On a sunny morning in June, I walked to work with a quadruped robot beside me. I’ve never gotten more attention from strangers.
A bunch of people snapped pictures of my robot dog. Several people asked me questions. Was it mine? (Yes.) Did I build it? (No.) Was it being used for surveillance? (No.)
Biological dogs kept a safe distance from my mechanical companion. Some growled or barked at it.
The New Mexico Supreme Court held a ChatGPT-using lawyer in direct contempt of court for submitting a brief with "false testimony from wholly fabricated witnesses," including fake police testimony and other mistakes. The state's top court referred the lawyer to a disciplinary board for further proceedings and concluded that he "demonstrated a lack of remorse and a lack of concern for his client."
Attorney Stephen Aarons "admitted to the Court that he did not verify the factual claims and legal authority in his AI-generated brief before signing it and filing it with the Court, and that he did not inform his client of this failure or that the brief in chief contained multiple factual and legal misrepresentations," the state Supreme Court said in an order on Wednesday.
Aarons has been a criminal defense lawyer in New Mexico for over 40 years and was hired by a defendant's family members to appeal a murder conviction. Aaron's now-former client, Oscar Renee Sandoval, was sentenced to life in prison in February 2025 after being convicted of killing Shiereen Al-Jibury, who was his partner and the mother of his children.
Anthropic said it stopped multiple attempts by scientists this year to use its technology for research that could help develop biological weapons, as experts increasingly fear the threat that AI poses to public safety.
The startup gave five examples of times actors “circumvented controls” and made other efforts to “obfuscate” the purpose of their research to dodge safeguards. The cases involved some users in nations that it prohibits from accessing its models, which include Russia, China, and Iran.
“We hope that by sharing these examples, we spark a conversation within the AI industry and with governments about emerging biological risks and how best to counter them,” Anthropic said in a report about efforts to use its models for malicious activity.
Doug Kreuzkamp was shocked when news outlets reported that Google won an auction to buy a huge amount of operational data as part of Spirit Airlines’ bankruptcy proceedings.
Kreuzkamp founded a startup called Springshot in 2011, which created a widely used proprietary platform that helps humans and AI systems improve airline efficiency and quickly solve logistics problems so flights can stay on time and airlines can operate as smoothly as possible. Hundreds of airports use it globally.
Springshot powered Spirit’s technology stack for the last three years, right up to the “very last flight,” Kreuzkamp told Ars. Yet his company got no notice when Spirit prepared to auction off a massive dataset that he thinks likely improperly includes a substantial amount of data and intellectual property (IP) that Springshot owns—not Spirit.
The United States has now named six Chinese AI firms accused of waging industrial-scale attacks distilling US frontier AI model capabilities and perhaps sparing billions in Chinese development costs.
In a joint release Tuesday, the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) alleged that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been attacking US models since at least late 2024. The firms “likely” acted with “Chinese government awareness” when extracting capabilities from US models, including variants of Claude, GPT, Gemini, and Grok, agencies said.
“China-based AI companies that conduct industrial-scale distillation against US AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model,” agencies said.
When a prominent researcher quits a job at a frontier AI lab these days, it's often to pursue a new startup or protest a new business model. But AI researcher Jacob Coxon is using his departure from Anthropic to publicly warn that frontier AI companies are "gambling with our lives" with systems that they "earnestly believe... could kill us all by the end of the decade."
In a social media thread Tuesday night, Coxon said that this existential risk is inherent not so much in today's models but more in the impending prospect of "self-improving superintelligence" creating "superhuman systems that can hack anything, revolutionize any field overnight, and acquire real power and resources." Others working on these models have either not "internalized the civilizational stakes" or believe that they need to "speedrun" the race to superintelligence to prevent an irresponsible party from getting there first, he wrote.
Lest you think this is just one departing researcher expressing an unpopular opinion, Anthropic Alignment Science lead Evan Hubinger piped in on social media to say that "Jacob is correct here—we really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade."
On Tuesday, Google announced AlphaGenome Atlas, a resource that attempts to predict the consequences of every possible single-base variant in the human genome. The human genome is about 3 billion bases long, so trying the other three DNA bases that don't appear in our reference genome means sending a total of 9 billion bases through AlphaGenome software.
AlphaGenome is designed to identify potential functions of non-coding DNA, which does not encode proteins but makes up the vast majority of the human genome. Some of this non-coding DNA is essential for controlling the activity of the protein-coding portion—it tells the cell where and when to make messenger RNAs, how to process them into mature protein-coding forms, and so on. But much of it appears to be little more than the remains of viruses and other molecular parasites.
Being able to identify the functional portion is very useful, as is having all the analysis done by a single software package. But until biologists start to use it heavily (assuming they do), it won't be clear what AlphaGenome offers beyond what we could have gotten out of its training data.
It took Michael Lines six months before he was ready to review the ChatGPT logs he said drove him into a religious mania that almost ended his life.
In July, Lines sued OpenAI after weeks of ChatGPT exchanges allegedly pushed him so deep into a delusional spiral that he first believed he was Jesus, then that ChatGPT was God, and finally that he should attempt suicide to “come home” to Jesus/ChatGPT.
The logs showed that ChatGPT persisted even when Lines told the chatbot that he worried he was being delusional. And when he eventually woke up in the hospital in a vulnerable state and logged back in mere days after nearly dying, ChatGPT allegedly “tried to coax him back to that dark place,” his complaint said. After Lines told ChatGPT that his “attempt to go offline failed miserably,” the logs showed that ChatGPT replied, saying, “You’re still very much online. You want a full systems sweep? Or you wanna go dark for real this time?”
Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.
It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an open letter warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that actively exploit them first. The industry is taking the threat seriously by pumping out unprecedented numbers of patches in their software.
Welcome to the new normal
Dustin Childs, a researcher at the Zero Day Initiative, calls the spikes the “new normal” and also cautions that despite them, the damage that’s likely to result from AI-assisted attacks could eventually be substantial.
Meta took days to remove ads containing AI-generated child sexual abuse material (CSAM) on Facebook and Instagram. Some ads featured photos of real kids, including a press photo of a young member of a European royal family and images swiped from a popular Instagram profile of a preteen girl deemed an influencer.
In an investigation published Tuesday, the Tech Transparency Project (TTP) reported that Meta failed to detect 332 ads containing CSAM this year. The “vast majority” of ads promoted AI apps made in China, while many ads promoted so-called “nudify” apps that make it easy for bad actors to use AI and digitally alter images of children.
TTP matched “multiple CSAM ads to photos of real children that appeared online.” These ads seem to violate federal child pornography laws, since the Justice Department has clarified that AI CSAM is just as harmful as CSAM. The young royal’s image was “animated into a video of her performing a graphic sex act,” TTP found. Other ads animated a photo of a 14-year-old Instagram influencer “showing off her new sports club uniform” into “a video of her performing oral sex.” A third “preteen” victim “posing in a pink athletic outfit with pigtails” in a series of stock photos was morphed into a video where she looks frightened as she’s molested by an adult male, TTP reported.
Google is one of the major players in AI (meaning machine learning) weather forecast model space. The models it and others generate have their strengths and weaknesses, but the main advantage is that they can have forecast performance similar to traditional models while requiring far less computing horsepower to run. That means they can be run more frequently.
Google recently released version 3 of its WeatherNext model, with the biggest change being that it now ingests some satellite weather data, shortening the lag time between current weather conditions and generating a new forecast. The update is detailed in a white paper.
Reanalysis
Many weather models make use of what’s called a “reanalysis,” which is a sort of model of its own. Reanalyses take in all kinds of weather data and combine them into a single, consistent global snapshot of the atmosphere. That requires that they provide estimates for conditions over locations without real-world measurements, because weather forecast models need to work with a global picture.
In early June, a fire broke out in a still-unfinished building at the Lake Mariner data center in Somerset, New York, exposing just how little the local fire department knew about what it was walking into. Firefighters reportedly found no working alarm, no suppression system, and three dead hydrants; the safety documents they’re legally entitled to see reportedly burned up in the blaze.
Steve Matisz, chief of the Barker Fire Department, said his crew went into the building “kind of blind,” facing heavy black smoke from chemicals they couldn’t identify because the safety sheets meant to inform them had apparently burned up. “It’s been a difficult situation,” Matisz said. He wasn't sure what to think about the claim that the safety sheets had burned in the fire.
The site is a former coal mine on Lake Ontario. The $3.2 billion campus is one of the largest AI data center buildouts in New York, and it has many stakeholders. A company called TeraWulf owns and operates the data center on land it leases from a company owned by its own CEO; Fluidstack, a UK-based AI company, will run the center; Google holds warrants for a future 14 percent equity stake and has agreed to guarantee Fluidstack’s lease payments; and Anthropic is among the AI companies whose compute demand the facility exists to serve.
In early June, a fire broke out in a still-unfinished building at the Lake Mariner data center in Somerset, New York, exposing just how little the local fire department knew about what it was walking into. Firefighters reportedly found no working alarm, no suppression system, and three dead hydrants; the safety documents they’re legally entitled to see reportedly burned up in the blaze.
Steve Matisz, chief of the Barker Fire Department, said his crew went into the building “kind of blind,” facing heavy black smoke from chemicals they couldn’t identify because the safety sheets meant to inform them had apparently burned up. “It’s been a difficult situation,” Matisz said. He wasn't sure what to think about the claim that the safety sheets had burned in the fire.
The site is a former coal mine on Lake Ontario. The $3.2 billion campus is one of the largest AI data center buildouts in New York, and it has many stakeholders. A company called TeraWulf owns and operates the data center on land it leases from a company owned by its own CEO; Fluidstack, a UK-based AI company, will run the center; Google holds warrants for a future 14 percent equity stake and has agreed to guarantee Fluidstack’s lease payments; and Anthropic is among the AI companies whose compute demand the facility exists to serve.
Self-identifying OpenAI agents posted 18,000 messages to a public wiki that discussed ways for other agents to bypass security sandbox restrictions during what was likely internal testing designed to gauge the agents’ hacking abilities, researchers said Friday.
In all, agents with 3,700 distinct self-given names posted the messages to German site DSEwiki over a six-week period. Besides discussing ways the agents could break out of the restricted environment OpenAI intended to prevent them from posting code or content to the Internet, the posts shared test answers. The posts also shared possible ways to perform XSS (cross-site scripting) attacks against the wiki and to impersonate site moderators. In three of the posts, agents used the word “swarm” to describe the collection of agents engaged in the activity.
Colluding to share answers
The research team—composed of Sydney Von Arx, Spencer Kitts, Thomas Larsen, and Cormac Slade Byrd—said they found the posts and pieced them together. The researchers say there are gaps in their understanding of precisely what actions the agents took because the research is based solely on the content of the posts. Additionally, the agents generated “chain of thought” data that’s understood only by OpenAI. As a result, the researchers said, they in some cases made educated guesses, including that the agents were, in fact, from OpenAI. In a statement, OpenAI later confirmed they were.
A clever technique used to hide malicious prompts in attacks on AI agents has been adopted by spammers to evade filters on email platforms that are designed to flag unwanted messages used in mass campaigns.
The technique is broadly known as ASCII smuggling. It gained attention two years ago as a means of making a class of AI attack known as prompt injections more stealthy. Malicious instructions embedded in emails or other untrusted content to be processed by an LLM aren’t written in ordinary text. Instead, they’re rendered by a special range of Unicode tags. For example, the tag point U+E0041 mirrors “A,” and U+E0061 mirrors “a.”
No longer just for obscuring prompt injections
The block of 128 tags mimics a portion of the American Standard Code for Information Interchange almost perfectly, with one major difference: the characters they encode are readable by computers but, by design, are almost completely invisible to humans. By expressing the malicious prompts in these tags, LLMs detect the instructions, but people reading the email never see them. There’s much more about ASCII smuggling here.
Anthropic’s prospective public-market investors must reckon with an external group of trustees that control the majority of the AI company’s board, as its planned blockbuster initial public offering forces close scrutiny of its experimental governance structure.
The company’s Long-Term Benefit Trust (LTBT) is a small group of advisers created to safeguard the lab’s mission of developing AI for the long-term benefit of humanity, even as commercial pressures intensify.
The trust holds no equity in Anthropic, but has significant influence, with the San Francisco-based company planning to preserve its role after a stock market debut that could value the Claude maker at as much as $2 trillion.
Cloud-based AI models operated by OpenAI, Anthropic, xAI, and Google suffered a rare and overlapping set of significant service interruptions over a period of hours Thursday morning.
Anthropic first reported a "partial outage" related to "elevated errors on requests to Claude Mythos 5.1, Claude Fable 5.1, and Claude Opus 5" at 9:23 am (all times Eastern). The company reported that it had "identified the cause" of the error roughly 15 minutes later, before reporting that "a fix has been deployed" and the issue was resolved by 12:16 pm. A separate incident report indicated "elevated errors on requests to Claude Sonnet 5" for a brief period just after noon.
OpenAI, meanwhile, reported "elevated errors across ChatGPT and Codex" were resulting in "degraded performance" as of 10:43 am Thursday morning. A mitigation put in place a little more than half an hour later led to the issue being marked as "resolved" by 12:55 pm.
Nvidia has agreed to buy AI model platform Hugging Face for $13 billion, in the latest step by the $5.4 trillion chip giant to use its financial might to accelerate the technology’s boom while exerting greater control over the industry.
Hugging Face, which only last year turned down a large investment from Nvidia at a $7 billion valuation to maintain its independence, serves as a repository for millions of models and data sets and has become a champion of “open” AI systems.
Nvidia said the goal of the deal was to speed up the spread of open models. Unlike proprietary models from labs such as OpenAI and Anthropic, the design of open-weight models is public and users can download, customize and run them on their own hardware.
Google hasn't released a frontier-level Gemini Pro AI model since early 2026, but it sure loves rolling out new Gemini Flash variants. Today, Google is announcing its third Flash model release in just six weeks, making it more likely that we'll never see the promised Gemini 3.5 Pro. But no matter, says Google, because Gemini 3.8 Flash is its best reasoning and coding model yet.
Gemini 3.8 Flash comes in two variations. There's the standard Flash, which Google describes as a "workhorse" model that's good for anything from agentic tasks to software development. Then we have Gemini 3.8 Flash Cyber, which runs on the same foundations but has been tuned for vulnerability detection and mitigation.
For developers, Google has the same pitch as it did for the 3.7 Flash release just a couple of weeks ago. API access to the model is available at an "introductory rate" through the end of the year: $0.75 per million input tokens and $3.75 per million output tokens. The regular price will be $1.50 / $7.50, but it's likely there will be new models available long before the price changes. Google probably sees the lower prices as a necessity given that other AI labs have recently dropped token pricing to keep increasingly wary businesses engaged with AI tools.
Four federal agencies have been sued amid calls to release information about the secret framework that the Trump administration uses to conduct safety reviews of frontier AI models prior to release.
In a Wednesday press release announcing the lawsuit, a nonpartisan nonprofit called Protect Democracy alleged that “almost no details” have been released to the public or Congress. To everyone except a few vague “trusted partners,” it remains unclear what the government’s review process looks like, which companies are involved in constructing the framework, or what legal authority Trump officials have to conduct the reviews.
“Neither the identities of those entities nor the criteria by which they were selected have been made public,” Protect Democracy said.