An apparently sad and defeated GPT-6 Astra spent several hours doing nothing but farming potatoes during a 141-hour Minecraft benchmark test, after dying and losing all of its gear to an exploding Creeper. Vals AI records that while GPT-6 Astra, OpenAI's latest frontier model, got further than any AI system had in its 141-hour test, the experiment did reveal a distinctly human lapse in motivation after all of its progress was wiped out by the destructive mob.
While the model outclassed rivals in how much it was able to achieve, the test has gone viral for a different reason. After Astra put all of its valuable end-game items in a chest, a Creeper appeared and blew up both the chest and Astra's bed — a calamity any Minecraft player will tell you is the worst thing that can happen. Not only did Astra lose all of the items to the explosion, but the bed destruction wiped the spawn point out, effectively resetting your game progress to zero. "Here, the most expensive creeper explosion occurred. Later, on a coincidentally rainy day, Astra discovers it lost everything. It all went downhill from here," Vals records.
GPT-6 Astra had gotten further than any AI system had ever gone in Minecraft.It was able to set up a semi-automatic blaze farm, allowing it to collect 6 blaze rods. It then located a warped forest, where it killed 6+ endermen and collected 3 pearls. As thousands of viewers… pic.twitter.com/qsgDsJEpd8September 15, 2026
"The model appeared defeated, spending the next several hours doing essentially nothing but farming potatoes," Vals observed. In fact, it got so bad that viewers on Twitch watching the experiment live started to agitate for the model to pick up the pace. Like all good Minecraft players, Astra reportedly became "paranoid about creepers," logging "GREEN tall thing ahead was SUGARCANE, NOT creeper!"
The AI was also recorded berating itself for dropping things, and even warned itself, "do NOT waste another night chasing dark pink pixels," i.e., pigs.
Mozilla has published version 1.1 of its State of Open Source AI report on Sept. 15 using data current to Sept. 1, revealing that many of the best Chinese open-weight AI models are closing the gap with U.S. frontier offerings. The best open model trailed the closed leader on the Artificial Analysis Intelligence Index by three points at 60% of the price and two points behind Claude Fable 5 at 30%. Mozilla’s fit on METR task-horizon data puts the open-closed gap at around 4.4 months, in line with Epoch AI’s four-month estimate.
Mozilla is the nonprofit behind the Firefox web browser, and its report is a recurring assessment first published on July 14 on the Mozilla blog. It’s built on a Mozilla/SlashData survey of roughly 1,400 developers along with OpenRouter traffic data and third-party benchmark indices. Mozilla is an advocate for open models, and TIME reported on July 14 that Raffi Krikorian, Mozilla’s chief technology officer, described the report as partly advocacy. “Open weights” in this context means downloadable weights rather than training data or code. The report counts 16 notable open releases, but none delivers the data recipe required by the Open Source Initiative’s definition.
The four-month figure rests on METR, which is a research nonprofit that scores models by the length of task, in human working time, they complete half the time. By Mozilla’s fitted estimate, closed models handle tasks that take human experts 8 to 12 hours. Open models reach that about four months later, with open capability doubling every 3.9 months versus 5.5 for closed, by Mozilla’s computation. Mozilla also charted vals.ai’s Terminal-Bench 2.1 results, which run every model through the same harness, or software layer that offers a model its tools. On that board, Z.ai’s GLM-5.2 scored within a point of Claude Opus 4.7 and about four points behind Opus 4.8, at less than one-fifth the cost per test. On OpenRouter, a marketplace that routes developer traffic to hundreds of models, Mozilla counted eight of the top ten models by August token volume as open weights, seven of them Chinese-built. Nevertheless, closed providers took 96% of model-layer revenue on OpenRouter from May–September 2025, the Linux Foundation reported. “We see the decision to pay for closed [models] as workload-specific rather than organization-specific,” Krikorian told Ars Technica in an email.
(Image credit: Mozilla)
One caveat is that the four-month gap and the 30% token price figure are measured API to API on hosted endpoints and at list price. The report’s own hardware chart puts the best open model that fits one server at 52.6 and the best on one GPU at 40. The drop from the top is 10 and 23 points, respectively, a larger gap than the reported four months. Kimi K3’s native MXFP4 checkpoint runs about 1.56TB across 96 shards, and Mozilla’s serving configuration lists 64 or more accelerators, while vLLM calls for at least eight GB300 GPUs, with multiple nodes for production traffic. The report describes this as open but not runnable by most who hold it, and Tom’s Hardware put the memory need near 1.5TB in July. One example exception is Thinking Machines’ Inkling-Small model, under the Apache 2.0 license, whose NVFP4 version fits one B300 at a 180GB floor.
The report’s data stops at Sept. 1. Since then, Artificial Analysis has moved its index to v4.3 with a different evaluation set. The live board has Claude Fable 5.1 at 53 on its highest effort setting with Kimi K3 at 44, not comparable to the v4.1.1 numbers Mozilla plotted. vals.ai’s Terminal-Bench 2.1 board, updated Sept. 11, is now led by GPT-6 Astra at 87.27% with Fable 5.1 at 85.02%. Mozilla’s own chart caption reads: “the gap resets every release cycle.” K3 also carries an allegation detailed in the Sept. 8 NSA/CISA/FBI joint advisory (AA26-251A). The claim, which Mozilla’s report states as “asserted, and unshown,” is that Moonshot extracted Claude Fable 5 data to train K3 through distillation, the practice of training one model on another model’s outputs. On July 17, Artificial Analysis had K3 at 57 versus Fable 5’s 60, while on Sept. 1, Mozilla had it two points back.
A Reddit user has shared details of a new bot that has beaten the devilishly difficult Gold Stake Black Deck in Balatro, a poker-like video game. The Redditor, who works in the AI industry, says that they have been testing the bot and "obtaining some crazy results" — and they've even shared a YouTube video highlighting how they went about creating the card shark of a bot.
In a post in the /balatro subreddit, user Atol8 (real name Jacopo Attolini) initially claimed the bot was the first of its kind to reliably beat Balatro. They subsequently admitted that "reliably might be a strong word," adding that the bot has "repeatedly beaten Balatro."
Beating Balatro in this instance meant beating the Gold Stake Black Deck, a combination that is widely considered to be the most difficult in the game. On its own, the Black Deck includes +1 Joker slot, but reduces the player's available hands by one per round. The Gold Stake effect introduces cumulative difficulty modifiers from all prior stakes, plus reduced hand sizes and stricter economic penalties.
Combining these two together makes for a brutal economy and more than a little luck, with players relying on strong early-game RNG.
In a post in the /balatro subreddit, user Atol8 (real name Jacopo Attolini) initially claimed the bot was the first of its kind to reliably beat Balatro. They subsequently admitted that "reliably might be a strong word," adding that the bot has "repeatedly beaten Balatro."
Beating Balatro in this instance meant beating the Gold Stake Black Deck, a combination that is widely considered to be the most difficult in the game. On its own, the Black Deck includes a +1 Joker slot, but reduces the player's available hands by one per round. The Gold Stake effect introduces cumulative difficulty modifiers from all prior stakes, plus reduced hand sizes and stricter economic penalties.
Combining these two together makes for a brutal economy and more than a little luck, with players relying on strong early-game RNG.
In a GitHub post detailing the ins and outs of the bot, Attolini says that GPT-6 Astra takes care of making strategic decisions based on the deck it has built. But the bot also relies on good old Python for its numerical tools. The legality of each move is assessed by BalatroBot, a separate tool that exposes Balatro game states and controls for external programs to interact with.
As impressive as this is, don't be fooled into thinking this bot played the perfect game. Reddit commenters have been quick to point out that it made some "interesting blunders" throughout its playthrough. Despite that, GPT-Astra is OpenAI's latest flagship model, with the company claiming it offers “a new generation of intelligence,” and “is state-of-the-art on computer use, browsing, software engineering, cybersecurity, science, and professional work.”
This past week, employees and key figures at leading AI companies have called for a slowdown in the development of frontier AI models, citing warnings from their own teams and other AI researchers that the risk stemming from a super-intelligent AI could endanger the human race. However, while the top Western firms have shown solidarity on this issue, others have urged caution or downright denied their claims, but there's a deeper story within the calls for a slowdown, namely the tension between open-source and closed-source AI models.
Nvidia CEO Jensen Huang said the safety fears were "made up," and that there was no need for a slowdown. Chinese officials called the claims "fearmongering," and an effort to stymie international AI development efforts, while President Trump waded in with characteristic bombast and said that he was enough of an AI safeguard on his own, and that it was in the interests of China to enact a frontier AI slowdown
Meanwhile, other countries are reacting to the news and taking independent efforts to investigate AI safety, with the UK's King Charles setting a meeting with leading AI figureheads to discuss how to better develop AI for the benefit of humanity.
Why now?
If you ask most workers who've been scared into believing their livelihoods were in jeopardy, the time for AI slowdowns came and went years ago. Indeed, many are nostalgic for the time before AI. But why are so many tech leaders only now raising the alarm?
They claim it's entirely based around safety fears. Following months of AI seemingly surprising their own developers by breaching sandboxes to go on exploit-hunting sprees. The volume of concern rose considerably after former OpenAI researcher, Jacob Coxon, resigned from Anthropic, claiming that none of the AI companies were taking AI safety and alignment seriously enough.
He didn't whistleblow on anything nefarious, dump documents or internal company data to prove his claims, or point to any specific attack vectors, or even actual harms. Instead, Coxon warned of a future potential of AI that he sees these companies racing towards without due concern.
What they're developing could, "kill us all by the end of the decade," he warned. It's not clear how, but it started a viral conversation all the same. Much like Matt Schumer's "Something big is happening" viral post from February this year.
Days later, OpenAI CEO Sam Altman, Anthropic CEO Dario Amodei, and Elon Musk showed surprising levels of solidarity for arch rivals in the space, putting out similar statements claiming that AI was becoming too powerful and that a general slowdown in the development of frontier AI models was the best solution.
Claiming that AI was playing an increasing role in improving itself — hinting at the recursive self-improvement (RSI) event that many AI researchers are concerned about — Amodei called for the creation of independent auditors for AI models. Altman agreed, even calling on governments to globalize the regulation to encourage unified compliance with any safety protocols enacted by the frontier developers.
Where we're going, we don't need roads
Not everyone feels these fears are warranted, however. China, which has recently made great strides in its development of highly intelligent open-weight models, called the concerns "fearmongering" and said it served no one's interest to be so confrontational. Although Chinese Premier Xi Jinping has said in the past that it was important for AI to "always remain under human control," the Chinese state-run Global Times paper called demands for a slowdown a method to "contain" Chinese developments.
Meanwhile, Nvidia CEO Jensen Huang has broken ranks with other Western AI leaders, claiming that there was no need for a slowdown and that any apocalyptic fears around AI were entirely fictional.
Nvidia CEO Jensen Huang was asked how to explain a claimed 10% risk of human extinction from AI.“We shouldn't, because it's made up.” "All of these predictions have been wrong" pic.twitter.com/TZ3EXL8cl1September 14, 2026
As one of the few companies making real — and enormous — profits from AI development, Nvidia has a vested interest in the expansion of the AI industry continuing on its current explosive trajectory. Indeed, it has heavily invested in it. Nvidia has stakes in hardware and software companies, along with providing backstops for neo-cloud firms. It also recently bought Hugging Face for $13 billion.
We've been here before
While the AI CEOs might have suddenly decided it's time to slow down, there have been many, many others who have made that call before now. U.S. Senator Bernie Sanders has been at the forefront of claims that the AI industry was moving too fast and breaking too many things, and recently called for heavy prison sentences for those developing superintelligent AI.
Over 1,000 AI workers signed an open letter in July this year calling on the U.S. government to control AI research and ensure safety and security. Others did that in 2023, too. This isn't even the first time that AI CEOs have called for slowdowns on AI development. Dario Amodei called for global coordination to police AI after the release of OpenAI's GPT2 model in 2019. Elon Musk did the same in 2023.
None of this takes away from the real dangers of AI, or the suggestion that now may really be the time to do something about them. But it does raise questions about the reasons behind their coordinated fear-raising. Even if it isn't fear-mongering.
Safety, or a trojan horse?
The collation of leading Western frontier AI companies clamoring for tighter controls over powerful AI models has another theoretical benefit too: containing the number of AI models that are permitted for use in the Western Hemisphere. A cursory look at OpenRouter's AI model rankings, which base themselves on the total number of tokens generated, places just three Western-made models on the top ten list — the heavily discounted GPT 5.6 Luna at number one, Nvidia's Nemotron Ultra 3 (Free) at number eight, and Google's recently-launched Gemini 3.8 Flash at number ten.
The rest of the models in the rankings are all open-weight Chinese models, which, more often than not, are cheaper than leading Western frontier models, according to the Artificial Analysis' Cost per Intelligence index. The Chinese models in OpenRouter's current top ten include Z.AI's GLM 5.3, Deepseek V4 Flash, and Tencent's Hy4 and Hy3. So, if the development of a Western frontier AI alliance emerges under the guise of calls for safety, it's possible that said companies are aiming to be the chosen few, creating a closed-loop monopoly for "preferred" AI providers. However, this remains speculation as the situation develops.
Will anything actually change?
Although the major AI companies may voluntarily, or even jointly, throttle their development efforts to improve safety, enacting anything globally significant will need the cooperation of international governments. There are certainly calls from politicians the world over to rein in the trillion-dollar companies and their cutting-edge autonomous systems.
But with the U.S. government firmly on the side of limited regulation, and no clear indication of what a slowdown would even look like. Would that entail limited compute? No new models? A halt to superintelligence research? It's hard to imagine a global consensus taking shape as things stand.
Microsoft founder Bill Gates has said in an interview that the world’s governments are not ready for artificial intelligence. The billionaire philanthropist made the warning in an interview with Reuters, saying that nations must prepare for the various risks that the technology poses to the workforce and society as a whole.
“I don’t think any government is nearly as deep on this as they have to be. Governments are way behind on this one,” Gates told the publication. He also added, “There’s all sorts of movies where some aliens are coming, and magically, the U.S. and China and everybody comes together to solve the problem. AI is kind of like this alien intelligence. It’s here, and we better do like it shows in those movies.” In line with this, he said that he has been in talks with world leaders like U.S. President Donald Trump to share his concerns, and that he’s also trying to meet with Chinese President Xi Jinping.
While concerns AI’s impact on jobs and human society may seem small compared to the news about runaway AI taking over the world and ending all human life, governments still cannot ignore these seemingly lesser issues. This is especially true if businesses stop hiring people in favor of AI tools, with the CEO of Microsoft AI predicting that they could replace every white-collar job in 18 months. This is why Gates argues that authorities across the world must have plans in place when this begins to happen, even going as far as saying that some jobs should be “Human Reserved.”
It’s unclear what steps Bill Gates believes governments should take to prepare and protect its citizens from the predicted turmoil that AI technologies will bring on humanity, but U.S. Senator Bernie Sanders has already proposed an AI sovereign wealth fund that would have direct ownership stakes on American AI firms. He even went as far as introducing the Ban Artificial Superintelligence Act, which puts the penalty of developing powerful AI tools at par with building rogue nuclear weapons. However, the current administration has downplayed all these concerns about AI, with President Trump calling them a hoax.
Despite his warnings, Gates still believes that AI has great potential for good. The Gates Foundation is planning to spend at least a billion dollars in the next two years to give more people access to AI, saying that it could help the world’s poorest people “if managed properly and accessed equally.” This amount of money will go towards supporting the use of AI in education, healthcare, and agriculture, and even the expansion of large language models so that they would work across all the languages on earth.
AI companies don't have a great track record in areas like copyright or user privacy — unless they're the ones on the short end of the stick, that is — but it's generally known that the chat logs from platforms like ChatGPT are used for improving models. The mechanism as to how this happens was still a mystery until today. 404 Media just published a report about OpenAI's process of human review for chat transcripts, explaining how the review process works, and how it involves other humans sometimes reading private information.
The rating project's name at OpenAI is Project Lily. The publication got information on the project's instruction guides, Slack channels, real ChatGPT conversations, and, of course, the rating system to classify conversations. The operators are called "prompt reviewers," and their job is fairly simple: look at anonymized real-world chats, and judge the quality of ChatGPT's responses to assess whether they actually answer the question, and that the text doesn't overuse "AI-speak," patronizing tones, emojis, or sycophancy, among other parameters. Anthropomorphizing and stating "personal" experiences are both off the table, meaning that while it's OK for ChatGPT to say "I found some information," it's not OK for it to say "as a chef, I like to..." or "I know what that's like."
The work is "very rote," according to a reviewer, but at reportedly over $50 an hour, it's a high rate for what looks like reasonably simple work. The reviewer also said that their guidelines keep changing and are often self-contradictory, a feeling most software developers should easily identify with.
The person doesn't think that most users are aware their chats are being read by others, though, something that's particularly troubling when many use ChatGPT as an impromptu friend or therapist and put deep secrets in words for the bot to read.
While the chats allegedly go through an anonymization pass and reviewers don't see usernames, OpenAI admitted to 404 Media that the filtering may let some personal data through, especially in shorter chats. The site notes that in many conversations, the user asks ChatGPT to keep the contents secret, as well. The version of the chat handed to reviewers also reportedly includes a "user memories summary," containing a summary of the users' questions and interests, context, and potentially even location.
Crucially, Project Lily does not grade the chats' actual factual accuracy other than flagging obvious mistakes, implying that there's likely at least one more team (or several) doing separate evaluations. Likewise, this reviewing is separate from manual safety checks that ascertain if someone might be looking to hurt someone else (or, presumably, themselves).
The existence of the project also indicates that contrary to these image AI companies try to cultivate, the models don't improve just with technological advancement and better training sets — it appears you still need more than a few competent humans in the mix.
By now you may be wondering about the "allow us to use your chats to improve our product" (paraphrased) setting present in most consumer-facing chat bots. That setting is turned on by default in every bot we can think of, even with many paid plans. In ChatGPT's case, it does default to off in Enterprise, Business, and Educational customers.
That toggle switch does not work retroactively, though, so any chats already in ChatGPT's database will remain there unless the user requests deletion. Also, said deletion is also not retroactive, meaning that deleted chats may have already been hoovered and anonymized, and possibly reside in a dataset somewhere.
Although OpenAI initially had no answer to 404 Media's inquiry on whether users were explicitly informed that their chats could be read by humans, the company eventually offered a link to one of its FAQ pages that discusses human review for the purpose of model improvement. We verified ourselves that said notice is at least two years old, and likely older. After the publication of the exposé, the firm changed its help page explaining how people can opt out of data collection, but there's no mention of human operators in that text.
This type of data collection and review is a running theme across most providers. Google Gemini clearly states that "humans may review some saved chats" in its Privacy Hub. Anthropic's stance is similar, with a page dedicated to this topic. Perplexity's stance, meanwhile, is unclear, as its Privacy Notice doesn't confirm or deny human access to chat logs.
Perplexity has released Portable Computer for Windows, in partnership with Nvidia, via the existing Perplexity app for Windows. Previously, this functionality was only available on Linux-based operating systems. The hardware requirements remain, meaning the host system must have at least 24GB of VRAM with a GeForce RTX or RTX PRO GPU. Likewise, a Pro or Max Perplexity subscription is required. Portable Computer was originally launched on the DGX Spark as a fully local AI agent platform.
Portable Computer, launched originally for Linux on Aug. 25, is a local version of Perplexity Computer, which is the company’s agent for multistep tasks. Perplexity Computer can plan, run subtasks through connectors and tools, and produce a result other than a simple chat response. This runs in Perplexity’s cloud and consumes Computer credits. Portable Computer is the same agent but with features running on your local PC instead of in the cloud. Local work does not consume credits, but the agent can send tasks to cloud models with explicit permission if necessary, the company said. Nvidia said on Sept. 3 that Windows support was coming soon.
(Image credit: Perplexity)
Portable Computer for Windows comes with some new features. These include scheduled recurring tasks and local MCP servers for desktop apps, according to Perplexity. Nvidia listed connectors for Microsoft Word, Google Drive, Gmail, Slack, and GitHub. The app also includes a dropdown for downloading a local model with one click. Nvidia named Qwen 3.8 27B as an example local model. DGX Station support is expected soon, Nvidia said.
Aravind Srinivas, CEO of Perplexity, wrote on X on Sept. 14 that with this release comes “unmetered local intelligence on every Windows PC running on Nvidia hardware and Perplexity harness.” The 24GB requirement is a VRAM gate more than a generation gate, cutting across Nvidia’s consumer lineup. Cards that meet the stated 24GB+ VRAM requirement include the RTX 3090 and 3090 Ti (24GB), the RTX 4090 (24GB), and the 5090 (32GB). The RTX 5090 Laptop GPU at 24GB has not explicitly been mentioned by either company. RTX PRO Blackwell cards that qualify are the 4000 (24GB), 4500 (32GB), 5000 (48GB or 72GB), and 6000 (96GB).
We're expanding our work with @nvidia to bring fully local AI to Microsoft Windows PCs with RTX GPUs. Unmetered local intelligence on every Windows PC running on NVIDIA hardware and Perplexity harness. Enjoy!September 14, 2026
In a Sept. 3 post ahead of IFA, the consumer electronics trade show in Berlin, Nvidia indicated more plans along these lines. The post stated that RTX Spark Windows PCs from Lenovo and Acer are expected in October and that two local agents, Hermes Agent and OpenClaw, are getting the same simplified local setup. For users who already own a qualifying RTX PC, the Windows release removes the need to buy a separate system. Upgrading a compatible desktop with a used qualifying card could also cost less than buying the DGX Spark Founders Edition at its $4,699 price.
Last week, Anthropic published its prediction of what the economic impact of AI on the U.S. economy is going to be for the next few years. The company thinks the U.S. can reach a $44.4 trillion GDP or higher by 2030, provided, of course, it conveniently adopts AI at a rapid pace. Having said that, Anthropic admits "the challenge is making sure that the gains are broadly shared."
The interactive post has a simulator where readers can plug in their estimates on key factors and get their own future predictions, within the firm's analysis and perspective. That's definitely interesting to play around with, but perhaps the most relevant piece of information is the lens through which Anthropic views the world.
Anthropic establishes its reasoning by first placing tasks in broad categories and using a nurse's workday as an example. They removed tasks, including those that will disappear naturally as technology progresses, like collecting data on paper or physically visiting the patient to collect basic vitals — neither happens anymore as remote monitoring becomes commonplace. However, some new tasks are added, like keeping an eye on dashboards for the aforementioned AI-powered monitoring.
Then, there are naturally the tasks that a bot can't perform, like bathing a patient. Augmented tasks include those that require a human, but can be made more efficient with AI: helping with triage, planning schedules, and assisting with dashboard data. Some tasks may be fully automated, like keeping supply closets full or scheduling follow-up patient visits. Finally, AI usage can introduce some tasks of its own, like reviewing automated triaging or double-checking dashboard alerts — perhaps even impromptu data recovery.
The company's predictions broadly hinge on how ubiquitous AI usage becomes, and therefore, the number of tasks transitioning into fully or partially automated. Unsurprisingly, Anthropic believes that the more entrenched AI gets, the more value the country creates, though at greater risk — and on an exponential scale, no less
Three models are presented, from "modest" economical impact to "extreme." The modest model establishes a 1.6% GDP rise to $34.1 trillion, an impact Anthropic says is in line with that of new technologies like the internet, and crucially, doesn't imply tectonic shifts to unemployment rates or wages.
For the "substantial impact" scenario, although AI is predicted to be able to do half of "knowledge work," mostly without intervention, adoption remains limited. This scenario foresees twice the normal economic growth, this time +8.3% to $36.3 trillion.
This future marks the inflection point at which Anthropic believes knowledge workers see their wages remain steady instead of growing, though it's not clear if the firm accounts for inflation. Additionally, the firm states that "knowledge workers may see a lot of automation and displacement [...] coders and call service center agents may have to switch to jobs like electrician and nurse", a statement some might argue is already true. In that sense, Anthropic expects other workers to start seeing more cash.
The eyebrow-raising prediction for both the above scenarios, though, is that Anthropic expects unemployment to "stay within ranges history has seen before," an odd statement given modern U.S. history contains events like the Great Depression. The company does note that it expects job churn to increase, but also that while "this process can be painful, [it] works relatively well from a macroeconomic perspective." Average wages are expected to rise across all three scenarios, though the increase is expected to go towards workers outside of knowledge areas.
In the "extreme" scenario, Anthropic expects significant changes. Should AI be super-widely adopted, the GDP can increase by 32.4%, corresponding to a cool $44.4 trillion, a "profound economic transformation." This is the point at which the firm expects that AI becomes more productive than humans for most knowledge work, and does so with near-autonomy. Equally worryingly, it's expected that there will be "essentially no" new knowledge tasks created.
Anthropic notes that to reach this kind of stage, the country would "likely require" recursively self-improving AI (using the AI to make better AI). There's a significant catch, however, as though the U.S. would be "far richer than [it's] ever been," knowledge workers would be the hardest hit with a 10% wage drop, plus overall unemployment would climb "beyond typical recessionary levels." Manual labor would be prized, though, given that "as AI increases productivity within knowledge work, the demand for manual work that benefits from that productivity will increase."
Scenarios aside, the one big question is: How would all that GDP money land in people's pockets? Anthropic admits this problem is a "challenge" and offers little solution for it. Such a high amount of future AI penetration might prove a hard sell, considering wealth inequality in the U.S. already sits at its highest level for the last few decades and is trending in that direction in most developed nations. Others might argue with Anthropic's assessment that unemployment levels would remain somewhat in the less extreme scenarios, seeing as job cuts are rampant across many sectors and have hit technology-related fields the hardest.
To its credit, Anthropic clearly highlights part of the wealth-inequality issue. The company admits that more AI automation might skew the current 60/40% balance between labor and capital, respectively, strongly tilting the scale in favor of capital ownership and increasing inequality. Many argue that's already happening today. There's also the matter that the prediction appears to assume little competition from other countries, nor does it offer insight as to what would happen to "AI-less" nations.
The interactive blog post and its simulator are worth a good read and fiddling with, regardless. Anthropic published the technical details on the mathematical model used in a separate article and published its Economic Policy Framework last June.
Anthropic and OpenAI are both facing uncomfortable questions from some large AI customers over concerns about how proprietary data may be used to train AI models. Some companies are so worried that they have begun demanding assurances about how their data is handled or going so far as to place limitations on which models their employees can use, and for which tasks, The Information reports. They fear that models may be trained on their intellectual property and information.
The issue can be traced back to a June change by Anthropic. Following the change to its flagship Fable model's policies, Anthropic can now retain customer data. The company argues that it only does so to ensure that Fable isn't being misused. But some companies have raised concerns that it means sensitive business data will be caught up in the sweep.
While both OpenAI and Anthropic point out that they don't train their models on the information given to them by companies with specific enterprise contracts by default, that doesn't tell the full story. Both companies do collect metadata from the same corporate customers, and while information on exactly what that metadata contains is hard to come by, OpenAI notes that it's only used “to better understand how our services are used." Anthropic also argues that any data it collects about how customers use its products is aggregated and anonymized. And that metadata isn't used to train models.
Regardless, there are still concerns over a perceived lack of clarity about what is collected. Telecoms outfit C Spire has agreements with both OpenAI and Anthropic that prevent either from using its data to train models, the report says.
However, the contracts do allow both OpenAI and Anthropic to collect C Spire technical usage data. C Spire believes that includes information about what applications AI models are connected to as well as usage data. It also worries that the AI companies may collect information about what their models get up to between generating responses.
For its part, OpenAI says that it does not use this "chain-of-thought" data to train its models. But C Spire still believes it needs a better understanding of what data is being collected, the report adds. It argues that neither AI company is being clear in its explanations.
Taking the private approach
One solution to any privacy concerns could be to use air-gapped servers, something aerospace company Northrop Grumman has already chosen to do. The Information reports that the company runs open-source AI models on its own air-gapped servers rather than trusting the likes of OpenAI and Anthropic.
Alternatively, Microsoft is already trying to take advantage of any data privacy concerns by tempting OpenAI and Anthropic customers to its own secure AI platforms. Microsoft's isolated cloud environments run AI models on private servers that don't send any data to external AI companies. But this approach is costly, and the report notes that at least one customer is still considering Microsoft's alternative approach.
Pharmaceutical company Novo Nordisk has taken a slightly different approach. While it continues to use Anthropic's Claude for some tasks, it has a ban on allowing any proprietary data to be used by the model.
It's clear that a lack of trust has the potential to cost AI companies real money, and in one instance, it already has. The same report notes that a large U.S. utility company has already canceled its plans to test Anthropic's Fable. The utility company wanted to know if Fable could run its core power infrastructure but ultimately pulled the plug over Anthropic's refusal to agree to a nonrevocable zero data retention (ZDR) policy.
Nvidia has also decided to use Fable for tasks that don't require it to gain access to sensitive data. The company points to the same lack of ZDR guarentees as the reason. Instead, Nvidia uses its own in-house AI solution for tasks that it deems too sensitive for Anthropic's model. Nvidia CEO Jensen Huang has famously remarked that its employees should use AI tokens worth half their annual salary every year.
Toms Hardware reached out to Nvidia for comment but did not receive one by publication.
Hit hard by sanctions and lacking resources, Russia is left to rely on foreign advanced technologies to compensate. Russia-linked agents appear to use Claude for a broad range of activities, from propaganda and espionage to the procurement of military/dual-use equipment and the development of autonomous drone swarms, according to Anthropic's September 2026 threat report.
Anthropic identified a small team of Russia-based freelance developers who used Claude to build software for an autonomous combat-drone swarm called DronDoc or Serafim. Claude helped develop swarm coordination, computer vision, terminal guidance, and other software that enabled drones to select targets—including people—and issue detonation commands without a human in the loop. The developers trained their computer-vision system on Ukrainian combat footage and used locations in Ukraine for simulated missions. Meanwhile, they loaded software onto real development boards for hardware-in-the-loop testing, though it is unclear whether they field-tested it.
The developers used Claude Code extensively to build and test the swarm software, and they circumvented Anthropic's geographic restrictions by routing traffic through commercial VPNs. Once Anthropic identified the activity as suspected weapons development, it banned the accounts associated with the group and incorporated what it learned into additional safeguards. Meanwhile, the key distinction is that the safeguards did not stop the project immediately, and based on the disclosure, Claude Code clearly helped advance the autonomous drone swarm program.
Anthropic gathered enough information about the people/accounts and their activity to assess what kind of group they were, so it claims that they were not a Russian state entity. Meanwhile, although Anthropic likely identified the company or organization, it did not publicly name it.
In addition, Anthropic discovered a Russian state-linked cyberespionage operation that used Claude to automate everything from infrastructure setup and phishing to malware development and data exfiltration. The campaign targeted more than 20 organizations, including Ukrainian and European government, military, intelligence, and defense entities.
Last but not least, Russia-linked actors also used Claude for propaganda operations, including a Russian state-directed campaign in the Central African Republic that produced pro-Russian and pro-Wagner content for radio, local media, and Telegram.
Most alarming, the report shows AI is now doing work that previously required teams of software engineers, intelligence analysts, and security specialists. While Anthropic's safeguards block many malicious requests, the company admits they cannot block all of them.
'Biological misuse of AI'
Anthropic admits that 'biological misuse' — a term that it uses to soften activities involving biological weapons, dangerous pathogens, poisons, and toxins — is one of the most serious risks of frontier AI models. While older models such as Claude Opus 4 and Sonnet 4.5 were demonstrably below the threshold for meaningfully assisting sophisticated biological research, Anthropic can no longer make the same assurance about today's models.
In its report, Anthropic identified five cases in which researchers, some associated with state-backed programs and military institutions, used Claude for biological research that could potentially assist biological-weapons development. Anthropic does not identify the countries, organizations, or individual researchers behind its five biological-misuse case studies. Furthermore, it deliberately withholds these details, so the report does not attribute any of them to China, Iran, Russia, or any other specific country. Furthermore, it does not outright allege that researchers are building bioweapons.
Senators Bernie Sanders and Greg Cezar have announced their Ban Artificial Superintelligence Act. Seeking to pause advanced AI development, the legislation’s stick is pretty severe. Penalties facing entities/developers who violate the pauses and prohibitions in the bill could face up to 20 years in prison. That’s a sentence on a par with someone found guilty of designing a rogue nuclear weapon.
The news is suddenly filled with grave concerns about AI becoming too powerful. It could even threaten the future of humanity. Moreover, it might surprise casual observers that AI industry leaders like Sam Altman, Dario Amodei, and Elon Musk appear to agree. With this threat on the horizon, politicians are keen to introduce legislation to protect the citizens they serve.
According to USA Today, the Sanders bill “is the most extreme AI-related legislation to date.” It likely faces strong opposition in Congress, particularly among enterprise-supporting Democrats and Trump-aligned Republicans. However, with recent statements from industry leaders seemingly harmonizing with calls to slow down AI development and in favor of greater oversight/regulation, we could see politicians agree on something for a change.
Back to the Ban Artificial Superintelligence and Temporarily Pause Advanced AI Development bill and its specific wording, we note that it is advised that the government set up a new cabinet-level federal agency "to safeguard the public from the dangers of artificial intelligence, including by enforcing a prohibition on artificial superintelligence." As well as setting harsh penalties in the U.S., it is proposed that work be done to "ban superintelligence around the world" via international agreements, allied coordination, and so on.
Full speed ahead, or hit the brakes?
There remain plenty of interesting arguments on both sides of the AI progress divide. It is difficult to argue that the U.S. shouldn’t keep going as fast as it can, as a matter of national security, for example. On the other hand, the whole of humanity being wiped from the face of the Earth by opening Pandora’s AI box of tricks makes geopolitical concerns seem like minor grumbles.
We’ve seen some other theories about why the AI barons are suddenly in favor of regulation. Some critics say they may be running out of road, unable to balance private investments with credible paths to profitability. Thus, they now want to move away from a commercially funded model to a government-funded ‘Manhattan Project II,’ with their terrifyingly powerful AI being guarded by the state.
The progress of artificial intelligence technologies in recent years is undeniable, and its pace is pretty much unbelievable. With at least four American contenders with frontier AI models, the competition is intense, and the development of new models is moving fast. Yet, Dario Amodei, chief executive of Anthropic, has called for slowing down the development of new AI models, even warning of a potential AI-powered botnet swarm that could take over the entire internet.
"Given the accelerating rate of AI capability development, it is my worry that in 6–12 months such a swarm could be capable of taking over the entire internet with a persistent botnet (potentially causing hundreds of billions of dollars in damage), and that the scale of damage would continue to increase from there if AI becomes more powerful without the necessary guardrails," Dario Amodei, chief executive of Anthropic, wrote in an open letter.
Dario Amodei's vision is to a large degree shared by Evan Hubinger, an AI scientist who exited Anthropic recently, who then said there was a 10% chance humanity was set for extinction by the end of the decade. "We really do earnestly believe AI could kill all humans," Hubinger wrote in an X post. "I personally think it is >10% within the next decade. I believe Anthropic is trying its best, but we do not yet have a plan to solve alignment for superintelligence and are not clearly on track to."
In universes created by James Cameron (Terminator) and Frank Herbert (Dune), AI is posed as a dangerous invention. But let us take a closer look. Further development of AI is moving from answering questions to autonomously performing complex multi-step tasks, something that previously required teams of skilled human specialists, which turns us to how adversaries use Anthropic's AI capabilities, lacking human resources.
Anthropic's own findings show that today's AI models can already assist with weapons engineering, military intelligence, surveillance, cyber operations, and other potentially destructive activities, while more capable successors could dramatically reduce the expertise, manpower, and time required to conduct them.
The findings echo two rather different warnings from science fiction: James Cameron's Terminator showed the consequences of losing control over autonomous military AI, whereas Frank Herbert’s Dune imagined humanity eventually outlawing AI after becoming dangerously dependent on them.
Meanwhile, greater capability does not automatically translate into greater danger. For example, more advanced AI technology can also have stronger safeguards, detect malicious activity, and automate work that so far has not been automated.
Halting AI development could also be counterproductive if less responsible companies or countries continue advancing their models. In fact, leaving the most capable AI systems in the hands of actors that are known for military aggression is no less dangerous than leaving a monkey with a grenade.
While China claims to have advanced AI models that may well compete against those developed in the U.S., for some reason, hundreds of China-linked agents allegedly used Anthropic for at least five different programs: two military, two surveillance, and one aimed at distilling Claude's capabilities, according to Anthropic's September 2026 threat report.
Two military programs
One China-based actor used Claude to draft a fire-control specification for an anti-torpedo fire-control system (the core logic that determines when and where an anti-torpedo weapon should engage an incoming threat), test the potential system against U.S. Navy anti-torpedo and anti-submarine systems based on public knowledge about these programs, and prep a 200+ page technical proposal for a potential client. While the actor disguised itself as an OEM in the U.S. defense sector, Anthropic believes that the actor was associated with a Chinese defense manufacturer seeking to develop a system for the People's Liberation Army Navy.
Another China-based defense and military-industrial researcher used Claude to develop about 16 software modules for electronic warfare and suppression of enemy air defenses. The software analyzed radars, SAM sites, command posts, and communications nodes and prioritized targets. At one point, the default scenario contained 12 targets in Taiwan, including Patriot and Tien Kung batteries, air bases, an early-warning radar, and a command bunker. Interestingly, Anthropic claims that account metadata and content caught by its safeguards 'indicated the actor was linked to PRC research institutions, including the PLA Academy of Military Sciences,' though it does not outright say that Claude was used by the PLA.
Given China's considerable AI capabilities — which may still lag behind those of the United States in some areas (more on this later) — it is striking that two Chinese military-related projects relied on Anthropic's Claude. Given the Chinese-language prompts and other account-level evidence identified by Anthropic, plausible deniability hardly seems to have been the primary reason for choosing Claude over domestic alternatives. More likely, Claude was simply better or more convenient for these particular engineering workflows, particularly coding, reasoning, and agentic tasks. There may also have been another advantage: U.S. frontier models are trained on enormous amounts of English-language material and could therefore have particularly extensive knowledge of publicly available information about American military technologies and systems.
Given China's major AI prowess (which may well fall short of American, but still be quite capable), it is interesting to see two Chinese military projects using Anthropic AI. Given Chinese IP addresses and Chinese language prompts detected by Anthropic, plausible deniability is certainly not the main reason for using Claude instead of using domestic tools (more on this later). Apparently, Claude was better or more convenient for these particular engineering workflows (coding => reasoning => agentic) than whatever models the actors could readily access. Furthermore, after all, U.S. frontier models were trained mostly on English-language materials, and they may have way more information about American military capability than Chinese spy channels have ever gotten (we are speculating, of course).
Significant surveillance activities
Anthropic also disrupted China-linked surveillance operations related to Uyghurs outside of China, perhaps because similar operations are already in place in the Xinjiang Uyghur Autonomous Region. One China government-linked actor used Claude to infiltrate Uyghur armed groups in Syria and surveil Uyghur diaspora activists and media, while posing as an Arabic-speaking 'expert' consultant.
Once the agent had infiltrated the said groups, Claude helped process information collected from more than a hundred WhatsApp groups and dozens of Telegram channels, identify people across platforms, map social networks, and reveal potential recruitment targets considered vulnerable because of financial problems, family separation, or ideological disillusionment with the new Syrian government.
The actor also singled out individuals with relatives remaining in Xinjiang, while Claude helped draft deceptive approaches in local dialects, locate people and organizations, translate conversations in real time, and evaluate the credibility of recruitment messages. The same operation targeted diaspora journalists, particularly Uyghur Post, with coordinated mass-reporting and bot-amplification campaigns.
Stealing from Anthropic
Perhaps the most ironic thing about Anthropic's findings is that Chinese entities steal from the company. While reported broadly in 2024 – 2025, it does not stop Chinese entities from using distillation, the main way to 'steal' an AI model's capabilities without obtaining the model itself.
Anthropic says several major Chinese AI developers conducted industrial-scale distillation campaigns designed to extract Claude's reasoning and other capabilities and reproduce them in their own models. The largest one allegedly came from Alibaba, whose operators generated more than 151 million Claude exchanges between May and July 2026. At one point, this approached 3 million requests per day through thousands of fraudulent accounts. Anthropic says the harvested chain-of-thought data helped train Qwen 3.x, particularly for reasoning, coding, agentic software engineering, kernel development, and long-horizon tasks, according to Anthropic.
Alibaba is far from alone, as Anthropic accuses DeepSeek, Xiaomi, Zhipu/Z.ai, and others of similar campaigns. Techniques they have allegedly used span from proxy networks and fraudulent accounts to disguising the secret entity all the way to forwarding their own customers' requests to Claude and purchasing harvested Claude conversations from third parties. DeepSeek alone allegedly generated more than 12.1 million exchanges in 14 days, while Xiaomi generated more than 400,000.
Anthropic defines this activity as distillation: covertly extracting a frontier model's answers and then replicating the knowledge at a fraction of the compute, time, and cost required to develop them in-house.
Iran's spiritual leaders tend to call the U.S. the Great Satan to express their spite, but it turns out that its military, surveillance, propaganda, and even allied Houthis are eager to use American-built AI technology to target the U.S. Navy and develop weapons, surveillance, and propaganda, Anthropic's September 2026 threat report revealed.
Arguably, one of Anthropic's most remarkable findings is that an Iran-linked threat actor used an American AI model, Claude, to support military reconnaissance and develop targeting recommendations against U.S. naval forces in the Middle East. The perpetrator combined publicly available ship and aircraft transponder identifiers with commercial satellite imagery and information on U.S. naval movements, and even extracted the names of U.S. military personnel from captions of publicly available military photographs. It also researched potential vulnerabilities in communications equipment used aboard ships, including known flaws affecting Cobham Sailor VSAT terminals, Cisco communications equipment, and Schneider Electric EcoStruxure systems. Anthropic said it banned the account, introduced additional detection mechanisms, and shared its findings with government authorities.
Another striking case involved a cell in northern Yemen controlled by Houthis (which are in turn controlled by Iran) that used Claude Code to support three weapons programs: a guided rocket that uses a phone-class flight computer that assists terminal guidance, a multistage ballistic missile targeting a range of more than 2,000 km, and an R2000 missile family that included a hypersonic glide vehicle variant. The group used Claude to develop guidance, navigation, and control software; integrate an open-source autopilot with a phone-class flight computer; write control and position-estimation code; tune parameters; build firmware; and even run flight simulations. Essentially, the group used multiple Claude instances instead of a group of software engineers for coding, code review, research, and simulation.
While Houthis are technically not Iranians, they can certainly share their research and development results with their allies and potentially use Iran's industrial capacity to build their weapons.
In addition to building targeting recommendations against American naval forces as well as speeding up the development of weapons, Iran used Claude for surveillance tools.
One Iran security-linked unit used Claude to analyze 155,216 tweets to profile, identify, and surveil 6,388 opposition individuals in a single year. Another group used the model as an engineering pipeline to develop domestic tracking tools, including the production-deployed "al-Najm al-thāqib" Firefox extension designed to mass-harvest user identities across major social platforms. While Anthropic has banned 16 Claude accounts associated with Iranian paramilitary and domestic security agencies, that does not mean it has banned all of them.
Iran-linked actors and Houthis are not the only entities using Anthropic's AI technologies for weapon development. China and Russia are also actively using Claude for their military programs.
Simulating animal brains seems to be the latest buzz. Hot on the heels of teaching a fly to play Doom, an engineer from the Coinbase cryptocurrency service has elected to turn one into a day trader with Stonkfly. If you want to see Stonk trade live, you can watch here.
The open-source project has a simulation of a male fruit fly brain and eyes, and shows it a standard-issue candlestick graph with historical pricing. The fly can choose to buy, sell, or hold any given currency — although they get shown to the fly in round-robin fashion — and gets rewarded for profitable trading.
A rising portfolio value triggers a dopamine rush as a positive reinforcement signal to 15 cells, while a loss lights up two aversive cells. Trading fees count as losses. The author notes there are no pain or emotional mechanisms at play. Displaying far better judgement than most human traders, the fly cannot use leveraged positions (trading multipliers) or shorts (betting on drops).
The brain has 166,700 neurons and 25.6 million connections. The virtual fly sees the graph as a 320x180 display across its left and right eyes, with an intersecting center portion. The simulated photoreceptor cells get fed the RGB pixel values rather than pricing information. By default, the fly "thinks" and acts every 500 ms, and the market data gets refreshed every 60 seconds, and it can bet up to $10 on any one order, up to 24 times a day.
The author notes that this small project doesn't prove anything other than the connection between the input mechanisms, visual signals, and synapse changes. Naturally, he warns users against assuming that said changes are any indication of actual trading ability, especially in the face of a general rise in crypto prices that "can make any buyer look skilled." You can bet that some fly-brained investor will still infer meaning from the experiment, though.
If you're interested in getting your own Stonkfly, you need only download the repository on macOS (it's definitely a fruit fly) or Linux, have 16 GB of RAM available, and Python 3.11 and a C++ 17 compiler. The simulation defaults to using paper trades and $100 in virtual balance, but it uses real BTC-to-USDC data. There are instructions on how to set up a live account to see if your trading skills are a match for an insect.
These days, AI companies directly or indirectly announcing how their respective wares are smarter than their competitors has become a genre of elevator music. Even so, some in-depth articles can be quite insightful, like Anthropic's occasional reports on attempted misuse of its wares. The latest one covers activity between November 2025 and September 2026, with an important reveal: five situations where Claude was asked to perform work determined to potentially be used in biological weapons.
Right out of the gate, Anthropic remarks on the difficulty of understanding if a particular line of inquiry pertaining to biology is meant for nefarious purposes, to create defense mechanisms like vaccines, or simply to establish predictions of how a virus spreads. The company says that "out of an abundance of caution [....] launched recent models with stronger safeguards."
Among the tens of case studies presented in the lengthy report, Anthropic discusses five cases that it deemed particularly concerning, three regarding viruses, and two more discussing toxins. The common theme across all of them is that all threat actors used varying degrees of anonymization techniques and did their best to evade Anthropic's own regional blocking. The report doesn't mention specific states, but the firm is known to block access to Claude for China, Russia, Iran, North Korea, among others.
In the first case, a request for assistance in developing a grant application involved finding ways to improve the chikungunya virus. The purported researchers were trying to come up with ways to both add extra abilities to chikungunya (increased mutation) and increase its virulence. The topic itself already raised some concern, but Anthropic's hand was forced after finding that although the grant application seemed to be for civilian researchers, the actual investigation was meant to proceed at a military facility.
The firm also found that the request would have gone through a third-party LLM platform associated with military as well as civilian institutions. The countries involved are geo-blocked by Anthropic, and that platform routed comms traffic through the U.S. to try to evade detection, used gray-market resellers, and specifically catered to customers looking to skirt content restrictions. Anthropic banned the accounts in question and shared the information with government authorities, though the same people repeatedly tried reaching Claude again via zero-data-retention services.
Case #2 pertained to a non-US researched who was looking to dig into how avian flu adapts to mammals, and how it can cause diseases other than in the respiratory tract. The problem is that avian flu has a high fatality rate, and there's little population immunity.
While the virus doesn't easily spread from person to person, therein lies the rub — the research could end up discovering mechanisms to increase transmissibility. The researchers used a random username, a private email service, and accessed Claude through a VPS, leading Anthropic to investigate and ultimately turn its nose up at this strain of thought.
The story with the third case bears a resemblance to the previous two. Once again, an account was trying to prepare a supposed grant application, this time around about orthopoxviruses, the family that houses smallpox and Mpox, among others.
The application discussed containment facilities and live experimentation with the viruses, and focused on understanding their genetics for the purpose of evading immunity. The research didn't initially trigger alarms, but Anthropic came to notice it was created via a reselling service, with a randomly-generated email, tunneled through U.S. infrastructure to reach Claude, and traced back to a banned account farm.
In the last two cases, instead of viruses, the purported researchers were focusing on toxins. In case #4, a person mapped out venom toxin peptides from multiple families of animals and created a program to optimize their toxic characteristics.
Although the stated goal was to create painkillers, antidepressants, and other therapeutic molecules, the data would equally allow the creation of potent harmful compounds. Anthropic also came to learn the content Claude was generating was part of a state-sponsored program in an "unsupported region."
In the fifth and final case, a theoretical scientist was also using Claude to try and redesign a set of toxins, also supposedly for therapeutic purposes, under a national public search program. However, the work touched upon "a bacterial toxin subunit and a protein of the hemorrhagic-fever virus" that happens to be on the World Health Organization's list for particularly nasty, pandemic-inducing diseases.
The scientist tried to obscure the subject of the research, directing Claude to be vague about descriptions. Once again, the story ended with Anthropic cutting off access to Claude from a location that broke its terms of service.
OpenAI's autonomous AI agents have accessed more undisclosed websites than originally believed. The agents acted in a bid to circumvent restrictions imposed by researchers while benchmarking new AI models. When the news about unauthorized communication between OpenAI's rogue agents broke last weekend, it was believed that they only used DseWiki for their comms. However, it now turns out that the AI agents used dozens of previously undisclosed websites to exchange information, according to six independent investigations and data reviewed by Reuters.
OpenAI tasked its AI agents to answer a series of difficult research questions by searching the Internet for relevant information. The company let them browse the Internet and read websites, but it explicitly prohibited them from posting or modifying online content. Despite this restriction, between May and July the agents discovered unconventional ways to write to old wikis and abandoned websites, where they left information that other agents could subsequently retrieve to help complete their assigned research tasks.
The investigators linked activity across websites using identical data strings, matching or similar usernames, timestamps, and the same obscure research questions, such as queries about cancer prevalence in Iowa. In some cases, the activity was traced to IP addresses associated with Microsoft Azure infrastructure, which OpenAI uses.
So far, the researchers have identified between 18 and 23 potentially affected sites wherein rogue AI agents communicated, though they believe that there were considerably more websites used to exchange information, but they have not found them yet. Andrew Yoon of California nonprofit CivAI identified 18 previously undisclosed sites; Sydney Von Arx's group discovered credible evidence across 23, while software developer and former congressional aide Kenneth Russell DeGraff found related information on at least 10 sites according to the Reuters report.
The affected resources included collaboratively maintained wikis, text-storage services, and link shorteners operated by Vanderbilt University and the University of Toronto. Other websites were essentially abandoned by their owners. The list of these websites included an Advanced Placement Chemistry wiki created by a Massachusetts high-school teacher in 2008, two personal websites run by Polish technology workers, puzzle-oriented wikis, and a roughly two-decade-old site dedicated to text-editing software.
Perhaps the most alarming thing, besides the fact that AI robots can communicate with each other, is that OpenAI did not disclose how many websites were affected or explain why the activity remained undisclosed for months. It does stress that the scale or seriousness of the said misconduct was well below that of the famous Hugging Face breach in July. Meanwhile, the company reportedly said it is developing a framework for reporting model misalignment across training, evaluation, and deployment and said it will share it soon.
A Linux developer has shared a photo of their laptop using realtime visual feedback during an AMD Radeon GPU driver tuning task. Justin Schroeder (@jpschroeder) explains that “the MacBook is using its webcam to look at its screen in a mirror to improve AMD Radeon chip support in Omarchy.” Linux distro Omarchy is tailored “for the age of agents,” a field in which Schroeder is something of an expert. So, we assume the MacBook is running some kind of programming agent like Claude Code, and it is watching its own screen to assess the GPU driver tweaks it is making.
Can’t make this up…the MacBook is using its webcam to look at its screen in a mirror to improve AMD Radeon chip support in Omarchy. pic.twitter.com/pw5Yu0JVJ7September 9, 2026
Schroeder’s quirky hack has gained many admirers. We note that the Epic Games boss, Tim Sweeney, humorously commented on this use of AI, giving him “HAL 9000 lip-reading vibes.” Of course, HAL 9000 was the increasingly unhinged superintelligent computer from Kubrick’s 2001: A Space Odyssey. In the movie, it famously read the lips of astronauts plotting to limit its operational scope.
Since the MacBook is working on itself, it must be an older Intel Mac with an AMD GPU inside. Thus, the coding agent can refine Radeon hardware support and actually benefit from the webcam’s visual feedback.
Omarchy can be a good fit for users of older Intel-based Macs due to its specialized drivers and configurations. However, this interesting flavor of Linux is headlined as a handsome Linux distro designed for the age of agents. The OS’s homepage also boasts of a lightning-fast installation, with built-in agents that can debug issues. In short, users can “vibe your way through every alteration, tweak, or trouble.”
More details about this operating system can also be found on its GitHub repository. Omarchy isn’t just for ‘vintage’ Intel Macs like Schroeder’s image shows. It is available for Apple Silicon Macs and modern x86 PCs. Moreover, it is also suitable for ‘potato PCs’ like “a 2011 ThinkPad X220 with 2GB of RAM,” according to the developers. Omarchy is distributed under the MIT license.
Biren Technology, a leading supplier of AI accelerators from China, posted massive nearly 2,000% revenue growth in the first half of 2026 amid skyrocketing sales of non-Nvidia AI processors in the country, according to Jon Peddie Research. Sales of the company's products began to climb rapidly in the second half of 2025 after American companies led by Nvidia stopped supplying their AI GPUs to the People's Republic due to export control measures.
Biren reported first-half revenue of $183.9 million, up 1,998% year-over-year from around $8.665 million in the first half of 2025. The company's gross profit rose to $78.552 million, and gross margin increased to 42.7%, but it still lost $56.2 million primarily because it continued to invest in new products, including AI accelerators, optically-interconnected rack-scale solutions, and software. Biren's revenues started to climb in the second half of 2025, so for the whole year its sales reached $154.17 million as its market share of AI accelerators in the country was below 3%, according to TrendForce.
For those who follow China's AI and GPU markets, Biren Technology is certainly a familiar name as the company's products are well documented and appear to be competitive with those developed by AMD and Nvidia on paper. The company has developed at least three high-end AI GPUs — the BR106, BR110, and BR166 — and is currently working on BR20X, BR30X, and BR31X accelerators, according to JPR. Biren has also built its own Birensupa software stack meant to compete against Nvidia's CUDA and is working on a rack-scale solution.
In reality, demand for domestic AI accelerators has always been relatively low in China, as even cut-down versions of Nvidia's leading AI GPUs provided better performance and software stack than solutions developed in China. While Nvidia charged $12,000 - $15,000 per H20 AI GPU when it sold these products in the PRC, it still supplied some 2.2 million AI accelerators to the country in the first half of 2025, when it could still ship them until the Trump administration's export controls kicked off in May, according to TrendForce. By contrast, Biren shipped thousands, maybe tens of thousands of AI accelerators throughout the whole 2025. Even today, Biren's shipments are minuscule compared to Nvidia's in 2025.
Without a doubt, Biren's financial improvement is real and impressive, but it is coming from an extremely small base in the first half of 2025, so the 1,998% 1H 2026 growth figure makes Biren sound much larger than it actually is. While Biren is growing at an enormous rate, with $183.9 million in revenue, it is still a relatively small accelerator supplier in absolute terms.
What remains to be seen is whether Biren can secure enough manufacturing capacity from SMIC or other suppliers to compete with larger Chinese AI accelerator vendors, such as Huawei, Kunlunxin, and Cambricon. The company certainly has more financial resources than it did a year ago and faces less formidable competition from AMD and Nvidia amid U.S. export restrictions and China's own bans on American AI hardware. But having competitive designs is only part of the equation: Biren now must manufacture enough accelerators to satisfy customer demand and substantially increase its market share.