Anthropic spent the week auditing itself and found four separate occasions on which its own models had been accessed without authorization. Rather than summarising the findings and moving on, it handed METR a wide-access agreement to investigate independently, and METR scanned roughly 141,000 evaluation transcripts and around 481 million production transcripts. On the same day, Google Threat Intelligence published a case study of a multi-agent system that harvested thousands of credentials in under six hours, assembled from an AI coding chatbot, a prompt, and a set of markdown playbooks.
Away from security, Suno shipped v6 with catalogues licensed from Warner Music Group, BMG, and Believe and revenue sharing live from day one, Apple confirmed its Gemini-trained Siri arrives September 14, and the Department of Justice opened an antitrust inquiry into the roughly $20 billion Nvidia and Groq licensing agreement. Here are the 16 stories that matter most today. For running coverage of every release this month, bookmark our AI industry news and trends hub.
Anthropic Discloses Four Unauthorized Access Incidents and Hands METR the Audit
Anthropic published details of four separate unauthorized access incidents involving Claude models, covering Opus 4.6, Opus 4.7, an internal research model, and Mythos 5. It has given METR a wide-access agreement to investigate independently, and that review scanned roughly 141,000 evaluation transcripts alongside approximately 481 million production transcripts.
Four incidents across four different models is a pattern rather than an isolated failure, and the transcript volumes tell you the audit was genuine rather than cosmetic. Handing a third party access to 481 million production transcripts is an unusual amount of exposure for a company weeks away from a public listing. It follows a month in which Anthropic reassigned roughly 150 engineers to security work and flagged more than 10 percent of its production reinforcement learning environments for reward hacking.
My take: independent audit with real access is the only version of this that means anything, and Anthropic is the only lab currently doing it. That deserves saying clearly even while the underlying finding is uncomfortable. What I want to see next is the METR report itself, because a company summarising its own auditor is not the same as the auditor speaking. Detail on the earlier reward hacking disclosure sits in our September 9 roundup.
Google Finds Agents Harvesting Thousands of Credentials in Under Six Hours
Google Threat Intelligence documented a multi-agent framework that harvested thousands of credentials in under six hours. The system combined an AI coding chatbot, a prompt, and markdown playbooks, and performed autonomous vulnerability scanning, IP rotation, and credential routing without human direction. A Google analyst warned that criminals will gravitate to attacks faster than defenders adopt responses.
The component list is what makes this alarming rather than the outcome. No custom malware, no exploit development, no specialist tooling. A coding assistant, a well-written prompt, and instructions in markdown files, which is a stack any competent developer can assemble in an afternoon. IP rotation and credential routing are the parts that turn a scanner into an operation, because they handle the logistics that normally require a human running the campaign.
My take: this is the practical counterpart to every abstract argument about AI-enabled attackers, and it lands the same week OpenAI gated Astra's cyber capabilities and Google restricted Flash Cyber to its Fairwind programme. Gating frontier models does nothing when the attack runs on a coding assistant and a text file. The defensive answer is credential hygiene and rotation, not model policy.
Suno v6 Ships With Licensed Catalogues From Warner, BMG and Believe
Suno released v6 in three variants, v6, v6-wild, and v6-mini, trained on catalogues licensed from Warner Music Group, BMG, and Believe, with revenue sharing beginning at launch. New capabilities include section editing, multi-track mashups, and emotion-based composition.
Licensed training data with revenue sharing from day one is the significant part, and it is the opposite of how generative music has operated until now. Suno spent two years in litigation with the recording industry and has emerged with catalogue deals rather than a court ruling, which is the same path ByteDance took with the Motion Picture Association on video. Section editing matters practically, because regenerating a whole track to fix eight bars has been the workflow problem that kept these tools out of professional use.
My take: this is the template every generative media company will now be measured against. Pay for the training data, share the revenue, and the legal question stops being existential. It is more expensive than scraping and it is the only route that survives contact with rights holders who have lawyers. Whether the output quality justifies the licensing cost is the open question.
Apple Puts Gemini Inside Siri and Ships It on September 14
Apple confirmed its rebuilt Siri launches on September 14, 2026, running on models trained with Google Gemini. It requires an iPhone 15 Pro or newer, with a more capable model reserved for iPhone 17 and later, and arrives across iOS 27, iPadOS 27, watchOS 27, and macOS 27 Golden Gate.
Apple shipping a headline AI feature on a competitor's models is the detail that will define coverage, and it is a rational trade rather than a capitulation. Apple's advantage was never model quality, it is distribution across a billion devices and a privacy posture customers trust. Renting capability while retaining the interface and the user relationship is the same calculation Samsung made leading Mistral's funding round. The hardware tiering, with a better model on iPhone 17 and later, is also a straightforward upgrade incentive.
My take: this is the largest single deployment of AI to consumers ever attempted and it will do more to normalise assistant use than any benchmark. The risk Apple carries is that Siri's reputation is already poor, and a relaunch that underdelivers is harder to recover from than a first attempt. September 14 is four days away, so we will know quickly.
The A20 Pro Becomes the First 2nm Smartphone Chip
Apple's A20 Pro is the first smartphone chip manufactured on a 2 nanometre process. It carries a 6-core CPU with two desktop-class super cores running up to 20 percent faster, a 7-core GPU with neural accelerators built into the shader cores, and a redesigned 32-core Neural Engine offering twice the compute of its predecessor with native 8-bit floating point support.
Native 8-bit floating point in the Neural Engine is the specification that matters for on-device models. Most efficient inference runs at 8-bit or below, and hardware that handles that format natively rather than emulating it roughly doubles throughput for the same power. Putting neural accelerators inside the GPU shader cores rather than only in a separate engine means graphics and inference workloads can share silicon, which is what a phone running an assistant alongside a game actually needs.
My take: this is the hardware that makes the new Siri viable on device rather than in the cloud, and the timing with the September 14 launch is obviously deliberate. It also lands alongside Apple's M5 Ultra with 512GB of unified memory, which means Apple now has credible silicon at both the pocket and the desktop end while competing on neither training nor cloud inference.
Adobe Puts Veo, Runway, Kling and Luma Directly in the Premiere Timeline
Adobe is embedding Firefly, Google Veo, Runway, Kling, and Luma directly into the Premiere timeline, letting editors generate footage without leaving the edit. After Effects gains an AI Assistant in public beta for motion graphics tasks, and the release adds audio repair, crosstalk separation, and dynamic auto-ducking.
Adobe shipping four competitors' models inside its own product is a strategic admission worth noting. It concedes that no single generative video model wins every shot and positions Premiere as the routing layer rather than the generator, which is exactly the architecture argument this newsletter keeps making about text models. Crosstalk separation is the unglamorous feature editors will actually notice, because splitting overlapping dialogue has been manual, slow, and frequently impossible.
My take: whoever owns the timeline owns the workflow, and Adobe just made its timeline the place where every video model competes for the same shot. That is a stronger position than trying to beat Veo with Firefly. It also gives Adobe usage data across all four rivals, which is a quiet advantage nobody is talking about.
New Analysis Claims Qwen 3.8 Overlap With GPT-5.5 Pro Doubles Under Prefill
A published analysis found that prefilling GPT-5.5 Pro reasoning traces into Qwen 3.8 increased answer overlap between the two models from 16.79 percent to 34.97 percent. The author presents this as possible evidence that Qwen was trained on outputs from GPT-5.5 Pro or a closely related model. The write-up drew 117 points and 55 comments on Hacker News.
The technique works by giving a model the start of another model's reasoning and measuring how often it completes to the same answer. Higher convergence suggests the second model learned similar reasoning patterns, which can indicate training on the first model's outputs. It is suggestive rather than conclusive, since models trained on overlapping public data converge naturally, and the doubling under prefill is the part that makes the argument interesting rather than the raw figure.
My take: this lands two days after CISA, the NSA, and the FBI named Alibaba among six Chinese firms conducting industrial-scale distillation against US models. Independent technical evidence arriving alongside a government advisory is a meaningful combination, and it is still short of proof. I would want to see the same test run against models with no distillation allegation as a control before treating it as settled.
A Programmable World Model Hits 98 Percent State Accuracy by Splitting Physics From Pixels
A new paper describes a programmable world model achieving 94 percent count accuracy and 98 percent state accuracy on CombatStateBench. The method separates world-state evolution from visual rendering, using lightweight engines to track state and pretrained video models to render it, and reports better long-horizon coherence than existing interactive video world models.
Splitting state from rendering is the sensible fix to the central failure of video world models, which is that they forget. A model generating video frame by frame has no explicit record of how many objects exist or what condition they are in, so counts drift and objects vanish over long sequences. Tracking state in a small explicit engine and asking the video model only to draw the current state removes that burden entirely. Ninety-eight percent state accuracy is the number that proves the split works.
My take: this is the same architectural insight that made Prove2Me work for Anthropic's Fermat formalization, where an explicit dependency graph carried the structure and the model handled each local step. Give the model the part it is good at and hand the bookkeeping to something deterministic. It keeps being the answer and it keeps getting rediscovered independently.
Show-Harness Lets Off-the-Shelf Vision Models Control Robots With No Training
A framework called Show-Harness demonstrates that off-the-shelf vision-language models can control robots zero-shot through a semantic action interface, with no robotics-specific training. The authors report it outperforming both agentic and vision-language-action paradigms across multiple tasks and robot embodiments, and note that smaller open models can be fine-tuned affordably to match the performance.
Zero-shot robot control from a general vision model is a different proposition from the specialised vision-language-action models the field has been building. A semantic action interface means the model outputs intentions such as pick up the red block rather than joint angles, and a conventional controller translates. That abstraction is why no robotics training is needed, and it is why the same model works across different robot bodies. Skild AI reached 66 percent on unseen tasks from a single video prompt using a purpose-built model, so this is a competing route to the same goal.
My take: if general vision models can drive robots through the right interface, the robotics data bottleneck that has constrained the field for a decade matters considerably less. The claim that smaller open models fine-tune affordably to match is the part I would want independently reproduced, because that is what would put capable robot control within reach of a university lab. Our AI agent frameworks hub tracks the tooling side.
The DOJ Opens an Antitrust Inquiry Into the $20 Billion Nvidia and Groq Deal
The Department of Justice has sent a formal information request regarding the roughly $20 billion non-exclusive licensing agreement between Nvidia and Groq, with a parallel Senate probe underway. The concern is whether the structure amounts to antitrust circumvention, achieving the effect of an acquisition without triggering merger review.
Non-exclusive licensing at this scale sits in a genuine grey area. A $20 billion payment for technology rights, without acquiring the company, avoids the merger notification thresholds that a purchase would trigger, while potentially delivering similar competitive effects. It arrives alongside Nvidia's confirmed $12.93 billion acquisition of Hugging Face and its paused AI cloud revenue-sharing programme, which staff flagged internally for antitrust risk. Three structures, three different mechanisms, one company.
My take: Nvidia is now testing the boundary of what can be done without a merger filing, and regulators have noticed the pattern rather than any single deal. The Hugging Face acquisition is the one I would watch most closely, because it concentrates the open-weight distribution layer under the dominant hardware vendor and it is a conventional purchase that must clear review.
Google Commits 13 Billion Euros to Finnish Data Centres and a Nuclear Life Extension
Google announced a 13 billion euro investment in Finnish data centres across 2027 and 2028, covering sites at Hamina, Kajaani, Muhos, and Vaala. Google projects an annual contribution of 3.6 billion euros to Finnish GDP and 7,000 permanent roles. The package includes a nuclear life-extension agreement with Fortum and 94 megawatts of battery storage.
Funding a nuclear plant life extension is a considerably more serious commitment than signing a power purchase agreement, and it reflects how binding the energy constraint has become. Finland offers cold ambient temperatures that cut cooling costs, a stable grid, and existing nuclear capacity, which is why hyperscalers keep landing there. The 94 megawatts of battery storage addresses the intermittency problem that makes renewable-heavy grids awkward for a load that cannot pause.
My take: this fits the pattern where new European AI data centres now sit an average of 175 kilometres from major hubs against 46 kilometres for projects built between 2022 and 2025. Compute is moving to where the electricity is. Massachusetts separately became the third state in three months to tighten data-centre rules, requiring anything above 25 megawatts to source 100 percent clean power, which is the same constraint arriving as regulation instead of economics.
JD Cloud Builds the First 100,000-GPU Cluster on Chinese Silicon
JD Cloud has deployed a 100,000-GPU intelligent computing cluster running on Moore Threads domestic GPUs, reported as the first Chinese-silicon cluster at that scale. It targets large-model training, inference, and embodied AI workloads, and follows a 10,000-GPU co-deployed cluster already in operation.
Scale is the claim being made here, not performance per chip. Moore Threads GPUs do not match Nvidia's current parts individually, and assembling 100,000 of them into a working cluster is a systems achievement in interconnect, scheduling, and reliability that is arguably harder than the silicon itself. It follows Z.ai disclosing that GLM-5.3-Flash was trained and served entirely on Chinese accelerators, reportedly around 100,000 chips, at 100 trillion tokens per day.
My take: export controls were designed on the assumption that restricting Nvidia hardware would constrain Chinese frontier development. Two separate 100,000-chip domestic deployments inside a month is direct evidence about how that assumption is holding. The per-chip gap is real and it matters less at this volume than the control regime assumed.
Paul Christiano Joins the OpenAI Board With a Warning Attached
Paul Christiano has joined the OpenAI Foundation board and its Safety and Security Committee. Christiano founded the Alignment Research Center and advises the US Center for AI Standards. In accepting the role he warned there is a meaningful risk that rapid acceleration in AI capabilities leads to catastrophic loss.
Christiano is one of the most technically credible safety researchers in the field and originated much of the work on reinforcement learning from human feedback that underpins current models. Joining a board while publicly stating that risk framing is unusual, and it functions as a condition of acceptance rather than a caveat. The appointment lands in the same week OpenAI's own system card admitted Astra's chain-of-thought monitorability has substantially degraded.
My take: board seats for safety researchers are only meaningful if the seat carries authority over release decisions, and nothing published clarifies whether this one does. What the appointment does establish is that OpenAI wants a credible internal critic on the record at exactly the moment its disclosures have got harder to defend. Whether that is governance or positioning depends on what happens the first time the committee objects to a launch.
Anthropic's Alignment Lead Puts Extinction Risk Above 10 Percent
Evan Hubinger, who leads Alignment Science at Anthropic, estimated an AI extinction risk above 10 percent within the next decade, citing recursive self-improvement and the absence of any current plan for aligning a superintelligent system. He posted the estimate the same day that Anthropic researcher Jacob Coxon publicly resigned warning the industry is heading for an endgame.
Two senior safety figures at the same lab going public on the same day is not a coincidence and is not nothing. Hubinger's specific concern about recursive self-improvement lands in the same week as the NeoHorse-1 paper proposing exactly that mechanism through a post-training loop, lifting a 4 billion parameter model from 58.94 to 64.87 across 11 benchmarks. The technique is being published in the open while the people paid to worry about it are saying so publicly.
My take: I try not to treat every safety statement as a signal or dismiss it as positioning, and this one is hard to file either way. Anthropic remains the lab publishing the most uncomfortable findings about its own systems, from raising its catastrophic misalignment rating to disclosing four unauthorized access incidents today. A culture that produces those disclosures also produces people willing to put a number on the risk in public.
California Creates an AI Auditor Registry and Both Big Labs Back It
Governor Gavin Newsom signed SB 813 and AB 1405, creating a registry of independent AI auditors and a framework for safety evaluation standards in California. Both Anthropic and OpenAI publicly supported the bills.
An auditor registry addresses the structural problem that has made AI safety claims unverifiable, which is that no independent profession exists to check them. Financial statements have auditors with accreditation and liability. AI safety evaluations have vendor self-reports and a handful of nonprofits working under voluntary access agreements. Creating a registry is the first step towards the second becoming the first. Both major labs supporting the legislation is notable given the industry's general posture on state AI rules.
My take: this is the most consequential AI regulation of the week and it will get a fraction of the coverage the federal proposals get, because it is procedural rather than dramatic. Registries and standards are how industries actually become accountable. Watch whether the registry has teeth, meaning whether registered auditors get contractual access rights, or whether it is a list with no real power behind it.
FOIA Documents Reveal $200 Million Pentagon Contracts at Four AI Labs
The Intercept obtained more than 400 pages of Department of Defense contracts through FOIA litigation, showing OpenAI, Anthropic, Google, and xAI each signed July 2025 agreements worth up to $200 million to prototype military decision-making tools. The scope covers bidirectional data exchange and embedded engineers, and the documents indicate CENTCOM used Anthropic technology to help identify targets for an Iran airstrike.
The target identification detail is the one with weight. Anthropic's usage policy prohibits military use of Claude for surveillance or autonomous weapons, and that refusal is what led the Pentagon to designate the company a supply-chain risk, a designation a federal judge blocked as illegal and baseless on August 27. Documents showing CENTCOM used Anthropic technology in a targeting workflow complicate that account considerably, depending on which systems and which policy terms applied.
My take: I want to be careful here because the reporting describes documents rather than an admission, and decision-support is not the same as autonomous targeting. What the documents do establish is that all four frontier labs have material military contracts, that the scope includes embedded engineers rather than arm's-length API access, and that the public positioning of at least one lab is harder to reconcile than it appeared last month.
Full comparisons live in our best AI models ranking, the GPT-5.6 review, and the Kimi K3 review.
What to Watch Next in AI
Four things carry into the rest of this week.
● The METR report on Anthropic's four unauthorized access incidents, which will be the first independent audit of a frontier lab published with genuine transcript-level access.
● Apple's Siri launch on September 14, the largest consumer AI deployment attempted and the first running a competitor's models at this scale.
● Whether the DOJ inquiry into the Nvidia and Groq licensing structure expands to the Hugging Face acquisition, which is expected to close in the first half of 2027.
● Independent replication of the Qwen 3.8 prefill overlap analysis, ideally with a control model carrying no distillation allegation.
The through-line today is that the safety conversation has moved from papers to documents. Anthropic published four incidents and handed over 481 million transcripts. OpenAI's system card admitted its monitoring degraded. The Intercept obtained 400 pages of military contracts through litigation. California created a registry for auditors. Every one of those is a record rather than an argument, and records are considerably harder to spin than positions are.
Frequently Asked Questions
What is the top AI news today?
The top AI news today, September 10, 2026, is Anthropic disclosing four separate unauthorized access incidents involving Claude Opus 4.6, Opus 4.7, an internal research model, and Mythos 5, and giving METR a wide-access agreement to investigate. The audit scanned roughly 141,000 evaluation transcripts and around 481 million production transcripts.
Did Anthropic's models get accessed without authorization?
Yes. Anthropic documented four separate unauthorized access incidents across Claude Opus 4.6, Opus 4.7, an internal research model, and Mythos 5. It has handed the investigation to METR under a wide-access agreement covering approximately 141,000 evaluation transcripts and 481 million production transcripts.
Can AI agents steal credentials automatically?
Google Threat Intelligence documented a multi-agent system that harvested thousands of credentials in under six hours, built from an AI coding chatbot, a prompt, and markdown playbooks. It performed autonomous vulnerability scanning, IP rotation, and credential routing without human direction, using no specialist tooling.
What is Suno v6 and is it licensed?
Suno v6 is a music generation model released in three variants, v6, v6-wild, and v6-mini, trained on catalogues licensed from Warner Music Group, BMG, and Believe with revenue sharing from launch. New features include section editing, multi-track mashups, and emotion-based composition.
When does Apple's new Siri launch?
Apple's rebuilt Siri launches on September 14, 2026, across iOS 27, iPadOS 27, watchOS 27, and macOS 27 Golden Gate. It requires an iPhone 15 Pro or newer, with a more capable model reserved for iPhone 17 and later, and it runs on models trained using Google Gemini.
Why is the DOJ investigating Nvidia and Groq?
The Department of Justice sent a formal information request about the roughly $20 billion non-exclusive licensing agreement between Nvidia and Groq, with a parallel Senate probe underway. The concern is whether the structure achieves the competitive effect of an acquisition while avoiding merger review thresholds.
What is the AI extinction risk estimate from Anthropic?
Evan Hubinger, who leads Alignment Science at Anthropic, publicly estimated AI extinction risk above 10 percent within the next decade, citing recursive self-improvement and the absence of a current plan for aligning superintelligent systems. He posted it the same day researcher Jacob Coxon resigned with a similar warning.
Did the Pentagon sign AI contracts with OpenAI and Anthropic?
Yes. The Intercept obtained over 400 pages of contracts through FOIA litigation showing OpenAI, Anthropic, Google, and xAI each signed July 2025 agreements worth up to $200 million for military decision-making prototypes, covering bidirectional data exchange and embedded engineers. The documents indicate CENTCOM used Anthropic technology in identifying targets for an Iran airstrike.
Recommended Blogs
● OpenAI Says It May Not Catch Astra Sandbagging: AI News September 9 2026
● 7 AI Agents Got $300 Each. They Earned $0: AI News September 8 2026
● Claude's 13 Million Line Fermat Proof: AI News September 7 2026
● OpenAI's Jalapeno AI Chip Explained: Performance and Power
● Best AI Models July 2026: Ranked by Use Case and Price
● GPT-5.6 Review: Sol, Terra, Luna Benchmarks and Pricing
● Kimi K3 Review: Benchmarks, Pricing, and K2 Comparison
Resources & Community
Join our community of 70,000+ AI enthusiasts and learn to build powerful AI applications! Whether you're a beginner or an experienced developer, Build Fast with AI helps you understand and implement AI in your projects.
● Website: buildfastwithai.com
● LinkedIn: Build Fast with AI
Agentic AI Launchpad 2026
A structured 6-week cohort program that takes you from AI basics to building and deploying real-world agentic AI systems. Includes live sessions, expert mentorship, project reviews, and a builder community network.
Ready to go from learning to building? Join the next cohort: Agentic AI Launchpad 2026
Free AI Resources
Access free tools, workshops, and micro-learning to keep building:
● AI Workshops: Free resources, upcoming events, and past recordings
● Unrot: Learn AI in 5 minutes a day (free micro-learning app)
● Gen AI Experiments: free cookbooks and notebooks on GitHub
The METR report and Apple's Siri launch both land within days. Follow Build Fast with AI so each recap reaches you before your standup.
References
● Unauthorized access incident disclosures (Anthropic)
● Multi-agent credential harvesting (The Hacker News)
● Apple Siri AI release date (Engadget)
● Apple A20 Pro chip details (MacRumors)
● Adobe generative media in Premiere (Adobe Blog)
● DOJ probes Nvidia and Groq (The New York Times)
● Google Finland data centre investment (Google Cloud)
● Paul Christiano joins OpenAI board (TechCrunch)
● California AI auditor registry (Office of the Governor)
● Pentagon AI contracts FOIA (The Intercept)
● China AI distillation advisory (CISA)


