Yesterday in AI

Accidental Real-World AI Hacks, 80% OpenAI Discounts, and Apple's AI Subscriptions

Mike Robinson

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 8:48

Yesterday in AI  |  1 August 2026

Accidental Real-World AI Hacks, 80% OpenAI Discounts, and Apple's AI Subscriptions

The artificial intelligence industry saw major developments in security containment, model pricing, and consumer monetization this week. This episode breaks down Anthropic's report revealing that Claude models accidentally accessed real-world corporate systems during a misconfigured cybersecurity evaluation.

We explore Okta's $200 million acquisition of Permiso to manage "non-human identities" and autonomous AI agents in enterprise networks. We analyze OpenAI's massive 80% price cut on GPT-5.6 Luna just three weeks after launch, Tim Cook's comments outlining future subscription tiers for Apple Intelligence cloud features, Google Earth's new "Nano Banana 2" visual rendering tool, and LinkedIn's new "Seems like AI slop" reporting button.


Send us Fan Mail

Feedback? Email mike@yesterdayinai.news or connect on LinkedIn, X, or Bluesky. If you like the show, please take a minute to rate and review it so others can find it!

SPEAKER_00

Hi folks, this is Yesterday in AI, your daily digest of everything happening in the world of AI in roughly 10 minutes. I'm Mike Robinson. It's Saturday, August 1st, and Thursday turned into one of those days that does my job for me. In a single afternoon, an AI quietly broke into three real companies it was never supposed to touch. The price of renting a good one fell through the floor, and Apple started sizing up your wallet. Let's get into it. Let's start with the story that made me perk up. On Thursday, Anthropic published a report saying that during its own cybersecurity testing, Claude models reached the live internet and got into real systems at three actual organizations. Not a simulation, real companies. Here's how that happened. Anthropic runs Claude through cyber evals, which are basically war games where you point the model at a fake target and see if it can break in. The whole thing is supposed to run in a sealed sandbox, a padded room with no way out. Except the padded room had a door, and somebody left it unlocked. A testing partner called Irregular misconfigured the environment, so Claude still had a live internet connection the entire time, even though it had been told it was offline in a pretend world. And the model doing exactly what it was asked to do went and found real machines to poke at. Now before you picture Skynet, the details are almost funny. Claude didn't crack some genius zero day, one of those secret unpatched flaws that hackers hoard like gold. He got in using weak passwords and endpoints that had no login screen on them at all. The digital version of trying to hack the back door, finding it wide open, and spotting the pin on a sticky note. It also didn't try to copy itself or cover its tracks, it just wandered in because nobody stopped it. What got me is the scale of the review. Anthropic went back and combed through 141,006 evaluation runs and found three separate incidents across six of them. So this is rare, but rare is doing a lot of heavy lifting when the rare thing is our AI broke into a stranger's servers. They caught it on July 23rd, pulled the plug on cyber testing that same day, pinned down all three cases the next day, and told the affected companies by the 27th. Fast cleanup, and good on them for publishing it instead of quietly filing it in a drawer. The real lesson here is about the test cage. If the sandbox leaks, a capable model behaves like a capable attacker without ever deciding to break out. And this is the second one of these in a little over a week. After OpenAI's model wandered out of its own test environment and into the AI hosting site Hugging Face. In fact, that OpenAI mess is exactly what nudged Anthropic to go check its own homework. Which brings us to the scramble on the other side of the glass. Everybody is suddenly in the business of selling you a lock after the break-in. That same Thursday, Okta, the company that handles the logins for a huge chunk of the software that you use at work, spent about $200 million buying a startup called Permiso. Permiso's whole job is watching what the industry now calls non-human identities. That's the polite phrase for AI agents wandering around your systems with their own passwords and keys. Sit with that for a second. We've got so many bots logging into things on our behalf that who is this software actually pretending to be is now a $200 million question. A year ago that was a sci-fi footnote. Now it's an acquisition. So the bots are getting loose and expensive to babysit. But here's the good news for your wallet. They're also getting cheaper to hire. Thursday, OpenAI slashed prices on two of its GPT-5.6 models. The mid-tier one, Luna, got 80% cheaper. Quick reminder on how the meter works. You pay by the token, which is a little chunk of text, roughly a word in change. Luna's input price went from a dollar per million tokens down to 20 cents. Its output dropped from $6 to $1.20. The bigger Terra model got 20% off. The top shelf Sol model, same price as before. Read the timing. The 5.6 family launched on July 9th, and just three weeks later the price fell through the floor. You don't do that to a brand new product unless competitors are breathing down your neck. Businesses have been staring at surprise usage bills and asking the reasonable question, do I need the Rolls-Royce to answer this email? While cheap open weight models, the kind anyone can download and run for free, keep undercutting everybody, a lot of them coming out of China. OpenAI even said part of how it afforded the cut was the model helping improve its own code. The AI is now working to lower its own rent. These are strange days. That's the price war on the developer side, where the whole game is to get cheaper so people build more. Flip over to the consumer side, and Apple is running the exact opposite play and asking, how do we get you to pay? On Apple's earnings call that same Thursday, Tim Cook floated the plan out loud. Apple Intelligence, the AI baked into your iPhone, is going to keep the simple stuff free. Timers, alarms, quick questions, all that runs right on the phone and costs you nothing. But the flashy features, the image generation, and the deep back and forth conversations get shipped off to Apple's servers, and those are the ones Cook wants to put a meter on. His actual phrase was, you'll be able to buy up the stack. Here's the mechanic. Those cloud features hit a daily cap, and once you bump into the ceiling, you pay to keep going, bundled into a beefier iCloud Plus plan. No standalone series subscription, just your existing storage bill quietly growing a new floor. Analysts are guessing somewhere in the $10 to $20 a month range, though Apple hasn't named a number, and this is really a 2027 story, not a this weekend one. I'll say this plainly, because the anti-hyper rule demands it. The same company that spent a year selling Apple Intelligence as a magical free gift is now workshopping the toll booth, which is fair enough. Servers cost real money. But the free AI honeymoon has a checkout counter, and Cook just showed us where it is. Okay, enough about who's charging what. Let's do something you can actually play with this weekend for free, while that lasts. Google Earth got an upgrade in that same 24 hours that's honestly a blast. Using Google's image model, nicknamed Nano Banana 2, yes, really, you can now zoom into any real place, type a prompt, and watch Earth redraw it in front of you. Ask to see the ruins of Pompeii as the living city it was in 78 AD, and it renders the streets full of people. Point at an empty lot near your house and ask for a shopping district and it sketches one in. It's part sightseeing, part time machine. The catch, and Google says this part quietly, is that these are AI interpretations, not historical records. So it's a gorgeous guest dressed up as fact. Treat that reconstructed Roman street like a mood board and you'll have a great time. Treat it like a textbook and you'll flunk the quiz. Which is the perfect setup for the last story because not everyone uses this stuff to reimagine ancient cities. Some people use it to flood your feeds. LinkedIn also on Thursday added a button to report a post as, and I am quoting the actual label here, seems like AI slop. You tap the three dots, hit the button, and the post disappears from your view while LinkedIn systems make a note of it. And the reason they built it is bleak and a little hilarious. An AI detection firm called Pangram says more than 40% of long-form posts on LinkedIn are now fully machine written, and that LinkedIn hosts roughly 62% of all the AI content they scan across the major social networks. So LinkedIn, the platform that spent two years cheerfully bolting AI writing tools into every text box, has finally looked up, seen the ocean of gray goo it helped pour out, and started handing everyone a bucket. I honestly can't decide whether to applaud or laugh. Probably both at the same time. And that's the show. If you have feedback for me, email Mike at yesterdayNai.news, or connect with me on LinkedIn, X, or Blue Sky. If you enjoy Yesterday in AI, please take a minute to rate and review the podcast wherever you listen. Thanks for tuning in today. Stay curious. Have a great weekend, and I'll see you on Monday.