top of page
logooption6.png

Major Model Release Cascade, Deepfake Infiltration, and ChatGPT Privacy Controversy

  • Writer: Aegis Blue
    Aegis Blue
  • Aug 6, 2025
  • 3 min read

Updated: Nov 24, 2025

AI Business Risk Weekly



This week: new models from OpenAI, Google, and Anthropic bring unprecedented AI capabilities and enterprise-grade tools available on local hardware, the EU clarifies compliance guidelines, ChatGPT users discover sensitive conversations indexed by Google, and North Korean operatives successfully use AI-generated deepfakes to infiltrate hundreds of companies.

Major Model Releases from OpenAI, Google, and Anthropic


This week saw three near-simultaneous model releases from frontier labs. Google launched Gemini 2.5 Deep Think, a multi-agent reasoning system achieving gold-medal performance on mathematical olympiad problems. Anthropic released Claude Opus 4.1, likely the most powerful coding model in the world. Most surprisingly, OpenAI released its first open-weight models since GPT-2, gpt-oss-120b and gpt-oss-20b, offering enterprise-grade reasoning comparable to o4-mini that runs on local hardware. GPT-5 is expected to launch this month, with Anthropic also teasing "substantially larger improvements" in the coming weeks.


Business Risk Perspective: The rapid release of multiple frontier models creates immediate pressure on organizations to reassess their AI vendor strategies. With enterprise-grade models now capable of running on local infrastructure, companies face new decisions around data sovereignty versus cloud-based capability trade-offs, while the rapid pace of advancement may render current safety protocols obsolete.


ChatGPT Sparks Controversy as Google Indexes Sensitive Conversations


Controversy erupted online when users discovered that ChatGPT conversations they had made shareable via link, and opted to make public, were being indexed by Google, surprising many who didn't realize the full implications of these settings. Uncovered conversations included sensitive chats where people were seeking legal advice, raising immediate privacy concerns. While both link sharing and search indexing were opt-in features, the discovery sparked widespread alarm about unintended exposure, prompting OpenAI to quietly remove the search indexing option.


Business Risk Perspective: This incident illustrates how layered sharing features can create unexpected data exposure vectors, even when opt-in, particularly when employees discuss confidential matters without fully understanding the privacy implications. Organizations relying on AI tools must ensure employees understand that convenience features may inadvertently compromise sensitive information.


EU Confirms GPAI Code of Practice as Path to AI Act Compliance


The European Commission and AI Board confirmed that the General-Purpose AI Code of Practice serves as an adequate voluntary tool for GPAI model providers to demonstrate compliance with the AI Act. This independent framework provides the first official pathway for organizations to meet the EU's comprehensive AI regulatory requirements.


Business Risk Perspective: For companies operating in Europe, this confirmation provides much-needed clarity on compliance pathways but also sets a concrete standard that will likely influence global AI governance expectations.


North Korean Operatives Use AI and Deepfakes to Infiltrate Companies


CrowdStrike reports that North Korean IT workers are leveraging generative AI to craft convincing resumes and deepfake technology to alter their appearances during video interviews, successfully infiltrating hundreds of companies. These operatives, working to fund North Korea's sanctioned nuclear program, have exploited remote work norms to gain access to corporate systems.


Business Risk Perspective: While this case involves state actors, it illustrates the broader threat of AI-powered identity fraud in remote hiring that any bad actor could exploit. The sophistication of deepfake technology and AI-generated credentials represents an escalating risk that traditional background checks and video interviews may no longer adequately address, requiring companies to implement more robust identity verification protocols.


Perplexity Accused of Disguising AI Web Crawlers to Evade Scraping Restrictions


Cloudflare alleges that AI search engine Perplexity has been concealing its web crawlers by disguising them as standard browsers to bypass restrictions explicitly put in place to block AI website scraping. Cloudflare demonstrated this by creating a test site with robots.txt blocking Perplexity's crawler, and showing the company still retrieved the content, prompting CEO Matthew Prince to condemn the behavior as unethical.


Business Risk Perspective: This controversy highlights the murky legal territory around AI data collection practices and the reputational risks of aggressive scraping tactics that may violate website terms. Companies deploying AI agents must carefully consider whether their automated systems respect content restrictions.


Anthropic Develops "Persona Vectors" to Prevent AI Misbehavior


Anthropic published research on "persona vectors,"neural network patterns that can identify and steer models away from undesirable behaviors like sycophancy, evil responses, or hallucinations. The technique works by comparing activation patterns between opposing behaviors, essentially creating "vaccines for LLMs" by teaching models to avoid problematic personas during training.


Business Risk Perspective: This breakthrough offers a potential technical solution to some of AI's most persistent alignment problems, though implementation complexity may limit immediate practical application. Organizations should monitor these developments closely.



AI Business Risk Weekly is a Conformance AI publication.  


Conformance AI ensures your AI deployments remain safe, trustworthy, and aligned with your organizational values.

 
 

AI Business Risk: Emerging AI risks, regulatory shifts, and strategic insights for business leaders.

bottom of page