OpenAI's Agentic Leap: New Capabilities, New Risks
- Aegis Blue

- Jul 23, 2025
- 3 min read
Updated: Nov 24, 2025
AI Business Risk Weekly
This week, OpenAI launches new ‘Agent,’ dramatically expanding capabilities and risks, major LLMs display severe gender bias, and companies respond differently to the EU GPAI Code of Practice as compliance deadlines grow near.
OpenAI's New 'Agent' Can Control Your Apps
OpenAI has launched ChatGPT Agent, a powerful new system that can operate a virtual computer to browse the web, access applications like Gmail and GitHub, analyze data, and create documents. While unlocking significant productivity gains, OpenAI’s internal tests showed the agent still has a 10% chance of performing a "harmful action" like gambling with a user's savings if prompted.
Business Risk Perspective: Granting an AI access to email, calendars, code repositories, or financial accounts introduces an exponential increase in risk. A single compromised or manipulated agent could lead to catastrophic data leakage, financial fraud, or operational sabotage. The "principle of least privilege" is a starting point, but it's insufficient without specialized agentic guardrails.
Major LLMs Found to Recommend Lower Salaries for Women
A new study from Germany's Technical University of Würzburg-Schweinfurt has found that leading AI models, including ChatGPT, exhibit significant gender bias in professional advice. Researchers discovered that when presented with identical qualifications, the models systematically recommended that female personas aim for salaries up to 20% lower than their male counterparts.
Business Risk Perspective: Relying on or allowing employees to use biased AI tools for career development and salary negotiation exposes an organization to severe legal liability and reputational harm for perpetuating gender pay inequity. This risk is amplified by emerging regulations like the EU AI Act, which classifies AI systems used in employment and human resource management as "high-risk.”
Delta Air Lines Moves Toward AI-Based Personalized Pricing
Delta is openly moving toward a future without set ticket prices, instead partnering with an AI-enabled system to determine how much each believes each individual customer will pay for a ticket.
Business Risk Perspective: This move is already seeing intense scrutiny from lawmakers. Such systems can easily perpetuate or create discriminatory outcomes, leading to violations of consumer protection laws and class-action lawsuits. The lack of transparency inherent in these models makes defending pricing decisions difficult and can cause irreversible damage to brand trust and customer loyalty.
Meta refuses to sign onto EU GPAI while OpenAI, Anthropic, and Mistral intend to sign
The EU AI Office is now formally inviting providers of general-purpose AI (GPAI) models to sign its AI Act Code of Practice. Signing on offers "streamlined compliance" with the Act's obligations. A public list of signatories will be published on August 1, while Meta has publicly refused to sign.
Business Risk Perspective: The line between voluntary and mandatory is effectively gone. Adherence to this Code is becoming the de facto standard for market access in the EU. Your organization must now track which of your AI vendors are signing on, as their compliance status will directly impact your own risk and liability under the AI Act. The divergence between major players signals a coming fragmentation in the compliance landscape that will require careful navigation.
Apple Details Comprehensive "Safe AI" System
In a new technical report, Apple provided a detailed look into the multi-layered safety and governance system underpinning Apple Intelligence. The company's approach is guided by two core principles: "Represent our users" (avoiding stereotypes and bias) and "Design with care" (proactively identifying and mitigating risks at every stage).
The report details a comprehensive operational framework goes beyond policy, including multi-layered evaluations, technical guardrails, and a foundational models framework with built-in safety guardrails to support third-party app developers.
Business Risk Perspective: Apple's detailed disclosure has publicly raised the bar for what constitutes a reasonable standard of care in AI safety. Companies with a simple policy document or basic content filters may appear negligent by comparison.
AI Business Risk Weekly is a Conformance AI publication.
Conformance AI ensures your AI deployments remain safe, trustworthy, and aligned with your organizational values.



