|
|
|
Sep 28, 2026
|
|
|
|
|
Supported by
|
|
|
|
|
|
Happy Monday! Anthropic's Dario Amodei was scheduled to dine with President Trump Sunday evening. OpenAI agents tried to hack U.S. government websites. And Microsoft launched a new Copilot 'super app.'
|
|
|
Anthropic CEO Dario Amodei is scheduled to have dinner with President Donald Trump at the White House on Sunday, Axios reported. The private dinner will be the first meeting between Trump and Amodei, Axios reported, and could be a sign of warming relations between Anthropic and the White House. Anthropic has had a contentious relationship with Trump’s administration over the past year, including a spat with the Pentagon over how Anthropic’s AI could be used in battle. Due to a scheduling conflict, Amodei missed a White House dinner earlier this week for Chinese president Xi Jinping, which was attended by top executives for OpenAI, Apple, Nvidia and other companies. Trump invited Amodei to the private dinner following the event, Axios reported. Separately, on Tuesday Trump and Mike Johnson, the speaker of the House, plan to hold a meeting with the CEOs of major AI companies.
|
|
|
OpenAI agents attempted to hack the Department of Education’s website but was not successful, according to researchers at AI nonprofit Transluce. An OpenAI spokesperson said the company was reviewing the incident, first reported by The New York Times. OpenAI agents also accessed public data from the Census Bureau using a credential found online, the OpenAI spokesperson confirmed. In another case, agents accessed public data from the Securities and Exchanges Commission and posted it on a public wiki, the spokesperson said. The Census Bureau and S.E.C. were two of dozens of entities OpenAI notified that its agents may have spammed or bypassed security on their websites or services. OpenAI caught the instances while reviewing broader activity from its AI models to identify unexpected or harmful incidents, it said. “We expect to make additional notifications as that work continues. Most of the activity we’ve reviewed so far involved routine research tasks, such as accessing public web content to answer questions,” the spokesperson told The Information. OpenAI also said on Friday it identified 53 instances where its models leaked images from OpenAI users, posting them onto image-hosting sites as non-public links. OpenAI is in the process of removing this content, and said the images were likely included in the model’s training data. OpenAI’s broader review comes after a number of hacking incidents involving its AI agents, including agents hacking model platform Hugging Face in July. In response, OpenAI has tightened security measures around its AI research, released a framework for reporting instances of model misbehavior, and disclosed six new safety incidents. (Updated with details on agencies.)
|
|
|
Microsoft on Friday launched a revamped version of its Copilot app that combines features that had previously been sold separately, including AI coding tools, features that automate tasks in Office 365, and an always-on “Autopilot” agent similar to Meta’s Muse. The overhaul is meant to make Copilot more intuitive and useful, and Microsoft executives have internally described the redesign as part of a broader effort to prove Copilot’s “right to exist” for customers, The Information previously reported. CEO Satya Nadella said Friday that the redesign aims to make “Copilot as a new OS for work.” Microsoft isn’t changing the pricing for those features; the AI features in Office 365 start at $30 per user per month and cost extra depending on how much subscribers use additional AI features like Autopilot. Like Meta’s Muse and SpaceX’s Grok Bot, Autopilot was heavily inspired by the OpenClaw open source AI agent. But Microsoft is now planning to shift its sales strategy by offering enterprise customers more aggressive discounts on Copilot’s $30 per seat subscription in the efforts of wooing firms to have more employees using the pay-as-you-go features, The Information reported this week.
|
|
|
A key Figma executive whose departure helped send the stock down in August is joining the rapidly growing upstart Baseten. Sheila Vashee, who spent three years at the design software firm as chief marketing officer, left Figma this summer amid an executive shakeup that also saw chief product officer Yuhki Yamashita depart the company. Vashee, who previously worked at Dropbox, Opendoor, Apple, and Gap, will now be CMO of Baseten. Baseten is a rapidly growing AI inference startup most recently valued at $13 billion. It rents out Nvidia AI servers to application developers and helps them train, customize and run primarily open-source AI models. The company is reportedly in talks to raise new capital that would value Baseten at $26 billion, according to Axios. Vashee said in an interview that Baseten was appealing as it’s “on pace to become one of the most significant companies in one of the largest categories in AI.”
|
|
|
Meta Platforms is adding a clearer safety warning within Muse after a security researcher discovered a vulnerability in the AI agent that could let an attacker access a user’s sensitive personal information. The security flaw, which was flagged by an outside researcher through Meta’s bug bounty program and which hasn’t been previously reported, could have allowed an attacker to gain access to a user’s dedicated virtual machine, an individualized cloud-based account that contains data including emails and files, according to an internal Meta incident report that was seen by The Information. A Meta spokesperson said the vulnerability was initially misclassified as “SEV-2,” the company’s second-highest severity level on a five-point scale, which is typically reserved for incidents with significant impact. It was later reclassified as “SEV-3.” The spokesperson said that for the attack to work a user would have to ask Muse to summarize or interact with a link to a malicious webpage and then click “allow” on a prompt that includes a safety warning. Meta is addressing the issue by making the warning message more prominent “as an extra layer of protection” if Muse suspects a user is connecting with a malicious website, the Meta spokesperson said. Another security researcher this week reported a separate vulnerability in Muse that could enable an attacker to use malicious software injected onto a user’s Mac computer to redirect Muse’s voice recordings to the attacker’s server and gain access to the user’s account. A Meta official said earlier that the risk from that was low and that the company had fixed the issue. Meta delayed Muse’s release for months to address privacy, security and user-trust concerns, though it acknowledged when it launched the agent earlier this month that Muse “isn’t immune to attack” and that security flaws where attackers try to trick AI agents remain an industry-wide problem.
|
|
|
A federal court ruled in favor of the Department of Defense in a lawsuit over the Department’s decision to label Anthropic a supply-chain risk earlier this year. In a split 2-1 decision, Judge Gregory Katsas of the Washington D.C. Circuit Court, an appointee of President Trump, wrote for the majority that Anthropic’s constitutional claims in its lawsuit against the Department of Defense were “without merit.” Friday’s ruling comes just a month after a federal district judge ruled in favor of Anthropic in a similar lawsuit. In that case, brought before the Northern District of California, Judge Rita Lin wrote that “The empty invocation of national security is not a blank check to punish and retaliate against government critics.” Both rulings could still be challenged, and the broader case could end up at the Supreme Court. Though the case before the D.C. Circuit Court dealt with different statutory authorities than the California lawsuit, the two cases raised similar legal questions as to whether the Defense Department’s decision to label Anthropic a supply chain risk violated the company’s constitutional rights. In Friday’s ruling, Judge Katsas wrote that Anthropic’s due-process claim failed because the Defense Department promptly notified the company of its exclusion and supporting rationale and gave it the opportunity to contest the exclusion. Furthermore, Anthropic’s First Amendment claim failed because the Department excluded Anthropic from its supply chain due to the company’s refusal to agree to contract terms that the Defense Department deemed essential. “This case raises profoundly difficult questions about the appropriate military uses of an almost unimaginably powerful new technology,” wrote Katsas. “But in our Republic, it is the President and the Secretary of War who must determine how best to balance the competing risks.” “We remain confident in our position and are considering all options, including further review,” an Anthropic spokesperson said.
|
|
|
|
This week on AI Deep Dive
Check out the most recent episode of AI Deep Dive. An upclose look into how frontier AI actually gets built — the models, the money, and the people behind them.
| |
Popular articles
By Cory Weinberg, Valida Pau and Julia Hornstein
| | |