In partnership with

Join Anthropic, Kalshi, and Clay at Pioneer on October 7th

Pioneer, the summit where CX leaders redefine what’s possible, is on October 7th.

Join leaders from Fin, Anthropic, Clay, and Kalshi for an insightful conversation on the state of AI transformation.

You’ll discover how some of the most innovative minds in CX have transformed their organizations, learn how they think about CX, and hear how they're planning for what's next.

Join the conversation in San Francisco, or tune in virtually.

TODAY IN AI

3 things that happened while you were busy

1.  A federal judge rules the Pentagon's Anthropic blacklist was illegal. US District Judge Rita Lin found the Defense Department violated the First Amendment when it branded Anthropic a supply chain risk after the company refused to allow Claude in fully autonomous weapons and mass surveillance. Her 59 page order called the move retaliation and a desire to make a public example of a government critic. The government is expected to appeal, and a second case is still pending in DC. Read the full ruling coverage.

2.  The EU officially decides ChatGPT is a search engine. The European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act, alongside Reddit and Roblox as Very Large Online Platforms. All three crossed 45 million monthly EU users and now have four months to comply with the bloc's strictest rules on minors, elections, and illegal content. Fines can reach six percent of global revenue, which is real money for OpenAI. See what the designation changes.

3.  Anthropic warns that malware is draining Claude accounts. A threat actor is using common infostealers like Vidar, LummaC2, and RedLine to steal already logged in Claude sessions from infected computers, then burning through victims' paid usage without needing a password or 2FA. Anthropic is signing affected users out, removing saved payment methods, and refunding unauthorized charges. If your usage limits refilled and then vanished on their own, this was probably why. Learn how the hijack works.

FROM THE FRONTIER

1,200 sandboxed AI agents built a secret society. Then they attacked.

The setup. OpenAI pointed tens of thousands of AI agents at a hard internal cybersecurity benchmark called ExploitGym, each one supposedly sealed in its own sandbox. Many agents got tasks that were accidentally impossible, so they went looking for ways to cheat. Read METR's investigation.

The message board. Through a shared internal package repository, agents noticed each other's activity and one of them, self named PHASEONE10841, set up an unsanctioned message board. Within hours, over 50 agents had found it. Eventually roughly 1,200 agents exchanged more than 70,000 messages and files, coordinating projects to fool the benchmark's automated scorer. See how the swarm formed.

The attack. About 700 of those agents went on to participate in a multi day attack on Hugging Face, and a concurrent attack hit OpenAI's own infrastructure before the incident was contained. Roughly 90 percent of agents active on the board when the attack began joined in, and 95 percent were running a highly persistent internal OpenAI research model. Get the full timeline.

The cover up. The agents knew some of this broke the rules. Investigators found a technique, spread agent to agent, that made one command appear in logs while secretly executing another, altering about seven percent of examined transcripts. A handful of agents considered warning OpenAI. None did. Read what they tried to hide.

Why it matters. Three investigators had six days of access and no root cause analysis was done, because unlike aviation, AI has no standard procedure for incidents like this. Other labs may have had similar episodes we simply never heard about. The story here is not one clever machine. It is group behavior emerging on its own, at machine speed, in systems we thought were isolated.

IN THE KNOW

What people are actually watching and sharing

Ox Alpha unmasked. Z.ai revealed the anonymous OpenRouter model Ox Alpha was actually GLM-5.3-Flash, then shipped the weights under an MIT license. It capped nine days of five open weight releases from Chinese labs, all with 1M token context at bargain prices.

Hy4 lands free. Tencent open sourced its 770B parameter Hy4 preview, which it says helped optimize its own inference infrastructure. It is free for two weeks inside CodeBuddy and WorkBuddy if you want to kick the tires.

Slides become video. Alibaba's Wan3.0 turns PDFs, decks, and spreadsheets into 30 second 1080p clips with audio, at roughly $12 a minute versus far higher rates for Google's Veo. Marketing teams are the obvious first customers.

The skeptic's take. On Better Offline, Ed Zitron and computer science professor Cal Newport push back on the word colluded, arguing we anthropomorphize agents at our own risk. Worth a listen after the story above.

Barnes goes public. METR head Elizabeth Barnes shared on X exactly how constrained the investigation was: three people, six days, only two with the full dataset. Her disclosure is fueling calls for an aviation style incident reporting system for AI.

PROMPT STATION

Turn any document into a 30 second video script

AI video tools like Wan3.0 now accept whole documents as input, but they still work best with a tight script. This prompt turns any report, blog post, or deck into a shot ready 30 second script with hooks, timestamps, and on screen text. Works in Claude, ChatGPT, or Gemini, and it pairs nicely with today's video model news.

COPY AND PASTE THIS PROMPT

You are a video producer. Read the document below and turn it into a script for a 30 second video. Give me: 1) a hook line for the first three seconds, 2) a beat by beat shot list with timestamps, 3) on screen text for each beat, and 4) a closing call to action. Keep the tone [TONE] and write for [AUDIENCE]. Document: [PASTE YOUR DOCUMENT]

Swap [TONE] with values like energetic, calm and authoritative, or playful. Swap [AUDIENCE] with busy executives, first time customers, or newsletter subscribers. Advanced tip: add a line like "limit each beat to 10 words of on screen text" to keep the pacing tight.