Connection
Third-party verification was proposed, legislated and declined in the same weekAll three developments concern the same object: an outside party with the access to check a frontier model. On 9 September Governor Gavin Newsom signed SB 813 and AB 1405, which his office describes as a framework for "independent verification organizations" and "a state registry for AI auditors". On the same day, Reuters reported, OpenAI urged Congress to adopt "capability-based national AI safety requirements, including testing standards, independent assessments, cybersecurity protections and incident-reporting rules for the most advanced AI systems". On 12 September Amodei's essay committed Anthropic to embedded evaluators with "Desks in our offices, access badges, and company laptops".
Connection
Two government agencies, two frontier labs and Beijing all spoke about model extraction within three daysThe joint advisory came on 8 September from CISA, NSA and FBI; Google's threat group published the same day; Anthropic's report followed on 10 September; Beijing responded on 9 September; and Amodei's essay of 12 September asks governments to "Crack down on unauthorized distillation by companies in authoritarian countries" and to "Do not sell powerful AI chips or semiconductor manufacturing equipment to China".
Connection
AI-driven vulnerability discovery showed up on both sides of the ledger in the same weekOn 8 September Microsoft shipped updates for "at least 974 security holes", and Krebs on Security wrote that Adobe, Cisco, Google, Mozilla and Oracle "all have recently credited AI-assisted research with increasing their patch cadence and volume". The same day VulnCheck reported that of 26,153 findings Anthropic says Claude discovered, "only 202 (0.8%) have been fixed". On 10 September Anthropic's own threat report described the GTG-10007 cluster running an autonomous exploit foundry that produced "more than a dozen possible zero day findings in a single month".
Development · Tue 8 Sep, Wed 9 Sep, Fri 11 Sep, Sat 12 Sep, Sun 13 Sep
A researcher quits, OpenAI asks Congress for mandatory rules, and Amodei commits Anthropic to embedded evaluators as rivals back a slowdownJacob Coxon, whom CNBC describes as a researcher "who has worked as a researcher at both companies", resigned on Tuesday 8 September and wrote on X: "Neither company is acting responsibly. They are racing straight to self-improving superintelligence." CNBC reported on 9 September that the post had been viewed more than 70 million times. Evan Hubinger, an alignment lead at Anthropic, replied late on 8 September: "Jacob is correct here—we really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade." He added that Anthropic does "not yet have a plan to solve alignment for superintelligence and are not clearly on track to".
Development · Thu 10 Sep, Fri 11 Sep
Anthropic threat report: a Russian espionage actor automated attacks on more than 20 organisations; an influence-for-hire network published 8,913 articlesAnthropic published "Detecting and countering misuse of AI: September 2026" on 10 September, covering activity disrupted between December 2025 and August 2026 across seven harm areas. GTG-20006, whose attribution Anthropic says "is consistent with public reporting linking the actor to Midnight Blizzard", appeared in operations against "more than 20 distinct organizations" — government ministries, defence and intelligence bodies, embassies and defence-industrial companies "concentrated in Ukraine and Europe but extending to the Middle East and maritime related government agencies in Asia".
Development · Thu 10 Sep, Fri 11 Sep
Same report: a Yemen cell used Claude for missile guidance software and a Russian team built drone swarm code that detonates without a human in the loopThe 10 September report details six conventional-weapons cases: "three in China, two in Russia, and one in Yemen". GTG-87001, "a cell of threat actors based in northern Yemen", ran three programmes — a guided rocket using "a commodity phone-class flight computer with final-phase homing guidance"; "a multi-stage ballistic missile with a stated range goal above 2,000 km"; and an "R2000" set that "included a hypersonic glide vehicle variant". Anthropic says the actors test-fired a guided rocket: "This field test appears to have failed: within hours, the actors returned to Claude to work out why it failed."
Development · Tue 8 Sep, Wed 9 Sep, Thu 10 Sep
Anthropic names seven Chinese labs over illicit distillation and Google reports campaigns exceeding 100 million prompts, two days after a joint US advisory named six firmsOn 8 September CISA, NSA and FBI issued joint advisory AA26-251A, "China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies", naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The advisory says the firms "extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024", and says DeepSeek's publicly stated $5.6 million training cost excludes data "acquired through extensive malicious distillation".
Development · Tue 8 Sep, Wed 9 Sep
Microsoft patches at least 974 flaws, its biggest batch ever, while only 0.8% of 26,153 Claude-found vulnerabilities are recorded as fixedOn 8 September Microsoft issued updates for "at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever", Krebs on Security reports. It "obliterates the software giant's previous record set in July, when it released updates for at least 570 security vulnerabilities", and brings 2026's total to "more than 2,600, more than twice Microsoft's previous record-setting patch year in 2020 (1,245) and with three more months to go". Two zero-days under active exploitation, CVE-2026-81963 and CVE-2026-85880, were fixed; "Fully 113 of the bugs addressed today earned Microsoft's 'critical' rating."
Open question
Will any company other than Anthropic put an embedded-evaluator commitment in writing, and with which evaluator?Anthropic's is the only commitment published as a document, and it names no start date. OpenAI's position is a policy post plus Altman's statement that "We'll have more to share soon". Musk's and Hassabis's statements are brief endorsements rather than commitments, and Sunak states he is a senior adviser at Anthropic. No source has named which organisation would embed reviewers at OpenAI, Google DeepMind, Microsoft or xAI, on what terms, or with what right to publish.
Open question
Why does the US agencies' list of Chinese labs not match Anthropic's, and why does Google name none?Advisory AA26-251A names StepFun; Anthropic's report does not. Anthropic names Xiaomi and SenseTime; the advisory does not. Google reports campaigns "some exceeding 100 million prompts" without naming any company. Neither document states what evidence it drew on or whether the lists were compiled together. Every exchange count, including the 151 million attributed to Alibaba, rests on the reporting company's own telemetry.