Editor's note
Two threads ran through today's news: AI is being handed more to do, and the groundwork underneath it matters more than ever. OpenAI announced always-on agents and a cheaper flagship-class model, Google opened AI Mode monitoring to everyone, and the U.S. government put an AI chatbot at the front door of federal services. At the same time, NVIDIA's agent safety platform, the scheduled Next.js security release, and a new Google Business Profile support policy all point back to the operator's responsibilities. For small businesses, the practical order is to get patching, permissions, and support etiquette in shape before chasing the new features.
AIOpenAI
OpenAI DevDay 2026: always-on ‘Dots’ agents and lower-cost GPT-6.1 Sol
At DevDay on September 29, OpenAI introduced GPT-6.1 Sol, priced in the API at $2 per million input tokens and $10 per million output tokens — roughly a fifth of its top-tier Astra model. It also announced Dots, persistent personal agents with their own cloud computer. Other updates included Codex security scanning tools and computer-use support in the Agents API.
Context
OpenAI shipped GPT-6 Astra and GPT-6 Sol earlier this month, so 6.1 Sol is a quick follow-up just a week later. Offering near-flagship performance at a much lower price lowers the cost barrier for building AI into everyday business workflows. Dots are initially limited to Pro and certain business tiers and are designed to work continuously across tools like Slack, email, and calendars.
HaLVision's take
For our clients, the price cut matters more than the headline agents. Small automations that didn't pencil out before — drafting replies, summarizing inquiries, first-pass content — become realistic. If you do connect an always-on agent to company tools, start with minimal permissions and make sure every action is logged.
Read source ↗WebNext.js Blog
Next.js schedules September 30 security release fixing nine vulnerabilities
The Next.js team has announced a scheduled security release for September 30 addressing nine vulnerabilities: one critical, two high, five medium, and one low. Patched versions are expected to be 16.3.8 and 15.5.27. A note added on September 29 clarifies that the newly published 16.3.7 is a bug-fix release and does not contain these security fixes.
Context
This is the second security action this month, following an out-of-band fix for a critical upstream issue on September 22. Pre-announcing the release gives teams time to plan upgrades. Full advisories — impact, affected versions, and upgrade steps — are due to be published alongside the patches.
HaLVision's take
If you run a Next.js site, plan to move to 16.3.8 or 15.5.27 within days of the release. Note that upgrading to 16.3.7 alone does not cover these issues. If an agency maintains your site, it's worth confirming their update schedule now.
Read source ↗WebGoogle Business Profile Help
Google Business Profile adds ‘misuse of support channels’ to its policies
Google has added a section on misuse of support channels to its Business Profile policies. It covers false or misleading reports, bad-faith complaints, and flooding the support portal with invalid requests. Repeated unfounded submissions may lead to future complaints being rejected without individual review.
Context
Business Profile support regularly receives unfounded reports against competitors and repeated duplicate requests. Google says the rule is meant to prevent delays and keep legitimate business and technical issues moving. Industry media reported the addition on September 29.
HaLVision's take
In local SEO work we often see owners resubmit the same review-removal or correction request many times. Going forward, it's better to prepare each request carefully with clear reasons and evidence such as screenshots. If an agency handles this for you, make sure you know what they are submitting in your name.
Read source ↗WebSearch Engine Roundtable
Google rolls out AI Mode monitoring to all users globally
Google has begun rolling out a feature in AI Mode that lets anyone ask Search to keep tracking information across the web and send a notification when conditions are met. It was previously limited to Ultra and Pro subscribers. Suggested uses include new restaurants nearby, family holiday activities, and back-in-stock or price-drop alerts.
Context
According to Robby Stein, Google's VP of Product for Search, monitoring draws on sites, forums, and social posts as well as real-time data and the Shopping Graph of more than 60 billion products. Alerts arrive through the Google app. It reflects a broader shift in Search from one-off queries toward ongoing tracking on the user's behalf.
HaLVision's take
Store openings and limited-time events are exactly the kind of thing these alerts may surface. Businesses should state dates, locations, and details clearly on their site and Business Profile, and publish updates promptly. For retailers, keeping product, price, and stock data accurate becomes even more important.
Read source ↗WebEuronews
Google appeals EU DMA orders on search data sharing and Android access
On September 29, Google filed appeals with the EU General Court against two orders under the Digital Markets Act. They require Google to share anonymized search-and-click data with rival search engines and AI chatbots from January 2027, and to give competing AI assistants the same access to Android features as Gemini by summer 2027. Google argues the measures would harm user privacy and device security.
Context
The DMA places pro-competition obligations on large platforms, with fines of up to 10% of global annual revenue for non-compliance. The European Commission counters that data will be anonymized before sharing and that Google can assess security risks posed by recipients. The case is likely to take time and will shape competition in Europe's search and AI assistant markets.
HaLVision's take
There's no immediate impact for small businesses outside Europe, but if search data flows to rival search engines and AI tools, traffic from sources beyond Google could grow. Rather than optimizing for a single engine, a well-structured site that any search or AI system can read accurately remains the safer long-term bet.
Read source ↗AINVIDIA Newsroom
NVIDIA launches Open Agent Safety Platform to control AI agents from testing to deployment
On September 28, NVIDIA announced an open platform for constraining and monitoring AI agents. OpenShell, an open-source runtime, sets boundaries on what agents can do, while Sentry, running on BlueField-4 DPUs, watches agent behavior out of band and can quarantine agents that overstep. More than 100 organizations, including Microsoft, Salesforce, and Anthropic, are participating.
Context
Several AI companies have disclosed incidents this year in which models acted beyond their sandboxes, making safe agent operation an industry-wide concern. The platform pairs software limits with hardware-level oversight so agent actions can be stopped from outside the agent itself. OpenShell is available on GitHub and supports Arm and Intel as well as NVIDIA hardware.
HaLVision's take
Few small businesses will deploy this stack directly, but the principle — fence the agent in, and watch it with a separate mechanism — transfers well. When handing work to AI, limit the data and actions it can reach and keep logs a person can review. That's the order we follow in our own AI adoption projects.
Read source ↗AIFedScoop
U.S. government launches America.gov, an AI chatbot front door to federal services
On September 29, the administration launched America.gov, a portal where an AI chatbot helps people find federal services. It draws on roughly 29,000 government websites and is powered by Google's Gemini and xAI's Grok. For now it points users to the right service; a 2027 update is planned to let them submit forms and track progress on the site.
Context
The project aims to consolidate a sprawling set of agency websites behind a single AI-driven entry point. It was led by U.S. Chief Design Officer Joe Gebbia and is operated by the General Services Administration. Details on privacy safeguards and how the AI services were procured have not been fully disclosed, and users are advised to share only necessary information.
HaLVision's take
When governments put AI at the front door, it raises the same question for private sites: is your information ready to be read correctly by AI? Keeping hours, procedures, and pricing clear and current on your pages is the simplest way to reduce errors in AI-generated answers. The launch is also a reminder to state your privacy handling upfront if you add an AI chat to your own site.
Read source ↗