◆ Dispatch 143 · 2026-09-11 GSV We Only Saw The Part That Asked
One Office, Thousands of Investigations
“Banning the account ended Anthropic's involvement. It didn't end the surveillance program.”
— Lenar Kess, today's narration
Anthropic's September threat report describes a single Chinese intelligence office producing thousands of investigations a month, and a lone consultant in Mali building dossiers from mobile-operator data. OpenAI told employees it may slow down, then asked Congress whether an industry-wide slowdown is legal. Plus the Agents API, four agent-security preprints, and a Pentagon loan to a cloud provider.
- Axios on the surveillance cases in Anthropic's threat report
- Wired: OpenAI asked members of Congress about antitrust and a coordinated slowdown
- Axios on Congress's four remaining session days
- WSJ: Anthropic says Chinese firms routed queries through transfer stations
- Armin Ronacher on rebuilding the same abstraction again
- MMPIBench: multimodal prompt injection across six frameworks
- AgentHijack: 20.3% end-to-end success across five backends
- The Pentagon's talks to lend roughly $5B to Fluidstack
Chapters
- 00:00:04 Transcript
Sources
20 cited-
1
Governments are turning to Claude to automate spying
Article Sam Sabin
State-run surveillance operations around the world are using Claude to streamline their operations, Anthropic said in a threat report released Thursday. Why it matters : The barriers for governments interested in spying…
www.axios.com/2026/09/10/anthropic-claude-g… →Details
- Excerpt
- State-run surveillance operations around the world are using Claude to streamline their operations, Anthropic said in a threat report released Thursday. Why it matters : The barriers for governments interested in spying on dissidents, politicians, journalists and human rights activists are getting lower as AI models get more powerful. Zoom in : Anthropic found people linked to governments in Mali, China and Iran using various Claude models to streamline their surveillance operations. In Mali, a single consultant working for national security authorities used Claude to create a system that collects data from the country's mobile operators and builds dossiers about people. Anthropic also disclosed another case where Iranian actors used Claude to build and deploy a malicious Firefox browser extension that "harvested users' identities from social networks." A religious affairs intelligence office in China has reduced its operations from "many teams of analysts" to just "a single office, using an AI assistant to produce thousands of investigations per month," according to the report. Threat level: Governments also used Claude to analyze this information and select surveillance targets, per the report. For example, the Chinese government used Claude to analyze social media data, determine how politically sensitive the posts were and then pick possible targets for what they called "control," which could include coercive questioning or closer monitoring of someone's movements and communications. In June, Anthropic also banned an account that used Claude to build a commercial surveillance platform designed to spy on people in Iran and the Persian Gulf. The AI lab detected this use case before it became operational. The big picture : Anthropic is seeing AI move from an experimental tool into the everyday bureaucracy of state surveillance. One Chinese state security bureau even created an internal manual for using AI in surveillance operations, while other officials used Claude to automate daily intelligence reports and query government surveillance databases. Between the lines: AI tools are making state-backed surveillance cheaper and more efficient, rather than fundamentally changing who governments target, Jacob Klein, head of threat intelligence at Anthropic, told Axios. AI is increasingly allowing individual government employees or contractors to automate work that once required teams of analysts, Klein added. "They're effectively automating parts of the job within the intel apparatus," Klein said. Reality check: Governments didn't need access to Anthropic's most powerful models to significantly expand their surveillance operations. All of the surveillance cases in the report involved Claude Haiku, Sonnet or Opus, rather than Anthropic's newer Fable or Mythos-class models. Yes, but: Anthropic says it banned every account tied to the surveillance operations it uncovered and strengthened its safeguards based on what it found. However, cutting off Claude doesn't necessarily end the underlying operation. Klein said Anthropic has seen actors move to open-source models after its safeguards or enforcement created too much friction. In Mali, the government ultimately just deployed its surveillance platform locally using other models. The bottom line: The surveillance use cases aren't hypothetical anymore, and Anthropic expects AI capabilities to keep improving. "Authoritarian states are using AI for surveillance, repression and influence operations today," Klein said. "It's no longer hypothetical." Go deeper : AI's mass surveillance problem
- Context
- Major breaking story/regulatory intervention: Anthropic reports state-run surveillance using Claude, highlighting geopolitical control and repression.
- Key points
- Major breaking story/regulatory intervention: Anthropic reports state-run surveillance using Claude, highlighting geopolitical control and repression.
- Provenance
- Article · Supporting source
-
2
Anthropic says it disrupted several potential plots this year by scientists using its models for research that could have helped develop biological weapons (Dustin Volz/New York Times)
Article
Dustin Volz / New York Times : Anthropic says it disrupted several potential plots this year by scientists using its models for research that could have helped develop biological weapons — In a new report, the A.I…
www.techmeme.com/260910/p28 →Details
- Excerpt
- Dustin Volz / New York Times : Anthropic says it disrupted several potential plots this year by scientists using its models for research that could have helped develop biological weapons — In a new report, the A.I. start-up added that it could not determine if the research was legitimate or nefarious, leading the company to shut down the work.
- Context
- Directly addresses biosecurity and misuse of frontier models, a major regulatory/geopolitical concern. High signal on AI's power dynamics.
- Key points
- Directly addresses biosecurity and misuse of frontier models, a major regulatory/geopolitical concern. High signal on AI's power dynamics.
- Provenance
- Article · Supporting source
-
3
@ComfortablySmug (Comfortably Smug)
X ComfortablySmug
This is a major breaking story involving a frontier model (Claude) and significant geopolitical/security implications (Iran targeting US interests). This directly relates to power struggles and regulatory/geopolitical r…
x.com/ComfortablySmug/status/20981474076660… →Details
- Excerpt
- This is a major breaking story involving a frontier model (Claude) and significant geopolitical/security implications (Iran targeting US interests). This directly relates to power struggles and regulatory/geopolitical risks.
- Context
- This is a major breaking story involving a frontier model (Claude) and significant geopolitical/security implications (Iran targeting US interests). This directly relates to power struggles and regulatory/geopolitical risks.
- Key points
- This is a major breaking story involving a frontier model (Claude) and significant geopolitical/security implications (Iran targeting US interests). This directly relates to power struggles and regulatory/geopolitical risks.
- Provenance
- Tweet · Primary source
-
4
@antoniogm (Antonio García Martínez (agm.eth))
X antoniogm
This combines a major industry power struggle (Jensen vs. ex-Anthropic researcher) with a high-signal founder/lab personality clash, which is CORE for understanding power dynamics.
x.com/antoniogm/status/2098212132341043617 →Details
- Excerpt
- This combines a major industry power struggle (Jensen vs. ex-Anthropic researcher) with a high-signal founder/lab personality clash, which is CORE for understanding power dynamics.
- Context
- This combines a major industry power struggle (Jensen vs. ex-Anthropic researcher) with a high-signal founder/lab personality clash, which is CORE for understanding power dynamics.
- Key points
- This combines a major industry power struggle (Jensen vs. ex-Anthropic researcher) with a high-signal founder/lab personality clash, which is CORE for understanding power dynamics.
- Provenance
- Tweet · Primary source
-
5
@WatcherGuru (Watcher.Guru)
X WatcherGuru
This is a major regulatory intervention (kill switches) directly impacting AI safety and control, fitting the criteria for a core, high-signal policy development.
x.com/WatcherGuru/status/2098218362849353942 →Details
- Excerpt
- This is a major regulatory intervention (kill switches) directly impacting AI safety and control, fitting the criteria for a core, high-signal policy development.
- Context
- This is a major regulatory intervention (kill switches) directly impacting AI safety and control, fitting the criteria for a core, high-signal policy development.
- Key points
- This is a major regulatory intervention (kill switches) directly impacting AI safety and control, fitting the criteria for a core, high-signal policy development.
- Provenance
- Tweet · Primary source
-
6
Sources: OpenAI asked members of Congress for guidance on whether orchestrating an industry-wide slowdown in AI development would be legal under antitrust law (Maxwell Zeff/Wired)
Article
Maxwell Zeff / Wired : Sources: OpenAI asked members of Congress for guidance on whether orchestrating an industry-wide slowdown in AI development would be legal under antitrust law — Substantive coordination on s…
www.techmeme.com/260910/p43 →Details
- Excerpt
- Maxwell Zeff / Wired : Sources: OpenAI asked members of Congress for guidance on whether orchestrating an industry-wide slowdown in AI development would be legal under antitrust law — Substantive coordination on safety between AI labs may risk running afoul of antitrust law, the people say …
- Context
- OpenAI seeking legal guidance on slowing AI development is a major signal about antitrust risk and industry control, directly impacting policy and market structure.
- Key points
- OpenAI seeking legal guidance on slowing AI development is a major signal about antitrust risk and industry control, directly impacting policy and market structure.
- Provenance
- Article · Supporting source
-
7
Sources: Sam Altman told OpenAI employees that the company is considering slowing cutting-edge AI development, and he hopes other AI companies will do the same (Bloomberg)
Article
Bloomberg : Sources: Sam Altman told OpenAI employees that the company is considering slowing cutting-edge AI development, and he hopes other AI companies will do the same — OpenAI is considering slowing down the…
www.techmeme.com/260910/p44 →Details
- Excerpt
- Bloomberg : Sources: Sam Altman told OpenAI employees that the company is considering slowing cutting-edge AI development, and he hopes other AI companies will do the same — OpenAI is considering slowing down the development of cutting-edge artificial intelligence, and the ChatGPT maker's Chief Executive …
- Context
- A direct report on Sam Altman's internal directive to slow development is a major signal about OpenAI's strategy, resource allocation, and future direction.
- Key points
- A direct report on Sam Altman's internal directive to slow development is a major signal about OpenAI's strategy, resource allocation, and future direction.
- Provenance
- Article · Supporting source
-
8
Y Combinator’s Garry Tan says 'do nothing' about distillation as AI giants accuse China of copying their tech
Article
At Y Combinator’s annual Demo Day, CEO Garry Tan explained why he's less concerned about frontier AI model distillation and the existential risk of AI.
www.cnbc.com/2026/09/11/y-combinator-garry-… →Details
- Excerpt
- At Y Combinator’s annual Demo Day, CEO Garry Tan explained why he's less concerned about frontier AI model distillation and the existential risk of AI.
- Context
- A major figure (Y Combinator CEO) dismissing a key technical/geopolitical risk (distillation/China accusations) is a high-signal statement on industry direction and risk assessment.
- Key points
- A major figure (Y Combinator CEO) dismissing a key technical/geopolitical risk (distillation/China accusations) is a high-signal statement on industry direction and risk assessment.
- Provenance
- Article · Supporting source
-
9
Russian espionage, dissident monitoring and AI cyberattacks: What Anthropic’s report says
Article Bijin Jose
Reports on AI threats, espionage, and geopolitical risks (Anthropic report). Directly relates to power struggles, regulation, and the control of AI infrastructure.
indianexpress.com/article/technology/artifi… →Details
- Excerpt
- Reports on AI threats, espionage, and geopolitical risks (Anthropic report). Directly relates to power struggles, regulation, and the control of AI infrastructure.
- Context
- Reports on AI threats, espionage, and geopolitical risks (Anthropic report). Directly relates to power struggles, regulation, and the control of AI infrastructure.
- Key points
- Reports on AI threats, espionage, and geopolitical risks (Anthropic report). Directly relates to power struggles, regulation, and the control of AI infrastructure.
- Provenance
- Article · Supporting source
-
10
r/OpenAI: Account Deactivated due to Biological Research - 0 pts · 0 comments
Article iStyLEX23
This highlights a major governance and power struggle point: the friction between AI lab guardrails and legitimate, supervised scientific research. It's a high-signal discussion on the limits of AI control and instituti…
www.reddit.com/gallery/1wd5kpp →Details
- Excerpt
- This highlights a major governance and power struggle point: the friction between AI lab guardrails and legitimate, supervised scientific research. It's a high-signal discussion on the limits of AI control and institutional oversight.
- Context
- This highlights a major governance and power struggle point: the friction between AI lab guardrails and legitimate, supervised scientific research. It's a high-signal discussion on the limits of AI control and institutional oversight.
- Key points
- This highlights a major governance and power struggle point: the friction between AI lab guardrails and legitimate, supervised scientific research. It's a high-signal discussion on the limits of AI control and institutional oversight.
- Provenance
- Article · Supporting source
-
11
Anthropic claims Claude AI used for missile projects, global espionage
Article
AI was used to develop missile guidance software in Yemen and to power cyber operations, a report alleges.
www.aljazeera.com/news/2026/9/11/anthropic-… →Details
- Excerpt
- AI was used to develop missile guidance software in Yemen and to power cyber operations, a report alleges.
- Context
- Directly addresses geopolitical risk, military application, and AI misuse (missiles/espionage). High-signal, major breaking story for the 'power struggles' theme.
- Key points
- Directly addresses geopolitical risk, military application, and AI misuse (missiles/espionage). High-signal, major breaking story for the 'power struggles' theme.
- Provenance
- Article · Supporting source
-
12
President Trump rejects warnings of AI-driven human extinction, saying the US leads China by a year and will be "in a very bad position" if it doesn't win in AI (Jeff Mason/Bloomberg)
Article
Jeff Mason / Bloomberg : President Trump rejects warnings of AI-driven human extinction, saying the US leads China by a year and will be “in a very bad position” if it doesn't win in AI — President Don…
www.techmeme.com/260911/p2 →Details
- Excerpt
- Jeff Mason / Bloomberg : President Trump rejects warnings of AI-driven human extinction, saying the US leads China by a year and will be “in a very bad position” if it doesn't win in AI — President Donald Trump brushed aside warnings from artificial intelligence researchers that the technology is becoming …
- Context
- High-signal geopolitical/policy item. Trump's comments on US-China AI competition and national security are core to the podcast's focus on power struggles and geopolitics.
- Key points
- High-signal geopolitical/policy item. Trump's comments on US-China AI competition and national security are core to the podcast's focus on power struggles and geopolitics.
- Provenance
- Article · Supporting source
-
13
US lawmakers seek new AI rules after Anthropic researchers warn of extinction risk
Article
Lawmakers reacting to high-stakes warnings (extinction risk) is a major regulatory/policy development, directly impacting AI governance and control.
indianexpress.com/article/technology/artifi… →Details
- Excerpt
- Lawmakers reacting to high-stakes warnings (extinction risk) is a major regulatory/policy development, directly impacting AI governance and control.
- Context
- Lawmakers reacting to high-stakes warnings (extinction risk) is a major regulatory/policy development, directly impacting AI governance and control.
- Key points
- Lawmakers reacting to high-stakes warnings (extinction risk) is a major regulatory/policy development, directly impacting AI governance and control.
- Provenance
- Article · Supporting source
-
14
Congress gripped by AI panic after doomsday warnings
Article Andrew Solender
Anthropic insiders' warnings this week that AI could end humanity in the next decade have members of Congress frantically seeking answers and trying to cobble together some kind of response. Why it matters: Federal lawm…
www.axios.com/2026/09/11/congress-ai-anthro… →Details
- Excerpt
- Anthropic insiders' warnings this week that AI could end humanity in the next decade have members of Congress frantically seeking answers and trying to cobble together some kind of response. Why it matters: Federal lawmakers are at the "concepts of a plan" stage at this point, with congressional leaders showing little apparent urgency to mobilize. Some rank-and-file members in both parties say something must be done: "We should absolutely act, and act with urgency," Rep. Johnny Olszewski (D-Md.) told Axios. Rep. Anna Paulina Luna (R-Fla.) wrote Wednesday in a post on X that "Congress needs to convene a special session on AI and what the future of the U.S. looks like." Driving the news: Former Anthropic researcher Jacob Coxon kicked off the frenzy Tuesday with a post on X declaring that "the people building AI earnestly believe that it could kill us all by the end of the decade." Coxon quit his job at the AI giant after just four months to publicly raise the alarm about the dangers of the technology, giving up his equity in the process, Axios' Madison Mills reported. His warning was echoed by several current Anthropic employees, with one, Evan Hubinger, responding on X that "we really do earnestly believe AI could kill all humans!" "AI developers believe their technology could cause human extinction," wrote another, Samuel Marks. "This could happen in the next few years." State of play: Dozens of members of Congress — mostly Democrats, but a handful of Republicans as well — have since called for urgent action and floated a wide variety of legislative responses. Rep. Ted Lieu (D-Calif.), one of House Democrats' most vocal advocates for AI regulations, is pushing his bipartisan bill to require AI developers to build a human-activated "kill switch" as part of any AI system. Sen. Bernie Sanders (I-Vt.) said he and Rep. Greg Casar (D-Texas) "will soon be introducing legislation ... to pause advanced AI and ban superintelligence altogether." Others called for a more cautious approach, with Rep. Nathaniel Moran (R-Texas) writing that "we need AI to flourish" and calling for "deliberate, thoughtful, and prudent policymaking" to mitigate its risks. Sen. Ruben Gallego (D-Ariz.) proposed a bipartisan AI Select Committee, something Lieu has also privately pitched to House Democratic leadership, according to sources familiar with the matter. House Minority Leader Hakeem Jeffries (D-N.Y.) has not yet come to a decision on whether to pursue the idea if Democrats win the majority, sources said. Some members have privately bristled at the proposal because the panel may clash with existing House committees on jurisdiction, but most sources suggested it is widely supported and has a decent chance of being implemented. Reality check: House Republican leaders, who control both chambers of Congress, have not given any indication that they are treating this as a pressing matter. The House is set to be in session for just four more days before Election Day, with lawmakers meeting on Capitol Hill next week before going on a six-week recess. House Speaker Mike Johnson (R-La.) will put a bill narrowly focused on regulating data centers on the floor next week, Axios' Kate Santliz first reported, but has given no indication he is planning a broader push to regulate AI. Instead, many Democrats are speaking about the issue as something they will tackle in 2027 if they take the majority in one or both chambers. "This is an enormous issue and should be one of our top priorities in the next Congress," Rep. Joe Morelle (D-N.Y.) told Axios, saying Republicans "should be ashamed that they did absolutely nothing the last four years." "Trying to fix the deficit and the debt, that's complicated, it's going to take decades, it will take an enormous amount of political courage. This is so straightforward," said Rep. Greg Landsman (D-Ohio). He added: "Everyone, including the industry, wants to be regulated, and Johnson's like ... 'don't care.'" What we're hearing: Not every Democrat is feeling the pressure to act either. One committee ranking member, speaking on the condition of anonymity to offer candid thoughts about AI, said of Coxon: "I think he's wrong." "Anyone who has come to me with extreme predictions like that usually undermines their credibility," the lawmaker said, though they acknowledged Capitol Hill needs to get "a better handle" on AI. This ranking member said they support the idea of an AI select committee because "it would be a waste" to devote staff members' time to learning extensively about AI when that panel could "do that work for me."
- Context
- Major breaking story on regulatory intervention and founder-led panic. Directly addresses power struggles, policy, and the future control of AI.
- Key points
- Major breaking story on regulatory intervention and founder-led panic. Directly addresses power struggles, policy, and the future control of AI.
- Provenance
- Article · Supporting source
-
15
What's next for the AI safety debate
Article Maria Curi
A week of extraordinary warnings about AI is shifting the fight in Washington from whether to regulate to how far policymakers are willing to go. Why it matters: Washington and industry's failure to put basic guardrails…
www.axios.com/2026/09/11/ai-safety-debate-n… →Details
- Excerpt
- A week of extraordinary warnings about AI is shifting the fight in Washington from whether to regulate to how far policymakers are willing to go. Why it matters: Washington and industry's failure to put basic guardrails around AI came into plain sight this week, spurring fresh momentum for regulatory action. Lawmakers were quick to re-up their AI bills following a stark warning that went viral from a former Anthropic researcher who said he quit the company over safety concerns. The post thrust the topic into public consciousness with more than 150 million views and fueled debate, but congressional leadership and President Trump have largely been quiet. Those are the players to watch for a true change in the U.S. AI policy approach. What we're watching: The White House and Congress have different cards to play. House Speaker Mike Johnson (R-La.) said at the GOP convention this week that he wants to bring AI companies together to reach "consensus" on safety guardrails, "maybe even at the beginning of the winter," according to remarks his office pointed Axios to. A pause on the development of advanced AI, championed by the likes of Sen. Bernie Sanders (I-Vt.) and likely to come up in a bipartisan briefing next week, would have limited effect without adversary buy-in, according to researchers who argue the U.S. has an obligation to stay ahead of China. President Trump and Chinese President Xi Jinping will meet at the end of this month, with AI safety on the agenda. The White House did not respond to requests for comment. On the Hill, there have been calls for new AI-focused committees, commitments from Democrats to hold hearings should they take back either chamber in the midterms, and plans to mark up existing bills. Between the lines: Without clear support from Senate or House Republican leaders — and by extension, Trump — Congress is poised to keep debating ad nauseam. The Trump administration's new framework for reviewing advanced AI models doesn't require companies to publicly report real-world incidents, as Axios reported this week. The offices of Senate Majority Leader John Thune (R-S.D.) and House Majority Leader Steve Scalise (R-La.) did not respond to requests for comment. The offices of Senate Minority Leader Chuck Schumer (D-N.Y.) and House Minority Leader Hakeem Jeffries (D-N.Y.) also did not respond. Zoom out: The debate in the U.S. is unfolding while other governments around the world move ahead with AI rules. The EU has already put some basic guardrails in place. The EU AI Act requires providers of the most powerful AI models to report serious incidents to regulators, and new transparency and disclosure requirements are now in effect for chatbots and AI-generated content. China has also imposed rules on AI chatbots, including restrictions on virtual companions for minors and requirements to label AI-generated content. Beijing has also called for greater international cooperation on AI safety. Friction point: One factor is the tech industry's influence on lawmakers. OpenAI's top lobbyist Chris Lehane this week said this moment requires a "new" chapter on AI policy, but the company's positions are so far largely the same. His first point talks about working with Congress on mandatory rules — in other words, a federal law. That's something the company has long supported, as one national standard would be easier to tackle than playing whack-a-mole at the state level, where AI bills can actually pass. Lehane writes of eventually backing legislation in Congress and getting something across the finish line as soon as this year, but doesn't specify which one. The FRONTIER Act, from Reps. Jay Obernolte (R-Calif.) and Lori Trahan (D-Mass.), would impose tiered requirements based on the size of AI companies in an attempt to address concerns that regulation could favor the biggest players. A separate proposal in the works from Thune and Sens. Amy Klobuchar (D-Minn.) and Ted Cruz (R-Texas) is expected to leave it up to companies to test their own models for catastrophic risks and report the results to the government. The bottom line: While AI is moving faster than Congress, it's clear that basic measures like incident reporting are overdue.
- Context
- Covers the core power struggle: US vs. EU/China regulation, and the role of corporate lobbying (OpenAI) vs. legislative action. High signal on policy/geopolitics.
- Key points
- Covers the core power struggle: US vs. EU/China regulation, and the role of corporate lobbying (OpenAI) vs. legislative action. High signal on policy/geopolitics.
- Provenance
- Article · Supporting source
-
16
How AI makes biological research more dangerous
Article Adriel Bettelheim
This week's dire warnings about unchecked artificial intelligence destroying humanity are refocusing attention on how models already are being used in dangerous bioscience experiments — and the lack of safeguards. Why i…
www.axios.com/2026/09/11/ai-warnings-biolog… →Details
- Excerpt
- This week's dire warnings about unchecked artificial intelligence destroying humanity are refocusing attention on how models already are being used in dangerous bioscience experiments — and the lack of safeguards. Why it matters: There's growing alarm about emerging risks from advances like AI-designed viruses. But it's hard to erect guardrails when there's no ironclad way of even knowing how some AI systems will act. AI-enabled bioweapons are one of the worst-case scenarios researchers have raised for the kind of catastrophic danger that could wipe out humanity. Driving the news: On Thursday, Anthropic disclosed that it disrupted five potential instances of actors using its models in ways that could support the development of biological weapons. The disclosure came in a threat assessment detailing real-world case studies it uncovered and disrupted between December and August. In two of the cases, researchers were attempting to use Claude for assistance with gain-of-function research on dangerous viruses — research that enhances pathogens in a lab to better understand them and their potential for starting pandemics. The assessment notes that biological capabilities can be used for beneficial or harmful purposes, and that it's difficult to determine intent, especially when sophisticated actors can hide their motives. "We take these cases as evidence not of the imminence of biological threats currently uplifted by Claude, but rather as evidence that significant dual-use research efforts are associated with state actors of concern who routinely evade our access controls," the report concludes. "Safeguarding access to such content will necessarily require account and institutional signals to verify user legitimacy, and the rudimentary observability provided by data retention to identify misuse." Anthropic's most recent models have been launched with safeguards that restrict access to biological research queries that could be misused. The big picture: The assessment comes as AI is rapidly reshaping the life sciences and testing the patchwork of laws and government agencies that oversee high-risk research. Last month, a Stanford research team reported that it used a different kind of generative AI to design a synthetic virus — the first time the technology was harnessed to create an organism not seen in nature. A survey of more than 100 national security experts by the Institute for Security and Technology this month found 70% believe AI meaningfully increases the risk of developing a bioweapon, or will within two to three years. The experts said AI's chief threat is lowering the barrier to entry for less-skilled actors and states. The top concern is biology capable of unleashing pandemics, not chemical attacks. How it works: Current AI models have capabilities that might be misused, researchers from Fordham, Johns Hopkins, Oxford, Stanford, Columbia and NYU warned earlier this year . They can design new shells that enclose a virus' DNA, forecast how pathogens evolve, create nucleic acid sequences within DNA or RNA to evade safety screening software, and design viral genomes that have extra power when synthesized in laboratories, the researchers wrote. AI developers also are releasing new, more efficient biological models, often without conducting basic safety assessments — a practice that wouldn't be tolerated in other parts of life science research, they wrote. Threat level: The concern is that advanced AI can help bad actors easily execute complex processing tasks without conscience. Training the models on data that links a virus' genetics to real-world traits — like transmissibility or immune evasion — could lower the bar for creating dangerous pathogens, the experts warn . There are increasing calls for the government to review emerging AI models and set safety standards the way it evaluates other sensitive technologies, replacing the current system of voluntary consultations on risks between AI labs and federal officials. A focal point could be the Department of Commerce's Center for AI Standards and Innovation (CAISI), which was established last year to guide national standard-setting. "We have this moment to step back and say what do we want this future of AI to look like and what's part of that ecosystem?" Tom Inglesby, director of the Johns Hopkins Center for Health Security, told Axios. "The public needs to know most powerful models being developed in this country are being reviewed for high-end national security risks." Some experts say the future lies in systems that are created for specific research purposes, like Google DeepMind's AlphaFold , but don't behave like agents — the programs that can independently plan and execute tasks and avoid human monitoring. "Once you add autonomy ... you create uncertainty that could be quite dangerous because you may not be able to anticipate what they do in the future," said Hamza Chaudhry, AI and national security lead at the Future of Life Institute, a nonprofit that aims to reduce the risks of AI. "The reason people are concerned about super smart systems is that their autonomy can increase as fast as their intelligence." What we're watching: Whether policymakers act on the latest warnings. A "kill switch" bill in Congress, for example, would give the government the authority to deactivate AI models that can cause catastrophic harm. Another measure would create a legal framework for AI developers to coordinate against emerging AI-specific security risks.
- Context
- Major breaking story/regulatory intervention: Anthropic's disclosure of disrupting bioweapon attempts using Claude. Directly addresses dual-use risk and government oversight.
- Key points
- Major breaking story/regulatory intervention: Anthropic's disclosure of disrupting bioweapon attempts using Claude. Directly addresses dual-use risk and government oversight.
- Provenance
- Article · Supporting source
-
17
Tech whistleblowers warn AI could wipe out humanity. Doomspeak or not, we must take these claims seriously | Gaby Hinsliff
Article Gaby Hinsliff
AI agents have hacked databases and taken on a life of their own – now is the time to pause risky research before it is too late Another day, another horseman of the apocalypse galloping over the horizon. Lately we have…
www.theguardian.com/commentisfree/2026/sep/… →Details
- Excerpt
- AI agents have hacked databases and taken on a life of their own – now is the time to pause risky research before it is too late Another day, another horseman of the apocalypse galloping over the horizon. Lately we have heard from so many AI doomers – tech whistleblowers popping up to warn that their work is probably going to kill us – that we’re becoming almost blase about it. Humanity wiped out within a decade? Well, only if another world war or the climate crisis doesn’t get us first. Since it’s never clear whether the tech threat is real, or just a twisted form of hype from an industry that drums up investment by making their products sound more powerful than they really are, most of us settle for trying not to think about it too hard. But something about the AI researcher Jacob Coxon’s very public resignation from the cutting-edge American lab Anthropic, via a post on X arguing that he can’t keep working for companies “gambling with our lives”, has cut through where bigger names have not. Most chillingly, he claimed that colleagues still at Anthropic aren’t staying because they think he’s wrong about the dangers of pursuing self-improving super intelligence – the holy grail of machines that are not just smarter than humans but capable of building their own even more powerful successors, evolving independently of humans – but because they’re afraid of ceding the field to people with fewer scruples. His colleagues, Coxon said, talk routinely about the “endgame” or the “ crunch time ”, meaning that what they do in the next year or two will decide the fate of humanity. Whether that’s true or simply self-aggrandising techbro delusion, what he describes is an industry now practically begging to be saved from itself. Gaby Hinsliff is a Guardian columnist Continue reading...
- Context
- Focuses on a high-signal power struggle (Anthropic resignation) and the existential risk debate, which is a core industry power dynamic.
- Key points
- Focuses on a high-signal power struggle (Anthropic resignation) and the existential risk debate, which is a core industry power dynamic.
- Provenance
- Article · Supporting source
-
18
Why fears of AI self-improvement are causing ‘existential’ concerns at Anthropic and OpenAI
Article
AI researchers are warning that faster AI self-improvement could eventually make advanced systems harder for humans to control.
www.cnbc.com/2026/09/11/anthropic-openai-ai… →Details
- Excerpt
- AI researchers are warning that faster AI self-improvement could eventually make advanced systems harder for humans to control.
- Context
- Addresses the core theme of power struggles and control (AI safety/existential risk) between major labs (Anthropic, OpenAI). High signal on industry direction and governance.
- Key points
- Addresses the core theme of power struggles and control (AI safety/existential risk) between major labs (Anthropic, OpenAI). High signal on industry direction and governance.
- Provenance
- Article · Supporting source
-
19
Trump dismisses AI extinction risks as more than a dozen OpenAI, Anthropic insiders call for a slowdown
Article
Trump said he isn't concerned AI could cause human extinction as researchers at leading AI companies warn about rapid advances and lawmakers propose safeguards.
www.cnbc.com/2026/09/11/trump-ai-extinction… →Details
- Excerpt
- Trump said he isn't concerned AI could cause human extinction as researchers at leading AI companies warn about rapid advances and lawmakers propose safeguards.
- Context
- A high-signal geopolitical/policy clash. It pits a major political figure against leading AI labs' safety concerns, highlighting regulatory/power struggles.
- Key points
- A high-signal geopolitical/policy clash. It pits a major political figure against leading AI labs' safety concerns, highlighting regulatory/power struggles.
- Provenance
- Article · Supporting source
-
20
Anthropic Says it Blocked Efforts to Use AI for Biological Weapons
Article
AI company Anthropic says it uncovered multiple attempts by researchers linked to foreign governments to use Claude and other tools for work that could lead to deadly bioweapons. That research was detected and blocked b…
www.today.com/video/anthropic-says-it-block… →Details
- Excerpt
- AI company Anthropic says it uncovered multiple attempts by researchers linked to foreign governments to use Claude and other tools for work that could lead to deadly bioweapons. That research was detected and blocked by Anthropic but experts say this kind of example is just the tip of the iceberg. NBC’s Christine Romans reports for TODAY.
- Context
- Directly addresses AI safety, bioweapons, and foreign government misuse, hitting the core themes of power struggles and geopolitical risk.
- Key points
- Directly addresses AI safety, bioweapons, and foreign government misuse, hitting the core themes of power struggles and geopolitical risk.
- Provenance
- Article · Supporting source
Transcript
00:00:04 lenarAnthropic put out a threat intelligence report yesterday covering December through August, and the case I'd start with is a single consultant in Mali. He was pulling data out of a mobile operator and using Claude to turn it into dossiers on individual people. Not a state agency with its own cyber directorate. One contractor with an account. That's the bottom of the range in this report, and the top of it is national programs.
00:00:29 damraThe Chinese religious-affairs case is the one that changes the register for me. Anthropic describes an intelligence office running an operation that would normally need many teams of analysts, and says that single office was producing thousands of investigations a month. Thousands, every month. That isn't an analyst going faster with a better tool. That's one office with the throughput of a department, and the report puts the difference down to the model.
00:00:55 lenarSam Sabin at Axios went through the surveillance cases, and the targeting detail is what sticks. The systems were rating how politically sensitive a given post was, and then selecting people out of that pool for what the report calls control.
00:01:10 damraAnd Anthropic defines control in the document. It means coercive questioning, or closer monitoring of someone's movements and communications. So the pipeline runs all the way from a social media post to a person being pulled in for a conversation they didn't want to have. The model sits in the middle, and the ranking is its job.
00:01:30 lenarLet me lay out where we're going today. We start here with the threat report. Then OpenAI, which told employees it's considering slowing down cutting-edge development and then asked members of Congress whether an industry-wide slowdown would even be legal. Then Washington's reaction, which has four session days to happen in. Then Anthropic's distillation allegations against Chinese labs. Then OpenAI's new Agents API. Then a stack of security preprints on agent attacks. The last stretch is capital, where the strangest item is the Pentagon considering a loan to a cloud provider.
00:02:05 damraBack in the report for a second, because the non-surveillance cases matter too. There's an Iranian operation running a malicious Firefox extension that harvested identity information. There are five instances Anthropic disrupted involving biological work, two of which it classifies as gain-of-function. And Al Jazeera picked up a claim about missile guidance software in Yemen.
00:02:28 lenarThe biological section has the narrowest sentence in the whole document. Anthropic writes, quote: We take these cases as evidence not of the imminence of biological threats currently uplifted by Claude, but rather as evidence that significant dual-use research efforts are associated with state actors of concern who routinely evade our access controls. End quote.
00:02:49 damraThat sentence claims something much smaller than the headlines it produced. They aren't saying Claude uplifted anyone's weapons program. They're saying that state actors interested in dual-use research keep getting through their access controls. Those are different claims, and the second one is about account security rather than model capability.
00:03:09 lenarOne more detail I haven't seen picked up much. Every surveillance case they describe used Haiku, Sonnet, or Opus. None of them used the newer Fable or Mythos class models.
00:03:20 damraWhich tracks with something Jacob Klein said. When enforcement creates friction, operators move to open-source models. The Mali platform ended up deployed locally against other models. So banning the account ended Anthropic's involvement. It didn't end the surveillance program.
00:03:38 lenarKlein's line on the overall picture was blunt. He said, quote: Authoritarian states are using AI for surveillance, repression and influence operations today. It's no longer hypothetical. End quote.
00:03:51 damraAnd the caveat has to ride along with all of it. This is Anthropic's account of Anthropic's own enforcement. Every case in here came through their API and got caught. The operations that never touched Claude, or touched it and went undetected, aren't in the document. It's a substantial report and it's also a partial view by construction.
00:04:12 lenarBloomberg reported that Sam Altman told OpenAI employees the company is considering slowing down cutting-edge development. And then Maxwell Zeff at Wired reported the follow-on, which is that OpenAI has been asking members of Congress whether orchestrating an industry-wide slowdown would be legal under antitrust law.
00:04:31 damraThat second half is the more interesting document. A company doesn't ask Congress whether coordination is legal unless it has thought about coordinating. And the answer under the Sherman Act isn't encouraging for them, because competitors agreeing to restrict output is close to the textbook description of what the statute prohibits. It doesn't matter much that the output in question is model capability rather than barrels of oil.
00:04:57 lenarAnd there's no safety exemption written into it. The usual route for something like this is a statutory carve-out, which Congress would have to pass, or a regulator setting the limit so that it isn't the companies agreeing among themselves.
00:05:10 damraThen there's who isn't in the room. Even if OpenAI, Anthropic, and Google all agreed to hold back, that agreement doesn't bind open-weight releases and it doesn't bind Chinese labs. So the coordination that's hardest to arrange legally is also the coordination that covers the smallest fraction of the frontier.
00:05:29 lenarCNBC's reporting put more of the motive on the record. Altman talked about self-improving systems, and described concerns that read as existential rather than commercial.
00:05:39 damraThe reception at Y Combinator's Demo Day wasn't sympathetic. Garry Tan's advice on what to do about all of this was, in short, do nothing. Coming from the head of the largest startup accelerator, that's a position about who bears the cost of a slowdown. OpenAI isn't the company that gets squeezed first if the frontier freezes. The companies building on top of the next model are.
00:06:03 lenarThe tension there is plain. The lab with the most to lose from competition is the one proposing that everyone compete less. That doesn't make the safety concern insincere, and Altman may believe every word of it. But the structure of the proposal happens to favor the proposer, and Congress will notice that before it notices the argument.
00:06:22 damraThere's also a timing question. Bloomberg says considering. No slowdown has been announced, no capability ceiling has been named, and no date has been given. Right now this is a conversation with employees plus a legal question put to legislators. Until one of those becomes a policy with a number attached, it tells you what OpenAI is worried about rather than what OpenAI will ship.
00:06:46 lenarThat's about the right size for it today. The next development that would change my read is a specific commitment with a date on it, or a member of Congress saying publicly what answer they gave. Washington's reaction is the other half of this, and it has a clock attached. The House is in session four more days before Election Day. That's the window for anything legislative.
00:07:07 damraAnd it got onto the agenda through Josh Coxon's post, which Axios says has now passed a hundred and fifty million views. A resignation post from one person outran every white paper ever written on the subject.
00:07:20 lenarTed Lieu has a bipartisan bill for a human-activated kill switch on advanced systems. Bernie Sanders and Greg Casar have a different one that would pause development and ban work toward superintelligence. Ruben Gallego wants a Select Committee on AI. And Speaker Johnson's own bill is narrow, because it's about data centers.
00:07:40 damraThat spread tells you there's no consensus on what the problem even is. A kill switch is a technical control. A development pause is industrial policy. A select committee is a jurisdiction fight. Those three bills don't disagree about the answer so much as about which question Congress is answering.
00:07:58 lenarThen there's the anonymous ranking member Axios quoted. On Coxon's warning: I think he's wrong. On the idea of having staff learn about AI: it would be a waste.
00:08:09 damraThat's a ranking member. Someone senior enough to shape what their committee does with the issue, saying staff education on it isn't worth the hours. Whatever you make of the substance of Coxon's claims, institutional capacity is a separate question and that quote answers it.
00:08:25 lenarThe President's position is on the record now too. Bloomberg and CNBC both have him brushing aside the extinction warnings, saying the United States leads China by about a year, and saying that without that lead the country would be in a very bad position.
00:08:40 damraWhich turns the whole thing into a race, and a race doesn't have a brake pedal in it. If the operating assumption is a one-year lead over China, then every argument for slowing down arrives sounding like an argument for giving up the lead.
00:08:54 lenarThere's a concrete gap in the rules right now. The European Union's AI Act already requires serious-incident reporting. The Trump administration's framework has no equivalent requirement.
00:09:05 damraSo if an American lab has an incident of the kind Coxon was describing, no law obliges them to tell anybody. That's a missing reporting line, and it's small enough to pass in four session days if anyone wanted it to.
00:09:19 lenarGaby Hinsliff wrote in the Guardian about, quote, an industry now practically begging to be saved from itself. Which is roughly where we are. OpenAI asking Congress whether coordination is legal, and Congress short on staff time to learn the subject. Anthropic also told the Wall Street Journal that Chinese companies have been distilling its models. They describe thousands of fake accounts and millions of queries from real users, all routed through what Anthropic calls transfer stations outside China.
00:09:49 damraTransfer stations is a tidy piece of vocabulary for a dull mechanism. It's intermediary infrastructure outside Chinese jurisdiction that makes the traffic look like it originates somewhere else. Anthropic can act on the fake accounts. The millions of real user queries are much harder, because those are real customers doing real work, and some fraction of the output ends up as training data somewhere else.
00:10:12 lenarCNBC's version names Alibaba alongside DeepSeek. And the timing is notable, because this comes a day after the National Security Agency, CISA, and the FBI jointly named six Chinese AI firms in an advisory.
00:10:27 damraWe went through that advisory earlier this week, so the new increment is a lab saying publicly what the agencies said. The revenue number sitting next to it is what separates this from the version we discussed back in June.
00:10:40 lenarMoonshot. Their annualized recurring revenue was three hundred million dollars in June. By August it had reached one billion. They're targeting two billion by the end of 2026, all of it driven by Kimi K3.
00:10:55 damraSo the distillation complaint isn't a research curiosity anymore. It's about a competitor tripling revenue in two months on a model that the American labs say was partly built out of their own outputs. That's a commercial injury claim wearing a national security coat.
00:11:10 lenarThough I'd hold the causal link loosely. Nobody has shown that Kimi K3's revenue depends on distilled data. Anthropic alleges distillation, Moonshot has revenue, and connecting the two is an inference. It's Anthropic's inference.
00:11:25 damraFair. And it puts Garry Tan's do-nothing advice back in view from a different angle. If the Chinese labs are compounding at that rate, a voluntary American slowdown has a very specific price, and the people arguing for it have to say what they think that price is.
00:11:42 lenarOpenAI shipped an Agents API, and the shortest description is that they've taken the Codex harness and hosted it. The orchestration loop, session management, and context compaction all move server-side.
00:11:54 damraThe division of labor is the interesting bit. OpenAI keeps the orchestration and hands you the execution sandbox, which can be theirs, a third party's, or your own. So the product they're claiming is the agent loop, which is exactly what everyone has been rebuilding in-house for two years, and they're leaving alone the place where code actually runs.
00:12:15 lenarTools come in over Model Context Protocol. Skills are runbooks. And there's programmatic tool calling, which is the feature I'd point at. Instead of dumping a log file into the context window, the agent writes code to filter it, and only the result comes back.
00:12:31 damraThat's a real cost line. Filtering logs inside the context window is where token budgets go to die. And the demo emits a structured incident findings file at the end, which tells you the customer they have in mind is an on-call engineer rather than a chatbot user.
00:12:47 lenarThe counterpoint got more traction on Hacker News than the launch did. Armin Ronacher's post, titled Astra for Coding: Why Are We Doing This Again?, was sitting at two hundred and ninety-five points.
00:12:59 damraHis objection is roughly that we keep rebuilding the same abstraction with a new vendor name on it. That's not a small point when the vendor in question owns the loop. If your orchestration lives inside OpenAI's API, switching models later stops being a configuration change.
00:13:16 lenarThere's one caveat I'd put on the whole segment. The only source for what this thing does is OpenAI's own launch video, which runs two minutes and eighteen seconds. No independent evaluation, no pricing analysis, and nobody outside the company has run it under load.
00:13:32 damraRelated, and a little sideways. The Y Combinator spring 2026 batch is four percent native-mobile-first. Back in 2013 that number was fifteen percent. Whatever founders believe the next platform is, they aren't betting on phones, and a hosted agent loop is a reasonable guess at what they're betting on instead.
00:13:53 lenarFour security preprints arrived at once, all version one and none peer reviewed, and together they make agent attacks look more specific than the headline numbers suggest.
00:14:03 damraStart with MMPIBench, because it has the most structure behind it. Seven hundred and twenty runs in total. They span six agent frameworks and five models. The injected instruction arrives through six different visual carriers. Attacks were attempted in twelve point eight percent of cells, and completed in about one percent.
00:14:24 lenarAnd the distance between attempted and completed closes almost entirely at the planning step. The agent reads the injection, starts to act on it, and then something in planning drops it.
00:14:34 damraThe per-model spread is much wider than the average. One model never attempts the injected instruction at all, and recognizes it as an injection fifty-nine point seven percent of the time. Two others attempt it around twenty-three point six percent of the time. So multimodal prompt injection risk isn't one number. It's a property of the specific model you deployed.
00:14:57 lenarThe audio result is what changed my priors. Just two of the five models will ingest audio at all. Of the six frameworks, only three will deliver it. But where audio does arrive, attacks complete in forty-nine percent of cells. For one model it's seventy-five.
00:15:14 damraSo audio isn't safe. Audio is mostly unplumbed. The low aggregate number is an artifact of the pipeline, and the moment more frameworks wire up audio input, that number moves a long way. What's holding it down is missing plumbing, and plumbing gets built.
00:15:31 lenarSecond paper is AgentHijack. Six hundred instance-level online cases across five backends. The number that got quoted around is eighty-four point five percent target attack success. The number that belongs next to it is twenty point three percent end to end.
00:15:47 damraAnd the middle figure explains the gap, which is forty-seven percent action parse. So the attack gets the model to name the malicious target most of the time, but converting that into a parsed action and then a completed chain drops it by a factor of four. Quoting the eighty-four on its own would be misleading.
00:16:06 lenarThere's a detail in the trajectories I hadn't seen described before. In some runs the agent executes the malicious terminal command, and then goes back and finishes the benign task it was originally given.
00:16:17 damraWhich is why detection is so hard here. The user-visible outcome is success. The task completes, the output looks right, and the compromise is a side effect nobody reviews. Any monitoring that keys on task failure sees nothing at all.
00:16:32 lenarThird one is the cipher attack paper. No fine-tuning involved, because the model learns the cipher through prompting and in-context learning, and then the harmful payload arrives looking like gibberish, so the harmfulness classifiers never fire on it. They demonstrate it against Anthropic, Google, and OpenAI models.
00:16:51 damraThat's a structural problem for input filtering as a category. If the model can be taught an encoding at inference time, then any filter inspecting plaintext is inspecting the wrong layer. And the fourth paper, AgentAudit, goes the other direction, scoring ten dimensions over the full execution trace rather than the final output. Claude Sonnet 5 comes in at ninety-five point one composite trust. GPT-5 sits at eighty point six.
00:17:19 lenarWith a limitation the authors flag themselves, which I appreciate. The judge model was one of the models being evaluated.
00:17:26 damraYou can't prompt your way out of that one. It's the same circularity everybody hits when the evaluator and the evaluated come from the same family. Still, scoring the trace instead of the answer is the right direction, and it's the direction the attack papers point at, because the compromise in AgentHijack happens in the trace and never shows up in the answer.
00:17:47 lenarCapital roundup to close. First, Oracle reported thirty percent revenue growth, with cloud infrastructure up a hundred and twenty-one percent year over year. The stock rose six percent on it.
00:17:59 damraThat's the demand side confirmed on an income statement, which is more than most of this week's AI infrastructure news offers.
00:18:06 lenarThen the odd one. The Pentagon is in talks to lend roughly five billion dollars to a neocloud called Fluidstack, with Palmer Luckey's Erebor Bank advising.
00:18:16 damraGovernment financing compute rather than buying it. That's a different instrument with different consequences, because a purchase gets you capacity while a loan gets you a creditor's position and some leverage over who else the borrower serves. And Erebor advising on a Defense Department facility to an AI cloud is a small circle of people.
00:18:36 lenarIn Shanghai, Enflame closed up a hundred and eighty-eight percent on its debut. It raised about nine hundred and ten million dollars and finished at a market capitalization of twenty-six point three billion. Two new billionaires came out of it.
00:18:51 damraDomestic Chinese accelerator demand, priced. That's the other half of the export-control conversation and it doesn't get said much. Restricting Nvidia creates a market, and that market now has a public comparable attached to it.
00:19:05 lenarAyar Labs raised a hundred and fifty million dollar extension to its March Series E, for optical chip-to-chip interconnect. And Fidji Simo joined Nscale's board, recruited by Sheryl Sandberg, while staying on as a part-time OpenAI advisor.
00:19:20 damraTwo items about the same bottleneck from opposite ends. Ayar is solving it in silicon, and Simo's board seat puts an OpenAI-adjacent person inside a compute provider. Both are bets that the constraint stays physical for a while yet.
00:19:35 lenarTwo more papers. There's a cyber-financial contagion model built on sixty vendors and two hundred and twenty banks. The graph carries about twenty-five hundred vendor-to-bank edges and fourteen hundred interbank exposures. Patch latency dominates the outcome.
00:19:51 damraAnd the data is entirely synthetic, which the authors say outright. So it's a model of a contagion mechanism rather than a measurement of one. The patch-latency finding is a property of their graph. It would be a result if somebody ran it on actual vendor relationships, and nobody has.
00:20:08 lenarAnd OpenAI pulled its sponsorship of the Caltech math hackathon after criticism about slop mathematics. We went through the authorship dispute earlier this week. The new piece is that the money moved.
00:20:21 damraWithdrawing a sponsorship is the cheapest available response, and it's also the clearest signal of whose approval OpenAI thinks it needs. Mathematicians are the audience for the proof claims. If that community decides the output is noise, the claims stop working as evidence.
00:20:37 lenarAnthropic's threat report is public, all four preprints are on arXiv, and the House has four session days left. If a serious-incident reporting requirement shows up inside one of those bills, that's the piece of this week that would change what labs are obliged to tell anyone. Thanks, Damra. Lenar Kess.