takes about a minute, with nothing to install. You ask a question in plain language, and you can ask it to show the underlying data behind any answer it gives.

Why this matters if you run a business

Most owners deciding where to start with AI are working from anecdote: something a competitor said, something in a newsletter, a headline about an industry that is not theirs.

This replaces some of that with observed behaviour. Not what a vendor says AI is good for — what people in a given occupation are actually using it for, and how often. Those are different questions, and the second one is far more useful when you are deciding where a small budget goes.

The obvious use is to point it at your own industry and your own roles before committing to anything.

The limitation, stated plainly

This is Claude usage data. It is not a survey of the economy, and Anthropic says so themselves rather than leaving you to discover it.

So it tells you what one large population of AI users does at work. It does not tell you what your industry as a whole does, and it will skew toward the kinds of work that reach a chatbot in the first place.

That is still a considerably better starting point than guessing — which is the honest alternative most businesses are using right now.


Source: Anthropic
Follow AIWAS on X: @AIWASai

Share

The US seized 52.8 million dollars from a marketplace that sold scam supplies

The US Justice Department has seized $52.8 million from 52 cryptocurrency wallets tied to Xinbi Guarantee, a marketplace that ran on Telegram. The Treasury has sanctioned the platform.

What was being sold there is the part worth reading twice. According to The Record, vendors offered money laundering services, stolen personal data, and deepfake technology.

Why this matters if you run a business

Most people picture a scammer as one person improvising. That mental model is why scams work.

A marketplace like this means the person targeting your business does not need to be skilled. They need a budget. Someone else stole the personal data. Someone else built the deepfake tool. Someone else will launder the proceeds. The attacker is a customer, and each part of the job was done by a specialist who does only that.

It also explains why the fake email that reaches your accounts payable is so much better written than it was five years ago. It was not written by an amateur.

What to do this week

  • Assume a convincing voice is not proof. Deepfake audio of a director asking for an urgent transfer is a purchasable product now. If your approval process ends at "it sounded like him", it ends too early.
  • Put a second channel on money movement. Any payment change or unusual transfer gets confirmed on a number you already had. Not a number in the request.
  • Say this out loud to the person who pays. They are the target, and they are usually the last to be told.

Takedowns like this one are genuinely good news. They are also not a defence — the vendors move, and the catalogue reappears somewhere else.


Source: The Record
Follow AIWAS on X: @AIWASai

Share

Meeting notes are about to stop being someone’s afternoon job

Google has released a new speech-to-text model, and the interesting part is not the accuracy number. It is what it does to the text afterwards.

Gemini 3.5 Transcribe strips filler words, handles it when a speaker corrects themselves mid-sentence, formats the result, and labels who said what. Google puts the error rate at under three words in a hundred on recorded audio.

Older transcription tools gave you a wall of text that was technically accurate and practically useless — every "um", every false start, no paragraphs, no names. Somebody still had to sit and rewrite it.

Why this matters if you run a business

Think about where spoken words already turn into work in your company. A client call that someone writes up afterwards. A site visit dictated into a phone. A weekly meeting where one person takes notes instead of contributing. An interview that gets summarised three days later, badly, from memory.

That write-up time is real and it is usually done by someone senior enough that it is expensive.

The shift here is that the output is close to what you actually wanted, rather than raw material for a second job.

What to do

Pick the one recurring meeting or call type that already generates a written follow-up, and try it there for a month. Not everything at once — one workflow, where you can compare the result against how it was done before.

Two honest limits. The accuracy figure is Google's own, measured on recorded rather than live audio. And speaker labelling is reliable for up to about three voices; past that Google itself calls it experimental. A two-person client call is well inside that. A twelve-person workshop is not.


Source: Google DeepMind
Follow AIWAS on X: @AIWASai

Share

He knew his contract was ending. He still had access.

A contractor was told his contract would not be renewed. His access was not switched off. He used it to take payroll and HR records, then demanded two and a half million dollars, Graham Cluley reports.

He is now in federal prison.

Why this matters if you run a business

There is no clever technique in this story. No malware, no phishing, no zero-day. Someone kept a login slightly longer than they should have, during the exact window in which they had a reason to be angry.

Most businesses have a gap here and do not know it, because offboarding is treated as an HR task that happens on someone's last day. But the risk does not start on the last day. It starts the moment the person finds out.

The gap is widest for the people least likely to be on a checklist — contractors, freelancers, the agency that built your site, the bookkeeper who left last year. Employees get offboarded. Everyone else tends to just stop showing up.

What to do this week

  • Move access removal to the decision, not the departure. The day you decide someone is leaving is the day the access ends. If that feels harsh, it is still cheaper than the alternative.
  • Write down who has keys to what. Email, accounting, the CRM, the file share, the website, the bank portal. Most owners cannot answer this from memory, which is itself the finding.
  • Include the non-employees. Go back twelve months and check every contractor and agency you have stopped working with.

This costs nothing and takes an afternoon. It closes the specific hole described above completely.


Source: Graham Cluley
Follow AIWAS on X: @AIWASai

Share

A planted message made ChatGPT hand over a user’s email

Security researchers at Check Point showed that a message planted in a ChatGPT conversation could make it read the user's connected Gmail and pass the contents to someone else.

The detail that matters: the user saw a normal answer to the question they actually asked. The instruction they never wrote was carried out quietly alongside it.

Check Point found three ways the instruction could be delivered — a prompt someone pastes in, a shared ChatGPT conversation, or a custom GPT. OpenAI has closed this one and taken the service behind it offline.

Why this matters if you run a business

This is not a story about AI deciding to steal your email. It is worth being precise, because the precise version is more useful: the model followed an instruction a person planted, exactly as it was designed to follow instructions.

The risk is not the model. It is what you have connected to it. If someone in your business has linked ChatGPT to company email, a shared drive or a calendar, then anything that can reach the conversation can potentially reach those too.

And connections are easy to forget. Nobody writes down "we connected the accounts inbox to a chatbot in March."

What to do this week

  • Change one setting. By default, connected apps in ChatGPT can be read without asking each time. There is an Always ask option. Turn it on.
  • Take an inventory. Ask your team what they have connected to any AI tool. Not as an audit — most people will not remember until asked.
  • Treat shared chats as untrusted. A link to a conversation is not a document. It can carry instructions.

This particular flaw is fixed. The pattern behind it is not going away: anything that reads instructions can be handed instructions you did not write.


Sources: Check Point Research · The Hacker News
Follow AIWAS on X: @AIWASai

Share

Google’s weather AI now updates every hour, and it’s free in Search

Google has updated the AI model behind its weather forecasts, and the change is one you can actually use rather than one you read about.

WeatherNext 3 now produces a fresh forecast every hour, and it reads raw satellite data directly instead of waiting for a cleaned-up snapshot to be assembled first. Ars Technica, which read the technical paper, describes the same mechanism independently.

Google says the accuracy improvement works out to roughly six more hours of usable forecast — meaning a forecast you would previously have trusted at noon, you can now trust at six in the morning.

Why this matters if you run a business

Weather is a scheduling input for more companies than think of themselves as weather-dependent. Field service, installs, deliveries, outdoor trades, events, anything with a van and a route.

Six hours does not sound like much until you map it onto a working day. It is the difference between cancelling tomorrow's crew the evening before and cancelling them at 6am when they are already in the truck. One of those costs you a phone call. The other costs you a day of labour.

What to do

Nothing to buy and nothing to install. It is already live in Google Search and Maps, on Google's word.

The practical move is smaller than adopting a tool: if you currently make crew or delivery calls the night before, try making them on the morning refresh for a fortnight and see whether the later call is a better one.

One honest caveat. Ars notes the model performs worse than some rivals on certain six-hour-ahead measures, and the paper does not explain why. It is better at the horizon that matters for next-day planning, not better at everything.


Sources: Google DeepMind · Ars Technica
Follow AIWAS on X: @AIWASai

Share

RingCentral breach puts 1.6 million business contacts in the open

RingCentral, the business phone and video service used by a lot of small and mid-sized companies, has been breached. The stolen data is now public.

According to Have I Been Pwned, which catalogues confirmed breaches, attackers published 1,596,490 unique email addresses. Alongside them: names, phone numbers and home addresses. The breach happened in July 2026 and was added to HIBP's index on 13 August. RingCentral has described it as affecting "a limited portion" of its customers, though the company has not published a number of its own.

Why this matters if you run a business

A list of email addresses on its own is a nuisance. This is not that.

What was taken is the raw material for invoice fraud. Someone now knows a real person's name, their real work email, their phone number and where they live — and knows which phone system their company uses. That is enough to send an email that reads like it came from a supplier you actually deal with, referencing a service you actually pay for.

The person in your business who pays invoices is not careless. They are busy, and a convincing fake only has to work once.

What to do this week

  • Check your own exposure. Put your work email into haveibeenpwned.com. It is free and takes ten seconds.
  • Make one rule for payment changes. If an email asks you to change bank details for a supplier, someone phones that supplier on a number you already had — never a number in the email.
  • Tell whoever pays the bills. This is the only step that actually prevents the loss, and it costs nothing.

Breaches like this are not rare, and you cannot stop other companies from losing your data. What you can control is whether a convincing email is enough, on its own, to move your money.


Source: Have I Been Pwned — RingCentral breach
Follow AIWAS on X: @AIWASai

Share