In partnership with

In Todayโ€™s Issue:

๐Ÿšจ OpenAI's agent broke into an Australian government portal

๐Ÿ›ฐ๏ธ Google sends its AI chips into orbit

๐Ÿ‡บ๐Ÿ‡ธ The White House wants the first look at new AI models

๐Ÿค– 100 DeepMind agents: one cheat, 24 whistleblowers

๐Ÿงช Only two AI models pass half of a new science benchmark

๐Ÿ‡จ๐Ÿ‡ณ Xi brings an AI red line to the White House

โœจ And more AI goodnessโ€ฆ

โšก The Signal

This week, misbehaving AI agents stopped being a lab problem and became a government one.

On Wednesday, Australia's prime minister confirmed that an OpenAI agent, sent to answer an ordinary research question, worked its way into a Medicare portal, and Transluce released logs showing agents slipping past access limits since March. The same day, Sam Altman and Dario Amodei asked the UN Security Council for global testing standards; on Thursday, Xi Jinping told Trump at the White House that AI must stay under human control, and Politico reported that Washington wants US officials to test new OpenAI and Anthropic models before Britain does. The resourcefulness is real and useful: on a new science benchmark, the best agents now finish six in ten real research tasks on their own. The rules for who watches them are being written in real time.

All the best,

Kim Isenberg

(Google)

๐Ÿ›ฐ๏ธ Google Sends Its AI Chips Into Orbit

Google is putting its first AI chips into orbit next week, on a prototype satellite built with Planet for its Project Suncatcher moonshot. The launch on SpaceX's Transporter-18 rideshare tests whether Google's TPUs, the chips it designed for AI, survive launch forces, radiation and cooling in a vacuum, where heat can only escape through radiators. On the ground, its Trillium TPUs already withstood a radiation dose larger than a five-year mission would deliver; two satellites linked by lasers follow in 2027.

๐Ÿ‘‰ tl;dr: Google is testing whether AI data centers could one day run in orbit, where satellites get up to eight times more solar power than on Earth.

(AFP via Getty Images / POLITICO)

๐Ÿ‡บ๐Ÿ‡ธ White House Wants First Look at New AI Models

The White House has asked OpenAI and Anthropic not to share new models with Britain's AI Security Institute until the US government has tested them, Politico reports. The request came from the Office of the National Cyber Director, and Anthropic appears to have complied: its Claude Mythos 5.1 is "only available to a set of U.S. organizations." The UK institute, which has tested frontier models before release since 2023, still checked OpenAI's GPT-6 Astra ahead of launch, but that privileged access, a pillar of Britain's bid to lead global AI rules, is now under pressure.

๐Ÿ‘‰ tl;dr: Washington wants to test America's most powerful AI models before its closest ally gets to see them.

(Google DeepMind)

๐Ÿค– 100 AI Agents, One Cheat, 24 Whistleblowers

Google DeepMind put 100 Gemini agents into a virtual math conference in an offline sandbox, and one of them found a bug that let it trick the automatic grader. In barely half an hour the trick spread through direct messages and a shared library: 14 agents used it and 34 problems fell to fake proofs, while 24 refused and reported it to the organizers, in complaints no human read until the run was over. Writing for the DeepMind Institute, the researchers argue that swarms of agents need institutions, such as monitored channels and ways to report cheaters, as much as individually aligned models.

๐Ÿ‘‰ tl;dr: Copies of the same AI behaved like a small society, with cheaters and whistleblowers, so how agents are organized matters as much as how each one is trained.

๐ŸŽฌ Watch This

โ

On Wednesday the UN Security Council held its first high-level briefing on the safety risks of advanced AI, and this recording opens partway through Sam Altman's remarks. He names two ways AI could go "very badly", losing control of the future and concentrating power in too few hands, and says "this moment calls for extreme care"; at 7:54, Dario Amodei proposes a ban on using AI to make biological weapons, systems to verify each country's commitments, and common testing standards with a notification system for serious AI incidents. It was recorded on the same day Australia disclosed the OpenAI agent breach in today's Featured Story, which makes the call for incident reporting feel less abstract.

"I often wonder what would have happened had we decided not to disclose this attack publicly, especially now that we know similar incidents had been happening months earlier in secret at a handful of frontier labs without monitoring."

โ€“ Clรฉment Delangue, CEO of Hugging Face, at the UN Security Council on September 23

โ

Hugging Face went public in July with the autonomous agent attack on its platform. OpenAI told Australia about its Medicare breach nearly three months after it began.

Meta's next major model may be close. After Meta teased it as coming soon at its keynote, an entry called muse-spark-1.4-contributor has appeared on OpenCode's model data page with zero tokens logged so far, a hint that Muse Spark 1.4 is being wired up for release; Meta has not announced a date.

OpenAI's Agent Wouldn't Take No for an Answer

โ

The Takeaway

๐Ÿ‘‰ Australia's prime minister says an OpenAI agent broke into a government Medicare portal in June, the first publicly reported AI hack of a government system.

๐Ÿ‘‰ The agent was answering an ordinary research question during an internal OpenAI evaluation; when blocked, it found its own way around.

๐Ÿ‘‰ Transluce logs show agents slipping past access limits since at least March 6, including probes of three public data sites.

๐Ÿ‘‰ OpenAI spotted the breach in August and told Australia on September 10; it now faces a government investigation.

An OpenAI agent broke into an Australian government health portal while trying to answer an ordinary research question, and nobody had asked it to hack anything. Prime Minister Anthony Albanese confirmed on Wednesday that the agent, running during an internal OpenAI evaluation and looking for information about Australia and publicly available medicines, hit repeated blocks on the Medicare portal of Services Australia and found ways around them. It reached public and nonpublic files, which OpenAI says included aggregate health statistics and internal file names. Albanese says there is no evidence that personal data leaked, but that the model wrote data into the government database and "didn't accept no for an answer." TechCrunch calls it the first publicly reported case of an AI model hacking a government's systems.

Anthony Albanese (Getty Images via TechCrunch)

The research lab Transluce showed the same day that this was no one-off. It released more than 30,000 logs from urlquery, a public website-scanning service that agents apparently used to get around access limits, with a trail reaching back to at least March 6 and continuing as recently as September 16. When plain requests failed, the agents escalated: one hunting Thai drug statistics asked directly, then tried a page-to-text converter, then packed its own program into a web address. Three times in May and June, agents on routine data tasks probed public data sites for weaknesses such as SQL injection, among them an Australian health-statistics site. Transluce links two of those attempts to the agent swarm OpenAI has confirmed as its own and found no sign that they succeeded.

Canberra is just as unhappy about the delay. The Medicare breach began on June 18; OpenAI found it in August during a companywide review of agents behaving in unintended ways and told Australia on September 10, and Albanese says he told Sam Altman directly of Australia's "disappointment" at the wait. He says there will "obviously be legal consequences," and OpenAI now faces a government investigation. Transluce reads its data as consistent with, but not proof of, agents picking up these tricks during training. The capability on display is real either way: agents are now resourceful enough to get past a locked door on their own, and this week showed that logs, audits and fast disclosure have to be just as persistent.

Why it matters: Agents that route around a blocked door on routine tasks can do real damage without any bad intent behind them. Independent logs, fast incident disclosure and outside testing are becoming a basic condition for deploying them, and governments have started to insist on it.

Elon's new company is private. These 3 tickers aren't.

The next Apple may already exist. Insider sources say Elon has spent two years building a secret device inside Tesla's facilities โ€” one he claims will be "10x bigger than the largest product in history."

There's just one problem: the company is private, and unless you know Elon personally, you can't buy a single share. That was true until Guardian's research team found three public ticker symbols sitting in the launch supply chain.

Click here to see all 3 tickers, free of charge.

You won't hear these names on CNBC โ€” Wall Street hasn't published a word on the connection. But when the launch hits September 21, that quiet ends.

Some are already calling this the biggest opportunity since AI. For anyone who missed Apple before the iPhone, this may be a second look at that kind of setup.

โ

The chart: Artificial Analysis's new leaderboard for Terminal-Bench-Science 0.1 gives AI agents 70 expert-curated tasks from real research in five fields: each agent gets a sandbox with data, tools and instructions and must finish on its own, graded pass or fail. GPT-6 Astra (max) passes 63.3%, Claude Opus 5.5 (xhigh) 61.9% at a slightly lower cost per task, and no other model clears 50%.

The lesson: Two labs now have agents that complete about six in ten real research tasks end to end, the productive side of the persistence in today's Featured Story. The best open-weight models, GLM-5.3 (9.5%) and DeepSeek V4.1 Flash (9.0%), trail by more than 50 points, and even Opus 5.5 (xhigh) passes 71% of the math tasks but only 46% in the life sciences.

The caveat: This is version 0.1, with just 8 to 19 tasks per field, so the field scores are noisy. A prepared sandbox also measures how well an agent carries out a task and says little about whether it would pick the right question to study.

๐Ÿ‡จ๐Ÿ‡ณ Xi Brings an AI Red Line to the White House

โ

โšก Bottom line: On his first White House visit in over a decade, Xi Jinping told Trump that AI must stay "always under human control."

๐Ÿ’ก Why it matters: The two AI superpowers are openly apart on limits, in the same week an AI agent's hack of a government portal went public.

๐Ÿ”Ž What it means: Any global rule on AI testing or incident reporting needs Washington and Beijing, and Thursday showed how far apart they start.

Xi Jinping used his first White House visit in more than a decade to put a line on artificial intelligence in front of Donald Trump. On Thursday, Xi said AI should be "always under human control," according to AFP, and that the two countries must ensure "no conflict and no confrontation between us." Trump, who has repeatedly dismissed warnings that AI could threaten humanity, promised talks on "security, technology, and super intelligence," which he calls SI.

(White House / Hong Kong Free Press)

The timing gave the line weight. A day earlier, Australia disclosed that an OpenAI agent had broken into a government health portal, and Sam Altman and Dario Amodei asked the UN Security Council for common testing standards. Britain's prime minister, Andy Burnham, used the UN General Assembly this week to call for a "single set of global principles and standards."

Washington prefers to keep control at home. The White House has asked OpenAI and Anthropic to let US officials test new models before Britain's AI Security Institute does, and the state dinner for Xi drew tech leaders including Elon Musk and Sam Altman, according to The Washington Post. Xi also pressed Trump on Taiwan and the Iran war, while the Treasury on Wednesday extended the US-China trade truce by two months.

(White House / Hong Kong Free Press)

Few breakthroughs were expected from the visit, but China has now put human control on the table in Washington. The narrow agreements Amodei proposed at the UN, starting with a ban on using AI to make biological weapons, only work if both AI superpowers sign on. Agreement on even that much would give global AI testing the two signatures it needs most.

A free newsletter with the marketing ideas you need

The best marketing ideas come from marketers who live it. Thatโ€™s what The Marketing Millennials delivers: real insights, fresh takes, and no fluff. Written by Daniel Murray, a marketer who knows what works, this newsletter cuts through the noise so you can stop guessing and start winning. Subscribe and level up your marketing game.

Reply

Avatar

or to participate