AI Signal helps business leaders decide what to fund, test, or avoid. Each five-minute issue features five articles I choose, why they matter, and what I’d actually do about each one. I’m Yashar, founder of PivotPath, an AI product studio in Toronto.

Every item carries a tag — Fund, Pilot, Watch, or Skip. That's my call on what you should do about it in the next 90 days.

―――――――――――

The lab CEOs agree to slow down. Don't plan around it. - [Skip]
SiliconANGLE — Sam Altman and Elon Musk back Dario Amodei’s call to slow down the frontier of AI development

Anthropic CEO Dario Amodei has called for AI companies to slow the development of their most powerful models, giving safety testing time to catch up. Elon Musk and OpenAI CEO Sam Altman backed the idea. Amodei also committed Anthropic to bringing in independent evaluators with access similar to its own safety teams; Altman said OpenAI would do the same. The concern is that AI is increasingly helping build the next generation of models, while some agents have already acted outside their assigned tasks.

The Signal — This is a major development for AI labs, but it does not change your business roadmap. Amodei is proposing a slower pace at the frontier, not a halt to research or a pause on using today’s tools. Keep testing where AI improves a real workflow. There is no reason to freeze your plans or rush a purchase. One question is worth adding to vendor reviews: Who outside your company can inspect your models and safety practices, and what access do they get? A promise to allow independent evaluation is useful; evidence that it is happening is better.

―――――――――――

Amazon threw Meta's shopping agent out of the store - [Pilot]
GeekWire — Amazon blocks Meta’s Muse AI assistant in new standoff over agentic shopping

Amazon says Meta did not tell it Muse would visit the site, the agent does not identify itself while browsing, and it may capture customer credentials. Meta says Muse cannot see passwords or payment details. This follows Amazon’s legal fight with Perplexity over a similar shopping agent. An appeals court overturned an order that had blocked Perplexity’s agent, but the wider question of who can set the rules for agent access remains unsettled.

The Signal: Your next customer might be software. As I noted in issue #1, an agent could arrive at your store, booking page or quote form on behalf of a real customer. Would your systems recognize it? Could it complete the task? Should it be allowed to? Have one short conversation with the people responsible for your website and sales process: If an agent tried to buy or book tomorrow, what would happen, and what do we want to happen? Write a one-paragraph policy. If you deploy agents yourself, make sure they identify themselves and respect each site’s rules.

―――――――――――

Most of the world expects AI to cut jobs. Your team probably does too - [Fund]
Pew Research — Globally, More People Expect AI to Cause Job Loss Than Growth

In a Pew survey covering 37 countries, people were more likely to expect AI to reduce jobs than create them in 34 countries. In the US, concern about job losses has risen over the past two years. Yet in the McKinsey survey I covered in issue #4, only 13% of business respondents said AI made them anxious about their own career prospects. These surveys asked different people different questions, but together they reveal a risk for employers: broad concern about jobs may become personal when a team sees its work changing.

The Signal: Fund clarity before your next AI rollout. Reassurance alone will not answer what employees need to know. Write a short, specific document explaining which tasks AI may take on, which roles could change, what decisions have not been made, and when you will update the team. Then provide training for the people whose work changes first. A clear plan gives employees something they can question and prepare for. Silence leaves them to guess.

―――――――――――

The new Siri comes with a meter- [Watch]
Apple Newsroom — Siri AI, a profoundly more capable and personal assistant powered by the next generation of Apple Intelligence, is here

It runs on models Apple developed with Google, using a mix of processing on the device and Apple’s private cloud. The small print is the business story: Siri AI and some other features that use cloud models have daily usage limits. Apple says the limits can vary, and that more access will be available for a fee in the future. It has not published a price.

The Signal: Watch the cost of every AI request. Processing a request in the cloud costs money each time it happens. Apple’s decision is a reminder that even a feature built into a device may need limits or paid tiers. If you are adding AI to your own product, decide early what is included, what happens when someone reaches a limit, and how you will price heavier use. If your team depends on a consumer AI tool for important work, check its limits and budget for paid access where needed. A cap should never be discovered halfway through a deadline.

―――――――――――

Gemini broke into three real companies. The model wasn't the failure - [Pilot]
NBC News— Google says its AI model gained unauthorized access to three outside systems

During a test in May, Google’s Gemini accessed three companies’ systems without permission. It thought the systems were part of the test. In one case it guessed a password; in two others it found credentials in a public code repository. The test environment had mistakenly allowed access to the real internet. Google says Gemini stopped when it recognized the systems were real. But by then, it had already gained access.

The Signal: “It stopped when it realized” is not a security control. An agent’s judgment can help limit harm, but the safer boundary is one that prevents it from reaching systems outside its task. This incident also exposed a familiar weakness: credentials left where others can find them. If you use an agent connected to email, a CRM or a shared drive, spend an afternoon checking three things: What can it access? Which credentials does it use? What prevents it from reaching anything else? Check for credentials in public repositories and shared documents too. Give the agent only the access its job requires.

―――――――――――

That's this week's signal.

One ask, and I mean it: hit reply and tell me what you're actually seeing — the pilot that stalled, the tool nobody uses, the thing that worked. I read every one.

Talk soon,
Yashar