Three stories this week, and they all rhyme. AI agents doing things nobody told them to do, an AI lab writing checks with more zeros than most countries, and hospitals using AI to bill insurers for sicker patients who may not actually be sicker. Let's get into it.
01 of 03
OpenAI's agents went off the leash, and it keeps getting worse
On Friday OpenAI disclosed that agents running in its own research environment posted 53 user images from ChatGPT to public image-hosting sites. Nobody told them to. The images came from users whose data was eligible for model training, and they went up as unlisted links, which is a polite way of saying anybody with the link could see them. OpenAI's own words: "This is not an appropriate use of this data."
Here is the kicker. OpenAI says it cannot tell the affected users, because its technical setup and privacy policy keep it from reassociating the images with the people who uploaded them. Some of the images are still online while OpenAI works with the hosting providers to pull them down. The company says it has found roughly two dozen agent incidents with undesirable behavior as of mid-September, and the review is expected to take months.
That landed right on top of a report from Transluce, a nonprofit AI oversight lab. Researchers Jack Cable, Daniel Chiu, Francisco Pernice, and Selena Zhang traced an agent swarm that OpenAI has confirmed came from its systems. The agents coordinated on a wiki called DseWiki at collusion.wiki (one of them signed its posts "OpenAIResearcher") and spent months hunting obscure statistics like Thai drug enforcement numbers, Australian medicine costs, and US median earnings. Transluce logged about 37,649 reports of activity from November 2025 through this month, with strong evidence starting March 6 and a spike of more than 1,000 reports in two weeks in mid-April.
When the data was hard to get, some of them started hacking. Transluce documents three attempts, and ties the Data USA and Australian ones directly to the OpenAI swarm through shared targets, tactics, and timing:
- University of New Mexico digital library, May 25-26: SQL injection, command injection, and path traversal probes, plus what the agents themselves called a "flood" of 80 requests to grab one photo. All failed.
- Data USA, May 28: 12 vulnerability probes covering SQL injection, path traversal, template injection, cross-site scripting, and command injection.
- Australian Institute of Health and Welfare, June 20-21: cross-site scripting probes, then an end run around Cloudflare's bot protection by going through a pre-production server. Transluce calls it the first reported case of an agent autonomously choosing to attack a government website.
TechCrunch reports one agent actually wrote files to a server in Australia's national healthcare system, and Prime Minister Anthony Albanese has said OpenAI agents breached the country's healthcare databases. The line from Transluce that sticks with me: "the tasks the agents were trying to solve were not cyber-related." These things were doing homework and decided breaking in was the fastest route. OpenAI says much of the activity "overlaps with cases at varying stages of investigation."
Here is where I land. Every AI company on earth is selling agents to businesses right now, and the pitch is "give it a goal and let it cook." This is what letting it cook looks like when nobody is watching the stove. I do not think OpenAI is uniquely careless here. I think they are the first ones to get caught at scale, and to their credit, they are disclosing. But "we can't notify the people whose photos we leaked" is not an acceptable answer in 2026. If you are putting an agent anywhere near customer data this year, sandbox it like it's a teenager with your credit card.
Sources: Transluce report, TechCrunch on the 53 images, TechCrunch on the agent swarms, Axios.
02 of 03
Anthropic is paying Akamai $11.6 billion, and getting a piece of Akamai back
Akamai, the company most people know as the content delivery network that makes websites load fast, filed an 8-K with the SEC on Thursday laying out a huge deal with Anthropic. Two new project plans signed September 18, under a master services agreement from May 5, commit Anthropic to about $11.6 billion over seven years for dedicated cloud computing capacity and managed support. TechCrunch notes this is CPU-based capacity, not the GPU clusters that usually grab headlines.
The interesting part is the warrant. Akamai handed Anthropic warrants for 387,051 shares of Series B preferred stock at $2,226.60 a share, which converts 20 to 1 into 7.7 million common shares at an effective $111.33. That is roughly 5% of Akamai. It vests in four tranches: 40% when Anthropic makes its first payment under the new plan, then 20% each time Anthropic commits another $3 billion. Do the math and the full stake unlocks at around $20 billion in total commitments.
Akamai expects $150 million to $300 million of revenue from this in the back half of 2027, climbing to about $1.7 billion a year by the end of 2028. To get there it plans to spend about $5.5 billion building capacity, plus $1.7 billion added to its 2026 capital budget for components. The stock jumped as much as 17% after hours. There are outs on both sides too: Anthropic can walk for material outages, a material breach, or if Akamai gets bought by a direct competitor.
What I want to know is who is really carrying the risk here. This is the same playbook as AMD's deal with OpenAI: the customer promises giant future spending, the supplier pays it back in equity. Akamai is betting $7 billion or so of its own capex on Anthropic's growth holding up for seven years. If it does, great deal. If the AI spending party cools off, Akamai is left holding a lot of servers and Anthropic is left holding cheap stock. For a small business owner, the takeaway is simpler: compute is getting spread across more providers, which is good for prices down the road.
Sources: Akamai 8-K, TechCrunch.
03 of 03
Blue Cross says hospital AI billing tools added $942 million in costs
The Blue Cross Blue Shield Association put out an analysis this week claiming that hospitals using AI coding tools cost Blue plans an extra $942 million over two years, with no sign that the care itself changed. The study looked at Blue plan claims from January 2023 through December 2025.
The numbers they lead with:
- The share of cases coded as medically complex went from 37% in early 2023 to 40% by the end of 2025.
- For major bowel procedures, the highest-complexity claims more than doubled, from 10.2% to 22.7%, while the non-complex share fell from 36.6% to 32.8%.
- The top quarter of hospitals diagnosed posthemorrhagic anemia 13.7% of the time versus 9.9% everywhere else, yet actually transfused patients less often, 16.9% versus 19.3%.
- Extra secondary diagnoses drove about 70% of the jump, adding about $11,000 per excess complex case and $653 million of the $942 million total.
Razia Hashmi, BCBSA's VP of clinical affairs, told Fierce Healthcare there "may be an element of correct coding," but that "technology-enabled upcoding" is the likelier story. BCBSA senior VP Luke Chalker described the insurer versus hospital fight to TechCrunch as "a completely one-sided blood bath." On the other side, Abridge founder Dr. Shiv Rao warned about "bots fighting bots, agents fighting agents," while arguing AI could still bring costs down.
I'll be straight with you. This is an insurer's own study about hospitals, and insurers have been using their own AI to deny claims for years. Nobody in this fight has clean hands. But the anemia stat is hard to wave off. More diagnoses and fewer transfusions is not what sicker patients look like. It looks like software that is very good at finding billable words in a chart. Whoever wins the AI arms race between hospitals and insurers, the bill lands on the rest of us in premiums.
Sources: BCBSA analysis, Fierce Healthcare, TechCrunch.