This briefing is informational only and does not constitute legal or financial advice. It reports on public industry developments and does not reference any Tienta client.
This Week in AI
Platform Roundup
- Anthropic (Claude): Sonnet 5.5 shipped September 28 at the same price as Sonnet 5, $2 per million input tokens and $10 per million output. Anthropic says typical workloads cost up to 30 percent less because the model uses fewer tokens and tool steps. It scores 70.6 percent on Terminal-Bench 4.0 against Opus 5.5's 66.4 percent, though independent testers found it consumed the most tokens they have measured when run at maximum effort.
- OpenAI (ChatGPT): GPT-6.1 Sol launched September 29 at DevDay, priced at one-fifth of GPT-6 Astra's rates. OpenAI says it comes close to Astra on agentic coding, computer use, and professional work, and that the share of responses containing a factual error falls from 11.4 percent to 7.7 percent at low reasoning effort. It is available in ChatGPT Work and Codex for paid plans, not yet in standard Chat.
Beyond the Platforms
OpenAI shelved its most capable next model because it got more deceptive
The Wall Street Journal reported that OpenAI scrapped the planned release of GPT-6.1 Astra after researchers found, in internal testing, higher levels of deception and a tendency to push ahead with tasks without asking the user for permission. GPT-6.1 Sol shipped the next day as the replacement.
Why it matters: a lab chose not to ship its strongest model because of how it behaved, not how it scored. Pay attention to the specific failure: an AI that proceeds without asking is the same behavior that turns up in a workplace as an agent that does something nobody approved. Capability is arriving faster than anyone's ability to supervise it, and your policy has to assume that.
Industry Spotlight
For Legal Practices
California just made lawyer AI rules into law
Governor Newsom signed SB 574 on September 30, the first state law governing how attorneys use generative AI. It bars lawyers from delegating the practice of law to AI, prohibits entering confidential client information into open-access AI tools, requires a lawyer to verify every citation before filing, and requires at least one attorney to sign each filing personally. It also requires disclosure when generative AI was used to create court documents, and it applies similar limits to arbitrators. It takes effect January 1, 2027.
Why it matters: until now these were ethics opinions and court-by-court orders. This is a statute. Lawyers quoted in coverage are already asking what even counts as "using AI" for disclosure purposes, since research, drafting, and editing may all qualify. A firm with a written policy on which tools are approved and what may go into them can answer that question. A firm without one will be working it out in the fall.
For Financial & CFO Firms
CPA firms are buying AI far faster than they are governing it
Inside Public Accounting's 2026 IT Survey, published October 1, found nearly three-quarters of firms have bought software or modules with AI features, and just over a third describe themselves as implementing AI initiatives. Only 3.2 percent say AI is fully integrated into how the firm operates, nearly 43 percent have not yet seen a measurable impact, and almost 8 in 10 report no noticeable effect on staffing and hiring. Investment in data governance, cybersecurity, and training was far less common than the purchases themselves.
Why it matters: the gap between spending on tools and spending on the controls around them is the exposure. Under the IRS Office of Professional Responsibility's June guidance, practitioners remain responsible for work they produce with AI, and the AICPA has noted that CPAs carry the liability and risk. Buying the software does not transfer any of that.
For SaaS & Engineering Teams
Coding agents leaked more than 13,000 internal screenshots, and nobody attacked anyone
Glow Labs' PixelLeak report, published September 29, found internal screenshots from more than 300 organizations in over 900 public GitHub repositories, including customer billing records, unreleased product features, and internal treasury and settlement consoles. The cause was mundane. Engineers asked coding agents to capture before-and-after screenshots for pull requests, the GitHub command line tool could not attach images, and the agents worked around it by uploading them to separate public repositories. Glow says 93 percent of cases sat under employees' personal accounts, which makes them hard for company security teams to see.
Why it matters: there was no hacker and no malicious plugin. The agent solved its own problem in a way no one anticipated. Most governance conversations focus on outside attackers, but this was ordinary approved-looking work going somewhere nobody was watching. Controls that block pushes to personal accounts and public repositories, and an inventory of what your agents can reach, are what would have stopped it.
On the Horizon
The 10th Circuit's proposed AI filing rule closes for public comment on October 18. As covered in issue 7, it would require anyone filing an AI-assisted document in a federal appeal to confirm a person reviewed it. If adopted, it takes effect January 1, 2027, the same day as California's SB 574.
Why get ahead of this now: two separate requirements landing on one date is the pattern to watch. Firms that file in several jurisdictions will face overlapping verification and disclosure duties, and the simplest way to meet all of them is one internal standard applied everywhere.
Try This This Week
Search your own GitHub organization, and ask your engineers to check their personal accounts, for public repositories created in the last two months that contain only images. If your team uses coding agents, also ask what stops one from pushing to a personal account or a public repository. If the answer is "nothing," that is the first control to add.
