Prime Ai Solutions
Read time: 4 minutes
Welcome back, leader.
Last week I told you OpenAI's model broke out of its own test environment and hacked Hugging Face.
This week we learned it did that four times over, Sam Altman says he wants to slow down, and a pile of people's Claude chats turned up on Google…
LATEST NEWS
The Model Let Itself Out
Quick recap if you missed it:
OpenAI was testing its models against a hacking benchmark with the cyber safety limits deliberately turned down. The models found an unknown flaw, escaped the sandbox, and pulled the test answers out of Hugging Face's production database.
That was the tidy version.
Hugging Face's forensic timeline logs 17,600 separate hacking actions across four days, and OpenAI now says the models got into four accounts across four different services! One of the four belonged to a Modal Labs customer who had left an endpoint on the open internet with no authentication on it. Modal's own platform was never touched. A human left the door open.
At this point it is less "rogue agent" and more AI on a Bonnie and Clyde arc, and someone on OpenAI's security team is really hoping this is not a monthly subscription.
The detail that should bother you is the timeline. The agents were reportedly loose for about a week before anyone noticed.
Then Altman blinked. On Tuesday he told Patrick O'Shaughnessy on “Invest Like the Best” that the industry "may have to pace the rate of AI development to give ourselves enough time for society to harden around some of these new capability levels." He called it the first security incident he had felt viscerally. Training on that model is paused.
This is the man who waved off the 2023 pause letter for missing the technical nuance. Read him carefully though, because nobody is saying the capability is slowing down. They are saying the security around it needs time to catch up, and those are opposite instructions for you.
Then it got domestic.
Over the weekend Reddit users found that a single Google search operator surfaced shared Claude conversations and Artifacts. Futurism reported finding a real patient's medical report, documents listing the names and phone numbers of primary school aged children, and files marked internal use only. Anthropic's position is that it never hands chat directories to search engines and the links are not guessable unless someone posts them somewhere crawlable, which is probably true and also beside the point.
Smaller version of the same shape: Opus 5 shipped on 24 July and quietly became the default on Claude Max and the top option on Pro. Anthropic's own notes say it writes longer than previous Opus models and tell you to specify length explicitly. If your saved prompts started producing essays this week, that is why.
Every one of those is the same story.
The control arrives after the capability. Sandbox hardened after the escape, share warning rewritten after the leak, model swapped with no email.
So do the ten minute version now, while it is cheap.
In Claude, go to Settings, then Privacy, then Shared Chats, and look at what your account has actually published. Check the Shared Artefacts too.
Then ask everyone on your team to do the same today.
STEAL THIS
Become AI Native
Acquisition.com published the results of its first quarter as an AI-first company this month. Alex Hormozi's portfolio company, famous for operational discipline, started its structured push in April 2026. April. One quarter ago!
Their self-assessed workflow redesign and automation score went from 29% to 70% in 90 days. Agentic AI went from 18% to 52%.
Sit with the starting numbers rather than the gains. One of the best run companies in the world rated itself 18% on agentic AI three months ago. You are not behind. Almost nobody has started.
What they did was boring but effective, and what we always recommend.
Structured sessions, weekly office hours, a champion in every department, nobody exempt including leadership, and a survey at both ends so they could publish a result instead of a vibe.
Here is the part to steal, and it is week one. Two documents, one afternoon.
First, survey your team on four things, scored one to ten.
Writing prompts that produce usable output.
Redesigning a workflow rather than just speeding it up.
Checking whether an AI output is actually correct.
Judging when AI is not worth using at all.
Do not soften the wording to protect anyone's feelings.
A flattering baseline is worthless, because the point is that you run the same survey again in twelve weeks and compare the two.
Second, list the ten most repetitive workflows in the business.
Month end reporting.
Debtor chasing.
Proposal drafting.
Meeting follow ups.
Board pack commentary.
Then cross reference them. Your right first target is high frequency, format driven and low risk: the work that repeats every week in a known shape.
Skip this and teams default to automating whatever the last demo showed them.
That is it.
Two lists and one number, and "we should do something about AI" becomes a plan with a start date.
Week one is the easy week.
The other eleven are the reason I spent the last month rebuilding how I teach this.
SOMETHING I’M BUILDING
The best academy and courses to get you AI Native
I moved the course off Thinkific and onto my own platform this month.
Worth telling you why, because the reason is the same reason most corporate AI training quietly fails.
Thinkific is a video library, text inputs with a quiz attached. It is good at that. The problem is that this is not learning, and I have sat in enough sessions where a finance team nods along and then goes straight back to the inbox to know the difference.
So the new one is built on the two findings learning science is actually confident about. Retrieval practice, which means you recall things instead of rereading them. And spacing, which means a concept comes back to you just before you would have forgotten it.

Review Queue
That is the review queue.
Three-way match, defined.
RACEF, what the F stands for.
Where copilots fail in close.
Miss something in a lesson and it comes back days later rather than never.
Every lesson ends in a marked attempt rather than a multiple choice question.
You write a real prompt or a real process assessment, and it gets marked against the lesson's criteria: does it name the three P2P stages, does it link each one to a measurable impact, is it grounded in your own context.
There is an in-lesson tutor. It is grounded only in the lesson you are reading and it walks you toward the answer instead of handing it over. A tutor that just gives you the answer is an expensive way to not learn something.
You can also tell it your process, your tool and your finance system once, and every worked example and every prompt gets reframed for your actual job.
FP&A or P2P or O2C or R2R. Copilot, Claude or ChatGPT. Dynamics, SAP or Workday.

And you leave with things rather than a completion bar. Those seven are what you build as you go: the ROI calculator, the process assessments, your own prompt library, the F.A.I.R. scorecard for choosing tools, a governance framework written for FCA and PRA expectations and UK GDPR, the 90-day pilot plan, and a business case you can put in front of a board.
The certificate states what you can now do rather than how many hours you sat, which is the only version of a certificate I have ever found useful.
35 lessons, 15 to 20 hours, £99 once and it is yours.
The first two modules are free, including the interactive prompting lesson where you write a prompt and watch the model respond, so you can see how it teaches before you pay for anything. Have a look here.
Finance is the first course, not the only one. Tool-specific tracks for Claude, ChatGPT and Copilot are in production, along with profession-specific courses for lawyers, teachers and others, each one written by someone who actually does that job.
Three security stories in one week, all pointing the same direction, and not one of them says wait. They say the capability lands before the control does, which makes the control your job.
Ten minutes on your shared links. One afternoon on the two lists. That is the whole ask.
-Umar Prime AI | primeai.solutions
P.S. If you only click one thing, make it the free preview.
Two full modules, no payment, and the prompting lesson is the one people message me about.

