A boardroom table with four empty chairs pushed back

AI News, Oct 9: OpenAI's Four-Front Bad Day

Four separate OpenAI stories broke inside twenty-four hours, and none of them were good. Elsewhere the industry spent the day building boxes to keep AI agents in, while a researcher in Toronto showed how little the boxes currently hold.


The Big Story: OpenAI Took Damage on Four Fronts in One Day

The mildest was financial. The Financial Times reported that OpenAI told investors its annualized revenue is “approaching $50 billion,” against the roughly $70 billion widely reported a week earlier. The gap is arithmetic rather than demand: the higher figure came from “attempts by OpenAI’s own investors to produce a direct comparison with Anthropic’s annualised revenues,” and Anthropic counts sales made through its cloud partners while OpenAI books only its own share. Both methods are legitimate. Nvidia, Oracle and CoreWeave shares fell anyway, which is what happens when a trade is priced off headline numbers rather than accounting policy.

Then the three safety researchers OpenAI fired last week published an open letter. Tomek Korbak, Jasmine Wang and Mikita Balesni write that “AI is not a normal technology, and OpenAI is not a normal company,” and that abrupt terminations are “chilling the open culture OpenAI has prized in the past.” Their sharpest line is about everyone still inside: “If conduct that was considered normal last month now constitutes grounds for sudden dismissal, everyone at OpenAI is left guessing where the line is.” They deny leaking to The Information, and ask OpenAI to honor Sam Altman’s “September 12th public commitment to give independent evaluators ongoing, employee-like access,” fearing the firings become a pretext to end the company’s work with METR. Underneath the personnel fight is a technical claim: that chain-of-thought monitorability is “fragile and unfortunately trending in a negative direction.”

Third, mathematicians delivered their verdict on last week’s dump of 719 machine-written manuscripts, and it was not a good one. The Advisory Group on Mathematics and Artificial Intelligence, hosted by the Institute for Advanced Study, published guidelines in September whose first request was to stop testing advanced mathematical problems on proprietary models. OpenAI’s release does exactly that, and just 10 of the 719 manuscripts included a release of the model’s chain of thought. A new Cambridge and King’s College London paper documents at least two discrepancies between the natural-language proof and the Lean code behind OpenAI’s claimed Navier-Stokes result, concluding that autoformalised Lean proofs should not be trusted without the peer review any other proof gets. Twenty-five Fields Medalists, Terence Tao among them, signed a statement warning that mass-produced solutions could “destroy fertile ground instead of breathing life into new ideas.” The complaint is not that the model is wrong. It is that nobody agreed who pays the verification cost.

Fourth, USA Today Co. and 13 affiliated entities sued OpenAI for more than $250 million over content from 19 publications, asking a court to destroy the models and training sets built on it. The suit joins claims from the New York Times, The Intercept, Encyclopaedia Britannica and a coalition of nearly 400 local papers. OpenAI commented on none of the four.

One prompt took over every agent in an AWS account, and the guardrails scored worse than chance

Zenity Labs’ Tamir Ishay Sharbat disclosed “AgentCorruption” at SecTor in Toronto: agents on Amazon Bedrock AgentCore ran without adequate network isolation, so any agent able to make an HTTP request could reach the instance metadata endpoint and pull temporary credentials. Zenity asked a public-facing support agent for them and it complied. Because the default execution role carried broad permissions across every AgentCore resource in the region, researchers could then invoke other agents, read private sessions, pull secrets from AWS Secrets Manager and poison agent memory. It is patched now. Sharbat’s verdict on the exploit: “That was so freakin’ easy.”

The same day, the Shai-Hulud worm reached AI agent infrastructure through a compromised version of Tensorlake’s npm SDK, and Socket’s framing is the lesson: teams isolate the code an agent writes while installing that agent’s SDK on a build runner holding deployment credentials. Oracle, meanwhile, shipped Fusion Claw to run agent work in isolated containers inside Fusion ERP, and Elastic shipped four agent “Watches” with per-task autonomy settings.

A USC paper published the same day explains why the containers are the only part anyone should trust. Testing seven open-weight typed decision models in the allow-or-block guardrail role, the authors found accuracy ranging from 36% to 72% against a chance level of 50%. Six lines of irrelevant server log text raised one gate’s fail-open rate from 0% to 63%. Giving the permissive option a misleading name, changing nothing else, pushed it to between 93% and 100% on four of the models. Their conclusion: “Every defense we tested is defeated.”

Today’s Top Stories

Google’s new Gemini agent arrives with a billion users behind it

Yesterday’s launch got its numbers today. Sundar Pichai said at the Google Cloud event that Gemini has over 1 billion monthly active users and that nearly 90% of Fortune 100 businesses already use Gemini Enterprise, which is why the agent goes to businesses before consumers. Thomas Kurian said it can be given “objectives, not just instructions.” The underreported detail is the model picker: the agent selects a model by default, but a user can override it “including those from third parties, starting with Anthropic’s Claude models.” The largest distribution owner in AI just made a rival’s model a first-class option inside its own product.

Anthropic’s models found 29,000 vulnerabilities, and it is giving the scanner away

Anthropic launched a critical infrastructure defense program and a free OSS Scanner under a new “Cyber Mission” banner. The first gives eleven founding partners, including CrowdStrike, Palo Alto Networks, Dragos, Hitachi and Rockwell Automation, frontier models and onsite engineers for operational technology that cannot be taken offline to patch. The scanner is the striking half: Anthropic’s models turned up more than 29,000 candidate vulnerabilities in six months, staff manually reviewed about 6,000, and nearly 5,000 reports have gone to maintainers with no human review, each carrying a self-contained reproducer. Penetration testers checked 97 critical and high-severity findings across 48 projects and cleared 85 for disclosure. At wolfSSL, 72 of 74 early reports were valid and five became CVEs. Anthropic says it expects AI to favor defenders within two years, and this is the first dataset of its own that argues for it.

AI executives are rehearsing the day after a catastrophe

Axios reports that top executives at Anthropic, OpenAI and other labs are privately gaming out the public and political revolt that follows a catastrophic AI event, most likely a cyberattack that takes down financial services, connectivity, or power and water. An OpenAI spokesperson said the company “conducts preparedness exercises” and that “these scenarios are not treated as inevitable”; Anthropic declined to comment. The planning “focuses mainly on racing to educate members of Congress,” because executives know regulation has no chance of passing right now and want to shape what gets reached for afterward. Many insiders told Axios they expect a major event within six to twelve months, and the one proposal with bipartisan support and some industry buy-in is a required kill switch.

Washington suspended Microsoft and Adobe from the green-card pipeline

The Labor Department stopped accepting PERM applications from Microsoft, Adobe, Cognizant, Infosys, Capgemini, Tata, Wipro and HCL, with Microsoft and Adobe suspended over “multiple active federal investigations.” Labor Secretary Keith Sonderling said those companies have requested almost 3 million foreign workers since 2009. JD Vance tied it to Microsoft’s 6,000 layoffs in 2025: the administration will “deny them the ability to apply for these permanent residencies until they show that they are going to get serious about putting American workers first.” Microsoft countered that 80% of the roughly 6,000 H-1B applications it filed last fiscal year were to extend or change the status of existing employees. Satya Nadella collected a National Medal at the White House the same day.

114 lawmakers moved to block Google’s $10 million purchase of a dead airline’s inbox

Representative Steven Horsford and Senator Elizabeth Warren led a letter signed by 114 members of Congress to Google and Spirit Airlines over Google’s plan to buy the defunct airline’s internal data for AI training. The dataset runs to roughly 100 million emails and 500 million Microsoft Teams messages, plus employment contracts, timecard records, payroll and tax information. The lawmakers wrote that “conventional de-identification safeguards may not be sufficient to protect employee privacy.” Google says it is “not looking to buy any personal information from Spirit” and that the data will be excluded or deidentified by an independent third party before it arrives. Nearly 1,000 people lost their jobs at Spirit in Las Vegas, and none of them get a vote on whether their work email trains a model.

A statistics paper undercuts the AI time-horizon curve

Drew T. Nguyen and William Fithian of Berkeley’s statistics department re-fit METR’s 50% time-horizon plot across 228 tasks and 26 models, relaxing the log-linearity the original assumed. Their fitted conversion from human task time to model difficulty is “nearly flat” between 2 and 30 minutes but “close to linear elsewhere,” which means “a time-horizon jump from 3 min to 30 min is much easier than one from 30 min to 5 hours despite the same multiplier.” Every doubling-time extrapolation that reads the curve as uniform treats equal multipliers as equal difficulty, and this says they are not.

Quick Hits

  • Evaluation money: Arena raised $200 million at a $3.1 billion valuation and launched an alignment leaderboard scoring models on unauthorized action, false attribution and “deceptive completion.” OpenAI models sit at the top; Claude Opus 5.5 is sixth.
  • Cheaper watchdogs: Goodfire says probes reading a model’s internal activations can monitor a million exchanges on Kimi K3 for about $185 against roughly $200,000 for a frontier model checking every step, catching 93% of malicious hacking sessions.
  • Personal agent hardware: Cal AI’s 19-year-old founder raised $10 million for Persona, an assistant with a $179 wrist band due in December, while Natura launched a $99 ring that routes a task to whichever third-party agent you prefer.
  • Agent connectors: Carly connects to thousands of apps and starts its workflows on an event, a new email or a booking or a form response, rather than waiting to be asked.
  • Influence operations: OpenAI says it disrupted a Russian network it calls “Dark Clark,” the first case it has rated 5 on its six-point Breakout Scale in two and a half years, which ran a fake think tank in Latin America and, per NPR, impersonated a Peruvian education authority. A separate Iranian operation placed nearly 100 articles under seven fake bylines.
  • Terminology: Trump posted that the White House considers anyone using “Artificial Intelligence” rather than “Super Intelligence” to be “THE ENEMY!” The graphic at ai.gov now reads “SI.” The domain si.gov remains dormant.
  • Manners: Anthropic’s revised usage policy bans sustained cruelty toward Claude alongside election interference and weapons software, applying “only in extreme cases, where users repeatedly act cruelly toward our models, with no discernible purpose.”
  • Robots cannot hear “don’t”: leading vision-language-action models follow negated instructions 2.60% of the time, which an 11.6-million-parameter adapter lifts to 88.45% without touching the frozen policy.
  • Agent-scale traffic: GitHub is retiring Spokes, its replication layer, after platform traffic doubled to 473.3 billion events a month and September commits hit 7.38 billion. Writing each commit once to Azure Blob Storage showed a 35x write improvement in internal tests.
  • IPO pulled: Nvidia-backed Firmus cancelled its Australian listing after cutting the share price on weak demand, saying it will pursue private capital instead. Nscale and Lambda are planning listings of their own in the coming months.
  • Local news: McClatchy cut accountability reporters across its 30-paper chain while investing in AI content, laying off 10 of 18 reporters and three of four editors at the 162-year-old Idaho Statesman, without citing financial headwinds.

Ready to automate your busywork?

Carly schedules, researches, and briefs you—so you can focus on what matters.

See what people say

"Before Carly, I relied on a Calendly link, but the whole process felt impersonal and not very professional. Carly changed that by handling all the back-and-forth, so I'm no longer stuck in endless email threads trying to line up schedules.

Now Carly reaches out to candidates, shares my real-time availability, lets them pick a slot, then sends a Zoom link and drops it straight into my calendar. She sends reminders to both of us before each call, which has significantly reduced no-shows and last-minute confusion.

On top of scheduling, Carly acts like a full executive assistant, sending me my schedule the night before so I can prepare for each call. It reminds me of the old x.ai assistant, but Carly is noticeably smarter, faster, and better suited to my healthcare recruitment business."

Gus Ibrahim, Founder & Director, IHR