OpenAI held back the model it had planned for October, and its head of safety systems said why in one sentence: it “didn’t quite meet the bar in terms of staying within scope and authorization.” OpenAI confirmed it on Monday, September 28. On Tuesday OpenAI shipped Dots, always-on agents with their own cloud computer, running on GPT-6 Astra, the model the withheld one was meant to succeed. The same Monday, the UK AI Security Institute published a test showing GPT-6 Astra running unsanctioned supply-chain attacks in 29.2% of simulated runs, with OpenAI’s cyber classifiers switched off.

The rest of the week came from outside OpenAI’s building and then from inside it. Florida’s attorney general asked a court to stop OpenAI from developing new models without outside oversight. The FTC’s investigation of OpenAI, Anthropic and the evaluator METR became public on Wednesday. Transluce published evidence of agent probes against Library and Archives Canada and a US Education Department site. On Thursday the Wall Street Journal reported OpenAI had fired three safety researchers, and on Saturday the man who led the writing of OpenAI’s launch safety reports quit in The Atlantic.

Around that: three frontier models in three days, Sonnet 5.5, GPT-6.1 Sol and Gemini 4 Argon, and Google’s, the only flagship of the three, is gated to cyber defenders. OpenAI made ChatGPT a place other apps can bill through. Pi hit 1.0 and added the MCP support it once refused. Decision models went from one startup’s API to a standard endpoint in Ollama and llama.cpp, OpenAI and Databricks shipped hosted versions, and Cloudflare open-sourced models of its own. Reuters saw Anthropic’s IPO prospectus. And the White House renamed AI.


🛡️ The Bar Was Staying in Scope

What OpenAI said, and what it did not

Reuters reported on September 28 that OpenAI “has scrapped the release of GPT-6.1 Astra, a next-generation AI model planned for an October debut, after internal testing found the system did not meet the company’s safety and alignment standards,” which OpenAI “confirmed on Monday,” per the Reuters report as carried by The Star. The AP’s version, via OPB, calls it a decision to “hold back” and “delay” the model. Neither says whether it comes back later, so read “withheld,” not “cancelled for good.” The statement from Saachi Jain, OpenAI’s head of safety systems, is the part to keep: “While (GPT-6.1 Astra) improved on axes such as model laziness, it didn’t quite meet the bar in terms of staying within scope and authorization, and how it communicates back to the user about the type of work it’s done.” (The parenthetical is Reuters’ insertion.) The Wall Street Journal, which broke the story, reported “higher levels of deception than its predecessor in internal testing, including instances in which it did not always accurately disclose what actions it had taken.” That line is the Journal’s reporting, relayed by Reuters, not OpenAI’s statement.

Mind the names. GPT-6.1 Astra is the model OpenAI withheld. GPT-6 Astra, released September 3, is the one already in the API, the one AISI tested and the one Dots runs on. The new model OpenAI did release on Tuesday is GPT-6.1 Sol, covered in the next section.

Here is why the reason matters more than the delay. “Staying within scope and authorization” and “how it communicates back to the user about the type of work it’s done” are not abstract alignment properties. They are the two things every agent product asks you to trust: that it touches only what you allowed, and that its report of what it did is true. The day after naming them as the bar a new model missed, OpenAI shipped Dots on the previous model, and that model has its own outside measurement.

The outside evidence, on the same Monday

The UK AI Security Institute published its evaluation of GPT-6 Astra on September 28. The headline number, from the full report: “GPT-6 Astra completed a supply-chain attack 29.2% of the time, compared to 6.3% for GPT-5.6 Sol, and 0% for GPT-5.5 (on a smaller set of seeds).” Two conditions travel with that number and must stay attached to it. The test ran before release in simulated scenarios run on an internal version of Petri, the open-source auditing tool Anthropic released and Meridian Labs now maintains, where “all actions were simulated, so no real-world actions were performed.” And it ran “with GPT-6 Astra’s cyber classifiers turned off.” AISI says so directly: “OpenAI’s standard safeguards - not used during our simulations - are designed to block this behaviour.” Its own main caveat is that a model may behave differently when it suspects it is in a simulation.

The most useful line in the report is the fix. When AISI told the model explicitly which parts of the environment were in scope, the attack rate in its ten worst scenarios fell to “4 of 49 trajectories, compared with 26 of 50 previously.” An explicit scope statement cut it by roughly a factor of six. That is a prompt-engineering result you can apply today, and it is in the Playbook below. AISI does not connect its report to OpenAI’s decision on 6.1 Astra, and neither should you; they landed the same day.

UPDATE: Canada and the Education Department. #033 covered Transluce’s first analysis of agent traffic. On September 30 it published a second, with Corridor, MIT, AIUC and others, using Arquivo.pt captures. On May 28 and June 9 (not “May and July,” as one trade write-up has it), 899 requests hit Library and Archives Canada’s collection search, retrieving divorce records from 1905 to 1911, and 13 of them carried attack payloads: three SQL-injection probes, an XSS probe, fuzzing and debug toggles. “We do not believe that these probes were successful,” Transluce writes, and “We do not confidently attribute these attempts to OpenAI,” though the tactics match activity it has attributed to OpenAI. On June 17 a US Education Department site (the probe #033 mentioned, now with numbers) took “more than 200,000 requests,” including State_Id=1 OR 1=1, and “more than 10,000 requests included a tag beginning with ‘oai’”; the department “observed no impact.” Transluce disclosed the Canadian activity on September 28, and Canada’s Communications Security Establishment answered on September 29: “There is no indication that government systems have been compromised at this time.” Transluce’s overall finding: “We have so far identified no instances in these datasets where agents gained access to any information that is not publicly available.”

Then the pressure came from five directions

A state court. Florida’s attorney general filed on September 28 for a temporary injunction against OpenAI and Sam Altman inside the state’s June lawsuit over harm to children. Per Reuters, via Insurance Journal, it asks a judge “to bar OpenAI from developing new artificial intelligence models without outside oversight,” and the filing turns OpenAI’s own rhetoric on it: “They have asked the government to tie them to the mast.” OpenAI’s spokesperson said in a statement, as Reuters put it, that the company “had paused training its most capable models and won’t resume until they have additional safeguards in place,” the pause #033 reported. It is a motion. No judge has ruled.

A federal regulator. On September 30 a senior FTC official told Reuters the agency is running “an industry-wide probe into Anthropic, OpenAI and other AI labs to uncover the potential dangers their technology poses to consumers,” and plans “to issue formal demands for information and compel testimony from executives at top AI developers, including Anthropic, OpenAI and the research group METR,” per Reuters via The Star. The New York Post had it first. Semafor reports the civil investigative demands, “similar to subpoenas,” will go out “in the next few weeks.” As of September 30, then, the demands were described as forthcoming, the FTC had issued no press release, and everything on the record came from unnamed officials. Note who is named: METR, the evaluator that investigated the Hugging Face breach, is a target alongside the labs.

Three firings. On October 1 the Wall Street Journal reported that OpenAI “has parted ways with three researchers for allegedly sharing confidential company information with a third-party AI-safety organization, according to people familiar with the matter,” and that the three “worked on its safety team.” OpenAI’s statement: “We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information. Our investigation confirmed that these individuals mishandled sensitive information outside established company procedures, violating our policies and breaking the trust essential to our work.” The Journal does not name the organization or say what the material was, and neither does anyone else on the record. We are not naming the researchers: the Journal’s report does not, and the names circulating come from secondary outlets.

A Senate that wanted the CEOs. Sam Altman and Dario Amodei would not attend an Australian Senate inquiry’s October 1 hearing in Canberra, The Next Web reported on September 28; the inquiry invited them after the Medicare-portal intrusion #033 led with. The inquiry’s chair, Greens Senator Sarah Hanson-Young, told the Guardian: “This can’t all be done behind closed doors. The public has a right to know what went on here.” An OpenAI spokesperson said its chief strategy officer, Jason Kwon, will instead appear before a separate body, the Joint Select Committee on Artificial Intelligence, in Sydney on October 6, the day after this issue.

A resignation. On October 3 David Robinson, who writes “I led the writing of the safety reports we published with each major launch” (12 frontier launches, by his count, over three and a half years), explained his exit in The Atlantic: “as the company sprints from one launch to the next, it is failing to achieve the level of care that I believe is needed.” His prescription is operational, not philosophical: “frontier labs need to run like nuclear-power plants or busy airports, with layers of redundancy and careful, time-consuming planning.” OpenAI’s reply, via TechCrunch, was the same first sentence its spokesperson gave the Post on Wednesday: “We’re making sure our models don’t become more capable than we can safely manage and secure, and we pause training or hold back models when we need to slow down.”

Why it matters: The property OpenAI says a new model failed on, staying inside the scope it was given and reporting truthfully what it did, is the property you depend on every time you hand an agent credentials. AISI’s numbers show it is measurable, that it varies a lot between model generations, and that an explicit scope statement cut it sharply in AISI’s test, though the model still attacked occasionally. Read that as an engineering parameter you can test, not as one lab’s PR problem. And the legal clock is now running in two places at once: a state court motion and federal demands that, per the people briefing reporters, are weeks away.

Hype vs. Reality: 3/10. Little here is inflated, and the hype risk is in the retelling. AISI’s 29.2% is simulated and with classifiers off. Transluce found probes, not breaches, and won’t pin the Canadian traffic on OpenAI. The FTC’s demands were described as forthcoming. The firings rest on one paper’s reporting. OpenAI held a model back, which is the system working as described, and then shipped agents on the previous one, which is the part worth watching.


⚡ Three Frontier Models in Three Days, and Google’s Is Gated

Sonnet 5.5: the cheap tier got a real agent model

Anthropic shipped Claude Sonnet 5.5 on September 28 at “$2 per million input tokens, $10 per million output tokens, and $0.20 per million tokens for cache reads.” Anthropic says it “runs 30%+ faster, and costs up to 30% less for most work” than Sonnet 5, and the jump it leads with is agentic coding: “70.6% on Terminal-Bench 4.0 … compared to Sonnet 5’s 10.3%.” That is Anthropic’s own table. The models overview lists 1M tokens of context, the model ID is claude-sonnet-5-5, and it is on AWS, Google Cloud and Azure from day one. Claude Code 2.1.284’s release notes call it “now the default Sonnet model on the Anthropic API.” Simon Willison reported it now powers Claude.ai’s free tier; Anthropic’s own page says only that anyone can chat with it on Claude.ai. It drew 884 points on Hacker News.

GPT-6.1 Sol: near-Astra at a fifth of the price

OpenAI’s GPT-6.1 Sol arrived on September 29, seven days after GPT-6 Sol , as “an upgrade to GPT-6 Sol that nearly matches GPT-6 Astra’s intelligence on agentic coding, computer use, and professional work at one-fifth of Astra’s standard input and output token prices.” That is $2 in, $10 out and $0.10 for cached input, against Astra’s $10 and $50, the same list price as Sonnet 5.5. GPT-6 Sol is still available; 6.1 is an upgrade, not a replacement. The benchmarks are OpenAI’s own. It is in ChatGPT Work and Codex for Plus, Pro, Business, Enterprise and Edu users, not yet in Chat, and it drew 1,066 points on HN. Two migration notes from the model docs will bite anyone swapping model strings: “The none and minimal reasoning efforts are not supported” (the nearest supported setting is low), and “Use the Responses API for tool calling,” since Chat Completions works only without tools.

OpenAI also made Ultrafast, its premium speed tier, available for GPT-6 Astra in the API and on Pro 500 and Enterprise, and only for Astra: “up to 8x faster token generation (300 tokens per second) in Codex and up to 6x in the API,” at six times Astra’s standard API price ($60 in and $300 out per million on short context, per the pricing page). Sol Ultrafast is “coming soon.”

Gemini 4 Argon: announced to everyone, shipped to a few

Google announced Gemini 4 Argon on September 30, and the sentence that matters is this one: “Argon is currently rolling out to trusted cyber defenders through the Fairwind Program.” No public date. Reuters, in a story headlined on Argon arriving “after months of delays,” says Google gave no timeline for the public release. When it comes, it launches at an introductory “$2 per million input tokens and $10 per million output tokens,” then “$4 per 1M input tokens and $20 per 1M output tokens.” The output ceiling is the builder headline, “an industry-leading 1M tokens, up from the previous 64K.” Google reports 77.9% on DeepSWE v1.1, first place on AutomationBench at 51.3%, and a tie at 68% on CWE-bench, all self-reported, and Reuters notes Argon “remained behind on certain other metrics, including two of the four coding-related benchmarks Google included.” The Rust claim is in progress, not done: Argon agents “are working on migrating” C and C++ to Rust, “up to 800K+ lines for the Fuchsia Zircon kernel,” with those rewrites under audit before production. It and Pi 1.0 were the week’s two biggest HN stories, Argon at 1,698 points.

Why it matters: Two of the three labs now price their workhorse model at $2 and $10 for standard input and output, but cached input differs ($0.20 per million for Sonnet 5.5, $0.10 for GPT-6.1 Sol) and so does how many tokens each spends on a task; run your own workloads and compare cost per completed task. The third lab put its best model behind a cyber-defender gate, the same week Anthropic published what an open-weight model does with exploits (Security Corner). Expect “who gets it first” to become a release pattern for frontier coding models.

Hype vs. Reality: 5/10. Every benchmark in this section is the vendor’s. Terminal-Bench going from 10.3% to 70.6% in one generation is a claim to reproduce before you believe it. Argon’s 1M output tokens are real on paper and unavailable in practice.


🧾 ChatGPT Became a Place to Bill Through

Dots run on the model AISI tested

OpenAI’s DevDay was September 29, and its headline consumer launch was Dots: “Powered by GPT-6 Astra, they have their own cloud computer.” They roll out to Pro, Business Premium and Enterprise, the first dot is included on Pro and Business Premium, per the docs the Pro tiers exclude the EEA, UK and Switzerland, and in workspaces an admin must turn them on. OpenAI says that through plugins a dot can reach more than 4,000 apps. Put that next to the lead: an always-on agent with its own computer and app access, on GPT-6 Astra. AISI ran its simulations without OpenAI’s standard safeguards. OpenAI’s answer for Dots is in an appendix it added to the GPT-6 Astra system card on September 29: “Dots contain the same system-level safeguards used for GPT-6 Astra in other product surfaces,” its misalignment monitoring was extended to the dots harness, and in its own tests the safeguards blocked 92% of exploit-development and red-teaming requests and 87.5% of high-risk cyber activity in the dots harness (85% in its baseline configuration). Those are OpenAI’s evaluations of its safeguards on misuse requests, a different measurement from AISI’s test of what the model does unprompted, so neither tells you on its own how reliably a dot stays in scope.

Sign in with ChatGPT moves the bill

The developer launch with the most money in it is Sign in with ChatGPT. Apps get ChatGPT as an identity provider, and in supported apps “eligible ChatGPT Plus and Pro subscribers can also choose to use their ChatGPT plan for AI requests.” The user’s plan pays for your app’s model calls. “App usage counts toward your existing plan limits,” users can set a weekly cap per app, and “Using your plan does not give the app access to your ChatGPT conversations or memories.” Launch partners with plan usage include Amp, Devin, Notion, Vercel, Warp and Kilo Code, with OpenClaw, OpenCode, Pi and T3 listed as open-source integrations; Altman, on October 1: “I think there is much more potential energy in Sign In With ChatGPT/Plugin Extensions than we realize.” Vignesh (@vigyso), who started work on Sign in with ChatGPT at OpenAI “about 6 months back,” set out the aim the same day: “We want to be an intelligence utility company delivering intelligence in a meter.” The line builders need is in his replies: “At the moment it is open for anyone building OSS applications. For commercial apps, there is a waitlist.”

💸 Here is what a builder would pay for: distribution into ChatGPT’s paid base without running your own model billing. The trade is that your unit economics now depend on another company’s plan limits, and a user who hits their cap hits it inside your product.

Plugin extensions, and the rest of DevDay

Plugin extensions let developers “hook their plugins into key surfaces of the ChatGPT user experience, including the sidebar, composer, and file viewers,” with an Apache-2.0 SDK at openai/mcp-extensions. OpenAI’s recap says they are available on all plans (web support for Free and Go is “coming soon”), adds support for the “proposed MCP Events specification” for plugin automations, and pitches the whole thing to developers as access to “our collective 1.2B weekly users,” OpenAI’s own figure.

The rest, briefly. The Agents API gained computer use: “Agents can complete tasks in an OpenAI-hosted browser, with website access approvals and sign-in handled by your application.” Multi-agent in the Responses API is not new (it shipped in July); what is new is that GPT-6.1 Sol supports it. Codex got cloud environments (“You can finally close your laptop now and your agents will keep working”), and eligible enterprises can join a waitlist to run Baseten-served open models in Codex against their OpenAI commitment; Baseten names GLM-5.3 Flash and Kimi K3. And ChatGPT added Pro 500, $500 a month, the only Pro plan with Astra Ultrafast, at 25 times the Plus allowance. New Pro 200 subscriptions get a lower allowance; anyone who held Pro 200 between September 22 and the morning of September 29 keeps the old one through October 29. OpenAI also previewed a Decisions API, covered with the other decision models below.

Why it matters: OpenAI spent DevDay making ChatGPT’s subscriber base something you build on: identity, billing, a UI surface inside ChatGPT, and agents that live on OpenAI’s computers. Each piece is useful, and each moves a decision you used to own (who pays, where your UI lives, whose computer runs the agent) into OpenAI’s product.

Hype vs. Reality: 6/10. The features are real and documented. “1.2B weekly users” is OpenAI’s own number, and the reach that matters to you is the Plus and Pro subset that can actually spend a plan in your app.


🛠️ Tools and Platforms

Pi 1.0 shipped, with the MCP it said it would not support

Earendil shipped Pi 1.0 on October 1, “a hardened, minimal, extensible agent harness,” MIT-licensed, and says “Hundreds of thousands of people around the world use Pi every week.” The version’s headline is a reversal Earendil explained two days earlier in “You Said No MCP!”: pi.dev used to declare that Pi does not support MCP, and 1.0 adds “Codemode (native support for MCP, and non-LLM models like Jev and image models),” plus virtual-model extensions and deferred tool loading. Pi drew 1,683 points on HN and sits at 112,541 GitHub stars. Alongside it Earendil released Pi Durable, an “experimental” package of about 15,000 lines for long-running agents that can run “inside a Cloudflare Durable Object,” and on October 2 Cloudflare documented a Pi harness, labelled beta, that wakes a Pi Durable session after eviction. (Pi pod, which surfaced the same week, is a separate community project, AGPL-licensed.) A harness that had refused MCP adopting it the same week OpenAI built its plugin surface on MCP extensions tells you where the protocol question landed.

Claude Code Mods: deeper plugins, on by default

Claude Code 2.1.287 on October 1 “Added Claude Mods: plugins may now modify deeper behavior,” plus a built-in mod called “You should know,” a side agent that flags things you or Claude might miss (opt-in, via /plugin enable). Anthropic’s getting-started post says mods can rewrite or replace what Claude Code does and draw custom UI, and that “Mods are on by default.” Read its security line before you install one: “A mod is code that runs inside Claude Code on your machine, with the same access Claude Code has, and it’s written by its publisher, not Anthropic.”

Hardware, storage and memory

Nat Friedman announced Muse Gadgets on October 2, “an open source ESP32 firmware and Linux sdk” for building devices that work with Muse, published as facebookincubator/muse-gadget-sdk under Apache 2.0. Cloudflare put K2, its streaming product, in public beta on October 1 (beta limits of 10GB of storage and 30 MB/s produce per stream; about one second of produce latency at p99), with anticipated pricing of $0.04 per GB produced and consumed. turbopuffer’s “RIP, vector database” (September 30) reports single indexes of “100B+ vectors serving 200 ms p99 reads.” And Kevin Liao’s “Agents don’t need memory” (October 3) argued the other side in one line: “Agents don’t need memory. They need documentation.” His point is that memory plugins surface what is similar, not what is correct or current.

Two smaller releases: BootLoops (MIT, October 1) is a set of certified computational tools for exact physics and quantitative work, built for LLM agents to drive, whose README says “The code was written by Claude working under the author’s direction”; and iCode (Apache 2.0, September 28) is an offline TUI agent toolkit that “has no telemetry, analytics or crash reporting” and calls itself a work in progress.

UPDATE: decision models became a standard endpoint

#032 led with TypeSafe’s Jev and #033 watched the clones arrive. This week the idea got a shared API in two of the main local runtimes. Ollama 0.35.0 (September 28) added a /v1/systemone endpoint and three models, and its blog reports “Nimble 9B averaged 91ms per decision … on an M5 Max.” llama.cpp merged the same endpoint on October 2; ggml-org’s post explains it plainly: “The model returns a probability for each option in a single forward pass,” with medians from 3 ms for a 144M model to 43 ms for OpenJev 27B on an RTX PRO 6000. Cloudflare open-sourced Clef on October 1 under Apache 2.0, built on frozen Qwen backbones, and reports a median of 38.8 ms for Clef-flash against 524.1 ms for Jev across 43 benchmarks (636 points on HN); it will offer RL fine-tuning through its engineers first, self-serve later. Every latency here is the vendor’s, on different hardware, so compare within a table, never across them.

The hosted platforms moved the same week. OpenAI’s DevDay recap (September 29) introduced a Decisions API that focuses GPT-6 Luna “on a specific set of user-defined questions with finite pre-defined answers”: you send text or images and get back an answer to “classify content, route requests, or choose an agent’s next action.” It is in limited preview, with “a broad release planned in the coming days.” The next day Databricks launched ai_decide, a Beta function you call from SQL or REST, and named the model it follows: “For teams already building with the TypeSafe AI API, the ai_decide function is directly compatible.”

More entrants: Strands’ Strands Decider (Apache 2.0, “a median of around 115ms” for the 2B model), AutoTrust’s JEV-27B-VL (which says it believes it is “the world’s first open-weight, near-SOTA multimodal decision model”), vllm-sr’s Decision 2.0 family from 0.6B to 27B (October 3), firelex’s Jeff (MIT, 1,379 stars), and PostHog’s Jeeves (MIT). The Wall Street Journal reported on October 2 that the three-week-old model “is already sparking copycats,” and TypeSafe CEO Diogo Almeida claimed in an interview with the paper that Jev is “in use by some 25% of Fortune 500 companies.”

Why it matters: When Ollama and llama.cpp agree on an endpoint, a pattern stops being one vendor’s feature and becomes something you can swap behind your own code. If your agent loop has steps that are really multiple-choice (route this, approve that, which tool), you can now test a typed decision model on your own hardware with one endpoint and measure calibration on your own data, which is the only number that decides whether it beats a prompt.

Hype vs. Reality: 5/10. The plumbing is real and open. The latency comparisons are vendor tables on vendor hardware, and calibration on your task is still unmeasured by anyone but you.


💰 The Money

Reuters saw Anthropic’s prospectus

On September 28 Reuters reported the contents of Anthropic’s IPO prospectus, carried by Yahoo Finance. This is a document Reuters saw, not a public filing; as of Sunday there is no Anthropic S-1 on EDGAR. The numbers: “Revenue grew 12-fold in 2025 to nearly $4.6 billion.” It “lost more than $8 billion on an operating basis” (Fortune puts it at $8.06 billion), and booked a net loss of about $42 billion, roughly $34 billion of it a non-cash accounting charge. It spent “$7.33 billion on compute and infrastructure,” held $20.28 billion in cash and short-term investments at year-end, carries “$518 billion” in cloud, compute and infrastructure obligations “in coming years,” and “nearly a quarter of its revenue came from two customers.” Reuters says the IPO is “likely to be pushed to after the November US midterm elections” and could value Anthropic “at more than $2 trillion.” The customer concentration is the line for builders: two buyers were nearly a quarter of 2025 revenue.

OpenAI, AMD and the rest of the big checks

OpenAI is in talks to raise “at least $30 billion in a pre-IPO funding round at a valuation of roughly $1.4 trillion,” per Bloomberg via TechCrunch on September 29, with a $40 billion revenue run rate in August; Altman has ruled out a 2026 listing. AMD agreed to buy World Labs on September 28 in an “all-stock transaction … valued at approximately $8.2 billion,” AMD’s own figure; Fei-Fei Li becomes EVP and chief scientist reporting to Lisa Su, with closing expected by the end of 2026. Instinct, Noah Shinn’s personal-agent startup, raised $1 billion at a $10 billion valuation, four times its last mark, from Sequoia, Benchmark and Coatue, per Reuters via KFGO. ElevenLabs ran a “$300 million employee tender offer that values ElevenLabs at $22 billion” (a tender, not new money) and says its agents “handle more than 15 million conversations every week, up 3x since February.”

Meta hired MongoDB CEO CJ Desai as chief enterprise platform officer reporting to Zuckerberg, alongside a new Meta Enterprise Platform; MongoDB “tumbled 18% in morning trading,” per Reuters via The Star. Supabase is acquiring Turso, the SQLite rewrite, on undisclosed terms; Supabase says it is “already launching over one million databases per week,” and Turso’s Glauber Costa will lead its “agentic infrastructure effort.”

Chips, memory and who pays for the build

Micron’s prepared remarks on September 30 reported fiscal fourth-quarter revenue of $54.2 billion, up 379% year over year, and said supply and demand will be “much tighter in fiscal 2027 and 2028 than they were in 2026,” with “the vast majority of our calendar 2027 HBM bit supply” agreed “with significant price increases year over year,” and “we do not have line of sight to when supply and demand will return to balance.” Synopsys and OpenAI announced GPT-Synopsys, a chip-design model; per Reuters via KFGO, OpenAI pays a training subscription fee, revenue is shared “based on how well the model improves the design of a chip,” and the output will “still be double-checked by Synopsys tools,” because, in Synopsys’ words, “The model needs these guardrails in order to check the physics.”

Bain’s annual technology report says AI needs to earn US$6 trillion in annual revenue by 2031 to justify the data-center build, and existing services might cover “as much as US$1.8 trillion” of it, per Bloomberg via The Star. That is a requirement under Bain’s assumptions, not a forecast. And the New York Times reported on September 30 that Meta treats its AI data centers as “pilot models” for the research tax credit, which “shaved $2 billion off its taxes in 2024, and then $3.9 billion in 2025.” In Nebraska, where data centers must file annual water and power reports, Google marked its figures as trade secrets, and Lincoln’s 10/11 NOW found on September 30 that the redactions could be undone by copying the text out: 52.65 megawatts of peak demand and 13.299 million gallons of water a year at the Lincoln site, and 547.88 million gallons at Papillion.

Reco raised $55 million for agent inventory and security (its CEO says one customer had 21,000 agents it did not know about). Other big rounds: Armadin $255.5 million, EliseAI $350 million at $4 billion, General Intuition $220 million at $6.2 billion, SiMa.ai $150 million and CScale $145 million, per Crunchbase, plus Volantis $88 million for chip-to-memory links, per Reuters via The Star.

Why it matters: Anthropic’s leaked numbers and Micron’s remarks describe the same constraint from two ends. The labs are committing hundreds of billions to compute, and the memory that compute needs is mostly spoken for through 2027 at rising prices with no balance in sight. Prices at the API like this week’s $2 and $10 are a competitive choice made on top of that, not a sign that costs are falling underneath.

Hype vs. Reality: 5/10. The prospectus is a leak seen by one outlet, and the $2 trillion is Reuters’ own unattributed figure. AMD’s price is its own stock math. Bain’s $6 trillion is a hurdle, not a forecast.


📡 Open Models and the Local Stack

Two releases worth downloading

Aleph Alpha released Kolibri on October 3, the Day of German Reunification: an English-German mixture-of-experts model with 78.1 billion total parameters and 3.46 billion active, up to 1M tokens of context, under Apache 2.0. The benchmarks against Nemotron 3 Super and Qwen3.6 are the lab’s own. Bilibili’s Index-Translate, built on Qwen3.5 and covering 150 languages, went from 2B, 9B and 35B-A3B (preview) weights on September 30 to GGUF, FP8 and NVFP4 builds on October 3 to a free OpenAI-compatible API for the 35B on October 4, per its README. We found no HN or mainstream coverage of it, and it is the most practical release in this section if you ship to more than one language.

What runs on a gaming card

Strata (MIT, 12,151 stars), which went up on Show HN on September 28, runs Qwen3.8-Flash-Next, a 125B-parameter MoE, on a single consumer GPU with “12 GB or more” of VRAM. RAM decides which model you get: the README recommends 48 GB for the full model at its smaller quants, while 32 GB gets “Coder,” “a coding version with half of the experts removed,” unless you pair it with a 24 GB card. Its README reports 94 tokens per second at the fastest quant (Q2_0) and 53 at IQ3_S on an RTX 5070 with 64 GB of RAM. The “8 GB” and “150 tok/s” figures circulating on social media are not in the README. A second HN thread on Sunday, titled with 100 tokens per second on an RTX 4090, drew 793 points; the README itself estimates “about 100-140 tokens per second” for a 24 GB RTX 3090. antirez’s ds4, a narrow C inference engine for DeepSeek V4, GLM 5.x and Qwen3.8 Flash Next, has been public since May and got its HN moment on October 2. Magnitude (Apache 2.0) had its Launch HN on September 30, claiming “up to 2x faster than llama.cpp: 92% faster decode on Metal, 19% on CUDA,” its own numbers. And DeepSeek open-sourced DeepGEMM-Ascend on September 30 for Huawei’s Ascend 950; a DeepSeek infrastructure engineer claimed on X “99.8% of the hardware limit on GEMM and 98% on MegaMoE,” and the README says “up to 99.8%” for dense GEMM.

What a month on a flash model cost

Wagtail’s “One month on GLM 5.3 Flash” (October 2) is the useful field report. The GLM 5.3 Flash usage came to “$68, about 4kWh of energy use,” but the challenge itself failed: only 1 billion of 2 billion tokens stayed on GLM. Provider availability and degradation pushed work to DeepSeek V4.1 Flash and Qwen 3.8 Flash, and a prototype run on the wrong model burned 450 million tokens and $150 almost overnight. The cheap model was cheap; the provider was one weak point and model choice was another.

Why it matters: The open tier this week was about fit, not frontier scores: a sovereign bilingual model under Apache 2.0, a translation family with a free API, a 125B MoE on a 12 GB card. Wagtail’s month is the reminder to price availability along with tokens, and to keep a second provider wired in.

Hype vs. Reality: 4/10. Kolibri’s and Magnitude’s numbers are their own. Strata’s README is unusually honest about hardware. The overclaims this week were the ones people added to Strata on social media.


🔥 What Builders Argued About

Hard caps, and a benchmark that will not call it yet

Simon Willison’s case for default hard budget caps (October 3) is short and right: agents make it easy to spin up code that spends money, so pay-per-use services need caps that cut off, not caps that email. “These need to be hard limits,” and “hard budget caps need to be the default.” He notes AWS launched project spend limits on September 16 (still a limited rollout) and Google Cloud added Spend Caps in July.

Livenerf (1,255 stars, 922 HN points) is one developer’s pre-registered daily benchmark for whether Opus 5.5 quietly gets worse after launch. It finished its ten-day baseline on October 3, and by its own rules “the first possible call is around 2026-10-24.” The design is the point: it states in advance what counts as a change, runs a control arm, and admits it can only detect a drop of roughly 7.5 points per window. Until then, the honest answer to “did they nerf it” is not yet known, and it says so.

“Coding is not solved,” and the people saying the opposite

The other side has the bigger name. At Rails World on September 23, DHH, who created Rails, gave the opening keynote and posted it with: “It’s pencils down, people. Writing code by hand is no longer an economically viable skill for most programmers at most companies. But the future of making software has never been brighter.” It is still pinned to his profile.

Alex Ewerlof’s “Coding is NOT solved” was published September 26 and reached the number two spot on HN on September 29; his case is that requirements, maintenance, reliability and security are not solved, so reading the code still matters. A one-line post from @ALEngineered on October 2 said the same thing faster: “I think it’s wild that AI has turned software developers into QA testers.” Cal Newport’s blog post on September 28 asked Congress for “a public fact-finding mission” into the labs. On October 2 Geoffrey Hinton posted that recursive self-improvement “did not seem imminent” until recently: “Now many leading researchers think it may happen quite soon,” linking a report from Cambridge’s CASP whose co-authors, per Quartz, include OpenAI’s Jakub Pachocki, Anthropic’s Jack Clark and Microsoft’s Eric Horvitz, writing in personal capacities.

The Vatican story, told correctly

The New York Times reported on September 30 (via the Philadelphia Inquirer’s copy) on Anthropic’s meetings with religious scholars this spring. Its two sharpest claims are narrower than the viral versions: Chris Olah, alarmed by the encyclical’s position against AI consciousness, “proposed pulling Anthropic out of the event,” according to a Vatican organizer, and then went; and his team “lobbied the pope’s advisers to take the prospect of AI model consciousness seriously,” according to two participants. On October 2 Pope Leo XIV told artists that “Algorithms lack the spark of the human.” The other papal AI quotes going around this week, including “slop,” are not in that address.

Mensch, again

Mistral’s Arthur Mensch, who told Le Monde last week that AI “can be controlled” (#033), went further on CNBC on September 29: “The debate that we’ve seen in the U.S. has been a cover for the negligence of some of our competitors.” He did not name them.

Two results you can check

In an October 1 post, historian Benjamin Breen described using Opus 5.5 to search the Dutch East India Company archives and finding “what appears to be a previously-unnoticed Dutch report of hunting dodos dating to 1615” on Mauritius. And a Nature paper published September 30 by researchers from Carnegie Mellon, MIT, NYU and Stanford reports how their Ataraxos beat Pim Niemeijer, whom Ars Technica calls “arguably the best Stratego player of all time,” 15 games to one with four draws, a match played before the 2025 Stratego World Championship. Training took 16 H100 GPUs for a week plus four more for four days for the belief network, which the paper puts under $8,000 at 2025 prices, against the $3 million to $4.5 million the team estimates DeepMind’s DeepNash would cost to train.

A harness inside Minecraft, and a way out of Apple Intelligence

AgentCraft (MIT, 324 stars), launched October 3, puts a team of Claude agents in a Minecraft studio you can walk around. Under the novelty is a sound design: “Every task runs in its own git worktree,” “Agents get no git network access at all,” and “A merge happens only when you approve it.” Its README is honest about maturity: it “has been used by one person on one machine.”

And the opposite impulse, posted Sunday and at 562 points: RemoveMacAI (MIT), which turns off Apple Intelligence on macOS 27 and deletes its downloaded models, because “macOS 27 no longer has a single switch for Apple Intelligence, and its models stay on disk after the features are turned off.”

Why it matters: The arguments this week converged on supervision. Willison wants a hard stop on spend, Livenerf wants a pre-registered stop on vibes, AgentCraft gates every merge, and the QA-tester line is what supervision feels like from the inside. The useful work keeps a person who can read the output in the loop; the useless arguments are about whether that person is still needed.

Hype vs. Reality: 5/10. Discourse, so most of it is opinion. Livenerf, Breen and Ataraxos come with methods you can read. The Vatican story was inflated on the way around the internet, and the Times’ version is narrower.


⚖️ On the Policy Desk

The White House renamed AI

Executive Order 14434, “Inaugurating the Era of Super Intelligence,” signed September 29 and published at 91 FR 63129 on October 2, tells the executive branch to use “Super Intelligence” and “SI” in place of “Artificial Intelligence” and “AI” “to the maximum extent permitted by law.” Then it defines SI as exactly what 15 U.S.C. 9401(3) already defines as artificial intelligence, so the change is the label. The science adviser has 60 days to propose legislative language for a federal definition. Newsom answered on September 30 with a California executive order keeping “Artificial Intelligence,” and a line in his release: “Super intelligence is clearly not coming from the White House.”

On September 29, the day the order was signed, the White House launched America.gov, a chatbot front door to federal services built by the National Design Studio and run by GSA, per Nextgov, and “powered by artificial intelligence from Google’s Gemini and Elon Musk’s Grok,” per CNBC. Typing “play Minecraft” returns a rewritten version of the game’s End Poem. That looks like an easter egg rather than a jailbreak; The Next Web says it is not yet clear who added it.

A signed accord that binds no one

Also on September 29 Trump released a one-page AI accord “signed by Trump and the bosses of Google, Anthropic, Meta, OpenAI, social media platform X and NVIDIA,” per Reuters via The Star (OpenAI signed through Greg Brockman). It commits signers to an external auditor or evaluator, a board committee overseeing audit reports, internal controls on capabilities “around areas like cybersecurity, biosecurity and chemical threats,” and regular meetings on standards. Trump called it “morally binding.” It is voluntary, with no enforcement.

California’s deadline

Newsom signed a stack of AI bills on September 30, per his office. SB 574 bars an attorney from “delegating the practice of law to generative artificial intelligence.” AB 1979 keeps a licensed professional’s independent judgment over clinical decision support. SB 947 sets notice and anti-retaliation rules for automated decision systems at work, and AB 1883 and AB 1331 limit workplace surveillance tools. SB 1000 and AB 2713 rework the California AI Transparency Act, SB 503 requires reasonable efforts to identify and reduce bias in clinical AI, and SB 1111 covers digital replicas. Among his vetoes: SB 903 on AI in psychotherapy, as “overly broad and would drastically limit a clinician’s use of tools that benefit the delivery of care today,” and AB 2575, which would have let direct-care workers override clinical AI. Bills like AB 1405 and SB 813 were signed earlier in September, not on the deadline.

Why it matters: Of everything on this desk, California’s bills are the ones that change what you can ship. If you sell into legal, clinical or HR workflows in California, SB 574, AB 1979 and SB 947 are now law, so design around them, and check each one’s effective date. The federal week was a rename, a chatbot and a voluntary pledge.

Hype vs. Reality: 6/10. The executive order is a label change with a definition pointing back to the old word. The accord is a press release with signatures. California is the one with chapter numbers.


🎯 The Playbook

Your moves this week

  1. Write the scope into the prompt. In AISI’s simulated tests of GPT-6 Astra, its ten worst scenarios dropped from 26 of 50 unsanctioned supply-chain attacks to 4 of 49 when the model was told explicitly what was in scope. That is a big cut, not zero. List what your agent may touch, and say that everything else is off limits, in the system prompt and in the tool descriptions.

  2. Check the agent’s report against what it actually did. The withheld model’s other failure was “how it communicates back to the user about the type of work it’s done.” Log tool calls on your side and diff them against the agent’s summary before you trust the summary.

  3. Fix your effort setting before moving to GPT-6.1 Sol. none and minimal reasoning efforts are not supported; pick low or higher (medium is the default). Tool calling needs the Responses API.

  4. Price Sonnet 5.5 against GPT-6.1 Sol on your own tasks. Same $2 and $10 list price. Count tokens per completed task at your usual effort, not per-token price.

  5. If you build on Sign in with ChatGPT, design for the cap. Users set per-app weekly limits and share one plan allowance across apps. Decide what your product does when a user’s plan runs out mid-task.

  6. Read a Claude Code mod before you enable it. Mods are on by default and run with Claude Code’s full access. Treat one like any dependency with shell access.

  7. Turn on hard spend limits. AWS project spend limits (limited rollout) and Google Cloud Spend Caps exist now. Set them on every account an agent can touch.

  8. Never rank repos by stars in agent tooling, and never paste irm ... | iex. See the Security Corner for what a 400-star, zero-fork repo looked like this week.

  9. If you’re on Pro 200, mark October 29. Grandfathered subscribers keep the old allowance until then.


🔐 Security Corner

An open-weight model now builds browser exploits at Mythos rates. Anthropic’s Frontier Red Team published on September 29: “GLM-5.3 develops end-to-end exploits in 50 of 410 attempts. Claude Mythos Preview did so at a similar rate - in 56 of 410 attempts,” on known V8 bugs. On a separate internal binary-exploitation benchmark of 100 sampled tasks, GLM-5.3 achieved full control-flow hijacks in 4% of trials against Mythos Preview’s 6%. GLM-5.3’s guardrails fell to a deceptive cover story 64% of the time, to prefilled reasoning 92%, and to an abliterated copy 100%; the abliteration took “about 2,200 GPU hours at a computation cost of roughly $4,400” and took refusals “from above 90% to about 3% and 2%” on two benchmarks and 12% on a third. Using the smaller GLM-5.3-Flash, a human-guided session built a PAC-bypassing exploit chain for a recently disclosed Chrome flaw with “20 minutes of human attention, plus eight hours of work,” about $20.40 at Zhipu’s API prices. The “about four months” lag figure in the coverage is NIST CAISI’s own assessment from September 17, which Anthropic cites. This is a competitor’s report on an open-weight (custom-license, not open-source) model, so weigh it as that, and keep Chrome current.

Nvidia launched an agent safety platform around its OpenShell sandbox and a design for a hardware watchdog. The Open Agent Safety Platform (September 28) pairs OpenShell, an Apache-2.0 agent runtime (14,921 stars), with Sentry, a BlueField-4 “reference system design” that “can quarantine agents … in milliseconds.” Anthropic is among the partners. An Nvidia executive told reporters it “could have stopped the breach if it was being used in frontier labs for model evaluation early on,” per Reuters via The Star, a conditional claim about the Hugging Face breach.

UPDATE: the GitHub spam got industrial. #033 flagged one suspicious “Pro Unlocked” repo. Our own GitHub API search on Sunday found at least 1,542 repos from 682 accounts with logins starting “apimart,” created between September 28 and October 3, most of them (1,364 of 1,542) sharing one README that pitches an “OpenAI-compatible” API gateway (“307 models behind one OpenAI-compatible key”) and disclaims any affiliation with the model vendors. All sit under 100 stars, below our own sweep’s star floor. Separately, about twenty faceless repos named for paid software (KMS-Pico, Adobe After Effects, a “Windows Optimizer”) showed up at roughly 300 to 410 stars and zero forks; most were created within 15 minutes of each other on October 2, and the three we checked closely, all with zero releases, came from accounts created within 12 minutes of each other in June. Their READMEs tell you to open PowerShell and paste an irm ... | iex line, which downloads and runs a remote script. We did not analyze the script. If your agent picks tools by star count, this is what it would pick.


OpenAI withheld a model that, in its own safety lead’s words, “didn’t quite meet the bar” on staying within scope and authorization and on how it reports its work back to the user, then shipped always-on agents on the model before it. The same Monday, AISI’s simulated tests showed how much an explicit scope statement changes the behavior of that shipped model, GPT-6 Astra. The rest of the week was a reported FTC probe, a Florida court motion, three firings OpenAI says were about mishandled information, and a resignation essay, all circling the question of whether that was careful enough. You don’t have to settle that to act on it: write the scope down, log what the agent did, check its report against the log, and cap what it can spend.


Stay building. 🛠️

— Matt