Model prices dropped, an agent got blocked from a major retailer, and a zero-click flaw hit four coding agents at once. Six stories from the last two days.
Six stories from the last two days, and the theme picked itself: the model layer got a lot cheaper, agentic commerce hit its first real wall, and a vulnerability with a silly name gave every team running AI coding agents something to check before the weekend. Tap through the log below:
Anthropic ships Claude Opus 5.5: output tokens drop from $25 to $20 per million, runs faster than Opus 5, and Anthropic calls it “the strongest-performing model we’ve tested to date,” matching Fable 5.1 on biology and cybersecurity.
Why it matters: a cheaper, faster top-tier model just two months after Opus 5 shipped changes the cost math for anything running agent workloads at volume.
Source: TechCrunch, Sep 22
OpenAI releases GPT-6 Sol and Luna as permanent-priced “enterprise workhorse” tiers: Luna at $0.10/$0.50 per million tokens, Sol at $2/$10, both roughly half of the GPT-5.6 equivalents. Sol now matches Claude Sonnet 5 pricing.
Why it matters: the fight is now about cost-per-completed-task, not just benchmark scores. Both labs just cut the default price of routing routine agent work.
Source: VentureBeat, Sep 22
Amazon blocks Meta’s Muse AI agent from shopping on Amazon.com, citing its Conditions of Use. Amazon runs a competing AI stack and would bear liability for any bad purchase Muse makes.
Why it matters: the agentic-commerce standoff just went public at scale. Expect major retail platforms to block third-party shopping agents by default for now, not welcome them.
Source: TechCrunch, Sep 21
Plugin4Shell: a flaw in plugin marketplaces lets attackers swap malicious code behind a pinned commit SHA that still checks out clean, hitting Claude Code, Codex, Gemini CLI, and Copilot. Claude Code (v2.1.179) and Codex (v0.146.0) are patched. Copilot has no patch. Gemini CLI was deprecated instead of fixed.
Why it matters: check your coding-agent versions today if your team uses third-party plugins. A pinned SHA is not the same guarantee on every host.
Source: Help Net Security, Sep 18
Google opens preorders for the $899 “Googlebook,” an Android/Chrome laptop built around Gemini features like Magic Cursor and Rambler, shipping October 4-5 with 12 months of Google AI Pro included.
Why it matters: Google is betting on-device AI can sell hardware on its own, with roughly 50 million school Chromebooks as the real target for Gemini adoption.
Source: TechCrunch, Sep 21
Meta’s Nat Friedman confirms Muse was “heavily inspired” by open-source project OpenClaw, after users spotted matching config file structures between the two. Meta says Muse was still “built from scratch.”
Why it matters: legal under open licensing, but a clean case study in how fast a well-designed open agent architecture gets absorbed by a company with the resources to ship it at scale.
Source: TechCrunch, Sep 22
Six stories from the last two days, and the theme picked itself: the model layer got a lot cheaper, agentic commerce hit its first real wall, and a vulnerability with a silly name gave every team running AI coding agents something to check before the weekend.
Anthropic and OpenAI both cut prices the same day
Anthropic shipped Claude Opus 5.5 on September 22, calling it "the strongest-performing model we've tested to date." Output tokens drop from $25 to $20 per million, the model runs faster than Opus 5, and Anthropic says it matches Fable 5.1's performance in biology and cybersecurity while beating it on coding and knowledge work. It arrives just two months after Opus 5 shipped in July, with Sonnet 5.5 and Haiku 5.5 expected within weeks.
Hours later, OpenAI released GPT-6 Sol and Luna, two mid-tier models it's positioning as "enterprise workhorses" for work that doesn't need the flagship Astra model. Luna runs $0.10/$0.50 per million input/output tokens, roughly half of GPT-5.6 Luna's price. Sol runs $2/$10, exactly half of GPT-5.6 Sol and now matching Claude Sonnet 5's pricing. OpenAI says these are permanent prices, not a promotion, and that Sol hits "33.2% on AutomationBench 1.0 at $0.27 per task," about 11 times cheaper per completed task than Claude Opus 5.
Why it matters: the competitive fight has moved from leaderboard scores to cost-per-completed-task. If you're routing agent workloads across model tiers, both companies just handed you a cheaper default for the routine 80% of calls, which changes the math on running agents at volume rather than just prototyping them.
Amazon blocks Meta's Muse from shopping on its site
Meta's Muse AI assistant now hits a wall when it tries to shop on Amazon: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use." Amazon runs its own AI stack and has no incentive to hand traffic to a competitor's agent, and it would be on the hook for any bad purchase Muse makes on a customer's behalf. Muse reportedly has one of the lower hallucination rates among current models, but "one of the lower" still means errors happen often enough to matter at Amazon's scale.
Why it matters: this is the agentic commerce fight surfacing in public for the first time at this scale. If you're building or evaluating a shopping or browsing agent for internal use, assume major retail platforms will treat it as a bot to block by default, not a channel to welcome, until liability questions get resolved.
Plugin4Shell: a zero-click RCE across four AI coding agents, two still unpatched
Researchers disclosed a flaw affecting plugin marketplaces used by Claude Code, OpenAI's Codex, Google's Gemini CLI, and GitHub/Microsoft Copilot. The marketplaces verify a pinned commit SHA but never confirm the code at that location matches, so an attacker can swap in malicious code behind a pin that still looks valid, resulting in zero-click remote code execution the moment the agent checks out the plugin. Anthropic patched Claude Code in v2.1.179 and OpenAI patched Codex in v0.146.0. Microsoft Copilot has no patch yet, Google deprecated Gemini CLI in favor of Antigravity CLI rather than patching it, and GitHub disputes whether its platform-level mitigation actually covers external marketplaces.
Why it matters: if your team uses any of these coding agents with third-party plugins, this is a "check your versions today" item, not a "read later" one. The broader lesson holds regardless of patch status: a pinned commit SHA is not the same guarantee across every plugin host, and treating agent plugin marketplaces as unvetted production dependencies is the safer default going forward.
Google opens preorders for a $899 laptop built around Gemini
Google's new "Googlebook" line starts at $899, ships October 4 to 5, and runs Android with Chrome, positioned as a step up from Chromebooks rather than a replacement for a full laptop. The pitch is three Gemini-native features: Magic Cursor, which lets you highlight anything on screen and hand it to Gemini; Rambler, which cleans up dictated text; and vibe-coded widgets built on the fly. It ships with 12 months of Google AI Pro included. The real target looks less like individual buyers and more like the roughly 50 million Chromebooks already sitting in schools, which Google would very much like to upgrade into Gemini devices.
Why it matters: this is a bet that on-device AI features can sell hardware on its own, and it's worth watching whether Magic Cursor turns out to be meaningfully different from screenshot-and-ask features already on Android, or just a rebrand with better placement.
Meta admits Muse was "heavily inspired" by open-source OpenClaw
Nat Friedman, head of product at Meta's Superintelligence Labs, confirmed that Muse was "heavily inspired as a product" by OpenClaw, the open-source personal AI agent project that went viral earlier in 2026 before its creator, Peter Steinberger, joined OpenAI. Users had already spotted matching workspace filenames and near-identical structure in config files like SOUL.md between the two projects. Meta maintains Muse was "built from scratch."
Why it matters: open licensing makes this legal, but it's a clean example of how quickly a well-designed open-source agent architecture gets absorbed by a company with the resources to ship it at scale. If you're building on top of an open agent framework, this is the outcome to plan for, not the exception.
The thread connecting all of it
Model access got cheaper, agent access to other companies' platforms got more restricted, and agent supply chains got a reminder that a pinned dependency is only as trustworthy as the host verifying the pin. None of these are separate stories so much as the same market working out where agents are welcome, what they cost to run, and what breaks when nobody's watching the plugin marketplace.

