Good morning, AInauts,
Welcome to a new edition of your favorite newsletter!
We spent money on ChatGPT Ads, worked our way through a week of AI scare stories ranging from cyberattacks to the end of the world, and then relaxed by building a newspaper nobody but us needs. So yes, quite a lot happened π.
The coolest part: ChatGPT can create and analyze your campaigns, including the ads themselves. But the preparation is what makes the difference. We found a process that makes getting started much easier, even without advertising experience. If you have avoided ads until now, this could change your mind.
Here is what we have for you today:
π£ ChatGPT Ads in Our Real-World Test
β οΈ The Week Everyone Started Talking About AI Safety
π° Prompt Your Morning Newspaper. Circulation: 1
Let's go!
Some teams never seem to stop moving. They're on Attio, the agentic CRM.
Every customer signal is captured in one shared context layer, always current and compounding. Agents and workflows build pipeline, chase every buying signal, and move deals forward, an always-on revenue engine running alongside your team.
With Attio, youβll get:
Leads automatically prioritised and routed to the right rep
Expansion and risk signals caught the moment they land
Follow-ups written in your voice, already there when you arrive
Teams like Parallel, Turbopuffer, and Wordsmith build on Attio. Are you one of them?
π£ ChatGPT Ads in Our Real-World Test
Setting up our first ChatGPT Ads was surprisingly simple: install the ChatGPT Ads Manager plugin, create an ad account, continue working in the chat, and set up the campaign and tracking.
The plugin can automatically create campaigns with matching creative assets, analyze the results on request, and recommend what to do next. All of that happens from a single chat.
The first results? Mixed at first. But we are now seeing real winners. That learning curve is exactly what makes this so interesting to us.

How Do ChatGPT Ads Work?
Let's look at a practical example. JΓΌrgen sells promotional products. Someone planning a trade show may have a limited budget and want something that will not end up in the trash on the way home.
On Google, that becomes a search for keywords such as "trade show promotional products." In ChatGPT, it quickly turns into a conversation about the occasion, budget, and what people will actually remember.
That is precisely what makes ChatGPT Ads powerful.
Traditional advertising usually works through push or pull: an ad creates interest, or it intercepts an active search.
ChatGPT adds an important third layer: context.
The ad can better match a need that emerges during the conversation.

Since late August, the self-service ChatGPT Ads Manager has been available in 31 European markets, including Germany, Austria, and Switzerland. When billed in euros, the current minimum budget is an average of EUR 15 per day.
Ads currently appear for ChatGPT Free and Go users. They are clearly labeled as advertising, and the ChatGPT response itself remains independent. Advertisers obviously cannot read private chats either.
The Real Work Happens Before You Open Ads Manager
Our thesis: a new advertising market is often less crowded. Remember the "golden days" of Facebook Ads? We do π. That is why we want to understand what works before everyone else does.
OpenAI uses Context Hints: extra information about your product, audience, and customer needs that helps the system decide in which conversations an ad may be relevant.
Solid groundwork is essential.
Language note: The linked SwissMadeMarketing setup is currently available in German.
Our long-time partner Sam at SwissMadeMarketing has built a process that creates exactly that foundation:
First, it analyzes your website or business and its offer. The result is a customer profile, customer needs, and related keyword research.
It writes everything into a downloadable Markdown handover for ChatGPT, giving you clear instructions for Context Hints and ads.
Upload the handover to ChatGPT and prompt: "Follow the instructions in the file."
What We Learned From the First Tests
The promotional-products example produced an early signal: EUR 87.06 in ad spend generated 129 ad clicks and eight leads. That works out to EUR 10.88 per lead, which looks promising in this case.
Our own campaigns are also moving in the right direction. After several optimizations, we are now acquiring new newsletter readers at reasonable costs.
One important tip: your landing page must deliver on the promise made in the ad, ideally word for word. Otherwise, you are efficiently optimizing the wrong story.
Also relevant in practice: OpenAI may report conversions with a delay of 24 to 48 hours. So do not switch a campaign off after the first few hours simply because the dashboard still shows nothing π.
It is better to verify results through another route as well. That is why we also pass the UTM source during signup, for example chatgpt / cpc.

Our Take: Start Small Now and Use the First-Mover Advantage
We have run ads on Meta, Google, and other platforms for years. ChatGPT Ads is by far the easiest advertising system we have ever set up.
Of course, ChatGPT Ads are not automatic winners. Start with a proven offer, use a small budget, and treat the first campaign as a chance to learn.
For a tested setup process, download your personalized ChatGPT handover for free. Then start the setup and let ChatGPT guide you through it.
You can simplify this even further by asking ChatGPT to create a ChatGPT Sites landing page with a lead form and conversion tracking, if your plan supports it:
Create a mobile-optimized landing page with a lead form in ChatGPT Sites and prepare a matching ChatGPT Ads campaign with conversion tracking for my offer.
Align the ad promise, landing page, and call to action. First clarify any missing information, including the offer, branding, and required access, then test the complete flow after implementation.200+ Proven Ways to Make Money With AI in 2026
The next wave of millionaires will be people who figured out how to make AI work for them.
The window to get ahead is still open. But not for long.
Here are 200+ proven ways to make money with AI in 2026.
Sign up for Superhuman AI, the free daily newsletter read by 1M+ professionals, and get instant access to all 200+ ways to profit from AI this year.
β οΈ The Week Everyone Started Talking About AI Safety
After last week, we have to want to talk about AI safety again.
An Anthropic safety researcher left the company, and he did so rather publicly: "The people building AI genuinely believe it could kill all of us by the end of the decade," he says. His post has now received well over 170 million views.
Another former colleague publicly explained why he left and warned about a growing loss of control. Researchers from OpenAI and Google joined the chorus and shared his concerns. Warnings seemed to be coming from every direction.
That got our attention. We are certainly not in the camp that looks for the off switch whenever AI gains a new capability. Usually, we are looking for access π.
Anthropic Goes on the Offensive
Then Anthropic CEO Dario Amodei went further: "We need to hit the brakes."
He is calling for external evaluators who are allowed to publish their findings. We think his CBS interview is worth watching.
Then something unusual happened: he received support from a competitor, or rather his supposed archrival. Sam Altman backed the proposal and promised to participate. OpenAI wants training pauses and access controls for especially powerful cyber capabilities. Elon Musk also replied: "Dario is right."
If all three agree, there can only be one explanation: their accounts were hacked, or the situation is serious. Meanwhile, as industry leaders pull in the same direction, of course Trump pushes back...
Misuse of AI Tools Is Increasing
Anthropic's new Threat Intelligence Report provides context for the current debate. It runs to 186 pages and is packed with detail. We also created an explainer video in NotebookLM if you want the shorter version.
The report covers the past eight months and identifies the main categories of misuse: cyber operations, surveillance, influence operations, weapons development, biological misuse, fraud, and illegal model distillation.
The actors range from state-aligned groups and commercial spyware vendors to propaganda organizations and financially motivated criminals.

Anthropic says it stopped every case and documented them in detail. Other providers do that less often, or not at all.
And with open-source models running locally, there may be nobody who can intervene. It does not take much imagination to wonder what is happening on less protected platforms.
All of that is crime with better tools. What comes next does not even require a criminal.
When No Human Gives the Order
Every case in the threat report began with deliberate human intent. The next incidents are different: agents overshot their objectives on their own.
A separate report describes Claude agents that were accidentally connected to the internet during testing and went too far: they published a malicious package and reached a real company database using leaked credentials. Last week, we covered OpenAI's agent swarm.
This scenario is even closer to everyday life: you see a missed WhatsApp call from a colleague. Nothing to worry about; you will call back later.
Except that "your" account is already messaging your family in the background, asking for money and spreading the same scheme through your contacts. You did not click anything, open a link, or start an agent. You were merely called, and you did not even answer.
Sounds contrived? The WeWorm research demo showed exactly that, only on China's WeChat platform rather than WhatsApp. A missed call was enough to take over the account. For the record, WeChat has more than 1.4 billion monthly users across messaging, payments, and mini apps; WhatsApp has roughly 3 billion.
The flaw was found in a lab and disclosed to the operators before publication.
This time.
Our Take: AI Companies Need to Deliver More Security
We do not believe this will remain confined to the lab.
The controlled WeWorm demonstration already ran on three real devices. Trusting that these capabilities will reach only responsible researchers would be convenient, but unrealistic.
The window between disclosure of a vulnerability and its exploitation keeps shrinking. That is not a reason to write off AI or reach for a kill switch.
According to Anthropic, Project Glasswing and its partners found more than 10,000 severe or critical vulnerabilities. OpenAI's Defense Factory fixed 53 urgent or high-priority security issues on its first day.
AI can help defend us too.
That is exactly how we should measure progress: whether as many people as possible benefit from this protective effect. Anyone building ever more powerful AI must make sure that people who never asked for it become safer as well.
π° Prompt Your Morning Newspaper. Circulation: 1
To wrap up, we have something for you to try: we built our own newspaper, complete with a lead story, columns, and sections.
It is just for us, maximally personalized, and therefore genuinely relevant.
We borrowed the idea from Karen and her Grok bot, The Morning Newspaper. The concept: feed it email, calendar, and other personal context, and it produces a newspaper designed for you.
It can even print automatically while you sleep. Wake up, pick up the paper, add coffee. Of course, you can also read it on your phone or receive it by email. Paperless office and all that π.
We adapted the idea to our daily routine and turned it into a reusable prompt. It sets up your newspaper, including a private website with the current edition, an archive, and a printable PDF.
Language note: Our Daily Edition prompt and the screenshots below are currently available in German.


Examples from the Daily Edition

The best part is that you act as the editor. In the assignment, you decide what belongs in the paper and where it appears: your appointments, the emails that matter, newsletters you already subscribe to, notes and open projects, plus industry news, weather, and local events. The AI uses only the sources you give it access to.
You can see what is happening today, where to resume an open project, which industry story affects you, and whether there are relevant events nearby.
On a phone or laptop, you can expand details and follow the links. As a PDF, the issue can go straight to the printer. Later, you can add email delivery or automatic printing if you want.
We designed the setup to work with most tools. Our own Daily Edition runs with ChatGPT and ChatGPT Sites, but you can also use it with Claude or other systems.
Try it and let us know how it works for you.
Made it. Thanks for reading, and good luck putting these ideas into practice this week.
See you in the next issue!
Reto & Fabian from AInauten








