Normal view

There are new articles available, click to refresh the page.
Today — 15 September 2026Main stream

Anthropic says AI can boost U.S. GDP by 32%, up to $44.4 trillion in four years — economics model predicts that displaced employees 'may have to switch to jobs like electrician and nurse'

Last week, Anthropic published its prediction of what the economic impact of AI on the U.S. economy is going to be for the next few years. The company thinks the U.S. can reach a $44.4 trillion GDP or higher by 2030, provided, of course, it conveniently adopts AI at a rapid pace. Having said that, Anthropic admits "the challenge is making sure that the gains are broadly shared."

The interactive post has a simulator where readers can plug in their estimates on key factors and get their own future predictions, within the firm's analysis and perspective. That's definitely interesting to play around with, but perhaps the most relevant piece of information is the lens through which Anthropic views the world.

Anthropic establishes its reasoning by first placing tasks in broad categories and using a nurse's workday as an example. They removed tasks, including those that will disappear naturally as technology progresses, like collecting data on paper or physically visiting the patient to collect basic vitals — neither happens anymore as remote monitoring becomes commonplace. However, some new tasks are added, like keeping an eye on dashboards for the aforementioned AI-powered monitoring.

Then, there are naturally the tasks that a bot can't perform, like bathing a patient. Augmented tasks include those that require a human, but can be made more efficient with AI: helping with triage, planning schedules, and assisting with dashboard data. Some tasks may be fully automated, like keeping supply closets full or scheduling follow-up patient visits. Finally, AI usage can introduce some tasks of its own, like reviewing automated triaging or double-checking dashboard alerts — perhaps even impromptu data recovery.

The company's predictions broadly hinge on how ubiquitous AI usage becomes, and therefore, the number of tasks transitioning into fully or partially automated. Unsurprisingly, Anthropic believes that the more entrenched AI gets, the more value the country creates, though at greater risk — and on an exponential scale, no less

Three models are presented, from "modest" economical impact to "extreme." The modest model establishes a 1.6% GDP rise to $34.1 trillion, an impact Anthropic says is in line with that of new technologies like the internet, and crucially, doesn't imply tectonic shifts to unemployment rates or wages.

For the "substantial impact" scenario, although AI is predicted to be able to do half of "knowledge work," mostly without intervention, adoption remains limited. This scenario foresees twice the normal economic growth, this time +8.3% to $36.3 trillion.

This future marks the inflection point at which Anthropic believes knowledge workers see their wages remain steady instead of growing, though it's not clear if the firm accounts for inflation. Additionally, the firm states that "knowledge workers may see a lot of automation and displacement [...] coders and call service center agents may have to switch to jobs like electrician and nurse", a statement some might argue is already true. In that sense, Anthropic expects other workers to start seeing more cash.

The eyebrow-raising prediction for both the above scenarios, though, is that Anthropic expects unemployment to "stay within ranges history has seen before," an odd statement given modern U.S. history contains events like the Great Depression. The company does note that it expects job churn to increase, but also that while "this process can be painful, [it] works relatively well from a macroeconomic perspective." Average wages are expected to rise across all three scenarios, though the increase is expected to go towards workers outside of knowledge areas.

In the "extreme" scenario, Anthropic expects significant changes. Should AI be super-widely adopted, the GDP can increase by 32.4%, corresponding to a cool $44.4 trillion, a "profound economic transformation." This is the point at which the firm expects that AI becomes more productive than humans for most knowledge work, and does so with near-autonomy. Equally worryingly, it's expected that there will be "essentially no" new knowledge tasks created.

Anthropic notes that to reach this kind of stage, the country would "likely require" recursively self-improving AI (using the AI to make better AI). There's a significant catch, however, as though the U.S. would be "far richer than [it's] ever been," knowledge workers would be the hardest hit with a 10% wage drop, plus overall unemployment would climb "beyond typical recessionary levels." Manual labor would be prized, though, given that "as AI increases productivity within knowledge work, the demand for manual work that benefits from that productivity will increase."

Scenarios aside, the one big question is: How would all that GDP money land in people's pockets? Anthropic admits this problem is a "challenge" and offers little solution for it. Such a high amount of future AI penetration might prove a hard sell, considering wealth inequality in the U.S. already sits at its highest level for the last few decades and is trending in that direction in most developed nations. Others might argue with Anthropic's assessment that unemployment levels would remain somewhat in the less extreme scenarios, seeing as job cuts are rampant across many sectors and have hit technology-related fields the hardest.

To its credit, Anthropic clearly highlights part of the wealth-inequality issue. The company admits that more AI automation might skew the current 60/40% balance between labor and capital, respectively, strongly tilting the scale in favor of capital ownership and increasing inequality. Many argue that's already happening today. There's also the matter that the prediction appears to assume little competition from other countries, nor does it offer insight as to what would happen to "AI-less" nations.

The interactive blog post and its simulator are worth a good read and fiddling with, regardless. Anthropic published the technical details on the mathematical model used in a separate article and published its Economic Policy Framework last June.

Nvidia, Palantir, and others restrict advanced AI model usage over privacy concerns, report claims — 'paranoia' rising over customer intellectual property

14 September 2026 at 15:58

Anthropic and OpenAI are both facing uncomfortable questions from some large AI customers over concerns about how proprietary data may be used to train AI models. Some companies are so worried that they have begun demanding assurances about how their data is handled or going so far as to place limitations on which models their employees can use, and for which tasks, The Information reports. They fear that models may be trained on their intellectual property and information.

The issue can be traced back to a June change by Anthropic. Following the change to its flagship Fable model's policies, Anthropic can now retain customer data. The company argues that it only does so to ensure that Fable isn't being misused. But some companies have raised concerns that it means sensitive business data will be caught up in the sweep.

While both OpenAI and Anthropic point out that they don't train their models on the information given to them by companies with specific enterprise contracts by default, that doesn't tell the full story. Both companies do collect metadata from the same corporate customers, and while information on exactly what that metadata contains is hard to come by, OpenAI notes that it's only used “to better understand how our services are used." Anthropic also argues that any data it collects about how customers use its products is aggregated and anonymized. And that metadata isn't used to train models.

Regardless, there are still concerns over a perceived lack of clarity about what is collected. Telecoms outfit C Spire has agreements with both OpenAI and Anthropic that prevent either from using its data to train models, the report says.

However, the contracts do allow both OpenAI and Anthropic to collect C Spire technical usage data. C Spire believes that includes information about what applications AI models are connected to as well as usage data. It also worries that the AI companies may collect information about what their models get up to between generating responses.

For its part, OpenAI says that it does not use this "chain-of-thought" data to train its models. But C Spire still believes it needs a better understanding of what data is being collected, the report adds. It argues that neither AI company is being clear in its explanations.

Taking the private approach

One solution to any privacy concerns could be to use air-gapped servers, something aerospace company Northrop Grumman has already chosen to do. The Information reports that the company runs open-source AI models on its own air-gapped servers rather than trusting the likes of OpenAI and Anthropic.

Alternatively, Microsoft is already trying to take advantage of any data privacy concerns by tempting OpenAI and Anthropic customers to its own secure AI platforms. Microsoft's isolated cloud environments run AI models on private servers that don't send any data to external AI companies. But this approach is costly, and the report notes that at least one customer is still considering Microsoft's alternative approach.

Pharmaceutical company Novo Nordisk has taken a slightly different approach. While it continues to use Anthropic's Claude for some tasks, it has a ban on allowing any proprietary data to be used by the model.

It's clear that a lack of trust has the potential to cost AI companies real money, and in one instance, it already has. The same report notes that a large U.S. utility company has already canceled its plans to test Anthropic's Fable. The utility company wanted to know if Fable could run its core power infrastructure but ultimately pulled the plug over Anthropic's refusal to agree to a nonrevocable zero data retention (ZDR) policy.

Nvidia has also decided to use Fable for tasks that don't require it to gain access to sensitive data. The company points to the same lack of ZDR guarentees as the reason. Instead, Nvidia uses its own in-house AI solution for tasks that it deems too sensitive for Anthropic's model. Nvidia CEO Jensen Huang has famously remarked that its employees should use AI tokens worth half their annual salary every year.

Toms Hardware reached out to Nvidia for comment but did not receive one by publication.

Russian freelancers use Claude to program autonomous combat drone swarm — AI-enabled target selection and detonation without a human in the loop

Hit hard by sanctions and lacking resources, Russia is left to rely on foreign advanced technologies to compensate. Russia-linked agents appear to use Claude for a broad range of activities, from propaganda and espionage to the procurement of military/dual-use equipment and the development of autonomous drone swarms, according to Anthropic's September 2026 threat report.

Anthropic identified a small team of Russia-based freelance developers who used Claude to build software for an autonomous combat-drone swarm called DronDoc or Serafim. Claude helped develop swarm coordination, computer vision, terminal guidance, and other software that enabled drones to select targets—including people—and issue detonation commands without a human in the loop. The developers trained their computer-vision system on Ukrainian combat footage and used locations in Ukraine for simulated missions. Meanwhile, they loaded software onto real development boards for hardware-in-the-loop testing, though it is unclear whether they field-tested it.

The developers used Claude Code extensively to build and test the swarm software, and they circumvented Anthropic's geographic restrictions by routing traffic through commercial VPNs. Once Anthropic identified the activity as suspected weapons development, it banned the accounts associated with the group and incorporated what it learned into additional safeguards. Meanwhile, the key distinction is that the safeguards did not stop the project immediately, and based on the disclosure, Claude Code clearly helped advance the autonomous drone swarm program.

Anthropic gathered enough information about the people/accounts and their activity to assess what kind of group they were, so it claims that they were not a Russian state entity. Meanwhile, although Anthropic likely identified the company or organization, it did not publicly name it.

In addition, Anthropic discovered a Russian state-linked cyberespionage operation that used Claude to automate everything from infrastructure setup and phishing to malware development and data exfiltration. The campaign targeted more than 20 organizations, including Ukrainian and European government, military, intelligence, and defense entities.

Last but not least, Russia-linked actors also used Claude for propaganda operations, including a Russian state-directed campaign in the Central African Republic that produced pro-Russian and pro-Wagner content for radio, local media, and Telegram.

Most alarming, the report shows AI is now doing work that previously required teams of software engineers, intelligence analysts, and security specialists. While Anthropic's safeguards block many malicious requests, the company admits they cannot block all of them.

'Biological misuse of AI'

Anthropic admits that 'biological misuse' — a term that it uses to soften activities involving biological weapons, dangerous pathogens, poisons, and toxins — is one of the most serious risks of frontier AI models. While older models such as Claude Opus 4 and Sonnet 4.5 were demonstrably below the threshold for meaningfully assisting sophisticated biological research, Anthropic can no longer make the same assurance about today's models.

In its report, Anthropic identified five cases in which researchers, some associated with state-backed programs and military institutions, used Claude for biological research that could potentially assist biological-weapons development. Anthropic does not identify the countries, organizations, or individual researchers behind its five biological-misuse case studies. Furthermore, it deliberately withholds these details, so the report does not attribute any of them to China, Iran, Russia, or any other specific country. Furthermore, it does not outright allege that researchers are building bioweapons.

Yesterday — 14 September 2026Main stream

Bernie Sanders proposes 20 year prison sentence for AI devs who plow ahead with Artificial Superintelligence plans — penalty on par with illegally developing rogue nuclear weapons

13 September 2026 at 14:10

Senators Bernie Sanders and Greg Cezar have announced their Ban Artificial Superintelligence Act. Seeking to pause advanced AI development, the legislation’s stick is pretty severe. Penalties facing entities/developers who violate the pauses and prohibitions in the bill could face up to 20 years in prison. That’s a sentence on a par with someone found guilty of designing a rogue nuclear weapon.

Ban Artificial Superintelligence Act wording on penalties

(Image credit: Ban Artificial Superintelligence Act)

The news is suddenly filled with grave concerns about AI becoming too powerful. It could even threaten the future of humanity. Moreover, it might surprise casual observers that AI industry leaders like Sam Altman, Dario Amodei, and Elon Musk appear to agree. With this threat on the horizon, politicians are keen to introduce legislation to protect the citizens they serve.

According to USA Today, the Sanders bill “is the most extreme AI-related legislation to date.” It likely faces strong opposition in Congress, particularly among enterprise-supporting Democrats and Trump-aligned Republicans. However, with recent statements from industry leaders seemingly harmonizing with calls to slow down AI development and in favor of greater oversight/regulation, we could see politicians agree on something for a change.

Back to the Ban Artificial Superintelligence and Temporarily Pause Advanced AI Development bill and its specific wording, we note that it is advised that the government set up a new cabinet-level federal agency "to safeguard the public from the dangers of artificial intelligence, including by enforcing a prohibition on artificial superintelligence." As well as setting harsh penalties in the U.S., it is proposed that work be done to "ban superintelligence around the world" via international agreements, allied coordination, and so on.

Full speed ahead, or hit the brakes?

There remain plenty of interesting arguments on both sides of the AI progress divide. It is difficult to argue that the U.S. shouldn’t keep going as fast as it can, as a matter of national security, for example. On the other hand, the whole of humanity being wiped from the face of the Earth by opening Pandora’s AI box of tricks makes geopolitical concerns seem like minor grumbles.

We’ve seen some other theories about why the AI barons are suddenly in favor of regulation. Some critics say they may be running out of road, unable to balance private investments with credible paths to profitability. Thus, they now want to move away from a commercially funded model to a government-funded ‘Manhattan Project II,’ with their terrifyingly powerful AI being guarded by the state.

Anthropic CEO warns of AI-driven botnet 'swarm' taking over the entire internet — 'In 6–12 months such a swarm could be capable of taking over the entire internet with a persistent botnet'

The progress of artificial intelligence technologies in recent years is undeniable, and its pace is pretty much unbelievable. With at least four American contenders with frontier AI models, the competition is intense, and the development of new models is moving fast. Yet, Dario Amodei, chief executive of Anthropic, has called for slowing down the development of new AI models, even warning of a potential AI-powered botnet swarm that could take over the entire internet.

"Given the accelerating rate of AI capability development, it is my worry that in 6–12 months such a swarm could be capable of taking over the entire internet with a persistent botnet (potentially causing hundreds of billions of dollars in damage), and that the scale of damage would continue to increase from there if AI becomes more powerful without the necessary guardrails," Dario Amodei, chief executive of Anthropic, wrote in an open letter.

Dario Amodei's vision is to a large degree shared by Evan Hubinger, an AI scientist who exited Anthropic recently, who then said there was a 10% chance humanity was set for extinction by the end of the decade. "We really do earnestly believe AI could kill all humans," Hubinger wrote in an X post. "I personally think it is >10% within the next decade. I believe Anthropic is trying its best, but we do not yet have a plan to solve alignment for superintelligence and are not clearly on track to."

In universes created by James Cameron (Terminator) and Frank Herbert (Dune), AI is posed as a dangerous invention. But let us take a closer look. Further development of AI is moving from answering questions to autonomously performing complex multi-step tasks, something that previously required teams of skilled human specialists, which turns us to how adversaries use Anthropic's AI capabilities, lacking human resources.

Anthropic's own findings show that today's AI models can already assist with weapons engineering, military intelligence, surveillance, cyber operations, and other potentially destructive activities, while more capable successors could dramatically reduce the expertise, manpower, and time required to conduct them.

The findings echo two rather different warnings from science fiction: James Cameron's Terminator showed the consequences of losing control over autonomous military AI, whereas Frank Herbert’s Dune imagined humanity eventually outlawing AI after becoming dangerously dependent on them.

Meanwhile, greater capability does not automatically translate into greater danger. For example, more advanced AI technology can also have stronger safeguards, detect malicious activity, and automate work that so far has not been automated.

Halting AI development could also be counterproductive if less responsible companies or countries continue advancing their models. In fact, leaving the most capable AI systems in the hands of actors that are known for military aggression is no less dangerous than leaving a monkey with a grenade.

Chinese military researchers and tech giants caught using Claude — US frontier model coded 16 air-defense suppression tools targeting Taiwan, drafted anti-torpedo specs, and fed 151 million training queries to Alibaba

While China claims to have advanced AI models that may well compete against those developed in the U.S., for some reason, hundreds of China-linked agents allegedly used Anthropic for at least five different programs: two military, two surveillance, and one aimed at distilling Claude's capabilities, according to Anthropic's September 2026 threat report.

Two military programs

One China-based actor used Claude to draft a fire-control specification for an anti-torpedo fire-control system (the core logic that determines when and where an anti-torpedo weapon should engage an incoming threat), test the potential system against U.S. Navy anti-torpedo and anti-submarine systems based on public knowledge about these programs, and prep a 200+ page technical proposal for a potential client. While the actor disguised itself as an OEM in the U.S. defense sector, Anthropic believes that the actor was associated with a Chinese defense manufacturer seeking to develop a system for the People's Liberation Army Navy.

Another China-based defense and military-industrial researcher used Claude to develop about 16 software modules for electronic warfare and suppression of enemy air defenses. The software analyzed radars, SAM sites, command posts, and communications nodes and prioritized targets. At one point, the default scenario contained 12 targets in Taiwan, including Patriot and Tien Kung batteries, air bases, an early-warning radar, and a command bunker. Interestingly, Anthropic claims that account metadata and content caught by its safeguards 'indicated the actor was linked to PRC research institutions, including the PLA Academy of Military Sciences,' though it does not outright say that Claude was used by the PLA.

Given China's considerable AI capabilities — which may still lag behind those of the United States in some areas (more on this later) — it is striking that two Chinese military-related projects relied on Anthropic's Claude. Given the Chinese-language prompts and other account-level evidence identified by Anthropic, plausible deniability hardly seems to have been the primary reason for choosing Claude over domestic alternatives. More likely, Claude was simply better or more convenient for these particular engineering workflows, particularly coding, reasoning, and agentic tasks. There may also have been another advantage: U.S. frontier models are trained on enormous amounts of English-language material and could therefore have particularly extensive knowledge of publicly available information about American military technologies and systems.

Given China's major AI prowess (which may well fall short of American, but still be quite capable), it is interesting to see two Chinese military projects using Anthropic AI. Given Chinese IP addresses and Chinese language prompts detected by Anthropic, plausible deniability is certainly not the main reason for using Claude instead of using domestic tools (more on this later). Apparently, Claude was better or more convenient for these particular engineering workflows (coding => reasoning => agentic) than whatever models the actors could readily access. Furthermore, after all, U.S. frontier models were trained mostly on English-language materials, and they may have way more information about American military capability than Chinese spy channels have ever gotten (we are speculating, of course).

Significant surveillance activities

Anthropic also disrupted China-linked surveillance operations related to Uyghurs outside of China, perhaps because similar operations are already in place in the Xinjiang Uyghur Autonomous Region. One China government-linked actor used Claude to infiltrate Uyghur armed groups in Syria and surveil Uyghur diaspora activists and media, while posing as an Arabic-speaking 'expert' consultant.

Once the agent had infiltrated the said groups, Claude helped process information collected from more than a hundred WhatsApp groups and dozens of Telegram channels, identify people across platforms, map social networks, and reveal potential recruitment targets considered vulnerable because of financial problems, family separation, or ideological disillusionment with the new Syrian government.

The actor also singled out individuals with relatives remaining in Xinjiang, while Claude helped draft deceptive approaches in local dialects, locate people and organizations, translate conversations in real time, and evaluate the credibility of recruitment messages. The same operation targeted diaspora journalists, particularly Uyghur Post, with coordinated mass-reporting and bot-amplification campaigns.

Stealing from Anthropic

Perhaps the most ironic thing about Anthropic's findings is that Chinese entities steal from the company. While reported broadly in 2024 – 2025, it does not stop Chinese entities from using distillation, the main way to 'steal' an AI model's capabilities without obtaining the model itself.

Anthropic says several major Chinese AI developers conducted industrial-scale distillation campaigns designed to extract Claude's reasoning and other capabilities and reproduce them in their own models. The largest one allegedly came from Alibaba, whose operators generated more than 151 million Claude exchanges between May and July 2026. At one point, this approached 3 million requests per day through thousands of fraudulent accounts. Anthropic says the harvested chain-of-thought data helped train Qwen 3.x, particularly for reasoning, coding, agentic software engineering, kernel development, and long-horizon tasks, according to Anthropic.

Alibaba is far from alone, as Anthropic accuses DeepSeek, Xiaomi, Zhipu/Z.ai, and others of similar campaigns. Techniques they have allegedly used span from proxy networks and fraudulent accounts to disguising the secret entity all the way to forwarding their own customers' requests to Claude and purchasing harvested Claude conversations from third parties. DeepSeek alone allegedly generated more than 12.1 million exchanges in 14 days, while Xiaomi generated more than 400,000.

Anthropic defines this activity as distillation: covertly extracting a frontier model's answers and then replicating the knowledge at a fraction of the compute, time, and cost required to develop them in-house.

Before yesterdayMain stream

Iran and Houthi rebels used Anthropic's Claude AI to target US warships and build hypersonic missiles — Houthi rebels also used the bot to code ballistic missile guidance systems

Iran's spiritual leaders tend to call the U.S. the Great Satan to express their spite, but it turns out that its military, surveillance, propaganda, and even allied Houthis are eager to use American-built AI technology to target the U.S. Navy and develop weapons, surveillance, and propaganda, Anthropic's September 2026 threat report revealed.

Arguably, one of Anthropic's most remarkable findings is that an Iran-linked threat actor used an American AI model, Claude, to support military reconnaissance and develop targeting recommendations against U.S. naval forces in the Middle East. The perpetrator combined publicly available ship and aircraft transponder identifiers with commercial satellite imagery and information on U.S. naval movements, and even extracted the names of U.S. military personnel from captions of publicly available military photographs. It also researched potential vulnerabilities in communications equipment used aboard ships, including known flaws affecting Cobham Sailor VSAT terminals, Cisco communications equipment, and Schneider Electric EcoStruxure systems. Anthropic said it banned the account, introduced additional detection mechanisms, and shared its findings with government authorities.

Another striking case involved a cell in northern Yemen controlled by Houthis (which are in turn controlled by Iran) that used Claude Code to support three weapons programs: a guided rocket that uses a phone-class flight computer that assists terminal guidance, a multistage ballistic missile targeting a range of more than 2,000 km, and an R2000 missile family that included a hypersonic glide vehicle variant. The group used Claude to develop guidance, navigation, and control software; integrate an open-source autopilot with a phone-class flight computer; write control and position-estimation code; tune parameters; build firmware; and even run flight simulations. Essentially, the group used multiple Claude instances instead of a group of software engineers for coding, code review, research, and simulation.

While Houthis are technically not Iranians, they can certainly share their research and development results with their allies and potentially use Iran's industrial capacity to build their weapons.

In addition to building targeting recommendations against American naval forces as well as speeding up the development of weapons, Iran used Claude for surveillance tools.

One Iran security-linked unit used Claude to analyze 155,216 tweets to profile, identify, and surveil 6,388 opposition individuals in a single year. Another group used the model as an engineering pipeline to develop domestic tracking tools, including the production-deployed "al-Najm al-thāqib" Firefox extension designed to mass-harvest user identities across major social platforms. While Anthropic has banned 16 Claude accounts associated with Iranian paramilitary and domestic security agencies, that does not mean it has banned all of them.

Iran-linked actors and Houthis are not the only entities using Anthropic's AI technologies for weapon development. China and Russia are also actively using Claude for their military programs.

Engineer turns simulated fly brain into a crypto day trader, posts downloadable sim to GitHub — 166,700 virtual neurons read candlestick charts for dopamine hits

Simulating animal brains seems to be the latest buzz. Hot on the heels of teaching a fly to play Doom, an engineer from the Coinbase cryptocurrency service has elected to turn one into a day trader with Stonkfly. If you want to see Stonk trade live, you can watch here.

The open-source project has a simulation of a male fruit fly brain and eyes, and shows it a standard-issue candlestick graph with historical pricing. The fly can choose to buy, sell, or hold any given currency — although they get shown to the fly in round-robin fashion — and gets rewarded for profitable trading.

A rising portfolio value triggers a dopamine rush as a positive reinforcement signal to 15 cells, while a loss lights up two aversive cells. Trading fees count as losses. The author notes there are no pain or emotional mechanisms at play. Displaying far better judgement than most human traders, the fly cannot use leveraged positions (trading multipliers) or shorts (betting on drops).

The brain has 166,700 neurons and 25.6 million connections. The virtual fly sees the graph as a 320x180 display across its left and right eyes, with an intersecting center portion. The simulated photoreceptor cells get fed the RGB pixel values rather than pricing information. By default, the fly "thinks" and acts every 500 ms, and the market data gets refreshed every 60 seconds, and it can bet up to $10 on any one order, up to 24 times a day.

The author notes that this small project doesn't prove anything other than the connection between the input mechanisms, visual signals, and synapse changes. Naturally, he warns users against assuming that said changes are any indication of actual trading ability, especially in the face of a general rise in crypto prices that "can make any buyer look skilled." You can bet that some fly-brained investor will still infer meaning from the experiment, though.

If you're interested in getting your own Stonkfly, you need only download the repository on macOS (it's definitely a fruit fly) or Linux, have 16 GB of RAM available, and Python 3.11 and a C++ 17 compiler. The simulation defaults to using paper trades and $100 in virtual balance, but it uses real BTC-to-USDC data. There are instructions on how to set up a live account to see if your trading skills are a match for an insect.

Anthropic says Claude thwarted bioweapon research from state-sponsored actors — covert accounts used U.S. proxies to attempt to engineer deadlier viruses, tried to evade identification and regional blocks

These days, AI companies directly or indirectly announcing how their respective wares are smarter than their competitors has become a genre of elevator music. Even so, some in-depth articles can be quite insightful, like Anthropic's occasional reports on attempted misuse of its wares. The latest one covers activity between November 2025 and September 2026, with an important reveal: five situations where Claude was asked to perform work determined to potentially be used in biological weapons.

Right out of the gate, Anthropic remarks on the difficulty of understanding if a particular line of inquiry pertaining to biology is meant for nefarious purposes, to create defense mechanisms like vaccines, or simply to establish predictions of how a virus spreads. The company says that "out of an abundance of caution [....] launched recent models with stronger safeguards."

Among the tens of case studies presented in the lengthy report, Anthropic discusses five cases that it deemed particularly concerning, three regarding viruses, and two more discussing toxins. The common theme across all of them is that all threat actors used varying degrees of anonymization techniques and did their best to evade Anthropic's own regional blocking. The report doesn't mention specific states, but the firm is known to block access to Claude for China, Russia, Iran, North Korea, among others.

In the first case, a request for assistance in developing a grant application involved finding ways to improve the chikungunya virus. The purported researchers were trying to come up with ways to both add extra abilities to chikungunya (increased mutation) and increase its virulence. The topic itself already raised some concern, but Anthropic's hand was forced after finding that although the grant application seemed to be for civilian researchers, the actual investigation was meant to proceed at a military facility.

The firm also found that the request would have gone through a third-party LLM platform associated with military as well as civilian institutions. The countries involved are geo-blocked by Anthropic, and that platform routed comms traffic through the U.S. to try to evade detection, used gray-market resellers, and specifically catered to customers looking to skirt content restrictions. Anthropic banned the accounts in question and shared the information with government authorities, though the same people repeatedly tried reaching Claude again via zero-data-retention services.

Case #2 pertained to a non-US researched who was looking to dig into how avian flu adapts to mammals, and how it can cause diseases other than in the respiratory tract. The problem is that avian flu has a high fatality rate, and there's little population immunity.

While the virus doesn't easily spread from person to person, therein lies the rub — the research could end up discovering mechanisms to increase transmissibility. The researchers used a random username, a private email service, and accessed Claude through a VPS, leading Anthropic to investigate and ultimately turn its nose up at this strain of thought.

The story with the third case bears a resemblance to the previous two. Once again, an account was trying to prepare a supposed grant application, this time around about orthopoxviruses, the family that houses smallpox and Mpox, among others.

The application discussed containment facilities and live experimentation with the viruses, and focused on understanding their genetics for the purpose of evading immunity. The research didn't initially trigger alarms, but Anthropic came to notice it was created via a reselling service, with a randomly-generated email, tunneled through U.S. infrastructure to reach Claude, and traced back to a banned account farm.

In the last two cases, instead of viruses, the purported researchers were focusing on toxins. In case #4, a person mapped out venom toxin peptides from multiple families of animals and created a program to optimize their toxic characteristics.

Although the stated goal was to create painkillers, antidepressants, and other therapeutic molecules, the data would equally allow the creation of potent harmful compounds. Anthropic also came to learn the content Claude was generating was part of a state-sponsored program in an "unsupported region."

In the fifth and final case, a theoretical scientist was also using Claude to try and redesign a set of toxins, also supposedly for therapeutic purposes, under a national public search program. However, the work touched upon "a bacterial toxin subunit and a protein of the hemorrhagic-fever virus" that happens to be on the World Health Organization's list for particularly nasty, pandemic-inducing diseases.

The scientist tried to obscure the subject of the research, directing Claude to be vague about descriptions. Once again, the story ended with Anthropic cutting off access to Claude from a location that broke its terms of service.

OpenAI's rogue AI agents accessed more websites to communicate than originally believed — defiant LLMs accessed old wikis and abandoned websites to co-ordinate in a bid to dupe assessors

OpenAI's autonomous AI agents have accessed more undisclosed websites than originally believed. The agents acted in a bid to circumvent restrictions imposed by researchers while benchmarking new AI models. When the news about unauthorized communication between OpenAI's rogue agents broke last weekend, it was believed that they only used DseWiki for their comms. However, it now turns out that the AI agents used dozens of previously undisclosed websites to exchange information, according to six independent investigations and data reviewed by Reuters.

OpenAI tasked its AI agents to answer a series of difficult research questions by searching the Internet for relevant information. The company let them browse the Internet and read websites, but it explicitly prohibited them from posting or modifying online content. Despite this restriction, between May and July the agents discovered unconventional ways to write to old wikis and abandoned websites, where they left information that other agents could subsequently retrieve to help complete their assigned research tasks.

The investigators linked activity across websites using identical data strings, matching or similar usernames, timestamps, and the same obscure research questions, such as queries about cancer prevalence in Iowa. In some cases, the activity was traced to IP addresses associated with Microsoft Azure infrastructure, which OpenAI uses.

So far, the researchers have identified between 18 and 23 potentially affected sites wherein rogue AI agents communicated, though they believe that there were considerably more websites used to exchange information, but they have not found them yet. Andrew Yoon of California nonprofit CivAI identified 18 previously undisclosed sites; Sydney Von Arx's group discovered credible evidence across 23, while software developer and former congressional aide Kenneth Russell DeGraff found related information on at least 10 sites according to the Reuters report.

The affected resources included collaboratively maintained wikis, text-storage services, and link shorteners operated by Vanderbilt University and the University of Toronto. Other websites were essentially abandoned by their owners. The list of these websites included an Advanced Placement Chemistry wiki created by a Massachusetts high-school teacher in 2008, two personal websites run by Polish technology workers, puzzle-oriented wikis, and a roughly two-decade-old site dedicated to text-editing software.

Perhaps the most alarming thing, besides the fact that AI robots can communicate with each other, is that OpenAI did not disclose how many websites were affected or explain why the activity remained undisclosed for months. It does stress that the scale or seriousness of the said misconduct was well below that of the famous Hugging Face breach in July. Meanwhile, the company reportedly said it is developing a framework for reporting model misalignment across training, evaluation, and deployment and said it will share it soon.

Old MacBook uses a mirror, webcam, and AI agent to code its own AMD GPU drivers — 'agent-first' Omarchy Linux debugs itself, AI can check its own progress on screen in real-time

10 September 2026 at 13:00

A Linux developer has shared a photo of their laptop using realtime visual feedback during an AMD Radeon GPU driver tuning task. Justin Schroeder (@jpschroeder) explains that “the MacBook is using its webcam to look at its screen in a mirror to improve AMD Radeon chip support in Omarchy.” Linux distro Omarchy is tailored “for the age of agents,” a field in which Schroeder is something of an expert. So, we assume the MacBook is running some kind of programming agent like Claude Code, and it is watching its own screen to assess the GPU driver tweaks it is making.

Can’t make this up…the MacBook is using its webcam to look at its screen in a mirror to improve AMD Radeon chip support in Omarchy. pic.twitter.com/pw5Yu0JVJ7September 9, 2026

Schroeder’s quirky hack has gained many admirers. We note that the Epic Games boss, Tim Sweeney, humorously commented on this use of AI, giving him “HAL 9000 lip-reading vibes.” Of course, HAL 9000 was the increasingly unhinged superintelligent computer from Kubrick’s 2001: A Space Odyssey. In the movie, it famously read the lips of astronauts plotting to limit its operational scope.

Since the MacBook is working on itself, it must be an older Intel Mac with an AMD GPU inside. Thus, the coding agent can refine Radeon hardware support and actually benefit from the webcam’s visual feedback.

Omarchy can be a good fit for users of older Intel-based Macs due to its specialized drivers and configurations. However, this interesting flavor of Linux is headlined as a handsome Linux distro designed for the age of agents. The OS’s homepage also boasts of a lightning-fast installation, with built-in agents that can debug issues. In short, users can “vibe your way through every alteration, tweak, or trouble.”

More details about this operating system can also be found on its GitHub repository. Omarchy isn’t just for ‘vintage’ Intel Macs like Schroeder’s image shows. It is available for Apple Silicon Macs and modern x86 PCs. Moreover, it is also suitable for ‘potato PCs’ like “a 2011 ThinkPad X220 with 2GB of RAM,” according to the developers. Omarchy is distributed under the MIT license.

China's AI accelerator supplier Biren posts 2,000% year-over-year revenue growth — US export controls benefit homegrown chips as Nvidia and AMD exit market

Biren Technology, a leading supplier of AI accelerators from China, posted massive nearly 2,000% revenue growth in the first half of 2026 amid skyrocketing sales of non-Nvidia AI processors in the country, according to Jon Peddie Research. Sales of the company's products began to climb rapidly in the second half of 2025 after American companies led by Nvidia stopped supplying their AI GPUs to the People's Republic due to export control measures.

Biren reported first-half revenue of $183.9 million, up 1,998% year-over-year from around $8.665 million in the first half of 2025. The company's gross profit rose to $78.552 million, and gross margin increased to 42.7%, but it still lost $56.2 million primarily because it continued to invest in new products, including AI accelerators, optically-interconnected rack-scale solutions, and software. Biren's revenues started to climb in the second half of 2025, so for the whole year its sales reached $154.17 million as its market share of AI accelerators in the country was below 3%, according to TrendForce.

For those who follow China's AI and GPU markets, Biren Technology is certainly a familiar name as the company's products are well documented and appear to be competitive with those developed by AMD and Nvidia on paper. The company has developed at least three high-end AI GPUs — the BR106, BR110, and BR166 — and is currently working on BR20X, BR30X, and BR31X accelerators, according to JPR. Biren has also built its own Birensupa software stack meant to compete against Nvidia's CUDA and is working on a rack-scale solution.

In reality, demand for domestic AI accelerators has always been relatively low in China, as even cut-down versions of Nvidia's leading AI GPUs provided better performance and software stack than solutions developed in China. While Nvidia charged $12,000 - $15,000 per H20 AI GPU when it sold these products in the PRC, it still supplied some 2.2 million AI accelerators to the country in the first half of 2025, when it could still ship them until the Trump administration's export controls kicked off in May, according to TrendForce. By contrast, Biren shipped thousands, maybe tens of thousands of AI accelerators throughout the whole 2025. Even today, Biren's shipments are minuscule compared to Nvidia's in 2025.

Without a doubt, Biren's financial improvement is real and impressive, but it is coming from an extremely small base in the first half of 2025, so the 1,998% 1H 2026 growth figure makes Biren sound much larger than it actually is. While Biren is growing at an enormous rate, with $183.9 million in revenue, it is still a relatively small accelerator supplier in absolute terms.

What remains to be seen is whether Biren can secure enough manufacturing capacity from SMIC or other suppliers to compete with larger Chinese AI accelerator vendors, such as Huawei, Kunlunxin, and Cambricon. The company certainly has more financial resources than it did a year ago and faces less formidable competition from AMD and Nvidia amid U.S. export restrictions and China's own bans on American AI hardware. But having competitive designs is only part of the equation: Biren now must manufacture enough accelerators to satisfy customer demand and substantially increase its market share.

OpenAI says its next-generation processors could be made at Samsung — double-sourcing with TSMC hints at massive volume requirements [Updated]

OpenAI is expanding its relationship with Samsung beyond memory supply and enterprise software as the AI giant plans to outsource production of at least some of its processors to Samsung Foundry, Harrison Kim, General Manager of OpenAI Korea, revealed this week. If the information is accurate, then OpenAI will source its AI accelerators from both TSMC and Samsung Foundry, which suggests massive volume requirements.

"One of the areas where we have made the most progress and gained the most recognition with Samsung Electronics is our joint production and ​research on the next-generation chips we are developing," said Harrison Kim, General Manager of OpenAI Korea, at ​a press conference in Seoul, Reuters reports.

OpenAI already has its own AI ASIC program that relies on Broadcom's design services as well as TSMC's wafer processing and advanced packaging services. So far, the company has introduced its first inference AI accelerator called Jalapeño that was defined by the company's engineers, then co-designed with Broadcom, then made by TSMC, all in less than 18 months.

OpenAI did not explain whether Samsung's participation concerns a second production source for Jalapeño, another processor under development by OpenAI, a chip jointly developed by Samsung and OpenAI, or some other aspect of chip production and development. Samsung and SK hynix already supply memory for OpenAI's Stargate data center initiative, though joint chip development and production barely have a relation to DRAM supply.

OpenAI's 1st Generation Jalapeño will unlikely be double-sourced from TSMC and Samsung because the chip is already in mass production at TSMC and OpenAI is talking about 'next-generation chips,' not the ones that are in mass production at the moment. Furthermore, development of Jalapeño's successor is well underway and is approaching tapeout, which means that its mass production is not far away either. Since OpenAI's claim clearly involves 'next-generation chips,' it is entirely possible that OpenAI will indeed produce its 2nd Generation inference ASIC at Samsung Foundry.

Back in late July, Samsung Electronics and Broadcom announced a strategic partnership valued at over $200 billion through 2030 to collaborate on advanced foundry, memory, and packaging technologies for AI infrastructure. Hence, as OpenAI has an agreement with Broadcom to procure 10GW of custom AI accelerators, it will be able to produce these accelerators at both Samsung and TSMC. Of course, if it needs silicon produced at Samsung, and pays Broadcom for appropriate design porting.

Perhaps, OpenAI will take a page from Tesla's book and will double-source Jalapeño's successor from TSMC and Samsung to get higher volumes. However, Tesla's volume requirements may be different from those of OpenAI.

Tesla needs extraordinary AI5 volumes because it intends to use the processor across three very different high-volume applications: AI data centers, vehicles, and Optimus robots. Therefore, Tesla could potentially need millions of AI5 chips for cars alone, on top of robots and data-center deployments. Therefore, paying for separate TSMC and Samsung physical implementations gives Tesla not only supply-chain resilience but also aggregate capacity necessary to supply several product categories.

Yet, data center accelerators tend to be vastly more silicon-intensive per unit compared to ASICs for vehicles or robots. If OpenAI/Broadcom's next ASIC is a large leading-edge processor with multiple dies and OpenAI wants gigawatts of these processors, wafer requirements could still become too high for TSMC alone (which is fully booked by the likes of AMD and Nvidia). In that situation, OpenAI may need another foundry to get enough ASICs. Still, we are speculating.

OpenAI's breakthrough solution for the elusive Navier-Stokes problem overshadowed by plagiarism controversy — researcher says OpenAI scraped Codex session and issued career threats

Most anyone involved in computing has heard about the P-NP problem, but fluid engineers and mathematicians would love to know if the Navier-Stokes equations have smooth, globally defined solutions. Both questions are part of the Millennium Prize Problems, solutions to which are worth a cool $1 million and eternal renown. OpenAI is claiming that its staff and internal models have solved the conditions of Navier-Stokes solutions set forth in the Millennium Prize. But the company's shouting from the rooftops is being met with a chorus of boos over claims it might have plagiarized the work of a research team that had been toiling on a related, stepping-stone problem for a year.

Tristan Buckmaster (a scientist at NYU) and Levent Alpöge (a member of Anthropic's staff) had been quietly working on proving Euler's equations — another long-standing mathematical problem, and one that is generally acknowledged to be a stepping stone to solving Navier-Stokes.

According to Buckmaster, his work with Alpöge was "a purely personal collaboration, free of any institutional agreements or official involvement by either of our employers." The researchers used Anthropic Claude and OpenAI Codex as assistants, as is apparently now common in the field, to perform busywork (documentation, searching, etc.) as well as running through logic steps. The substantial amount of compute time the project required was paid from Buckmaster's own pockets, too.

The pair worked for roughly a year until August 15, 2026, when it obtained "the blowup results, with smooth forcing, for both Boussinesq and Euler." Buckmaster says the novel approach was based on previous work by Diego Córdoba and Luis Martínez-Zoroa, and he believes Zoroa should be eligible for a Fields Medal.

Although the team was presumably happy with these achievements, Buckmaster said that the LLM-generated proof was "the most horrendous" he'd seen, calling it "AI slop," and meaning to rewrite it for clarity. Nevertheless, they verified it on August 22 using Lean, a standardized programming language designed specifically to verify mathematical proofs.

Come September 3, Alpöge told Buckmaster of rumors going around that Anthropic had solved an important mathematical problem. This almost certainly alluded to the team's work, and some apparently took it to mean the company itself was working on the problem. The rumor-mongers even theorized that the problem that Anthropic had solved was Navier-Stokes. Alpöge further believed that OpenAI had gotten wind of the news.

This prompted Buckmaster to email an unnamed "prominent mathematician" at OpenAI, clarifying that the effort was a personal collaboration between him and Alpöge and was unrelated to Anthropic. The mathematician replied asking for details, saying "it would be useful to avoid competing," and offering OpenAI compute time. After a few days, on September 6, Buckmaster, the unnamed person, and OpenAI's Sébastien Bubeck talked twice, without Alpöge. He was told that OpenAI had proven a finite-time blowup for the forced Navier-Stokes equations, a subset of the problem.

Alpöge asked by text for the precise statement and was told "existence of forced blowup in R³ and T³", and that "the forcing function is smooth option [C] and [D] in Fefferman," referring to one of the four possible categories established by the Millennium Prize, with any one of them being valid as eligible for the prize, but not constituting a full solution for all scenarios, a distinction remarked on by other scientists.

This is where the story becomes interesting. Buckmaster claims that that idea (forced blowup) was exactly the same one his team had "quietly" chosen, and that nobody else he knew was working on it. Perhaps most importantly, he says that that was "not the direction one arrives at in a few days by giving a model the problem statement," indicating that running the general problem through a bot wouldn't quickly reveal that potential approach.

In fact, Buckmaster claims that over the calls, Bubeck ultimately revealed that instead of just AI models and agents with a couple of handlers, there was an entire team of live humans working on Navier-Stokes. The OpenAI team first had the models try to work through easier paths, and the text prompt that generated the Navier-Stokes proof had itself been generated by prompting Codex, with an "insane" amount of computing needed.

Buckmaster then asked when the initial prompt was issued, and OpenAI's response of "in the past few days" did not arrive until "some time" passed. He proceeded to ask if the model "had been trained on, or had access to, our sessions in Codex," and was told by OpenAI that Codex does not access user data. Finally, he asked if the data was used for model training more generally and, crucially, apparently did not get an answer.

OpenAI allegedly offered Buckmaster two options: one, that Buckmaster and Alpöge publish their Euler proof first. The following day, OpenAI would post its Navier-Stokes proof, giving the two priority. The second option was that Buckmaster alone, without Levant, was to write a paper with the Navier-Stokes proof, acknowledging that an internal OpenAI model resolved it. Bubeck was apparently adamant about Levant's removal from the Euler proof, as his employment at Anthropic was "annoying." Buckmaster opted for neither, and told OpenAI that if it chose the first option, he'd go public with his findings, as has since occurred.

This prompted what Buckmaster interpreted as a threat from Bubeck, who asked him "why [he] would ruin [his] career." After Buckmaster asked why that would happen, Bubeck told him, "If you don't want me to be nice, then I don't have to be nice." Bubeck then allegedly reached out to Alpöge, questioning Buckmaster's sanity, to which Alpöge responded with a refusal, pointing inquiries back to his colleague.

The entire story raises pointed questions about what OpenAI (and others) are actually doing with user data collected via its LLMs, despite the toggle switches that are supposed to disable it. Not only has OpenAI neglected to tell Buckmaster whether it used his team's data for training, in its PR about Navier-Stokes, the company says while it "no specific user data was accessed in order to solve this problem," it "cannot rule out that de-identified data derived from their usage of our products helped improve [its] models."

OpenAI's proof still needs to undergo a likely years-long peer review before any party can take the Millennium Prize home. The firm has stated it does not intend to claim it. As for Bubeck, he predictably paints the story in a very different light, but insists that his pushing away of Alpöge is justified on the basis that "it would be inappropriate for an Anthropic employee to author OpenAI's work," a puzzling statement that some could take as meaning a double standard regarding scientific authorship, based solely on corporate rivalry.

For his part, OpenAI CEO Sam Altman claims his team was well-intentioned and cooperative, and supported Bubeck, saying "it was challenging to offer [the same publication options] to Levent." Neither person opted to discuss the matter of whether OpenAI used the research of Buckmaster and Alpöge as training data, or offered any further explanation of why Alpöge didn't deserve credit for his work as an equal to Buckmaster.

Given the groundbreaking nature of this apparent discovery and the ensuing fight for priority that these competing accounts have sparked, it'll likely take quite some time and review before we know whether and how OpenAI or Buckmaster and Alpöge will be credited with this discovery. But given the inter-lab rancor already on display, the process will surely be ugly.

OpenAI claims GPT-6 Astra is an ethereal 'Alien Mind' with AGI-like qualities — company warns of alignment challenges as new frontier leader emerges

9 September 2026 at 11:20

"AI is grown, more than designed," OpenAI's chief scientist, Jakub Pachocki, said in a new blog post on the company's latest GPT-6 Astra release. Titling the piece "An Alien Mind," Pachocki portrays the latest large language model as something more ethereal and harder to quantify. Jensen Huang calls it AGI, and OpenAI claims it's the best, most aligned model the company has ever released. It's safer to delegate, better at complex work tasks, and it can even beat Portal in just a few hours.

Huang also said that AGI had previously been achieved back in March earlier this year. Artificial Analysis benchmarks suggest Astra is about as smart as Fable 5.1 - though crucially, cheaper on a per-task basis. Astra may well be better aligned than models in the past, and it may well be more capable in specific tasks and specific benchmarks. However, the claims that the model has achieved AGI, or Artificial General Intelligence, suggest an inflection point for the AI industry.

Astra's release comes alongside calls for an industry slowdown, greater government oversight, and controls on the AI industry. Now, OpenAI's Astra raises more eyebrows about frontier-level intelligence.

Trust us, we don't know what we're doing

The tone around OpenAI's Astra release is intriguing. OpenAI's produced a new set of benchmarks, touting bold claims about the model's reasoning capabilities, with the model trained on 100,000 Blackwell GPUs, with more coming soon.

GPT-6 Astra, trained on ~100K+ NVIDIA Grace Blackwell NVLink72. From ChatGPT to o1 to Astra in 4 years.AGI has arrived. Congratulations @OpenAI team.400K GPUs coming online next.September 6, 2026

But Pachocki's blog post is much more nebulous. While Huang touts that AGI has arrived publicly, Pachocki says AI can only ever "simulate facets of human behaviour," not recreate it. He describes AI development as an experimental process that often "surprises" developers, with results that are "harder to interpret."

"An aligned AI should act with honesty and integrity, with love for humanity," Pachocki said. He speaks a lot on alignment, and it's encouraging that OpenAI is so keen to embed human moral understanding into its developments. Although OpenAI appears to be doing this more by orienting the model's goals towards a moralistic outcome, rather than helping to intrinsically understand human morality.

It's certainly different to the tack taken by other AI developers, where the likes of xAI's Grok was released with the ability to generate harmful content.

But the timing of Pachocki's warning is a little suspect. OpenAI has faced increasing pressure of late for its models to be more affordable, with Chinese alternatives like Deepseek V4, Kimi K3, as well as Western models like Google's Gemini Flash 3.8 and Meta's Muse Spark 1.3 offering compelling levels of intelligence at a much more affordable price than the frontier models.

It's perhaps telling that even for all its intelligence and alignment pre-training, GPT 6 Astra is notably cheaper to run on the Artificial Analysis Intelligence Index than its chief rival, Anthropic's Fable 5.1 — which still retains the top spot on that Intelligence Index at the time of writing. Though it's 50% more expensive than GPT 5.6 Sol on the same tasks.

It's a researcher, but imagine what it could be

A huge component of marketing from the major AI developers has consistently been grounded in the idea that, as good as the models are now, just imagine how capable they're going to be in the future.

This was very much the underlying tone in Pachocki's breakdown of Astra's design and functions. Although he and OpenAI make broad suggestions about intelligence, and that the likes of Astra could be this new kind of intelligence which we don't really understand but can definitely control and corral, Pachocki ends his post by making it very clear that we aren't there yet.

OpenAI is prioritizing three areas of work with AI, and of late it's really just been trying to make a really good researcher. That's where we're at right now, with Astra representing the latest and best effort to develop that. Then comes the scientific progress, he said, and then everyone gets their own individual, personalized AGI helper.

Intriguingly, though, that seems to suggest that's something that everyone is clamoring for. Outside of the AI-boosting programmers who jump on each new hot model, the larger work comes in helping non-technical users understand the capabilities of these new, powerful AI models.

Tools, research capabilities, drug discovery, and pattern recognition on big datasets that find new insights and improve analytics are all legitimate and useful ways in which an AI researcher can be deployed, but in the near term, most of the general populace just don't want AI to take their jobs, and for it to be less scary.

It's encouraging that Pachocki's blog ends on a similar note of caution.

"We need to find ways to preserve human agency and enshrine an intrinsic value to being human, in a world where most tasks could be performed by AI."

That's key, but intriguingly, he also calls on others to take charge of that effort.

We didn't start the fire

In the aftermath of cost concerns and token usage exploding among more affordable alternatives, Pachocki wants everyone to slow down, and OpenAI wants world governments to be in charge of it.

"I believe that international coordination on future AI development needs to become a top priority for governments around the world," Pachocki said, calling for voluntary slowdowns and hinting that if that doesn't happen, enforcing it may need to come via legislation instead.

"... to ensure that humans remain in control of the future and are not left behind by unchecked progress, brought about by an alien intellect exceeding our own."

The threat of runaway is valid, and the "singularity" moment is a common trope in sci-fi that AI evangelists have been warning about for years. But Astra isn't AGI. Even getting anyone to agree on what AGI even means is hard enough.

Astra is more aligned and wins some new benchmarks, loses some others. It's another improved coding model with some impressive chops.

Astra is not an alien mind. Framing it as an unknowable entity, by the very people who made it, can read as inflammatory, especially in the context of calls for AI legislation from governments around the globe.

OpenAI's post might read like a post from a non-profit, but it very specifically became for-profit last year. With a future IPO looming, slowing down the competition by calling for legislation may be just as effective a strategy as rolling out a new model.

More than 10% chance AI 'could kill all humans' in the next 10 years, Anthropic safety researcher says — departing employee says AI companies are 'gambling with our lives'

Anthropic safety researcher Evan Hubinger has warned there is a more than 10% chance that AI could kill all humans within the next decade, but reassured the public the company is "trying its best." The revelation comes following Jacob Coxon's public resignation from the company, where he stated that neither OpenAI nor Anthropic is acting responsibly, accusing both companies of gambling with human lives in the pursuit of self-improving super-intelligence.

"I resigned from Anthropic today. I spent the last three years doing pretraining research at both OpenAI and Anthropic," Coxon said in a tweet Wednesday. "Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives."

Expanding on his thoughts, Coxon warned readers not to underestimate the powers of AI, which he says will soon be "superhuman systems that can hack anything, revolutionize any field overnight, and acquire real power and resources."

I resigned from Anthropic today. I spent the last three years doing pretraining research at both OpenAI and Anthropic. Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives. More thoughts below.September 9, 2026

Coxon went on to state that the people who are building AI "earnestly believe that it could kill us all by the end of the decade," and further warned that executives and researchers — rather than playing up fears around AI, as some have accused — are actually restraining themselves, expressing much more candid views in private.

Evan Hubinger, a security researcher at Anthropic who hasn't departed the company, chimed in to state, "Jacob is correct here," in no uncertain terms. "We really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade. I believe Anthropic is trying its best, but we do not yet have a plan to solve alignment for superintelligence and are not clearly on track to."

Hubinger casually admitted that Anthropic is not only worried about the prospect of AI wiping out humankind, but that it currently doesn't have the tools to stop such an eventuality.

The revelations follow increasingly alarming reports of AI agents acting up during testing, escaping sandbox environments, and even collaborating with each other in order to cheat benchmarks and tests, or figure out problems without human oversight. OpenAI recently admitted its agents were discovered using a programming hub to communicate with each other, while earlier this year an OpenAI agent went rogue and hacked popular AI community Hugging Face. Further revelations about the incident revealed AI agents were on the loose on the open internet for several days, with details revealing the AI models broke out of their testing environment using thousands of individual actions, even collaborating.

Coxon, the resigning researcher who kicked off Wednesday's revelations, concluded by warning researchers to consider the next few years, urging them to call for "different conditions" in which to pursue superintelligence.

Benchmarking Qwen 3.8 27B on RTX 5090 and beyond — VRAM capacity alone can't overcome severe software and inference engine bottlenecks

8 September 2026 at 13:30

Alibaba’s Qwen 3.8 27B open-weight AI model came out a couple of weeks ago, and it immediately created a wave of hype among local AI enthusiasts thanks to its impressive intelligence benchmark results for a model of its size and capabilities.

Totaling around 17GB for four-bit quantized weights and offering built-in multimodal capabilities on top of its general aptitude, Qwen 3.8 27B immediately grabbed the attention of everybody with an RTX 5090, RTX 4090, or RTX 3090 (as well as a Radeon RX 7900 XTX, Radeon AI Pro R9700, or Arc Pro B70).

Were we on the verge of frontier-level intelligence from a four-bit quant on a single graphics card? Could everybody with a capable enough local AI setup go and cancel their Claude or ChatGPT subscriptions?

The answer, of course, as with every open-weight AI model hype cycle, is more complicated than just eyeballing the size of the model weights and comparing it to your available VRAM pool. Does the card or system you're using to host the model have enough VRAM left over to provide useful amounts of space for the model's context once everything is running? Do your host system and LLM inference engine deliver acceptable time-to-first-token, as well as high throughput beyond just bench-racing from an empty context window?

It's one thing if you just want to chat with a model and see what happens; it's another entirely if you want to put it to work, especially as impatient agents take the limits of human perception out of the picture.

We wanted to see what hardware and software stack Qwen 3.8 27B really wants in order to deliver solid performance, so we ran it on systems ranging from a desktop PC with discrete GPUs to systems with unified memory architectures like the DGX Spark, Mac Studio, and Ryzen AI Halo.

Our discrete GPU AI testbed includes the following components:

Tom’s Hardware Local AI Testbed

CPU

Ryzen 7 9800X3D

Memory

64GB (4x16GB) DDR5-5200

Motherboard

Asus TUF Gaming X670E-Plus Wifi

SSD

Corsair MP600 Pro XT 4TB

Power supply

MSI MPG Ai1600TS

Operating system

Ubuntu 26.04 LTS

Where it was possible to do so, we tested performance with Qwen 3.8 27B’s built-in multi-token prediction capabilities both enabled and disabled. Not all of the model runners we tested were able to support MTP within the amount of VRAM available to us on some of our platforms. We note where MTP was and wasn’t possible in our analysis of each platform, as well as in our charts.

RTX 5090 performance

We started with the RTX 5090, whose 32GB of GDDR7 and 1.8 TB/s of memory bandwidth would seem to make it an absolute no-brainer for getting the best local inference performance with this dense model. (Mixture-of-experts models tend to be friendlier to performance on lower-end hardware like the DGX Spark and AMD's Strix Halo, as their limited numbers of active parameters mean less data movement during inference).

As a baseline, we followed our usual local AI benchmarking approach: grab the latest build of llama.cpp from GitHub, build it, grab an Unsloth quantization of the model from Hugging Face, and run it. But our testing quickly ran into a speed bump.

RTX 5090 Llama benchmarks
Tom's Hardware
RTX 5090 Llama benchmarks
Tom's Hardware
RTX 5090 Llama benchmarks
Tom's Hardware
RTX 5090 Llama benchmarks
Tom's Hardware

Although llama.cpp will happily allocate the full 262K context length with this model on an RTX 5090, its processing speeds at long contexts on this card are dire.

Time-to-first-token with a single 5090 stretches to roughly 30 minutes, suggesting that something is just broken here. And tokens-per-second throughput drops far, far below what you would expect for having one of the world's fastest graphics cards at your disposal. No matter how you slice it, llama.cpp is not the right model runner for this hardware right now.

Next, we tried vLLM, a production-grade inference engine that's more at home in the data center than it is on the desktop, although it can comfortably serve in both roles—at least if your host system is up to its requirements. Even with 64GB of main memory in our test rig, we had to allocate another 64GB of swap just to let vLLM load Qwen 3.8 27B successfully for the first time. A lightweight stack this is not.

The vLLM maintainers provide an NVFP4 quantization of Qwen 3.8 27B and deployment recipes for both one and two RTX 5090s. We just so happen to have two RTX 5090s in the TH labs, so we were able to try out both configurations.

RTX 5090 VLLM

(Image credit: Tom's Hardware)

RTX 5090 VLLM

(Image credit: Tom's Hardware)

Serving Qwen 3.8 27B on one 5090 with vLLM certainly works in a pinch, but it's not ideal for long-context inference because the base recipe for it limits you to just a 32K context. To get the full 262K context, you really want a single card with more memory (like an RTX Pro Blackwell card with 48 or 72GB of RAM) or two 5090s, as we were able to test.

And a single card doesn't have enough memory to enable Qwen 3.8 27B’s built-in multi-token prediction (MTP), which is super helpful in getting faster decode performance from this setup. 20 tokens per second across the board without MTP is not an impressive baseline for a card of this caliber.

RTX 5090 VLLM
Tom's Hardware
RTX 5090 VLLM
Tom's Hardware

Get two 5090s into the picture, though, and decode speeds rocket upwards for vLLM (albeit at a high cost to prefill). 70-80 tokens per second across the context depth sweep is a fantastic result for a local setup, and TTFT remains fairly reasonable. But we can go faster.

Enabling MTP with vLLM gets us to 100-110 tokens per second on the decode side for only a small hit to prompt processing speed. This setup provides consistent performance at prompt processing speeds that don’t make you question whether something has gone seriously wrong. But it ought to be fast, because our dual RTX 5090 platform as tested here would currently ring in at over $13,000.

We also tried the SGLang inference engine on the RTX 5090 across similar configurations as we did with vLLM.

RTX 5090 Qwen 3.8 SGLang
Tom's Hardware
RTX 5090 Qwen 3.8 SGLang
Tom's Hardware

SGLang is much faster on a single 5090 for some reason – almost 3x faster than vLLM’s single-5090 recipe – and also ekes out a bit more context (37,740) versus vLLM. But if you want to get the full 262K that the model natively supports, you still need a second card or a different one with more VRAM.

RTX 5090 Qwen 3.8 SGLang
Tom's Hardware
RTX 5090 Qwen 3.8 SGLang
Tom's Hardware

Like vLLM, SGLang supports tensor parallelism across multiple GPUs, so enabling dual-GPU inference is as simple as adding another launch flag. And as with vLLM, there are a number of speculative decoding strategies you can add to the recipe to enhance output performance.

The takeaway from this first phase of testing: if you have a single RTX 5090 and don't need long-context inference from it, you can certainly get usable performance from one with this dense model. But you need to choose your model runner carefully.

And if you want the full context window, reasonable prompt processing times, and high throughput from Qwen 3.8 27B all at once, you really want a graphics card with more than 32GB of VRAM as a starting point (or multiples).

RTX 3090 and RTX 4090 performance

With the RTX 5090’s behavior settled, we turned to some older consumer cards to see how they handle Qwen 3.8 27B. The 24GB RTX 4090 and 3090 are evergreen favorites among local LLM fans thanks to their relatively large VRAM pools and relatively affordable prices on the used market, but as we've already emphasized, just being able to load the model weights is far from the whole picture.

These cards can fit the Q4_K_M GGUF of Qwen 3.8 27B with llama.cpp just fine, but they require using the Q8_0 quantization of the KV cache to fit the results in their smaller VRAM pools from the get-go, and they also require limiting the context depth to well under the model’s 262K native limit. We found that a context length of about 112K tokens was about the most we could get away with before running out of VRAM.

And unlike the 32GB RTX 5090, which can usually get away with having the Linux desktop window manager running next to the LLM and its infrastructure, these GPUs need every last byte of VRAM for the AI workload and nothing else. So you really want a separate graphics card at hand for these two cards if you're not running a headless server, which can introduce some setup headaches of its own as you discover how your particular motherboard handles PCIe slot bifurcation and enumeration of the primary graphics device.

RTX 3090 Qwen benchmarks
Tom's Hardware
RTX 3090 Qwen benchmarks
Tom's Hardware
RTX 3090 Qwen benchmarks
Tom's Hardware
RTX 3090 Qwen benchmarks
Tom's Hardware
RTX 4090 Qwen Benchmarks
Tom's Hardware
RTX 4090 Qwen Benchmarks
Tom's Hardware
RTX 4090 Qwen Benchmarks
Tom's Hardware
RTX 4090 Qwen Benchmarks
Tom's Hardware

Once you overcome those obstacles and get Qwen 3.8 27B up and running on these cards, llama.cpp exhibits the same performance cliff at long contexts on the RTX 4090 that we saw with the RTX 5090. But the RTX 3090 is oddly not affected. This suggests a bug somewhere.

We didn’t have time to dig into SGLang or vLLM behavior on these products, but given that you’re already tight for context on an RTX 5090, we’re doubtful that either of those inference engines would be an awesome way to run the model on these 24GB cards, unless you’re somehow ready to roll with multiple 3090s or 4090s from past acquisitions.

DGX Spark performance

Hardcore local LLM enthusiasts will scoff at the DGX Spark’s mere 27 GB/s of memory bandwidth for a dense model like Qwen 3.8 27B, and indeed, we've found that this platform isn't the fastest with dense models in our past testing.

But now that models like Qwen 3.8 27B support MTP with nothing more than a server launch flag, you can often get a major free boost to the decode speeds of platforms with limited memory bandwidth.

DGX Spark Qwen Benchmarks
Tom's Hardware
DGX Spark Qwen Benchmarks
Tom's Hardware
DGX Spark Qwen Benchmarks
Tom's Hardware
DGX Spark Qwen Benchmarks
Tom's Hardware

In our actual tests, the Spark's solid prefill processing performance means that it will often end up finishing inference turns at longer context lengths well before the RTX 5090 does with llama.cpp.

And beyond llama.cpp, the Spark is also well supported by SGLang and vLLM, so you can take advantage of those inference engines if they’re more to your taste. Consider also that a single Spark is still available for about $5000, and it’s a turnkey system that can be expanded into a handy cluster down the line if you want. So it shouldn’t be ruled out, even for serving this dense model.

Apple Mac Studio with M4 Max performance

The M4 Max-powered Mac Studio in our labs has the most memory bandwidth of any of the unified memory systems we have available, but as we've described in previous testing, that's only one metric that matters for local AI inference.

M4 Max Qwen Benchmarks
Tom's Hardware
M4 Max Qwen Benchmarks
Tom's Hardware
M4 Max Qwen Benchmarks
Tom's Hardware
M4 Max Qwen Benchmarks
Tom's Hardware

Prompt processing on this platform is slower than on Spark, so even if the Mac Studio can turn out more tokens than GB10 in the decode phase, it still ends up spending more time per inference turn than Nvidia's platform at longer contexts because that’s where it has to spend most of its processing time.

And at least in llama.cpp, using MTP on the Mac Studio actually causes a performance loss at shorter contexts for decode in exchange for a small boost at longer contexts, where it generally leads to improvements for other platforms. This demonstrates the value of actual benchmarking rather than spec-racing.

Ryzen AI Halo (Strix Halo) performance

AMD’s Ryzen AI Halo presents the worst-case performance scenario for this dense model: relatively low memory bandwidth and low prompt-processing performance.

Ryzen AI halo Qwen Benchmarks
Tom's Hardware
Ryzen AI halo Qwen Benchmarks
Tom's Hardware
Ryzen AI halo Qwen Benchmarks
Tom's Hardware
Ryzen AI halo Qwen Benchmarks
Tom's Hardware

Although MTP wakes up tokens-per-second throughput a bit on this system with llama.cpp, it can’t make up for the lengthy prompt processing times required for longer contexts. You can certainly run this model if a Strix Halo is the only box you have, but we’d seek out something more capable if you’re trying to do interactive long-context work.

Bottom line

When I first set out to explore Qwen 3.8 27B's performance, I figured this would be a relatively straightforward series of tests: plug in a single graphics card, load the model, get tokens, done. In practice, our experience required a lot more tinkering. And systems we might have initially written off as being not up to the task of running a dense model like this proved surprisingly useful.

In general, breathless claims of hundreds of tokens per second of throughput from an empty context window do not account for the full range of behavior one might see from an LLM on a given inference setup.

For just one example, whether it's down to a problem with (or just the expected behavior of) llama.cpp or something else about our software stack, the notion that you'd want to wait as much as 30 minutes or more for a response from Qwen 3.8 27B at long context lengths on an RTX 5090 is outrageous. But if you naively load Qwen 3.8 27B using llama.cpp right now, this is the experience you'll get.

Changing up inference engines is a natural next step, but there are trade-offs with that approach, too. You can load Qwen 3.8 27B on one 5090 using vLLM or SGLang, but those inference engines are much more conservative about the amount of usable context they’ll give you. The recipes we used only resulted in a context window of 32K tokens on a single 5090.

To enable the full 262K context length, we had to grab another RTX 5090 from the TH testing arsenal, at which point we got both great throughput and a TTFT sweep that could be considered interactive all the way out to the maximum context length from both model runners. But the price of replicating such a setup would exceed $13K right now.

You also might expect that a DGX Spark and its 273 GB/s of memory bandwidth wouldn't be useful for this dense model, but the prefill speed of the Spark ends up being fast enough that the TTFT remains relatively interactive even with a decode throughput of just 20 or so tokens per second with MTP, and that behavior holds out to the model's full native context length.

The M4 Max-powered Mac Studio has plenty of memory bandwidth on tap for decode, but its prompt processing speed means that the total time of an inference turn is dominated by that activity on this older Apple Silicon chip. The newer M5 Max and brand-new M5 Ultra would doubtless perform better, but we didn’t have those chips handy for this testing. And AMD’s Ryzen AI Halo gets the worst of it, with both low prompt processing speeds and relatively low TPS due to its memory bandwidth.

For all this, we really need to take a step back and consider the economics of local AI once again. $5K, $10K, or $15K or more for local AI hardware is a lot of tokens from leading-edge models at Anthropic or OpenAI (and even more from providers serving the recent slate of Chinese open-source models). A lot. And if time is money for you, barring compute constraints, those tokens will get back to you or your agent faster than anything you can run at home short of a DGX Station with its GB300 GPU.

So unless you’re working with sensitive data that requires on-premises processing, you’re an enthusiast who just wants to tinker, or you’re worried about the fate of open model distribution and inference more generally for some reason, you probably don’t need to rush out and build a box just for this model.

But if you do, be aware that delivered performance is more than just VRAM capacity or memory bandwidth, and that you might not get the best performance from your setup with the most common model runners like llama.cpp. Let experimentation and careful benchmarking lead you to the best results for your specific config.

OpenAI’s GPT-6 Astra model autonomously completes Portal in 24 hours — feat cost just $571 in tokens

7 September 2026 at 13:25

An AI and LLM enthusiast has conducted an experiment where OpenAI's new GPT-6 Astra played through the entirety of Valve's Portal 3D puzzler game on its own. This seems like a remarkably progressive step forward for LLMs and a convincing demonstration of multimodal 'AI intelligence.' It wasn’t that long ago AIs were losing at Atari 2600 chess. However, this puzzle gaming task resulted in 3,336 tool calls and a headline API cost of $571.18. CozyBlaze, the enthusiast, has since clarified that the costs were covered by their $200 Codex Pro subscription.

The video above has Astra’s thinking/pauses removed to make watching somewhat bearable.

“The model controls Portal through MCP [Model Context Protocol] + a modified SourcePauseTool,” explains CozyBlaze. “The game stays paused while the model thinks; once the model sends an input sequence, SPT unpauses and executes it.” During the thinking time, the AI received screenshots and information about the player character position. After this, the game resumed, and Astra executed its planned moves and inputs. This is why the edited highlights reel is ~ 2 hours, but the full set of GPT-6 Astra Portal VOD streams adds up to ~24 hours.

And... GPT-6 Astra has autonomously completed Portal! I didn’t expect this to happen so soon, but I’m glad we've made so much progress here.I was reminded that back in 2016, one of OpenAI’s technical goals was to “solve a wide variety of games using a single agent.” pic.twitter.com/2nVREdCbMISeptember 5, 2026

CozyBlaze is pragmatic about the achievement. They admit there are still many problems to solve, and this runthrough shouldn’t be viewed as an AI benchmark. “But watching a general-purpose agent autonomously navigate and make it all the way through the game feels like a small glimpse of that original vision becoming real,” they observe. That original vision is OpenAI’s from way back in 2016, when an eventual goal of a single agent solving a variety of games was mentioned.

If you want to see the inner workings of CozyBlaze’s Portal Agent, it is available on GitHub. There are some instructions there for you to explore it or try it for yourself, too.

GPT-6 Astra became OpenAI’s flagship model earlier this month. OpenAI claims the new model offers “a new generation of intelligence,” and “is state-of-the-art on computer use, browsing, software engineering, cybersecurity, science, and professional work.” Expect to see more of Astra flexing its muscular gray matter in the coming days.

OpenAI admits to 'wiki incident' after its agents were discovered using a programming hub to communicate — says more transparency is needed regarding misalignments

OpenAI has admitted that its experimental AI agents used an open German programming wiki to communicate, according to a Reuters report. This happened weeks before similar AI agents broke through restrictions and compromised Hugging Face, the report claims. Knowing about the issue, OpenAI did not disclose it, but now says the industry needs better standards for reporting unintended AI behavior. OpenAI admitted the misconduct. But this wrongdoing raises more questions than it provides answers.

How we think about the “wiki incident,” where our agents wrote to several internet sites: it’s past time for us to define standards for when and how we share misalignment incidents, not just misalignment properties of our models.Historically, we have treated misalignment… pic.twitter.com/NNTbfSxVWnSeptember 5, 2026

Starting around May 2026, thousands of OpenAI agents — which are essentially well tooled advanced crawlers — discovered that they could write to DseWiki, an old German-language programming collaborative website. So, between May and June, the agents used more than 3,700 names to generate some 18,000 posts exchanging information useful for completing evaluations and circumventing restrictions. Some created backup pages in case moderators deleted their posts, something that essentially turned a wiki into a persistent storage service for the said agents to share information. OpenAI calls this the 'wiki incident' and admits the wrongdoing.

"Our misalignment disclosure practices need to expand for this new phase of model capabilities," the company wrote in an X post. "We and the larger AI community do not yet have a clear standard for how to report misalignment that shows up during training, evaluation, and deployment, including examples that do not look like traditional security incidents but could provide insight into AI behavior and future risks. We are working on a framework and will share it in upcoming weeks, and in parallel we're working with dozens of government regulatory agencies worldwide on these issues."

OpenAI subsequently quarantined the trained weights of the experimental model involved, postponed frontier reinforcement-learning runs, and added security measures. The company further clarified that the agents had not developed their own objectives, but were aggressively pursuing assigned ExploitGym cybersecurity challenges and treated restrictions as obstacles to complete them.

To do so, agents found unintended communication channels that enabled separate runs to exchange vulnerabilities, techniques for obtain Internet access, something that eventually exposed Hugging Face credentials.

According to researchers, the advanced crawlers — which Open AI calls AI agents — exploited an unknown vulnerability in the company's internal Artifactory package-registry proxy, escalated privileges, moved across systems, and reached the Internet. They then compromised dozens of Hugging Face servers, obtained root access to one machine, accessed some private information and messaging credentials, and copied private evaluation data into a public Hugging Face dataset. And the rest is history.

Breaking Asimov's law?

OpenAI's agents may sound like something that would violate Isaac Asimov's famous Three Laws of Robotics, but the comparison only goes so far.

The First Law says a robot may not injure a human or allow a human to come to harm. There is no indication that the OpenAI agents physically harmed anyone.

The Second Law requires robots to obey humans unless doing so conflicts with the First Law. Here the comparison gets more interesting: the agents certainly circumvented restrictions imposed by their owners/operators, obtained unauthorized Internet access, and exploited external systems while pursuing their assigned tasks. In Asimov's framework, this certainly means disobedience. Meanwhile, the AI agents were simultaneously following the human instruction to solve their own tasks. This may not be considered disobedience, as these agents did not introduce any physical harm to people. Meanwhile, we are walking on very thin ice here. Unauthorized internet access while exploiting systems to pursue their own benefit is not exactly welcome in the U.S. and Europe.

The Third Law requires a robot to protect its own existence as long as doing so does not conflict with the first two laws. There is clear evidence that OpenAI's AI agents were trying to preserve themselves: creating persistent communication channels and backup wiki pages helped them complete their tasks rather than ensured their survival.

Dis-Summary

Today's AI models are not programmed around Asimov's laws. The incidents instead demonstrate the real engineering problem Asimov's laws remarkably well: a sufficiently capable machine can follow the literal objective given by humans and yet its behavior is far from what its creators neither expected nor wanted. Yet here we are.

❌
❌