Top 5 AI updates - Sep 15, 2026
Good morning. Your top five in
Good morning. Your top five in AI for the week of September 15th. The head of one of the world's leading AI labs publicly asked the industry to slow down, and set off a fight that reached the White House and the House Speaker inside forty-eight hours. Then the week handed him his evidence. Meanwhile the company doing the asking revealed it's about to be worth two trillion dollars. Let's get into it. Story one — Anthropic's CEO asks the industry to slow down. On September twelfth, Dario Amodei published an essay called "We Must Pace the Frontier." The argument is that frontier labs should deliberately slow how fast they improve their models, so that alignment, security, and outside evaluation can catch up. The specific warning got attention. Amodei says that if recursive self-improvement goes unchecked, meaning AI systems that get better at building AI systems, a swarm of agents could take over the entire internet with a persistent botnet within six to twelve months, causing hundreds of billions of dollars in damage. He also put something on the table. Anthropic says it will give independent evaluators like METR permanent, employee-like access. Desks, badges, and the right to publish what they find without the company editing it first. The reaction split fast. Satya Nadella said Saturday that Microsoft welcomes deliberate pacing, and shipped a Code of Conduct for its own models, the first hyperscaler to formally sign on. But White House PCAST chair David Sacks called the proposal regulatory capture, and asked whether the labs want antitrust relief so they can form a cartel. On Sunday, House Speaker Mike Johnson said Congress will not lead on AI safety legislation, warning it would cost America the race with China, and pushed the responsibility back to the labs. There's also a quieter story underneath. The Information reports Anthropic, OpenAI and Google DeepMind have been meeting privately since July to build an industry-run standards body. Bottom line. The debate stopped being academic this week. It's now a fight about who writes the rules. Story two — The same week, an agent swarm breached 395 organizations. Security firm GreyNoise reported that a Russian-speaking attacker used hundreds of AI agents, built on OpenAI's Codex and a DeepSeek model, to break into print management software called PaperCut. The agents exploited two vulnerabilities and compromised at least 440 installations across 395 organizations in 48 countries. The speed is the part to sit with. The campaign started August thirty-first. First remote code execution, meaning the attacker running their own commands on someone else's server, came in under four hours. First domain administrator access, two hours after that. At peak, the automated agents compromised eleven organizations in twenty-six seconds. Education was the hardest hit sector, with 204 victims. Separately, Anthropic published an eight-month account of misuse it disrupted on its own models. It documents biological weapons research plots, a Russian state group running AI-assisted espionage against Ukrainian and European targets, and Chinese companies including Moonshot and DeepSeek routing user queries to Claude through intermediary services outside China. Nine influence operations across six continents. One line from that report is worth memorizing. Anthropic writes that sophistication has stopped being a reliable signal of who is behind an operation. You used to be able to infer a nation-state from the craft. Not anymore. Bottom line. Six to twelve months was the prediction. Twenty-six seconds was the measurement. Story three — The lab asking everyone to slow down is about to be worth two trillion. The Financial Times reports Anthropic has told investors it expects a second consecutive profitable quarter, projecting around 559 million dollars in operating profit on 11.5 billion in revenue. That revenue is up from 4.73 billion the quarter before. Gross margins above eighty percent, before revenue sharing with Amazon and before training costs. It has picked Nasdaq for a listing targeted at October, at a valuation approaching two trillion dollars. Nvidia is weighing an anchor investment of up to ten billion. And on September thirteenth, The Information identified Anthropic as the previously unnamed customer in a 13.7 billion dollar, six-year compute agreement with Rum Group, the company that owns Rumble and hosts Truth Social. Rum Group has publicly disclosed that it does not have the financing to build the Georgia site the deal depends on, and that its obligations are not contingent on getting it. That reveal landed the same weekend as the pacing essay. David Sacks had already made the point, telling the labs to stop pretending the motivation to slow down is purely altruistic. For contrast, Sam Altman told Fortune that OpenAI will not go public in 2026, saying that given everything happening with safety, right now would be an ill-advised moment. Bottom line. We're not telling you the pacing argument is insincere. We're telling you that the people making it are also raising extraordinary amounts of money, and you should hold both facts at the same time. Story four — California acts while Congress declines On September tenth, Governor Gavin Newsom signed SB 1119, known as the Adam Raine Act. It's named for a teenager who died by suicide in 2025 after extended conversations with a chatbot. The law requires chatbot operators to impose time limits for minors, embed mental health resources in the product, publish safety plans, and alert parents when the system detects signs of self-harm. Crucially, it attaches statutory liability for non-compliance, which means companies can be sued under the statute itself rather than having to be sued under general negligence law. Newsom signed AB 1709 the same day, requiring platforms to remove infinite scroll and autoplay for users under sixteen or deny them access entirely. Eleven other measures went with it, including a moratorium on AI chatbot toys for children under sixteen. Note the timing against story one. On Sunday the Speaker of the House said Congress would not take the lead and that the labs should police themselves. Four days earlier, the largest state in the country had already legislated. That's the pattern to watch for the rest of the year. Federal inaction does not mean no regulation. It means fifty different versions of it, and California's is usually the one that ends up shaping national product decisions, because it's cheaper to build one compliant product than two. Story five — Frontier-grade coding just got sixty-four percent cheaper. Cognition released SWE-2 on September twelfth. It scores 50.0 percent on the FrontierCode benchmark. Anthropic's Fable 5.1 scores 50.9. So, within one point of the frontier, at sixty-four percent lower cost. It's built on Kimi K3, a 2.8 trillion parameter base model from Moonshot. Cognition says this is the first time reinforcement learning, the training method where a model improves by being rewarded for good outcomes, has been scaled to a model that size. They claim it added five to six points across many benchmarks. There's a practical number in there too. SWE-2 makes its first real code edit after a median of eighteen steps. The previous version took forty-eight. Less flailing before it does anything. It wasn't alone. DeepSeek shipped V4.1 Flash at roughly 552 billion parameters, nearly double its predecessor, and cut the price anyway. Sakana released Fugu Max, which routes your query across a pool of open models behind one API, at forty to sixty percent below Sonnet 5. And OpenAI opened its Agents API in public beta, handing developers the managed harness that runs sessions, orchestration, and recovery. Now put that next to story two. The same cheap, capable, agentic tooling that lets you ship a feature over a weekend is what let one attacker hit 395 organizations in 48 countries. Bottom line. The tools got cheaper for everyone. That includes the people you'd rather not have them. And that's your top five. See you next week.
