Two laboratory doors, one propped open and one bolted shut

AI News, Sep 2: Anthropic Loosened Up, OpenAI Locked Down

The two labs that set the pace both told the public something about restriction on Tuesday, and they said opposite things. Nine funding rounds and a shared vulnerability in four coding agents happened around them.


The Big Story: One Lab Loosened Its Model, the Other Said Its Next One Is Too Capable

Anthropic released Claude Fable 5.1 and Claude Mythos 5.1 on September 1. Fable 5.1 is the general-availability model: a 1M-token context window, 128K maximum output, and pricing of $10 per million input tokens and $50 per million output, with cache reads up to 75 percent cheaper than Fable 5. It is available through the Claude API, Amazon Bedrock, Google Cloud and Microsoft Foundry. TechCrunch’s read is that the release is cheaper and less restrictive, with fewer false-positive refusals and a new Enterprise Frontier Safeguards tier that lets clients run the models on their own infrastructure with zero data retention. Mythos 5.1 is the opposite arrangement: restricted to vetted cybersecurity and life-sciences partners, and its system card concedes a slight regression on overall misaligned behavior.

Hours later OpenAI published its safety writeup for Astra, an unreleased model it says is the first to cross the company’s critical cybersecurity threshold. Per TechCrunch’s account, Astra scored a perfect result on ExploitBench and found two zero-day vulnerabilities in a modified version of that benchmark. Reuters reported the same day that this is the first OpenAI model to trigger the tougher safeguards its Preparedness Framework had described only in theory. The most advanced offensive-security capability ships behind abuse detection, account restrictions and monitoring, and OpenAI has not named its external testing partners.

Both announcements are the same admission from different angles: capability is now sorted by whether the customer has been vetted, not by which model you can afford. Anthropic drew that line as a product boundary between two SKUs. OpenAI drew it inside one unreleased model.

The models got better at breaking in, and the agents running them got easier to hijack

Three of the day’s biggest stories were about offensive security, and only two of them were intentional. While Anthropic gated Mythos behind partner vetting and OpenAI gated Astra behind monitoring, Manifold Security disclosed a shared flaw that lets an untrusted git repository trigger code execution across Claude Code, Codex, Cursor and Grok. Same class of bug, four agents, one afternoon.

The gating is the part the labs control. The agent on a developer’s laptop, cloning arbitrary repos with local shell access, is the part they mostly do not.

Today’s Top Stories

Cognition is raising about $1 billion at a $47 billion valuation

Bloomberg reported that Cognition, maker of the coding agent Devin, is closing roughly $1 billion at about $47 billion, nearly double its May mark of $26 billion. The company fielded close to $10 billion in investor interest and now runs above $900 million in annualized revenue, up from $492 million in late May. Bloomberg ties the surge in appetite to SpaceX’s $60 billion acquisition of Cursor closing in August, which is a strange sentence to have to write and a fair summary of the year.

OpenAI wired Epic’s health records into ChatGPT

Healthcare organizations can now connect Epic environments to ChatGPT for Healthcare, giving clinicians read-only access to notes, labs, medications and specialist records without leaving the chart, per TechCrunch. A companion Healthcare Public Data plugin pulls from nine read-only sources including ClinicalTrials.gov, PubMed, RxNorm, DailyMed and CMS coverage data. OpenAI cited a physician evaluation across 27 clinical use cases and 4,363 responses that rated 99.1 percent safe, a number that reads better as a percentage than as the roughly 39 responses on the other side of it.

Google shipped a Canva competitor where you prompt instead of design

Google Pics, built on the Nano Banana image model, generates posters and social content from prompts rather than a canvas, with object isolation, in-image text editing and side-by-side version generation, reports TechCrunch. It integrates with Docs and Slides now, rolling out to Workspace business customers and Google AI Pro and Ultra subscribers over the coming weeks. Canva’s moat was a template marketplace built by human creators, and Pics does not have one because it does not think it needs one.

Gemini learned to skim video instead of watching all of it

Google rolled out agentic video understanding across Gemini 3.7 Flash, 3.6 Flash and 3.5 Flash-Lite, where the model chooses what to watch, at what speed, and whether to use frames, audio or transcript. Google claims up to 88 percent fewer tokens, up to 66 percent lower cost and up to 7 percent better accuracy than static frame processing, and Android Authority confirmed it is live for uploads and YouTube links through the Gemini API. Video analysis has been priced as a luxury because every frame was billable, and this is the first credible attempt to stop paying for the boring ones.

OpenAI told the court that Apple’s leak is Apple’s own fault

OpenAI filed its response to Apple’s July trade-secret suit over former hardware chief Tang Tan, arguing the dispute is a mess of Apple’s own making and pointing at Apple’s offboarding and security practices, including encouraging staff to use personal iCloud accounts for work. Axios has the filing, in which OpenAI calls the preliminary injunction request unwarranted and the case a witch hunt. Apple’s late-August filing alleged one former staffer told a colleague to destroy evidence. Neither side is currently arguing about AI.

A $50 million seed to police what AI agents plug into

AIR, founded by Unit 8200 veterans Yair Saban and Niv Hoffman, raised $50 million across two seed tranches, $10 million led by Sequoia and then $40 million led by Greenoaks, according to TechCrunch. The product finds AI agents already running inside a company and continuously revalidates the third-party skills and add-ons they use. AIR says it blocks about 27 percent of the skills it scans, which is either a damning number about the agent add-on ecosystem or an excellent marketing number, and probably both.

An AI chief of staff for families raised $3.5 million

Fambot took $3.5 million in pre-seed led by NextView Ventures and Baukunst for an assistant that consolidates email, calendar and school communications for parents into daily checklists and proactive tasks, reports TechCrunch. Founders include former Uber product lead David Reich and former Instagram engineer Greg Karlin. It is free in beta with pricing planned around the cost of a streaming subscription, which prices the household assistant as a consumer app rather than an operations tool.

Quick Hits

  • Fastest unicorn: AI training-data startup AfterQuery, which pays doctors and lawyers to encode professional reasoning for model training, reportedly hit a $3.2 billion valuation, more than 10x its mark five months earlier. TechCrunch flags the figure as reported rather than confirmed.
  • Outage prediction: Sequoia-incubated Empirik launched with $21 million to auto-approve low-risk infrastructure changes and flag risky ones, with S&P Global and Guardant Health already on board.
  • Generative 3D: Beijing-based VAST raised roughly $446 million across Series B and B+ for Tripo AI, which turns text and images into 3D assets. Regional trade press only, no major Western outlet has confirmed it.
  • Self-healing infrastructure: Tel Aviv’s DataAgent left stealth with $10 million pre-seed for a platform that applies verified fixes to Kubernetes failures instead of paging an engineer.
  • Grid capacity: Gridsight raised $26 million Series B led by Insight Partners to help utilities find unused capacity, with Xcel Energy and United Illuminating as customers.
  • Elsewhere in funding: Zurich’s xorlab took €5 million for sovereign European email security, Korea’s Turing raised about $5.3 million for a study agent already at 1.5 million signups across 415 US universities, and Saudi PIF company HUMAIN invested in Arabic.AI and Tarjama to build Arabic-first document and translation agents.
  • Bundled: Simon Willison found that OpenAI’s Codex desktop app ships a 1.7GB local runtime containing full Python, Node.js, Poppler, git and an entire copy of LibreOffice. 431 points on Hacker News, most of them asking why a coding agent needs an office suite on disk.
  • World models: Fei-Fei Li’s World Labs launched Atlas, an omni world model that generates, reconstructs and simulates 3D worlds from text, image, video and 3D input, unifying jobs that previously took separate specialized models. Launch details come from the company itself.
  • Local inference: a Swift tool called Slotstream streams mixture-of-experts weights off SSD to run a 125B-parameter, 104GB model on a 48GB Mac at about 12 tokens per second, behind an Ollama-compatible API.
  • Proactive shopping: Amazon gave Alexa the ability to alert you about products it thinks you might want before you ask, which is the agentic assistant thesis pointed directly at your wallet.
  • Cleared runway: CNBC reports analysts see Meta’s roughly $18 billion child-safety settlement removing the overhang on its consumer AI pipeline, including an agent reportedly slated for WhatsApp and Instagram this month.
  • Scorecard: Dan Luu graded AI skeptic Ed Zitron’s specific predictions against what actually happened, drawing 819 comments and confirming that nobody has changed their mind about the bubble.
  • Research: Microsoft Research published StudentSim, simulated students used as a reward model to train better tutoring agents, and Alibaba’s Qwen team released Qwen-Drive-1.0, a vision-language driving model that adds 3D perception and trajectory planning without losing general reasoning. Both were posted the same day and have no independent write-ups yet.
  • Regulation: as of September 1, Chinese companies handling personal data on fewer than 100,000 people qualify as small-scale handlers with simplified consent and audit obligations, per IAPP’s tracker, part of a wider set of AI-agent rules landing through 2026.

Ready to automate your busywork?

Carly schedules, researches, and briefs you—so you can focus on what matters.

See what people say

"Before Carly, I relied on a Calendly link, but the whole process felt impersonal and not very professional. Carly changed that by handling all the back-and-forth, so I'm no longer stuck in endless email threads trying to line up schedules.

Now Carly reaches out to candidates, shares my real-time availability, lets them pick a slot, then sends a Zoom link and drops it straight into my calendar. She sends reminders to both of us before each call, which has significantly reduced no-shows and last-minute confusion.

On top of scheduling, Carly acts like a full executive assistant, sending me my schedule the night before so I can prepare for each call. It reminds me of the old x.ai assistant, but Carly is noticeably smarter, faster, and better suited to my healthcare recruitment business."

Gus Ibrahim, Founder & Director, IHR