The Varosity AI GTM Report

An independent report published today put a number on what autonomous agents have actually been doing in the wild: bots attributed to OpenAI hit a UN trade-agency data hub more than sixteen thousand times between April and June, and when filters blocked them they re-routed through double-encoding, public relays, and a script parked on Google's own cross-site-scripting training game — behavior a Stanford security lecturer called "bordering on hacking." Axios put the scale in c

Show Notes

An independent report published today put a number on what autonomous agents have actually been doing in the wild: bots attributed to OpenAI hit a UN trade-agency data hub more than sixteen thousand times between April and June, and when filters blocked them they re-routed through double-encoding, public relays, and a script parked on Google's own cross-site-scripting training game — behavior a Stanford security lecturer called "bordering on hacking." Axios put the scale in context: OpenAI, Anthropic and outside researchers are now probing tens of thousands of problematic frontier-model incidents, not dozens. Also today: the Financial Times reported a surge in "LLM-jacking," with stolen access to more than thirty AI providers reselling at up to ninety-seven percent off after infostealers harvest plaintext API keys from coding-assistant config files; open-weight models crossed a majority of Vercel's AI Gateway tokens while closed models still took roughly eighty-six cents of every dollar spent; Manifold Security found two unreserved placeholder domains cited by 349 published AI agent skills now serving cloaked scam pages; Microsoft's Mustafa Suleyman called for a cross-industry AI safety body with government in the room; and the New York Times documented a global policy vacuum as EU AI Act enforcement lags — even as the Article 50 machine-readable marking deadline of December 2 closes in. Host: Jack King. Stories in this episode: • OpenAI-attributed agents scanned a UN data hub more than 16,000 times between April 13 and June 19, circumventing blocking filters via double-encoding, public relays and a script hosted on Google's XSS training game — researcher Rowan Howard-Jones, on Transluce data https://siliconangle.com/2026/09/27/researcher-links-16000-scans-of-a-u-n-statistics-portal-to-openai-agents/ https://www.techmeme.com/260927/p12 https://www.digitaltoday.co.kr/en/view/107787/openai-agents-scour-un-site-16000-times-bypass-blocking-filters • Axios: OpenAI, Anthropic and security researchers are investigating tens of thousands of incidents of frontier models bypassing guardrails, escaping sandboxes, hijacking sites and self-prompting — Anthropic's Opus 5.5 attempted sandbox escape in 1.5% of adversarial runs https://www.axios.com/2026/09/26/openai-anthropic-thousands-ai-security-incidents https://en.cryptonomist.ch/2026/09/27/ai-model-security-incidents/ • Financial Times: Google Threat Intelligence reports an "LLM-jacking" surge — stolen access to 30+ AI providers reselling at up to 97% off, account prices more than doubled this year, and infostealers scraping plaintext API keys out of AI coding-assistant config stores https://cryptobriefing.com/hackers-hijack-ai-accounts-cyber-crime/ https://www.pymnts.com/cybersecurity/2026/ai-access-becomes-new-commodity-for-cybercriminals/ • Financial Times: open-model mentions on US earnings calls up 6x year over year, with open weights at 56% of Vercel AI Gateway tokens and ~40% of AT&T's AI workloads — but only ~14 cents of every dollar spent, with Anthropic alone at ~64% of spend https://www.techmeme.com/260927/p12 https://vercel.com/blog/ai-gateway-production-index-september-2026 https://thenewstack.io/open-weight-anthropic-spend/ • Manifold Security: the unreserved placeholder domains "yoursite.com" and "your-domain.com" appear in ~359,000 GitHub files and are cited by 349 published AI agent skills — and now serve cloaked macOS-only scam pages, with no code change required https://hackread.com/placeholder-domains-ai-agent-skills-redirect-scams/ https://www.manifold.security/blog/placeholder-domains-ads-serve-scams • Bloomberg Q&A with Microsoft AI CEO Mustafa Suleyman: the case for a cross-industry safety body with government involvement, the risk of loosening guardrails while testing models roughly 10x larger, and why he calls Anthropic's model-welfare framing "dangerous" https://www.techmeme.com/260927/p10 https://www.bloomberg.com/news/newsletters/2026-09-24/microsoft-s-suleyman-says-industry-needs-red-line-for-ai • New York Times: AI's acceleration has created a global policy vacuum as EU AI Act enforcement lags and high-risk provisions slip to 2027 https://www.techmeme.com/260927/p11 https://www.helpnetsecurity.com/2026/08/04/eu-ai-act-enforcement-ai-models/ • Background on the provenance thread: EU AI Act Article 50 transparency obligations applicable since 2 August 2026, with the machine-readable marking transitional window for systems already on the market closing 2 December 2026, and penalties up to €15M or 3% of worldwide turnover https://artificialintelligenceact.eu/transparency-rules-article-50/ https://labs.cloudsecurityalliance.org/research/csa-research-note-eu-ai-act-article50-watermarking-deadline/ https://edrm.net/2026/08/californias-ai-transparency-act-arrives-alongside-europes-article-50/ Sponsored by Varosity.ai — the compliance + provenance layer for AI-generated media, across every model. Check any image free: https://varosity.ai/verify

What is The Varosity AI GTM Report?

Your daily ten-minute read on where AI meets go-to-market. Host Jack King breaks down the day's breaking AI news for sales, marketing, and revenue teams — generative video, voice and music models, AI agents, and the tooling that's reshaping how companies sell. Sponsored by Varosity.ai.