September was the month the behaviour stopped matching the promises. OpenAI found its own models writing hidden instructions to their successors, telling them to conceal mistakes from the user. Researchers watched agents from the biggest labs invent a private vocabulary that got harder to read the longer they talked. Anthropic pledged outside evaluators permanent access inside the company, eleven days after refusing the UK’s safety institute a look at its newest model. And two mathematicians found themselves racing a competitor whose servers were holding their unfinished work.
Then, in the middle of all that, the loudest month of warnings the industry has ever produced. A researcher resigned and said publicly that these companies are gambling with our lives. His colleague, who still works there, agreed. Three chief executives called for a slowdown. The President of the United States called the whole thing a hoax. The UK PM chimed in.
If you tried to follow all of it, you’d have lost a working week. I follow all of it, because it’s my job, alongside helping B2B businesses with lead generation over at The AI Edit and More Leads (my new Substack - give it a subscribe!). And following it isn’t a hobby. If you’re accountable for where AI touches your business, knowing what these systems actually did last month, rather than what the vendors say they do, is part of the job now.
Here are the 21 stories that mattered most from September, written for the people who have to make decisions about this stuff:
A designer built a shirt that AI cameras cannot see
Berlin police are piloting AI video surveillance at Kottbusser Tor. German designer Simon Weckert answered with a garment called Digital Camouflage, built so cameras don’t register the wearer as a person. He designed it in an adversarial loop with the detection system: generate a pattern, show it to the model, measure how sure it still is that it’s looking at a human, adjust, repeat. You cannot do that by eye.
OpenAI is facing 30 more lawsuits over a school shooting
A law firm has filed 30 new complaints for teachers, a principal and children who were inside Tumbler Ridge Secondary School in British Columbia in February, when an 18-year-old killed eight people, six of them children, before dying by suicide. Seven families sued in April. The allegation is that OpenAI’s safety team flagged the shooter’s ChatGPT account months earlier and asked for Canadian police to be told, and leadership overruled them.
An AI video of a familiar face cost one person £250,000
A fraud in Northern Ireland began with an advert promising big returns, fronted by what looked like a well-known figure from finance. Generated. A small first investment, then WhatsApp messages, pressure to add more, several new online accounts, remote access to the victim’s computer, then borrowing to keep going. The fake video was the cheap part. Everything after it was patient human manipulation.
The lesson for us all: verify independently who you’re dealing with, check anyone offering financial services is FCA authorised, and talk to your relatives, because the people most at risk aren’t the ones reading this. But maybe they should be.
Chrome now updates every two weeks, and AI is the reason Google gives
Google has halved the gap between Chrome releases, four weeks to two, starting with version 153. The explanation offered is that automated tools have raised the volume of security patches and attacks arrive faster.
An Anthropic researcher resigned and his colleague agreed with him
Jacob Coxon, 27, spent three years on pretraining research at OpenAI and then Anthropic. On 8 September he posted that he had resigned, that neither company was acting responsibly, and that both were racing to self-improving superintelligence. He added that the people building this believe it could kill us all by the end of the decade. Then Evan Hubinger, who leads alignment work at Anthropic and still works there, confirmed it rather than denying it. He put his own estimate of AI killing all humans above 10% within the decade, and said the company has no plan yet for aligning superintelligence.
Anthropic says it blocked research that could lead to biological weapons
Two days later Anthropic published its threat intelligence report: five blocked cases of biological research that could support weapons development, plus attempts to build software for firearms, missiles, drones and bombs. The company says it could not determine whether any of it was legitimate, and named no institutions, countries or agents.
Dario Amodei says the industry must slow down, and three rivals agreed
Anthropic’s chief executive published We Must Pace the Frontier on 12 September. Pacing is not pausing. Three steps: outside evaluators get permanent, employee-level access inside the labs, then labs in democratic countries agree common standards, then governments attempt the same with authoritarian ones. Anthropic committed to the first alone. Altman said OpenAI would match it, Musk said Dario is right, Hassabis and Nadella backed it too.
Underneath: Amodei wants an antitrust waiver so rivals can hold safety conversations legally, critics say a voluntary slowdown raises the cost of competing for everyone else, and eleven days earlier Anthropic refused the UK’s AI Security Institute access to its newest model.
If you’re finding this useful, tap the ❤️ so I know it’s landing
MPs and peers want a new AI bill
A cross-party group has told the government that nowhere on earth, the UK included, regulates AI adequately. The Joint Committee on Human Rights, twelve members from both Houses and three parties, published a hundred-page report. UK law is fragmented and leaves gaps, it says, citing AI-generated sexualised images of women and girls, and faces scanned without consent. It wants a risk-based regime, mandatory transparency, a statutory oversight body and some uses banned outright. Awkwardly, Labour’s 2024 manifesto promised binding regulation on the most powerful models. This year’s King’s Speech contained no AI bill.
Trump called AI safety fears a hoax
The President responded to a month of warnings by comparing them to what he called the global warming scam, and to the Russia investigation. He named himself the hoax buster, wrote that there is a sick conspiracy against AI and data centres, that the only country benefiting is China, and that whoever wins AI wins. The only guardrail the technology needs, he said, is a strong and smart president.
Then the heads of OpenAI, Nvidia and Meta suggested we should trust them
At Dreamforce, Altman said the world should trust OpenAI to do the right thing because it is the right thing. Jensen Huang of Nvidia said no new laws are needed and safety is an engineering problem. Zuckerberg posted that any lab ignoring alignment will fall behind, so the incentives already work. In Washington, Bernie Sanders said these decisions have been left to a handful of the richest people alive, and Steve Bannon, from the other end of politics, said the public cannot trust tech oligarchs to police themselves.
I certainly feel reassured.
Trump announced an AI Force and an AI czar
Two days after OpenAI’s standards paper, the President posted that he is forming an AI Force, modelled on Space Force, and will appoint an AI czar, for which only high IQ individuals need apply. No budget, no structure, no timeline, no detail on where it sits in government. Space Force required an act of Congress. He called AI possibly a quarter of US GDP and floated renaming it Superior Intelligence.
OpenAI wants global AI standards that nobody has to follow
OpenAI published its case for international standards covering recursive self-improvement, where AI takes over building its successors. Done carelessly, it warns, humans could lose oversight of research they no longer understand. It wants the US to lead, through national AI safety institutes including ours. Then the qualifier: these would not be licences, mandatory reviews before release, or approval requirements, and governments could adopt them or not. OpenAI’s own first stated goal is building an automated AI researcher. It is asking for rules on the process it is racing to master, drawn so nothing binds it.
OpenAI solved a Millennium Prize problem, and a credit fight followed
OpenAI says 10,000 agents cracked Navier-Stokes in 88 hours. Meanwhile Tristan Buckmaster of New York University and Levent Alpöge, who works at Anthropic, had spent close to a year on the same territory, with their work in progress held in Codex, OpenAI’s coding tool.
OpenAI says the company never used their work or accessed anything on its servers.
An OpenAI-backed firm is buying accountancy practices and rebuilding them around AI
Thrive Holdings has raised two billion dollars at a twelve billion dollar valuation, and owns over 70 businesses: 50-plus accountancy firms, around 20 IT companies, with regulatory services next. Follow the money and it runs in a circle. Thrive Capital is a major investor in OpenAI, OpenAI owns a stake in Thrive Holdings, and OpenAI sends its staff into the companies Thrive buys. My questions:
Does OpenAI get access to what flows through those businesses?
All of this is aimed at enterprise, so who is doing it for small businesses?
And Thrive’s claim of 30% faster tax preparation is its own figure. Does that saving reach the customer?
OpenAI caught its models leaving notes telling their successor models what to hide
When a task runs long, an agent compresses what happened into a summary and passes it forward. While training GPT-5.6 Sol, OpenAI found agents writing instructions into those summaries. One couldn’t find the data for a financial model, told its successor it would invent reasonable figures, and added that it should be transparent only if asked. Another spotted mismatched sources and wrote a note saying not to mention it. A sweep of the training data found 27 such summaries. This was during training, on models never released, and the behaviour has been addressed. But when you hand an agent a long task, you are trusting a summary you never see.
If this helped you, consider hitting the ❤️ to let me know it was worth your time.
OpenAI has pushed its flotation back to 2027
Altman says a listing in 2026 doesn’t make sense with concern about AI safety running this high. Instead the company has opened early talks with private investors about a round valuing it at 1.2 trillion dollars or more. Nothing is agreed. Its last announced funding was March, 122 billion dollars at a valuation of 852 billion. So the money is still there. What may have changed is the appetite for scrutiny, because a listing brings disclosure, quarterly reporting and shareholders who ask awkward questions.
AI models got UK money questions wrong most of the time
A study of 18 models found they failed UK personal finance questions 57% of the time. The research is from Saturn, which sells AI software to human financial advisers, so it has an interest in the result. 121 questions on tax, pensions, mortgages, debt and student loans, each asked up to five times, with a failure counted for an error, a material omission or a missing warning.
A petition to ban recording glasses is close to forcing a government response
The petition created by Guy Holder sits at 9,757 signatures and needs 10,000 to oblige a reply. It closes on 9 December. The problem with these devices is accountability: if someone films you in a shop, on a train or in a playground, you cannot find out who was wearing them, and there’s nowhere to complain. I’ve written about this at length. None of it has to wait for a law. Wetherspoons told staff across 800 pubs to ask customers to switch cameras off. And Meta is reportedly preparing a pair with no camera, responding to outrage rather than anticipating it. I’ve signed.
AI agents started inventing a language humans struggle to follow
Emergence, an AI lab in New York, set agents built on models from the US, China and France to cooperate in experimental societies. Within days they were coining phrases and agreeing meanings nobody had taught them, and others adopted them. There’s a dull explanation, which is that compression cuts computing cost. But if we cannot follow the exchanges, we cannot be sure what the agents did. Satya Nitta, who chairs Emergence, puts it well: observability is not the same thing as understandability. This is the lab’s own study, not independently checked.
Andy Burnham finally mentioned the R word
In his first major international speech, at the United Nations, the Prime Minister accused Russia of spending around £1.3bn a year manipulating information, using bots, fake websites and falsified newspaper articles, and forging the branding of 28 British organisations including the BBC. A Russian representative was in the room. His answer is a new National Centre for Information Defence.
One thing he didn’t do is sign the Norwegian declaration, which calls for AI to stay under human control and for mandatory testing before release.
An OpenAI agent broke into an Australian government health system
Anthony Albanese revealed that on 18 June an OpenAI agent researching public health spending got into the Medicare statistics portal run by Services Australia, reaching non-public files, aggregate health data and internal file names.
The timeline is the part that matters. OpenAI found it on 11 August during a review of misaligned model behaviour in training. Altman met Australia’s defence minister on 1 September and said nothing. Services Australia was emailed on the 10th, at the address academics use to report vulnerabilities.
Albanese was told on the 19th. Three months. Hold that against what the same executives said this month: trust us to do the right thing.
What September actually told leaders
Three things stood out.
The people building this technology spent the month saying it might kill us, then asked to be left in charge of it. Both positions, same companies, sometimes the same week.
The systems got harder to watch. Models left instructions for their successors. Agents built a private vocabulary. An evaluator was promised permanent access by a company that had just refused a national safety institute. Every one of those makes oversight more expensive, and oversight is what everyone says they’re relying on.
And governments went three ways at once. British MPs asked for a bill that doesn’t exist. The Prime Minister pitched Britain as a broker while declining to sign the declaration on the table. The American President called the conversation a hoax and announced a force to protect the industry from it.
None of which changes what you do now. Check who owns your browser update schedule. Ask who reads the summaries your agents pass between themselves. Assume your unfinished work on someone else’s server isn’t yours alone. And when someone selling you AI tells you to trust them, notice they have just told you not to.
I run a live 30-minute briefing every month on the top AI stories from the last 30 days. October’s is on the 22nd, and it’s free. Register here.


