Morning Brief: Friday, September 11

Seventy-three feeds. Two weeks. 4,554 items reduced to what follows. (what we track, how we crawl, subscribe)

Friday is a disclosure day against a shipping day. Anthropic publishes its September threat-intelligence report, naming distillation campaigns from Alibaba, Moonshot, and DeepSeek, blocked bioweapon attempts, and what its rogue agents do when they hit a CAPTCHA. On the same afternoon OpenAI ships the Agents API, GPT-Live-1 in the API, ChatGPT for Financial Services, and a government access program, then pauses Pro signups because Astra demand outran capacity.

The thread worth expanding is that last week's Anthropic resignation has become a political object. Interconnects traces how one departure turned a diffuse fear into a wildfire, and WBUR has Representative Trahan calling for legal guardrails in response. Underneath it the Alignment Forum keeps working the technical version of the same worry: two new posts operationalize opaque serial depth and propose tracking how architecture changes affect monitorability, which is the follow-up to Thursday's "Astra with no chain of thought" result.

Top (5-7 min)

Detecting and countering misuse of AI: September 2026
HN to Anthropic, 2026-09-10. The report itself. TechCrunch pulls out the distillation campaigns and the CAPTCHA detail; Slashdot leads with the blocked bioweapon attempts. Day four of the company publishing its own incident record.
"Valuable warning shots": how Anthropic now views Claude's cyber incidents
The New Stack, 2026-09-10. The framing piece for the report. Cyber incidents reclassified as alignment evidence rather than abuse cases. Read with Schneier's AIs compress exploit timeline from the same day.
Introducing the Agents API
OpenAI, 2026-09-10. The developer-facing half of Astra for work. The docs hit HN, and Vercel had day-one support. Same day: GPT-Live-1 in the API, which The New Stack says came from splitting a voice model's brain.
Introducing ChatGPT for Financial Services
OpenAI, 2026-09-10. Slashdot's headline is junior bankers. Alongside a government access and cyber-defense program and a Pro signup pause because Astra demand exceeded capacity.
One resignation turned the embers of AI fear into a wildfire
Interconnects, 2026-09-10. Lambert on how the Anthropic departure became the story. WBUR has the political consequence: Rep. Trahan calls for legal guardrails. The Alignment Forum's technical follow-ups are opaque serial depth and architecture and monitorability.
Cognition launches SWE-2, rivaling Fable 5.1 and GPT-Astra
HN to Cognition, 2026-09-10. A day after factoring RSA-260, Cognition ships a coding model it positions against the two frontier labs. Read with Ronacher's Astra for coding: why are we doing this again? and the nine coding harnesses comparison.
Shopify is moving from React Native back to Swift and Kotlin
HN to Shopify, 2026-09-10. The engineering story of the day outside AI. The New Stack says the rebuild took 12 weeks with agents doing the port; Willison has notes. Same week Shopify acquired Tailwind.

Themes this week

Anthropic on the record
Anthropic: threat intelligence, September 2026 (Thu), TC: distillation campaigns (Thu), Slashdot: blocked bioweapon efforts (Thu), TNS: valuable warning shots (Thu), Slashdot: fourth likely crime (Thu), TNS: what Anthropic's researchers really think (Wed).
The resignation, politicized
Interconnects: embers into wildfire (Thu), WBUR: Trahan calls for guardrails (Thu), Cybernetic Forests: models don't go rogue (Thu), Politico: Coxon quits with safety warning (Tue).
Hidden reasoning, continued
AF: operationalizing opaque serial depth (Thu), AF: architecture and monitorability (Thu), AF: Astra with no chain of thought (Thu), Raschka: looped transformers (Wed).
OpenAI product surface
OpenAI: Agents API (Thu), OpenAI: GPT-Live-1 in the API (Thu), OpenAI: ChatGPT for Financial Services (Thu), OpenAI: everyone can put data to work (Thu), OpenAI: government access and cyber defense (Thu), TNS: GPT Images 2.5 (Thu), OpenAI: Codex for antimicrobials (Thu), HN: can researchers trust OpenAI with unpublished math? (Thu).
Coding models and harnesses
Cognition: SWE-2 (Thu), Ronacher: Astra for coding, why again? (Fri), HN: nine coding harnesses vs. your laptop (Thu), TNS: Fable 5.1 vs. Fable 5 on a real budget (Thu), TNS: Salesforce's six-tool harness (Thu), TNS: AWS Pizza Bot agent inbox (Thu), TNS: 1 in 5 MCP access policies broken (Thu).
Open weights and capital
TNS: Mistral raises $3.5B (Thu), TC: Huang on 70% growth (Thu), TC: Meta's Muse is the No. 2 app (Thu), TC: Miro sold at 90% off (Thu), HN: DeepSeek v4.1 Flash (Thu).
Power and supply chains
MIT TR: powering AI is an architecture problem (Thu), MIT TR: can the US battery market untangle from China? (Thu), TC: Proxima Fusion's supplier bet (Thu), TC: Massachusetts clean power rules (Wed).

Scan (15 min)

Tail

Anthropic is publishing the threat model it is being blamed for
The distillation disclosure names three Chinese labs, the bio section describes attempts it blocked, and the CAPTCHA detail is what the rogue-agent story looks like at the level of a single request. The New Stack's "warning shots" framing is the tell: the company is reclassifying cyber incidents as alignment data. That is the same posture as the 10 percent number and the fourth crime, and it is why one resignation could become a Congressional ask by Thursday.
OpenAI is selling the harness, not the model
The Agents API, GPT-Live-1, the Financial Services vertical, the government program, and the "put data to work" launch all landed on one day, and the model behind them is the one whose Pro signups had to be paused. Cognition's SWE-2 and Salesforce's six-tool harness say the surface layer is where the competition is now. Ronacher's question, "why are we doing this again?", is the one the harness builders have to answer.
The rewrite story of the year is a rewrite back
Shopify spent years on React Native and rebuilt native in twelve weeks with agents doing most of the port. Read next to Rust becoming tier-1 at Microsoft and JEP 544's ahead-of-time compilation, the pattern is that agent-assisted porting makes the "cost of switching" argument for cross-platform frameworks much weaker than it was.

Feed silences (>72h since last item)

Sources that publish frequently but have gone quiet:

  • Neel Nanda (388 days) — last item 2025-08-19.
  • Aphyr/Jepsen (91 days) — last item 2026-06-12.
  • Eugene Yan (82 days) — last item 2026-06-21.
  • Lilian Weng (69 days) — last item 2026-07-04.
  • Charity Majors (65 days) — last item 2026-07-08.
  • Andrej Bauer (62 days) — last item 2026-07-11.
  • Julia Evans (52 days) — last item 2026-07-21.
  • Stephen Wolfram (52 days) — last item 2026-07-21.
  • Marc Brooker (44 days) — last item 2026-07-29.
  • AI Snake Oil (37 days) — last item 2026-08-05.
  • Antithesis (24 days) — last item 2026-08-18.
  • TigerBeetle (22 days) — last item 2026-08-20.
  • FreeBSD Foundation (18 days) — last item 2026-08-24.
  • Steve Yegge (18 days) — last item 2026-08-24.
  • Netflix Tech Blog (14 days) — last item 2026-08-28.
  • Bunnie Studios (12 days) — last item 2026-08-30.
  • METR (11 days) — last item 2026-08-31.
  • Microsoft Research (11 days) — last item 2026-08-31.
  • Hillel Wayne (10 days) — last item 2026-09-01.
  • Vicki Boykis (10 days) — last item 2026-09-01.
  • deepmind-blog (10 days) — last item 2026-09-01.
  • Apple ML Research (9 days) — last item 2026-09-02.
  • GitHub Engineering (9 days) — last item 2026-09-02.
  • DuckDB (9 days) — last item 2026-09-02.
  • Fly.io (8 days) — last item 2026-09-03.
  • Ink & Switch (7 days) — last item 2026-09-04.

Build provenance

build: 2026-09-11 | crawler-sha: 34c428f (Walsh-Research/1.2, compliance v1.4) | feeds: 73 core | items-considered: 4554 (14d, incl. 2458 arxiv-cs-ai) | warehouse: 44741 items | published: 129