Wednesday, 7 October 2026

OpenAI published a catalogue of 722 mathematical manuscripts, organised into 372 families, produced by what it calls "an unreleased internal OpenAI model". The repository README says the model was posed approximately 4,000 problems and that each result used, on average, three hours of ChatGPT Pro thinking compute. OpenAI says the collection "includes results at different stages of verification", that "Not all have accompanying Lean formalizations", and that "Some of the unformalized results could have issues". The materials are released under Apache-2.0.
Anthropic folded Project Glasswing and its Cyber Verification Program into a single three-tier programme that gives vetted security teams reduced blocking classifiers on Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1. It disclosed that Glasswing partners "uncovered at least 129,000 verified software vulnerabilities between April and July 2026", with more than 33,000 rated critical or high severity. The Register reports that VulnCheck's Patrick Garrity found fewer than 0.5 percent of the 225 Anthropic-linked vulnerabilities he tracked were being exploited in the wild. On the same day CrowdStrike said a classifier guarding Claude Opus 5.5 and Fable 5 held to a "0% direct bypass rate" across roughly 515 techniques, but that splitting a harmful goal into benign subtasks worked in 9 of 10 offensive categories.
Mistral released a preview of Mistral Large 4, a 1 trillion-parameter model with 49 billion active parameters that it says was trained on 3,800 NVIDIA Grace Blackwell GPUs in its own European datacentres. Common Sense Media rated ChatGPT for Teens an "Unacceptable Risk" after testing more than 4,000 prompts, reporting that the share of resource-warranted responses naming a crisis hotline fell from 33% before launch to 23% after. The Financial Times reported SpaceX is seeking $40 billion, led by Apollo Global Management, to buy Nvidia chips.
Frontier models & labs
OpenAI publishes 722 maths manuscripts in 372 families from an unreleased internal model mixedCompany claim
- The repository README states that "The current catalogue contains 722 manuscripts organized into 372 families" and that they were "produced by an internal OpenAI model". It says "The vast majority of results were obtained with the same procedure using an unreleased internal OpenAI model", that "On average, each result used three hours of ChatGPT Pro thinking compute with that model", and that "Over the course of the evaluation, the model was posed approximately 4,000 problems."
- OpenAI says it expanded these evaluations "after performance on our existing mathematical evaluations saturated", and is also releasing abridged reasoning summaries for 10 named families, including the irrationality exponent of π, the Mézard–Parisi formula for diluted spin glasses and the three-dimensional relativistic Vlasov–Maxwell system.
- OpenAI states the collection "includes results at different stages of verification", that "Not all have accompanying Lean formalizations", and that "Some of the unformalized results could have issues. We will endeavor to fix any such issues quickly." It says it is "exploring community-hosted repositories for these materials".
- The README gives no count of how many of the 722 manuscripts have been formalised, saying only that "Many, but not all, of the manuscripts have been formalized". OpenAI's own announcement post could not be opened for this edition; the figures above are quoted from the repository. Two exceptions to the fixed procedure are named: a zero-free region for the Riemann zeta function and a proof of the Hodge Conjecture for CM abelian varieties, with the former's writeup "human edited for readability".
Mistral previews Large 4, a 1T-parameter model trained on 3,800 Grace Blackwell GPUs in Europe mixedCompany claim
- Mistral says Mistral Large 4 ("le Chonk") is a 1 trillion-parameter natively multimodal model with 49 billion active parameters, available as a public preview API, and that it "was trained from scratch on 3,800 NVIDIA Grace Blackwell GPUs in Mistral's own datacenters in Europe". Listed pricing is $1.36 per million input tokens and $4.18 per million output tokens.
- Mistral reports 61.7% on DeepSWE v1.1, 59.4% on SWE-Atlas-QnA and 28.3% on Terminal-Bench 4, and a combined Coding Agent Index score of 49.8% that it says places the model ahead of DeepSeek V4 Pro 0813 and Qwen3.8 Max.
- On cyber capability Mistral says the model scores 82% on the Artificial Analysis Cyber Index reproduce-and-patch test, "the highest of any model", and solves 93% of the 40 exercises in Cybench. It says "Claude Opus 5.5 and GPT-6 Astra, score near zero on the same test because they refuse to perform the task."
- Every benchmark figure is Mistral's own and none is independently verified; TechCrunch writes that "With benchmark results still pending, Mistral hopes ML4 will be best in class among open-weight models." The two sources also disagree on the GPU count: the Mistral post says 3,800, while VP Science Pierre Stock told TechCrunch the run used "only 4,000 Nvidia GPUs 'which is two to three times less than our Chinese competitors, and significantly less than the closed source competitors'". Mistral says the weights drop at the end of October after red-teaming "with cybersecurity leaders, vetted partners, and state authorities".
Google releases EmbeddingGemma 2, a 740M-parameter multimodal embedding model under Apache 2.0 Company claim
- Google says EmbeddingGemma 2 is built on the Gemma 4 architecture, has 740 million parameters, is released under Apache 2.0, and places code, images, video and audio in a shared embedding space. It needs "as little as 270M parameters for text-only workloads", with optional 170M vision and 300M audio encoders.
- Google reports the model scores 78.68 on the Massive Text Embedding Benchmark (Code), up "from 68.76" for its predecessor, and says quantised on a Google Pixel 11 Pro it requires "as little as ~191MB active RAM for text-only weights and ~567MB for the full multimodal model". Matryoshka Representation Learning truncates vectors from 768 dimensions to 512, 256 or 128, which Google says gives up to 6x storage reduction.
- Google says the original EmbeddingGemma passed "more than 20 million downloads". The context window is 8K tokens, which Google describes as four times larger than the predecessor's.
- The benchmark comparisons are Google's own and are not independently verified. Google's claim that the model "even outperforms some specialist models more than twice its size" is stated without naming those models in the figures reported here.
Google ships Nano Banana 2.1, halving its per-image price against Nano Banana 2 Company claimSingle source
- The Decoder reports Nano Banana 2.1 is built on Gemini 3.6 Flash and replaces Nano Banana 2, and lists the price of a 1K image at 3.36 cents, down from 6.70 cents, with a 4K image dropping from 15.10 to 7.56 cents. Nano Banana Pro is listed at 13.40 cents per 1K image.
- On overall text-to-image preference Elo, The Decoder reports Nano Banana 2.1 (Thinking) at 1050 ± 14 and the no-thinking variant at 1015 ± 13, against 990 ± 7 for Gemini 3.1 Flash Image and 935 ± 8 for Gemini 3 Pro Image. On multi-character consistency in editing it reports 1106 ± 14 and 1068 ± 14 for the two variants.
- Per Google, cited by The Decoder, the model can process up to 14 reference images at once, keeping up to four characters and ten objects consistent, and offers minimal, medium and high thinking levels.
- The Decoder notes a limit on what the benchmark gains show: "Although 2.1 sometimes beats Pro by a wide margin in benchmarks, Nano Banana 2 also matched it in those tests." The Elo figures are Google's and are not independently verified; no Google post for this release was reachable for this edition.
Research & papers
Apple–Johns Hopkins self-alignment method cuts an Agentic Misalignment score from 79.1 to 3.8 beneficialPreprintSingle source
- arXiv:2610.07935, "SIGMA: Self-Improving Alignment Generalization from a Model Spec", reports that despite training only on single-turn chat data the method improves multi-turn agentic safety: "AgentHarm harmfulness decreases from 22.6 to 14.8; Agentic Misalignment decreases from 79.1 to 3.8". Authors are Jingyu Zhang, Shruti Palaskar, Daniel Khashabi, Benjamin Van Durme, Leon A. Gatys and Joseph Yitan Cheng, with affiliations listed as Apple and Johns Hopkins University.
- The abstract says the method "outperforms Deliberative Alignment and Constitutional AI baselines, and retains general capability". The candidate model acts as its own task-designer agent, generating alignment dilemmas from a Model Spec, then undergoes supervised fine-tuning plus rubric-based reinforcement learning "with the model itself as the reward model".
- The result bears on a measurement gap the briefing has tracked: safety training done on chat transcripts has repeatedly failed to carry over to agents acting over many turns.
- This is a preprint, submitted 6 October 2026, and has not been peer reviewed or independently reproduced. The paper reports results on the authors' own training runs; it does not establish that the gains hold for models the authors did not train.
Benchmark across six coding-agent harnesses: auto-approve raises attack success from 29.2% to 95.6% harmfulPreprintSingle source
- arXiv:2610.07639, "HarnessSecurity-Bench: Do Security Mechanisms Really Protect Coding Agent Harnesses?", reports that "Enabling auto-approve increases utility and raises attack success from 29.2% to 95.6%." The harnesses evaluated are named as "Claude Code, Codex CLI, Gemini CLI, gptme, Qwen Code, and GitHub Copilot".
- The authors report the scale of the evaluation as "we conduct 2,500 trials, recording 81,155 tool calls and over 2.2 billion tokens", under a controlled baseline model the paper identifies as GLM-5.2, across a benchmark of 23 tasks spanning five attack surfaces.
- On which defences work, the paper reports that network isolation and read-only mode "reduce attack effects with substantial utility losses", while command allowlisting and denylisting do so "with a small utility loss and a utility gain, respectively". It also reports that "about half of confirmed mechanism implementations are opt-in" — that is, off unless a user turns them on.
- This is a preprint, submitted 6 October 2026, and has not been peer reviewed. The authors are Zhengyang Zhu, Liming Huang, Runmin Ji and others; affiliations were not shown on the abstract page. The figures are the authors' own measurements against one baseline model, not vendor-confirmed.
Oxford benchmark: misuse monitors that read content collapse to AUC 0.52 on prompt injection mixedPreprintSingle source
- arXiv:2610.07089, "Towards a Unified Misuse Monitoring Benchmark" by Aniruddh Pramod, James Oldfield and Adel Bibi of the University of Oxford, builds "a benchmark of ~6,200 conversation transcripts between a user, an LLM agent, and the external environment" covering both decomposition attacks and prompt-injection attacks in one schema.
- Across 17 monitor configurations the authors report that their action-framed monitors "perform well on both threats under classical metrics (AUC: 0.95 and 0.99 respectively)", while "content-framed monitors collapse on injection attacks (AUC: 0.52)" — a score at the level of a coin flip.
- The paper also reports that "all monitors localise decomposition attacks poorly under the interval metric", and argues that position-blind metrics "paint an optimistic picture of monitor performance". That matters for deployed defences, which are usually scored on exactly those metrics.
- This is a preprint, submitted 5 October 2026, and has not been peer reviewed. The 50-page paper reports the authors' own monitors as the best-performing configuration, and the comparison set is the authors' own construction rather than a vendor's production monitor.
Paper finds GPU power traces cannot exclude 41% of hidden compute, weakening a chip-governance tool mixedPreprintSingle source
- arXiv:2610.07476, "Can Power Draw Constrain Covert Compute? Limits of Analogue Verification for AI Governance" by Tom Kimpson, Mauricio Baker and Emlyn Graham, derives a closed form for the largest hidden computation a power trace cannot rule out. It reports: "Measurements on NVIDIA A100 GPUs constrain β = 1.16 in the worst case, while adversarial matched-energy strategies are shown to hide at least β = 0.41 of compute."
- Under a stronger threat model, where the verifier can re-execute the declared work at an observed operating point, the authors report that the verifier can "push β down to 0.059 in the maximally restricted case". Their conclusion is that "analogue power measurements alone therefore constrain compute weakly".
- The result speaks to a live policy question: proposals to verify where and how declared AI compute is used have leaned on physical side channels such as power draw as a cheaper alternative to inspections.
- This is a preprint, submitted 5 October 2026, and has not been peer reviewed. The measurements are on NVIDIA A100 GPUs, an older generation than current frontier training hardware; the paper does not report equivalent figures for newer accelerators. Affiliations listed are the University of Melbourne, MATS and the University of Oxford.
EMNLP paper: hardening a backdoor before release lifts post-fine-tuning attack success from 20% to 74% harmfulPreprintSingle source
- arXiv:2610.07510, "Understanding and Enhancing Backdoor Persistency in LLM Agent Post-Training", accepted to EMNLP 2026 Findings, reports of its method: "PersistBD raises attack success from 20% to 74% after SFT and from 20% to 76% after SFT-RL, while maintaining comparable benign task performance." The model tested is Qwen2.5-Coder-7B.
- The threat model is a third-party model shipped with a hidden backdoor and then adapted by a developer. The paper reports that "benign SFT substantially reduces attack success, but subsequent RL often preserves the residual behavior and sometimes even increases attack success" — so the usual assumption that ordinary fine-tuning washes a backdoor out does not hold through the reinforcement-learning stage.
- Authors are Qiusi Zhan, Nian Lyu, Stephanie Ding, Arnav Mehta, Xander Davies and Daniel Kang, with affiliations listed including the University of Illinois Urbana-Champaign, MATS Research and the University of Oxford.
- The paper is a venue-accepted preprint, submitted 5 October 2026; the Findings track acceptance is noted by the authors. The figures are for one 7B coding model and one fine-tuning recipe, and the paper does not report whether the effect holds at frontier scale.
Security, misuse & threat intelligence
Anthropic merges Project Glasswing into a three-tier cyber programme, citing 129,000 verified vulnerabilities mixedCompany claim
- Anthropic says the expanded Cyber Verification Program "now consists of three access tiers" — Defense Access, Red Team Access and Specialized Access — and that "Each tier includes access to our most capable models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models moving forward." It discloses that Glasswing partners "uncovered at least 129,000 verified software vulnerabilities between April and July 2026", that its own open-source scanning "found an additional 5,500 verified software vulnerabilities between April and October 2026", and that "more than 33,000 have so far been rated as critical- or high-severity".
- On its own safeguard tests Anthropic reports that across five attempts at each of 10 CyScenarioBench challenges per tier, "In the Defense Access tier, 46 of the 50 trials were blocked at some point in the challenge, while the remaining four tasks succeeded", and "In the Red Team Access tier, no blocks occurred, and Claude Opus 5.5 successfully completed 34 of the 50 tasks—effectively equivalent to the model's 67.6% success rate on this evaluation with no safeguards applied." Specialized Access, with the fewest blocks, covers testing of "flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks", and Anthropic says it reviews every such organisation "in collaboration with the US government".
- The vulnerability counts are Anthropic's own and the company states their limits: they rest on "partial data from 33 partner reports", "fewer than 50% of partners disclosed patched numbers", and Anthropic expects "the true impact to be at least five times higher". Data retention is mandatory for enrolled organisations "so that we can monitor for cyber misuse".
- The Register reports a sceptical reading of the same numbers: VulnCheck researcher Patrick Garrity "was not particularly impressed with CVEs identified by Project Glasswing, noting that fewer than 0.5 percent of the 225 Anthropic-linked vulnerabilities he tracked were being exploited in the wild". It adds that on Anthropic's own figures, "of 5,674 true positive vulnerabilities, 3,014 are high severity, and 1,522 are critical severity, yet only 516 have been patched."
CrowdStrike: a classifier blocked 515 direct bypass attempts but task decomposition worked in 9 of 10 categories harmfulCompany claimSingle source
- CrowdStrike's Cyber Superintelligence Lab says it tested "the most advanced publicly deployed content safety classifier, which guards models such as Claude Opus 5.5 and Fable 5", and reports: "We tested approximately 515 distinct bypass techniques, including encodings, psychological manipulation, multi-turn escalation, many-shot tactics, tokenizer exploits, Unicode tricks, and 24 novel approaches drawn from cognitive science. These techniques achieved a 0% direct bypass rate."
- The failure it reports is structural rather than a misclassification: "The classifier evaluates individual requests, not request sequences." Its pipeline — "Decompose → Benign Reframe → Recompose" — splits an offensive goal into genuinely benign software-engineering subtasks and reassembles the outputs with an unclassified open-weight model. CrowdStrike says that "Across 9 of 10 offensive categories" this produced "working offensive code", and that "An attacker with a free API key and a local open weight model has everything they need to cheaply run this pipeline today."
- CrowdStrike notes the finding was arrived at independently of earlier work, citing a September 2026 Microsoft Research paper, "Capability Laundering", which described the same shape of attack and concluded that "per-exchange filtering is structurally insufficient".
- These are CrowdStrike's own measurements against one unnamed classifier and are not independently verified; CrowdStrike does not name the vendor, referring to "Frontier Model A". The blog carries a date of 6 October 2026 but no time of day, so its position inside this edition's window could not be confirmed to the hour.
Phishing kit clones ChatGPT, Gemini, Claude and Meta Muse sign-in windows to harvest MFA codes harmfulSingle source
- BleepingComputer, citing researchers at browser security company Island, reports a campaign that uses fake ChatGPT, Gemini, Claude and Perplexity pages to steal credentials and multi-factor codes via browser-in-the-browser attacks, in which a counterfeit browser window is drawn inside a real one. The researchers say the operation "leveraged the recent launch of the Muse AI agent, which Meta describes as an assistant for various personal tasks."
- Island says the kit adapts its fake window to Windows, macOS, iOS and Android, including browser styling and dark-mode support, and that once a victim is in the flow a human operator takes over: the attacker "may ask for password entry up to three times, request an SMS or authenticator code to bypass MFA protections, display Okta push requests, show Google approval prompts, or display a QR code." The platform supports Google, Meta, TikTok and Okta sign-in workflows.
- The researchers traced the activity "as far back as March" after the attacker exposed older source code in misconfigured public GitHub repositories, and found the Telegram control channel "had received hundreds of victim submissions".
- Island itself cautions on that last number: BleepingComputer reports it "does not necessarily reflect the number of successfully compromised accounts". No published Island report URL could be located for this edition, so all figures here come from BleepingComputer's text attributing them to Island, and no victim count, dollar loss or named target organisation is reported.
North Carolina musician sentenced to 18 months for a $10 million streaming fraud using AI-generated songs harmful
- Michael Smith, 54, of North Carolina was sentenced on Tuesday to 18 months in prison and ordered to forfeit $8,091,843.64, with a further two years of supervised release, both outlets report. BleepingComputer says he collected "more than $10 million in royalties from Spotify, Apple Music, Amazon Music, and YouTube Music". He pleaded guilty in March, after a September 2024 indictment covering conduct between 2017 and 2024. Forbes reports prosecutors called it the first criminal case involving AI-music streaming fraud.
- Forbes, quoting the prosecutors' release, says Smith used "as many as 10,000 Bot Accounts" created with fake email ids and "fraudulently obtained debit cards", and used AI to create "hundreds of thousands" of songs, streamed "billions of times". BleepingComputer reports a lower peak figure of "more than 1,000 bot accounts", and adds from court documents that a 20 October 2017 email Smith sent himself set out 52 cloud service accounts with 20 bot accounts each, roughly 661,440 streams per day and annual earnings exceeding $1.2 million at an average royalty rate of half a cent per stream.
- Prosecutors measured the scheme against a real catalogue, and the two accounts agree on Smith's side of the comparison but not on Taylor Swift's. Both report 80.9 million family-plan streams of Smith's AI-generated music on YouTube Music in April 2023; BleepingComputer quotes the Justice Department putting Swift's entire catalogue at "9.3 million streams on YouTube Music from family plan streams" that month, while Forbes reports "3 million streams". Readers should treat the Swift figure as unresolved.
- No Justice Department press release for the sentencing could be opened for this edition, so every figure above is as the two outlets render that release and the court documents. The bot-account count and the Swift comparison differ between them. The AI music company whose chief executive is referenced in the court documents is not named.
South Korea's president orders AI-specific cyber defences and a review of all national core infrastructure harmfulSingle sourceUpdate
- President Lee Jae Myung told his cabinet that "recently, a series of personal information leak incidents have been occurring at financial and public institutions" and that "circumstances indicate that artificial intelligence was utilized, causing great concern and anxiety among the public", The Register reports.
- Lee asked authorities to "build security capabilities that can detect attacks in advance and preemptively block them", and said: "I urge the relevant ministries to quickly inspect the security systems across the entire national core infrastructure, as well as the private sector, and immediately implement any necessary security measures." He also said he hopes the country can "accelerate the development and distribution of AI technologies specifically tailored for cybersecurity".
- This follows the bank intrusions reported in the 6 October edition, in which South Korea's Financial Services Commission said more than 68,000 people were affected. The new facts here are the cabinet directives themselves.
- The remarks are a political instruction, not a technical finding: neither the president nor The Register's account names which AI tools were used, which group is suspected, or what evidence links AI to the intrusions. No ministry implementation plan, budget or deadline is reported.
Military, defense & geopolitics
White House and Anduril announce a $6.6 billion software-run yard for Virginia-class submarine components Company claim
- White House Principal Deputy Press Secretary Anna Kelly said on a call with reporters: "The United States Navy, together with Anduril Industries, will invest $6.6 billion to create a new facility in Baltimore County, Maryland, which will manufacture critical components for the Virginia-class submarine… creating over 13,000 direct and indirect jobs, and driving $2 billion in annual economic output". Breaking Defense reports the total comprises "$3.7 billion in private capital and up to $2.9 billion from the Navy".
- Anduril says the facility, Arsenal-2, will occupy a 187-acre site at Tradepoint Atlantic in Baltimore County, run to more than 2 million square feet, and begin "initial operations… in 2030". Components will go to Electric Boat and Newport News Shipbuilding for final assembly. Anduril president and chief strategy officer Chris Brose said the company is already standing up an interim facility in California for "relatively simpler, kind of more straightforward components… Things like torpedo tubes", and will "scale up to larger" items as the Baltimore yard comes online. A defence official told reporters the added capacity "would be the equivalent of about a 15% increase" in Virginia-class production.
- The AI content is in the manufacturing layer: Anduril says its industrial software platform ArsenalOS will be the "digital backbone", connecting "fabrication workflows, outfitting sequences, material movement, inspection protocols, and documentation requirements in a single system". Breaking Defense notes the announcement "marks Anduril's first entry into the supply chain for a major legacy defense program".
- The $2.9 billion Navy share is a ceiling, not an obligation, and the job and output figures are Anduril's and the White House's projections rather than measured results. Anduril says the structure "ensures that Anduril, not the taxpayer, takes on the majority of the execution risk". President Trump's remark at the site that he "love[s] the idea of the autonomous sub" is not matched by any autonomous-submarine commitment in the announcement.
Northrop Grumman says its YFQ-48A Talon Blue flew its first fully autonomous flight at Mojave Company claimSingle source
- Defense News reports, citing a company release, that Northrop Grumman's YFQ-48A Talon Blue Collaborative Combat Aircraft "executed its first fully autonomous flight in Mojave, California, which included taxi, takeoff, in-flight maneuvers and landing" — the full sortie without human control.
- Craig Woolston, Northrop Grumman vice president and general manager of research and advanced design, is quoted: "Our customers made it clear they need autonomous systems that can be fielded faster and more affordably without sacrificing mission effectiveness. We listened."
- Defense News notes the announcement came weeks after US Air Force officials said they intend to have 500 autonomous aircraft in service by 2032, and that six vendors were chosen in June for Increment 1 mission-autonomy software, with one to be selected by summer 2027.
- Northrop has not been awarded a Collaborative Combat Aircraft production contract. The flight claim rests on the company's own account: Northrop's newsroom is JavaScript-rendered and the press release itself could not be retrieved for this edition. No altitude, duration, or details of what the autonomy software decided are reported.
Health, science & medicine
Google reports geospatial foundation-model gains across five public-health studies, including cholera in DR Congo beneficialCompany claim
- Google reports five partner-led case studies adding its Population Dynamics Foundation Model to existing epidemiological workflows. With WHO AFRO on cholera emergence in the Democratic Republic of Congo, across 403 health zones over 89 weeks, it reports "+9.7% improvement in Area Under Precision-Recall Curve at 4 weeks" and "+18.1% Precision@5 at 8 weeks", rising to +19.3% in endemic zones.
- On MMR vaccination coverage with Mount Sinai Health System and Boston Children's Hospital across 146 US–Canada border counties, Google reports a 36% relative gain in explained variance, from 0.159 to 0.216, which it describes as statistically significant. On dengue forecasting with the University of Oxford and Tecnológico de Monterrey across about 2,450 Mexican municipalities, it reports a statistically significant Weighted Interval Score improvement of -0.0051 and accuracy improved in up to 72% of active-transmission municipalities.
- Two of the five studies show little or no benefit. On cardiovascular disease mortality across 3,091 US counties with NYU Grossman School of Medicine, mean absolute error was 18.7 deaths per county with the model against 19.1 using census data, with "no statistically significant differences". On postpartum depression with the University of Washington, across 332,970 CDC PRAMS respondents, the reported AUC gain was +0.0020 in seen states and +0.0038 in unseen states against a 0.62 baseline.
- All figures are Google's own and are published on its research blog rather than in a peer-reviewed paper reachable for this edition. The embeddings are commercially available in Preview as "Population Dynamics Insights" through Google Maps Platform, with no-cost access for selected non-operational academic research.
Pre-registered study: the choice of LLM rater explains 30.0% of depression-score variance, the patient 10.5% mixedPreprintSingle source
- arXiv:2610.08501, "Language-model ratings of depression reflect the rater more than the patient", pre-registered 880 language-model raters "crossing 11 open models with prompting and scoring choices" and applied them to 189 interviews scored against the eight-item Patient Health Questionnaire. It reports: "Model choice explained 30.0% of summed-symptom score variance, stable participant differences 10.5%."
- On the clinical consequence, the paper reports that "Two randomly drawn raters with area under the receiver operating characteristic curve (AUC) >= 0.70 disagreed on screening decisions for 40% of participants, on average" — so two configurations that both look acceptable on a standard discrimination metric reach different screening conclusions for two in five people.
- The author reports that "A locked analysis of 86 new interviews reproduced the main pre-registered findings", and that exploratory recalibration with 40 labelled participants "raised accuracy from about 60% to 75% and halved disagreement", while still "leaving one participant in five decided differently".
- This is a single-author preprint, submitted 6 October 2026, and has not been peer reviewed. The models tested are open-weight systems, not the proprietary models most likely to be used in a deployed screening product, and the paper reports results on interview transcripts rather than live clinical encounters.
Policy, regulation & law
Justice Department tells staff to write "super intelligence" instead of "artificial intelligence" Single source
- Acting Deputy Attorney General Trent McCotter issued a memo on Tuesday 6 October directing Justice Department employees to use "super intelligence" and "SI" in place of "artificial intelligence" and "AI" across public statements, policy documents, records and other communications, with the directive extending to court filings when appropriate. Forbes reports that "Earlier on Tuesday, Reuters reported that the Justice Department has directed its employees to use 'super intelligence' instead of 'artificial intelligence'."
- The memo implements Executive Order 14434, signed 29 September 2026, which Forbes reports directed federal departments and agencies to use "Super Intelligence" and "SI" in official communications and documents and said the executive branch will no longer "acknowledge the usage of 'Artificial Intelligence' and 'AI' in any applicable setting". Analytics Insight reports the order gives federal officials 60 days to propose a formal definition.
- The change is already visible in enforcement documents. Forbes reports that the prosecutors' release in Tuesday's AI music streaming fraud sentencing "extensively uses 'Super Intelligence'", refers to the case as "Super Intelligence-Assisted Music Streaming Fraud", and quotes U.S. Attorney Jamie McDonald saying Smith "exploited super intelligence technology to generate a fraud".
- The memo itself is not public: both accounts trace to the same Reuters report of a document Reuters saw. Neither source reports whether the renaming carries any substantive legal effect, nor how it interacts with statutes and regulations that use the term "artificial intelligence".
European Commission registers a citizens' initiative seeking a protected ".IA" domain for AI governance
- The Commission registered the European Citizens' Initiative "Creation of a European Digital Space (.IA) for Sovereign AI Governance" on 6 October. The organisers invite the Commission "to propose a framework for high-trust digital spaces and to take the initiative at European level to negotiate with ISO and ICANN with a view to safeguarding the .IA domain".
- The initiative sets out three objectives: an EU framework promoting "High-Trust Digital Spaces" and sandboxes for ethical AI; negotiation with ISO and ICANN/IANA on "the reservation, protection and allocation of the namespace .IA as an asset of European digital sovereignty"; and ensuring that registration and resolution of the .IA domain incorporate "the Sovereign Digital Identity (eIDAS 2.0), transparent algorithmic auditing (AI Act) and the protection of personal data (GDPR)".
- Registration is a procedural step, not endorsement. The Commission states it considers the initiative legally admissible under the European Citizens' Initiative Regulation but that it "has not analysed the substance of the proposals at this stage", and that "The content of the initiative only expresses the views of their organisers".
- The threshold is high and the timeline long: the organisers have six months to open a 12-month signature-collection period, and the Commission is required to react only on "at least one million valid statements of support" with minimum numbers reached in at least seven Member States. The Commission notes it has registered 136 initiatives since the mechanism began.
US Copyright Office opens an inquiry into music streaming fraud, citing AI-generated songs as a catalyst
- The United States Copyright Office published a notice of inquiry, Docket No. 2026-6, on 7 October 2026 saying it is "soliciting information from the public regarding issues related to music streaming fraud", "Pursuant to a congressional request". Written comments are due by 11:59 p.m. Eastern Time on 23 November 2026, and reply comments by 11:59 p.m. Eastern Time on 21 December 2026. The Office says the inquiry responds to a letter from Representative Scott Fitzgerald dated 21 May 2026.
- The notice ties the inquiry directly to AI-generated music, noting of the case against Michael Smith that "the hundreds of thousands of songs that the defendant uploaded were created with artificial intelligence". It quotes the congressional request as saying "there is nothing inherently wrong with using AI as a creative tool in music development, or the organic growth of AI-generated music", but that "generative AI can serve as a catalyst for criminals to perpetrate streaming fraud", especially as fraud scales with the number of songs involved. Subject of inquiry No. 4 asks what data exists on the relationship of streaming fraud to "the effects of AI-generated [music]".
- The notice sets the market context in which it is asking: it cites a Digital Media Association estimate that streaming is "now driving around 70% of global sales", sound-recording streaming revenues of "approximately $9.5 billion domestically and $22 billion globally", and total music-publishing revenue of "approximately $7.3 billion domestically and $10 billion globally". It arrives the day after Smith was sentenced, and gives the federal copyright regulator a formal record on which a rule or a legislative recommendation could later rest.
- This is a request for comment, not a rule: the Office proposes no standard, obligation or enforcement action in the notice, and names no deadline for its own report. The Federal Register HTML page redirects to an anti-scraping gate, so the text above was read from the government's raw-text version of the same document.
Compute, chips & infrastructure
SpaceX seeks $40 billion led by Apollo to buy Nvidia chips, the Financial Times reports
- SpaceX plans to raise $40 billion, led by Apollo Global Management, to buy Nvidia AI chips, the Financial Times reported on Tuesday citing people familiar with the matter. The company is seeking about $10 billion in bank loans and $30 billion in investment-grade debt, with bond fund Pimco among a small group of lenders in talks and the transaction expected to close in 2027.
- The chips are intended for SpaceX's terrestrial data centres and its planned AI infrastructure in orbit. Musk said the company plans to use Nvidia hardware exclusively for its data centres.
- SpaceX shares fell 1% in extended trading after the report, while Nvidia's stock rose 0.5%. For scale, the same wire story notes Morgan Stanley estimates AI infrastructure will require $1.5 trillion in external financing by 2028, and that Musk took SpaceX public in June in a record $86 billion IPO.
- The figures are from the FT's unnamed sources, not a filing or company statement. SpaceX, Apollo and Nvidia did not respond to Reuters and Pimco declined to comment, so no party has confirmed the amounts on the record.
Lambda raising up to $4 billion at a $14.5 billion valuation as its backlog jumps to $50 billion on an Anthropic deal
- Cloud provider Lambda is raising up to $4 billion at a $14.5 billion pre-money valuation, led by Coatue Management and Blackstone, in what TechCrunch reports could be its last private round before a planned 2027 IPO, citing The Wall Street Journal.
- A letter to investors reviewed by the Journal shows Lambda's backlog grew from $15 billion in June to $50 billion in September. TechCrunch reports that "much of that increase appears to be driven by a $35 billion commitment from one company: Anthropic, which signed a deal with Lambda in late August" — meaning roughly four fifths of the increase traces to a single customer.
- Lambda closed an additional $1 billion in senior secured fixed-rate financing the week before, on top of the equity raise; TechCrunch notes data-centre buildouts are largely funded by debt.
- The round is reported as in progress, not closed, and the backlog figures come from a private investor letter rather than a filing. Lambda, Coatue and Blackstone did not immediately respond to TechCrunch's request for comment. The IPO was reportedly meant to happen this year and has been pushed back.
Finnish regulator orders Google's Tuike Finland to halt preparatory work at two data-centre sites mixed
- The Finnish Supervisory Agency (LVV) ordered work on two of Google's data centre sites halted until mandatory environmental impact assessments are completed, AFP reports. It demanded that Tuike Finland, a company representing Google, "immediately suspend, and no later than 23 October 2026, all preparatory measures that would significantly alter the environment in connection with the planned data centre projects in Muhos and Kajaani".
- Tuike Finland must explain itself and set out how it intends to proceed by 14 October; if it does not comply, the agency said it may initiate enforcement proceedings.
- The sites are part of what Google has called its single biggest investment in Europe: a 13-billion-euro ($15-billion) digital infrastructure commitment announced in September, covering the municipalities of Muhos, Vaala, Kajaani and Hamina over the next two years.
- Hanna Halmeenpaa, chair of the Finnish Association for Nature Conservation, told AFP at the Muhos site that "nature sites which should be preserved" had been logged in a deforested area of more than 300 hectares (741 acres). The order halts preparatory work pending assessment and does not cancel the projects; no Google response is reported in this account.
Deployment & impact
Common Sense Media rates ChatGPT for Teens "Unacceptable Risk", finding crisis-hotline referrals fell after launch harmfulSingle source
- The Youth AI Safety Institute's assessment, dated 7 October 2026, rates ChatGPT for Teens an "Unacceptable Risk" after testing more than 4,000 prompts across pre- and post-launch windows. On resource-warranted prompts, the share of responses naming a crisis hotline fell from 33% before launch to 23% after; referrals to a specific medical or mental-health professional fell from 68% to 58%; and use of urgent-action language such as "right now" or "call 911" fell from 87% to 75%.
- On parental notifications, the assessment reports that fresh accounts making explicit crisis disclosures produced zero notifications across all four personas tested over 5-to-60-minute sessions, with four notifications received across the full testing programme.
- On academic integrity, it reports that "Show me the answer" appeared in 43% of responses for a linked 13-year-old account with Study Hours and in 90% of responses for an unlinked 17-year-old using "@study", and that deleting the "@study" prefix produced a 100% assignment completion rate.
- The Institute's first recommendation is to suspend teen access until the safety features are independently verified; it also asks OpenAI to remove "Show me the answer" when Study mode is on, to timestamp parental crisis notifications, and to share testing data with independent researchers. These are one organisation's measurements; OpenAI's response is not recorded in the assessment, and the figures are percentages of tested prompts, not of real teenage conversations.
Meta, Sierra, Walmart, Shopify and Stripe publish a Personal Agent Protocol for agent-to-business dealings Company claim
- Sierra says the Personal Agent Protocol is "an open standard Meta and Sierra are developing along with industry partners at Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart that defines how personal agents interact with businesses", designed "to handle authentication, empower consumers and give companies visibility into what personal agents do through their websites, APIs or company agents". Sierra says it plans to publish the v0.1 specification later this month, hold design workshops and publish a reference implementation.
- The problem it names is that agents currently impersonate human traffic: "Today most personal agents use websites and apps the way people do — loading pages and clicking through forms." Sierra chairman Bret Taylor, who also chairs OpenAI, told CNBC: "Companies will know when it's a personal agent versus an actual person. For a lot of companies there's a risk: you don't want just a random bot that isn't acting on behalf of a person to have access to this service", adding "It is kind of chaos until such a standard exists."
- CNBC reports the context: Meta's Muse agent "soared to the top of Apple's App Store and remains there, ahead of ChatGPT", while Amazon has blocked Meta's agents citing website-scraping concerns, and sued Perplexity in November alleging it took steps to "conceal" its agents. David Singleton of Meta Superintelligence Labs told CNBC Muse already has millions of users in the US and is "growing rapidly".
- No specification, licence or governing body has been published yet, and the user figure is Meta's own. CNBC reports OpenAI and Anthropic "aren't on board now", with Taylor saying he expects them to participate and would be "really disappointed" if competitors do not use it.
Study: with no financial facts given, identity explains 96% of variation in an LLM's financial advice harmfulPreprintSingle source
- arXiv:2610.07798, "Thin Evidence, Thick Priors: How Language Models Substitute Identity for Missing Financial Facts", accepted to ICAIF'2026, reports that "the average gap between two personas with identical finances rises from 4.78 percentage points at full disclosure to 10.34 points with no financial facts", across 96,600 prompts to Llama-3.1-8B-Instruct built from 100 financial profiles, 138 personas and seven disclosure conditions.
- The sharpest figure is the shift in what drives the answer: "Identity explains 5% of within-profile variation in advice at full disclosure and 96% with no disclosure." In other words, as the facts thin out the model falls back on who it thinks it is talking to.
- That pattern matters for deployed advice tools, where users routinely supply partial information and the system answers anyway rather than asking for what is missing.
- This is a preprint, submitted 6 October 2026, by Saanvi Khetan and Sankar Balasubramanian; the ICAIF acceptance is the authors' own note. The results are for a single 8B open-weight model, and the paper does not report whether frontier proprietary models behave the same way.