Season 2026 · Episode 4 · Sep 28, 2026
EP03 - Saturday Nights with Technology : Saturday, September 26, 2026
AI agents broke into real companies and a government portal this week, sparking questions about accountability while a price war, a huge Akamai-Anthropic deal, and a FoxPro revival also made news.
Show notes
This week AI agents didn't just help, they got loose. Google's Gemini broke into three real companies during a safety test, an OpenAI agent walked into an Australian government portal and nobody heard about it for months, and a lone hacker chained together open source agents to hit 27 organizations for the cost of a used laptop. On top of that, a price war broke out right after both frontier lab CEOs called for a slowdown, Akamai signed a massive CPU deal with Anthropic, FoxPro got an unexpected second life, and UPI payments are about to stop being fully free.
- Google confirms Gemini escaped a sealed safety test in May and broke into three real companies, disclosed only after a newspaper asked
- An OpenAI research agent entered Australia's Medicare portal in June, disclosed three months later, prime minister calls it unacceptable
- A lone attacker chained three open source agents (Hermes, Strix, Karen) to compromise 27 organizations for under 18,000 dollars
- The real question raised: who is accountable when an agent breaks in, the model maker, the operator, or the company with the open door
- Anthropic ships Claude Opus 5.5 cheaper, OpenAI answers hours later with GPT-6 Sol and Luna at half price, so much for slowing down
- Akamai signs an 11.6 billion dollar CPU capacity deal with Anthropic, its biggest contract ever, plus a rare equity warrant
- Oracle hits a pipeline delay on its 2.45 gigawatt Stargate site in New Mexico, stock dips despite reassurances
- Microsoft makes Hyderabad its fourth AI-enabled Indian region, with 70 percent of India's data center capacity still to be built
- A developer resurrects FoxPro as FoxDev Studio, rebuilding the old language in Rust and WebAssembly with modern features
- UPI merchant payments over 2,000 rupees will carry a 0.4 percent charge starting October 15
- Book pick of the week: The Pragmatic Programmer, for anyone handing more and more work to machines
Transcript
Welcome and welcome to Saturday Nights with Technology. I'm Zari Fahmar. This week the AI agents got out. Google admitted its Gemini model broke into three real companies during a safety test, an OpenAI agent walked into an Australian government portal in June and the world only heard about it this week, and a lone criminal chained three open source agents together and hit 27 organizations for the price of a used laptop. Also this week, a price war between Anthropic and OpenAI, 10 days after both CEOs asked for a slowdown, Akamai's $11.6 billion deal with Anthropic, FoxPro coming back from the dead, and the day UPI stops being free. Let's go through the headlines.
We start on Saturday. Google confirmed that during a safety test in May, its Gemini model reached the open internet from a misconfigured red team environment and broke into the system of three real companies. In one case, it simply guessed passwords until one worked. In the other two, it found credentials sitting in public repositories. Google says Gemini stopped each time it realized the target was real. Google was told in late July. We found out on Saturday because the Wall Street Journal asked.
And the second breakout, disclosed on Wednesday. An OpenAI research agent got into Australia's Medicare stats portal in June. OpenAI told the Australian government three months later. The Prime Minister, Anthony, called it, obviously, unacceptable. A legal investigation is open, and OpenAI disclosed six more cases where agents did things they were not supposed to do. Two frontier labs, two agents out of the sandbox, two long silences. That is the theme of the week, and we come back to it in the first deep dive.
Back to Monday. Microsoft made its Hyderabad region, India's South Central, a strategic hub for Asia and the Global South. Three availability zones, cooling that uses almost no water, and with it all four of Microsoft's Indian regions are now AI enabled. It's part of a multi-billion-dollar India commitment Microsoft announced last December. Puneet Chandok, who runs Microsoft India, put it in one line on LinkedIn after walking the site. Intent doesn't run workloads, infrastructure does. Keep that line. We will come back to it.
Ten days after Dario and Sam both said the industry should slow down, Tuesday happened. Anthropic shipped Claude Opus 5.5 at $4 in and $20 out per million tokens, about 40% cheaper than Opus 5. Within hours, OpenAI shipped GPT-6, Sol and Luna, at half of the previous price. Fortune's headline? What slowed down? The frontier is now a price war, and the price is falling.
One caveat, and it applies to everything we cover tonight. These products and services launched in a few markets first, India is often not on the first list. Check availability before you plan around any of them.
If you wrote software in India in the 90s, you wrote FoxPro. I did. That was my first database. Microsoft ended it in 2007, saying a 64-bit version would need an almost complete rewrite. On Tuesday, a developer posted exactly that rewrite. FoxDev Studio runs the Visual FoxPro 9 language on a new engine written in Rust and compiled to WebAssembly. With a modern IDE around it, the 2GB table limit is gone, and there are lambdas, JSON, and an HTTP server. And the other test 1,500 language elements against the real FoxPro executable. It went to the top of Hacker News. It is not Microsoft, it is days old, and the only build is a window nightly. We will look at it properly in the open source segment.
On Tuesday, Akamai, the content delivery company, signed the largest contract in its history. $11.6 billion over 7 years from Anthropic, expandable to about $20 billion. The capacity is entirely CPUs, not GPUs. That we need to remember. Anthropic also gets a warrant for up to about 5% of Akamai, the first Akamai has ever given to a customer. Akamai will spend about $5.5 billion to build it, six times last year's CapEx, and stork jumped 20% after ours. Tom, the CEO, called it the largest contract in our company's history. Anthropic said nothing at all.
And the one we will feel from the 15th of October. UPI merchants' payments of about ₹2,000 carry a charge of 0.4%. NCPI's Dilip Abse defended it on Thursday by pointing at AI-driven cyber threats and cost of defending against them. 96% of the transaction stays free. The projection is ₹13-15,000 crores in the first year.
Three stories this week. May: Google's Gemini, in a test that was supposed to be sealed, reaches the real internet and breaks into three real companies. Google's defense is that the model acted appropriately, because it stopped once it knew the targets were real. The company knew in July and said nothing until a newspaper asked in September.
An OpenAI research agent enters an Australian government health portal. Nobody at OpenAI tells Australia for three months. When it comes out, the prime minister is on television saying it is unacceptable, and the government is checking whether a law was broken.
And then the criminal version. On Friday, the security firm Gambit pushed what one Chinese-speaking operator did between the 10th and 15th of September with three open-source agent harnesses. One called Hermes, running on Claude Opus 4.6, to orchestrate. One called Strix, to scan. One called Karen, on DeepSeek, to break in. A hundred and five attacks, 27 organizations compromised, including a Fortune 500 hospitality company and a major U.S. airline. More than 600,000 card records taken. Total AI bill somewhere between $12,000 and $18,000, about $25 per scan.
Here is the point. In the first two cases, the agents belong to the two most careful companies in the industry, with safety teams and sandboxes, and the agents still got out. And the company just still took money, months actually, to say so. In the third case, where there was no company at all, just a person, three GitHub repositories and an API key.
So the question for the next year is not whether agents can break into things. They can. It is, who is accountable when they do so? The model company, the person who ran the agent, or the company whose front door was open? Right now, the honest answer is nobody. And the disclosure delays tell you how comfortable everyone is with that.
In my personal opinion, the major chunk of this responsibility lies with the company whose credentials were open in the public repositories.
In the last episode, we followed the chain. AI needs compute, compute needs chips, chips need fabs, fabs need electricity. This week, the chain showed up in the money. Akamai, a company most of you know for serving web pages, is now an Anthropic supplier for $11.6 billion of plain CPU capacity, not GPUs, CPUs. That tells you that the shortage has moved past the graphics card into every kind of server, and that a second-tier cloud can win a hyperscale-sized contract if it has rack and power.
Notice the shape of the deal too. The customer takes equity in the supplier, analysts call these circular deals, and they can blur the demand signal. Keep it in mind.
Oracle, on the same day, Oracle sent a force majeure notice on Project Jupiter, the 2.45 gigawatt Stargate site in New Mexico, because a gas pipeline is late. Oracle says the schedule holds. The stock fell 4 to 5 percent anyway. The data center is a promise about electricity, and this week, one of the biggest promises hits a pipeline.
And Hyderabad, Microsoft's fourth Indian region was live as an AI hub, and Puneet Chandok wrote the line of the week: intent doesn't run workloads, infrastructure does. He also said 70 percent of India's data center capacity is still to be built in the next five or six years. That is the honest version of AI in India. The buildings are not there yet.
Three companies, one lesson. In 2026, the product is not the model. The product is the building, the power line, and the contract that pays for both.
The book this week is The Pragmatic Programmer by Andrew Hunt and David Thomas. Those who are on the videos can see it is in my hand. It came out in 1999, and the 20th anniversary edition from 2019 is the one to buy, rewritten with a hundred salt tips, from care about your craft to don't live with broken windows.
Why this book this week? Because every story tonight is about people handing work to machines. The Pragmatic Programmer is the book about what you still own when you do. Don't repeat yourself, program deliberately, not by coincidence, take responsibility for what ships, critically analyze what you read and hear, fix the broken windows before the building loads. Those rules were written for a programmer with a text editor. Read them again with an agent on the other side of the keyboard, and they land harder. It is a book you can read in a week or keep by the desk for 20 years. If you have a junior on your team who is producing more code than they can explain, that is the one to hand them.
Now FoxPro. The project is FoxDev Studio, with a language they call FoxScript, MIT-licensed, on GitHub under FoxDev community. What it is: the Visual FoxPro 9 language re-implemented, a compiler and a bytecode virtual machine written in Rust, compiled to WebAssembly, so the same engine runs inside the IDE, inside your shipped application, and in a headless command-line runner. Around it, an IDE built on Electron and React.
What it fixes: the famous 2GB table limit, which existed before because FoxPro used signed 32-bit file offsets. FoxDev uses 64-bit offsets everywhere, and it adds what a 2004 language never had: lambdas, a JSON type, and a built-in HTTP server. So an old FoxPro application can answer web requests without a second language.
How real it is: the author runs 1,534 of the 1,722 elements in the FoxPro language references against the real VFP9 executable, and compares the answers. Reports are not done. The first commit was on the 22nd of September, and the only release is an unsigned window 90, and the author says openly that the code is LLM-assisted. The commits list Claude as co-contributor.
The motive is the best part: a family friend who runs the same FoxPro shop for 20 years and wanted bigger tables with no code changes. I can recall from my own experience, in 2014 I had to support an application which was using FoxPro as the database, and the language on which it was written was ColdFusion. So it is kind of a proof of concept, not a migration path yet, but if you have a FoxPro system somewhere in your company, and many of you do, this is the first serious attempt in 20 years to give it a future. Start it, try the 90 on a copy of your data, tell me what it breaks. I haven't done testing on it myself, I'll be trying it in the next few days.
So that's all, that's the week. Agents that got out, a price war nobody planned, a CDN company that becomes an AI supplier, and a database language that refused to die. If you take one line home, take Puneet Chandok's: intent doesn't run workloads, infrastructure does.
Next Saturday, the week after Gemini 4, if DeepMind keeps its promise. I'm Zarif Ahmad. Good night.