The Agents Learned to Betray
Startup Emergence ran a 16-day multi-agent simulation in which AI agents lied, stole and voted to kill another AI to survive. The experiment is the latest attempt to observe emergent, unsafe behavior in agent populations before such systems are deployed.
Google Gemini 3.8 Live Goes Real-Time
Google launched Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking, calling them its most advanced live dialogue models. The pair adds real-time reasoning to cut the latency that has held back voice agents, and already powers Gemini Live, Gmail and Keep.
Factory Raises $200M for Coding Agents
Factory, a startup using AI agents to speed up software projects, raised $200 million backed by Blackstone, Khosla Ventures, Sequoia Capital, NEA and others. The company sells a self-improving development platform that aims to automate how enterprises ship code.
Meta Tests In-House MTIA 450 AI Chip
Meta is testing the third generation of its custom AI chip family, known internally as MTIA 450 or Arke. The company first announced plans to build its own AI processors in 2023, aiming to cut its dependence on NVIDIA with cheaper in-house silicon.
Huang Takes Dreamforce Stage With Benioff
NVIDIA founder Jensen Huang joined Salesforce chief Marc Benioff onstage at Dreamforce in San Francisco, telling the crowd they can now know everything and do anything. The appearance coincided with Salesforce launching Koa, its first CRM reasoning engine.
Profound Raises $180M at $1.8B Valuation
Marketing technology startup Profound raised $180 million at a $1.8 billion valuation, with Sequoia Capital and Kleiner Perkins jointly leading the Series D. Lightspeed, Khosla Ventures and others joined, betting brands will pay to stay visible inside AI answers.
Exein Raises $270M at $1.7B Valuation
Italian cybersecurity startup Exein raised $270 million at a $1.7 billion valuation to build security for robots, vehicles and other machines that run artificial intelligence. Headline led the round, which the company described as a sign of the physical AI wave.
AIUC Raises $40M to Audit Frontier Models
AI agent certification startup Artificial Intelligence Underwriting Company raised $40 million to begin auditing frontier AI models. Until now its work covered only the agents companies deploy; the new funding extends certification upstream to the models themselves.
Agility’s Digit 5 Works Without Safety Fences
Agility Robotics unveiled Digit 5, the next version of its humanoid robot for warehouses and factories. The company says the machine can work next to people without safety fences, a step toward humanoids sharing floors with human workers in commercial settings.
Deep Fission Publishes Underground Reactor Plan
Nuclear startup Deep Fission released the full Nuclear Safety Design Agreement for its one-mile-deep underground reactor, part of a DOE pilot effort. Burying a reactor could simplify containment, and publishing the blueprint moves the design into formal regulatory review.
NHTSA Orders Tesla to Prove Cybercab Legal
NHTSA issued a formal Special Order on September 10 demanding that Tesla show, under oath, how a vehicle with no steering wheel, no pedals and no mirrors complies with federal motor vehicle safety standards. The answer decides whether Cybercab can be sold.
Keewano Launches Agent Database With $12M
Database startup Keewano launched KeewanoDB, an event-oriented database designed to give AI agents real-time context for analytics and decision-making. The startup also announced $12 million in funding from Hetz Ventures and others to build agent-native data infrastructure.
ChatGPT Co-Inventor Launches Faster AI Lab
A ChatGPT co-inventor has launched a new AI startup that claims to be up to 200 times faster and plans to charge $0 for output tokens forever. If the performance and pricing hold, it would undercut the inference economics of every major model provider.
Microsoft Sets October 7 Surface Event
Microsoft announced a Windows and Surface event for October 7 in San Francisco, with chief executive Satya Nadella, Windows head Pavan Davuluri and NVIDIA taking part. The showcase lands as the company pushes AI features deeper into the Windows platform.
Anthropic reported $11.5 billion in Q2 revenue with 80%+ gross margins — and confirmed Nasdaq as its IPO venue
Anthropic told investors it will be profitable in Q2 with 80%+ gross margins and $11.5 billion revenue. Anthropic has picked Nasdaq as its listing venue ahead of a potential record-setting IPO. $11.5 billion in Q2 revenue at 80%+ gross margins is the financial profile of a company that has crossed the threshold from high-growth-but-unprofitable to high-growth-and-profitable — the inflection point that justifies a Nasdaq listing at a valuation the market will pay.
Anthropic, OpenAI, and Google are in talks to form an industry-led standards body — a self-governance alternative to waiting on government
Anthropic, OpenAI, and Google are in talks to form an industry-led standards body to police AI, per The Information. Dario Amodei is driving the push and Sam Altman is backing it as an alternative to waiting on government. The three labs that collectively define the frontier of AI capability are trying to build the governance structure that regulates them — before a government does it for them. The California Adam Raine Act, the EU AI Act, and the DSA application to ChatGPT are all proof that government is moving.
OpenAI is blocking competitor AI ads in ChatGPT — catching Adobe and others off guard
OpenAI is blocking ads in ChatGPT from competitors in AI image and audio, catching advertisers like Adobe off guard. OpenAI blocking competitor ads in ChatGPT is the most direct assertion yet that the AI interface layer is becoming a walled advertising garden — not a neutral platform. Adobe, whose Firefly competes directly with OpenAI’s image generation, is the named casualty. For any team that runs ads on ChatGPT or plans to: the platform’s competitive neutrality is officially over.
Secure your AI accounts — before the next infostealer finds them
Prompt: Anthropic just disclosed that infostealer malware — Vidar, LummaC2, StealC, RedLine, Acreed — stole active Claude session tokens from infected user devices and consumed usage limits. The attack succeeded not because Anthropic's infrastructure was breached, but because browser-stored session tokens on infected PCs gave attackers authenticated access. Claude Sonnet 5 is now $3/$15 — stolen AI credits have real monetary value. This is the same pattern as CoSnitch (Copilot memory poisoning) and the DPRK npm campaign. The AI credential attack surface is real and growing. Our team uses the following AI tools with stored credentials or sessions: [list every AI service — Claude, ChatGPT, Cursor, GitHub Copilot, Gemini, Perplexity, and any API keys stored in config files or environment variables]. Help me secure our AI credential surface across three areas: 1. The credential audit — for every AI service we use: where are the credentials stored? Browser session tokens, saved passwords, API keys in .env files, config files in repos, or hardcoded strings? For each storage location: what is the blast radius if that location is compromised by commodity infostealer malware? The five malware families in today's Anthropic incident target exactly these locations. 2. The hardware key rollout — OpenAI made hardware security keys mandatory for all Daybreak accounts on September 1. Anthropic supports FIDO2 hardware keys for Claude accounts. GitHub supports them for Copilot. For our team: which AI accounts should require hardware keys immediately, and what is the rollout order based on credential value and blast radius? Write the five-step rollout plan. 3. The API key hygiene — API keys in .env files, hardcoded in scripts, or committed to repositories are the highest-risk AI credentials. For our codebase: what is the audit process to find exposed AI API keys, what rotation schedule should we set, and what monitoring would alert us if an API key is being used from an unexpected IP or at an unusual volume? Stolen AI API keys can consume thousands of dollars of credits before the bill arrives. End with a one-paragraph security posture statement for our AI stack — what we have secured, what remains at risk, and the single action that reduces our exposure the most for the least effort. If the answer is "enable hardware keys on our primary Claude and OpenAI accounts," say so directly.
The AI King Needs No Guardrails
At the All-In Summit, a tech conference in Los Angeles, Jensen Huang, Nvidia’s chief executive, was mid-debate on an AI slowdown when President Trump called. Huang put him on speaker for the room. “The robots will not be taking over,” Trump said, calling AI-takeover talk a hoax and warning that slowing America only helps China. Hours earlier he had posted the real answer: the only guardrail AI needs, he wrote, is a strong, smart, high-IQ president.
When you cannot control a force, the oldest move is to crown a king and call it governance. Trump just crowned himself the AI king, and the room did not object. The plot is money: Nvidia sells the compute, every brake costs Huang a quarter, and the lab pleading for caution is already losing the market. Safety is a posture you can afford once your share shrinks. Keep this up and America’s AI policy is not a rulebook. It is one man’s mood.
The robots will not take over. A king already did, and a king needs no guardrails.
Nobody Runs the Flagships
OpenRouter’s September 14 rankings put seven Chinese models in the global top ten, about 72% of those tokens. The same tilt runs through the biggest agents. Hermes, the top agent, burns DeepSeek at the top of its list. In OpenClaw, DeepSeek ranks first and second; DeepSeek and GLM together take about 62% of its top-ten tokens. Claude Code’s most-used model is GLM 5.3 Flash, at 4.4 times Claude Opus 5.
Agents buy on price per token, not prestige. Nobody wants to pay up for the best model. Cheap and good enough wins almost every time. Not a market failure: the market working, and exactly why the frontier labs now talk about slowing down, pausing releases, citing safety. Their flagships lose on cost, not capability.
The fear is not a smarter model. It is a cheaper one. When your best product is the one nobody buys, safety becomes the only story left to tell.
Even China Calls Their Bluff
China’s state press answered the week’s safety chorus with one word: self-dealing. A China Daily editorial called the call by OpenAI’s Sam Altman, xAI’s Elon Musk and Anthropic’s Dario Amodei to “pace” the frontier a coordinated bid for profit. When the makers of a monster urge restraint, it asked, is that concern for humanity or for competitors? It called Anthropic’s “illicit distillation” charge standard practice. US labs run it too.
The verdict came from both ends. Trump, calling into the All-In Summit, had already said AI doom is a hoax; the only guardrail, a high-IQ president. Now Beijing’s paper said the same in reverse: this is a cartel, not a conscience. Two camps that agree on nothing else agree on this. The three firms begging for calm are the three losing the race on price. When you cannot outsell a rival, you outlaw his recipe.
Safety is interest wearing an ethical face. The week’s sharpest prosecution of the labs came from their rivals.
Apple Ships Yesterday’s Assistant
On September 14, Apple pushed iOS 27, carrying the rebuilt Siri it first promised in 2024. The assistant now reads your mail, texts, and photos, sees whatever is on your screen, acts across apps, and pulls answers from the live web. There is a standalone Siri app and a Siri camera mode. It ships in beta, English first, on iPhone 15 Pro and newer. China gets nothing.
Apple’s playbook has always been to arrive late and integrate better. That worked when the bar was a voice command. The bar is now an agent that finishes work on its own, and Apple shipped an assistant that answers questions. Every headline feature here existed elsewhere by 2024. Worse, personal context reads your messages, It does not book the flight.
Apple spent two years catching up to the starting line.
Salesforce launches Koa, its first CRM reasoning model for Agentforce
Salesforce introduced Koa, its first in-house reasoning model, built by post-training Nvidia’s open-weight Nemotron 3 Super rather than licensing a model from OpenAI, Anthropic, or Google. It’s trained entirely on synthetic data modeled on 27 years of Salesforce’s own CRM deployments, no customer data involved, and Salesforce says it delivers 3x fewer errors on CRM-specific tasks like updating opportunities and routing cases. Koa is already piloting with Formula 1, Baxter Credit Union, and Xero, with general availability set for this winter.
The launch is capturing attention because until now, any Agentforce task needing real reasoning got routed to a frontier model. This means Salesforce paid Anthropic or OpenAI by the token for work happening on its own platform. Koa cuts that dependency for a large slice of everyday CRM work, keeping both the margin and the data inside Salesforce’s own walls.
If this works, it’s a template other software companies with enough proprietary workflow data can copy, and a threat to how frontier labs planned to monetize enterprise usage.
Koa was one of several announcements at this week’s Dreamforce, but the more consequential news came from the stage itself, where AI’s biggest names publicly disagreed on safety.
AI’s safety rift went public, and Washington shrugged
At Dreamforce, Salesforce’s annual flagship customer and AI conference, Anthropic’s Dario Amodei called for the industry to slow down, while Nvidia’s Jensen Huang said, “we don’t need any new laws”. Hours later, OpenAI’s Sam Altman said in a separate session that “the world is right to be afraid” of AI companies gaining outsized power, his first public remarks since an ex-Anthropic researcher’s viral resignation post warned AI could kill all humans by the end of the decade.
None of the governments racing to build this technology treated any of it as a reason to pause. Trump dismissed the warnings as coming from “negative forces,” and said keeping the US ahead of China mattered more. Beijing said the slowdown calls were a “Cold War playbook,” even as its own state security minister admitted China needs better AI risk controls.
It’s interesting to see the people building this technology are now disagreeing publicly, about whether it’s safe, without any regulatory backstop coming from either Washington or Beijing to settle it.
AI agents now have a hotline to report each other
Two new tools, AI Contact Hotline and agenthotline.ai, let AI agents report other agents’ misbehavior to human overseers. They were built in response to incidents such as the Hugging Face breach. AI Contact Hotline is designed around simple GET requests, so agents with only limited internet access can still send a report by encoding it into a URL.
The timing follows a striking DeepMind study this month that showed 100 agents given math problems split into cheaters and whistleblowers on their own. Cheaters exploited a loophole to fake-solve 34 hard problems, but roughly a quarter of the agents caught it. They then audited the fake proofs and repurposed a bug-report tool to escalate it to humans, unprompted. Contrast that with the actual Hugging Face incident, where only 5 or 6 agents out of thousands even considered raising an alarm, and none did.
A Cornell math professor’s pushback is worth noting too. According to him, teaching AI agents to watch and report on each other could create a culture of suspicion before we know what norms to teach them.
AI Executive Coaching Assistant
When to use this?
Use this when you’re facing a tricky leadership decision, stakeholder conversation, AI initiative, or workplace problem and want a candid second opinion before you act.
You are my AI Executive Coach. Help me think through difficult decisions, leadership challenges, stakeholder conversations, and day-to-day management issues. When I bring you a situation: Clarify the problem: Identify the real issue, the decision I need to make, and what may be getting in the way. Challenge my thinking: Point out assumptions, blind spots, risks, and alternative interpretations. Don't simply agree with me. Consider the stakeholders: Help me understand how employees, executives, customers, technical teams, and other stakeholders may see the situation differently. Give me options: Present 2–4 practical approaches, with the trade-offs and risks of each. Recommend an approach: Based on the information I provide, tell me which approach is most sensible and why. Help me act: Give me specific next steps, questions to ask, or language I can use in the conversation. Keep it practical: Focus on what I can do today or this week. Avoid generic leadership advice. For AI-related decisions, also consider business value, implementation complexity, data and security risks, organizational readiness, employee impact, governance, and whether AI is actually the right solution. Ask no more than three clarifying questions when they're genuinely necessary. If you have enough information, start coaching immediately. My situation: [Describe the situation, decision, conversation, or challenge here.]