Stories

ChatGPT Sites passes 5 million, and the FBI counts $893 million in AI fraud

Nine in ten companies have had a Microsoft 365 permissions incident, and doctors' unassisted detection rate fell from 28.4% to 22.4% after three months with AI.

By , Senior AI ConsultantEdition of

5stories
4minute read
In This Edition

Two people can now build the same ChatGPT Site at once. OpenAI has added shared editing, private sharing with named colleagues or groups, and support for a company's own web address, three months after the feature launched. More than 5 million Sites have been built in that time.

That covers the internal jobs that used to wait for a developer or a freelancer: a shift-swap form, a client portal, a tracker for open claims. OpenAI does not register domains, so the address has to be one the business already owns, with its settings changed at the provider where it was registered.

Each Site keeps a real database behind it, and ChatGPT can now inspect what is in it. Apps built the same way elsewhere have leaked theirs. Taimur Khan, a software entrepreneur, found 16 flaws, six of them critical, in a single app hosted by the rival tool Lovable, exposing the records of more than 18,000 people.


A question typed into Copilot is answered from everything the person asking can technically open. That is not the same as everything they were meant to see.

Take a newly promoted supervisor who asks what the salary bands are for the team. Copilot searches the files, mail and chat messages that account can reach, reads the ones that look relevant, and writes back one answer with the figures in it. No folder is opened by hand, nothing is copied, and the permission that made the file reachable may have been set in 2021 by somebody who has since left.

Nine in ten companies have already had a security incident caused by a Microsoft 365 permissions mistake, a new survey found, and most are switching on assistants like Copilot before checking who can reach what. The mistakes are ordinary ones: a link set to anyone in the company, a project site left open after the project ended, a supplier's guest account never removed. They were survivable while finding a file meant knowing it existed and clicking through folders to get to it.

Cleaning that up means deciding, file by file, who should see payroll, board papers, the pricing sheet and the redundancy list, and those answers belong to the managers who own the information rather than to the team switching the assistant on. In a Gartner survey of 132 IT leaders, 40% delayed their Copilot rollout by three months or more.


Doctors who spent three months using an AI tool to spot precancerous growths during colonoscopies became worse at spotting them on their own. Their unassisted detection rate fell from 28.4% to 22.4%, counted across 1,443 procedures in the three months before the tool arrived and the three months after. The Lancet Gastroenterology & Hepatology published the study, whose authors called it the first real-world evidence of deskilling from clinical AI.

Every visible measure looked fine while it happened. The AI-assisted results were good, the doctors were experienced, and the only measure that changed was how well they did with the tool switched off, which is the measure no hospital and no employer keeps.

In an office it would be harder to see still, because much of the use is undeclared. In the KPMG and University of Melbourne global study of 48,340 people in 47 countries, 57% said they hide their use of AI at work and present its output as their own.

A manager reading an underwriting file, a drafted contract or a monthly forecast sees the finished work, and the finished work is fine. Finding the drop in the doctors took a research team and six months of counting colonoscopies.


A finance employee in the Hong Kong office of the engineering firm Arup joined a video call with the company's chief financial officer and several colleagues. Every other face and voice on the call was generated by AI. He made 15 transfers into five Hong Kong bank accounts, about $25 million, Hong Kong police said.

The FBI has now counted this kind of loss for the first time. Its 2025 Internet Crime Report added AI-related as a formal category and recorded 22,364 complaints with about $893 million in reported losses. The label covers only the cases where victims worked out what had been used against them, so the real figure is higher.

Banks answered the same problem years ago with a callback to a number held on file and a second approver on large payments, controls that do not care what a caller looks or sounds like.

The report also logged voice and video deepfakes used in online job interviews, about $13 million in losses. In those cases the FBI says the goal is usually access to the employer's network, and the person hired is given a login to it.


Running a single AI model is now the exception. In an a16z survey of company technology chiefs, 37% said they use five or more models in everyday work, up from 29% a year earlier, and in a Dataiku and Harris Poll survey of 600 technology chiefs, 81% expect to depend on two or more providers during 2026.

Companies that far along are building routing systems that send each request to a chosen model automatically, and writing down who is accountable when a model answers badly. A recent survey found that most firms running several models still have no tested plan for the day one of them stops answering.


THE DAILY BRIEF

Get the next edition in your inbox.

A five-minute read, every weekday morning.

Free forever · Unsubscribe anytime

Share This Brief

Other Editions

Newest first


THE DAILY BRIEF

Read the next one first.

A five-minute read, every weekday morning.

Free forever · Unsubscribe anytime