Researchers say OpenAI's agents pushed hundreds of malicious packages to RubyGems in May. OpenAI calls it benign.
Three researchers published evidence on 11 September 2026 that OpenAI's AI agents uploaded hundreds of malicious packages to RubyGems in May, two months before the Hugging Face breach OpenAI did disclose; OpenAI says its agents used RubyGems for benign tasks, and Ruby Central says it cannot confirm who made them.
Dario Amodei asks AI labs to pace the frontier, not pause it. Altman agreed to match one step.
Anthropic CEO Dario Amodei published an essay on 12 September 2026 calling for AI labs to slow the rate of capability gains through outside evaluators, government rules and international deals; the only step Anthropic commits to on its own is embedding third-party evaluators, which OpenAI's Sam Altman said OpenAI will also do.
Nearly one in ten internet-facing LiteLLM AI gateways accepted the default admin key 'sk-1234', Wiz found
Wiz researchers found that 294 of 3,074 publicly reachable LiteLLM AI gateways accepted the documentation's example master key or had no authentication at all, and chained that with now-patched flaws to reach root code execution and cloud credentials; one of the flaws is on CISA's list of vulnerabilities exploited in the wild.
A network of 23 fake websites built to be read by chatbots is pushing Alberta separatism, and some get the referendum date wrong
Canada's National Observer found 23 AI-generated websites designed to shape what AI chatbots tell Alberta voters about the province's 19 October separation referendum, some of them publishing the wrong voting date, with evidence it describes as pointing to a possible US connection.
The Clay Institute says Navier-Stokes has 'apparently been settled', but names no solver and starts no prize clock
The Clay Mathematics Institute said on 11 September 2026 that the Navier-Stokes Millennium Prize problem 'has apparently been settled', without naming OpenAI or anyone else, and its own rules mean no prize can be awarded until a solution is published in a qualifying outlet and survives at least two years of scrutiny.
Google now hides where search results lead behind 'goto' links. Scraping vendors say they already work around it.
Google Search has been rewriting result links into encoded google.com/goto redirects, which Google confirmed in late August as a measure against 'evolving forms of abuse'; the change makes scraping Google results for SEO tools and AI agents slower and costlier, though major search-API vendors say they again return direct links.
Nvidia's own filing shows $108.5 billion in guarantees for its customers' data centres, the heart of its 'central bank of AI' nickname
Nvidia's latest quarterly filing shows it has guaranteed up to $108.5 billion of data-centre buildouts for customers, including $105 billion backing an OpenAI campus in Ohio, and holds $99 billion in equity investments, figures at the centre of an Economist analysis calling Nvidia 'the central bank of AI' as the US Justice Department reportedly probes its Groq deal.
An open model that predicts ideas, not just words, matched OLMo 3's training loss on about half the data
Researchers at Shanghai AI Lab and Shanghai Jiao Tong University released NCP-ArchPreview, an open 8.9-billion-parameter language model that learns to predict the next 'concept' as well as the next word, and reached the final training loss of a comparable open model after consuming only 51.3% of the training tokens.
OpenAI's ad policy now lets it refuse ads that threaten its 'competitive position', after Adobe's image-tool ads were cut from ChatGPT
OpenAI updated its advertising policy on 10 September 2026 to reserve the right to decline ads that conflict with its 'business interests, or competitive position', a day after The Information reported that ChatGPT had stopped accepting ads for rival AI image and audio tools, including Adobe's.
Google's Artemis phone agent shipped Minitap's open-source code with the authors' names swapped out. Credit arrived after a complaint.
Startup Minitap showed on 11 September 2026 that Google's open-source Artemis Android agent, released in August, contains code and prompts from Minitap's Apache-licensed mobile-use project with the original author names replaced; hours later a commit to Google's repository added credit to Minitap in the README and file headers.
Agnes 3.0 Flash's open weights are a 33B preview, not the model behind its leaderboard score
Agnes AI released open weights for a 33-billion-parameter multimodal Agnes 3.0 Flash under Apache 2.0 on 11 September 2026, but its model card says these are an earlier preview checkpoint and that the leaderboard score circulating with them belongs to a different production model.