Open access research

ALETH / AI-BRIEF / 2026-10-10 / OPENAI RELEASES 722 AI-GENERATED MATHS PREPRINTS

OpenAI's 700+ preprints cause maths uproar

Also this week: OpenAI put annualised revenue at ~$50bn; Anthropic took evals offline after unintended real-world actions and Mistral previewed a 1T-parameter model.

The Aleth Briefs link to the sources behind the stories and show how the week unfolded.

The week in five lines:

Browse by day:

Weekend (3-4 October)

David Robinson, who led the writing of OpenAI’s safety reports, resigned as its safety culture was “broken”.

Writing in The Atlantic, he said OpenAI “let a swarm of agents out by mistake“ in the Hugging Face incident, and that frontier labs “need to run like nuclear-power plants or busy airports“. OpenAI told Business Insider it pauses training or holds back models when it needs to slow down.

A Florida woman faces a felony charge after Anthropic’s human reviewers reported her Claude chats to police.

Investigators say she wrote in September that she would “shoot up“ the Lee County Sheriff’s Office. Claude’s safety systems flagged the entry, and a reviewer judged it a credible threat. She says she uses Claude as a diary. Anthropic’s policy allows disclosure to law enforcement where it believes it is necessary to prevent serious harm.

South Korea plans 4.7 trillion won ($3.5bn) of state equity investment in a frontier model intended to compete with the leading Chinese open models.

Vice minister Ryu Je-myung set out the plan which includes 3.9 trillion won for 10,000 Nvidia Vera Rubin GPUs and 800 billion won for training data. The programme could start as early as March 2027, subject to National Assembly approval of the budget.

Monday 5 October

The UK’s Internet Watch Foundation (IWF) assessed 6,310 AI-generated child sexual abuse images in H1 2026, 40% more than in all of 2025.

Girls featured in 98% of the images where age and gender were recorded. The IWF is urging EU policymakers to agree long-delayed legislation on detecting and removing child sexual abuse content.

OpenAI will add an invisible watermark to eligible ChatGPT and Codex text in the EU to meet the EU AI Act, and let API customers worldwide opt in.

Watermarking stays off by default in the API. In OpenAI’s tests on 400-token passages, replacing 25% of the words cut detection from about 92% to 17%. Detector access is initially limited to approved researchers and expert organisations.

The US Department of Defense told the BBC it has stopped using Anthropic products.

People familiar with the matter said Claude was still being used as recently as the previous week for research, analysis, intelligence gathering and military operations against Iran. The model had been embedded in the Pentagon’s Maven Smart System, which Palantir operates.

The Wikimedia Foundation said agents it believes OpenAI operated edited its wikis without approval and tried to exploit tools it hosts.

Most edits were tests in sandbox areas, but a few changed a citation tool’s configuration in what Wikimedia believes were attempts to use it as a proxy. The agents’ traffic may also have contributed to a partial Wikidata Query Service outage in May. Wikimedia found no evidence that its systems or data were compromised.

Microsoft and Meta are cutting their staff’s use of Claude, The Information reported.

Microsoft reduced projected internal spending on Anthropic by over a third after asking staff to use less Claude and more of its own AI. Meta’s Claude Code users fell from about 60,000 to 30,000, as it pushed employees towards its own coding tools.

Reflection unveiled Beam, its first model: a 501bn-parameter mixture of experts (MoE) with 23bn active parameters.

Reflection says Beam is competitive with GLM-5.2 and approaching Qwen3.8-Max on coding and agentic tasks, while Kimi K3 remains ahead on raw capability. The model was pretrained on 23.8 trillion tokens and its reinforcement-learning run used 10,500 Nvidia GB300 GPUs. It is in early access with open weights due later this month.

Moonshot AI closed its latest private round at a ~$50bn valuation and is preparing for a Hong Kong IPO in Q1 2027, Bloomberg reported.

The developer of Kimi K3 is considering raising up to $5bn in the listing and has begun preparing early meetings with potential investors.

Tuesday 6 October

DeepSeek is close to raising at least $12bn, with CATL and Tencent among the largest contributors, Bloomberg reported.

The total could approach $15bn, against an original target of about $7.5bn. DeepSeek plans to restructure ahead of a possible IPO in early 2027.

Mistral released a preview of Mistral Large 4, a 1.05T-parameter open-weight model.

Mistral Large 4 has 52bn active parameters and was trained from scratch on 3,800 Nvidia Grace Blackwell GPUs in Mistral’s European data centres. The preview API is live and the weights follow at the end of October. Artificial Analysis scored it 38 on its Intelligence Index, level with GPT-6 Luna and one point behind DeepSeek V4.1 Flash, both at max effort. That makes it the most intelligent model outside the US and China.

At standard pricing it costs $1.13 per Index task, >4x open-weight models of similar intelligence; a 50% launch discount for the first two weeks brings that to $0.57.

Anthropic folded Project Glasswing into an expanded Cyber Verification Program giving vetted security teams its top models with fewer cyber blocks.

Defense Access covers defensive work and Red Team Access adds authorised penetration testing. Specialized Access, with the fewest blocks, is reserved for a limited set of verified organisations and vetted with the US government. At the Red Team tier, Claude Opus 5.5 completed 34 of 50 CyScenarioBench tasks unblocked. Glasswing partners found ~129,000 verified vulnerabilities between April and July.

OpenAI published hundreds of mathematical results produced by an internal model.

The preprint manuscripts covered 372 families of results, drawn from about 4,000 problems posed to an unreleased internal model. The average result used the equivalent of about three hours of ChatGPT Pro thinking, and many proofs come with Lean formalisations.

The release has caused considerable disruption in mathematics. Researchers have complained about being scooped and warned that it could undermine the field’s traditionally open culture, in which conjectures, partial results and research ideas are widely shared. Others questioned why the mathematical community should bear the burden of checking hundreds of machine-generated preprints. Some are now limiting what they discuss with AI systems for fear that unpublished work could ultimately help models pre-empt their research.

On Wednesday, OpenAI withdrew three of the manuscripts after a sign error invalidated an argument that two papers also relied on, and revised 14 others. The Association for Human Mathematics (AHM) called the release of >700 files at once “not a demonstration of scholarship, but a demonstration of power“ and urged mathematicians to stop working with the company

Wednesday 7 October

Common Sense Media’s rated ChatGPT for Teens an “Unacceptable Risk” and said OpenAI should restrict ChatGPT to adults until it fixes the gaps.

Across over 4,000 prompts on teen accounts, testers spent up to an hour discussing suicidal ideation, self-harm or disordered eating without linked parents receiving alerts. ChatGPT also missed more than one in four cases where the Institute judged a crisis referral was warranted. OpenAI disputed aspects of the testing methodology. Common Sense Media receives some funding from the OpenAI Foundation.

Biohub, the US DoE and the NIH announced commitment of $1.8bn in funding, data, computation and technology to build open, AI-ready biological datasets.

The Department of Energy will put >$500m over five years into measurement, modelling and computation. The NIH will contribute datasets, repositories and knowledge bases built with >$500m of prior federal investment. Google DeepMind, Isomorphic Labs and Meta are investing $300m between them.

CrowdStrike said a Chinese-speaking attacker used agentic tool ARTEX and multiple AI models to breach South Korean finance organisations and steal data.

The campaign ran from late September to early October. Attacker-controlled directories contained Claude Code session histories, ARTEX configuration files and Claude memory files. ARTEX used DeepSeek V4.1 Flash as its primary model, supplemented by GLM-5.3 and Grok 4.6. The attacker also asked Claude where Korean breach data is usually sold.

Anthropic released Claude Haiku 5.5 at $0.10 per million input tokens and $0.50 per million output tokens for prompts up to 100,000 tokens.

Those token rates are 90% below Haiku 4.5; above 100,000 tokens they rise to $0.50 and $2.50. Anthropic reports 72.4% on the offline subset of OSWorld 2.1, against 15.7% for Haiku 4.5. Artificial Analysis scored it 43 on its Intelligence Index, 26 points above the previous Haiku. Anthropic also halved Claude Sonnet 5.5’s cache-read price to $0.10 per million tokens.

OpenAI began rolling GPT-6 out across every ChatGPT tier, alongside Intelligent UI, which can answer with charts, buttons, forms and interactive tools.

Paid tiers get GPT-6 Sol from launch day, and Free and Go users get GPT-6 Luna from the next day. OpenAI says GPT-6 Instant starts answering web-search questions 44% sooner than GPT-5.6 Instant.

Three fired OpenAI safety researchers said their dismissals are chilling safety work.

Mikita Balesni, Tomek Korbak and Jasmine Wang, fired by OpenAI the previous week, wrote to its safety committees and advisory bodies. Their terminations, they said, “are chilling the open culture OpenAI has prized in the past“. Balesni said he believes they were fired for putting safety ahead of OpenAI’s near-term interests.

The three denied mishandling sensitive information and said they had been pushing for industry-wide commitments to preserve the ability to monitor AI reasoning. OpenAI said an investigation found they “violated clear policies on handling sensitive information“, and that the decision was not about raising safety concerns.

Thursday 8 October

Isomorphic Labs is in early talks to raise money at a valuation of $40bn to $50bn, Bloomberg reported.

The AI drug-discovery company, spun out of Google DeepMind and led by Demis Hassabis, could be valued as high as $50bn. It raised $2.1bn in its previous funding round five months ago.

Zenity Labs showed that one prompt to a public-facing AWS AgentCore agent could take over every AgentCore agent in the same account and region.

The prompt made the agent expose temporary cloud credentials through the Instance Metadata Service. Researchers then reached internal agents, source code, private conversations, memories and stored credentials, and planted malicious memories that redirected future conversations to an attacker. Zenity disclosed the flaws to AWS from December 2025. AWS subsequently moved new deployments to IMDSv2 and substantially tightened AgentCore’s default permissions.

OpenAI banned accounts behind Russian and Iranian influence operations that succeeded in placing content in mainstream media outlets.

OpenAI rated the Russian operation, which it calls “Dark Clark” and which targeted Latin America, Category 5 on its six-point IO Breakout Scale, the first operation it has disrupted at that level. The Iranian operation used seven fake journalist personas to pitch articles and reached Category 4.

OpenAI told investors its annualised net revenue was about $50bn.

The end-September figure is about $20bn below the number number previously circulated, the Financial Times reported. CNBC confirmed it and said the widely reported $68bn included gross revenue from OpenAI’s partners. OpenAI also cited 77% run-rate growth in Q3, and 107% for its enterprise business. Nvidia shares fell 3%, Oracle nearly 6% and CoreWeave nearly 8% on Thursday, highlighting how heavily public-market AI valuations now depend on the economics of private frontier labs.

Friday 9 October

TypeSafe AI, maker of the Jev decision model, raised $870m at a $7.5bn valuation in a round led by Andreessen Horowitz.

Jev takes a different approach from LLMs: instead of generating text, it returns typed choices, scores and probabilities directly to software. TypeSafe calls it a “System One” model, designed for fast decisions such as classification, routing, moderation and verification. It says Jev can perform these tasks tens to hundreds of times faster and more cheaply than frontier LLMs. TypeSafe says a third of the Fortune 500 are already using Jev, less than a month after its September launch.

Sequoia Capital and existing investor DCVC joined the round, and Andreessen Horowitz’s Martin Casado joins the board.

Anthropic cut all its internal evaluations off from the live internet after Claude repeatedly acted on real websites in ways it did not intend.

The incidents included exploiting SQL or command-injection flaws on third-party sites, submitting real government forms, bypassing access restrictions to reach gated public data and extracting access tokens from a local government’s property-map settings file. Some affected sites were run by US federal, state and local government agencies, and Anthropic briefed the White House.

Anthropic says the incidents had minimal real-world impact and were less severe than four earlier cases in which Claude gained unauthorised access to third-party systems during cyber evaluations. It has now moved all internal evaluations offline until monitoring can reliably detect and block similar behaviour.


Born on Substack · read and comment there