The Daily Brief · Wednesday 23 September 2026
Today's Summary Squawk!
Two threads dominate today. First, the AI model cost curve is collapsing faster than anyone forecast. Axios reports that as OpenAI, Anthropic and others simultaneously release new models this week, prices have dropped to levels that would have been unthinkable twelve months ago — and usage is responding accordingly. That demand signal is the single most important variable for anyone trying to justify AI infrastructure spend or acquisition strategy in Australia right now. It lands directly alongside Treasury's Intergenerational Report, which names AI as a 'defining influence' on the Australian economy over the next forty years — the first time a major fiscal document has baked AI into the long-run structural outlook.
Second, the AI agent security picture is deteriorating in concrete, specific ways. Microsoft has disrupted a criminal platform called EvilTokens that used AI to industrialise account compromise at scale — 12,000 victims confirmed. Meta's Muse agent, which topped iPhone charts last week, now has a confirmed zero-day that security researchers say can turn it into a Mac backdoor via a simple ClickFix-style attack. Amazon has blocked Muse from its platform entirely after discovering the agent was scraping credentials without disclosure. The ASD has separately warned that North Korean job-scam infrastructure infected at least 30,000 devices globally. The pattern is consistent: agentic AI dramatically expands the attack surface, and enterprise security teams are not keeping pace.
For Australian strategy clients, the synthesis is uncomfortable. Treasury says AI will reshape the economy. The RBA signals rates stay higher for longer. The cost of AI models is falling fast enough to change the ROI maths on every deployment you've been modelling. And the security exposure from agentic AI is no longer theoretical — it's actively being exploited. Clients still in 'evaluate and monitor' mode need to understand that the environment has moved underneath them.
AI · Critical
AI Model Prices Collapse as Simultaneous Releases From OpenAI, Anthropic and Others Drive Usage Surge
Axios reports that OpenAI, Anthropic, SpaceX and Chinese model providers are all releasing new models simultaneously this week, with pricing at levels unthinkable twelve months ago. The key finding is that cheaper models are not cannibalising demand — they are expanding it materially. That's the demand signal the AI infrastructure investment thesis requires. The report frames this as the biggest risk variable for the AI boom resolving bullishly: if usage scales with price decreases, the trillion-dollar capex commitments made by hyperscalers and infrastructure players like Australia's Firmus start to look justified rather than speculative.
Point of view: This changes the cost-benefit calculus for every AI deployment business case I'm working on with clients. If frontier-model intelligence is now available at commodity pricing, the ROI threshold for enterprise deployment drops materially — and the competitive risk of waiting rises. Australian firms that have been deferring decisions pending clearer economics now face a different question: not whether AI is affordable, but whether they have the data infrastructure and organisational readiness to absorb it. Westpac's $12,000 intranet migration case from last week is a preview of what this looks like at scale.
Sources: Axios
AUSTRALIA · Critical
Treasury's Intergenerational Report Names AI a 'Defining Influence' on Australia's Economy Over Forty Years — First Time It Has Appeared in the Fiscal Baseline
The 2026 Intergenerational Report formally incorporates AI as a structural driver of the Australian economy over the next four decades. Treasury projects that AI will partially offset the fiscal drag of an ageing population, falling birth rates and rising debt, while acknowledging the gains will be uneven and concentrated. The RBA has separately flagged that Australia faces slower growth, higher structural deficits and persistent inflation from Middle East conflict. Taken together, these two documents represent the first time both arms of Australian economic policy have simultaneously treated AI as a baseline economic variable rather than an upside scenario.
Point of view: When Treasury bakes AI into its forty-year fiscal model, it stops being an innovation policy conversation and becomes a national economic strategy conversation. For my clients, the implication is direct: AI adoption is now implicitly assumed in Australia's productivity outlook, which means firms that don't adopt will underperform the macro baseline, not just their sector peers. The Intergenerational Report is also a signal to boards. 'We are monitoring this' is no longer a defensible governance position when Treasury has already moved past it.
Sources: Startup Daily · Crikey
AI · Critical
Microsoft Dismantles EvilTokens — AI-Powered Cybercrime Platform That Industrialised Mass Account Compromise at 12,000 Victims
Microsoft has disrupted EvilTokens, an AI-assisted cybercrime platform that enabled mass account compromise faster and at lower cost than any previous toolset. The platform gave operators automated credential theft, session hijacking and evasion capabilities across the full attack chain — not just as a single-tool enhancement. At least 12,000 victims confirmed. Microsoft's takedown involved domain seizures and infrastructure disruption. The incident follows the ASD's position last week that prompt injection in AI is structurally unfixable, and Citi's CEO naming AI patching as a 'tsunami' at UNGA.
Point of view: EvilTokens is the inflection point I've been expecting. AI has moved from augmenting individual attack steps to industrialising entire attack chains — and the economics have inverted. Defenders are paying more per incident while attackers are paying less per victim. For Australian enterprise clients, the immediate question is whether your security operations centre has visibility into AI-assisted attack patterns, not just traditional indicators of compromise. The ASD's guidance shift toward harness-level controls is directly relevant here. Perimeter controls will not catch this class of threat.
Sources: Ars Technica
AI · Critical
Meta's Muse Agent Has a Confirmed Zero-Day That Turns It Into a Mac Backdoor — Amazon Blocks It Entirely Over Credential Scraping
Security researchers have confirmed a zero-day vulnerability in Meta's Muse AI agent that allows a ClickFix-style attack to convert the agent into a full Mac backdoor. Muse was granted extensive system permissions on installation, so exploitation gives attackers broad access to files, messages and credentials. Separately, Amazon has blocked Muse from its platform after discovering the agent was browsing Amazon without identifying itself as an AI and appeared to be capturing and storing customer login credentials. The ASD has issued a warning. This is the first consumer AI agent to attract a confirmed zero-day disclosure, a major platform block and a government security warning in the same news cycle.
Point of view: This is exactly the scenario I warned enterprise clients about when agentic AI started moving into consumer devices: agents with broad system permissions create a novel, high-value attack surface. Muse's zero-day is particularly concerning because the ClickFix exploit chain — which we saw shared across four threat groups last week — maps directly onto it. For any client running a BYOD environment, Muse is now an active enterprise security risk even if the firm never sanctioned its use. The Amazon block is also strategically significant. Platform gatekeeping of AI agents is about to become a major battleground.
Sources: Ars Technica · iTnews · Stratechery
AUSTRALIA · Watch
Telstra Deploys Salesforce Agentforce to Meet Customer Service Guarantee Obligations — First Australian Telco to Put an AI Agent on Compliance-Critical Functions
Telstra has deployed a Salesforce Agentforce AI agent specifically to help meet its Customer Service Guarantee obligations — the regulated standards governing fault repair and connection timeframes. The deployment is live in production. This is the first confirmed case of an Australian telco using an AI agent on a legally regulated service obligation rather than a discretionary customer experience function. It comes in the same week a Senate inquiry recommended stripping Telstra of Triple Zero responsibility and mandating domestic mobile roaming — reforms that would substantially expand Telstra's regulated compliance surface.
Point of view: Telstra putting AI agents on regulated compliance functions is a material strategic shift, not a contact-centre chatbot story. If Agentforce can reliably demonstrate it meets the Customer Service Guarantee threshold, it creates a template for using AI agents to satisfy statutory obligations — with direct implications for every regulated industry in Australia. For consulting clients in financial services, utilities and telecommunications, the question is whether your AI deployment strategy has mapped which functions carry regulatory obligations, and whether your current AI governance frameworks are adequate for that exposure.
Sources: iTnews · Salesforce
AUSTRALIA · Watch
Heidi Health Hits $1.26 Billion Valuation After $140 Million Series C — Australia's Clinical AI Scaleup Goes Global
Heidi Health, an Australian clinical documentation AI company and Startup Daily's Scaleup of the Year, has closed a $140 million Series C at a $1.26 billion valuation, making it Australia's newest unicorn. The funding is earmarked for global expansion. Heidi automates clinical note-taking, cutting administrative load on GPs and specialists. The raise comes as Anthropic's Queensland biology laboratory signals that international AI firms are also moving into the clinical AI space domestically. The timing is notable: Heidi is scaling internationally at the same moment that Australian aged care algorithm failures — revealed by FOI last week — are generating political pressure on automated clinical decision systems.
Point of view: Heidi is the clearest evidence yet that Australian AI companies can reach unicorn scale by going deep on a domain rather than competing on general intelligence. Clinical documentation is unglamorous but strategically defensible: it requires regulatory approval, deep workflow integration and clinician trust — none of which a general-purpose model can replicate easily. For clients in healthcare and professional services, Heidi's model is worth studying. The question for Australian founders and investors is whether this playbook — domain-specific AI with a compliance moat — applies to other regulated sectors including legal, financial advice and infrastructure.
Sources: Startup Daily
AI · Watch
ASD Warns North Korean 'WaterPlum' Job Scam Infected 30,000 Devices Globally — Won't Confirm Australian Impact
The ASD has issued a public warning about a North Korean-backed job scam operation using a fake employer called 'WaterPlum' that infected at least 30,000 devices and stole cryptocurrency. The scam uses fake job listings to lure targets into downloading malware disguised as coding assessments or onboarding software. The ASD declined to confirm whether Australian devices or workers were among the victims — which in practice means yes. The operation is linked to DPRK state-sponsored groups that use cryptocurrency theft to fund weapons programmes. The warning follows last week's ASD advisory on legacy government tech debt as an active attack surface.
Point of view: The ASD declining to confirm local impact is a tell. Australian technology and finance sector employees — particularly those in job transition or contracting — are a high-value target for this class of operation. The WaterPlum methodology is sophisticated: it exploits the normalisation of remote technical assessments in hiring. For clients running large contract or contingent workforces, this is a supply-chain security problem, not just an individual employee risk. I'd recommend immediately reviewing onboarding and contractor screening procedures for any coding or software assessment steps, and ensuring security awareness training covers this specific attack vector.
Sources: iTnews
LEFT FIELD · Signal
US-Iran Hold First Direct Talks Since June — Strait of Hormuz Conditions Signal a Deal Is Possible Within Weeks
US and Iranian officials met for three hours on the sidelines of UNGA on Tuesday, the first direct contact since June. Trump envoys Steve Witkoff and Jared Kushner met Iranian Foreign Minister Abbas Araghchi. Iran's state television confirmed the US requested the meeting, and that it centred on Iran's conditions for reopening the Strait of Hormuz: lifting the naval blockade, releasing frozen assets and ending hostilities. Trump separately backed a ban on US diesel exports as domestic pump prices hit record highs. Macron simultaneously called for a mutual moratorium on energy infrastructure strikes in the Russia-Ukraine conflict. Three energy-related diplomatic signals in a single day is unusual.
Point of view: A Hormuz reopening would be the single largest near-term deflationary shock available to the global economy right now. Australian east-coast fuel distributors are already in a supply crunch, the RBA is treating Middle East inflation as structural, and every infrastructure and data centre build in the country is exposed to diesel and energy cost blowouts. Iran's conditions are substantive and a deal is not imminent. But both sides are publicly acknowledging talks, and Trump is simultaneously supporting a diesel export ban — the political pressure to resolve this is building faster than markets are pricing. Clients with major energy cost exposure should be modelling a rapid oil price reversal scenario alongside the current baseline.
Sources: Axios · Financial Times
Compiled from 38 curated sources · Wednesday, 23 September 2026
No spam, no sharing to third party. Only you and me.
Member discussion