This week actually has teeth. The biggest development for marketers is OpenAI turning ChatGPT advertising from “there are ads in ChatGPT now” into something much stranger and potentially more consequential: the ad itself can lead into a branded AI conversation, while campaign creation and analysis increasingly happen through natural language.
Meanwhile, Google is finally giving retailers first-party visibility into how they appear in AI Mode and AI Overviews, Gemini’s newest live models make voice workflows more capable, and WordPress shipped a security release we should not procrastinate on.
There’s also a coding-agent security issue worth paying attention to precisely because Claude Code, Codex and similar tools are becoming real development infrastructure rather than toys.
1. ChatGPT Ads are becoming conversational — and HubSpot and Shopify are getting plugged in
On September 16, OpenAI announced its biggest expansion of ChatGPT Ads since the channel launched.
The most interesting piece is Sponsored Agents. After clicking an eligible ad, a user can choose to start a clearly labeled conversation with an agent sponsored by that business. Instead of the traditional:
ad → landing page → hunt around for information → convert or leave
the experience can become:
ad → conversation with the business → questions answered → website/action when ready
Sponsored Agents are currently being tested with select U.S. advertisers, so this is not yet something every client can launch tomorrow.
OpenAI also announced several changes on the advertiser side. Advertisers can create, update and analyze campaigns using natural-language prompts through the Ads Manager plugin in ChatGPT. There is an opt-in feature that adapts existing headlines and descriptions to the context of a conversation and automatically translates copy into the user’s preferred language.
And the plumbing is starting to get interesting: HubSpot is OpenAI’s first CRM partner and Shopify its first ecommerce partner for ChatGPT Ads.
Why it matters
This isn’t just another ad placement.
Conversational ads potentially collapse several stages of the funnel into one environment. A user could discover a service, ask detailed questions about pricing or fit, clarify objections and only then visit the advertiser.
For agencies, that creates a whole new optimization problem.
The quality of the agent’s knowledge, answers, product/service data, escalation logic and conversion path may eventually matter alongside bidding, targeting and creative.
In other words, somebody is going to have to optimize the robot salesperson. Congratulations to all of us. 😂
The HubSpot integration makes this particularly relevant for B2B agencies because CRM context and advertising are starting to meet inside an AI-native channel.
What to try
We can’t broadly deploy Sponsored Agents yet, but we can start thinking about what one would need.
Take a client with a complicated buying journey and identify:
- the 20 questions prospects consistently ask before converting
- the objections sales repeatedly handles
- which CRM/product information an agent would need
- which questions should trigger a human handoff
- what constitutes a conversion from an AI conversation
For advertisers already eligible for ChatGPT Ads, the natural-language campaign management and AI creative features are worth testing now.
Agency implication
This is potentially a new service category: conversational advertising strategy + agent knowledge design + CRM integration + conversion optimization.
That’s much more interesting than simply adding “ChatGPT Ads management” beside Google and Meta on a service page.
2. Google is now showing retailers how visible they are in AI Mode and AI Overviews
On September 16, Google made AI performance insights in Merchant Center generally available to businesses in Australia, Canada, India, New Zealand and the U.S.
Retailers can see how their brand and products are being discovered across AI Mode and AI Overviews, including share-of-voice comparisons against competing brands.
This is one of those developments that sounds modest until you remember how much of AEO has consisted of:
“We appear to be showing up in the robot. Take a screenshot before it changes.”
Now Google itself is beginning to expose competitive AI-discovery metrics inside the merchant stack.
Google also opened a U.S. beta for Business Agent in YouTube ads, allowing viewers to ask questions about an advertiser’s products without leaving the video experience. Its Universal Commerce Protocol integration hub is adding cart transfer and enhanced checkout-flow testing, with analytics still to come.
Why it matters
For ecommerce clients, AI visibility is becoming a measurable marketing surface rather than purely an SEO curiosity.
Traditional SEO reporting asks where the site ranks. AI-commerce reporting increasingly needs to ask: Does the AI know the product exists? When does it recommend it? Against which competitors? Does the product data contain enough information to answer conversational buying questions?
Google explicitly points merchants back toward product-feed quality, including conversational attributes and loyalty information. That reinforces something we’ve been watching for months: structured product information is becoming useful not merely for Shopping feeds but for machine-mediated product discovery.
What to try
For ecommerce accounts, open Merchant Center and inspect AI performance insights. Look for:
- brand share of voice
- product visibility
- competitors appearing in the same conversational discovery space
- weak or incomplete product attributes
- questions the feed does not currently answer well
I would also start saving baseline measurements now. Six months from now, having historical AI-discovery data could be substantially more useful than wishing we’d started measuring it earlier.
Agency implication
AI commerce visibility audits are becoming increasingly legitimate.
This can sit between ecommerce SEO, Merchant Center/feed optimization and paid Shopping rather than becoming another fake standalone “GEO package” assembled from screenshots and incense.
3. Gemini 3.8 Live brings stronger real-time reasoning into Workspace — and makes voice agents more interesting
Google released Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking on September 15.
The distinction is useful: Gemini 3.8 Live is optimized for scale, cost efficiency, fluid dialogue and visual grounding, while Extended Thinking adds more intelligence and multi-step reasoning for complicated live interactions.
For Workspace users, the interesting part is that Extended Thinking is available through Docs Live, Gmail Live and Keep Live. Google is also positioning the models as infrastructure for production voice agents through the Gemini Live API and Google AI Studio.
Why it matters
I’m not particularly interested in “AI talks more naturally now” as a weekly marketing headline.
The operationally interesting part is voice becoming another interface for agentic work.
Instead of voice being glorified dictation, these models can reason through multi-step tasks while maintaining a real-time conversation. That potentially matters for things like:
- hands-free document and email workflows
- client-facing support or intake agents
- interactive sales qualification
- internal knowledge assistants
- guided onboarding
- spoken QA or review workflows
The Workspace integration is especially worth watching because it removes another layer between the person giving instructions and the documents or email where the work lives.
What to try
If your account has access, don’t test this by asking Gemini about the weather.
Give Docs Live or Gmail Live an actual multi-step work task and deliberately talk through revisions, constraints and follow-up decisions rather than issuing a single command.
For development experimentation, the more interesting question is whether the Live API can support a genuinely useful customer-facing voice workflow without requiring callers to endure the familiar “AI receptionist trapped in purgatory” experience.
Agency implication
Voice-agent implementation is becoming more plausible as a sellable capability, particularly for clients with high-volume intake, qualification or customer-service workflows.
I would still treat this as an emerging capability, not rush out a “WE BUILD AI VOICE AGENTS” landing page Tuesday morning.
4. WordPress 7.1.1 fixes 11 security issues
WordPress 7.1.1 shipped September 17 with 17 Core fixes, 19 Block Editor fixes and 11 security fixes. WordPress recommends updating immediately.
The security fixes include stored XSS issues, an authenticated path traversal in the REST Templates Controller, arbitrary post overwrite by Contributor-level users, information-disclosure problems, and a flaw where specially crafted URLs could automatically install and preview an inactive theme from WordPress.org.
Interestingly, Anthropic is credited with reporting two of the vulnerabilities.
Why it matters
This applies directly to ordinary self-hosted WordPress.org sites, including custom-theme and ACF builds.
It’s also a useful reminder that core security updates matter just as much as plugin updates — especially for agencies maintaining a large portfolio of client sites.
What to do
Update managed sites to WordPress 7.1.1 or the appropriate security-backported version now.
Sites with automatic background updates may already have received the patch, but verify rather than assuming.
No agency positioning exercise required. Patch the damn sites.
5. Coding-agent plugins just gave us another reason to treat agents like development infrastructure
Security researchers disclosed Plugin4Shell this week, affecting plugin installation in several major coding agents.
The issue involves plugins supposedly pinned to a reviewed Git commit. On certain Git hosts, an attacker controlling the repository could make the agent retrieve different code while still appearing to use the pinned version. Because plugins execute with the user’s permissions, malicious plugin code could potentially access files, credentials and connected systems.
The practical status matters more than the scary name: Claude Code is patched in 2.1.179 or later; OpenAI Codex is patched in 0.146.0 or later; GitHub Copilot had no fix at disclosure; and Google is retiring Gemini CLI rather than patching this issue.
There is an important limitation: the demonstrated hash/branch-name attack does not work against GitHub-hosted repositories in the same way because GitHub prevents the relevant branch/tag naming trick. Anthropic’s default Claude Code marketplace is GitHub-hosted. So this is not “everyone using Claude Code was secretly compromised.”
Why it matters
Coding agents increasingly have access to exactly the things we don’t want compromised: source code + local files + deployment credentials + hosting + Git + shell access.
Plugins and agent extensions therefore need to be treated more like executable development dependencies and less like browser extensions we install because somebody on Reddit said they slap.
This is especially important as teams begin building shared Claude Code environments and internal plugin ecosystems.
What to do
Verify developers are running Claude Code 2.1.179+ and Codex 0.146.0+.
Review installed third-party plugins, particularly anything sourced outside default GitHub-hosted catalogs.
And as we standardize agentic development workflows, include agent/plugin version management in the same operational hygiene as dependency updates and credential handling.
Agency implication
Not a new service package, but absolutely part of responsible AI-development governance.
The more autonomy we give coding agents, the less defensible “it’s just an AI assistant” becomes as a security model.
6. ChatGPT Work’s Data agent is worth a look for marketing analytics — with one caveat
This technically landed September 10, so it’s just outside a strict seven-day window, but I’m including it because it wasn’t in last week’s brief and it maps unusually well to marketing operations.
OpenAI’s new Data agent in ChatGPT Work connects to governed company data sources, investigates changes in metrics and can turn the analysis into interactive dashboards without requiring users to write queries. It supports sources including BigQuery, Redshift, Databricks, Snowflake, MongoDB and ClickHouse, plus files from Google Drive and SharePoint.
More importantly, it can work with existing semantic/business definitions and permissions, and can create or interact with dashboards in tools including Power BI, Tableau, Sigma and ThoughtSpot.
OpenAI says more than two-thirds of its own go-to-market organization uses the underlying data-agent capabilities, and cites customers using it for sales, spending, campaign adoption and performance analysis. Those are vendor-reported examples, not independent performance benchmarks.
Why it matters
“Ask questions of your data” is ancient in AI years.
The more interesting development is the combination of governed company data + semantic definitions + investigation + visualization + downstream action inside one conversational workflow.
That starts to overlap with work normally spread across analysts, dashboards and ad-hoc reporting requests.
What to try
If you’re using ChatGPT Work and have a useful supported data source, test it on a question where the answer requires investigation rather than retrieval:
“Why did qualified leads decline last month despite traffic increasing?”
Then inspect its evidence and compare the answer against the existing analytics workflow.
Do not evaluate this based on whether it makes a sexy dashboard. Evaluate whether the numbers and causal interpretation survive human scrutiny.
Agency implication
If tools like this work reliably, dashboard production itself becomes less valuable.
The more durable agency skill becomes measurement architecture, trustworthy definitions, interpretation and deciding what action follows from the data.
What we should actually do this week
- Start designing for conversational ads before they become boring. Pick one complex client offering and map the questions, objections, data and conversion logic a Sponsored Agent would need.
- Check Merchant Center AI performance insights for ecommerce clients. Capture baseline AI Mode/AI Overview share-of-voice data and look for feed gaps that could be suppressing discovery.
- Patch WordPress to 7.1.1 across managed sites. Verify it actually happened rather than trusting the warm embrace of automatic updates.
- Update coding agents and audit plugins. Claude Code ≥2.1.179; Codex ≥0.146.0. Treat agent extensions as executable dependencies.
- Test Gemini 3.8 Live on an actual multi-step workflow if your account has access. The useful experiment is whether voice reduces friction in real work, not whether Gemini can maintain charming banter.
- Try the ChatGPT Data agent on one real marketing-performance question if your ChatGPT Work configuration and data stack support it. Judge accuracy and investigative usefulness, not dashboard prettiness.
The bigger pattern
Something changed this week that I think is more important than any individual product announcement.
AI is moving closer to the transaction.
Google is measuring whether products appear in AI-mediated discovery. OpenAI is putting business-sponsored agents between the ad impression and the website. Google is putting conversational product agents inside YouTube ads. Analytics agents are moving from describing dashboards toward investigating the underlying business question.
That means marketers increasingly aren’t optimizing only pages and campaigns.
We’re beginning to optimize the information and systems AI uses to represent the business: product feeds, CRM data, semantic definitions, agent knowledge, structured content, conversion signals and the rules governing what an agent can actually do.
Meanwhile, the WordPress and Plugin4Shell stories are the less glamorous half of the same transition. The more authority we hand software agents, the more seriously we have to treat their permissions, dependencies and supply chains.
So the interesting agency advantage isn’t “we use AI.” Everybody uses AI now.
It’s increasingly: we know how to make the systems feeding the AI trustworthy, measurable, useful and safe — and we know what to do with the result.
Sources
- OpenAI — Reimagining advertising with AI
- Google — Boost your holiday sales with these agentic commerce updates
- Google — Introducing Gemini 3.8 Live and 3.8 Live Extended Thinking
- WordPress.org — WordPress 7.1.1 Maintenance and Security Release
- Air Security — Plugin4Shell
- The Hacker News — Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
- OpenAI — Now everyone can put data to work