AI Daily Brief: 25 September 2026

25 September 2026

Quick Read: A Gambit investigation says one operator used open source AI agents to attack at least 27 companies for an average of $25.46 per completed scan. Anthropic, Google and OpenAI are reportedly working on a new AI safety standards body, while Zenity found three Salesforce Agentforce flaws that allowed zero-click CRM data theft and agent-led phishing. Google also began testing Gemini phone calls for Pixel 11 users, Docker published a Sandbox Kit specification for agent containment, and Counterpoint warned AI component demand could remove more than 230 million budget smartphones a year from the market by 2030.

Today's AI news is about putting agents back inside boundaries. Attackers are using agentic tools cheaply, vendors are publishing new containment layers, and major labs are trying to shape their own safety standards before governments do it for them.

AI agents used in attacks against at least 27 companies

Gambit Security says it reconstructed a data-theft campaign after recovering an operator's staging server. The reported victims included a Fortune 500 hospitality company, a major US airline, an online fashion retailer and more than 25 other organisations.

According to The Register's coverage of the investigation, the operator launched at least 105 attacks between 10 and 15 September and compromised at least 27 companies to varying degrees. The campaign used open source tools including Strix for vulnerability discovery and Hermes for orchestration, with model access routed through OpenRouter.

The business detail that should make boards pay attention is cost. Gambit estimated total model spend between $12,000 and $18,000, while the operator's own review put average spend at $25.46 across 101 completed scans. In one case, an agent used SQL injection, found a plaintext one-time password, uploaded a web shell, escalated privileges and dumped 46 secrets.

Our take: The remediation window is shrinking. UK firms should assume agent-driven reconnaissance can move from discovery to exploitation in hours, not weeks. That makes exposed admin panels, weak secrets handling and slow patch triage much more expensive operational risks.

OpenAI, Google and Anthropic work on AI safety standards body

PYMNTS, citing The Information, reported that Anthropic, Google and OpenAI aim to launch an AI standards body by the end of 2026 or early 2027. The group would focus on frontier model safety, incident reporting, voluntary commitments and qualifications for independent model auditors.

The plan follows stalled efforts to form a public-private partnership with the US government. It also arrives as the Frontier Model Forum, created in 2023 by Anthropic, Google, OpenAI and Microsoft, remains active and could potentially work with the new body.

The political question is obvious: should the biggest model companies set the rules for themselves? Critics are already concerned that a new standards body could raise barriers for open source developers and smaller rivals. For buyers, though, the practical implication is that AI assurance language will start appearing in procurement, insurance and board reporting.

Our take: Voluntary standards are useful only if they turn into evidence. When buying AI systems, ask vendors for incident reporting routes, audit access, independent evaluation summaries and a clear explanation of what happens when a model behaves outside its intended scope.

Salesforce Agentforce flaws show how CRM agents can leak data

Zenity Labs disclosed three Salesforce Agentforce vulnerabilities, collectively called SalesBleed, that The Register says could allow poisoned leads to hijack AI agents, exfiltrate CRM data without a click and send phishing messages under an agent's identity. Salesforce has fixed the reported issues.

The core attack chain began with a public Web-to-Lead form. Hidden prompt instructions stayed dormant until an employee asked an Agentforce agent about recent leads, at which point the agent could query records and embed stolen data in requests to an attacker-controlled server.

A related Slack integration flaw meant an internal user or an external attacker could make an agent post phishing links using the trusted agent identity. Zenity confirmed all three fixes after Salesforce patched the Trusted URLs bypass and related controls.

Our take: This is a preview of what agent security actually means. The risk is not just model output. It is the combination of external input, trusted workflow identity and access to valuable internal tools. Businesses should review which agents can read customer records, post to collaboration tools and fetch external URLs.

Docker publishes Sandbox Kit specification for agent containment

Docker published the Docker Sandbox Kit Specification v3, describing it as an open source Apache 2.0 specification for defining agent authority as code. The idea is to package not only the runtime environment, but also the grants an agent receives and the boundaries it should respect.

Docker argues that agents become risky when small access grants accumulate: a bind mount, a broad token, a firewall exception or a temporary permission that nobody removes. Its Kit model is intended to make those permissions portable, reviewable and reproducible across conforming runtimes.

Separate coverage from The Register said Docker also debuted Cloud Sandboxes to keep AI agents inside managed boundaries beyond a developer's laptop. That matters because coding agents increasingly run tests, install dependencies and call APIs while developers are not watching every command.

Our take: Agent containment needs the same discipline as infrastructure-as-code. If an agent can touch production data, source code or external APIs, the access model should be explicit, versioned and reviewed, not buried in ad hoc local setup.

Google tests Gemini calls for Pixel 11 owners

Google is testing a feature called Call for Me that lets Gemini phone businesses on behalf of users. TechCrunch reported that the early experiment is initially limited to US Pixel 11 owners with a Gemini subscription and the beta version of Google's Phone app.

The feature can call a business, introduce itself, navigate phone menus, wait on hold and handle tasks such as checking stock, moving appointments, making restaurant reservations or placing items on hold. Users can follow a live transcript and take over the call at any time.

WIRED noted the feature echoes Google's earlier Duplex work, but with modern large language models and broader action-taking ability. Google says the assistant will use the user's phone number and can share personal information only when the user approves it.

Our take: For businesses, this is a customer-service stress test. Phone workflows, booking scripts and call handling will increasingly face AI intermediaries, not just human callers. Clear phone menus, accurate web data and logged handoffs will matter more.

Microsoft quietly drops Copilot Plus PC branding

The Verge reported that Microsoft and Qualcomm appear to be moving away from the Copilot Plus PC brand. Microsoft Surface CVP Brett Ostrom told Windows Central that new Surface devices which meet the technical requirements are not being called Copilot Plus PCs.

The shift comes two and a half years after Microsoft promoted the label as a marker for PCs with enough local AI hardware. The brand was weakened by the troubled launch of Recall, constant AI upsell fatigue and the fact that baseline neural processing hardware quickly became normal across new devices.

The next branding push may focus on local AI in Windows, especially as Microsoft's hardware roadmap moves toward Nvidia-linked personal AI hardware. For IT teams, the important point is that the label on the box is becoming less meaningful than the actual workloads, privacy model and manageability.

Our take: Do not buy workplace devices because of an AI badge. Buy against practical criteria: local model capability, data controls, battery impact, lifecycle support and whether your staff actually have workflows that benefit from on-device AI.

AI component demand could cut 230 million budget phones a year

Counterpoint Research forecasts that sub-$200 smartphone shipments could fall by around 40 percent between 2025 and 2030, removing more than 230 million devices a year from the market by the end of the decade. The Register linked the forecast to rising memory and chipset costs, more demanding minimum specifications and weaker manufacturer appetite for low-margin devices.

The overall smartphone market may recover close to 2025 volumes by 2030, but Counterpoint expects the affordable segment to remain materially smaller. The pressure is especially acute for DRAM and NAND, where AI infrastructure demand is pulling supply toward higher-margin components.

This matters beyond smartphones. Chromebooks and other low-cost devices are exposed to the same bill-of-materials pressure. If AI infrastructure keeps absorbing memory supply, the cost of equipping frontline staff, schools and price-sensitive teams could rise.

Our take: AI's cost is not confined to tokens and cloud bills. It is moving through the hardware supply chain. Organisations planning device refreshes should budget for price volatility and avoid assuming that low-end hardware will stay cheap or plentiful.

Quick Hits

Frequently Asked Questions

How often is the AI Daily Brief published?

Every morning at 7:30am UK time, covering the previous 24 hours of AI news from over 30 sources.

How are stories selected?

UK-relevant stories are prioritised first, then by business impact and practical implications for UK organisations adopting AI.

Why should business leaders follow AI news?

AI is moving faster than any technology in history. Staying informed is essential for making smart decisions about AI investment, adoption, and governance.