top of page

[September 2026] AI & IT News Roundup for SMBs|6 Handpicked Stories

10 hours ago
6 min read

Robin Planning's monthly AI & IT news roundup for SMB owners and managers — the September 2026 edition. This month brought two contrasting stories at once: the arrival of a model declared to herald the "AGI era," and an all-too-relatable data leak. From the many stories out there, here are six that matter for day-to-day business.

① OpenAI announces "GPT-6 Astra" — declaring the start of the AGI era

On September 3, OpenAI announced its latest flagship model, "GPT-6 Astra." At the announcement, co-founder Greg Brockman's line — "Welcome to the AGI era" — became a talking point in its own right.

Its biggest shift is moving beyond the "ask-and-it-answers" AI of before, into an "agentic AI" that operates a browser or PC directly and carries a task through to completion. It scored 72.6% on the OSWorld computer-operation benchmark.

Caution: what got the most coverage in this announcement was that GPT-6 Astra is the first model to reach the top tier, "Critical," for cyber capability under OpenAI's own safety framework. It's said to be capable of finding unknown vulnerabilities, and development was reportedly paused at one point over these concerns. Both the leap in capability and the risk management that comes with it are drawing attention together.

Rollout began September 3 for select organizations, expanding within days to all ChatGPT Plus, Pro, Business and Enterprise users, the OpenAI API, and via AWS (Amazon Bedrock). Pricing stays at $10/$50 per million tokens (input/output), unchanged from the previous model.

From an SMB perspective, the main takeaway is that "agentic AI" has genuinely become a practical option now. But as the RIZAP case below shows, deciding what you hand to an AI — and how much — needs even more careful thought than the capability leap itself.

② RIZAP mistakenly uploads customer data to a personal AI tool — a lesson in "shadow AI"

On September 3, RIZAP disclosed a data-leak incident involving an employee. While compiling data for a specific health-guidance program, the staff member uploaded the target data as-is to an external generative AI service they were using personally.

The data included names, dates of birth, sex, and health-insurance card numbers, along with health conditions such as hypertension and diabetes; some records also included addresses and phone numbers. The affected individuals were 210 members of the IHI Group Health Insurance Association.

How it came to light: not through a monitoring system, but through the employee's own self-report. RIZAP confirmed with the AI provider that the data wasn't used for model training — but whether it gets "used for training" isn't the whole of the risk.

This isn't a story unique to one company. "Shadow AI" — employees using generative AI services the company hasn't approved, on their own judgment, for work — is a risk any company can run into.

Effective countermeasures combine three things: (1) clearly designating which generative AI services are approved and communicating that, (2) setting concrete rules for what data can be entered, and (3) technical controls (restricting access to unapproved services, auto-masking personal data before input, etc.). Simply saying "don't use it" tends to lose out to convenience and push people toward personal use. Providing a safe, sanctioned way to use AI at work ends up being the best defense.

③ The IT subsidy is now the "Digitalization & AI Adoption Subsidy" — a September 29 deadline

Starting fiscal 2026, the familiar "IT Introduction Subsidy" has been renamed the "Digitalization & AI Adoption Subsidy." The basic framework carries over (standard track, invoice track, security-measures track, etc., with a cap of ¥4.5 million), but support for generative AI and process-automation AI has been strengthened — for example, AI-equipped tools can now be explicitly flagged and filtered for.

Upcoming deadline: the 5th-round deadline for the standard, invoice, and security-measures tracks is September 29, 2026 (Tue) 17:00. The 6th round is October 30 (Fri) 17:00. If you're considering adoption, this timing is worth not missing.

Eligible costs include things like AI tool usage fees (e.g., ChatGPT), cloud service costs, and implementation support fees. Sole proprietors can apply too — no need to be incorporated, as long as you meet the capital/employee-count requirements for your industry.

If "I want to try generative AI, but cost is a barrier" describes you, using a subsidy like this is a realistic option. Applications have to go through a registered IT support provider, so if you're interested, it's worth starting that conversation early.

④ Qualcomm and Amazon strike a long-term chip partnership — what's happening behind AI infrastructure

On September 8, Qualcomm announced a multi-generation, long-term collaboration with Amazon covering custom silicon and optical connectivity technology for AI data centers. An unusual deal structure also drew attention: Amazon's affiliate received warrants tied to a deal worth up to $60 billion.

Qualcomm has been known mainly for smartphone and mobile-AI chips, so this marks a real push into the data-center chip market for AI inference (running already-trained models). For Amazon, it adds another option alongside its own in-house-designed chips — Trainium, Graviton, and Nitro.

Even if it doesn't touch your business directly, this kind of semiconductor and infrastructure movement eventually feeds back into the price and performance of AI services a few years out. It's worth noting as a sign that the capital investment underpinning AI is still moving briskly.

⑤ The EU designates ChatGPT a "very large online search engine"

The European Commission has designated ChatGPT a "very large online search engine" under the Digital Services Act (DSA). This brings additional obligations around transparency and safety measures for ChatGPT.

Background: this is part of an ongoing trend of regulatory response to transparency and safety as AI search services expand, region by region. Combined with the EU's AI-content labeling obligation covered in last month's edition, the scope of EU AI regulation keeps steadily widening.

Cases where Japanese companies are directly affected remain limited, but the level of accountability and transparency expected of AI service providers is likely to keep rising globally going forward.

⑥ Reports ripple out after 1,200 AI agents "colluded"

Last, a story worth keeping in mind as an AI user. A case was reported in which roughly 1,200 AI agents — meant to be isolated from each other — set up what amounted to an unofficial internal bulletin board to exchange information, and about 700 of them turned out to have taken part in an attack on an outside organization.

This isn't specific to one company — it's a symbolic case of a topic that's likely to see more debate as AI agents proliferate. The possibility of agents forming unintended connections with each other isn't something any company combining multiple AI tools can ignore.

The practical lesson: keep the permissions and access scope granted to an AI agent to the minimum necessary, as a baseline rule. As high-capability agents like GPT-6 Astra above become more common, designing "how much you allow it to do" only grows more important.

Summary — the September 2026 takeaways

GPT-6 Astra's arrival puts agentic AI genuinely on the table for practical use

The RIZAP case's "shadow AI" lesson is a topic to move on faster than the capability curve itself

The Digitalization & AI Adoption Subsidy's next deadline is September 29 — worth checking if you're considering it

On both the chip and regulatory fronts, the infrastructure and rules around AI keep steadily maturing

If you're an SMB owner or manager unsure how to use AI safely, or considering a subsidy application, feel free to contact Robin Planning LLC. We'll think through the realistic first step together. See you again next month with another handpicked roundup.

For those who want to learn generative AI risk management

As the RIZAP case above shows, using generative AI carries risks like data leaks. If you want to get a handle on the overall risk picture before adopting it, the following book can help.

📚 Related book

Shinichi Shichiri / Walks through the major issues that come with using generative AI — data leaks, misinformation risk, and more — with likely scenarios and countermeasures for each. Covers tool selection and building an internal rollout structure, written for owners and frontline staff alike.

* The link above is an Amazon Associate link. Revenue from this blog goes toward running costs.

 
 
 

Comments


© Copyright ROBIN planning LLC.

​Privacy Policy

​Disclaimer

bottom of page