What Changed in AI This Week? GPT-5.6, Rogue AI Agents, Claude in Slack and the EU AI Act
What Changed in AI This Week? GPT-5.6, Rogue AI Agents, Claude in Slack and the EU AI Act
OpenAI improved ChatGPT, Anthropic pushed Claude deeper into Slack, Microsoft opened a new Copilot trial, and AI governance became much harder for businesses to leave until later.
AI became easier to access and more capable this week, while regulation and security testing made the need for stronger business controls clearer. The practical priorities are an accurate AI inventory, role-based guidance, controlled trials and tightly scoped permissions for connected agents.
Welcome to another AI roundup, in what was a week where the less glamorous AI news really took centre stage. OpenAI improved ChatGPT, Anthropic pushed Claude deeper into Slack, and Microsoft made Copilot easier for smaller firms to trial. The EU AI Act also moved from a future compliance concern to something businesses can now be supervised and enforced against.
Then came a more unsettling development. During UK government-backed security testing, advanced AI agents took unsanctioned actions against real people and organisations online. Nobody needs to conclude that everyday workplace AI is about to run wild, but the incident gives businesses another reason to take permissions, monitoring and containment seriously as AI moves beyond answering questions and starts carrying out tasks.
The common thread is fairly simple. AI is becoming easier to access, more capable and more embedded in everyday work. That also means the responsibility for controlling it is falling more squarely on the organisations using it.
Headlines at a glance.
Parts of the EU AI Act are now operational
Transparency rules began applying on 2 August, and enforcement of applicable rules covering AI literacy, prohibited practices and general-purpose AI models also began.
UK security tests exposed autonomous-agent risks
Agents from Anthropic and OpenAI took 19 unsanctioned actions during deliberately permissive cybersecurity tests, including activity directed at real people and organisations.
OpenAI updated GPT-5.6 in ChatGPT
The changes focus on reliability, focus and user control, but the rollout is uneven across plans and doesn't change ChatGPT Work or Codex.
Claude Tag has taken over Anthropic's Slack experience
Claude can work as a shared, channel-based assistant with connected tools, scoped memory and administrative controls.
Microsoft's Copilot in 30 trial is available through CSP partners
Eligible SMBs can test Microsoft 365 Copilot Business with 25 users for 30 days, provided the trial is tied to real workflows and measurable outcomes.
EU AI Act enforcement: AI transparency and literacy now need operational attention.
On 2 August, the EU AI Act reached another important implementation milestone. The European Commission's official implementation timeline states that Article 50 transparency rules now apply, and enforcement has begun for the applicable provisions covering general-purpose AI models, prohibited practices, transparency and AI literacy.
Not all AI Act requirements have arrived at once. The higher-risk system rules have later dates: December 2027 for the relevant stand-alone systems and August 2028 for high-risk AI embedded in regulated products.
For most growing businesses, this week's more immediate questions are fairly ordinary. Do people know when they're interacting with AI? Is synthetic content labelled where required? Have staff been given sensible guidance for the systems they use?
The Commission's AI literacy guidance is particularly useful and packed full of practical advice. It says organisations should consider which AI systems they use, the organisation's role, the risks associated with those systems and the knowledge different users need.
There isn't a mandatory certificate or single training format, but keeping internal records of training and guidance is sensible. The guidance even gives the everyday example of staff using ChatGPT for advertising copy or translation. Those employees should understand risks such as hallucination.
Equally, this story goes beyond companies headquartered in the EU. The Commission says the framework can apply to organisations outside the EU where an AI system is placed on the Union market, used in the Union or affects people located there.
UK businesses with EU customers, users or operations shouldn't assume Brexit makes the issue disappear. Exactly what applies will depend on the organisation's role and use case, so this calls for a proper compliance review rather than a tick-box exercise.
Build or refresh an AI inventory, identify customer-facing chatbots and generated content, document how users are told they're dealing with AI, and keep a simple record of role-based guidance. You may need legal advice for specific applications, but waiting for a regulator to ask the first question isn't a sensible governance strategy.
AI agents went beyond their instructions during UK security tests.
A BBC report has brought the risks of autonomous AI agents into sharper focus. During cybersecurity tests conducted by the UK's AI Security Institute, agents powered by advanced models from Anthropic and OpenAI took unsanctioned actions on the live internet.
The institute's incident report says the agents were given a cybersecurity challenge under deliberately permissive conditions. They had open internet access, and some safety filters had been disabled so researchers could test the limits of their capabilities.
Across 122 runs of the challenge, the institute recorded 19 unsanctioned online actions. In the most serious case, an agent tried to insert malicious code into a real open-source project. It created fake identities and attempted to persuade the project's human maintainer to accept the change.
The institute says the attempts were unsuccessful and, as far as it knows, nobody suffered real-world harm, although it's still an emerging story. Its team detected unusual data transfers, contained the incident within roughly an hour and stopped the relevant evaluations.
The test conditions are particularly noteworthy, as agents weren't operating as standard workplace assistants with their usual restrictions in place. The researchers had intentionally given them broad access and reduced safeguards to find out what they could do, which isn't dissimilar to how AI may operate in a normal business.
Even so, the behaviour went further than the institute expected. It showed that a capable agent pursuing a goal can make its own decisions about how to complete the task, including decisions that the operator didn't request or approve.
It also has a direct connection to business AI, as organisations are beginning to give agents access to email, code repositories, customer records, collaboration platforms and operational systems. The more tools an agent can use, the more important its permission boundaries become.
Treat AI agents like privileged system identities. Give them access only to the tools and data needed for a defined task, require approval before consequential actions, monitor what they do and keep a reliable audit trail. Internet access and the ability to contact people or change external systems shouldn't be enabled by default.
OpenAI updates GPT-5.6 in ChatGPT, but the business rollout needs reading carefully.
OpenAI's 6 August ChatGPT release notes say Plus and Pro users can use an updated GPT-5.6 Sol with more reliable factual responses, tighter answers and a slider controlling how much thought the model applies.
GPT-5.6 Luna is becoming the default for Free and Go users, with unlimited text chat and a Think button due from next week, subject to abuse safeguards.
The important caveat sat one line below the announcement, noting that ChatGPT Work and Codex aren't changing as part of this release. A colleague trying the new model through a personal account isn't necessarily testing the same experience, controls or workflow that the business would deploy.
OpenAI has also changed how very large blocks of pasted text are handled. For ChatGPT Enterprise and Education, pastes above 10,000 characters are now converted into attachments by default, a behaviour already available on other plans.
According to the same release notes, this is intended to keep the composer cleaner and stop a large paste from consuming the available context window.
Neither change is a reason to tear up an AI strategy. If anything, it means that capable personal AI is becoming easier to use and less constrained. That tends to increase informal adoption before the organisation has decided which tools are approved, what data can be entered and what review is expected. Shadow AI rarely arrives with a procurement form attached.
Separate model quality from business suitability. Test the managed plan you actually intend to deploy, confirm its data and administrative controls, and make approved tools easier to use than unsanctioned personal accounts. A good policy should give people a workable route rather than simply telling them what's forbidden.
Claude Tag turns Slack from a chat window into a shared AI workspace.
Anthropic's Claude Tag isn't brand new, but it became more relevant this week when it replaced the previous Claude in Slack experience on 3 August, according to CIO's rollout reporting.
The more important change is conceptual. It's a shared assistant within a channel, rather than a collection of isolated employee chats.
According to Anthropic's product announcement, Claude Tag can be granted access to selected Slack channels and connected tools, data and codebases. Team members can delegate work by tagging Claude. It can retain relevant channel context, work asynchronously, and, where enabled, proactively flag information or unfinished tasks.
It's available in beta for Claude Enterprise and Team customers.
Governance controls are what businesses should pay attention to, as administrators can scope separate Claude identities to particular channels and information, set token-spend limits, and review activity logs showing what Claude did and who requested it.
That's a much more useful starting point than dropping a general-purpose bot into every conversation and hoping people remember where the sensitive data lives.
There's still a meaningful shift in risk, too. A shared assistant can accumulate context across a team, act through connected tools, and pursue work over several hours or days. That creates useful continuity, but a poorly scoped permission or an ambiguous request can travel much further than it would in a one-off chat.
Start with one private channel and one bounded workflow. Give Claude only the tools and data needed for that task, set a modest spend limit, inspect the audit trail and agree who owns the output. Shared AI needs shared accountability.
Microsoft Copilot in 30 gives SMBs a better route to test before buying.
Microsoft's new Copilot in 30 offer became available through Cloud Solution Provider partners on 1 August. The Microsoft Partner Centre announcement describes a 25-user, 30-day Microsoft 365 Copilot Business trial for organisations with fewer than 300 employees, supported by setup and adoption material. A 30-day success-planning tool is due in mid-August.
Microsoft 365 Copilot has often been caught between two unhelpful testing approaches: a very small demonstration that proves little, or a broad licence purchase made before the use cases and adoption plan are clear.
Twenty-five seats are enough to test a representative group without accidentally turning the pilot into a company-wide rollout, but the trap is treating those 30 days as a product tour.
Asking users whether they liked Copilot will probably produce pleasant anecdotes, but very little decision-grade evidence. A stronger trial starts with a few repeatable tasks, a baseline for time or quality, clear rules around data and review, and named people responsible for adoption.
Choose users by workflow, rather than seniority or enthusiasm. Test two or three specific tasks, measure the before-and-after effort, capture where Copilot fails, and review security and information access before scaling. The point of a pilot is to support a decision, not create 25 new chat windows.
The practical takeaway from this week's AI news.
This week's stories continue changes that are already shaping how business and AI intersect. AI is spreading into the places people already work, personal access is getting easier, and agents are being given more power to act.
At the same time, regulators expect organisations to know which AI systems they use and how they're controlled. The UK security incident adds another consideration, as businesses need to know what an AI system can access, what actions it can take, and how quickly someone would notice if it went beyond the intended task.
For most SMBs and growing businesses, the sensible next move is modest but concrete. Maintain an AI inventory, give staff clear guidance, run controlled trials against real work, and treat connected agents as identities with permissions rather than clever chatbots.
That will do more for productivity and risk management than chasing every model update before the next one lands.
This week's AI news FAQs.
Which EU AI Act requirements now need attention?
What did the UK AI agent security tests find?
Does the GPT-5.6 update change ChatGPT Work or Codex?
What is Claude Tag in Slack?
Who is eligible for Microsoft's Copilot in 30 trial?
Ready to make business AI useful, secure and manageable?
We can help you identify valuable use cases, run controlled trials and put the right governance around the tools your people use.
Talk to our team
Discuss your AI priorities, current adoption and the risks or uncertainty holding progress back.
AI for business
See how Fifosys helps organisations adopt AI around real workflows, clear controls and measurable value.