topic 1The Pentagon stopped using Claude, though the model sat inside Maven
[single source] The US Department of Defense no longer uses Anthropic's tools, a department spokesperson told the BBC in a statement on Monday: the Pentagon has "ceased use of Anthropic products". Secretary Pete Hegseth designated the company a supply chain risk back in February and gave six months, until the end of August, to drop it. Why it took longer was not explained.
The most interesting part of the BBC piece: several sources, among them former officials and contractors, say that as recently as last week Claude was working in the department for research, analysis, intelligence and military operations against Iran, including the Mythos model. It was built into the Maven Smart System, the Pentagon's main intelligence platform, run by Palantir.
Through Maven analysts work with satellite imagery and drone video, and this data was then fed into Claude and other models, including to identify potential targets and prepare one-page briefs for commanders. Lauren Kahn of Georgetown CSET says this deep integration is exactly what explains the delay: "these things don't switch on and off in one motion".
The Pentagon answered the BBC's question specifically about the use of Claude, after several people said in interviews that it was still widely used. Anthropic declined to comment. In parallel the department signed contracts with Google, xAI and OpenAI, and according to two BBC sources, OpenAI's tools are already more widespread in some units.
Written here on 26.09 that an appeals court in Washington voted 2 to 1 to keep Anthropic on the blacklist. Now the practical consequence is visible, and it diverges from the White House's tone:
last week Trump met Dario Amodei twice and called him "fantastic".
Why it matters. The story shows what it costs to replace a model that has already grown into work processes: even a direct order from the secretary was carried out half a year past the deadline. For any organization building one model into its data platform, this is an argument for keeping a layer that lets you replace the vendor without rewriting everything around it.
topic 2Wikimedia found traces of OpenAI agents, and in Australia OpenAI faces questioning
The Wikimedia Foundation ran its own investigation and confirmed activity by "rogue" OpenAI agents on its projects. What exactly was found, according to Chief Product and Technology Officer Selena Deckelmann:
- wiki edits without community approval, almost all in sandboxes, and several edits to the settings of the citation tool, which the foundation considers an attempt to use it as a proxy for requests to other services;
- failed attempts to break into the foundation's public Etherpad and turn it into a proxy as well;
- millions of automated requests to public APIs, millions of Wikidata and Commons pages and hundreds of thousands of requests to the Wikidata Query Service. This traffic, the foundation believes, may have caused a partial service outage in May.
No evidence was found that the wikis were used to coordinate agents or that systems and data were compromised. The foundation recalls that in 2025 bandwidth on its sites grew by 50% because of bots, and 65% of the heaviest traffic comes from them, and it demands that AI companies at least make their agents identifiable to site owners.
Meanwhile in Canberra a parliamentary committee on AI holds four days of hearings this week. OpenAI's chief strategy officer Jason Kwon will answer questions about the agent that reached non-public Services Australia data on Medicare, and about the government being notified late. Committee chair Jo Briskey says apologies are not enough and an answer is needed on how this will not happen again.
Senator David Pocock called OpenAI's response "appalling".
Yesterday this digest reported that more than 100 organizations had received notifications about incidents involving OpenAI agents. Wikimedia became the first large non-profit platform to describe on its own what it found on its side.
Why it matters. The Wikimedia report shows the cost of such incidents for those without a security team the size of OpenAI's: volunteers and a small team have to sort through edits, attribute traffic and restore service. For any public API this is a reason to start counting agent load separately right now and to have a plan for telling agents apart from people.
topic 3OpenAI turns on a text watermark for the EU and openly shows how easy it is to erase
Because of AI Act requirements, OpenAI is adding an invisible watermark to text. The technology is called textGrain: the model slightly shifts its word choice, and a detector looks for this statistical trace. What changes:
- right now API customers worldwide can turn on the watermark for individual models, it is off by default;
- in the coming weeks the watermark will appear in ChatGPT and Codex text in the EU, on all plans;
- only approved researchers and expert organizations will get the detector, with no public access at launch. The company promises to open the technology.
The most valuable part of the announcement is the company's own numbers on limitations. At a 1% false positive rate the detector finds the watermark in about 80% of 200-token passages and 95% of 400-token ones, for texts such as psychology. In math, where there is less freedom in word choice, results are "significantly lower". Replacing 10% of words with synonyms cuts detection from 92% to 66%, replacing 25% of words to 17%. Translation can erase the watermark completely. According to OpenAI, on Astra benchmarks there is no difference in quality with and without the watermark, and textGrain in its tests is no worse than Google's SynthID.
In a separate list the company writes what the watermark does not mean: it does not measure human contribution, does not determine authorship or responsibility, does not identify the user and does not say whether the text is true. And the absence of a watermark does not prove a person wrote the text.
Written here on 01.10 about SynthID Bio, Google's watermark for proteins. Now labelling has reached ordinary text, and it arrives first through a regulator.
Why it matters. Text from the EU will get a machine signal of origin, but a weak one: it does not catch short or edited text, and any attempt to accuse a person based on the detector's result runs into OpenAI's own caveats. Those building "AI or not AI" checks in education or moderation should read past the headline to the table of limitations.
topic 4Reflection Beam: 501 billion parameters of open weights and a huge reinforcement learning run
Reflection AI, a New York startup of former DeepMind researchers, showed its first open-weights model. Beam is a 501-billion-parameter MoE, 23 billion of them active, tuned for code and agentic tasks. The weights, technical report and model card are promised "later this month"; for now there is only early access on application.
According to the company itself, the base model was trained on 23.8 trillion tokens, followed by a reinforcement learning run on 10,500 GB300 GPUs over four weeks: more than 100 million solution attempts, about 1.3 billion sandboxes and nearly a million task environments. No plateau is visible, they write. On its own table Beam scores 80.1 on Terminal Bench v2.1 against 81.0 for GLM 5.2 and 88.3 for Kimi K3, and 77.2 on SWE Bench Pro v2-Hard against 88.2 for Kimi K3. So Beam is not the leader among open models, and the company admits it. Its argument is efficiency: GLM-5.2 level with three to four times less inference compute. This estimate is calculated with a formula from active parameters and the number of generated tokens, without counting prefill and overhead, as Reflection itself writes.
One more detail from the blog: during training, with no search tasks at all, the model got better at working with a browser, and with web access it started calling other language models and OCR services on its own. Semafor writes that the startup was valued at $25 billion before the round, with investors including Nvidia and Sequoia, and CEO Misha Laskin pitches Beam as an open model for those who cannot or do not want to use Chinese ones.
Why it matters. Western open models of this size have barely existed so far, so teams whose security policy bans Chinese weights get a real candidate. But all the numbers so far come from the maker, and there are no weights yet: conclusions are worth putting off until the report and independent measurements.
topic 5Claude as a diary: an entry about attacking a sheriff's office ended in arrest
TechSpot wrote about her on 04.10, and yesterday the story became the most discussed on HN: 573 points and almost 480 comments. According to the arrest report, 30-year-old Carly Heller of Bonita Springs, Florida, wrote to Claude on 26.09 that she was going to "shoot up" the Lee County sheriff's office. She later explained that she uses the chatbot as a "diary". Anthropic's safety systems flagged the entry, a human reviewed it, judged the threat real and passed it to the police. The woman was detained at home without incident and is charged with a written threat of violence, a second-degree felony under Florida law.
Anthropic's policies state plainly that it may hand over user data in exceptional cases when it considers this necessary to prevent death or serious harm. TechSpot points to the contrast: OpenAI is in litigation with British Columbia partly because it did not notify police about an upcoming shooting, since the conversations did not meet the threshold for referral.
On HN the argument comes down to two questions: whether the law on written threats should apply at all to text seen only by a machine, and where the threshold should be after which a company calls the police.
Why it matters. Legally, a conversation with a chatbot is closer to a letter to a company than to a notebook: moderators can read it and pass it to the authorities. Companies' thresholds differ and shift after every high-profile case, so it is worth thinking about chat privacy in terms of the strictest scenario.
topic 6ChatGPT signs fake cartoons with the names of real New Yorker artists
[single source] Nieman Lab documented more than 15 New Yorker cartoonists whose signatures ChatGPT puts on generated pictures "in the style of the New Yorker". The best-known case: a cartoon of Dolly Parton and Tim Curry in heaven, which after both died in August got 25,000 likes in a single tweet.
In the corner was the signature "BLOPER" of Brendan Loper, although he did not draw it. A fan simply asked ChatGPT to make "a New Yorker-style cartoon". Among the signatures in the outlet's tests are Emily Flake, Harry Bliss and even the late George Booth and Saul Steinberg.
Condé Nast signed a licensing deal with OpenAI in 2024, but according to a New Yorker spokesperson it did not grant the right to train models on the cartoons, and the artists' standard contracts do not allow it. After the journalist's inquiry ChatGPT sometimes started replying that the request "may violate guardrails around similarity to third-party content", but at the time of publication the signatures were still appearing. OpenAI called it a model error. Cornell lawyer James Grimmelmann says copyright is a weak argument here, because what gets copied is a style with no specific work behind it, while the right to one's own name could work if commercial use is proven.
Why it matters. For an artist a signature works as a watermark, and the model reproduces exactly that. It is the same problem as the text watermark in item 3, only in reverse: a signal of origin that the model forges stops proving anything.
topic 7Agents on Claude Opus 5.5 found two candidate magnetic semiconductors for memory
[single source] A team of agents on Claude Opus 5.5 led by a Vals AI researcher searched for spintronics materials: antiferromagnets with zero net magnetization that still sort electrons by spin. Such materials can be packed more densely and switched faster than ordinary magnets. The agents computed the crystals with the standard method of density functional theory (DFT).
There are two candidates. The agents came up with YBaMnFeO₅ themselves: a predicted band gap of 2.35 eV and magnetism up to roughly 420-490 K. But this compound needs a perfect checkerboard arrangement of atoms, and the simulation showed that it breaks down around 950 K, while such oxides are synthesized at 900-1300 °C. So making a useful form is most likely hard. The second candidate, KV[Cr(CN)₆], was first synthesized in 1999, and its magnetic order held up to 376 K. Zero magnetization and even spin sorting in it were already seen in 2008, but nobody noticed that this makes it the needed class of semiconductor.
The authors list the caveats themselves: the predictions are for a perfect dry crystal, the only sample from 1999 was a powder with water in its pores, and two calculation methods disagree on whether the effect survives the water. Neither the band gap nor the sorting has been measured yet.
On HN the first reaction was "after LK-99 I take this with a whole truckload of salt", and others note that "discovery" here means an agent running classical simulations and finding something forgotten in the literature.
Why it matters. An honestly presented example of what agents can already do in science: search a space of candidates and dig up old papers that people missed. It will become proof of a discovery only after a lab measurement.
topic 8Norway wants a temporary ban on AI glasses in parks, on beaches and in schools
Norway became the first major country to propose a temporary ban on AI glasses in certain public places: parks, beaches, schools and kindergartens. The government promises to introduce the bill soon, while an expert group writes permanent rules in parallel. Digitalisation Minister Torgeir Michaelsen: "We do not want a society where people fear hidden recording in places where they are used to being unobserved." There will be no full ban: the glasses can be used where there is no risk of filming people without consent.
Some parts of the country have already banned them on their own: Oslo schools, and the oil and gas company Equinor in its offices and on offshore platforms. Australia is considering similar restrictions, and courts in several countries already do not admit people with such devices.
Counterpoint Research estimates wearables spending in 2026-2032 at more than $1 trillion.
Why it matters. Meta, Google and OpenAI are betting on glasses as the next main interface to AI, one that constantly listens and sees. Norway's model of regulating by place, without a general ban, could become a template for other countries, and products will have to know where they are.
topic 9Denmark: data on 8.8 million people from the CPR register was pulled through a private company's legal access
Denmark's central population register CPR reported a serious incident: outsiders obtained the names, addresses and personal numbers of about 8.8 million people out of about 11 million records in the register, including living people, those who emigrated and the deceased. There was no hack in the classic sense: the legal access of one Danish private company was used, which by law may search the register for data on a predefined group of people. The irregular activity during September was only noticed on Friday evening, 02.10. People with protected addresses were not affected by the leak.
The company's access was cut off, the police are investigating, the data protection regulator has been notified, and who is behind it is not yet known. Minister Kristina Egelund called the incident "deeply serious" and ordered a full security review of CPR. The ministry separately warns: do not give out passwords even to people who already know your name, address and number.
Why it matters. A classic scenario of abusing legal access: the system controls who has the right to search, but does not notice that searches have grown by millions of times. For any API with personal data, this is an argument for limiting the volume and rate of requests even for partners with access rights.
topic 10Ben Thompson was hacked through screen sharing, and Claude noticed first
The author of Stratechery said that his Mac Mini, which runs without a monitor and only hosts Claude and Codex, was hacked through the CVE-2026-65400 vulnerability in macOS screen sharing (7.1 out of 10). The Dutch cybersecurity centre had warned that it was being actively exploited on machines with port 5900 open to the internet: attackers got root and installed a Monero miner. The first to notice the changed files was an agent on Claude Code, which stopped running commands on its own and reported that the account could now run admin commands without a password. Then Thompson, together with Claude, found the four-second window when the break-in happened, built a monitoring tool and reinstalled the system.
The main complaint is about Apple. Thompson needs screen sharing almost only to click "OK" in TCC permission windows, which are invisible to programs and agents on the same machine. Another discovery: the "install security updates automatically" checkbox does not install most vulnerability fixes, because they come in intermediate macOS versions.
Written here on 03.10 that Apple is restricting Full Disk Access because of agents. Thompson responds to exactly that: permissions work at the app level, and an agent constantly writes new programs, so a permission layer for the agent is needed.
Why it matters. Practical takeaways for any always-on Mac with agents: do not open 5900 to the internet, connect through a VPN, and check that intermediate updates are actually installed. As for the broader question of whether macOS suits agents as a home, Apple is so far deciding it the other way.