Plans
Learn Library

AI Spends Money Now — and Causes Trouble Now

A news roundup on how AI now works, spends money, and causes trouble: model-driven security risks, chat ads and AI search visibility, agentic payments, and open versus closed model strategies, with takeaways for marketers.

ai-marketingadsgeollm-visibility
2026-09-26SupaMarketers9 min read

I have a habit: on weekend mornings, I brew a cup of tea and go through the AI news that has piled up, one item at a time.

This April's batch? I finished reading and realized my tea had gone cold, untouched.

Why?

Because I spread twenty or thirty news items across the table, stared at them for a long while, and realized they were all telling the same story:

AI is no longer just "good at chatting." It does work. It spends money. And it causes trouble.

And every one of those three things matters to you if you run a business. Let me take them one by one.

The First Thing: AI Learned to Pick Locks

Start with the one that sent a chill down my spine.

What does "a model that can pick locks" even mean?

In April of this year, Anthropic discovered that Mythos, its own preview model — not yet released to the public — showed alarming offensive capability in safety testing: it could find software vulnerabilities on its own, then exploit them, with success in more than 80% of test cases. It could even chain exploits across several systems. Flaws buried for years in mainstream operating systems, old wounds in venerable open-source projects — it dug them all up, one by one.

Keep this in mind: vulnerability hunting used to mean a hacker gnawing away inch by inch. Now it's a single model chewing through tens of thousands in one sitting.

Anthropic's response was blunt: don't ship it. Give it to only a handful of institutions. At the same time, it pulled in Amazon, Microsoft, Apple, Google, and NVIDIA to launch Project Glasswing, dedicated to testing whether this model could be turned around to play defense. Anthropic also put up $100 million in usage credits, letting participants run a health check on their own systems first.

Oh, and one more thing. OpenAI announced a similar program called Trusted Access for Cyber, likewise restricted to a small batch of trusted institutions.

Think about what this means.

The security industry's basic assumption has changed. It used to be: "Where there's a lock, someone wants a key cut" — a game of people versus people. Now, a model has had keys cut for every lock in one go, and the vendors are scrambling to lock those keys in a safe.

Then: a human picks one lock at a time — Now: a model gets 80%+ exploit success on every lock at once, prompting Project Glasswing

And here's an ironic footnote. Around the same time, Microsoft's Copilot terms of service stated, in plain words, that the tool is for entertainment purposes and you shouldn't rely on it for important decisions. On one hand, shoving AI into enterprise products as fast as it can; on the other, telling you in its legal paperwork that it's for entertainment only.

So my advice is simple: for every bit of efficiency AI gives you, you have to run your own verification.

Especially customer data and brand assets. Don't let them run around naked.

The Second Thing: AI Starts Doing the Advertising Math

Now, the money.

OpenAI laid out a very big number: advertising revenue, projected at $2.5 billion for 2026; by 2030, $100 billion a year.

How big is that? The scale of the world's leading ad platforms.

On what basis?

Because chat ads and search ads run on fundamentally different logic.

Search ads are a guess. You type "cold medicine which brand is best," and the platform guesses what you want, then slides an ad over.

Chat ads are you saying it out loud. In the conversation, the user spells out their intent, word for word. Search is guessing what you want; conversation is you telling me outright.

Search ads guess your intent from a query; chat ads hear it stated outright — OpenAI projects $2.5B ad revenue in 2026, $100B by 2030

Can the value of that ad slot possibly be the same?

Google wasn't sitting idle either. It was testing ads inside AI search, and offered one example: a retailer that switched on AI Max saw revenue climb 80%.

Eighty percent.

It's even building something called Universal Commerce Protocol, aiming to let users complete a purchase right inside the conversation. Though it also said that, for now, no ads in Gemini.

But every coin has a flip side.

As for ChatGPT's ads, I'd say hold your horses. It's true they already have several hundred advertisers and annualized revenue past $100 million. But the premium is steep, the daily ad inventory is thin, and the click performance is just so-so.

To put it plainly: the demand is real; the channel's value hasn't been proven.

My take: for high-ticket categories that require repeated deliberation — B2B, say — it's worth testing with small money. Everyone else, sit back and watch the show.

There's one more story worth pulling out on its own: brands have started buying media.

Why? Because when AI search and chatbots assemble their answers, they favor citing authoritative third parties. However polished your own website looks, the AI may not even glance at it; but if a reputable media outlet mentions you, the AI will repeat it.

So a company like HubSpot went straight out and acquired AI-focused media networks, stockpiling endorsements for itself.

The old battle was fighting for shelf space in the store. The new battle is fighting to be the name the shopping guide actually mentions.

Oh, and positioning itself is changing too. Cognitiv launched AudienceGPT: no more fencing people into rigid audience segments. Marketers describe their target audience in plain language, and it generates consumer profiles that keep updating — refreshed as often as every fifteen minutes. It looks at individuals, not groups.

The shotgun just became a missile.

The Third Thing: AI Starts Spending Money for You

The third thing, I believe, matters most for the future: agents have walked into the "spending money" stage.

Visa launched Intelligent Commerce Connect, giving AI agents payment capability: browsing, selecting, ordering — end to end. Along with it come identity verification and spending limits.

Translated: your customer list just gained an algorithm.

One step further. Cloudflare and GoDaddy did something interesting: they handed the "gatekeeping" power back to website owners. When an AI crawler comes to scrape your content, you can let it in, block it, or charge it a toll. They also pushed new standards that issue each AI agent an "ID card" — called Agent Name Service and Web Bot Auth.

See what happened? The internet's default setting changed. It used to assume every visitor was human. Now a crowd of robot guests has arrived, and website owners are starting to wonder: are these bots bringing me customers, or just freeloading?

How that toll gets collected and split — no consensus yet. But the direction is no secret.

Of course, with more robot guests come more mishaps.

This spring, just as autonomous agents were rolling out, things broke: internal company data accidentally exposed by an agent; misconfigured permissions directly causing a major outage. Anthropic even kicked the wildly popular OpenClaw out of its Claude subscriptions. Not because it wasn't good — because it was too good. Users ran automation with it, burned through the compute, and in the end had to pay for usage by the meter.

So look around: a whole ring of companies, each paving its own road.

Visa is laying the pipes for "robots that spend money." Cloudflare and GoDaddy are installing access control at "the robots' front door." Nunchuk put three locks on its Bitcoin wallets — multi-signature, spending limits, and mandatory human sign-off above thresholds — before an agent can touch the money. And the startup Poke stuffs agents into SMS and chat apps, so an ordinary person sends a single message and the AI schedules meetings and watches the inbox.

To you, the marketer, I have just one line:

Add "the algorithm" to your list of audiences to persuade.

Only when it understands you will it place the order on your customer's behalf.

The Fourth Thing: The Table Gets Reshuffled

Last, the landscape. Three news items from that moment, read together, are rather telling.

The first: Meta released the Muse Spark model, plastered across the whole family — Facebook, Instagram, WhatsApp, smart glasses. Multimodal, and able to orchestrate multiple sub-agents. At the same time it announced a hybrid open-source strategy: ordinary versions stay open; the strongest parts go behind closed doors.

The second: China's Z.ai open-sourced GLM-5.1 under the MIT license. Its selling point is long-horizon tasks: officially, it can grind on a single task for eight hours straight, thousands of tool calls without drifting off course, and on hard benchmarks like SWE-Bench Pro it beat a bunch of top Western models.

Strong.

The third: Anthropic's Claude opened read access to Microsoft 365 for all users. Email, documents, meeting notes, chat logs — all readable in one sweep. Read-only, no editing, and an enterprise admin has to approve before it's switched on.

Put these three side by side — what do you see?

Open source fights for the ecosystem; closed source defends the moat.

Open source is like the drugstore's free sample: free, everywhere, and everyone helps improve it. Closed source is like prescription drugs: locked in a drawer, yours only if you can pay. Meta and Z.ai are betting: get everyone using it first, and the ecosystem is mine. Anthropic and OpenAI are betting: the strongest model — why give it away?

Two routes. Neither is right or wrong. Each is running its own numbers.

For you, the good news is that good models keep getting cheaper. The bad news is, when everyone's cheap, your only remaining moats are creativity and understanding your customer.

Oh, one more detail. Google upgraded Vids — AI-generated video, automatic scoring, digital humans, all free — and tossed in small tools like dictation and 3D presentations for good measure. Companies like Dentsu and Later are using AI to screen influencers and predict performance; brands now dare to sign hundreds of micro-creators in one go.

In one sentence: the cost of making good content is collapsing.

From here on, the contest isn't who can make it — it's who can make it different.

Epilogue

Oh, and in April of this year, OpenAI's CEO Sam Altman published an essay laying out an economic policy checklist for the AI age: create a public wealth fund, tax automated labor, encourage a four-day work week, and make AI accessible to everyone.

Some say he's worrying over nothing. Some say he's jumping the gun on legislation.

I don't know the answer.

But having read twenty or thirty news items and picked up that stone-cold cup of tea, here's what I felt:

AI is rewriting what "business" means. The AI that works forces you to redo your security math. The AI that collects money forces you to redo your channel math. The AI that spends forces you to redo your customer math.

The bill comes due sooner or later. Those who run the numbers early pick their seat. Those who run them late just pick up the bill.

May you be one of the early ones.

Continue reading