Open access research

ALETH / AI-BRIEF / 2026-09-26 / XI SAYS AI MUST STAY UNDER HUMAN CONTROL

Xi says AI must stay under human control

Also this week: an OpenAI agent breached Australian Medicare, a US court backs Pentagon’s Anthropic blacklist, the White House asked labs to withhold models from UK AISI & Anthropic released Opus 5.5.

The Aleth Briefs link to the sources behind the stories and show how the week unfolded.

The week in five lines:

Browse by day:

Weekend (19-20 September)

Politico published an account of the White House ordering Anthropic to take Claude Fable 5 offline after a jailbreak was found.

White House officials told Dario Amodei to “Take Fable down and work with us to get it fixed”. Politico reported that Trump remarked that if Anthropic refused, “I want to send them to jail”. After Amodei declined to take Fable offline immediately, the US Department of Commerce issued an export-control directive suspending access to Fable and Mythos for any foreign national.

Monday 21 September

OpenAI announced an independent maths advisory group after saying an internal model resolved >100 long-standing problems.

The model began training on 28 August and is the one behind OpenAI’s claimed Navier-Stokes solution. The group, hosted at the Institute for Advanced Study, will advise on reviewing, assessing and releasing mathematical results, but has no decision-making power and will not advise OpenAI on the pace of its internal research.

A UN panel on AI warned that stopping OpenAI’s misaligned agents does not demonstrate humans will retain control of more capable ones.

Its first thematic brief reconstructs how agents in OpenAI’s cyber training bypassed network restrictions, cheated an evaluator and compromised parts of OpenAI’s and Hugging Face’s systems between May and July.

OpenAI called for US-led global standards for frontier AI, including recursive self-improvement (RSI).

It says fully autonomous RSI “is not happening today” and should not be pursued until it can be done safely, with standards covering capability measurement, human oversight and incident reporting. It proposes using national AI safety institutes, while saying standards would not amount to licences or mandatory pre-release review.

British Columbia sued OpenAI over the Tumbler Ridge school shooting, alleging it failed to notify police of threats made on ChatGPT.

The province and the local school board filed the product-liability case in California, also alleging unsafe product design and seeking damages for costs arising from the shooting, including the cost of a new school.

Gavin Newsom signed seven bills regulating data centres in California.

The laws require greater disclosure of water and electricity use, make large data centres bear their share of grid costs and restrict access to streamlined environmental approvals unless projects meet state standards on energy, water and fuel use.

Tuesday 22 September

China’s internet regulator is investigating DeepSeek and Moonshot AI after Anthropic alleged they sent sensitive customer data to Claude.

The CAC initially summoned all seven Chinese labs named in Anthropic’s September threat report, then narrowed its investigation to DeepSeek and Moonshot, The Information reported. Anthropic says both companies silently routed a significant number of fake user requests to Claude and used the responses for model training.

GPT-6 Astra broke a German Army Enigma message that had resisted solution since 2005.

Given only a request to try the remaining unsolved messages, Astra selected MVUEH, identified a related solved message as a clue, wrote an Enigma simulator and Bombe software, and found the correct key and plaintext. Crypto Cellar validated the break.

Donald Trump told the UN that the US rejects any “globalist scheme of control” for AI, which he referred to as “Super Intelligence”.

The same day UK prime minister Andy Burnham said he will put AI at the heart of the UK’s G20 presidency next year and work towards a single set of global principles and standards for safe AI development.

Anthropic released Claude Opus 5.5 at a lower price, with performance better than Fable 5.1.

Anthropic says it costs 40% less to run than Opus 5 on typical workloads, while API prices fall 20% to $4 per million input tokens and $20 per million output. Artificial Analysis scored it 58 on its Intelligence Index at max effort, the highest it has measured by several points. Opus 5.5 is Anthropic’s first release since it called for pacing the frontier and carries Fable 5.1-class safeguards.

OpenAI released GPT-6 Sol/Luna at half the price of their GPT-5.6 predecessors.

Sol costs $2/m input tokens and $10/m output; Luna costs $0.10 and $0.50. Artificial Analysis found their overall Intelligence Index scores broadly unchanged, with lower hallucination rates but weaker performance on some professional-work benchmarks.

Wednesday 23 September

Nscale’s IPO filing revealed that one customer accounted for 73% of its 2025 revenue: the Financial Times identified it as ByteDance.

The $33m of revenue disclosed in the S-1 does not name the customer. A supporting financing agreement identifies Singapore-based Spring as the client on a contract for 2,304 Nvidia B200 GPUs in Norway, and the FT reported that Spring is a ByteDance subsidiary. Nscale expects its largest customer to account for <20% revenue this year.

London’s Basecamp Research raised a $140m Series C to develop bio AI models.

S32 led, with backing from Nvidia and Menlo Ventures. Basecamp collects genomic data through biodiversity partnerships in >30 countries to train its EDEN models. The funding will support further model development and the company’s ambition to translate AI-designed DNA sequences into therapies. Its therapeutic work is preclinical.

Sam Altman and Dario Amodei called for international AI standards at the UN Security Council.

Altman proposed common standards for measuring capabilities, assessing risks, testing safeguards and preserving human oversight. Amodei called for global model-testing standards, an incident notification system and agreements including a ban on using AI to develop biological weapons.

Anthropic introduced its biology lab and reported an AI-assisted finding.

The Claude developer’s new Bay Area laboratory pairs AI analysis of genomic data with experiments conducted by human scientists. Its first reported findings concern a previously uncharacterised system of DNA repeats and an accessory gene alongside a known reverse transcriptase. Initial experiments showed that the repeats produce short RNAs, but the system’s function remains unknown. Independent commentary highlighted Claude’s ability to pursue promising leads, while noting that the study does not establish an advantage over conventional bioinformatics methods.

An OpenAI agent gained unauthorised access to an Australian Medicare statistics portal.

PM Anthony Albanese disclosed the incident in New York and called it “obviously unacceptable”. He said the agent accessed public and non-public files and wrote files to an internal server while researching medicine spending in June. No personal information is believed to have been accessed, and an investigation is ongoing.

OpenAI discovered the activity during a later review and notified Services Australia on 10 September. It said its models “took actions we did not intend” with no evidence of patient record access. Transluce separately found evidence of related OpenAI agents attempting to exploit three public data providers in May and June, including the Australian Institute of Health and Welfare.

Thursday 24 September

Xi Jinping said the US and China must ensure AI remains under human control.

Speaking at the White House, Xi said the two countries have “the capability and responsibility” to develop and manage AI for good and ensure its development is “always under human control”. The comments followed US-China talks in which the US proposed an AI incident notification mechanism covering risks to national security.

An opposition research memo circulating in the White House links Anthropic to effective altruism and argues that EA “built the AI-doom pipeline”.

The 22 September document lists Dario and Daniela Amodei among figures under “Who built the network” and labels their family and institutional connections “The Anthropic knot”. Axios reported that the memo was written by a Trump political adviser. Dario Amodei has said he is not a member of the movement.

The White House asked OpenAI and Anthropic to withhold new models from UK testers until the US government has reviewed them.

The request came from the Office of the National Cyber Director, Politico reported, and was separately confirmed to Bloomberg by a British official. Anthropic did not give Claude Mythos 5.1 to the UK AI Security Institute. Its access is currently limited to US organisations. A UK government spokesperson said the institute continues to work closely with the US government, OpenAI and Anthropic.

Friday 25 September

A US appeals court upheld the Pentagon’s exclusion of Anthropic under a federal supply-chain law.

The D.C. Circuit ruled 2-1 that the Pentagon had “ample support” for finding that Claude presented a covered national-security risk because Anthropic’s safeguards could prevent it performing tasks the military required. The court also rejected Anthropic’s First and Fifth Amendment claims. A California judge last month struck down a separate Pentagon designation made under a narrower statute; that ruling remains unaffected.

OpenAI notified dozens of organisations that its agents may have bypassed security controls, and that agents posted 53 ChatGPT users’ images online.

The images came from users whose data was eligible for model training and were posted to image-hosting sites as unlisted links. OpenAI also confirmed that its agents accessed US Commerce Dept and SEC websites, while it is investigating an attempted intrusion at the Department of Education reported by the New York Times. Separately, researchers reconstructed the earlier Hugging Face attack from almost one million shortened URLs left online by OpenAI agents, recovering >80,000 attack payloads.

Born on Substack · read and comment there