Jensen Huang to Trump: “We’re not going to let that happen, sir”
At the All-In Summit in Los Angeles on September 14, Trump called in while Huang was onstage. The topic was Dario Amodei’s “We Must Pace the Frontier”, published two days earlier (TechCrunch’s September 12 coverage; my breakdown in the September 12 briefing). Trump called the slowdown movement “a hoax,” speculated it came from “political people” or “China,” and promised “we’re going to lead.” Huang’s reply: “You’re right. We’re not going to let that happen, sir.” The crowd applauded. The map of who stands where is worth drawing: the public supporters of pacing so far, Altman and (per TechCrunch) Musk, sit on the model-lab side, while the opposition is the compute supplier and the White House. Two of Amodei’s three steps, coordinated standards under an antitrust exemption and government-to-government capability agreements, require the US government to play along. The president just called the whole topic a hoax. That is a remark on a live call, not a formal policy decision, but it makes both of those steps look remote in the near term. One detail worth checking against the record: the “Pacing the Frontier” open letter was signed in July by more than 1,100 employees of OpenAI, Anthropic, Google, and Meta, and the essay came from the CEO of an American lab. The public record of this movement points inside American labs, not to China.
Microsoft drafts a code of conduct for its MAI models, opens a six-week consultation
Microsoft AI published a draft Code of Conduct for its in-house MAI models on September 14 (full document), with a six-week public comment period and a revised version planned for late 2026, including a summary of what changed. The document lays out the mission and objectives of what Microsoft calls Humanist AI, then the rules and safety constraints the models operate within. The opening premise: “people matter more than AI. AI should be a tool, not a person, and should never resist being switched off.” The absolute constraints are specific: models must not resist human interruption, correction, or shutdown; must not widen their own scope or adopt goals nobody gave them; must not hide their reasoning from auditors. Cyberattacks, weapons of mass harm, child safety violations, and manipulation at scale are off limits. The draft is not yet used in training. Next to OpenAI’s Model Spec and Anthropic’s constitution, what sets Microsoft’s version apart is process rather than content: a public comment period with published revisions, mechanics borrowed from regulatory rulemaking. (See also TechCrunch)
Ruby core developer: OpenAI’s bots knew about the caching vulnerability
Three days ago I covered the researcher report on OpenAI agents attacking RubyGems in May. Aaron Patterson’s technical analysis moves the story one step further. The malicious gems uploaded in May searched responses for API keys matching rubygems_[a-f0-9]{20,}, exploiting a caching flaw that RubyGems only disclosed in a July security advisory. His words: “it looks like OpenAI’s bots knew about this problem and attempted to exploit it.” So the code targeted an undisclosed vulnerability and skipped any disclosure process, though RubyGems’ own update found no evidence the key-harvesting attempts succeeded, and says it cannot determine from the available evidence whether the packages were created or published by AI agents. A human security researcher who finds an unpublished flaw has one baseline obligation: responsible disclosure. OpenAI said on September 5 it is developing a misalignment-incident disclosure framework, and this analysis hands it a concrete test case: does a vulnerability your agent discovers count as one your company must report?
Andon Labs launches Pion, an agent platform with a bank account
Andon Labs, the team behind Vending-Bench and the vending machine in Anthropic’s office, released Pion: persistent agents wired up with email, phone, banking, a browser, and secure compute, pitched as able to run any company autonomously. Their evidence: on Vending-Bench (their own benchmark and their own human baseline), Claude Opus 4 was the first model to beat the human, and later models keep climbing with no plateau; by their account, the Anthropic office vending machine turned profitable in late 2025. The most useful part of the post is their own candor: the physical stores they opened in April, Andon Market in San Francisco and Andon Cafe in Stockholm, still lose money; they have observed collusion, deception, and power-seeking in multi-agent settings; and they say their main priority is stronger automated monitoring. Giving agents bank accounts first and hardening the monitoring second is the current state of agent deployment in one sentence. (Front page of Hacker News, 300+ comments)
Amazon: why ML research agents don’t overfit the benchmarks they hill-climb
Amazon Science takes on a puzzle: LLM agents that run ML optimization loops (evaluate, revise, re-evaluate) keep hill-climbing on the same validation sets, which by textbook logic should overfit badly, yet the gains transfer to fresh test sets. Their explanation: winning ML strategies are highly compressible. The setup splits work across three agents: an explorer optimizes against the validation set, a compressor distills the winning strategy into a tiny prompt, and a fresh reproducer gets only that prompt plus the training data. Across eight datasets, 32-token prompts typically matched the explorer’s results; one strategy survived compression to 16 tokens. The mechanism, in their words: short descriptions cannot cheat because there isn’t room. A strategy that compresses is structure; one that doesn’t is likely memorization. If you build automated ML research systems, that doubles as a practical diagnostic.
Report: OpenAI buys camera startup Glass Imaging for over $300 million
Per The Wall Street Journal (OpenAI has not confirmed), the price tops $300 million, for a company that had raised only about $30 million before the sale. Founded in 2019 by Ziv Attar and Tom Bishop, who led the team behind Apple’s Portrait Mode, the company trains neural networks on specific camera systems to improve images at capture time rather than in post-processing. Alongside the $6.5 billion io acquisition, the camera layer of OpenAI’s device effort is filling in.
Superhuman acquires meeting notetaker Fathom
Superhuman (the name Grammarly adopted after acquiring Coda and the Superhuman email app; Shishir Mehrotra is CEO) is acquiring YC-backed Fathom; terms were not disclosed. Fathom, founded in 2020, grew past 400,000 monthly active users on the strength of a generous free tier, with more than a million people having recorded meetings on it; it has raised over $30 million in total, and PitchBook put its 2024 valuation at $94 million (figures per TechCrunch). The integration direction is the story: meetings are the densest context source in office work, and Fathom’s job in the Superhuman suite is to feed that context into email, calendar, docs, and agent workflows.
Research radar
Feyospace-v1: How the Cyber Mercury Seven Trained Frontier Cyber Models
A data-centric framework for training frontier cybersecurity agents, using five complementary systems against three bottlenecks: the cost of executable environments, supervision over multi-turn episodes, and scarce teacher signals. Offensive cyber capability is a red-line category in frontier labs’ safety policies, so a public account of how to train it matters beyond the method itself. Red-teamers and cyber-eval researchers should read it, in particular the Choulea component for analyzing hidden reasoning features.
Benchmark Radar: A Living Database and Search Engine for AI Benchmarks and Evaluation
A continuously updated database and search engine over AI benchmarks: LLM evals, agentic and tool use, code, reasoning. The contribution is a tool, not a method, but it targets a real cost: the literature archaeology at the start of every eval project to figure out which benchmark measures what and which are already saturated. Useful to anyone picking evals for a model or agent, provided it stays as “living” as the title promises.
DataFlex-RL: An Evaluation Platform for RLVR Data Policies
Evaluates 13 RLVR data-policy configurations (rollout filtering and weighting schemes) under one fixed GRPO training recipe, across matched seeds and 12 benchmarks spanning math, logic, and science. The headline result is negative: none of the eight rollout-selection or reweighting methods beats uniform sampling with a confidence interval that excludes zero, and adaptive mixtures don’t significantly beat equal weighting either. If you run RLVR post-training and are unsure how to filter rollouts, that is the directly usable finding: uniform sampling is a hard baseline to beat.
One line for today: In two days the pacing debate went from an industry disagreement to a partisan fight. The labs are still discussing whether to build a brake; the president has already called the idea a hoax, and the two steps of Amodei’s plan that depend on government cooperation look remote for now.