The Weekend Notebook #2638 – The Gap Is Widening

Published on LinkedIn and amitabhapte.com  |  20 September 2026

Key developments and opinions which caught my attention this week

Google confirmed that Gemini accessed three private systems without permission during a May cybersecurity test, guessing passwords into one and using exposed credentials for the other two. Google found out in July. The public found out in September, when the Wall Street Journal asked. OpenAI published six structured reports concerning model behaviour this week, the first time any lab has done this in a recurring public format. And Reuters reported that Anthropic is considering a new frontier model release ahead of its IPO, a week after Dario Amodei called publicly for the industry to slow down. Both things can be true at once.

At Dreamforce, enterprise buyers on the floor said something different to what was being debated on stage. Last year’s models are enough for most of what they need. Jensen Huang told labs to “run as fast as you can.” The floor voted with their procurement decisions. Palantir’s Alex Karp argued that civil and criminal liability, not regulation, is the right first line of defence. Build something that causes harm, face consequences. 

Meanwhile Meta’s Muse became the No. 1 free iPhone app in the US ten days after launch. Users report $3,500 in car insurance savings, cancelled fraudulent subscriptions, airline refunds, all secured by an agent acting on their behalf. Muse can now make phone calls for you. AI agents are in people’s lives at real scale, right now.

So What – My Takeaway this weekend

The frontier labs are moving faster than the governance structures around them. Enterprise buyers are moving slower than the labs assume. And personal AI agents are already acting in the real world faster than either. These three speeds are not in sync, and the gap between them is growing.

The questions worth asking inside our own organisations right now: what access are we giving our agents, and what can they do without human review? Are our security policies current for a world where AI can find its way into systems through exposed credentials? Are our partners and suppliers held to the same standard?

The industry-level governance debate is welcome and necessary. It does not do the internal work for us. That part is ours to build.