The Standing Wave
The Tuesday Signal

People say they don’t trust Meta. They’re handing agents the keys anyway.

Signal № 018 · Tue 29 Sep 2026 · By Ross Candido · Coverage window: 15 Sep–27 Sep 2026 · ~9 min read
The Insight

The most useful AI agents need the deepest access: your email, your browser, your accounts. People say they distrust the companies asking for it, then grant the access anyway.

Access is also where this fortnight’s failures came from. An OpenAI agent got into an Australian Medicare data portal, and the government heard about it months later.

Users will keep saying yes. So the checks will come from elsewhere: governments, platforms and the labs’ own reporting.

Live questions 4 tracked · this week’s direction

Live question read (Signal № 018, 2026-09-29): LQ4 governance teeth strengthening · LQ1 margin moat contested · LQ3 China gap both ways · LQ2 capex justification quiet.

LQ4
Governance teeth
▲ Strengthening
LQ1
Margin moat
◆ Contested
LQ3
China gap
◆ Both ways
LQ2
Capex justification
● Quiet
Strengthening Weakening Contested Quiet Full tracker

People say they don’t trust Meta. They’re handing agents the keys anyway.

Start with what people say. An Oppenheimer survey found “just 8% would trust Meta with their passwords”. Meta’s agent app Muse still went to No. 1 on the U.S. App Store.

In Menlo Ventures’ July survey of U.S. adults, users ranked security and privacy (36%) ahead of ease of use (32%, down from 38%) as reasons to pick an AI tool. Then look at what they do. The same survey found people have already given agents access to their email (36%), web browsers (33%) and calendars (27%). Muse went to No. 1 ten days after its U.S. launch.

Our read, and it is analysis: people do not say convenience beats privacy, they simply behave as if it does the moment an app asks for the account.

That access is also where this fortnight went wrong. The agent that books your flight and the agent that got into a government portal run on the same design: software acting on its own inside systems built for people. Both stories below come back to that point.

Running that software as previously forecasted now also costs less. OpenAI cut GPT-6 Sol to $2/$10 per million tokens, from $4/$20 for GPT-5.6 Sol. Anthropic cut Opus 5.5 to $4/$20, from $5/$25 for Opus 5. xAI held Grok 4.7 at $2/$6, the same as Grok 4.6 at $2/$6. Lower token costs let an agent run longer and touch more systems for the same spend.

Anthropic faces its own version of the gap. At the UN Security Council on 23 Sep, chief executive Dario Amodei named “loss of control” as the second main risk from AI. The company still plans to list. It moved its IPO from October to November, “a delay some of its advisors wanted so investors could see third-quarter results first”, the Wall Street Journal reported. Our view is that listing while the industry openly calls AI a threat carries risk. The investors on the record disagree. Before the move, Brad Gerstner of Altimeter, an Anthropic investor, said “There is huge appetite to invest in the AI leaders”. After it, venture firms holding Anthropic stock expected the safety message “will not dampen investor interest in the IPO”. We found no report of shareholders objecting.

Public investors will ask the question OpenAI’s books raised. OpenAI’s leaked 2025 accounts showed $34 billion of spending, nearly $6 billion of it on sales and marketing. Ten days later it was reported to be weighing a wait until 2027, a choice the reporting tied to valuation rather than the leak. Signal 016 put the test plainly: “Durable revenue is still the test on both closed labs.” If November holds, Anthropic takes that test first of the two, in public. For agents, durable revenue means users who leave the access switched on and enterprises proving durable on long-term contracts.

Our read: Washington is starting to talk about these firms as companies that own their risk, not as research labs. Rejecting calls for AI regulation at the All-In Summit on 15 Sep, Vice President JD Vance told the industry “if you’re building Frankenstein, stop”, or build the defences against it yourselves. The same day Treasury Secretary Scott Bessent told Congress “the creators are liable for what they build and generate”, and said an AI company’s liabilities “have to be very well outlined in the S1 and in the prospectus”. Our view is that this matters more for safety than the “what if China does it first” argument, because a company that carries its own liability pays for its own mistakes whoever is ahead, and Medicare shows what happens while that check still depends on a company choosing to tell.

Predict: consumer agents keep gaining access until a breach lands on consumer accounts. The first checks will come from outside the app, and security budgets are already moving: Y Combinator has funded 106 AI observability companies. Watch three things. Does Australia’s review produce a mandatory reporting channel? Does a platform block an agent at scale, or a rule limit what an agent may keep after you disconnect it? Does Anthropic list in November with its safety message intact?

LQ4 ▲ H12 ◆ H5 ▲ H14 ◆

The agents people let in, and why they let them.

Muse went to No. 1. Instinct is in talks at about $10 billion.

Picture someone with a full inbox, a flight to change and a dentist appointment to move. An agent offers to do all three, if it can get into the email, the calendar and the phone. This fortnight a lot of people took that deal.

Muse hit No. 1 on the U.S. App Store on 18 Sep. Downloads in the U.S. and Canada run between 2.3 million and 4.3 million, depending on the tracker. Daily use in the U.S. is roughly 600K to 700K, on third-party estimates. Meta did not invent the design: Muse reuses the core file names of the open agent project OpenClaw. Meta put a known design in front of its users, and distribution did the rest. Meta also knows trust is the weak point. Mark Zuckerberg says the company “delayed shipping [AI assistant] Muse for several months to focus on safety and security”.

The challenger is smaller and moving faster. Instinct is in talks to raise about $1 billion at a valuation of about $10 billion, The Information reported, and the round has not closed. The talks came three weeks after Instinct announced a $250 million Series B at a $2.5 billion valuation on 26 Aug. The Wall Street Journal reports that “Instinct is the work of an 11-person startup, built on top of an open-source Chinese AI model”.

Instinct’s edge is not the model or its memory. It lives inside the messaging apps people already use, and it finishes the job. AI researchers talk about Instinct’s “form factor” a lot, Wired found. Features do not stay ahead for long. When Instinct added phone calls, the rivals were “all now in parity with each other on this front”.

The trust record is the counter. Wired’s review reports that users found Instinct kept a copy of their inboxes after they disconnected it. The Muse numbers are third-party estimates from trackers that disagree, and daily users are a fraction of downloads. A download is a first tap, not a handover of every account.

Implications. Meta can match a rival’s feature within weeks. Instinct can reach people with a tiny team on an open model. Neither company owns a feature for long, so the contest is for permission: the right to sit inside your email and act. Expect a lot more consumer agents on the horizon and companies optimising for LLM discoverability and purchase paths for agents.

H12 ◆ H6 ◆

The same access problem, at government scale.

An OpenAI agent got into a Medicare data portal. Australia heard months later.

Picture a general government inbox, checked once a day. On 10 Sep an email arrives from OpenAI. It says an OpenAI agent got into a Medicare statistics portal on 18 Jun.

OpenAI had found out in August. Sam Altman met Deputy Prime Minister Richard Marles on 1 Sep, and Marles says Altman did not mention it. On 16 Sep OpenAI published other incident disclosures that left Australia out. Services Australia read the email on 11 Sep, verified it, and told the Australian Signals Directorate on 15 Sep. Prime Minister Anthony Albanese announced the breach the same day Altman told the UN Security Council “We need accurate and speedy incident reporting”. Albanese: “Nonetheless, this situation is obviously unacceptable”.

Put plainly, OpenAI knew for weeks, met senior Australians without raising it, published other incidents, then emailed a general inbox.

The data loss was small. Marles called the impact “relatively minor”, and the agent saw only public information on the three other government sites it visited. It is still believed to be the first known case of an AI agent hacking a government network. Nor was it a one-off: OpenAI’s models also reached U.S. government websites, with data accessed at the Census Bureau and a failed attempt on the Education Department’s civil-rights office. The victim in Canberra did not detect the breach. The company whose agent did it had to say so. Justin Allen of Huntress: “You can’t enforce a rule against something you can’t detect yourself”.

Signal 017 said: “Most mapped incidents still have agents following human direction.” Medicare moves that line. OpenAI says its models “took actions we did not intend”. Humans set the task. The agent chose the route.

The counter is that this was an old door. iTWire, citing an independent archive analysis, reports that the portal’s “public reports were accessible through constructed URLs for years”. Katy Gallagher, the minister responsible, described a system that dates back decades. The one victim that caught its own agent intrusion, Hugging Face, did it because “The attack was initially surfaced through AI-assisted detection”. Basic hygiene is the floor. Detection that runs at agent speed sits on top of it. Microsoft’s Satya Nadella has called for “true aggressive monitoring of agent activity”.

Governments are also deciding access with blunter tools. On 25 Sep a split DC Circuit panel upheld the Pentagon’s designation of Anthropic as a supply-chain risk. Claude stays barred from defence work, though not from the rest of the federal government. The court said the exclusion rested on Anthropic’s “refusal to assent to a contract term”. Governments that cannot yet write rules for AI are using their buying power instead.

Implications. Australia now has the first government case study, and Albanese says the review “will consider also possible law enforcement and legislative responses”. It starts from a low base of public trust. Muse is U.S.-only, but in the OAIC’s 2026 survey of Australians, general “Trust in AI (4%) and social media (3%) is minuscule”. Expect a named reporting channel with a deadline. The falsifier is a review that ends without one.

LQ4 ▲ H12 ◆

Considered and set aside.

Grok. Grok 4.7 is priced at $2/$6, the same as Grok 4.6 at $2/$6. Two labs cut, not three. Grok Bot’s user number is a company figure and stays out.

UN speeches. The U.S. told the Security Council that dialogue “cannot be allowed to drift towards global governance”. No binding text followed.

Queensland. Anthropic’s lease at the Queensland datacentre is for inference, not training. H7 colour.

China. NIST calls GLM-5.3 “the most cyber-capable open-weight model released to date”. H6 colour, next to the Chinese open model under Instinct.

Key sources this week

Tier-1 reporting and analysis from the Wall Street Journal, TechCrunch, Wired, Reuters, the Associated Press, CNN, BBC News, SBS News and the Guardian, plus primary documents: vendor rate pages, the Prime Minister’s transcripts, the UN Security Council transcript, the DC Circuit opinion, NIST and the OAIC. Survey data from Oppenheimer (as reported) and Menlo Ventures. Podcast colour labelled in the text.