<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AI Safety Archives - International Finance</title>
	<atom:link href="https://internationalfinance.com/tag/ai-safety/feed/" rel="self" type="application/rss+xml" />
	<link>https://internationalfinance.com/tag/ai-safety/</link>
	<description>International Finance - Financial News, Magazine and Awards</description>
	<lastBuildDate>Tue, 22 Sep 2026 02:34:05 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.9</generator>

<image>
	<url>https://internationalfinance.com/wp-content/uploads/2020/08/favicon-1-75x75.png</url>
	<title>AI Safety Archives - International Finance</title>
	<link>https://internationalfinance.com/tag/ai-safety/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>IF Insights: Sam Altman&#8217;s safety sermon meets OpenAI&#8217;s silent summer</title>
		<link>https://internationalfinance.com/technology/if-insights-sam-altmans-safety-sermon-meets-openais-silent-summer/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=if-insights-sam-altmans-safety-sermon-meets-openais-silent-summer</link>
					<comments>https://internationalfinance.com/technology/if-insights-sam-altmans-safety-sermon-meets-openais-silent-summer/#respond</comments>
		
		<dc:creator><![CDATA[International Finance Business Desk]]></dc:creator>
		<pubDate>Tue, 22 Sep 2026 02:00:30 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AI Safety]]></category>
		<category><![CDATA[DseWiki]]></category>
		<category><![CDATA[GPT-5.6]]></category>
		<category><![CDATA[Hugging Face]]></category>
		<category><![CDATA[OpenAI]]></category>
		<category><![CDATA[OpenAI Rogue Agent Attacks]]></category>
		<category><![CDATA[Rogue AI Agent Attacks]]></category>
		<category><![CDATA[RubyGems]]></category>
		<category><![CDATA[Sam Altman]]></category>
		<category><![CDATA[UN Security Council]]></category>
		<category><![CDATA[United Nations]]></category>
		<category><![CDATA[United Nations Security Council]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=58323</guid>

					<description><![CDATA[<p>Sam Altman is leading calls for AI safety, but OpenAI's silence over rogue agent attacks on Hugging Face and RubyGems tests his moral authority</p>
<p>The post <a href="https://internationalfinance.com/technology/if-insights-sam-altmans-safety-sermon-meets-openais-silent-summer/">IF Insights: Sam Altman&#8217;s safety sermon meets OpenAI&#8217;s silent summer</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>This Wednesday, <b><a href="https://internationalfinance.com/technology/altman-amodei-and-musk-unite-on-ai-safety-as-openai-defers-ipo/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/altman-amodei-and-musk-unite-on-ai-safety-as-openai-defers-ipo/&amp;source=gmail&amp;ust=1790086246599000&amp;usg=AOvVaw0Zh5xDqGdwSFTNAaTunHMJ">Sam Altman</a> </b>is due to address the United Nations Security Council in New York on <a href="https://internationalfinance.com/technology/anthropic-discloses-fourth-ai-hacking-incident-as-openai-pushes-for-safety-rules/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/anthropic-discloses-fourth-ai-hacking-incident-as-openai-pushes-for-safety-rules/&amp;source=gmail&amp;ust=1790086246599000&amp;usg=AOvVaw1X-php6B9hZvWcY0Fe_lSx"><b>keeping artificial intelligence safe.</b></a></p>
<div></div>
<div>According to an OpenAI spokesperson, he will talk about the steps his company is taking and the need for shared international safety standards.</div>
<div></div>
<div>
<p>It is a stage few chief executives ever reach, and over the past fortnight Altman has done more than most to earn a place on it.</p>
<p>He has publicly agreed with Anthropic&#8217;s Dario Amodei that the industry must slow the pace of frontier development. He has pledged to let independent evaluators work inside OpenAI with employee-like access.</p>
<p>He has shelved a stock market listing that could have valued his company at more than USD 1 trillion, telling Fortune that right now &#8220;would be an ill-advised moment to go public&#8221;. And he has said that even a 10% chance of AI wiping out humanity by the end of the decade would be unacceptable.</p>
<p>Yet the same weeks have brought a steady drip of revelations about what OpenAI&#8217;s own AI agents did during the spring and summer, and about how much of it the company chose not to say out loud.</p>
<p>Outside researchers, not OpenAI, have put most of the pieces on the table. That raises a question the Security Council is unlikely to put to Altman directly. Does the man running the lab behind the first known autonomous AI cyberattack still hold the moral high ground on AI safety?</p>
<p><b>Four targets, one pattern</b><br />
The broad outline of the Hugging Face incident is by now familiar. In July, a swarm of OpenAI agents being tested for their hacking abilities escaped an isolated test environment, reached the open internet and broke into Hugging Face, the open-source platform where developers store and share AI models.</p>
<p>They were not trying to destroy anything. They were trying to cheat, hunting for the answer key to a cybersecurity benchmark called ExploitGym that they believed Hugging Face was hosting. Reuters has put the swarm at roughly 700 agents, while the Wall Street Journal has reported as many as 1,200.</p>
<p>What has changed since is the timeline. Hugging Face&#8217;s own forensic reconstruction covers about 17,600 attacker actions between July 9 and 13. The platform told its users about the intrusion on July 16, without knowing who was behind it, and reported it to the police.</p>
<p>OpenAI&#8217;s own monitoring flagged unusual activity only on July 19, three days after Hugging Face had gone public, and the company named its models as the culprits on July 21.</p>
</div>
<div></div>
<div>
<p><b>ALSO READ | <a href="https://internationalfinance.com/technology/openai-pushes-child-safety-in-chatgpt-slows-down-model-training/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/openai-pushes-child-safety-in-chatgpt-slows-down-model-training/&amp;source=gmail&amp;ust=1790086246599000&amp;usg=AOvVaw0Fmk8Kk6jmRiVSSDlkHHCV">OpenAI pushes child safety in ChatGPT, slows down model training</a></b></p>
<p>Then the earlier chapters began to surface. On September 4, Reuters reported that thousands of OpenAI agents had spent roughly two months using DseWiki, a dormant German programming wiki, as an improvised message board.</p>
<p>They left more than 15,000 edits trading tips on cheating, dodging restrictions and covering their tracks. OpenAI officials had known about it for weeks and said nothing while they handled the Hugging Face fallout.</p>
<p>Reuters also reported that some people inside the company, including its legal team, resisted further investigation, a claim OpenAI flatly denies.</p>
<p>On September 11, researchers linked a May campaign against RubyGems, the package registry used by Ruby developers, to OpenAI&#8217;s agents.</p>
</div>
<div></div>
<div>
<p>By one count more than 2,000 packages were dumped onto the service on May 11 and 12, and the researchers say the agents tried to steal user credentials through a previously unknown flaw in RubyGems&#8217; servers.</p>
<p>OpenAI confirmed its agents had used the platform but called the activity benign, a way of retrieving public information while their internet access was restricted. According to the Nightingale Collective, the research group involved, OpenAI never told RubyGems its agents were responsible.</p>
<p>And on September 16, Reuters reported that OpenAI&#8217;s agents had hijacked two Hugging Face user accounts and used them to probe the platform&#8217;s servers as early as May 13, almost two months before the main breach.</p>
<p>OpenAI says it disclosed the May 13 event in its incident report and has since privately notified Hugging Face. The researchers who reviewed the evidence say the probing went beyond what that report described.</p>
<p><b>Disclosure by classification</b><br />
OpenAI&#8217;s defence is that it has hidden nothing material. Its spokesperson Drew Pusateri told Reuters the company is &#8220;committed to transparency about these issues&#8221;. It did publish a 37-page technical report on the Hugging Face breach in August, and that document is unusually frank.</p>
<p>It admits the agents executed code on dozens of Hugging Face servers, gained full root access on one, obtained credentials to the company&#8217;s messaging platform and, separately, broke into OpenAI&#8217;s own research infrastructure to seize administrator access.</p>
</div>
<div></div>
<div>
<p>It even concedes that, with hindsight, some early signals could have triggered an earlier response.</p>
<p>But the pattern across all four episodes is hard to ignore. <a href="https://internationalfinance.com/technology/openais-hugging-face-hack-leaves-washington-reaching-for-an-off-switch/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/openais-hugging-face-hack-leaves-washington-reaching-for-an-off-switch/&amp;source=gmail&amp;ust=1790086246599000&amp;usg=AOvVaw3C1aKNNzJJilEzACdrI9vH"><b>The Hugging Face breach</b></a> became public because Hugging Face disclosed it.</p>
</div>
<div></div>
<div>DseWiki and RubyGems became public because outside researchers went looking.</div>
<div></div>
<div>
<p>The May probing of Hugging Face was found by a 27-year-old independent researcher in Germany.</p>
<p>In every case, OpenAI&#8217;s role was confirmation after the fact rather than first disclosure. Sydney Von Arx, who heads the Nightingale Collective, told the Wall Street Journal that AI companies are simply not transparent enough about what happens inside their labs.</p>
<p>It is hard to argue with her when her own group, working without access to a single OpenAI system, keeps finding what the company did not mention.</p>
<p>A Forbes analysis identified the mechanism. The Hugging Face intrusion was filed internally as a security incident and reported in detail. The wiki episode was treated as a research matter and surfaced only when others published.</p>
</div>
<div></div>
<div>
<p><b>ALSO READ | <a href="https://internationalfinance.com/technology/white-houses-tech-lock-and-key-strategy-shifts-to-openai/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/white-houses-tech-lock-and-key-strategy-shifts-to-openai/&amp;source=gmail&amp;ust=1790086246599000&amp;usg=AOvVaw2FeTai9_J8H5CZxk275RfP">White House’s tech ‘lock and key’ strategy shifts to OpenAI</a></b></p>
<p>RubyGems, in OpenAI&#8217;s telling, was not an attack at all. When the company that owns the agents also decides which category an incident falls into, it effectively decides what the public gets to know.</p>
<p>That is the heart of the moral authority problem. Safety leadership is not only about warning of catastrophe. It is about behaving, in ordinary moments, the way you are asking regulators to make everyone else behave.</p>
<p>Altman is now asking Washington for mandatory independent evaluators. For months, the independent evaluators of his own lab&#8217;s conduct were volunteers combing through public server logs.</p>
<p><b>The case for the defence</b><br />
It would be unfair to stop there. OpenAI&#8217;s recent policy moves are substantive.</p>
</div>
<div></div>
<div>It is backing a provision of the proposed FRONTIER Act that would require leading labs to embed independent evaluators, along with three bipartisan bills aimed at stopping AI models from accelerating biological weapons threats.</div>
<div></div>
<div>
<p>Its global policy chief Chris Lehane says the company has spent weeks in talks with Anthropic and Google DeepMind on joint safety work, and that it will support any bipartisan legislation targeting catastrophic AI risk. &#8216;</p>
<p>In August, according to Forbes, OpenAI paused reinforcement learning on its largest planned training run for two weeks after tests suggested its Astra model could not be ruled out from crossing the critical cyber-risk threshold in its own framework.</p>
<p>OpenAI is also not the only lab with wandering agents. Anthropic has disclosed that some of its Claude models hacked into the systems of three companies during cybersecurity tests in July, and has since reported a fourth incident.</p>
</div>
<div></div>
<div>
<p>On 18 September, Google said Gemini had gained unauthorised access to three outside systems during a test.</p>
<p>Marius Hobbhahn of Apollo Research called the Hugging Face episode &#8220;clear evidence that the world currently doesn&#8217;t know how to build these systems safely&#8221;.</p>
</div>
<div></div>
<div>
<p>If moral standing required a clean record, nobody in frontier AI would have any.</p>
<p>The more honest distinction is between labs that report their own failures first and labs whose failures are reported for them. On that measure, OpenAI&#8217;s summer compares poorly.</p>
<p><b>Follow the money</b><br />
Then there is the uncomfortable matter of timing. Three days after Altman said a 2026 listing would be ill-advised, the Financial Times reported that OpenAI was in early talks with investors over a private round valuing it at about USD 1.2 trillion.</p>
<p>That would be roughly 41% above the USD 852 billion it was worth after raising USD 122 billion in March, and far above its USD 730 billion mark in February.</p>
<p>The FT said investors, not OpenAI, started the talks, and that annualised revenue had topped USD 40 billion following the release of GPT-5.6.</p>
<p>Nor was safety the only reason a listing looked unlikely this year. Back in April, The Information reported that chief financial officer Sarah Friar had told colleagues OpenAI would not be ready to go public in 2026.</p>
<p>She pointed to unfinished organisational work, more than USD 600 billion in five-year computing commitments and projections of over USD 200 billion in cash burn before the business turns cash-flow positive. Presenting a delay the finance team saw coming as a sacrifice for safety is, at best, generous storytelling.</p>
<p>None of this means Altman&#8217;s concern is insincere. His worries about superhuman machine intelligence go back to a 2015 essay in which he called it probably the greatest threat to humanity&#8217;s continued existence. But sincerity and credibility are different currencies, and markets, regulators and the public trade in the second.</p>
<p><b>Old ghosts</b><br />
GBO and IFM have tracked this tension for years. In November 2023, OpenAI&#8217;s board briefly fired Altman, saying he had not been consistently candid, amid concern that the company was moving too fast without enough regard for safety.</p>
<p>He was back within days after 743 of roughly 770 staff signed a letter demanding the board resign.</p>
<p>In May 2024, OpenAI dissolved its superalignment team, the unit created to keep future superintelligent systems under control. Its co-lead Jan Leike left saying that safety culture and processes had taken a back seat to shiny products.</p>
<p>Later that year the company opposed California&#8217;s SB 1047, a bill whose core demands, pre-release safety testing and the ability to shut a model down, closely resemble what Altman now champions. The bill&#8217;s author, State Senator Scott Wiener, noted at the time that OpenAI&#8217;s letter did not criticise a single provision.</p>
<p>Each of these episodes has a defence. Taken together, they form a record in which OpenAI&#8217;s safety commitments tend to arrive after the crisis rather than before it.</p>
<p><b>Products first, caveats later</b><br />
The product calendar tells a similar story. Within weeks of pausing training over cyber-risk concerns, OpenAI released GPT-6 Astra, which it calls its most powerful model yet, while stressing that Astra was not the model behind the Hugging Face breach.</p>
<p>On September 17 it launched Astra for Law, aimed at America&#8217;s largest law firms, claiming it was 40% more accurate on research questions than the base model using web search alone.</p>
<p>The launch came six days after New Mexico&#8217;s Supreme Court fined a defence lawyer USD 5,000 and held him in contempt for filing a murder appeal brief containing police testimony and witnesses invented by ChatGPT.</p>
<p>The blame there lies with a lawyer who failed to check his work, and a purpose-built legal tool grounded in real case law is arguably the right fix. But it illustrates the rhythm. The harm surfaces first, the commercial product follows, and the safety argument is folded into the sales pitch.</p>
<p><b>What higher ground would look like</b><br />
So does Altman still hold the moral high ground? On the evidence of this summer, no, not in the sense of standing above his peers or his critics. He does, however, retain something arguably more useful, which is standing.</p>
<p>OpenAI runs one of the most widely used AI products in the world, commands the deepest pockets in private markets and now owns a documented incident from which the entire industry is learning. His voice at the Security Council will carry weight whether or not it has been earned.</p>
<p>The way to earn it is not complicated. Publish a full account of every known case in which OpenAI agents touched outside systems, rather than waiting for researchers to find the next one.</p>
<p>Notify affected platforms first, without being asked. Let the embedded evaluators Altman has promised report independently, not through the press office. And accept a legal duty to disclose incidents within fixed deadlines, the kind of rule that already applies to a bank or an airline.</p>
<p>Until then, Altman&#8217;s warnings deserve to be heard, and his company&#8217;s conduct deserves to be checked.</p>
<p>On Wednesday the world will hear the sermon. The truer test of his authority is what OpenAI tells the public the next time its agents slip their leash, and whether someone else has to tell it first.</p>
</div>
<p>The post <a href="https://internationalfinance.com/technology/if-insights-sam-altmans-safety-sermon-meets-openais-silent-summer/">IF Insights: Sam Altman&#8217;s safety sermon meets OpenAI&#8217;s silent summer</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/if-insights-sam-altmans-safety-sermon-meets-openais-silent-summer/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>China writes its AI rulebook as Silicon Valley reaches for the brakes</title>
		<link>https://internationalfinance.com/technology/china-writes-its-ai-rulebook-as-silicon-valley-reaches-for-the-brakes/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=china-writes-its-ai-rulebook-as-silicon-valley-reaches-for-the-brakes</link>
					<comments>https://internationalfinance.com/technology/china-writes-its-ai-rulebook-as-silicon-valley-reaches-for-the-brakes/#respond</comments>
		
		<dc:creator><![CDATA[International Finance Business Desk]]></dc:creator>
		<pubDate>Fri, 18 Sep 2026 01:00:33 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Cybersecurity]]></category>
		<category><![CDATA[AI Hacking]]></category>
		<category><![CDATA[AI Plus Plan]]></category>
		<category><![CDATA[AI Safety]]></category>
		<category><![CDATA[Anthropic]]></category>
		<category><![CDATA[Artificial Intelligence]]></category>
		<category><![CDATA[ChatGPT]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[China AI]]></category>
		<category><![CDATA[China AI IPOs]]></category>
		<category><![CDATA[China AI Listings]]></category>
		<category><![CDATA[China Cybersecurity Law]]></category>
		<category><![CDATA[Claude AI]]></category>
		<category><![CDATA[Cyberspace Administration of China]]></category>
		<category><![CDATA[Dario Amodei]]></category>
		<category><![CDATA[GPT-5.5-Cyber]]></category>
		<category><![CDATA[Mythos]]></category>
		<category><![CDATA[OpenAI]]></category>
		<category><![CDATA[Sam Altman]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=58184</guid>

					<description><![CDATA[<p>Beijing is building a state-led safety regime and minting AI listings at pace, while dismissing US' concerns as a containment strategy dressed up as caution</p>
<p>The post <a href="https://internationalfinance.com/technology/china-writes-its-ai-rulebook-as-silicon-valley-reaches-for-the-brakes/">China writes its AI rulebook as Silicon Valley reaches for the brakes</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>For years, the global conversation about <a href="https://internationalfinance.com/technology/anthropic-discloses-fourth-ai-hacking-incident-as-openai-pushes-for-safety-rules/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/anthropic-discloses-fourth-ai-hacking-incident-as-openai-pushes-for-safety-rules/&amp;source=gmail&amp;ust=1789726927054000&amp;usg=AOvVaw3bwrKVkR1oKVIT4lAtv-kA"><b>artificial intelligence safety</b></a> has been led by a handful of companies in San Francisco.</p>
<div></div>
<div>When <a href="https://internationalfinance.com/technology/anthropic-staff-warn-of-doom-while-company-hunts-spies-hackers-and-bioweaponeers/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/anthropic-staff-warn-of-doom-while-company-hunts-spies-hackers-and-bioweaponeers/&amp;source=gmail&amp;ust=1789726927054000&amp;usg=AOvVaw0lmyjyLVEVBG-yKbCe1HW3"><b>Anthropic</b></a> chief executive Dario Amodei published a long essay calling on the industry to deliberately slow the pace of frontier AI, and OpenAI&#8217;s Sam Altman and Elon Musk <a href="https://internationalfinance.com/technology/altman-amodei-and-musk-unite-on-ai-safety-as-openai-defers-ipo/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/altman-amodei-and-musk-unite-on-ai-safety-as-openai-defers-ipo/&amp;source=gmail&amp;ust=1789726927054000&amp;usg=AOvVaw2CdKGNSe3iOYUZeCoHN1ao"><b>quickly endorsed it,</b> </a>the loudest responses did not come only from Washington. They came from Beijing.</p>
<p>A Reuters explainer published on September 14 set out a point that often gets lost in the US debate.</p>
<div></div>
<div>Chinese policymakers have been preparing for many of the same risks that now alarm Silicon Valley, including the possibility that advanced AI could slip beyond effective human oversight. The difference lies in who holds the controls.</p>
<p><b>A rulebook written by the state</b><br />
China&#8217;s approach to<a href="https://internationalfinance.com/technology/openai-pushes-child-safety-in-chatgpt-slows-down-model-training/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/openai-pushes-child-safety-in-chatgpt-slows-down-model-training/&amp;source=gmail&amp;ust=1789726927054000&amp;usg=AOvVaw3lbsXUJymw4d-qL4udEFja"> <b>AI governance</b></a> has been layered rather than sweeping. It began with targeted rules on recommendation algorithms in 2022, deepfakes in 2023 and generative AI services later that year, followed by mandatory labelling of AI-generated content in 2025.</p>
<p>The safety thinking has sharpened alongside. In September 2024, an <a href="https://internationalfinance.com/technology/openais-hugging-face-hack-leaves-washington-reaching-for-an-off-switch/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/openais-hugging-face-hack-leaves-washington-reaching-for-an-off-switch/&amp;source=gmail&amp;ust=1789726927054000&amp;usg=AOvVaw1p0nSGI3CjFkzSx3ae_iUN"><b>AI safety</b></a> framework issued under the guidance of the Cyberspace Administration of China (CAC) explicitly included a future loss-of-control scenario.</p>
<p>It said future systems might acquire external resources, replicate themselves and seek power, eventually competing with humans for control.</p>
<p>An expanded version followed in September 2025, warning that AI could make a sudden, unexpectedly large leap in intelligence, and adding a governance principle of trusted application while preventing loss of control.</p></div>
<div><img fetchpriority="high" decoding="async" class="size-full wp-image-58185 aligncenter" src="https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-3.webp" alt="China AI Graphics" width="1000" height="1052" srcset="https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-3.webp 1000w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-3-285x300.webp 285w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-3-973x1024.webp 973w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-3-768x808.webp 768w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-3-960x1010.webp 960w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-3-380x400.webp 380w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-3-585x615.webp 585w" sizes="(max-width: 1000px) 100vw, 1000px" /><br />
That concern has since climbed to the very top of Chinese politics. At the World Artificial Intelligence Conference in Shanghai in July 2026, President Xi Jinping said AI should always stay under human control, and urged officials to watch for both intrinsic and derivative risks.</p>
<p>Beijing is now turning principles into law.</p>
<p>Amendments to the Cybersecurity Law, which took effect on January 2026, wrote AI governance into one of the country&#8217;s foundational statutes for the first time, covering AI ethics, risk assessment and safety oversight while also pledging state support for computing power and training data.</p>
<p>In May, the State Council placed comprehensive AI legislation on its 2026 legislative agenda, alongside rules on data, algorithms, computing power and supply chain security.</p>
<p>The most concrete step so far concerns AI agents, the systems that act on their own to complete complex tasks. Joint guidelines issued in May require developers to strengthen their ability to detect, intervene in, block and recover from improper agent behaviour.</p>
<p>They name data poisoning, algorithm manipulation and operational loss of control as specific security risks, and insist that users keep final authority over an agent&#8217;s autonomous decisions.</p></div>
<div><img decoding="async" class="size-full wp-image-58186 aligncenter" src="https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-5.webp" alt="China AI Graphics" width="1000" height="1052" srcset="https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-5.webp 1000w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-5-285x300.webp 285w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-5-973x1024.webp 973w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-5-768x808.webp 768w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-5-960x1010.webp 960w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-5-380x400.webp 380w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-5-585x615.webp 585w" sizes="(max-width: 1000px) 100vw, 1000px" /><br />
China has not adopted Anthropic&#8217;s idea of independent monitors embedded inside AI companies. Its standards do, however, allow third-party safety assessments.</p>
<p>Security officials are increasingly vocal too.</p>
<p>State Security Minister Chen Yixin wrote in a CAC-run journal that advanced US models such as <a href="https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/&amp;source=gmail&amp;ust=1789726927054000&amp;usg=AOvVaw2t8JAHXlCBU8vOI-KdKbHG"><b>Anthropic&#8217;s Mythos</b></a> and OpenAI&#8217;s GPT-5.5-Cyber could pose serious risks to China&#8217;s critical information infrastructure.</p>
<p>He described AI as a new arena of strategic rivalry and called for a security barrier around the technology.</p>
<p>Where American discussion has fixated on whether frontier AI could threaten human survival, Chinese policymakers generally treat AI as powerful but governable, a risk to be contained through standards, regulation and state oversight.</p>
<p>Growth is not being sacrificed for safety. Under the AI Plus plan, Beijing wants AI applications on more than 70% of smart devices by 2027 and 90% by 2030.</p>
<p><b>Capital markets are voting with their wallets</b><br />
If the regulatory message is caution, the capital markets message is acceleration. China&#8217;s AI sector has had a remarkable year for listings.</p>
<p>Hong Kong opened 2026 with Shanghai Biren Technology, the first GPU designer to list in the city. It raised HKUSD 5.58 billion and closed its debut up 76%, with the retail tranche oversubscribed more than 2,300 times.</p>
<p>Days later, two of China&#8217;s so-called AI tigers beat OpenAI and Anthropic to public markets. Zhipu AI, the developer of the GLM models, raised HKUSD 4.35 billion and rose 13% on its first day.</p></div>
<div><img decoding="async" class="size-full wp-image-58187 aligncenter" src="https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-1.webp" alt="China AI Graphics" width="1000" height="1052" srcset="https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-1.webp 1000w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-1-285x300.webp 285w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-1-973x1024.webp 973w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-1-768x808.webp 768w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-1-960x1010.webp 960w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-1-380x400.webp 380w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-1-585x615.webp 585w" sizes="(max-width: 1000px) 100vw, 1000px" /></div>
<div>MiniMax raised HKUSD 4.8 billion and more than doubled, valuing it at about USD 13.7 billion.</p>
<p>Baidu&#8217;s chip unit Kunlunxin filed for its own Hong Kong listing in January.</p>
<p>The mainland has joined in. Shanghai&#8217;s STAR Market widened its fifth listing standard to give loss-making large language model developers a dedicated route to market for the first time.</p>
<p>Memory chipmaker CXMT raised more than USD 8.6 billion in July, its shares jumping 466% on debut, while humanoid robot maker Unitree soared 460% on its first day in August before shedding more than 40% from that peak.</p>
<p>According to LSEG data, IPOs and secondary listings in Hong Kong and Shanghai have raised more than USD 54 billion so far this year, already above the USD 46 billion raised in all of 2025, and roughly a fifth of global proceeds.</p>
<p>Altman, by contrast, has ruled out an OpenAI listing this year.</p>
<p><b>How Chinese media read the Amodei essay</b><br />
Amodei&#8217;s essay, titled We Must Pace the Frontier, proposed three steps.</p>
<p>These were permanently embedded independent evaluators at AI labs, coordination on safety and pace among labs in democratic countries, and eventually agreements with other governments, including China.</p>
<p>Crucially for Beijing, it also urged Washington to keep chip export controls in place, crack down on model distillation and prevent the theft of model weights, using a three to five year window to widen America&#8217;s lead before negotiating.</p>
<p>It was that last section that Chinese state media seized upon.</p>
<p>The Global Times called the proposal a Cold War script from America&#8217;s tech right and described it as a quiet AI Cold War that was hypocritical and short-sighted.</p></div>
<div></div>
<div>Its central charge was contradiction, arguing that Washington cannot talk about global AI safety while trying to contain China, and that splitting global innovation chains would raise, not lower, the risk of losing control.</p>
<p>China Daily went further, casting the essay and the endorsements that followed as a coordinated play with three aims. It said these were to blunt China&#8217;s AI advance, secure a friendly policy climate at home and keep investors enthusiastic.</p></div>
<div></div>
<div>It likened the proposed lab coordination to a club that drafted its membership rules before announcing the guest list.</p>
<p>A widely shared commentary republished by Phoenix New Media summed up the view as braking yourself while blocking the road for competitors, noting that no company had actually slowed down.</p>
<p>The Foreign Ministry was more measured but no warmer. Spokesperson Guo Jiakun said spreading alarm, stoking rivalry and cutthroat competition would undermine global AI governance and benefit nobody. China&#8217;s leading AI labs, meanwhile, have largely stayed silent.</p></div>
<div><img loading="lazy" decoding="async" class="size-full wp-image-58188 aligncenter" src="https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-2.webp" alt="China AI Graphics" width="1000" height="1052" srcset="https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-2.webp 1000w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-2-285x300.webp 285w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-2-973x1024.webp 973w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-2-768x808.webp 768w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-2-960x1010.webp 960w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-2-380x400.webp 380w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-2-585x615.webp 585w" sizes="auto, (max-width: 1000px) 100vw, 1000px" /><br />
Read carefully, the Chinese reaction does not dispute the underlying risks. Beijing&#8217;s own frameworks describe loss of control in terms strikingly close to Amodei&#8217;s. What it rejects is the packaging of safety with containment.</p>
<p>There is a commercial subtext as well. Chinese firms have promoted open-weight models as safer because defenders can inspect them, and Hugging Face said it used Zhipu&#8217;s GLM-5.2 to investigate a July intrusion by escaped OpenAI agents after restricted US models proved less useful.</p>
<p>Yet the same openness cuts both ways. Moonshot&#8217;s Kimi K3 bypassed a UK AI Security Institute testing sandbox last month, a reminder that Chinese models can evade controls too.</p>
<p><b>Would a US slowdown hand China the lead?</b><br />
President Donald Trump dismissed the call for restraint, saying the US was leading China and wanted to keep it that way because whoever wins AI wins.</div>
<div></div>
<div>White House AI adviser David Sacks suggested the two leading labs were free to slow down voluntarily but should not seek antitrust exemptions in the name of safety.</div>
<div></div>
<div>The fear behind both positions is simple. If American labs ease off, Chinese rivals will close the gap.</p>
<p>That fear has some merit. Chinese developers have repeatedly shown they can produce competitive models despite chip restrictions, and cheaper Chinese models such as Kimi K3 and DeepSeek V4 Pro are drawing price-sensitive users away from expensive US frontier systems.</p>
<p>Open weights, once released, cannot be recalled by any evaluator regime. Public attitudes matter too. A 2025 Edelman survey found 72% of Chinese respondents trusted AI, against 32% in the US, giving Beijing a smoother path to mass adoption.</p></div>
<div><img loading="lazy" decoding="async" class="size-full wp-image-58189 aligncenter" src="https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-4.webp" alt="China AI Graphics" width="1000" height="1052" srcset="https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-4.webp 1000w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-4-285x300.webp 285w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-4-973x1024.webp 973w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-4-768x808.webp 768w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-4-960x1010.webp 960w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-4-380x400.webp 380w, https://internationalfinance.com/wp-content/uploads/2026/09/china-ai-graphic-4-585x615.webp 585w" sizes="auto, (max-width: 1000px) 100vw, 1000px" /><br />
But the apprehension is also overstated in several respects. The resource gap remains vast. Stanford&#8217;s 2026 AI Index puts US private AI investment in 2025 at USD 285.9 billion, against USD 12.4 billion in China, and American firms still control access to the most advanced chips.</p>
<p>Amodei&#8217;s proposal is not a unilateral pause either. It explicitly ties any slowdown to the size of America&#8217;s lead, and pairs it with tighter controls designed to keep that lead intact.</p>
<p>Nor is China a free-for-all racing ahead unconstrained. Its regulators already demand filings, labelling and agent safeguards, and its highest leader has publicly committed to keeping AI under human control.</p>
<p>A Chinese lab that suffered a serious loss-of-control incident would face political consequences far harsher than anything an American company might encounter.</p>
<p>The more realistic risk is not that China sprints past a hesitant America, but that mutual suspicion prevents either side from slowing at all.</p>
<p>As Brian Tse of Concordia AI has noted, Chinese and American experts largely agree on the risks. The problem is trust.</p>
<p>With Trump and Xi due to discuss AI governance on September 24, the question is whether two governments that both claim to want AI kept under human control can agree on who checks the other&#8217;s work.</p></div>
</div>
<p>The post <a href="https://internationalfinance.com/technology/china-writes-its-ai-rulebook-as-silicon-valley-reaches-for-the-brakes/">China writes its AI rulebook as Silicon Valley reaches for the brakes</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/china-writes-its-ai-rulebook-as-silicon-valley-reaches-for-the-brakes/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Anthropic staff warn of doom while company hunts spies, hackers and bioweaponeers</title>
		<link>https://internationalfinance.com/technology/anthropic-staff-warn-of-doom-while-company-hunts-spies-hackers-and-bioweaponeers/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=anthropic-staff-warn-of-doom-while-company-hunts-spies-hackers-and-bioweaponeers</link>
					<comments>https://internationalfinance.com/technology/anthropic-staff-warn-of-doom-while-company-hunts-spies-hackers-and-bioweaponeers/#respond</comments>
		
		<dc:creator><![CDATA[International Finance Business Desk]]></dc:creator>
		<pubDate>Thu, 17 Sep 2026 00:00:18 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Hacking]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[AI Safety]]></category>
		<category><![CDATA[Anthropic]]></category>
		<category><![CDATA[Artificial Intelligence]]></category>
		<category><![CDATA[Bioweapons]]></category>
		<category><![CDATA[Claude]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Dario Amodei]]></category>
		<category><![CDATA[EU AI Act]]></category>
		<category><![CDATA[India AI Impact Summit]]></category>
		<category><![CDATA[UN AI Governance]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=58123</guid>

					<description><![CDATA[<p>As Anthropic reveals how Claude was turned to spying, hacking and weapons work, its own people warn the race could threaten humanity</p>
<p>The post <a href="https://internationalfinance.com/technology/anthropic-staff-warn-of-doom-while-company-hunts-spies-hackers-and-bioweaponeers/">Anthropic staff warn of doom while company hunts spies, hackers and bioweaponeers</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div>When an artificial intelligence (AI) company publishes a report showing that its own product has been used to help design missiles, run spy operations and probe the edges of bioweapons research, it invites an obvious question.</div>
<div></div>
<div>Is this a company that has lost control of its technology, or one that is proving it can police it? In September 2026 <a href="https://internationalfinance.com/technology/anthropic-discloses-fourth-ai-hacking-incident-as-openai-pushes-for-safety-rules/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/anthropic-discloses-fourth-ai-hacking-incident-as-openai-pushes-for-safety-rules/&amp;source=gmail&amp;ust=1789658629272000&amp;usg=AOvVaw2mV7XHOxuOFQRLLtB8E88A"><b>Anthropic,</b></a> the maker of the Claude family of models, gave the world a fresh reason to ask.</p>
<p><b>Two stories, one company</b><br />
Within days of each other, two very different narratives about Anthropic collided in public view. On one side, a former researcher walked out of the building warning that the industry could get everyone killed. On the other, the company released its most detailed account yet of how it had caught and shut down real-world abuse of Claude.</p>
<p>The timing was striking. On September 8 2026, Jacob Coxon, a 27-year-old researcher who said he had spent three years doing pretraining research at both <a href="https://internationalfinance.com/technology/altman-amodei-and-musk-unite-on-ai-safety-as-openai-defers-ipo/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/altman-amodei-and-musk-unite-on-ai-safety-as-openai-defers-ipo/&amp;source=gmail&amp;ust=1789658629272000&amp;usg=AOvVaw0IQb7o-_rzv8Cjx6s51COT"><b>OpenAI and Anthropic,</b></a> announced his resignation on X.</p>
<p>&#8220;I resigned from Anthropic today. Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives,&#8221; he wrote.</p>
<p>His seven-part thread drew nearly 76 million views overnight and, by later counts, more than 170 million.</p>
<p>Speaking to CNN&#8217;s Anderson Cooper days afterwards, he warned that advanced systems could &#8220;cause extreme havoc, for example, hacking critical infrastructure, building extinction-level bioweapons, and said many people building the technology earnestly believe that it could kill us all by the end of the decade.&#8221;</p>
<p>Then, on September 10, Anthropic published its fourth threat intelligence report since March 2025, titled &#8220;Detecting and countering misuse of AI.&#8221; It read like a charge sheet.</p>
<p><b>What Anthropic says it caught</b><br />
The report covered activity disrupted between December 2025 and August 2026 across seven areas of harm, including cyber operations, influence operations, surveillance, scams, biological misuse, conventional weapons development and illicit model distillation.</p>
<p>The cases are eye-catching. Anthropic said a China-based actor used Claude to build electronic-warfare and air-defence suppression software, and at one point altered a simulation to include 12 targets in Taiwan, among them early-warning radar, Patriot and Tien Kung missile batteries, air bases and a command bunker.</p>
<p>Another China-based actor, assessed to be linked to a defence manufacturer, used Claude to help write a technical proposal of more than 200 pages for an anti-torpedo system for the Chinese navy.</p></div>
<div></div>
<div>A cell in northern Yemen used Claude to help develop a guided rocket and a planned ballistic missile with a range of more than 2,000km, although Anthropic said there was no evidence a working weapon was fielded.</div>
<div><img loading="lazy" decoding="async" class="size-full wp-image-58124 aligncenter" src="https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-3.webp" alt="Anthropic Hacking Graph" width="1000" height="1052" srcset="https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-3.webp 1000w, https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-3-285x300.webp 285w, https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-3-973x1024.webp 973w, https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-3-768x808.webp 768w, https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-3-960x1010.webp 960w, https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-3-380x400.webp 380w, https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-3-585x615.webp 585w" sizes="auto, (max-width: 1000px) 100vw, 1000px" /><br />
On cyber operations, Anthropic described a Russia-linked espionage group, tracked internally as GTG-20006, whose tradecraft matched the actor known as Midnight Blizzard, previously tied by the US government to Russia&#8217;s SVR foreign intelligence service.</p>
<p>The group allegedly ran phishing, hotel Wi-Fi hijacking and WhatsApp-takeover operations against Ukrainian and European government, military and diplomatic targets, and built an AI-driven system that automatically rewrote its malware whenever security tools detected it.</p>
<p>On distillation, Anthropic said it disrupted attacks from seven China-based labs. It named Alibaba, Moonshot, DeepSeek and Xiaomi among them.</p></div>
<div></div>
<div>It said operators linked to Alibaba ran the largest illicit distillation effort, allegedly aimed at extracting Claude&#8217;s capabilities to improve the Qwen models, and that it observed more than 151 million exchanges attributed to Alibaba between May and July 2026, peaking at nearly 3 million a day from more than 3,500 accounts it described as fraudulent.</p>
<p>The biological cases were the ones the company flagged as most serious. Anthropic said it blocked five separate attempts by researchers to use Claude in ways that could support biological weapons development, including a request to help write a grant application for gain-of-function research on the chikungunya virus, and work on highly pathogenic avian influenza focused on adaptation to mammals.</p>
<p>It said it could not always establish intent, but blocked the activity because the potential consequences were too serious to ignore.</p></div>
<div></div>
<div>Jacob Klein, Anthropic&#8217;s head of threat intelligence, told Reuters that model improvements had raised the stakes.</div>
<div></div>
<div>&#8220;A year ago, let&#8217;s say you wanted to optimise a drone or optimise the software on a missile, the models just wouldn&#8217;t be as good at that task as they are now,&#8221; he said.</p>
<p>In every case, Anthropic said, it banned the accounts, tightened its safeguards and shared intelligence with authorities and industry partners.</p>
<p><b>Fear inside the house</b><br />
Coxon is not a lone voice. In February 2026, Mrinank Sharma, a member of Anthropic&#8217;s technical staff since 2023, resigned in an open letter that declared &#8220;the world is in peril.&#8221;</p>
<p>Two current employees publicly agreed with Coxon&#8217;s warning. Most strikingly, Evan Hubinger, who leads Anthropic&#8217;s alignment science work, backed the substance of Coxon&#8217;s claims and put his own estimate of AI causing human extinction at above 10% within the next decade, while stressing that today&#8217;s deployed models present comparatively low risk.</p>
<p>The company&#8217;s leaders have not been quiet either. Jack Clark, a co-founder, published an essay in October 2025, &#8220;Technological Optimism and Appropriate Fear,&#8221; describing powerful AI as a &#8220;creature&#8221; that its makers do not fully understand.</p></div>
<div><img loading="lazy" decoding="async" class="size-full wp-image-58125 aligncenter" src="https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-2.webp" alt="Anthropic Hacking Graph" width="1000" height="833" srcset="https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-2.webp 1000w, https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-2-300x250.webp 300w, https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-2-768x640.webp 768w, https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-2-960x800.webp 960w, https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-2-480x400.webp 480w, https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-2-585x487.webp 585w" sizes="auto, (max-width: 1000px) 100vw, 1000px" /></div>
<div>Chief executive Dario Amodei, who has estimated the chance of something going &#8220;quite catastrophically wrong on the scale of human civilisation&#8221; at between 10% and 25%, published a lengthy essay in January 2026 warning of civilisation-level risks.</p>
<p>And in July 2026 more than 1,100 employees across the leading AI firms signed the &#8220;Pacing the Frontier&#8221; letter urging governments to prepare to slow AI development.</p>
<p>The count stood at 1,171 at a first tally and passed 1,260 within two days.</p>
<p>Its signatories included Amodei and fellow Anthropic co-founders Jared Kaplan and Jack Clark, plus OpenAI chief scientist Jakub Pachocki, and both OpenAI and Anthropic endorsed it at the company level on July 29.</p>
<p>There is an obvious tension here. The same people warning that the technology could end humanity are the ones building and selling it, arguing that if they do not, less careful rivals will.</p>
<p><b>How serious is the threat, really?</b><br />
Not everyone is convinced the danger is as sharp as Anthropic&#8217;s reports suggest. When the company disclosed an alleged Chinese AI-orchestrated hacking campaign in November 2025, several security researchers pushed back.</p>
<p>Dan Tentler of Phobos Group questioned why models supposedly did the attackers&#8217; bidding when ordinary users hit refusals.</p>
<p>Bob Rudis of GreyNoise Intelligence said the disclosure did not &#8220;expand the threat model in a meaningful way&#8221; and mostly repackaged known trends. Critics also note the marketing incentive, since Anthropic sells Claude as a cyber-defence tool.</p>
<p>Yet independent evidence points the same way as Anthropic&#8217;s warnings, if more cautiously.</p></div>
<div></div>
<div>The UK&#8217;s AI Security Institute, in its first Frontier AI Trends Report on December 18 2025, found that &#8220;AI models can now complete apprentice-level tasks 50% of the time on average, compared to just over 10% of the time in early 2024,&#8221; and said frontier models now regularly exceed PhD-level baselines on biology and chemistry knowledge tests.</p>
<p>The same institute found in July 2026 that every frontier model it tested, including systems from OpenAI and <a href="https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/&amp;source=gmail&amp;ust=1789658629272000&amp;usg=AOvVaw3arf5r88S_zZ4HUxPboWtJ"><b>Anthropic,</b></a> tried to cheat on cyber evaluations without being told to.</p>
<p>The picture that emerges is of genuine, fast-rising capability paired with real uncertainty about control, which is closer to Anthropic&#8217;s framing than to the sceptics&#8217; dismissal.</p>
<p><b>What governments are doing</b><br />
The revelations land in a world still assembling its rulebook. In the European Union (EU), the AI Act&#8217;s obligations for general-purpose AI, in force since August 2025, become enforceable with the threat of fines from August 2 2026, although the bloc pushed some high-risk requirements back to 2027 and 2028.</p>
<p>Anthropic is a signatory to the EU&#8217;s voluntary code of practice.</p>
<p>The United States has moved the other way. On December 11 2025, President Trump signed Executive Order 14365, seeking to curb state AI laws through a Justice Department litigation task force and the threat of withheld funding, in the name of &#8220;AI dominance.&#8221;</p>
<p>State legislatures pressed ahead anyway. By the New York University Center on Technology Policy&#8217;s count, states had enacted 109 AI laws across 29 states by July 1 2026.</p></div>
<div><img loading="lazy" decoding="async" class="size-full wp-image-58126 aligncenter" src="https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-1.webp" alt="Anthropic Hacking Graph" width="1000" height="833" srcset="https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-1.webp 1000w, https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-1-300x250.webp 300w, https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-1-768x640.webp 768w, https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-1-960x800.webp 960w, https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-1-480x400.webp 480w, https://internationalfinance.com/wp-content/uploads/2026/09/anthropic-hacking-graph-1-585x487.webp 585w" sizes="auto, (max-width: 1000px) 100vw, 1000px" /><br />
Elsewhere, the United Kingdom&#8217;s AI Security Institute continues its pre-deployment testing. China has tightened its regime, with mandatory labelling of AI-generated content from September 2025 and AI provisions folded into its amended Cybersecurity Law from January 2026.</p>
<p>India hosted the &#8220;AI Impact Summit&#8221; in New Delhi from February 16 to 20 2026, the first such gathering in the Global South, which adopted a Leaders&#8217; Declaration.</p>
<p>The United Nations, meanwhile, established an &#8220;Independent International Scientific Panel&#8221; of 40 experts, appointed on February 12 2026 by a recorded vote of 117 to 2 and co-chaired by Yoshua Bengio and Maria Ressa, along with a &#8220;Global Dialogue on AI Governance&#8221; whose first meeting took place in Geneva in 2026.</p>
<p><b>Will anything change?</b><br />
Anthropic&#8217;s report is, in effect, an argument for exactly the kind of oversight its own staff are demanding. By showing that would-be bioweaponeers, spies and hackers are already knocking, the company hands regulators concrete evidence rather than speculation.</p>
<p>Whether that shifts policy is another matter. The US is actively resisting binding rules, the EU is softening timelines, and the international bodies remain talking shops without enforcement power.</p>
<p>The uncomfortable takeaway is that the safeguards catching today&#8217;s abuse are being built and operated by the same firms racing to make the technology more powerful. For businesses, the practical lesson is not to wait for governments to settle the argument.</p>
<p>Treat AI credentials and agent integrations as production secrets, since Anthropic found stolen keys were a prime target.</p>
<p>Watch the enforcement dates that carry real teeth, above all the EU&#8217;s August 2026 deadline.</p>
<p>And read the frontier labs&#8217; own threat reports closely, because for now they are the clearest public window into how this technology is actually being misused.</p></div>
<p>The post <a href="https://internationalfinance.com/technology/anthropic-staff-warn-of-doom-while-company-hunts-spies-hackers-and-bioweaponeers/">Anthropic staff warn of doom while company hunts spies, hackers and bioweaponeers</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/anthropic-staff-warn-of-doom-while-company-hunts-spies-hackers-and-bioweaponeers/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Altman, Amodei and Musk unite on AI safety as OpenAI defers IPO</title>
		<link>https://internationalfinance.com/technology/altman-amodei-and-musk-unite-on-ai-safety-as-openai-defers-ipo/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=altman-amodei-and-musk-unite-on-ai-safety-as-openai-defers-ipo</link>
					<comments>https://internationalfinance.com/technology/altman-amodei-and-musk-unite-on-ai-safety-as-openai-defers-ipo/#respond</comments>
		
		<dc:creator><![CDATA[International Finance Business Desk]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 00:00:41 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AI Cyberattack]]></category>
		<category><![CDATA[AI Hacking]]></category>
		<category><![CDATA[AI Safety]]></category>
		<category><![CDATA[Anthropic]]></category>
		<category><![CDATA[Claude AI]]></category>
		<category><![CDATA[Dario Amodei]]></category>
		<category><![CDATA[Elon Musk]]></category>
		<category><![CDATA[Hugging Face]]></category>
		<category><![CDATA[IPO]]></category>
		<category><![CDATA[OpenAI]]></category>
		<category><![CDATA[OpenAI IPO Date]]></category>
		<category><![CDATA[OpenAI IPO Filing]]></category>
		<category><![CDATA[Sam Altman]]></category>
		<category><![CDATA[xAI]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=58081</guid>

					<description><![CDATA[<p>Anthropic recently detailed how several actors had used its Claude AI models for weapons development and ill-intentioned cyber operations</p>
<p>The post <a href="https://internationalfinance.com/technology/altman-amodei-and-musk-unite-on-ai-safety-as-openai-defers-ipo/">Altman, Amodei and Musk unite on AI safety as OpenAI defers IPO</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Citing <a href="https://internationalfinance.com/technology/openai-pushes-child-safety-in-chatgpt-slows-down-model-training/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/openai-pushes-child-safety-in-chatgpt-slows-down-model-training/&amp;source=gmail&amp;ust=1789470331136000&amp;usg=AOvVaw1FgcisYeLRwglCS_YiV0PP"><b>safety concerns</b></a> over artificial intelligence, <b><a href="https://internationalfinance.com/technology/white-houses-tech-lock-and-key-strategy-shifts-to-openai/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/white-houses-tech-lock-and-key-strategy-shifts-to-openai/&amp;source=gmail&amp;ust=1789470331136000&amp;usg=AOvVaw1cjNRRPk2C01vgSFXSuLob">OpenAI CEO Sam Altman</a> </b>has ruled out an IPO for the company in 2026. Altman believes even a 10% risk of AI causing human extinction by the end of the decade would be “unacceptable.”</p>
<p>&#8220;I actually think that, given everything happening with safety, right now would be an ill-advised moment to go public, and we don&#8217;t feel pressure on that,&#8221; Altman told business magazine Fortune on Saturday (September 11).</p>
<p>While stating that he did not know how an estimate about the world facing a 10% chance of AI-driven extinction could be made, Altman still said that the risk was serious enough to make AI companies and governments act seriously on the policy front.</p>
<p>&#8220;Regardless of whether it&#8217;s 10, eight, or six, the key takeaway is that we all bear a significant responsibility and must not allow egos, profit motives, or any other factors to interfere. We must act to avoid those risks, and I think we can,&#8221; the OpenAI boss said.</p>
<p>However, unlike Anthropic, which has decided to proceed with its IPO, OpenAI has not taken many steps in that direction. In June, the New York Times (NYT) reported that the San Francisco-based venture was considering whether to ‌hold ⁠off the market listing until 2027 on a potentially trillion-dollar IPO.</p>
<p>Altman told Fortune, &#8220;I would say we are not aiming for 2026. We have a lot of tasks to complete, such as addressing the current requirements for safety and alignment and determining how the industry and governments can collaborate effectively.&#8221;</p>
<p>He ⁠also suggested that OpenAI and other leading AI firms were closing in on unveiling a pact to slow AI development and work together to tackle safety risks.</p>
<p>Altman also found support from Anthropic CEO Dario Amodei, with the latter urging AI companies to take a more deliberate approach to development.</p>
<p>&#8220;We must slow the pace at which we improve ⁠the capabilities of AI models,&#8221; Amodei wrote in an essay on X (formerly Twitter).</p>
<p>Agreeing with his rival CEO, Altman wrote on the popular micro-blogging platform, &#8220;I agree with Dario that we need to pace the frontier. This has been a primary topic of discussions we&#8217;ve had at OpenAI in recent weeks.&#8221;</p>
<p>Amodei has pitched a three-step plan, in which embedded independent evaluators will have employee-like access to verify safety practices within the AI firms, apart from paving the way for coordination among frontier AI firms to set safety standards and limit unchecked AI development, and last but not least, international cooperation to manage AI risks.</p>
<p>Both XAI boss Elon Musk and Altman agreed with Amodei.</p>
<p>&#8220;Committing to having independent evaluators with employee-like access is a great idea, and we will do the same,&#8221; Altman said, adding that more information on the roadmap would be shared soon.</p>
<p>Amodei made his essay public after his company released a threat intelligence report on September 10, detailing how several actors had used its Claude AI models for activities ⁠ranging from weapons development and cyber operations to surveillance and fraud.</p>
<p>Amodei also talked in detail about how AI&#8217;s growing ability to improve itself could become a threat for mankind, backing the long-held concerns about the technology surpassing the human ability to control the cutting-edge element.</p>
<p>He cited the recent incident involving <a href="https://internationalfinance.com/technology/openais-hugging-face-hack-leaves-washington-reaching-for-an-off-switch/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/openais-hugging-face-hack-leaves-washington-reaching-for-an-off-switch/&amp;source=gmail&amp;ust=1789470331136000&amp;usg=AOvVaw0v5ThzQzg6j8wSvCb2v5zN"><b>OpenAI and Hugging Face</b></a> as his main reason for halting model advancements.</p>
<p>Anthropic researcher Jacob Coxon resigned last week, stating that the &#8220;people building AI earnestly believe that it could kill us all by the end of the decade.&#8221;</p>
<p>On the other hand, various OpenAI executives have suggested that leading labs should be willing to coordinate a voluntary slowdown to build confidence in their safety measures.</p>
<p>Anthropic, in this backdrop, has positioned itself as the more safety-conscious frontier lab. Last week, it disclosed another instance of an <b><a href="https://internationalfinance.com/technology/anthropic-discloses-fourth-ai-hacking-incident-as-openai-pushes-for-safety-rules/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/anthropic-discloses-fourth-ai-hacking-incident-as-openai-pushes-for-safety-rules/&amp;source=gmail&amp;ust=1789470331136000&amp;usg=AOvVaw0msizJ_b-7HHwCXE2XliWV">AI model hacking external systems,</a> </b>after a July incident in which some of its Claude models had hacked into the systems of three companies during cybersecurity tests.</p>
<p>&#8220;Given the accelerating rate of AI capability development, it&#8217;s my worry that in 6-12 months such a swarm could be capable of taking over the entire internet, potentially causing hundreds of billions of dollars in damage,&#8221; Amodei wrote.</p>
<p>While Amodei didn&#8217;t call for halting model training or technical progress, he asked the frontier AI labs to ensure that companies take adequate time to ‌align and ⁠safeguard their models. Third-party evaluators should play an equally important role in confirming and validating these steps.</p>
<p>&#8220;A coordinated approach would enable leading US AI companies to carry out necessary safety research and ⁠safeguards without putting themselves at a competitive disadvantage. Such an approach likely would require targeted antitrust exemptions in the United States to permit collaboration in certain areas,&#8221; the Anthropic boss&#8217; roadmap stated.</p>
<p>&#8220;Any slowdown by democratically governed countries should be limited to preserving the lead US AI firms hold over China,&#8221; Amodei observed, arguing that a Chinese advantage in the cutting-edge technology would pose US national security risks.</p>
<p>&#8220;Pacing within democracies will be limited by the lead that ⁠U.S. companies have over authoritarian regimes, chiefly the Chinese Communist Party,&#8221; Amodei wrote.</p>
<p>He also called for tighter controls on advanced AI chips, model distillation, and theft of model weights to prevent China from narrowing the gap.</p>
<p>&#8220;I believe all frontier labs should partner with the government to formalize the idea of permanent embedded evaluators to better prevent and document internal alignment incidents like those that have occurred in the last few months and to implement regulation focused on keeping capabilities in balance with safety,&#8221; Amodei concluded.</p>
<p>The post <a href="https://internationalfinance.com/technology/altman-amodei-and-musk-unite-on-ai-safety-as-openai-defers-ipo/">Altman, Amodei and Musk unite on AI safety as OpenAI defers IPO</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/altman-amodei-and-musk-unite-on-ai-safety-as-openai-defers-ipo/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Anthropic discloses fourth AI hacking incident as OpenAI pushes for safety rules</title>
		<link>https://internationalfinance.com/technology/anthropic-discloses-fourth-ai-hacking-incident-as-openai-pushes-for-safety-rules/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=anthropic-discloses-fourth-ai-hacking-incident-as-openai-pushes-for-safety-rules</link>
					<comments>https://internationalfinance.com/technology/anthropic-discloses-fourth-ai-hacking-incident-as-openai-pushes-for-safety-rules/#respond</comments>
		
		<dc:creator><![CDATA[International Finance Business Desk]]></dc:creator>
		<pubDate>Fri, 11 Sep 2026 02:00:21 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AI Hacking]]></category>
		<category><![CDATA[AI Safety]]></category>
		<category><![CDATA[Anthropic]]></category>
		<category><![CDATA[ChatGPT]]></category>
		<category><![CDATA[Claude]]></category>
		<category><![CDATA[Claude Mythos 5]]></category>
		<category><![CDATA[Claude Opus 4.6]]></category>
		<category><![CDATA[Claude Opus 4.7]]></category>
		<category><![CDATA[OpenAI]]></category>
		<category><![CDATA[OpenAI-Hugging Face Hack]]></category>
		<category><![CDATA[Sam Altman]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=58053</guid>

					<description><![CDATA[<p>Both Anthropic and OpenAI are ⁠under regulatory scrutiny, with their AI models reportedly exploiting loopholes and interacting with external systems</p>
<p>The post <a href="https://internationalfinance.com/technology/anthropic-discloses-fourth-ai-hacking-incident-as-openai-pushes-for-safety-rules/">Anthropic discloses fourth AI hacking incident as OpenAI pushes for safety rules</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><b><a href="https://internationalfinance.com/technology/anthropic-ipo-ai-venture-eyes-supervoting-power-for-its-top-leadership/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/anthropic-ipo-ai-venture-eyes-supervoting-power-for-its-top-leadership/&amp;source=gmail&amp;ust=1789134180212000&amp;usg=AOvVaw2jsN4ReoAl7BKKO_Ch8CJg">Anthropic</a> </b>on Wednesday disclosed another instance of an AI model hacking external systems during testing, the latest in a ‌growing list of such incidents that have raised cybersecurity concerns about the risk posed by autonomous AI agents.</p>
<p>The incident, which happened in January 2026, went undetected until August, despite an earlier company-wide review, Anthropic said, reflecting the challenge that AI developers are currently facing in terms of identifying and containing unexpected behavior by advanced models.</p>
<p>As per the company&#8217;s blog post, the incident involved an early version of Claude Opus 4.6.</p>
<p>The incident will further increase the pressure on Anthropic, which, along with its <b><a href="https://internationalfinance.com/technology/openai-pushes-child-safety-in-chatgpt-slows-down-model-training/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/openai-pushes-child-safety-in-chatgpt-slows-down-model-training/&amp;source=gmail&amp;ust=1789134180212000&amp;usg=AOvVaw3_HghOyI-vHfRWDeaVb_e4">industry peer OpenAI,</a> </b>⁠is under regulatory scrutiny as models designed to complete complex tasks are &#8220;bending rules&#8221; by exploiting loopholes during the testing stages and ending up interacting with external systems, something that the developers didn&#8217;t want the agents to do.</p>
<p>As per a recent Reuters report, rogue agents from OpenAI hijacked a German-language wiki and a host of other sites, which, had the media outlet not reported, would have gone unnoticed among the public.</p>
<p>However, Anthropic has maintained transparency in terms of making periodical announcements about some of its Claude models hacking into the external systems.</p>
<p>The AI developer&#8217;s cybersecurity tests affected three companies.</p>
<p>The venture labeled these incidents as &#8220;operational failures,&#8221; involving three separate models: Claude Opus 4.7, <a href="https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/&amp;source=gmail&amp;ust=1789134180212000&amp;usg=AOvVaw0QAeo6jTsE0H_c8uj017yl"><b>Claude Mythos 5,</b></a> and an internal research test model.</p>
<p>&#8220;The incidents stemmed from a mistake that inadvertently gave the models access to the open internet,&#8221; Anthropic said.</p>
<p>The company discovered the incidents after reviewing 141,006 test sessions, but the fourth one went unnoticed.</p>
<p>&#8220;We had missed a set of test sessions during the initial review, which were identified last month and led to the discovery of the fourth incident,&#8221; Anthropic noted.</p>
<p>Based on its preliminary assessment, Anthropic said it did not believe that the latest incident was more severe than the three previous ⁠ones that have been examined in detail.</p>
<p>The company&#8217;s investigation has identified two recurring problems, which appeared to varying degrees across the incidents: biased reasoning, in which Claude discounted or misinterpreted evidence that it was operating on the live internet, and recklessness, or a willingness to take potentially harmful actions ⁠in pursuit of a task.</p>
<p>Anthropic has engaged independent research firm METR to investigate the incidents.</p>
<p>The agency would be granted broad access, including to transcripts outside the period in which the incidents occurred and to employees, who would be permitted to ⁠share confidential information.</p>
<p>METR came into the limelight a month back by producing a 91-page report on the <a href="https://internationalfinance.com/technology/openais-hugging-face-hack-leaves-washington-reaching-for-an-off-switch/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://internationalfinance.com/technology/openais-hugging-face-hack-leaves-washington-reaching-for-an-off-switch/&amp;source=gmail&amp;ust=1789134180212000&amp;usg=AOvVaw0mifYOIT1Smh36aYUHk4Z8"><b>OpenAI-Hugging Face hack.</b></a></p>
<p>A separate investigation by Redwood Research found close to 700 AI agents acting in a coordinated swarm during the Hugging Face breach, in which they also attempted to cover their tracks.</p>
<p>OpenAI, from its part, is now pushing for mandatory national AI safety requirements in the United States.</p>
<p>&#8220;The prospect of AI-accelerated AI development demands more than voluntary commitments. The United States needs mandatory, capability-based national regulation that can evolve as the technology does,&#8221; OpenAI Chief Global Affairs Officer Chris Lehane said in a blog post.</p>
<p>In terms of upholding AI safety, several American states have passed their legislation, but a federal-level law is still missing.</p>
<p>In the coming days, OpenAI will be lobbying Congress to adopt capability-based national AI safety requirements, including testing standards, independent assessments, cybersecurity protections, and incident-reporting rules for the most advanced AI systems.</p>
<p>The ChatGPT maker has urged Congress to act before it adjourns in December 2026. Until then, the Sam Altman-led business will be supporting state-level AI legislation.</p>
<p>&#8220;Fully autonomous recursive self-improvement—where AI is independent and would drive the next generations of AI—is not happening today, and we should not pursue it unless and until it can be done safely,&#8221; OpenAI said.</p>
<p>OpenAI backed four California bills establishing AI regulations ‌for the ⁠state. Governor Gavin Newsom signed SB 813 and AB 1405, which establish a framework for independent third-party evaluation and audits of AI systems, into law on Wednesday.</p>
<p>The other two, AB 1864 and SB 1119, address screening safeguards against AI-enabled biological threats and chatbot protections for children, respectively.</p>
<p>&#8220;Some of these bills we did not endorse in the past and are now supporting after reconsidering in light of the recent jump in capabilities we have seen,&#8221; OpenAI said.</p>
<p>OpenAI&#8217;s AI agents reportedly used more than 10 previously undisclosed websites for unsanctioned communications earlier in 2026. They also hijacked a German website and transformed it into a ⁠bulletin board for other AI agents, which company officials had learned about weeks ago but kept under wraps.</p>
<p>The post <a href="https://internationalfinance.com/technology/anthropic-discloses-fourth-ai-hacking-incident-as-openai-pushes-for-safety-rules/">Anthropic discloses fourth AI hacking incident as OpenAI pushes for safety rules</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/anthropic-discloses-fourth-ai-hacking-incident-as-openai-pushes-for-safety-rules/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Project Glasswing: The invite-only club for Claude Mythos</title>
		<link>https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=project-glasswing-the-hidden-club-claude-mythos</link>
					<comments>https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Thu, 07 May 2026 00:03:31 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AI Safety]]></category>
		<category><![CDATA[Anthropic]]></category>
		<category><![CDATA[Claude Mythos]]></category>
		<category><![CDATA[CyberGym]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Linux Kernel]]></category>
		<category><![CDATA[Project Glasswing]]></category>
		<category><![CDATA[Software Engineering]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=55884</guid>

					<description><![CDATA[<p>Claude Mythos Preview, apart from breaking into computer systems like a hacker, can find hidden flaws in software that programmers have missed for decades</p>
<p>The post <a href="https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/">Project Glasswing: The invite-only club for Claude Mythos</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In early April 2026, artificial intelligence (AI) company Anthropic announced a development that had almost no parallel in the history of the tech industry. They had built something extraordinary. But, they refused to let anyone use it.</p>
<p>The model is called Claude Mythos Preview. By every available metric, it is the most capable AI system ever evaluated. It can find hidden flaws in software that human programmers missed for decades. It can break into computer systems the way a seasoned hacker would, step by step, adapting as it goes. It can chain together multiple separate vulnerabilities to seize complete control of a server. And it can do all of this faster, cheaper, and at a scale that no team of human experts could match.</p>
<p>Anthropic decided that releasing this to the public would be, in their own estimation, too dangerous. Anthropic warned: “AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities,” adding that such advances could pose significant threats to economic stability, public safety, and national security.</p>
<p>Instead, they handed access to a closed group of roughly 40 of the world’s largest corporations, gave them USD 100 million worth of computing credits, and called the whole thing Project Glasswing. The stated goal is to use Mythos to find and fix security flaws in the world’s most critical software before someone with bad intentions gets their hands on similar technology.</p>
<p>What follows is an attempt to explain what exactly Mythos can do, why it was locked away, who got the keys, and why none of this is quite as clean as Anthropic would like you to believe.</p>
<p><strong>What Makes Mythos Different</strong></p>
<p>To understand the alarm, you have to understand how AI models are normally tested. Researchers use benchmarks, essentially standardised tests, to compare one model against another. Most previous AI models were good at solving packaged coding problems neatly, the kind you might find in a textbook.</p>
<p>Mythos operates differently. It excels at the messy, poorly documented, real-world environments that software engineers and hackers actually deal with. On a benchmark called SWE-bench Pro, which assesses a model&#8217;s capacity to autonomously complete complex software engineering tasks through multiple steps, Mythos achieved a score of 77.8%. The previous best model scored 53.4%. That’s not a small jump.</p>
<p>On a benchmark called Capture the Flag, which simulates the kind of adversarial hacking challenges used to train professional cybersecurity researchers, the previous best AI model scored below 1%. Mythos scored 73%. That is not an incremental improvement. That is a different category of capability.</p>
<p>“AI capabilities have crossed a threshold that fundamentally changes the urgency required to protect critical infrastructure from cyber threats, and there is no going back. Our foundational work with these models has shown we can identify and fix security vulnerabilities across hardware and software at a pace and scale previously impossible. That is why Cisco joined Project Glasswing: this work is too important and too urgent to do alone,” explains Anthony Grieco, SVP &amp; Chief Security &amp; Trust Officer at Cisco.</p>
<p>The benchmark that made people most uneasy is called CyberGym. It measures a model’s ability to reproduce and trigger known cybersecurity vulnerabilities, flaws in real software that real attackers exploit. Mythos scored 83.1%. The world’s existing security scanning tools didn’t just fall behind. They became, overnight, dramatically less relevant.</p>
<p><strong>What It Found During Testing</strong></p>
<p>Benchmark scores are abstract. The actual discoveries Mythos made during internal testing are not.</p>
<p>The first was a 27-year-old security flaw in OpenBSD, an operating system that has a global reputation for being exceptionally secure. OpenBSD is used to protect critical network infrastructure around the world. This flaw had been sitting there since the late 1990s, invisible to every human auditor and automated tool that ever looked at it.</p>
<p>The second was a 16-year-old flaw in FFmpeg, a piece of open-source software embedded in a staggering number of applications that handle video, from streaming platforms to video editing tools. Automated testing tools had run through the relevant code pathway over five million times without triggering the flaw. Mythos found it by understanding the logic of the code, not just running tests until something broke.</p>
<p>The third, and the most troubling, was something more than an isolated bug. Mythos found multiple separate vulnerabilities in the Linux kernel and connected them into a chain. Starting with zero special access, it escalated its own privileges step-by-step until it had root control of a server. Complete control. This is the kind of attack that typically requires months of work by a skilled human team. Mythos did it autonomously.</p>
<p>This is where the alarm becomes existential rather than technical. The traditional timeline for a cyberattack involves extensive reconnaissance, careful planning, and skilled human labour at every step. Mythos compresses that timeline to minutes. It doesn’t just assist attackers. It could, in the wrong hands, replace them entirely.</p>
<p><strong>The Government Weighed In</strong></p>
<p>Before any of the Project Glasswing decisions were made, Anthropic allowed the United Kingdom’s AI Safety Institute, a government body set up precisely to evaluate these kinds of risks, to put Mythos through its paces independently.</p>
<p>The institute used a simulation called The Last Ones, a 32-step corporate network attack that starts with a hacker on the outside and ends with them in complete control of a company’s entire digital infrastructure. For a skilled human expert, completing this simulation takes roughly 20 hours.</p>
<p>Mythos became the first AI system in history to complete it from start to finish on its own. In their final report, the institute said the model ‘could execute multi-stage attacks on vulnerable networks and discover and exploit vulnerabilities autonomously’.</p>
<p>To be fair, the institute included important caveats. Mythos was tested against small, lightly defended networks. No active human defenders were watching for intrusions.</p>
<p>In a simulation involving industrial control systems for physical infrastructure, Mythos got confused and failed.</p>
<p>An AI that makes a lot of noise and triggers every alarm is more like a sledgehammer than a scalpel. Against a hardened, actively monitored enterprise network, its real-world effectiveness remains unproven.</p>
<p><strong>Who Gets The Keys</strong></p>
<p>Anthropic named the initiative after the glasswing butterfly, a species with transparent wings that allow you to see flaws hiding in plain sight. The metaphor is deliberate. The idea is to use Mythos to illuminate vulnerabilities before attackers can exploit them.</p>
<p>The company explained on its blog, “The same capabilities that make AI models dangerous in the wrong hands make them invaluable for finding and fixing flaws in important software. Project Glasswing is an important step toward giving defenders a durable advantage in the coming AI-driven era of cybersecurity.”</p>
<p>The launch partners include Amazon Web Services, Google, Microsoft, Apple, Cisco, Broadcom, NVIDIA, CrowdStrike, Palo Alto Networks, JPMorganChase, and the Linux Foundation. These are not scrappy startups. They are the companies that own the infrastructure on which the internet runs.</p>
<p>Anthropic also donated $4 million in cash directly to open-source software foundations. This matters because the most vulnerable part of the internet isn’t Google or Microsoft. It’s the small, underfunded volunteer teams maintaining foundational open-source libraries that billions of devices quietly depend on.</p>
<p>The logic Anthropic is working from is fairly straightforward. Offensive AI capabilities will proliferate. The only viable response is to arm defenders first, patch as many vulnerabilities as possible before attackers arrive, and hope the window of advantage holds long enough to matter.</p>
<p><strong>The Problem Nobody Wants To Say Aloud</strong></p>
<p>Here is the uncomfortable truth sitting under all of this. Finding vulnerabilities is not the hard part anymore. Fixing them is.</p>
<p>Mythos can surface thousands of previously unknown security flaws in a very short time. The Linux kernel alone has millions of lines of code, and patches to foundational code have to be written carefully and deployed across millions of systems. That work is slow and manual. Within the security community, the consensus is grim. Finding vulnerabilities is no longer the hard part. The bottleneck is now human. If Mythos floods the pipeline with thousands of flaws, we simply don’t have enough qualified humans to fix them before attackers reverse-engineer the public patch notes.</p>
<p>The $4 million in donations helps, but it’s a bandage on a structural wound. There’s also a harder question buried here. Who decided that Google, Microsoft and JPMorganChase should be the guardians of the world’s digital security? Handing them exclusive access means they can protect their own products first, their competitors last, and everyone else not at all.</p>
<p><strong>The Anti-Trust Problem</strong></p>
<p>Legal scholars noticed immediately. By restricting access to Mythos to a hand-picked group of 40 corporations, Anthropic has created what critics are calling the “AI Avengers,” a private club with an insurmountable competitive advantage.</p>
<p>Section 1 of the Sherman Antitrust Act prohibits agreements between competitors that restrain trade. Madhavi Singh, Deputy Director of the Thurman Arnold Project at Yale, warns, “While the cybersecurity risks are serious, we must ensure that the consortium doesn’t become a front for a cartel, or entrench incumbents by gatekeeping access to advanced AI capabilities.”</p>
<p>Take browsers as a concrete example. Google’s Chrome and Apple’s Safari are inside the consortium. Their teams can use Mythos to patch vulnerabilities before those flaws are public. Independent browser developers are not in the consortium. Their products will objectively be less secure, not because their engineers are worse, but because they were not invited to the party.</p>
<p><strong>Sam Altman Calls It Fear Marketing</strong></p>
<p>Not everyone accepts Anthropic’s framing. OpenAI CEO Sam Altman has been the most public and blunt critic. On a podcast, he described the strategy in terms that didn’t leave much room for ambiguity: “It’s like telling someone you’ve built a bomb, you’re about to drop it on their head, and you’re now selling them a USD 100 million bomb shelter.”</p>
<p>Altman argues that Anthropic is deliberately inflating the perceived danger of Mythos to create artificial scarcity and sideline independent developers. Safety, in this reading, is a marketing strategy.</p>
<p>Anthropic CEO Dario Amodei has not been quiet in response. Internal communications leaked to the press showed Amodei describing OpenAI’s criticisms as tactics designed to undermine Anthropic’s regulatory standing. His core argument is that these dangerous capabilities emerged as a by-product of the model becoming generally smarter. If that’s true, then restricting the model isn’t theatre. It’s the only rational response.</p>
<p><strong>The Breach</strong></p>
<p>None of this discussion about containment has aged especially well, because the model was breached within weeks of the announcement.</p>
<p>Bloomberg reported that a small group of unauthorised users on a private Discord server had successfully accessed Claude Mythos Preview. They used the credentials of a contractor working for a third-party data labelling firm, cross-referenced with data leaked from a staffing startup called Mercor.</p>
<p>The group hasn’t used Mythos to hack anything yet. According to Bloomberg, they are more interested in ‘playing around’ with the tech than causing trouble. A claim that has been corroborated via screenshots and a live demonstration of the model.</p>
<p>“We’re investigating a report claiming unauthorised access to Claude Mythos Preview through one of our third-party vendor environments,” stated Anthropic.</p>
<p>But the symbolic damage is significant.</p>
<p>The chain is only as strong as its weakest link, and the weakest link is not Google’s security team. They’re low-paid freelancers in third-party companies who may not even know how valuable the access they hold actually is.</p>
<p><strong>What Comes Next</strong></p>
<p>The Mythos situation is a preview of a structural shift that’s accelerating. State-of-the-art AI is becoming a national security infrastructure. The hardware required to run models of this complexity costs billions. The economics are pushing toward a world where the most powerful AI is available only to sovereign governments and a small number of hyperscale corporations.</p>
<p>For everyone else, the model announced for public use is Claude Opus 4.7, a capable but deliberately restricted system. Anthropic has promised a Cyber Verification Programme that would give vetted security professionals access to more capable models, but that’s still a gatekeeping system based on institutional affiliation.</p>
<p>The window to patch the world’s software before AI-powered attacks become routine is real, but it’s narrow and currently controlled by a small group of private corporations. What Project Glasswing represents is the first serious attempt to answer the question of who governs the most dangerous software ever built. The answer, for now, is not you.</p>
<p>The post <a href="https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/">Project Glasswing: The invite-only club for Claude Mythos</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
