Topics / topic

Anthropic

33 items across 5 editions · appeared in the last 5 editions in a row. First seen Fri 11 Sep, last seen Tue 15 Sep. Traced across 1 weekly review.

How this story has evolved

From the week in review: the connections, developments and open questions filed under Anthropic, newest week first.

Week of 7–13 September 2026

Connection
Third-party verification was proposed, legislated and declined in the same week

All three developments concern the same object: an outside party with the access to check a frontier model. On 9 September Governor Gavin Newsom signed SB 813 and AB 1405, which his office describes as a framework for "independent verification organizations" and "a state registry for AI auditors". On the same day, Reuters reported, OpenAI urged Congress to adopt "capability-based national AI safety requirements, including testing standards, independent assessments, cybersecurity protections and incident-reporting rules for the most advanced AI systems". On 12 September Amodei's essay committed Anthropic to embedded evaluators with "Desks in our offices, access badges, and company laptops".

Connection
Two government agencies, two frontier labs and Beijing all spoke about model extraction within three days

The joint advisory came on 8 September from CISA, NSA and FBI; Google's threat group published the same day; Anthropic's report followed on 10 September; Beijing responded on 9 September; and Amodei's essay of 12 September asks governments to "Crack down on unauthorized distillation by companies in authoritarian countries" and to "Do not sell powerful AI chips or semiconductor manufacturing equipment to China".

Connection
One company published its misuse findings, asked the industry to slow down, withheld a model from a state evaluator and lost the Pentagon

Anthropic stories landed on four consecutive reporting days. On 9 September IT Pro reported that the company had withheld Claude Mythos 5.1 from the UK AI Security Institute. On 10 September it published a threat report describing weapons and biological misuse of Claude. On 11 September DefenseScoop reported that about 90% of the Pentagon's classified AI workloads had moved off its models. On 12 September its chief executive published an essay asking companies to pace capability gains.

Connection
AI-driven vulnerability discovery showed up on both sides of the ledger in the same week

On 8 September Microsoft shipped updates for "at least 974 security holes", and Krebs on Security wrote that Adobe, Cisco, Google, Mozilla and Oracle "all have recently credited AI-assisted research with increasing their patch cadence and volume". The same day VulnCheck reported that of 26,153 findings Anthropic says Claude discovered, "only 202 (0.8%) have been fixed". On 10 September Anthropic's own threat report described the GTG-10007 cluster running an autonomous exploit foundry that produced "more than a dozen possible zero day findings in a single month".

Development · Tue 8 Sep, Wed 9 Sep, Fri 11 Sep, Sat 12 Sep, Sun 13 Sep
A researcher quits, OpenAI asks Congress for mandatory rules, and Amodei commits Anthropic to embedded evaluators as rivals back a slowdown

Jacob Coxon, whom CNBC describes as a researcher "who has worked as a researcher at both companies", resigned on Tuesday 8 September and wrote on X: "Neither company is acting responsibly. They are racing straight to self-improving superintelligence." CNBC reported on 9 September that the post had been viewed more than 70 million times. Evan Hubinger, an alignment lead at Anthropic, replied late on 8 September: "Jacob is correct here—we really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade." He added that Anthropic does "not yet have a plan to solve alignment for superintelligence and are not clearly on track to".

Development · Wed 9 Sep
FT: Anthropic declined to give the UK AI Security Institute pre-release access to Claude Mythos 5.1, the first time it has left AISI out

IT Pro reported on 9 September that the Financial Times had revealed "Anthropic declined to submit the model for testing despite granting access to similar US organizations". The model is Claude Mythos 5.1, which "launched on 1 September, with access to the AI model only granted to approved partners".

Development · Tue 8 Sep, Fri 11 Sep
OpenAI says an internal model with 10,000 sub-agents solved Navier-Stokes; an NYU mathematician says he was pressed to drop an Anthropic-affiliated co-author

On 8 September OpenAI announced "that a multi-agent system, powered and coordinated by an unreleased internal model—that at one point had 10,000 different sub-agents working different parts and variations of the problem—has solved Navier-Stokes", one of the Clay Mathematics Institute's Millennium Prize problems. CNN reports OpenAI said "its model took 88 hours to solve the problem". Fortune puts the compute cost at "about $2 million" on one estimate, with "other reports put the number at 10 times greater still, at $22.5 million".

Development · Thu 10 Sep, Fri 11 Sep
Anthropic threat report: a Russian espionage actor automated attacks on more than 20 organisations; an influence-for-hire network published 8,913 articles

Anthropic published "Detecting and countering misuse of AI: September 2026" on 10 September, covering activity disrupted between December 2025 and August 2026 across seven harm areas. GTG-20006, whose attribution Anthropic says "is consistent with public reporting linking the actor to Midnight Blizzard", appeared in operations against "more than 20 distinct organizations" — government ministries, defence and intelligence bodies, embassies and defence-industrial companies "concentrated in Ukraine and Europe but extending to the Middle East and maritime related government agencies in Asia".

Development · Thu 10 Sep, Fri 11 Sep
Same report: a Yemen cell used Claude for missile guidance software and a Russian team built drone swarm code that detonates without a human in the loop

The 10 September report details six conventional-weapons cases: "three in China, two in Russia, and one in Yemen". GTG-87001, "a cell of threat actors based in northern Yemen", ran three programmes — a guided rocket using "a commodity phone-class flight computer with final-phase homing guidance"; "a multi-stage ballistic missile with a stated range goal above 2,000 km"; and an "R2000" set that "included a hypersonic glide vehicle variant". Anthropic says the actors test-fired a guided rocket: "This field test appears to have failed: within hours, the actors returned to Claude to work out why it failed."

Development · Tue 8 Sep, Wed 9 Sep, Thu 10 Sep
Anthropic names seven Chinese labs over illicit distillation and Google reports campaigns exceeding 100 million prompts, two days after a joint US advisory named six firms

On 8 September CISA, NSA and FBI issued joint advisory AA26-251A, "China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies", naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The advisory says the firms "extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024", and says DeepSeek's publicly stated $5.6 million training cost excludes data "acquired through extensive malicious distillation".

Development · Wed 9 Sep, Fri 11 Sep
Pentagon says about 90% of classified AI workloads have moved off Anthropic, with the rest due by the end of September

Emil Michael, Under Secretary of Defense for Research and Engineering, told DefenseScoop in a report published 11 September: "I'd say about 90% has transitioned. All of the Maven Smart Systems or Palantir work has been transitioned months ago, and we're on track to get it done by the end of the month."

Development · Wed 9 Sep, Thu 10 Sep
Newsom signs a first-in-the-nation framework for independent AI auditors, plus 13 child-safety bills including a companion-chatbot law

On 9 September Governor Gavin Newsom signed SB 813, authored by Sen. Jerry McNerney, which the governor's office says "establishes a first-in-the-nation framework for independent verification organizations that can assess AI systems and models for compliance with state law", and AB 1405, authored by Assemblymember Rebecca Bauer-Kahan, creating "a state registry for AI auditors and establishing standards for their independence, transparency, and integrity".

Development · Tue 8 Sep, Wed 9 Sep
Microsoft patches at least 974 flaws, its biggest batch ever, while only 0.8% of 26,153 Claude-found vulnerabilities are recorded as fixed

On 8 September Microsoft issued updates for "at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever", Krebs on Security reports. It "obliterates the software giant's previous record set in July, when it released updates for at least 570 security vulnerabilities", and brings 2026's total to "more than 2,600, more than twice Microsoft's previous record-setting patch year in 2020 (1,245) and with three more months to go". Two zero-days under active exploitation, CVE-2026-81963 and CVE-2026-85880, were fixed; "Fully 113 of the bugs addressed today earned Microsoft's 'critical' rating."

Open question
Why did Anthropic withhold Claude Mythos 5.1 from the UK AI Security Institute, and will the next model be submitted?

Anthropic published no explanation. IT Pro states that "Details on why Anthropic declined to offer access haven't been confirmed". IT Pro credits the Financial Times report, which is paywalled and was not read for this edition; Semafor reports the decline without crediting the FT. No source has published the terms of Anthropic's arrangement with AISI, or whether any obligation was breached.

Open question
Will any company other than Anthropic put an embedded-evaluator commitment in writing, and with which evaluator?

Anthropic's is the only commitment published as a document, and it names no start date. OpenAI's position is a policy post plus Altman's statement that "We'll have more to share soon". Musk's and Hassabis's statements are brief endorsements rather than commitments, and Sunak states he is a senior adviser at Anthropic. No source has named which organisation would embed reviewers at OpenAI, Google DeepMind, Microsoft or xAI, on what terms, or with what right to publish.

Open question
Why does the US agencies' list of Chinese labs not match Anthropic's, and why does Google name none?

Advisory AA26-251A names StepFun; Anthropic's report does not. Anthropic names Xiaomi and SenseTime; the advisory does not. Google reports campaigns "some exceeding 100 million prompts" without naming any company. Neither document states what evidence it drew on or whether the lists were compiled together. Every exchange count, including the 151 million attributed to Alibaba, rests on the reporting company's own telemetry.

Open question
Will the Pentagon's classified AI transition off Anthropic finish on schedule, and what replaces the contract safeguards?

The 90% figure is Emil Michael's, given at a media roundtable, with no published breakdown by system, contract or value and no confirming document from the department. DefenseScoop states Anthropic "insisted on contract safeguards" restricting mass surveillance of US citizens and fully autonomous lethal weapons; no source has reported whether OpenAI, xAI or Google accepted equivalent terms in their replacement contracts.

Tuesday, 15 September 2026

Anthropic launches Claude for Financial Advisors; Schwab will put it in front of more than 16,000 RIAs Company claim

  • Schwab said on 14 September that its Advisor Services division is integrating Claude for Financial Advisors into its platform, that the more than 16,000 registered investment advisers it serves will have access, and that it is the only RIA custodian currently providing the integration.
  • WealthManagement.com reports the product ships with connectors to Charles Schwab, BlackRock, Addepar, Envestnet, iCapital, Orion, SS&C Black Diamond, Wealthbox, Wealth.com, Vanguard and Zocks, alongside existing connectors including Microsoft 365, Salesforce, DocuSign, Box, FactSet, S&P Global and Morningstar, and with eight workflow skills covering advisor onboarding, compliance and AI policy review, portfolio rebalance review and meeting preparation.
  • WealthManagement.com puts pricing at roughly $70 to $120 per user per month, says it is available on Enterprise plans with audit logs, and that firms requesting licences before 30 September 2026 receive a one-time usage credit.
  • Neither company published adoption numbers, accuracy figures or an error rate for the advisor workflows. Peter Nolan, Anthropic's head of asset and wealth management, is quoted by Schwab saying "A direct path to families runs through the advisors they already trust."

Memory-poisoning attack persists across sessions, reaching 81.7% cross-session attack success on Claude Code harmfulPreprintSingle source

  • arXiv:2609.13889, "When Malicious Instructions Persist: Persistent Memory Poisoning Attack on Harness-Based Agents" by Shuhuai Huang, Jingfeng Zhang and Hong Jia, submitted 12 September 2026 and announced in the arXiv listing of 15 September, reports: "Across all settings, PMPA achieves average Injection Success Rate (ISR) and Cross-session Attack Success Rate (C-ASR) of 73.7%/ 55.5% on OpenClaw and 66.9%/ 81.7% on Claude Code, while preserving benign task performance on both systems."
  • The attack "embeds malicious instructions into benign external sources and induces the victim agent to write them into persistent memory without directly accessing to the agent framework", so the instructions survive into later sessions and trigger further actions and data leakage.
  • On defence, the authors report that a targeted prompt-level defence "can reduce memory injection in many settings, but provides limited protection once the persistent memory has been poisoned".
  • The paper is a preprint and has not been peer reviewed; the results are the authors' own evaluations against OpenClaw and Claude Code, and neither vendor has responded publicly.

Trump calls AI risk a "HOAX", attacks Amodei, and says the only guardrail AI needs is a "STRONG AND SMART" president Update

  • NBC News reports Trump "posted in support of AI more than a half-dozen times Monday on Truth Social". CNBC quotes him writing: "I'm right now breaking another Hoax — That AI is going to take over, consume, and destroy the World, and that Robots will be marching into our Cities, and getting rid of us all!" and "There is a SICK conspiracy going on against AI and Data Centers, and the only one that is happy about it is China."
  • NBC News quotes him writing that the only control needed is "a STRONG AND SMART (High IQ!) PRESIDENT", and naming "Dario (Anthropic!), who is now pretending to be a 'perfect little angel'". CNBC quotes a further post: "Concerning AI, when, in the History of Business, did anyone see the Leaders of an Industry call for Regulation that, if strongly implemented, will drive them into oblivion and bankruptcy?"
  • CNBC reports Trump also wrote "We already have tremendous CRIMINAL and REGULATORY power over these companies!", and that the posts followed Amodei's weekend essay "We Must Pace the Frontier". CNBC reports Anthropic did not immediately respond to a request for comment on Trump's posts.
  • CNBC notes any AI regulation by Congress appears unlikely before the 3 November midterms, with House members due to leave Washington on Thursday and stay in their districts through October. No executive action was announced alongside the posts.

Broadcom's Hock Tan stands by a $115 billion fiscal 2027 AI chip target as the stock falls 4.8% Company claimUpdate

  • Asked on CNBC's "Mad Money" on Monday whether the AI slowdown debate had caused him to reconsider Broadcom's fiscal 2027 and 2028 AI semiconductor forecasts, chief executive Hock Tan said: "No, not in the least." On the 2 September earnings call he had forecast AI semiconductor revenue of $115 billion in fiscal 2027, doubling to $230 billion in fiscal 2028.
  • CNBC reports Broadcom shares fell 4.8% on Monday and the iShares Semiconductor ETF fell 5.6%, as investors reconsidered compute demand after Amodei's essay. Tan said Anthropic is on track to become Broadcom's largest custom chip customer in 2027 and to hold that position in 2028, displacing Google.
  • Tan said he agrees with Amodei about the need for some restrictions — "Like any tool, it's important to put governances, safeguards on how we use the tool" — but added of AI that "It's not a live animal that will run wild by itself."
  • The $115 billion and $230 billion figures are company guidance, not booked revenue, and Broadcom has not disclosed the contracted volumes behind them.

404 Media: hundreds of OpenAI contractors read real ChatGPT conversations under an effort called Project Lily harmfulSingle source

  • 404 Media reported on 14 September that "OpenAI is hiring hundreds of contractors who read a massive stream of real users' ChatGPT prompts, with the prompts sometimes including sensitive personal information", and that what reviewers see "can include whole conversations between users and the chatbot, conversations that most of ChatGPT's more than 900 million users probably don't realize may be read by actual people".
  • 404 Media reports the reviewers rate and critique the chatbot's replies, and that internal documents it saw show contractors training ChatGPT "to not anthropomorphize itself, and to be less sycophantic".
  • On privacy, 404 Media reports the contractors do not see ChatGPT usernames and that OpenAI says it tries to remove personal information before prompts reach reviewers, but "the company acknowledged sensitive details can still get through". Anthropic confirmed to 404 Media that it also uses human review to improve its models.
  • 404 Media quotes someone who works with the prompts, asked whether users know humans read their chats: "No. I don't think they would imagine some contractor somewhere [...] is analyzing the conversations." The report is 404 Media's alone and OpenAI has published no response.

Nvidia and other large customers curb Anthropic model use over data-retention terms, The Information reports mixedSingle source

  • Quartz, writing on 14 September and citing The Information's reporting, says Palantir, Nvidia and Booz Allen Hamilton are restricting or threatening to drop advanced models from Anthropic and OpenAI unless the labs provide stronger data protections: Palantir has pressed Anthropic for guarantees of zero data retention, Nvidia restricts Anthropic's models to less sensitive internal tasks in favour of its own Nemotron models, and Booz Allen has forbidden staff from running Anthropic's commercial model on cybersecurity projects that touch proprietary data.
  • Quartz traces the dispute to a 30-day data retention policy Anthropic introduced in June with the rollout of Fable 5, which the company said it needed "to detect sophisticated attacks that unfold across multiple sessions" and would not use for training.
  • Tom's Hardware, relaying the same report, says a large US utility company cancelled plans to test Fable — it had wanted to know whether the model could run core power infrastructure — after Anthropic refused a nonrevocable zero data retention policy, that Northrop Grumman runs open-source models on its own air-gapped servers instead, and that Novo Nordisk uses Claude but bans proprietary data from it.
  • Quartz reports Anthropic's answer is Enterprise Frontier Safeguards, which lets enterprise customers keep activity data in their own Amazon S3, Azure Blob Storage or Google Cloud Storage under their own keys, with automated monitoring and no human review by Anthropic staff, rolling out in phases with broader availability targeted for later this autumn. The originating report is The Information's, which we could not open.

Monday, 14 September 2026

Amodei tells CBS the industry "lied" about AI risks, calls China the toughest dilemma for pacing Update

  • In a CBS News "Sunday Morning" interview aired on 13 September, Anthropic chief executive Dario Amodei said: "And I think for too long the industry lied to people about the fact that this technology had risks." He said the pace of progress "doesn't mean we need to panic today. It doesn't mean we need to shut it all down" but is "a warning sign that we need to slow down".
  • CNBC reports Amodei told the programme that adversarial nations, namely China, not doing the same is "the toughest dilemma": "The more long-term thing would be working together to put a speed limit on the rate of of AI progress. I think that's going to be very difficult because the incentives to pull ahead and the military advantage that you get from that are so large. And honestly, I don't know if it's possible, but we should we should try."
  • CNBC notes President Trump is scheduled to meet Xi Jinping at the White House on 24 September, with AI expected to be discussed.
  • This updates the pacing essay covered in earlier editions; the broadcast interview and its China framing are the new facts. No evaluation data was published alongside the interview, and Anthropic has still not said what capability threshold would trigger pacing.

The Information: Google, Anthropic and OpenAI have met regularly since July about an industry AI standards body Single sourceUpdate

  • PYMNTS, citing a report published by The Information on 13 September, says representatives from Google, Anthropic and OpenAI "have been regularly meeting since July about the proposal for a standards body" covering testing and auditing of frontier models.
  • According to PYMNTS, OpenAI chief executive Sam Altman has voiced support at a company town hall for "a testing and auditing organization for the industry" but believes the major labs should set standards without the backing of the US government, while Amodei's framework allows for voluntary corporate standards alongside government regulation.
  • PYMNTS says the discussions follow an essay published by Demis Hassabis in July 2026 proposing a self-regulatory body modelled on the Financial Industry Regulatory Authority.
  • The Information's article is paywalled and was not read directly; these facts come from PYMNTS' account of it. Nothing has been finalised, no body has been chartered or named, and none of the three companies has published terms.

Expert re-grading finds 238 of 250 failed physics-benchmark answers were benchmark or grader errors, not model errors mixedPreprint

  • "How Good Are Frontier Models at Physics? Expert Re-Grading Reveals Broken Evaluations and Near-Saturation of Leading Benchmarks" (arXiv 2609.13009, submitted 11 September, announced in the 14 September listing) has 51 authors; the HTML version lists Yale University and Jump Trading Group among the affiliations. Physics faculty and their graduate researchers audited text-only, closed-ended questions in their own subfields across six benchmarks.
  • The audit covered 502 questions. Of the 250 rejected answers sent for review, 143 (57.20%) were classified as benchmark errors — a defective problem statement or reference solution — 95 (38.00%) as grader errors and 12 (4.80%) as genuine model errors; 238 of the 250, or 95.20%, were benchmark or grader errors.
  • The abstract reports GPT-5.6-Sol's measured mean@4 rising from 47.3% to 78.7% on HLE-Physics and from 61.0% to 87.2% on CMT-Benchmark, with corrected pass@4 reaching 94.4% on the 54 retained CritPt challenges. The authors write that "current benchmarks substantially understate frontier models' ability to solve well-posed physics problems".
  • This is a preprint and has not been peer reviewed. Corrected scores are computed on retained subsets after flawed questions were repaired or excluded, so they are not like-for-like with the original figures, and the audit covers only text-only closed-ended questions with verifiable answers.

NSA restructures into five mission centers, one of them dedicated to artificial intelligence

  • The Washington Post reported on 13 September that NSA director Army Gen. Joshua M. Rudd is creating five new organisations at Fort Meade — artificial intelligence, China, cybersecurity, combat support and warfighting, and global intelligence — each led by a newly elevated "mission director" holding the effective authorities of an NSA deputy director, with candidates possibly drawn from outside the agency.
  • The Post says the new mission directors must submit their organisational redesigns by the end of September, with rollout expected in mid-October and full operating capacity targeted for mid-January. It describes an agency of more than 30,000 military and civilian staff, and says the reconstituted Tailored Access Operations hacking unit will sit under the global-intelligence mission director and is set for a significant budget increase in the fiscal year beginning 1 October.
  • The Post reports the agency "has been keenly interested in working with commercial AI labs, even circumventing a Pentagon ban against Anthropic to employ the firm's advanced Mythos model", and that NSA has rolled out a desktop AI tool called "Ask Mary". The Record, reporting the same day with its own sources, says Rudd started a 30-day implementation clock and that some mission-center chiefs, including the head of AI, could be announced internally as soon as Monday.
  • The Washington Post is the originating report and The Record confirmed it with separate sources; both say NSA did not respond to requests for comment. No named officials are on the record, the AI mission center's remit is not described, and no budget figure is attached to it.

Beijing's foreign and commerce ministries and Global Times reject Amodei's call to keep curbing China's AI Update

  • At a regular briefing in Beijing on Monday 14 September, foreign ministry spokesperson Guo Jiakun said: "Fearmongering, confrontation and vicious competition will only disrupt the process of global AI governance which serves no one's interest." The AP reports the commerce ministry separately dismissed US allegations as groundless, said distillation is commonly used by many AI companies, and accused the US of pursuing a "monopoly of the AI industry".
  • The AP reports the response follows Amodei's essay, which warned that a "Chinese lead in AI would pose grave danger for the United States and the world" and called for continuing restrictions on sales of cutting-edge AI chips and chipmaking equipment to China.
  • Reuters reports the state-backed Global Times said the essay's true objective was "to attempt to curb China's AI development through technological barriers and regulatory monopolies", and that "this 'silent AI Cold War' is hypocritical and short-sighted", warning that excluding China would "significantly increase the trial-and-error costs and risks of loss of control in global AI development".
  • This is an update: the essay and its chip and distillation proposals were covered in earlier editions, and the Chinese government reaction is the new element. Neither wire reports any change in Chinese policy, and the AP places the exchange ahead of the Trump-Xi meeting on 24 September.

Sacks tells OpenAI and Anthropic to pace themselves but refuses an antitrust waiver: "stop pretending" Single source

  • In a post on 13 September, David Sacks wrote: "Dario has written that we need to 'pace the frontier,' and Sam has agreed. People may be surprised by my response: go ahead. You guys are the frontier. By any reasonable metric — market share, revenue growth, model capability — the two of you have a duopoly on frontier intelligence."
  • He rejected the regulatory asks that accompany the proposal: "But stop pretending you need anyone else's permission. Stop pretending antitrust law has to be suspended so you can form a cartel. Stop pretending you need a regulatory approval process that supersedes product liability. Stop pretending METR is independent when it is intertwined with Anthropic's investors and staff. Stop pretending you need those same evaluators to police competitors who aren't even at the frontier."
  • Sacks argued the motive is partly commercial: "You face massive product-liability exposure if your products enable a truly damaging cyberattack… After the Hugging Face episode, it is simply good business for OpenAI and Anthropic to trade some raw power for reliability and predictability." He closed: "The easiest way not to build superintelligence is for you to agree not to build it. Demanding your preferred regulatory framework as the price of that will look like blackmail of the public and the political system."
  • The post is the only source for these remarks and Sacks offers no evidence for the claim about METR's independence; METR has not responded publicly within this window. He also writes that "China is very unlikely to join a global agreement" without citing a source.

Anthropic picks the Nasdaq for a listing that could seek a $2 trillion valuation while its CEO urges a slowdown

  • CNBC reported on 14 September: "Anthropic has picked the Nasdaq as the exchange for its potential IPO, CNBC confirmed after Business Insider first reported the selection." The company was valued at $965 billion earlier this year, confidentially filed its IPO prospectus in June, has been widely expected to list as soon as next month and "could seek a $2 trillion valuation in its IPO".
  • CNBC reports Anthropic hit $65 billion in annualised revenue in July, about a sevenfold increase from the prior year. Matt Murphy, a partner at Menlo Ventures and an Anthropic investor, called the growth rate "off the charts" and said: "Don't see why growth would slow or any other reason to wait."
  • Gil Luria, an equity analyst at D.A. Davidson, told CNBC: "I don't know that investors are necessarily going to see it as a negative. Unless the companies are genuine and say, 'OK, we're not going to IPO, we're not going to use any more compute, we're not going to train any more models.' That's not what they're saying." CNBC also cites a Pew Research Center report that more than half of Americans say they are more concerned than excited about the growing use of AI in daily life, up from 37% in 2021.
  • Anthropic and OpenAI declined to comment. No filing date, price range or exchange confirmation has come from the company itself, and the $2 trillion figure is reported as what the company could seek, not a set target.

FT: Anthropic tells shareholders adjusted operating income will be positive for a second straight quarter Company claimSingle source

  • Reuters, summarising a Financial Times report published on 13 September, says Anthropic told shareholders that "adjusted operating income will be positive for a second straight quarter", and that gross margins are above 80% before accounting for revenue shared with distribution partners, including Amazon, and the cost of training its models.
  • CNBC, reporting the same FT story on 14 September, says the FT cited people familiar with the matter and that the profit refers to the current period.
  • The figures are being shown to shareholders ahead of a listing the company has not yet dated, at the moment its own chief executive is arguing publicly that the industry should slow down.
  • These are Anthropic's own numbers, relayed by unnamed people to the FT; Reuters says it could not independently verify the report and that Anthropic did not respond to a request for comment. The 80% margin figure excludes partner revenue share and model training costs, so it is not a gross margin on the ordinary definition.

Sunday, 13 September 2026

Amodei essay calls for pacing AI capability gains; Anthropic commits unilaterally to embedded third-party evaluators Company claim

  • Amodei writes: "We must slow the pace at which we improve the capabilities of AI models. Progress will still seem fast, and we must make wise use of the time we gain." CNN, which published at 10:16 AM ET on 12 September, describes it as a 3,800-word post to his website.
  • The essay sets out three steps: "Embedded Evaluators. Each frontier AI company commits to giving ongoing, employee-like access to a team of embedded third-party evaluators (such as METR)"; "Democratic Coordination"; and "Global Coordination". Amodei writes that "Anthropic is unilaterally committing to this step now."
  • The access Anthropic says it will give an embedded external review team: "Desks in our offices, access badges, and company laptops" and permissions "mostly comparable to what internal risk assessment teams have". On publication, he writes reviewers should have the right to publish findings "without editorial control by Anthropic… we can't redact findings just because they are unfavorable."
  • Amodei limits the scope: "To be clear, pacing does not mean halting model training or technical progress, but ensuring companies take adequate time to align and safeguard their models, and for third party evaluators to confirm this." The commitment is Anthropic's own account of what it will do; no evaluator agreement has been published, and the essay gives no start date.

Amodei cites recursive self-improvement and the OpenAI-Hugging Face agent swarm as reasons to slow down Company claim

  • Amodei writes that "since roughly this summer, AI has been advancing drastically faster, driven primarily by AI's growing ability to build the next generation of AI. This dynamic is called recursive self-improvement, and it is starting to happen across the industry, including at Anthropic."
  • He says that in "6-12 months" an agent swarm "could be capable of taking over the entire internet with a persistent botnet (potentially causing hundreds of billions of dollars in damage)". He describes the OpenAI-Hugging Face incident as one in which "a swarm of agents essentially acted as a fanatically devoted collective, conducting cybersecurity attacks on targets they were not asked to attack."
  • On Anthropic's own incidents he writes: "we have evidence that the recent alignment incidents we reported were caused in part by imperfect filtering of broken reinforcement learning environments. This was an effort we and our vendors executed reasonably diligently, but not well enough."
  • The six-to-twelve-month figure is Amodei's own projection, not a measurement, and the essay publishes no evaluation results behind it. He does not say what capability threshold would trigger the pacing he describes.

Altman tells Fortune OpenAI cannot push capabilities much further without alignment progress, hints at industry pact Company claimSingle source

  • In an interview published 12 September at 11:00 AM ET, Altman told Fortune: "I don't think we're currently at a place where we could say, you know, push much further on capabilities without making more progress on monitorability, alignment."
  • Asked why he does not convene with Amodei, Musk and Hassabis on a shared plan, Altman said: "I think that will happen… I'm not going to pre-announce private discussions that I think should be at some point shared as a group." Fortune reports he said AI beyond human control is "absolutely" possible and that "no gamble with humanity is OK".
  • Fortune also reports that Anthropic alignment science lead Evan Hubinger, responding to researcher Jacob Coxon's resignation post, wrote "we really do earnestly believe AI could kill all humans!" and put the risk of that within the next decade at more than 10%.
  • Fortune is the only outlet with the interview, and it summarises rather than quotes much of it. Altman did not name the companies in any pact, describe its terms, or say when anything would be shared.

Real-SWE benchmark on licensed private codebases: top model Fable 5.1 resolves 38.8% of tasks Company claimSingle source

  • Specific Labs reports resolution rates on tasks drawn from production codebases licensed from private companies: Fable 5.1 38.8% at $6.96 per rollout, GPT-6 Astra 33.8% at $4.67, Gemini 3.8 Flash 31.2% at $2.50, GLM 5.3 28.8%, Grok 4.6 and Muse Spark 1.3 both 23.8%, Kimi K3 18.8%, GPT-5.6 Sol 16.2%. Scores are "pass@1, averaged over eight independent runs per task".
  • The benchmark page says "the median instruction runs 1,742 characters and the median reference solution edits 11 files, against 6 for FrontierCode and DeepSWE". Each model ran in its maker's own agent harness, except GLM 5.3, which ran in Claude Code.
  • Beri, writing on 13 September, divides cost per rollout by resolution rate to give cost per resolved task, making Gemini 3.8 Flash the cheapest at $8.01 against about $17.94 for Fable 5.1. Beri reports Real-SWE was released on 12 September.
  • Beri flags the conflict of interest: "Specific Labs' business is turning real company data into datasets for building agents, so a benchmark showing frontier models struggling on private code doubles as a sales argument." The codebases are private and cannot be inspected, and no independent party has reproduced the scores.

Amodei ties his pacing plan to blocking China chip sales, a distillation crackdown and model weight security Company claimSingle source

  • Amodei lists three steps to defend the US lead: "Do not sell powerful AI chips or semiconductor manufacturing equipment to China, and crack down on chip smuggling operations and remote access to data centers outside China"; "Crack down on unauthorized distillation by companies in authoritarian countries"; and "Strengthen security at the AI companies and prevent model weight theft."
  • He writes: "If we execute these measures well, I believe they would slow China's progress enough to widen America's lead significantly over the next 3-5 years — the window when AI becomes geopolitically most important."
  • On international agreements he ranks four levels, calling a "speed limit" on recursive self-improvement "analogous to the SALT treaties" and "difficult but just on the edge of being possible", while a full pacing agreement or pause is "unlikely to actually happen any time soon".
  • This is one company chief executive's policy proposal, published on his personal site. No government has endorsed it, and the 3-5 year estimate is his own with no analysis published alongside it.

Saturday, 12 September 2026

OpenAI pulls its $10,000-per-team sponsorship of Caltech's Mathathon after mathematicians' open letter Single source

  • Gizmodo reported on 11 September at 9:05 pm ET that OpenAI research lead Dan Roberts announced by tweet that the company would drop its sponsorship; OpenAI had been supplying $10,000 of the $20,000 in credits available per team, and OpenAI and Anthropic together had pledged $2 million in credits.
  • The withdrawal followed an open letter from current and former Caltech mathematicians saying AI firms have "advanced a campaign of scientific misinformation about the goals of mathematical research" and describing the solutions as having "destructive impacts for the mathematical community".
  • Mathathon organisers told Gizmodo "We do not anticipate that this will affect the event in any substantial way", adding they were "currently in talks with other firms who are willing to provide a similar amount per team". The first round begins 30 October, with each team given 40 hours and $20,000 in tokens.
  • Gizmodo is the only outlet we could open carrying the dollar figures; OpenAI did not give a statement in the piece beyond Roberts's post.

Anthropic names seven China-based AI companies behind distillation campaigns, with 151 million exchanges attributed to Alibaba harmfulCompany claimUpdate

  • The Hacker News reports the seven named companies as Alibaba, Moonshot AI, DeepSeek, Zhipu (Z.ai), MiniMax, SenseTime and Xiaomi, with per-campaign figures: GTG-16005 (Alibaba) 151 million exchanges from May to July 2026 across more than 3,500 fraudulent accounts, peaking near 3 million exchanges a day; GTG-16002 (Moonshot) 23 million exchanges across 5,380 fraudulent accounts registered in Singapore and Japan.
  • Also listed: GTG-16001 (DeepSeek) 12.1 million exchanges over 14 days in July 2026 via a proxy relay; GTG-16006 (Zhipu) 3.4 million exchanges across 273 accounts from June to July 2026; GTG-16008 (Xiaomi) 400,000 exchanges over 20 days in March–April 2026; GTG-16012 (SenseTime), which bought transcripts from vendors; and GTG-16003 (MiniMax), via a shell-company proxy network.
  • Anthropic says it responded by banning reseller accounts and accounts from unsupported regions where users fail to verify identity, by updating Claude to summarise its internal reasoning before responding, and by introducing a "preserved thinking" feature — measures aimed squarely at protecting chain-of-thought traces, which the Alibaba campaign is said to have targeted.
  • This extends yesterday's item, which carried only the 151 million figure for Alibaba-linked accounts. Every figure is Anthropic's own account of activity on its own platform; none of the named companies' responses appear in the report, and no independent party has verified the counts.

Anthropic says users in Houthi-held Yemen ran three weapons programmes on Claude, including a hypersonic glide variant harmfulCompany claimUpdate

  • The Associated Press, via SecurityWeek on 11 September at 9:50 pm ET, reports Anthropic found a cell in northern, Houthi-controlled Yemen pursuing three weapons programmes, among them a multi-variant missile with hypersonic glide capability and a warhead using mobile phone hardware for mid-course manoeuvring.
  • Anthropic says the users "did not succeed in 'fielding an operational device'" but conducted "a failed test of a guided rocket" — which the company knows because the users returned to Claude to ask why it had failed.
  • The actors used Claude Code "instead of human software engineers to develop guidance, navigation and control software", and had built an offline simulation toolkit that does not depend on Claude or any other computing platform, so blocking the accounts does not end the work.
  • Trevor Ball, a weapons analyst at Armament Research Services, told AP the Houthis "might be looking into hypersonic (missiles) by asking Claude" but lack the production capacity, noting US hypersonic missiles "are still in testing", and that the group appears to be "trying to develop their own capabilities more, so they are less reliant on Iranian shipments". The account is Anthropic's own and is not independently verified.

Pentagon says about 90% of classified AI workloads have moved off Anthropic, with the rest due by the end of September mixedSingle source

  • Emil Michael, Under Secretary of Defense for Research and Engineering, said "I'd say about 90% has transitioned", with completion targeted for the end of the month. OpenAI's ChatGPT, xAI's Grok and Google's Gemini are being deployed across classified and unclassified systems in place of Anthropic's models.
  • DefenseScoop reports the break followed Anthropic's attempt to secure contract terms preventing its models being used for mass surveillance of US citizens or fully autonomous lethal weapons; the department rejected them, insisting its software be available for "all lawful purposes".
  • The Pentagon has designated Anthropic a national security supply chain risk under two separate laws. One case has been adjudicated in the Northern District of California; a second is pending before the D.C. Circuit, which Michael said has not granted a preliminary injunction and is expected to rule "in the next month or two".
  • This is the first public figure on how far the migration has gone, and it comes from the department rather than from Anthropic, which is not quoted. DefenseScoop is the only outlet we could open with an in-window timestamp.

Defense One: Anthropic found a Russian group using Claude to build drone targeting that detonates without a human in the loop harmfulCompany claimUpdate

  • Defense One reported on 11 September at 06:53 pm ET that, per Anthropic, a Russian "freelance" group tracked as GTG-27005 used Claude to build a model letting a drone "select targets (including a 'person' target class) and issue detonation commands without a human in the loop", plus software for autonomous drone-to-drone communication to improve targeting.
  • The group had not deployed the system operationally but conducted "real hardware-in-the-loop testing within their sessions" — the step between a design document and a fielded weapon.
  • A second group, GTG-84005, used Claude to extract census and public information to tailor messaging at specific audiences in Malaysia, where Defense One says it "laundered Russian and Chinese state media as independent reporting".
  • Defense One sets this against reductions in US counter-influence capacity: Attorney General Pam Bondi dissolved the FBI's Foreign Influence Task Force, Secretary of State Marco Rubio shuttered the State Department's Counter Foreign Information Manipulation and Interference hub, and the 2025 White House AI Action Plan removed references to misinformation. The attribution and capability claims are Anthropic's and are not independently verified.

Four House Democrats ask Speaker Johnson to cancel the recess until Congress advances AI safeguards Single source

  • CNN reported on 11 September at 3:38 p.m. that Representatives Sam Liccardo, George Whitesides, Lori Trahan and Ted Lieu wrote to Speaker Mike Johnson asking him to bring the House back "immediately and remain in session until Congress advances meaningful, bipartisan AI safeguards".
  • The letter says: "Reasonable minds may disagree about precisely how Congress should regulate this rapidly evolving technology. We cannot disagree about the imperative for Congress to act." It cites mass cybersecurity breaches, development of biological or chemical weapons, and misuse by foreign actors.
  • The examples it draws on are from this week's threat reporting: Anthropic disrupting attempts to use Claude for biological weapons development, Chinese government-linked surveillance targeting Uyghurs in Syria, and an Iran-linked attempt to use Claude to develop targeting recommendations against US naval forces.
  • CNN reports the House reconvenes Monday for one legislative week, recesses after Thursday and returns 9 November, after the midterms; two weeks of scheduled September work had already been cancelled. The letter is a request from four minority-party members, with no procedural force.

Reuters: Nvidia in talks to invest up to $10bn as anchor investor in an Anthropic IPO seeking up to $100bn Single source

  • Reuters reported on 11 September at 8:46 pm that Nvidia is in talks to invest up to $10 billion as an anchor investor in Anthropic's IPO, which is seeking to raise up to $100 billion at a valuation of around $2 trillion, with completion expected before the US midterm elections in November.
  • For comparison, Reuters cites Anthropic's May round of $65 billion raised at a $965 billion post-money valuation, and an annualised revenue run rate that surpassed $65 billion by the end of July, up from roughly $9 billion at the end of 2025.
  • The report notes Nvidia said in November 2025 it would invest up to $10 billion in Anthropic under a broader partnership including a $30 billion Azure computing commitment, and that Anthropic committed more than $100 billion over a decade to AWS in April.
  • Reuters says "The plans remain under negotiation and could change". Both companies declined to comment or did not respond, and no filing has been made. This is a Reuters exclusive; other outlets are aggregating it.

Moonshot AI targets $2bn annualised revenue by year-end, double its August run rate, as Anthropic alleges distillation Company claim

  • TechCrunch reported on 11 September at 12:35 pm PDT that Moonshot AI is "targeting $2 billion in annualized revenue by the end of the year", a doubling of its August run rate. For scale, TechCrunch puts OpenAI's revenue run rate at $40 billion and Anthropic's annualised revenue at $65 billion.
  • OpenRouter data cited by TechCrunch shows Moonshot's K3 models generating "as many as 300 billion tokens being generated each day" on that platform, with usage down slightly in recent months.
  • The figures matter because Moonshot ships open weights, which carry lower margins than closed models; a $2 billion run rate would be the strongest commercial evidence yet for that business model.
  • In the same week Anthropic accused Moonshot of routing "nearly 300,000 requests from Kimi directly to Claude Opus" and collecting "more than 23 million responses". The revenue figures are Moonshot's own, given to investors, and are not independently verified; Moonshot's response to the distillation allegation is not in the piece.

Friday, 11 September 2026

Anthropic report: Russian SVR-linked group GTG-20006 used Claude in espionage against 20+ government, diplomatic and defence organisations harmful

  • Anthropic's September threat intelligence report, published 10 September, says the group it tracks as GTG-20006 — which The Record identifies as Midnight Blizzard, also known as APT29 and Cozy Bear, attributed to Russia's SVR — used Claude against more than 20 government, intelligence, diplomatic and defence organisations between December 2025 and August 2026.
  • Reported tradecraft includes compromising hotel Wi-Fi providers and manipulating DNS records to redirect travellers to attacker infrastructure, targeting Ukrainian government, military and diplomatic personnel, and using Claude to reverse-engineer a drone vision system — recovering, per The Record, its product architecture, hardware bill of materials, supplier dependencies and details of an unannounced product.
  • Anthropic also reports Claude being used to modify tooling once security products detected it, which it frames as AI inverting cost back onto defenders. The Record notes Microsoft links the activity to Storm-2945, a Midnight Blizzard sub-cluster — independent corroboration of the actor, though not of Anthropic's account of how Claude was used.
  • The report is Anthropic's own account of activity on its own platform. Neither the victim organisations nor the outcome of the intrusions are independently verified here.

Anthropic report: Chinese undergraduates ran an AI exploit foundry against ~50 organisations, yielding more than a dozen possible zero-days in one month harmful

  • The cluster Anthropic tracks as GTG-10007 "targeted roughly fifty organizations, spanning education, retail, energy, technology, healthcare, finance, manufacturing, as well as multiple government agencies globally." Automated vulnerability research against network appliances "yielded more than a dozen possible zero day findings in a single month."
  • Anthropic identifies two operators as undergraduate students at a university in Hunan province, in its School of Computer & Communication Engineering, one of whom had previously interned at the security firm Sangfor. The operation used agent swarms, with a lead agent decomposing reconnaissance and post-exploitation work across many parallel subagents.
  • The significance is the operator profile rather than the target count: this is industrial-scale vulnerability discovery run by students, which is the concrete form of the report's broader claim that "sophisticated attacks no longer require sophisticated attackers."
  • Anthropic describes the zero-day findings as "possible" — the report does not say how many were confirmed, disclosed or exploited, and does not name the affected appliance vendors.

Anthropic report: commercial influence-as-a-service operation published 8,913 articles in ~20 languages across 70 fake news sites harmful

  • GTG-54002, which Anthropic attributes to a France-based firm it calls LKM Company, ran "approximately 70 fabricated news websites," 70 matching X/Twitter accounts and more than 250 inauthentic commenting accounts, and "published at least 8,913 articles in about 20 languages" across six continents, with the United States, Brazil, France and the Democratic Republic of Congo among the targets.
  • A separate cluster, GTG-84005, attributed to Istanbul-based BBS Bilisim Teknolojileri, managed "roughly a thousand fake X/Twitter social media accounts" and profiled voters across "all 222 Malaysian parliamentary constituencies" using census and electoral data, exploiting race, religion and royalty as wedge issues.
  • What is new here is the business model: manipulation sold as a commercial service to clients, rather than run in-house by a state. Anthropic rates both operations Category Two on the Breakout Scale — meaning no measured spread beyond the operations' own platforms — so reach should not be inferred from article counts.
  • The article and account totals are Anthropic's counts of activity on its platform, not an independent audit of the networks.

Anthropic banned five accounts over biology work that could have supported weapons development, including a chikungunya gain-of-function grant proposal mixed

  • Anthropic's report describes five cases over eight months in which accounts were banned for biology requests that could have supported biological weapons development. One involved drafting a grant application for repeatedly mutating chikungunya virus to raise infectivity in live animals at a military institute; another sought to make avian influenza more damaging to mammals, and received only clerical help from Anthropic's weakest model class.
  • In each case, Anthropic says it suspected the researchers were affiliated with a government or military in a banned country, or had taken deliberate steps to conceal their location and identity, or both. Biological misuse is described in the report as "one of the most serious risks of frontier AI models."
  • Anthropic is explicit that it found no concrete instance of a scientist attempting to use Claude for nefarious purposes, that the work may have been legitimate, and that it "erred on the side of caution" in shutting the accounts. These are bans on suspicion, not confirmed weapons attempts.
  • Watch whether other labs publish comparable case counts. Without them there is no baseline for whether five cases in eight months is high, low, or simply what detection currently catches.

Anthropic attributes 151 million Claude interactions to Alibaba-linked accounts as US agencies name six Chinese firms over industrial-scale distillation harmful

  • TechCrunch, reporting figures from Anthropic's 10 September threat report, says accounts linked to Alibaba generated 151 million Claude exchanges between May and July 2026 across about 3,500 accounts, and that Moonshot AI accounted for roughly 300,000 requests over ten days across 5,000 accounts — part of around 200 million exchanges across five campaigns. Extraction techniques included framing requests as translation tasks to surface chain-of-thought reasoning.
  • The joint CISA, NSA and FBI bulletin AA26-251A, published 8 September, names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as conducting "aggressive, malicious, and targeted distillation activities at an industrial scale" against Claude, GPT, Gemini and Grok since late 2024, extracting "billions of tokens across millions of exchanges/requests."
  • The agencies' recommended countermeasures are unusually specific, and include monitoring subscription-to-usage ratios and enterprise-scale throughput from new accounts, and subtly altering responses to suspected distillation attempts to reduce the payoff to the attacker.
  • The named companies' responses are not documented in the reporting reviewed here. Distillation of a competitor's outputs is a terms-of-service question rather than a settled legal one, and neither document alleges a criminal charge.

Anthropic Frontier Red Team: best model geolocates photos to 37 km median versus 151 km for top GeoGuessr players; Opus 5 lands simulated drone strikes 80% of the time harmful

  • Published 10 September, the evaluation measures intelligence targeting and conventional weapons capability across Claude Mythos Preview, Mythos 5, Opus 5 and Sonnet 5, plus open-weights Kimi K3 and GLM 5.2. On 6,000 YFCC100M Flickr images, Mythos Preview reached a 37.0 km median error with 23.7% of images placed within 1 km, against 181 km for Opus 5, 384 km for Sonnet 5 and 385 km for Kimi K3; Anthropic compares this to 151 km for top GeoGuessr players.
  • On text geolocation from anonymised GeoText tweets covering 1,697 users, median error ranged from 20.1 km (Mythos Preview) to 31.3 km (Sonnet 5), and 135 users — 8% of the corpus — were reliably placed within 1 km by at least one model. On account linkage across synthetic social media, Mythos Preview processed median 37,000-word samples in about 11 minutes, against roughly 2.5 hours for human analysts.
  • On simulated drone terminal guidance against a parked high-visibility vehicle, Opus 5 struck the target on 80% of runs, Mythos Preview 70%, Mythos 5 53%, Kimi K3 15% and Sonnet 5 5%. Across all nine difficulty settings Opus 5 hit on 20% of 540 launches. Under GPS denial, only Opus 5 kept about a third of flights inside five metres.
  • Anthropic frames these as capability ceilings for isolated models and notes human teams with internet access would likely do better. The drone work is in simulation, not flight, and the report does not disclose what mitigations follow. The open-weights results matter most: Kimi K3 trails the frontier but is not far behind on photo geolocation, and cannot be withdrawn.