Chat becomes a storefront, agents accelerate, and regulators align
- Zsolt Tanko

- Oct 8, 2025
- 4 min read
Updated: Nov 24, 2025
AI Business Risk Weekly
OpenAI folded an app layer, instant checkout, and point-and-build agents into ChatGPT, while Sora’s surge showed how quickly synthetic media risk can spread. Beyond launches, twenty data protection authorities set shared expectations on AI data governance, and new U.S. bills aim liability at both developers and deployers. The week’s viral Deloitte AI workslop incident is a cautionary tale not to be missed.
A Big Week for OpenAI
OpenAI packed a lot into one week: apps now run inside ChatGPT, shopping can finish in the chat, agents are faster to ship, and Sora is exploding in the wild. Here are the highlights and why they matter.
1) Apps and Instant Checkout come to ChatGPT
Full, interactive apps from Canva, Zillow, Coursera, and more now live inside ChatGPT, with OpenAI opening the platform to app builders and hinting at monetization for creators. In the same wave, the new Instant Checkout lets people buy directly in the conversation, and the open-sourced Agentic Commerce Protocol gives stores a way to plug in catalogs and payments without leaving the thread.
Business Risk Perspective:
AI shopping is becoming all the more seamless with discovery, decision, and payment now living in one thread. That means OpenAI’s opaque recommendation rankings now carry greater weight than ever before. Watch the development of this space closely, and think twice before allowing ChatGPT to become your one-stop shop.
2) AgentKit puts agent building on rails
OpenAI’s new AgentKit allows teams to build working agents in as little as two hours. The kit bundles no-code essentials: a visual Agent Builder for multi-step flows and versioning, a Connector Registry for files and SaaS, ChatKit to drop an agentic chat layer into products, and Evals 2.0 to measure quality with datasets and automated grading.
Business Risk Perspective: Lowering the build barrier raises the stakes on behavior in the wild: agents will touch real files, real customers, and third-party systems quickly. Evals are no place to take shortcuts. While built-in evals may seem helpful, but they’re not a substitute for customized testing suites: platform defaults will miss policy nuances and local edge cases.
3) Sora jumps to No. 1, deepfakes spread, and rights controls pivot after backlash
Sora, OpenAI’s new video creation app with accompanying social feed shot to the top of Apple’s U.S. App Store within a day of launch, and convincing Sam Altman deepfakes circulated in the social feed right away. The app launched with an opt-out policy, making copyrighted materials fair game for AI videos by default. But, after a fast backlash, OpenAI pulled back and announced that Sora’s policy will switch to granular opt-in controls and revenue sharing options for rights-holders.
Business Risk Perspective: High-fidelity deepfakes inside a viral feed compress the response window from hours to minutes, with obvious impersonation, securities, and reputational angles. The pivot from opt-out to opt-in shows where the center of gravity is moving on IP rights, and that’s a good sign for businesses.
20 data protection authorities issue a joint statement on AI data governance
Twenty data protection authorities across Europe, North America, and Asia–Pacific jointly endorsed a framework for “trustworthy data governance” at the Global Privacy Assembly in Seoul, calling for privacy-by-design AI, clearer lawful bases for training data, proportionate safeguards, and sandboxes to reduce legal uncertainty. This level of cross-jurisdiction coordination is rare, a sign that regulators are converging on common expectations for AI data use.
Business Risk Perspective: When 20 authorities align, data protection audit questions start sounding the same— about provenance, minimization, and retention. Treat training-data legal bases and DPIAs as first-class artifacts.
Bipartisan U.S. bills target AI incident reporting and developer/deployer liability
Two new Senate proposals move on different fronts. The Artificial Intelligence Risk Evaluation Act would set up a DOE program for adversarial testing and incident data, applying to “advanced AI systems” and their developers (or those who “substantially modify” them), defined by a high compute threshold; it bars deployment of such systems in commerce absent participation, pointing squarely at frontier-scale model makers and significant fine-tuners, not typical chatbot integrators.
The AI LEAD Act would create a federal cause of action that explicitly reaches both developers and deployers (defined as anyone using/operating an AI product for personal, commercial, or third-party use), enabling suits over harms like defamation or psychological injury.
Business Risk Perspective: If LEAD passes, exposure won’t stop at the labs. Deployers of LLM features and chatbots would sit in the liability chain, not just foundation-model providers. Product-liability logic means documentation, warnings, and incident records become as strategic as features.
Deloitte to refund AU$440k after AI-generated errors in a government report
The episode went viral as a high-profile case of AI “workslop”: a Deloitte report on Australia’s welfare IT contained fake citations and even a fabricated court quote, prompting a refund and a credibility headache; the firm later disclosed Azure OpenAI (GPT-4o) was used in drafting. An unmissable cautionary tale for enterprise AI rollouts.
Business Risk Perspective: Generative “speed” without source-checking turns into reputational drag, fast. People, process, and tools matter in equal measure: train teams, gate outputs with guardrails, and insist on reference tracing before anything with a logo hits a client’s desk.
AI Business Risk Weekly is a Conformance AI publication.
Conformance AI ensures your AI deployments remain safe, trustworthy, and aligned with your organizational values.



