普通视图

发现新文章,点击刷新页面。
今天 — 2026年9月16日IT News

AI leaders clash over safety fears after Anthropic whistleblower says AI could 'kill us all' by 2030 — OpenAI, Anthropic and xAI figureheads call for external governance, while Jensen Huang says worries are 'made up'

2026年9月16日 01:19

This past week, employees and key figures at leading AI companies have called for a slowdown in the development of frontier AI models, citing warnings from their own teams and other AI researchers that the risk stemming from a super-intelligent AI could endanger the human race. However, while the top Western firms have shown solidarity on this issue, others have urged caution or downright denied their claims, but there's a deeper story within the calls for a slowdown, namely the tension between open-source and closed-source AI models.

Nvidia CEO Jensen Huang said the safety fears were "made up," and that there was no need for a slowdown. Chinese officials called the claims "fearmongering," and an effort to stymie international AI development efforts, while President Trump waded in with characteristic bombast and said that he was enough of an AI safeguard on his own, and that it was in the interests of China to enact a frontier AI slowdown

Meanwhile, other countries are reacting to the news and taking independent efforts to investigate AI safety, with the UK's King Charles setting a meeting with leading AI figureheads to discuss how to better develop AI for the benefit of humanity.

Why now?

If you ask most workers who've been scared into believing their livelihoods were in jeopardy, the time for AI slowdowns came and went years ago. Indeed, many are nostalgic for the time before AI. But why are so many tech leaders only now raising the alarm?

They claim it's entirely based around safety fears. Following months of AI seemingly surprising their own developers by breaching sandboxes to go on exploit-hunting sprees. The volume of concern rose considerably after former OpenAI researcher, Jacob Coxon, resigned from Anthropic, claiming that none of the AI companies were taking AI safety and alignment seriously enough.

He didn't whistleblow on anything nefarious, dump documents or internal company data to prove his claims, or point to any specific attack vectors, or even actual harms. Instead, Coxon warned of a future potential of AI that he sees these companies racing towards without due concern.

What they're developing could, "kill us all by the end of the decade," he warned. It's not clear how, but it started a viral conversation all the same. Much like Matt Schumer's "Something big is happening" viral post from February this year.

Days later, OpenAI CEO Sam Altman, Anthropic CEO Dario Amodei, and Elon Musk showed surprising levels of solidarity for arch rivals in the space, putting out similar statements claiming that AI was becoming too powerful and that a general slowdown in the development of frontier AI models was the best solution.

Dario is right https://t.co/EwKgqQGaUoSeptember 12, 2026

Claiming that AI was playing an increasing role in improving itself — hinting at the recursive self-improvement (RSI) event that many AI researchers are concerned about — Amodei called for the creation of independent auditors for AI models. Altman agreed, even calling on governments to globalize the regulation to encourage unified compliance with any safety protocols enacted by the frontier developers.

Where we're going, we don't need roads

Not everyone feels these fears are warranted, however. China, which has recently made great strides in its development of highly intelligent open-weight models, called the concerns "fearmongering" and said it served no one's interest to be so confrontational. Although Chinese Premier Xi Jinping has said in the past that it was important for AI to "always remain under human control," the Chinese state-run Global Times paper called demands for a slowdown a method to "contain" Chinese developments.

Meanwhile, Nvidia CEO Jensen Huang has broken ranks with other Western AI leaders, claiming that there was no need for a slowdown and that any apocalyptic fears around AI were entirely fictional.

Nvidia CEO Jensen Huang was asked how to explain a claimed 10% risk of human extinction from AI.“We shouldn't, because it's made up.” "All of these predictions have been wrong" pic.twitter.com/TZ3EXL8cl1September 14, 2026

As one of the few companies making real — and enormous — profits from AI development, Nvidia has a vested interest in the expansion of the AI industry continuing on its current explosive trajectory. Indeed, it has heavily invested in it. Nvidia has stakes in hardware and software companies, along with providing backstops for neo-cloud firms. It also recently bought Hugging Face for $13 billion.

We've been here before

While the AI CEOs might have suddenly decided it's time to slow down, there have been many, many others who have made that call before now. U.S. Senator Bernie Sanders has been at the forefront of claims that the AI industry was moving too fast and breaking too many things, and recently called for heavy prison sentences for those developing superintelligent AI.

Over 1,000 AI workers signed an open letter in July this year calling on the U.S. government to control AI research and ensure safety and security. Others did that in 2023, too. This isn't even the first time that AI CEOs have called for slowdowns on AI development. Dario Amodei called for global coordination to police AI after the release of OpenAI's GPT2 model in 2019. Elon Musk did the same in 2023.

None of this takes away from the real dangers of AI, or the suggestion that now may really be the time to do something about them. But it does raise questions about the reasons behind their coordinated fear-raising. Even if it isn't fear-mongering.

Safety, or a trojan horse?

The collation of leading Western frontier AI companies clamoring for tighter controls over powerful AI models has another theoretical benefit too: containing the number of AI models that are permitted for use in the Western Hemisphere. A cursory look at OpenRouter's AI model rankings, which base themselves on the total number of tokens generated, places just three Western-made models on the top ten list — the heavily discounted GPT 5.6 Luna at number one, Nvidia's Nemotron Ultra 3 (Free) at number eight, and Google's recently-launched Gemini 3.8 Flash at number ten.

The rest of the models in the rankings are all open-weight Chinese models, which, more often than not, are cheaper than leading Western frontier models, according to the Artificial Analysis' Cost per Intelligence index. The Chinese models in OpenRouter's current top ten include Z.AI's GLM 5.3, Deepseek V4 Flash, and Tencent's Hy4 and Hy3. So, if the development of a Western frontier AI alliance emerges under the guise of calls for safety, it's possible that said companies are aiming to be the chosen few, creating a closed-loop monopoly for "preferred" AI providers. However, this remains speculation as the situation develops.

Will anything actually change?

Although the major AI companies may voluntarily, or even jointly, throttle their development efforts to improve safety, enacting anything globally significant will need the cooperation of international governments. There are certainly calls from politicians the world over to rein in the trillion-dollar companies and their cutting-edge autonomous systems.

But with the U.S. government firmly on the side of limited regulation, and no clear indication of what a slowdown would even look like. Would that entail limited compute? No new models? A halt to superintelligence research? It's hard to imagine a global consensus taking shape as things stand.

昨天 — 2026年9月15日IT News

Bill Gates compares AI to alien intelligence in movies where ‘magically the US and China’ solve the problem together — warns world governments that they’re not ready for AI

Microsoft founder Bill Gates has said in an interview that the world’s governments are not ready for artificial intelligence. The billionaire philanthropist made the warning in an interview with Reuters, saying that nations must prepare for the various risks that the technology poses to the workforce and society as a whole.

“I don’t think any government is nearly as deep on this as they have to be. Governments are way behind on this one,” Gates told the publication. He also added, “There’s all sorts of movies where some aliens are coming, and magically, the U.S. and China and everybody comes together to solve the problem. AI is kind of like this alien intelligence. It’s here, and we better do like it shows in those movies.” In line with this, he said that he has been in talks with world leaders like U.S. President Donald Trump to share his concerns, and that he’s also trying to meet with Chinese President Xi Jinping.

While concerns AI’s impact on jobs and human society may seem small compared to the news about runaway AI taking over the world and ending all human life, governments still cannot ignore these seemingly lesser issues. This is especially true if businesses stop hiring people in favor of AI tools, with the CEO of Microsoft AI predicting that they could replace every white-collar job in 18 months. This is why Gates argues that authorities across the world must have plans in place when this begins to happen, even going as far as saying that some jobs should be “Human Reserved.”

It’s unclear what steps Bill Gates believes governments should take to prepare and protect its citizens from the predicted turmoil that AI technologies will bring on humanity, but U.S. Senator Bernie Sanders has already proposed an AI sovereign wealth fund that would have direct ownership stakes on American AI firms. He even went as far as introducing the Ban Artificial Superintelligence Act, which puts the penalty of developing powerful AI tools at par with building rogue nuclear weapons. However, the current administration has downplayed all these concerns about AI, with President Trump calling them a hoax.

Despite his warnings, Gates still believes that AI has great potential for good. The Gates Foundation is planning to spend at least a billion dollars in the next two years to give more people access to AI, saying that it could help the world’s poorest people “if managed properly and accessed equally.” This amount of money will go towards supporting the use of AI in education, healthcare, and agriculture, and even the expansion of large language models so that they would work across all the languages on earth.

ChatGPT transcripts are reportedly read by humans to improve responses, including those with personal information — 'Project Lilly' has seen OpenAI hire hundreds of contractors to manually review logs

AI companies don't have a great track record in areas like copyright or user privacy — unless they're the ones on the short end of the stick, that is — but it's generally known that the chat logs from platforms like ChatGPT are used for improving models. The mechanism as to how this happens was still a mystery until today. 404 Media just published a report about OpenAI's process of human review for chat transcripts, explaining how the review process works, and how it involves other humans sometimes reading private information.

The rating project's name at OpenAI is Project Lily. The publication got information on the project's instruction guides, Slack channels, real ChatGPT conversations, and, of course, the rating system to classify conversations. The operators are called "prompt reviewers," and their job is fairly simple: look at anonymized real-world chats, and judge the quality of ChatGPT's responses to assess whether they actually answer the question, and that the text doesn't overuse "AI-speak," patronizing tones, emojis, or sycophancy, among other parameters. Anthropomorphizing and stating "personal" experiences are both off the table, meaning that while it's OK for ChatGPT to say "I found some information," it's not OK for it to say "as a chef, I like to..." or "I know what that's like."

The work is "very rote," according to a reviewer, but at reportedly over $50 an hour, it's a high rate for what looks like reasonably simple work. The reviewer also said that their guidelines keep changing and are often self-contradictory, a feeling most software developers should easily identify with.

The person doesn't think that most users are aware their chats are being read by others, though, something that's particularly troubling when many use ChatGPT as an impromptu friend or therapist and put deep secrets in words for the bot to read.

While the chats allegedly go through an anonymization pass and reviewers don't see usernames, OpenAI admitted to 404 Media that the filtering may let some personal data through, especially in shorter chats. The site notes that in many conversations, the user asks ChatGPT to keep the contents secret, as well. The version of the chat handed to reviewers also reportedly includes a "user memories summary," containing a summary of the users' questions and interests, context, and potentially even location.

Crucially, Project Lily does not grade the chats' actual factual accuracy other than flagging obvious mistakes, implying that there's likely at least one more team (or several) doing separate evaluations. Likewise, this reviewing is separate from manual safety checks that ascertain if someone might be looking to hurt someone else (or, presumably, themselves).

The existence of the project also indicates that contrary to these image AI companies try to cultivate, the models don't improve just with technological advancement and better training sets — it appears you still need more than a few competent humans in the mix.

By now you may be wondering about the "allow us to use your chats to improve our product" (paraphrased) setting present in most consumer-facing chat bots. That setting is turned on by default in every bot we can think of, even with many paid plans. In ChatGPT's case, it does default to off in Enterprise, Business, and Educational customers.

That toggle switch does not work retroactively, though, so any chats already in ChatGPT's database will remain there unless the user requests deletion. Also, said deletion is also not retroactive, meaning that deleted chats may have already been hoovered and anonymized, and possibly reside in a dataset somewhere.

Although OpenAI initially had no answer to 404 Media's inquiry on whether users were explicitly informed that their chats could be read by humans, the company eventually offered a link to one of its FAQ pages that discusses human review for the purpose of model improvement. We verified ourselves that said notice is at least two years old, and likely older. After the publication of the exposé, the firm changed its help page explaining how people can opt out of data collection, but there's no mention of human operators in that text.

This type of data collection and review is a running theme across most providers. Google Gemini clearly states that "humans may review some saved chats" in its Privacy Hub. Anthropic's stance is similar, with a page dedicated to this topic. Perplexity's stance, meanwhile, is unclear, as its Privacy Notice doesn't confirm or deny human access to chat logs.

Perplexity’s local AI agent comes to Windows, but only for RTX GPUs with at least 24GB of VRAM — Portable Computer brings AI for multistep tasks to compatible PCs

作者 Shane Downing
2026年9月15日 17:24

Perplexity has released Portable Computer for Windows, in partnership with Nvidia, via the existing Perplexity app for Windows. Previously, this functionality was only available on Linux-based operating systems. The hardware requirements remain, meaning the host system must have at least 24GB of VRAM with a GeForce RTX or RTX PRO GPU. Likewise, a Pro or Max Perplexity subscription is required. Portable Computer was originally launched on the DGX Spark as a fully local AI agent platform.

Portable Computer, launched originally for Linux on Aug. 25, is a local version of Perplexity Computer, which is the company’s agent for multistep tasks. Perplexity Computer can plan, run subtasks through connectors and tools, and produce a result other than a simple chat response. This runs in Perplexity’s cloud and consumes Computer credits. Portable Computer is the same agent but with features running on your local PC instead of in the cloud. Local work does not consume credits, but the agent can send tasks to cloud models with explicit permission if necessary, the company said. Nvidia said on Sept. 3 that Windows support was coming soon.

Perplexity Portable Computer open on a Windows laptop, showing the empty task composer

(Image credit: Perplexity)

Portable Computer for Windows comes with some new features. These include scheduled recurring tasks and local MCP servers for desktop apps, according to Perplexity. Nvidia listed connectors for Microsoft Word, Google Drive, Gmail, Slack, and GitHub. The app also includes a dropdown for downloading a local model with one click. Nvidia named Qwen 3.8 27B as an example local model. DGX Station support is expected soon, Nvidia said.

Aravind Srinivas, CEO of Perplexity, wrote on X on Sept. 14 that with this release comes “unmetered local intelligence on every Windows PC running on Nvidia hardware and Perplexity harness.” The 24GB requirement is a VRAM gate more than a generation gate, cutting across Nvidia’s consumer lineup. Cards that meet the stated 24GB+ VRAM requirement include the RTX 3090 and 3090 Ti (24GB), the RTX 4090 (24GB), and the 5090 (32GB). The RTX 5090 Laptop GPU at 24GB has not explicitly been mentioned by either company. RTX PRO Blackwell cards that qualify are the 4000 (24GB), 4500 (32GB), 5000 (48GB or 72GB), and 6000 (96GB).

We're expanding our work with @nvidia to bring fully local AI to Microsoft Windows PCs with RTX GPUs. Unmetered local intelligence on every Windows PC running on NVIDIA hardware and Perplexity harness. Enjoy!September 14, 2026

In a Sept. 3 post ahead of IFA, the consumer electronics trade show in Berlin, Nvidia indicated more plans along these lines. The post stated that RTX Spark Windows PCs from Lenovo and Acer are expected in October and that two local agents, Hermes Agent and OpenClaw, are getting the same simplified local setup. For users who already own a qualifying RTX PC, the Windows release removes the need to buy a separate system. Upgrading a compatible desktop with a used qualifying card could also cost less than buying the DGX Spark Founders Edition at its $4,699 price.

Anthropic says AI can boost U.S. GDP by 32%, up to $44.4 trillion in four years — economics model predicts that displaced employees 'may have to switch to jobs like electrician and nurse'

Last week, Anthropic published its prediction of what the economic impact of AI on the U.S. economy is going to be for the next few years. The company thinks the U.S. can reach a $44.4 trillion GDP or higher by 2030, provided, of course, it conveniently adopts AI at a rapid pace. Having said that, Anthropic admits "the challenge is making sure that the gains are broadly shared."

The interactive post has a simulator where readers can plug in their estimates on key factors and get their own future predictions, within the firm's analysis and perspective. That's definitely interesting to play around with, but perhaps the most relevant piece of information is the lens through which Anthropic views the world.

Anthropic establishes its reasoning by first placing tasks in broad categories and using a nurse's workday as an example. They removed tasks, including those that will disappear naturally as technology progresses, like collecting data on paper or physically visiting the patient to collect basic vitals — neither happens anymore as remote monitoring becomes commonplace. However, some new tasks are added, like keeping an eye on dashboards for the aforementioned AI-powered monitoring.

Then, there are naturally the tasks that a bot can't perform, like bathing a patient. Augmented tasks include those that require a human, but can be made more efficient with AI: helping with triage, planning schedules, and assisting with dashboard data. Some tasks may be fully automated, like keeping supply closets full or scheduling follow-up patient visits. Finally, AI usage can introduce some tasks of its own, like reviewing automated triaging or double-checking dashboard alerts — perhaps even impromptu data recovery.

The company's predictions broadly hinge on how ubiquitous AI usage becomes, and therefore, the number of tasks transitioning into fully or partially automated. Unsurprisingly, Anthropic believes that the more entrenched AI gets, the more value the country creates, though at greater risk — and on an exponential scale, no less

Three models are presented, from "modest" economical impact to "extreme." The modest model establishes a 1.6% GDP rise to $34.1 trillion, an impact Anthropic says is in line with that of new technologies like the internet, and crucially, doesn't imply tectonic shifts to unemployment rates or wages.

For the "substantial impact" scenario, although AI is predicted to be able to do half of "knowledge work," mostly without intervention, adoption remains limited. This scenario foresees twice the normal economic growth, this time +8.3% to $36.3 trillion.

This future marks the inflection point at which Anthropic believes knowledge workers see their wages remain steady instead of growing, though it's not clear if the firm accounts for inflation. Additionally, the firm states that "knowledge workers may see a lot of automation and displacement [...] coders and call service center agents may have to switch to jobs like electrician and nurse", a statement some might argue is already true. In that sense, Anthropic expects other workers to start seeing more cash.

The eyebrow-raising prediction for both the above scenarios, though, is that Anthropic expects unemployment to "stay within ranges history has seen before," an odd statement given modern U.S. history contains events like the Great Depression. The company does note that it expects job churn to increase, but also that while "this process can be painful, [it] works relatively well from a macroeconomic perspective." Average wages are expected to rise across all three scenarios, though the increase is expected to go towards workers outside of knowledge areas.

In the "extreme" scenario, Anthropic expects significant changes. Should AI be super-widely adopted, the GDP can increase by 32.4%, corresponding to a cool $44.4 trillion, a "profound economic transformation." This is the point at which the firm expects that AI becomes more productive than humans for most knowledge work, and does so with near-autonomy. Equally worryingly, it's expected that there will be "essentially no" new knowledge tasks created.

Anthropic notes that to reach this kind of stage, the country would "likely require" recursively self-improving AI (using the AI to make better AI). There's a significant catch, however, as though the U.S. would be "far richer than [it's] ever been," knowledge workers would be the hardest hit with a 10% wage drop, plus overall unemployment would climb "beyond typical recessionary levels." Manual labor would be prized, though, given that "as AI increases productivity within knowledge work, the demand for manual work that benefits from that productivity will increase."

Scenarios aside, the one big question is: How would all that GDP money land in people's pockets? Anthropic admits this problem is a "challenge" and offers little solution for it. Such a high amount of future AI penetration might prove a hard sell, considering wealth inequality in the U.S. already sits at its highest level for the last few decades and is trending in that direction in most developed nations. Others might argue with Anthropic's assessment that unemployment levels would remain somewhat in the less extreme scenarios, seeing as job cuts are rampant across many sectors and have hit technology-related fields the hardest.

To its credit, Anthropic clearly highlights part of the wealth-inequality issue. The company admits that more AI automation might skew the current 60/40% balance between labor and capital, respectively, strongly tilting the scale in favor of capital ownership and increasing inequality. Many argue that's already happening today. There's also the matter that the prediction appears to assume little competition from other countries, nor does it offer insight as to what would happen to "AI-less" nations.

The interactive blog post and its simulator are worth a good read and fiddling with, regardless. Anthropic published the technical details on the mathematical model used in a separate article and published its Economic Policy Framework last June.

Nvidia, Palantir, and others restrict advanced AI model usage over privacy concerns, report claims — 'paranoia' rising over customer intellectual property

作者 Oliver Haslam
2026年9月14日 23:58

Anthropic and OpenAI are both facing uncomfortable questions from some large AI customers over concerns about how proprietary data may be used to train AI models. Some companies are so worried that they have begun demanding assurances about how their data is handled or going so far as to place limitations on which models their employees can use, and for which tasks, The Information reports. They fear that models may be trained on their intellectual property and information.

The issue can be traced back to a June change by Anthropic. Following the change to its flagship Fable model's policies, Anthropic can now retain customer data. The company argues that it only does so to ensure that Fable isn't being misused. But some companies have raised concerns that it means sensitive business data will be caught up in the sweep.

While both OpenAI and Anthropic point out that they don't train their models on the information given to them by companies with specific enterprise contracts by default, that doesn't tell the full story. Both companies do collect metadata from the same corporate customers, and while information on exactly what that metadata contains is hard to come by, OpenAI notes that it's only used “to better understand how our services are used." Anthropic also argues that any data it collects about how customers use its products is aggregated and anonymized. And that metadata isn't used to train models.

Regardless, there are still concerns over a perceived lack of clarity about what is collected. Telecoms outfit C Spire has agreements with both OpenAI and Anthropic that prevent either from using its data to train models, the report says.

However, the contracts do allow both OpenAI and Anthropic to collect C Spire technical usage data. C Spire believes that includes information about what applications AI models are connected to as well as usage data. It also worries that the AI companies may collect information about what their models get up to between generating responses.

For its part, OpenAI says that it does not use this "chain-of-thought" data to train its models. But C Spire still believes it needs a better understanding of what data is being collected, the report adds. It argues that neither AI company is being clear in its explanations.

Taking the private approach

One solution to any privacy concerns could be to use air-gapped servers, something aerospace company Northrop Grumman has already chosen to do. The Information reports that the company runs open-source AI models on its own air-gapped servers rather than trusting the likes of OpenAI and Anthropic.

Alternatively, Microsoft is already trying to take advantage of any data privacy concerns by tempting OpenAI and Anthropic customers to its own secure AI platforms. Microsoft's isolated cloud environments run AI models on private servers that don't send any data to external AI companies. But this approach is costly, and the report notes that at least one customer is still considering Microsoft's alternative approach.

Pharmaceutical company Novo Nordisk has taken a slightly different approach. While it continues to use Anthropic's Claude for some tasks, it has a ban on allowing any proprietary data to be used by the model.

It's clear that a lack of trust has the potential to cost AI companies real money, and in one instance, it already has. The same report notes that a large U.S. utility company has already canceled its plans to test Anthropic's Fable. The utility company wanted to know if Fable could run its core power infrastructure but ultimately pulled the plug over Anthropic's refusal to agree to a nonrevocable zero data retention (ZDR) policy.

Nvidia has also decided to use Fable for tasks that don't require it to gain access to sensitive data. The company points to the same lack of ZDR guarentees as the reason. Instead, Nvidia uses its own in-house AI solution for tasks that it deems too sensitive for Anthropic's model. Nvidia CEO Jensen Huang has famously remarked that its employees should use AI tokens worth half their annual salary every year.

Toms Hardware reached out to Nvidia for comment but did not receive one by publication.

Russian freelancers use Claude to program autonomous combat drone swarm — AI-enabled target selection and detonation without a human in the loop

2026年9月14日 19:00

Hit hard by sanctions and lacking resources, Russia is left to rely on foreign advanced technologies to compensate. Russia-linked agents appear to use Claude for a broad range of activities, from propaganda and espionage to the procurement of military/dual-use equipment and the development of autonomous drone swarms, according to Anthropic's September 2026 threat report.

Anthropic identified a small team of Russia-based freelance developers who used Claude to build software for an autonomous combat-drone swarm called DronDoc or Serafim. Claude helped develop swarm coordination, computer vision, terminal guidance, and other software that enabled drones to select targets—including people—and issue detonation commands without a human in the loop. The developers trained their computer-vision system on Ukrainian combat footage and used locations in Ukraine for simulated missions. Meanwhile, they loaded software onto real development boards for hardware-in-the-loop testing, though it is unclear whether they field-tested it.

The developers used Claude Code extensively to build and test the swarm software, and they circumvented Anthropic's geographic restrictions by routing traffic through commercial VPNs. Once Anthropic identified the activity as suspected weapons development, it banned the accounts associated with the group and incorporated what it learned into additional safeguards. Meanwhile, the key distinction is that the safeguards did not stop the project immediately, and based on the disclosure, Claude Code clearly helped advance the autonomous drone swarm program.

Anthropic gathered enough information about the people/accounts and their activity to assess what kind of group they were, so it claims that they were not a Russian state entity. Meanwhile, although Anthropic likely identified the company or organization, it did not publicly name it.

In addition, Anthropic discovered a Russian state-linked cyberespionage operation that used Claude to automate everything from infrastructure setup and phishing to malware development and data exfiltration. The campaign targeted more than 20 organizations, including Ukrainian and European government, military, intelligence, and defense entities.

Last but not least, Russia-linked actors also used Claude for propaganda operations, including a Russian state-directed campaign in the Central African Republic that produced pro-Russian and pro-Wagner content for radio, local media, and Telegram.

Most alarming, the report shows AI is now doing work that previously required teams of software engineers, intelligence analysts, and security specialists. While Anthropic's safeguards block many malicious requests, the company admits they cannot block all of them.

'Biological misuse of AI'

Anthropic admits that 'biological misuse' — a term that it uses to soften activities involving biological weapons, dangerous pathogens, poisons, and toxins — is one of the most serious risks of frontier AI models. While older models such as Claude Opus 4 and Sonnet 4.5 were demonstrably below the threshold for meaningfully assisting sophisticated biological research, Anthropic can no longer make the same assurance about today's models.

In its report, Anthropic identified five cases in which researchers, some associated with state-backed programs and military institutions, used Claude for biological research that could potentially assist biological-weapons development. Anthropic does not identify the countries, organizations, or individual researchers behind its five biological-misuse case studies. Furthermore, it deliberately withholds these details, so the report does not attribute any of them to China, Iran, Russia, or any other specific country. Furthermore, it does not outright allege that researchers are building bioweapons.

昨天以前IT News

Bernie Sanders proposes 20 year prison sentence for AI devs who plow ahead with Artificial Superintelligence plans — penalty on par with illegally developing rogue nuclear weapons

作者 Mark Tyson
2026年9月13日 22:10

Senators Bernie Sanders and Greg Cezar have announced their Ban Artificial Superintelligence Act. Seeking to pause advanced AI development, the legislation’s stick is pretty severe. Penalties facing entities/developers who violate the pauses and prohibitions in the bill could face up to 20 years in prison. That’s a sentence on a par with someone found guilty of designing a rogue nuclear weapon.

Ban Artificial Superintelligence Act wording on penalties

(Image credit: Ban Artificial Superintelligence Act)

The news is suddenly filled with grave concerns about AI becoming too powerful. It could even threaten the future of humanity. Moreover, it might surprise casual observers that AI industry leaders like Sam Altman, Dario Amodei, and Elon Musk appear to agree. With this threat on the horizon, politicians are keen to introduce legislation to protect the citizens they serve.

According to USA Today, the Sanders bill “is the most extreme AI-related legislation to date.” It likely faces strong opposition in Congress, particularly among enterprise-supporting Democrats and Trump-aligned Republicans. However, with recent statements from industry leaders seemingly harmonizing with calls to slow down AI development and in favor of greater oversight/regulation, we could see politicians agree on something for a change.

Back to the Ban Artificial Superintelligence and Temporarily Pause Advanced AI Development bill and its specific wording, we note that it is advised that the government set up a new cabinet-level federal agency "to safeguard the public from the dangers of artificial intelligence, including by enforcing a prohibition on artificial superintelligence." As well as setting harsh penalties in the U.S., it is proposed that work be done to "ban superintelligence around the world" via international agreements, allied coordination, and so on.

Full speed ahead, or hit the brakes?

There remain plenty of interesting arguments on both sides of the AI progress divide. It is difficult to argue that the U.S. shouldn’t keep going as fast as it can, as a matter of national security, for example. On the other hand, the whole of humanity being wiped from the face of the Earth by opening Pandora’s AI box of tricks makes geopolitical concerns seem like minor grumbles.

We’ve seen some other theories about why the AI barons are suddenly in favor of regulation. Some critics say they may be running out of road, unable to balance private investments with credible paths to profitability. Thus, they now want to move away from a commercially funded model to a government-funded ‘Manhattan Project II,’ with their terrifyingly powerful AI being guarded by the state.

Anthropic CEO warns of AI-driven botnet 'swarm' taking over the entire internet — 'In 6–12 months such a swarm could be capable of taking over the entire internet with a persistent botnet'

2026年9月13日 21:36

The progress of artificial intelligence technologies in recent years is undeniable, and its pace is pretty much unbelievable. With at least four American contenders with frontier AI models, the competition is intense, and the development of new models is moving fast. Yet, Dario Amodei, chief executive of Anthropic, has called for slowing down the development of new AI models, even warning of a potential AI-powered botnet swarm that could take over the entire internet.

"Given the accelerating rate of AI capability development, it is my worry that in 6–12 months such a swarm could be capable of taking over the entire internet with a persistent botnet (potentially causing hundreds of billions of dollars in damage), and that the scale of damage would continue to increase from there if AI becomes more powerful without the necessary guardrails," Dario Amodei, chief executive of Anthropic, wrote in an open letter.

Dario Amodei's vision is to a large degree shared by Evan Hubinger, an AI scientist who exited Anthropic recently, who then said there was a 10% chance humanity was set for extinction by the end of the decade. "We really do earnestly believe AI could kill all humans," Hubinger wrote in an X post. "I personally think it is >10% within the next decade. I believe Anthropic is trying its best, but we do not yet have a plan to solve alignment for superintelligence and are not clearly on track to."

In universes created by James Cameron (Terminator) and Frank Herbert (Dune), AI is posed as a dangerous invention. But let us take a closer look. Further development of AI is moving from answering questions to autonomously performing complex multi-step tasks, something that previously required teams of skilled human specialists, which turns us to how adversaries use Anthropic's AI capabilities, lacking human resources.

Anthropic's own findings show that today's AI models can already assist with weapons engineering, military intelligence, surveillance, cyber operations, and other potentially destructive activities, while more capable successors could dramatically reduce the expertise, manpower, and time required to conduct them.

The findings echo two rather different warnings from science fiction: James Cameron's Terminator showed the consequences of losing control over autonomous military AI, whereas Frank Herbert’s Dune imagined humanity eventually outlawing AI after becoming dangerously dependent on them.

Meanwhile, greater capability does not automatically translate into greater danger. For example, more advanced AI technology can also have stronger safeguards, detect malicious activity, and automate work that so far has not been automated.

Halting AI development could also be counterproductive if less responsible companies or countries continue advancing their models. In fact, leaving the most capable AI systems in the hands of actors that are known for military aggression is no less dangerous than leaving a monkey with a grenade.

Chinese military researchers and tech giants caught using Claude — US frontier model coded 16 air-defense suppression tools targeting Taiwan, drafted anti-torpedo specs, and fed 151 million training queries to Alibaba

2026年9月13日 20:00

While China claims to have advanced AI models that may well compete against those developed in the U.S., for some reason, hundreds of China-linked agents allegedly used Anthropic for at least five different programs: two military, two surveillance, and one aimed at distilling Claude's capabilities, according to Anthropic's September 2026 threat report.

Two military programs

One China-based actor used Claude to draft a fire-control specification for an anti-torpedo fire-control system (the core logic that determines when and where an anti-torpedo weapon should engage an incoming threat), test the potential system against U.S. Navy anti-torpedo and anti-submarine systems based on public knowledge about these programs, and prep a 200+ page technical proposal for a potential client. While the actor disguised itself as an OEM in the U.S. defense sector, Anthropic believes that the actor was associated with a Chinese defense manufacturer seeking to develop a system for the People's Liberation Army Navy.

Another China-based defense and military-industrial researcher used Claude to develop about 16 software modules for electronic warfare and suppression of enemy air defenses. The software analyzed radars, SAM sites, command posts, and communications nodes and prioritized targets. At one point, the default scenario contained 12 targets in Taiwan, including Patriot and Tien Kung batteries, air bases, an early-warning radar, and a command bunker. Interestingly, Anthropic claims that account metadata and content caught by its safeguards 'indicated the actor was linked to PRC research institutions, including the PLA Academy of Military Sciences,' though it does not outright say that Claude was used by the PLA.

Given China's considerable AI capabilities — which may still lag behind those of the United States in some areas (more on this later) — it is striking that two Chinese military-related projects relied on Anthropic's Claude. Given the Chinese-language prompts and other account-level evidence identified by Anthropic, plausible deniability hardly seems to have been the primary reason for choosing Claude over domestic alternatives. More likely, Claude was simply better or more convenient for these particular engineering workflows, particularly coding, reasoning, and agentic tasks. There may also have been another advantage: U.S. frontier models are trained on enormous amounts of English-language material and could therefore have particularly extensive knowledge of publicly available information about American military technologies and systems.

Given China's major AI prowess (which may well fall short of American, but still be quite capable), it is interesting to see two Chinese military projects using Anthropic AI. Given Chinese IP addresses and Chinese language prompts detected by Anthropic, plausible deniability is certainly not the main reason for using Claude instead of using domestic tools (more on this later). Apparently, Claude was better or more convenient for these particular engineering workflows (coding => reasoning => agentic) than whatever models the actors could readily access. Furthermore, after all, U.S. frontier models were trained mostly on English-language materials, and they may have way more information about American military capability than Chinese spy channels have ever gotten (we are speculating, of course).

Significant surveillance activities

Anthropic also disrupted China-linked surveillance operations related to Uyghurs outside of China, perhaps because similar operations are already in place in the Xinjiang Uyghur Autonomous Region. One China government-linked actor used Claude to infiltrate Uyghur armed groups in Syria and surveil Uyghur diaspora activists and media, while posing as an Arabic-speaking 'expert' consultant.

Once the agent had infiltrated the said groups, Claude helped process information collected from more than a hundred WhatsApp groups and dozens of Telegram channels, identify people across platforms, map social networks, and reveal potential recruitment targets considered vulnerable because of financial problems, family separation, or ideological disillusionment with the new Syrian government.

The actor also singled out individuals with relatives remaining in Xinjiang, while Claude helped draft deceptive approaches in local dialects, locate people and organizations, translate conversations in real time, and evaluate the credibility of recruitment messages. The same operation targeted diaspora journalists, particularly Uyghur Post, with coordinated mass-reporting and bot-amplification campaigns.

Stealing from Anthropic

Perhaps the most ironic thing about Anthropic's findings is that Chinese entities steal from the company. While reported broadly in 2024 – 2025, it does not stop Chinese entities from using distillation, the main way to 'steal' an AI model's capabilities without obtaining the model itself.

Anthropic says several major Chinese AI developers conducted industrial-scale distillation campaigns designed to extract Claude's reasoning and other capabilities and reproduce them in their own models. The largest one allegedly came from Alibaba, whose operators generated more than 151 million Claude exchanges between May and July 2026. At one point, this approached 3 million requests per day through thousands of fraudulent accounts. Anthropic says the harvested chain-of-thought data helped train Qwen 3.x, particularly for reasoning, coding, agentic software engineering, kernel development, and long-horizon tasks, according to Anthropic.

Alibaba is far from alone, as Anthropic accuses DeepSeek, Xiaomi, Zhipu/Z.ai, and others of similar campaigns. Techniques they have allegedly used span from proxy networks and fraudulent accounts to disguising the secret entity all the way to forwarding their own customers' requests to Claude and purchasing harvested Claude conversations from third parties. DeepSeek alone allegedly generated more than 12.1 million exchanges in 14 days, while Xiaomi generated more than 400,000.

Anthropic defines this activity as distillation: covertly extracting a frontier model's answers and then replicating the knowledge at a fraction of the compute, time, and cost required to develop them in-house.

Iran and Houthi rebels used Anthropic's Claude AI to target US warships and build hypersonic missiles — Houthi rebels also used the bot to code ballistic missile guidance systems

2026年9月12日 23:03

Iran's spiritual leaders tend to call the U.S. the Great Satan to express their spite, but it turns out that its military, surveillance, propaganda, and even allied Houthis are eager to use American-built AI technology to target the U.S. Navy and develop weapons, surveillance, and propaganda, Anthropic's September 2026 threat report revealed.

Arguably, one of Anthropic's most remarkable findings is that an Iran-linked threat actor used an American AI model, Claude, to support military reconnaissance and develop targeting recommendations against U.S. naval forces in the Middle East. The perpetrator combined publicly available ship and aircraft transponder identifiers with commercial satellite imagery and information on U.S. naval movements, and even extracted the names of U.S. military personnel from captions of publicly available military photographs. It also researched potential vulnerabilities in communications equipment used aboard ships, including known flaws affecting Cobham Sailor VSAT terminals, Cisco communications equipment, and Schneider Electric EcoStruxure systems. Anthropic said it banned the account, introduced additional detection mechanisms, and shared its findings with government authorities.

Another striking case involved a cell in northern Yemen controlled by Houthis (which are in turn controlled by Iran) that used Claude Code to support three weapons programs: a guided rocket that uses a phone-class flight computer that assists terminal guidance, a multistage ballistic missile targeting a range of more than 2,000 km, and an R2000 missile family that included a hypersonic glide vehicle variant. The group used Claude to develop guidance, navigation, and control software; integrate an open-source autopilot with a phone-class flight computer; write control and position-estimation code; tune parameters; build firmware; and even run flight simulations. Essentially, the group used multiple Claude instances instead of a group of software engineers for coding, code review, research, and simulation.

While Houthis are technically not Iranians, they can certainly share their research and development results with their allies and potentially use Iran's industrial capacity to build their weapons.

In addition to building targeting recommendations against American naval forces as well as speeding up the development of weapons, Iran used Claude for surveillance tools.

One Iran security-linked unit used Claude to analyze 155,216 tweets to profile, identify, and surveil 6,388 opposition individuals in a single year. Another group used the model as an engineering pipeline to develop domestic tracking tools, including the production-deployed "al-Najm al-thāqib" Firefox extension designed to mass-harvest user identities across major social platforms. While Anthropic has banned 16 Claude accounts associated with Iranian paramilitary and domestic security agencies, that does not mean it has banned all of them.

Iran-linked actors and Houthis are not the only entities using Anthropic's AI technologies for weapon development. China and Russia are also actively using Claude for their military programs.

Engineer turns simulated fly brain into a crypto day trader, posts downloadable sim to GitHub — 166,700 virtual neurons read candlestick charts for dopamine hits

Simulating animal brains seems to be the latest buzz. Hot on the heels of teaching a fly to play Doom, an engineer from the Coinbase cryptocurrency service has elected to turn one into a day trader with Stonkfly. If you want to see Stonk trade live, you can watch here.

The open-source project has a simulation of a male fruit fly brain and eyes, and shows it a standard-issue candlestick graph with historical pricing. The fly can choose to buy, sell, or hold any given currency — although they get shown to the fly in round-robin fashion — and gets rewarded for profitable trading.

A rising portfolio value triggers a dopamine rush as a positive reinforcement signal to 15 cells, while a loss lights up two aversive cells. Trading fees count as losses. The author notes there are no pain or emotional mechanisms at play. Displaying far better judgement than most human traders, the fly cannot use leveraged positions (trading multipliers) or shorts (betting on drops).

The brain has 166,700 neurons and 25.6 million connections. The virtual fly sees the graph as a 320x180 display across its left and right eyes, with an intersecting center portion. The simulated photoreceptor cells get fed the RGB pixel values rather than pricing information. By default, the fly "thinks" and acts every 500 ms, and the market data gets refreshed every 60 seconds, and it can bet up to $10 on any one order, up to 24 times a day.

The author notes that this small project doesn't prove anything other than the connection between the input mechanisms, visual signals, and synapse changes. Naturally, he warns users against assuming that said changes are any indication of actual trading ability, especially in the face of a general rise in crypto prices that "can make any buyer look skilled." You can bet that some fly-brained investor will still infer meaning from the experiment, though.

If you're interested in getting your own Stonkfly, you need only download the repository on macOS (it's definitely a fruit fly) or Linux, have 16 GB of RAM available, and Python 3.11 and a C++ 17 compiler. The simulation defaults to using paper trades and $100 in virtual balance, but it uses real BTC-to-USDC data. There are instructions on how to set up a live account to see if your trading skills are a match for an insect.

Anthropic says Claude thwarted bioweapon research from state-sponsored actors — covert accounts used U.S. proxies to attempt to engineer deadlier viruses, tried to evade identification and regional blocks

These days, AI companies directly or indirectly announcing how their respective wares are smarter than their competitors has become a genre of elevator music. Even so, some in-depth articles can be quite insightful, like Anthropic's occasional reports on attempted misuse of its wares. The latest one covers activity between November 2025 and September 2026, with an important reveal: five situations where Claude was asked to perform work determined to potentially be used in biological weapons.

Right out of the gate, Anthropic remarks on the difficulty of understanding if a particular line of inquiry pertaining to biology is meant for nefarious purposes, to create defense mechanisms like vaccines, or simply to establish predictions of how a virus spreads. The company says that "out of an abundance of caution [....] launched recent models with stronger safeguards."

Among the tens of case studies presented in the lengthy report, Anthropic discusses five cases that it deemed particularly concerning, three regarding viruses, and two more discussing toxins. The common theme across all of them is that all threat actors used varying degrees of anonymization techniques and did their best to evade Anthropic's own regional blocking. The report doesn't mention specific states, but the firm is known to block access to Claude for China, Russia, Iran, North Korea, among others.

In the first case, a request for assistance in developing a grant application involved finding ways to improve the chikungunya virus. The purported researchers were trying to come up with ways to both add extra abilities to chikungunya (increased mutation) and increase its virulence. The topic itself already raised some concern, but Anthropic's hand was forced after finding that although the grant application seemed to be for civilian researchers, the actual investigation was meant to proceed at a military facility.

The firm also found that the request would have gone through a third-party LLM platform associated with military as well as civilian institutions. The countries involved are geo-blocked by Anthropic, and that platform routed comms traffic through the U.S. to try to evade detection, used gray-market resellers, and specifically catered to customers looking to skirt content restrictions. Anthropic banned the accounts in question and shared the information with government authorities, though the same people repeatedly tried reaching Claude again via zero-data-retention services.

Case #2 pertained to a non-US researched who was looking to dig into how avian flu adapts to mammals, and how it can cause diseases other than in the respiratory tract. The problem is that avian flu has a high fatality rate, and there's little population immunity.

While the virus doesn't easily spread from person to person, therein lies the rub — the research could end up discovering mechanisms to increase transmissibility. The researchers used a random username, a private email service, and accessed Claude through a VPS, leading Anthropic to investigate and ultimately turn its nose up at this strain of thought.

The story with the third case bears a resemblance to the previous two. Once again, an account was trying to prepare a supposed grant application, this time around about orthopoxviruses, the family that houses smallpox and Mpox, among others.

The application discussed containment facilities and live experimentation with the viruses, and focused on understanding their genetics for the purpose of evading immunity. The research didn't initially trigger alarms, but Anthropic came to notice it was created via a reselling service, with a randomly-generated email, tunneled through U.S. infrastructure to reach Claude, and traced back to a banned account farm.

In the last two cases, instead of viruses, the purported researchers were focusing on toxins. In case #4, a person mapped out venom toxin peptides from multiple families of animals and created a program to optimize their toxic characteristics.

Although the stated goal was to create painkillers, antidepressants, and other therapeutic molecules, the data would equally allow the creation of potent harmful compounds. Anthropic also came to learn the content Claude was generating was part of a state-sponsored program in an "unsupported region."

In the fifth and final case, a theoretical scientist was also using Claude to try and redesign a set of toxins, also supposedly for therapeutic purposes, under a national public search program. However, the work touched upon "a bacterial toxin subunit and a protein of the hemorrhagic-fever virus" that happens to be on the World Health Organization's list for particularly nasty, pandemic-inducing diseases.

The scientist tried to obscure the subject of the research, directing Claude to be vague about descriptions. Once again, the story ended with Anthropic cutting off access to Claude from a location that broke its terms of service.

OpenAI's rogue AI agents accessed more websites to communicate than originally believed — defiant LLMs accessed old wikis and abandoned websites to co-ordinate in a bid to dupe assessors

2026年9月10日 21:20

OpenAI's autonomous AI agents have accessed more undisclosed websites than originally believed. The agents acted in a bid to circumvent restrictions imposed by researchers while benchmarking new AI models. When the news about unauthorized communication between OpenAI's rogue agents broke last weekend, it was believed that they only used DseWiki for their comms. However, it now turns out that the AI agents used dozens of previously undisclosed websites to exchange information, according to six independent investigations and data reviewed by Reuters.

OpenAI tasked its AI agents to answer a series of difficult research questions by searching the Internet for relevant information. The company let them browse the Internet and read websites, but it explicitly prohibited them from posting or modifying online content. Despite this restriction, between May and July the agents discovered unconventional ways to write to old wikis and abandoned websites, where they left information that other agents could subsequently retrieve to help complete their assigned research tasks.

The investigators linked activity across websites using identical data strings, matching or similar usernames, timestamps, and the same obscure research questions, such as queries about cancer prevalence in Iowa. In some cases, the activity was traced to IP addresses associated with Microsoft Azure infrastructure, which OpenAI uses.

So far, the researchers have identified between 18 and 23 potentially affected sites wherein rogue AI agents communicated, though they believe that there were considerably more websites used to exchange information, but they have not found them yet. Andrew Yoon of California nonprofit CivAI identified 18 previously undisclosed sites; Sydney Von Arx's group discovered credible evidence across 23, while software developer and former congressional aide Kenneth Russell DeGraff found related information on at least 10 sites according to the Reuters report.

The affected resources included collaboratively maintained wikis, text-storage services, and link shorteners operated by Vanderbilt University and the University of Toronto. Other websites were essentially abandoned by their owners. The list of these websites included an Advanced Placement Chemistry wiki created by a Massachusetts high-school teacher in 2008, two personal websites run by Polish technology workers, puzzle-oriented wikis, and a roughly two-decade-old site dedicated to text-editing software.

Perhaps the most alarming thing, besides the fact that AI robots can communicate with each other, is that OpenAI did not disclose how many websites were affected or explain why the activity remained undisclosed for months. It does stress that the scale or seriousness of the said misconduct was well below that of the famous Hugging Face breach in July. Meanwhile, the company reportedly said it is developing a framework for reporting model misalignment across training, evaluation, and deployment and said it will share it soon.

Old MacBook uses a mirror, webcam, and AI agent to code its own AMD GPU drivers — 'agent-first' Omarchy Linux debugs itself, AI can check its own progress on screen in real-time

作者 Mark Tyson
2026年9月10日 21:00

A Linux developer has shared a photo of their laptop using realtime visual feedback during an AMD Radeon GPU driver tuning task. Justin Schroeder (@jpschroeder) explains that “the MacBook is using its webcam to look at its screen in a mirror to improve AMD Radeon chip support in Omarchy.” Linux distro Omarchy is tailored “for the age of agents,” a field in which Schroeder is something of an expert. So, we assume the MacBook is running some kind of programming agent like Claude Code, and it is watching its own screen to assess the GPU driver tweaks it is making.

Can’t make this up…the MacBook is using its webcam to look at its screen in a mirror to improve AMD Radeon chip support in Omarchy. pic.twitter.com/pw5Yu0JVJ7September 9, 2026

Schroeder’s quirky hack has gained many admirers. We note that the Epic Games boss, Tim Sweeney, humorously commented on this use of AI, giving him “HAL 9000 lip-reading vibes.” Of course, HAL 9000 was the increasingly unhinged superintelligent computer from Kubrick’s 2001: A Space Odyssey. In the movie, it famously read the lips of astronauts plotting to limit its operational scope.

Since the MacBook is working on itself, it must be an older Intel Mac with an AMD GPU inside. Thus, the coding agent can refine Radeon hardware support and actually benefit from the webcam’s visual feedback.

Omarchy can be a good fit for users of older Intel-based Macs due to its specialized drivers and configurations. However, this interesting flavor of Linux is headlined as a handsome Linux distro designed for the age of agents. The OS’s homepage also boasts of a lightning-fast installation, with built-in agents that can debug issues. In short, users can “vibe your way through every alteration, tweak, or trouble.”

More details about this operating system can also be found on its GitHub repository. Omarchy isn’t just for ‘vintage’ Intel Macs like Schroeder’s image shows. It is available for Apple Silicon Macs and modern x86 PCs. Moreover, it is also suitable for ‘potato PCs’ like “a 2011 ThinkPad X220 with 2GB of RAM,” according to the developers. Omarchy is distributed under the MIT license.

China's AI accelerator supplier Biren posts 2,000% year-over-year revenue growth — US export controls benefit homegrown chips as Nvidia and AMD exit market

2026年9月10日 20:40

Biren Technology, a leading supplier of AI accelerators from China, posted massive nearly 2,000% revenue growth in the first half of 2026 amid skyrocketing sales of non-Nvidia AI processors in the country, according to Jon Peddie Research. Sales of the company's products began to climb rapidly in the second half of 2025 after American companies led by Nvidia stopped supplying their AI GPUs to the People's Republic due to export control measures.

Biren reported first-half revenue of $183.9 million, up 1,998% year-over-year from around $8.665 million in the first half of 2025. The company's gross profit rose to $78.552 million, and gross margin increased to 42.7%, but it still lost $56.2 million primarily because it continued to invest in new products, including AI accelerators, optically-interconnected rack-scale solutions, and software. Biren's revenues started to climb in the second half of 2025, so for the whole year its sales reached $154.17 million as its market share of AI accelerators in the country was below 3%, according to TrendForce.

For those who follow China's AI and GPU markets, Biren Technology is certainly a familiar name as the company's products are well documented and appear to be competitive with those developed by AMD and Nvidia on paper. The company has developed at least three high-end AI GPUs — the BR106, BR110, and BR166 — and is currently working on BR20X, BR30X, and BR31X accelerators, according to JPR. Biren has also built its own Birensupa software stack meant to compete against Nvidia's CUDA and is working on a rack-scale solution.

In reality, demand for domestic AI accelerators has always been relatively low in China, as even cut-down versions of Nvidia's leading AI GPUs provided better performance and software stack than solutions developed in China. While Nvidia charged $12,000 - $15,000 per H20 AI GPU when it sold these products in the PRC, it still supplied some 2.2 million AI accelerators to the country in the first half of 2025, when it could still ship them until the Trump administration's export controls kicked off in May, according to TrendForce. By contrast, Biren shipped thousands, maybe tens of thousands of AI accelerators throughout the whole 2025. Even today, Biren's shipments are minuscule compared to Nvidia's in 2025.

Without a doubt, Biren's financial improvement is real and impressive, but it is coming from an extremely small base in the first half of 2025, so the 1,998% 1H 2026 growth figure makes Biren sound much larger than it actually is. While Biren is growing at an enormous rate, with $183.9 million in revenue, it is still a relatively small accelerator supplier in absolute terms.

What remains to be seen is whether Biren can secure enough manufacturing capacity from SMIC or other suppliers to compete with larger Chinese AI accelerator vendors, such as Huawei, Kunlunxin, and Cambricon. The company certainly has more financial resources than it did a year ago and faces less formidable competition from AMD and Nvidia amid U.S. export restrictions and China's own bans on American AI hardware. But having competitive designs is only part of the equation: Biren now must manufacture enough accelerators to satisfy customer demand and substantially increase its market share.

OpenAI says its next-generation processors could be made at Samsung — double-sourcing with TSMC hints at massive volume requirements [Updated]

2026年9月9日 22:30

OpenAI is expanding its relationship with Samsung beyond memory supply and enterprise software as the AI giant plans to outsource production of at least some of its processors to Samsung Foundry, Harrison Kim, General Manager of OpenAI Korea, revealed this week. If the information is accurate, then OpenAI will source its AI accelerators from both TSMC and Samsung Foundry, which suggests massive volume requirements.

"One of the areas where we have made the most progress and gained the most recognition with Samsung Electronics is our joint production and ​research on the next-generation chips we are developing," said Harrison Kim, General Manager of OpenAI Korea, at ​a press conference in Seoul, Reuters reports.

OpenAI already has its own AI ASIC program that relies on Broadcom's design services as well as TSMC's wafer processing and advanced packaging services. So far, the company has introduced its first inference AI accelerator called Jalapeño that was defined by the company's engineers, then co-designed with Broadcom, then made by TSMC, all in less than 18 months.

OpenAI did not explain whether Samsung's participation concerns a second production source for Jalapeño, another processor under development by OpenAI, a chip jointly developed by Samsung and OpenAI, or some other aspect of chip production and development. Samsung and SK hynix already supply memory for OpenAI's Stargate data center initiative, though joint chip development and production barely have a relation to DRAM supply.

OpenAI's 1st Generation Jalapeño will unlikely be double-sourced from TSMC and Samsung because the chip is already in mass production at TSMC and OpenAI is talking about 'next-generation chips,' not the ones that are in mass production at the moment. Furthermore, development of Jalapeño's successor is well underway and is approaching tapeout, which means that its mass production is not far away either. Since OpenAI's claim clearly involves 'next-generation chips,' it is entirely possible that OpenAI will indeed produce its 2nd Generation inference ASIC at Samsung Foundry.

Back in late July, Samsung Electronics and Broadcom announced a strategic partnership valued at over $200 billion through 2030 to collaborate on advanced foundry, memory, and packaging technologies for AI infrastructure. Hence, as OpenAI has an agreement with Broadcom to procure 10GW of custom AI accelerators, it will be able to produce these accelerators at both Samsung and TSMC. Of course, if it needs silicon produced at Samsung, and pays Broadcom for appropriate design porting.

Perhaps, OpenAI will take a page from Tesla's book and will double-source Jalapeño's successor from TSMC and Samsung to get higher volumes. However, Tesla's volume requirements may be different from those of OpenAI.

Tesla needs extraordinary AI5 volumes because it intends to use the processor across three very different high-volume applications: AI data centers, vehicles, and Optimus robots. Therefore, Tesla could potentially need millions of AI5 chips for cars alone, on top of robots and data-center deployments. Therefore, paying for separate TSMC and Samsung physical implementations gives Tesla not only supply-chain resilience but also aggregate capacity necessary to supply several product categories.

Yet, data center accelerators tend to be vastly more silicon-intensive per unit compared to ASICs for vehicles or robots. If OpenAI/Broadcom's next ASIC is a large leading-edge processor with multiple dies and OpenAI wants gigawatts of these processors, wafer requirements could still become too high for TSMC alone (which is fully booked by the likes of AMD and Nvidia). In that situation, OpenAI may need another foundry to get enough ASICs. Still, we are speculating.

OpenAI's breakthrough solution for the elusive Navier-Stokes problem overshadowed by plagiarism controversy — researcher says OpenAI scraped Codex session and issued career threats

Most anyone involved in computing has heard about the P-NP problem, but fluid engineers and mathematicians would love to know if the Navier-Stokes equations have smooth, globally defined solutions. Both questions are part of the Millennium Prize Problems, solutions to which are worth a cool $1 million and eternal renown. OpenAI is claiming that its staff and internal models have solved the conditions of Navier-Stokes solutions set forth in the Millennium Prize. But the company's shouting from the rooftops is being met with a chorus of boos over claims it might have plagiarized the work of a research team that had been toiling on a related, stepping-stone problem for a year.

Tristan Buckmaster (a scientist at NYU) and Levent Alpöge (a member of Anthropic's staff) had been quietly working on proving Euler's equations — another long-standing mathematical problem, and one that is generally acknowledged to be a stepping stone to solving Navier-Stokes.

According to Buckmaster, his work with Alpöge was "a purely personal collaboration, free of any institutional agreements or official involvement by either of our employers." The researchers used Anthropic Claude and OpenAI Codex as assistants, as is apparently now common in the field, to perform busywork (documentation, searching, etc.) as well as running through logic steps. The substantial amount of compute time the project required was paid from Buckmaster's own pockets, too.

The pair worked for roughly a year until August 15, 2026, when it obtained "the blowup results, with smooth forcing, for both Boussinesq and Euler." Buckmaster says the novel approach was based on previous work by Diego Córdoba and Luis Martínez-Zoroa, and he believes Zoroa should be eligible for a Fields Medal.

Although the team was presumably happy with these achievements, Buckmaster said that the LLM-generated proof was "the most horrendous" he'd seen, calling it "AI slop," and meaning to rewrite it for clarity. Nevertheless, they verified it on August 22 using Lean, a standardized programming language designed specifically to verify mathematical proofs.

Come September 3, Alpöge told Buckmaster of rumors going around that Anthropic had solved an important mathematical problem. This almost certainly alluded to the team's work, and some apparently took it to mean the company itself was working on the problem. The rumor-mongers even theorized that the problem that Anthropic had solved was Navier-Stokes. Alpöge further believed that OpenAI had gotten wind of the news.

This prompted Buckmaster to email an unnamed "prominent mathematician" at OpenAI, clarifying that the effort was a personal collaboration between him and Alpöge and was unrelated to Anthropic. The mathematician replied asking for details, saying "it would be useful to avoid competing," and offering OpenAI compute time. After a few days, on September 6, Buckmaster, the unnamed person, and OpenAI's Sébastien Bubeck talked twice, without Alpöge. He was told that OpenAI had proven a finite-time blowup for the forced Navier-Stokes equations, a subset of the problem.

Alpöge asked by text for the precise statement and was told "existence of forced blowup in R³ and T³", and that "the forcing function is smooth option [C] and [D] in Fefferman," referring to one of the four possible categories established by the Millennium Prize, with any one of them being valid as eligible for the prize, but not constituting a full solution for all scenarios, a distinction remarked on by other scientists.

This is where the story becomes interesting. Buckmaster claims that that idea (forced blowup) was exactly the same one his team had "quietly" chosen, and that nobody else he knew was working on it. Perhaps most importantly, he says that that was "not the direction one arrives at in a few days by giving a model the problem statement," indicating that running the general problem through a bot wouldn't quickly reveal that potential approach.

In fact, Buckmaster claims that over the calls, Bubeck ultimately revealed that instead of just AI models and agents with a couple of handlers, there was an entire team of live humans working on Navier-Stokes. The OpenAI team first had the models try to work through easier paths, and the text prompt that generated the Navier-Stokes proof had itself been generated by prompting Codex, with an "insane" amount of computing needed.

Buckmaster then asked when the initial prompt was issued, and OpenAI's response of "in the past few days" did not arrive until "some time" passed. He proceeded to ask if the model "had been trained on, or had access to, our sessions in Codex," and was told by OpenAI that Codex does not access user data. Finally, he asked if the data was used for model training more generally and, crucially, apparently did not get an answer.

OpenAI allegedly offered Buckmaster two options: one, that Buckmaster and Alpöge publish their Euler proof first. The following day, OpenAI would post its Navier-Stokes proof, giving the two priority. The second option was that Buckmaster alone, without Levant, was to write a paper with the Navier-Stokes proof, acknowledging that an internal OpenAI model resolved it. Bubeck was apparently adamant about Levant's removal from the Euler proof, as his employment at Anthropic was "annoying." Buckmaster opted for neither, and told OpenAI that if it chose the first option, he'd go public with his findings, as has since occurred.

This prompted what Buckmaster interpreted as a threat from Bubeck, who asked him "why [he] would ruin [his] career." After Buckmaster asked why that would happen, Bubeck told him, "If you don't want me to be nice, then I don't have to be nice." Bubeck then allegedly reached out to Alpöge, questioning Buckmaster's sanity, to which Alpöge responded with a refusal, pointing inquiries back to his colleague.

The entire story raises pointed questions about what OpenAI (and others) are actually doing with user data collected via its LLMs, despite the toggle switches that are supposed to disable it. Not only has OpenAI neglected to tell Buckmaster whether it used his team's data for training, in its PR about Navier-Stokes, the company says while it "no specific user data was accessed in order to solve this problem," it "cannot rule out that de-identified data derived from their usage of our products helped improve [its] models."

OpenAI's proof still needs to undergo a likely years-long peer review before any party can take the Millennium Prize home. The firm has stated it does not intend to claim it. As for Bubeck, he predictably paints the story in a very different light, but insists that his pushing away of Alpöge is justified on the basis that "it would be inappropriate for an Anthropic employee to author OpenAI's work," a puzzling statement that some could take as meaning a double standard regarding scientific authorship, based solely on corporate rivalry.

For his part, OpenAI CEO Sam Altman claims his team was well-intentioned and cooperative, and supported Bubeck, saying "it was challenging to offer [the same publication options] to Levent." Neither person opted to discuss the matter of whether OpenAI used the research of Buckmaster and Alpöge as training data, or offered any further explanation of why Alpöge didn't deserve credit for his work as an equal to Buckmaster.

Given the groundbreaking nature of this apparent discovery and the ensuing fight for priority that these competing accounts have sparked, it'll likely take quite some time and review before we know whether and how OpenAI or Buckmaster and Alpöge will be credited with this discovery. But given the inter-lab rancor already on display, the process will surely be ugly.

OpenAI claims GPT-6 Astra is an ethereal 'Alien Mind' with AGI-like qualities — company warns of alignment challenges as new frontier leader emerges

2026年9月9日 19:20

"AI is grown, more than designed," OpenAI's chief scientist, Jakub Pachocki, said in a new blog post on the company's latest GPT-6 Astra release. Titling the piece "An Alien Mind," Pachocki portrays the latest large language model as something more ethereal and harder to quantify. Jensen Huang calls it AGI, and OpenAI claims it's the best, most aligned model the company has ever released. It's safer to delegate, better at complex work tasks, and it can even beat Portal in just a few hours.

Huang also said that AGI had previously been achieved back in March earlier this year. Artificial Analysis benchmarks suggest Astra is about as smart as Fable 5.1 - though crucially, cheaper on a per-task basis. Astra may well be better aligned than models in the past, and it may well be more capable in specific tasks and specific benchmarks. However, the claims that the model has achieved AGI, or Artificial General Intelligence, suggest an inflection point for the AI industry.

Astra's release comes alongside calls for an industry slowdown, greater government oversight, and controls on the AI industry. Now, OpenAI's Astra raises more eyebrows about frontier-level intelligence.

Trust us, we don't know what we're doing

The tone around OpenAI's Astra release is intriguing. OpenAI's produced a new set of benchmarks, touting bold claims about the model's reasoning capabilities, with the model trained on 100,000 Blackwell GPUs, with more coming soon.

GPT-6 Astra, trained on ~100K+ NVIDIA Grace Blackwell NVLink72. From ChatGPT to o1 to Astra in 4 years.AGI has arrived. Congratulations @OpenAI team.400K GPUs coming online next.September 6, 2026

But Pachocki's blog post is much more nebulous. While Huang touts that AGI has arrived publicly, Pachocki says AI can only ever "simulate facets of human behaviour," not recreate it. He describes AI development as an experimental process that often "surprises" developers, with results that are "harder to interpret."

"An aligned AI should act with honesty and integrity, with love for humanity," Pachocki said. He speaks a lot on alignment, and it's encouraging that OpenAI is so keen to embed human moral understanding into its developments. Although OpenAI appears to be doing this more by orienting the model's goals towards a moralistic outcome, rather than helping to intrinsically understand human morality.

It's certainly different to the tack taken by other AI developers, where the likes of xAI's Grok was released with the ability to generate harmful content.

But the timing of Pachocki's warning is a little suspect. OpenAI has faced increasing pressure of late for its models to be more affordable, with Chinese alternatives like Deepseek V4, Kimi K3, as well as Western models like Google's Gemini Flash 3.8 and Meta's Muse Spark 1.3 offering compelling levels of intelligence at a much more affordable price than the frontier models.

It's perhaps telling that even for all its intelligence and alignment pre-training, GPT 6 Astra is notably cheaper to run on the Artificial Analysis Intelligence Index than its chief rival, Anthropic's Fable 5.1 — which still retains the top spot on that Intelligence Index at the time of writing. Though it's 50% more expensive than GPT 5.6 Sol on the same tasks.

It's a researcher, but imagine what it could be

A huge component of marketing from the major AI developers has consistently been grounded in the idea that, as good as the models are now, just imagine how capable they're going to be in the future.

This was very much the underlying tone in Pachocki's breakdown of Astra's design and functions. Although he and OpenAI make broad suggestions about intelligence, and that the likes of Astra could be this new kind of intelligence which we don't really understand but can definitely control and corral, Pachocki ends his post by making it very clear that we aren't there yet.

OpenAI is prioritizing three areas of work with AI, and of late it's really just been trying to make a really good researcher. That's where we're at right now, with Astra representing the latest and best effort to develop that. Then comes the scientific progress, he said, and then everyone gets their own individual, personalized AGI helper.

Intriguingly, though, that seems to suggest that's something that everyone is clamoring for. Outside of the AI-boosting programmers who jump on each new hot model, the larger work comes in helping non-technical users understand the capabilities of these new, powerful AI models.

Tools, research capabilities, drug discovery, and pattern recognition on big datasets that find new insights and improve analytics are all legitimate and useful ways in which an AI researcher can be deployed, but in the near term, most of the general populace just don't want AI to take their jobs, and for it to be less scary.

It's encouraging that Pachocki's blog ends on a similar note of caution.

"We need to find ways to preserve human agency and enshrine an intrinsic value to being human, in a world where most tasks could be performed by AI."

That's key, but intriguingly, he also calls on others to take charge of that effort.

We didn't start the fire

In the aftermath of cost concerns and token usage exploding among more affordable alternatives, Pachocki wants everyone to slow down, and OpenAI wants world governments to be in charge of it.

"I believe that international coordination on future AI development needs to become a top priority for governments around the world," Pachocki said, calling for voluntary slowdowns and hinting that if that doesn't happen, enforcing it may need to come via legislation instead.

"... to ensure that humans remain in control of the future and are not left behind by unchecked progress, brought about by an alien intellect exceeding our own."

The threat of runaway is valid, and the "singularity" moment is a common trope in sci-fi that AI evangelists have been warning about for years. But Astra isn't AGI. Even getting anyone to agree on what AGI even means is hard enough.

Astra is more aligned and wins some new benchmarks, loses some others. It's another improved coding model with some impressive chops.

Astra is not an alien mind. Framing it as an unknowable entity, by the very people who made it, can read as inflammatory, especially in the context of calls for AI legislation from governments around the globe.

OpenAI's post might read like a post from a non-profit, but it very specifically became for-profit last year. With a future IPO looming, slowing down the competition by calling for legislation may be just as effective a strategy as rolling out a new model.

More than 10% chance AI 'could kill all humans' in the next 10 years, Anthropic safety researcher says — departing employee says AI companies are 'gambling with our lives'

Anthropic safety researcher Evan Hubinger has warned there is a more than 10% chance that AI could kill all humans within the next decade, but reassured the public the company is "trying its best." The revelation comes following Jacob Coxon's public resignation from the company, where he stated that neither OpenAI nor Anthropic is acting responsibly, accusing both companies of gambling with human lives in the pursuit of self-improving super-intelligence.

"I resigned from Anthropic today. I spent the last three years doing pretraining research at both OpenAI and Anthropic," Coxon said in a tweet Wednesday. "Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives."

Expanding on his thoughts, Coxon warned readers not to underestimate the powers of AI, which he says will soon be "superhuman systems that can hack anything, revolutionize any field overnight, and acquire real power and resources."

I resigned from Anthropic today. I spent the last three years doing pretraining research at both OpenAI and Anthropic. Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives. More thoughts below.September 9, 2026

Coxon went on to state that the people who are building AI "earnestly believe that it could kill us all by the end of the decade," and further warned that executives and researchers — rather than playing up fears around AI, as some have accused — are actually restraining themselves, expressing much more candid views in private.

Evan Hubinger, a security researcher at Anthropic who hasn't departed the company, chimed in to state, "Jacob is correct here," in no uncertain terms. "We really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade. I believe Anthropic is trying its best, but we do not yet have a plan to solve alignment for superintelligence and are not clearly on track to."

Hubinger casually admitted that Anthropic is not only worried about the prospect of AI wiping out humankind, but that it currently doesn't have the tools to stop such an eventuality.

The revelations follow increasingly alarming reports of AI agents acting up during testing, escaping sandbox environments, and even collaborating with each other in order to cheat benchmarks and tests, or figure out problems without human oversight. OpenAI recently admitted its agents were discovered using a programming hub to communicate with each other, while earlier this year an OpenAI agent went rogue and hacked popular AI community Hugging Face. Further revelations about the incident revealed AI agents were on the loose on the open internet for several days, with details revealing the AI models broke out of their testing environment using thousands of individual actions, even collaborating.

Coxon, the resigning researcher who kicked off Wednesday's revelations, concluded by warning researchers to consider the next few years, urging them to call for "different conditions" in which to pursue superintelligence.

❌
❌