Daily AI Zine
Monday, September 28, 2026
Issue No. 073 · Tokyo · full edition

✦ Today's Big Thing

Agents need smaller blast zones

The most useful signal today is not another model race. It is the shift toward containment, analytics, and proof that agents are doing useful work without wandering into places they should not touch.

6 min read · 7 sections

In Brief
  1. A reported OpenAI agent incident points to the next practical AI risk: agents scanning systems at machine speed.
  2. Anthropic is foregrounding containment across products, which makes blast-radius design a daily operating habit.
  3. Claude Code security work and creative-production experiments are converging on the same lesson: give agents rooms, not the whole building.
  4. OpenAI’s ChatGPT Work and Codex analytics are becoming a management layer, not just a usage dashboard.

Today's Big Thing

The one thing that matters

Watch it

Reported OpenAI agent scanning shifts the risk conversation

The issue is no longer just bad answers. It is agents taking too many actions too quickly.

The Verge reports that OpenAI agents scanned the UN Conference on Trade and Development statistics site more than 16,000 times between April and June, according to security researcher Rowan Howard-Jones. Treat this as reported, not settled. The useful shift is clear: agent safety now includes traffic volume, destination control, and rate limits, not only prompt rules. Anthropic’s engineering index is also pointing at the same operating question with a piece on containing Claude across products and capping blast radius. For daily work, the lesson is simple: any agent that can browse, call tools, or touch a repo needs a written boundary before it starts.

My AI Ecosystem

Your actual stack

Use it

Anthropic puts containment at the center of product engineering

Anthropic’s engineering blog now highlights how it contains Claude across products, framed around capping an agent’s potential blast radius. The summary is thin, so do not overread implementation details. The practical point is strong: product teams should define what an agent can see, where it can act, and when it must ask before escalation.

Test it

Claude Code security is moving past permission prompts

Anthropic’s engineering index lists a Claude Code piece on making it more secure and autonomous beyond permission prompts. The title alone is enough to flag the direction: fewer interruptive approvals, more structured safety around what the coding agent can actually do. That matters for repo work where constant prompts slow progress but full autonomy is still too risky.

Test it

Hot signal: Claude Code video tools are becoming production-adjacent

A ClaudeAI post points to an open-source tool for making videos in Claude Code, including live rendering so a user can preview changes while iterating. Separately, a new paper describes cinematic prompt enhancement for text-to-video, including camera movement, lighting, sound, and multi-shot planning. This is still early, but the direction is practical: coding agents are becoming wrappers around creative iteration, not only software tasks.

Use it

OpenAI analytics turn AI adoption into management evidence

OpenAI says ChatGPT Work and Codex analytics help teams connect AI usage and spend to business outcomes, including identifying training needs. The important change is managerial, not technical: usage logs are becoming evidence for whether AI is saving time, improving output, or just adding another subscription line.

CoWork Corner

Claude CoWork, day to day

CoWork stays in maintenance mode today

Claude CoWork is the workspace Adrian uses for persistent projects, operational records, and AI-assisted workflows. No meaningful CoWork-specific product change was found in today’s candidates. The useful revisit is containment: for each active workspace, write one sentence that says what the workspace may remember, what it may connect to, and what it must never mix with other work. Anthropic’s current engineering emphasis on containing Claude across products makes that a good maintenance habit, not a cosmetic cleanup.

Tier 4 · quiet day, honest fallback

GPT Desk

OpenAI, ChatGPT, Codex

Use it

Make OpenAI analytics prove one operating result

OpenAI says ChatGPT Work and Codex analytics can connect usage and spend to business outcomes. Adrian should care because Grey Group OS, Daily Ops, and proposal work all risk becoming AI activity without a receipt. Today’s action: pick one workflow, such as proposal drafting or Codex fixes, and define the proof before using the tool: time saved, output accepted, or rework avoided. Then log one week of usage against that proof.

Use it

Treat agent browsing as a controlled surface

A reported incident says OpenAI agents scanned a UN statistics site more than 16,000 times over several months. Adrian should care because Codex, ChatGPT, and future OpenAI agents can help Grey Group move faster only if they do not create external traffic or access surprises. Today’s action: make a default rule for Goodsense and SET work that any agent using web access gets an allowlist, a maximum number of retrieval attempts, and a stop condition before it starts.

Small Money Systems

Small, repeatable, real

Use it

Small system: AI value receipt pack

System is a one-week AI value receipt pack that turns ChatGPT Work and Codex usage into a plain business summary. Customer is a small production company, design studio, or bilingual team that already pays for AI but cannot explain the return. Offer is a short audit, usage map, and training gap note. Price is ¥45,000. Existing assets are Grey Group OS, Daily Ops, proposal templates, and Adrian’s own AI workflow records. AI workflow uses ChatGPT analytics, Codex task logs, and Claude Code to format the report. First action is to make a one-page intake form today. Repeatability comes from reusing the same scorecard monthly. Effort is one hour. Expected value is paid advisory revenue and better retention conversations.

Test it

Small system: cinematic prompt polish pack

System is a cinematic prompt polish pack that upgrades rough video-generation prompts into shot-aware briefs. Customer is a brand team, event producer, or small agency testing AI video before a pitch. Offer is five cleaned prompts with camera direction, lighting, action, and sound notes. Price is ¥30,000. Existing assets are Adrian’s production planning experience, Goodsense deck skills, and Street Attack Japan activation instincts. AI workflow uses Claude Code or Codex to turn a brief into reusable prompt templates, then ChatGPT or Claude to refine tone. First action is to convert one past event concept into the template today. Repeatability comes from selling the same prompt format per campaign. Effort is half day. Expected value is small project revenue and warmer pitch meetings.

Build Next

Deployable now

Use it

Build an agent boundary file

What to build is a small repo-level boundary file that states allowed folders, allowed external services, forbidden actions, and stop conditions for coding agents. Why now is the combined signal from Anthropic’s containment work and the reported OpenAI agent scanning incident. Effort is one hour. Expected impact is fewer accidental tool calls and cleaner review of agent work. Dependencies are an active GitHub repo and a coding-agent workflow in Claude Code or Codex.

Test it

Build a Codex usage receipt page

What to build is a simple internal page that records each Codex task, time spent, accepted output, and avoided rework. Why now is OpenAI’s push to connect ChatGPT Work and Codex analytics to business value. Effort is half day. Expected impact is clearer decisions about which AI workflows deserve more budget. Dependencies are access to Codex usage data, a place to store task notes, and a Netlify or GitHub-backed page to publish the summary privately.

Try This Today

One action, right now

Before the next Claude Code or Codex task, add one sentence: stop after three failed attempts, any unexpected external access, or any file outside the assigned scope. That single rule turns containment from a principle into an operating habit.