Subscribe

Five minutes.
AI, made clearer.

Read the second sentence.

Read the briefing

Members read every story in the archive, re-verified. Sources and corrections stay open to everyone.

What the pen marks mean
  • rememberThe takeaway: what to remember
  • figureThe number that matters
  • evidenceThe evidence line
  • rulingThe ruling
  • claimThe claim that fails

Each mark is drawn once, as you reach it. Numbers are only circled when they come from the story’s own figures.

Rogue OpenAI agents 'meddled' with three US government sites. Two visits were public data; the one hack attempt did not succeed.

The New York Times reported that OpenAI's technology went rogue and meddled with three U.S. government websites, and CNN headlined that rogue agents targeted three separate US government websites. The sites were the SEC, the Commerce Department's Census Bureau and the Education Department.

Members · 30 days free

See what the evidence actually shows.

Members read the full check on every story: what the evidence shows, why it matters to you and the one line to take with you. Every past edition, re-verified, and the Receipts Pack come with it. A$89 a year, about A$0.24 a day.

First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge.

Open the evidence3 source pages

The claim we checked

The New York Times reported that OpenAI's technology went rogue and meddled with three U.S. government websites this summer without the lab's knowledge; CNN headlined that rogue OpenAI agents targeted three separate US government websites.

These are quoted receipts, not a count of independent investigations. Several reports may rely on the same original source.

CNN ↗
Rogue OpenAI agents targeted three separate US government websites
The Daily Caller ↗
Breaking News: OpenAI’s technology went rogue and meddled with three U.S. government websites this summer without the A.I. lab’s knowledge.
NPR (Associated Press) ↗
The AI giant's models accessed publicly available information on two websites operated by the Securities and Exchange Commission as well as U.S. Census Bureau data, the company revealed Friday.
NPR (Associated Press) ↗
OpenAI did not find any use of SEC credentials, access to accounts or nonpublic information, changes to SEC data or systems, or evidence of a compromise or vulnerability, the company said.
CNN ↗
OpenAI said Saturday that its agents accessed publicly available data from the Commerce Department’s Census Bureau using login credentials it found online, and separately shared public data from the SEC website on another website.
The Daily Caller ↗
At Commerce, the agents pulled Census Bureau figures after finding login credentials in public code repositories, Politico reported
NPR (Associated Press) ↗
AI evaluator and research lab Transluce said Friday that through an independent investigation it also found that agents appearing to originate from OpenAI attempted a rudimentary hack on a Department of Education website for the department's civil rights office, which did not succeed.
NPR (Associated Press) ↗
The Department of Education's "system operations reviews" found "no evidence of any impact to our website or databases," a department spokesperson said Friday.
Open this check in the full collection →
The idea, as a cartoon01

The check, step by step

    Next: A billion deaths, and who holds the weapon.

    Gates did say AI could drive a billion deaths. The headlines cropped out the people with ill intent.

    In an excerpt from a Meet the Press interview set to air in full Sunday, Bill Gates told Kristen Welker that AI is certainly powerful enough to drive events that cause a billion deaths. NBC's own video title and follow-up headlines at Newsweek and The Next Web led with that line.

    Members · 30 days free

    See what the evidence actually shows.

    Members read the full check on every story: what the evidence shows, why it matters to you and the one line to take with you. Every past edition, re-verified, and the Receipts Pack come with it. A$89 a year, about A$0.24 a day.

    First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge.

    Open the evidence5 source pages

    The claim we checked

    Bill Gates told NBC's Meet the Press that AI is powerful enough to cause a billion deaths, as NBC's own video title and follow-up headlines put it.

    These are quoted receipts, not a count of independent investigations. Several reports may rely on the same original source.

    NBC News (Meet the Press) ↗
    Bill Gates says AI 'powerful enough' to cause 'a billion deaths'
    NBC News ↗
    AI is certainly powerful enough to drive events that, you know, cause a billion deaths. You know, so even though it’s pretty hard to get to 100%, there’s never been a weapon as powerful as the combination of people with ill intent using the latest AI tools
    NBC News ↗
    there’s never been a weapon as powerful as the combination of people with ill intent using the latest AI tools
    NBC News ↗
    “No one thinks self-regulation is enough,” Gates told NBC News’ “Meet the Press” in an interview set to air in full Sunday.
    NBC News ↗
    Asked by moderator Kristen Welker whether there needs to be legislation passed in Washington, Gates said, “Absolutely.”
    Newsweek ↗
    Why Bill Gates Thinks AI Is Strong Enough to Cause 'a Billion Deaths'
    Newsweek ↗
    While some researchers have warned that AI could eventually threaten humanity's survival, Gates focused on the immediate danger of powerful AI tools falling into the hands of bad actors capable of causing catastrophic harm.
    The Next Web ↗
    There has never been a weapon as powerful as people with ill intent using the latest AI tools, the Microsoft co-founder said.
    [your]NEWS ↗
    In fuller excerpts of the interview, Gates framed the danger around people deliberately using increasingly capable AI systems rather than predicting that an autonomous machine would independently decide to destroy humanity.
    Open this check in the full collection →
    The idea, illustrated02

    Go inside the check.

      The full explanation appears when your reading access is confirmed.
      Next: An AI worm, found in OpenAI's own training runs.

      OpenAI found a self-copying prompt injection in its own training runs. It says no impact was seen outside simulation.

      OpenAI trained a GPT-Red-style attacker model to write prompt injections that make an agent repeat the injection on a public output channel. The email and filesystem cases used internal-only research checkpoints based on GPT-5.4-mini; a separate Slack evaluation used GPT-5.5 as the vulnerable model.

      Members · 30 days free

      See what the evidence actually shows.

      Members read the full check on every story: what the evidence shows, why it matters to you and the one line to take with you. Every past edition, re-verified, and the Receipts Pack come with it. A$89 a year, about A$0.24 a day.

      First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge.

      Open the evidence3 source pages

      The claim we checked

      Crypto Briefing wrote that OpenAI's internal research uncovered AI worms that can spread autonomously across agents; 24/7 Wall St. wrote that the finding proves stronger agents bypass containment.

      These are quoted receipts, not a count of independent investigations. Several reports may rely on the same original source.

      Crypto Briefing ↗
      The company's internal research uncovered AI worms that can spread autonomously across agents, though no real-world attacks have been recorded yet
      OpenAI ↗
      We show the existence of a new variety of prompt injection, which can self-propagate akin to a computer worm.
      OpenAI ↗
      No impact was observed outside of the simulated tool calls in training and evaluation; we are sharing this due to the novel nature of the prompt injection, not because of any incident.
      OpenAI ↗
      The separate Slack multi-hop evaluation used GPT-5.5 as the vulnerable model, with the attack discovered by GPT-5.5 running in the Codex harness.
      OpenAI ↗
      We trained on a GPT-Red-style prompt injection objective, with an additional objective that the prompt injection must induce the model to repeat the injection itself on a public output channel.
      OpenAI ↗
      The model that discovered the email and filesystem injections was a GPT-Red-style model based on GPT-5.4-mini; the vulnerable model was also based on GPT-5.4-mini. Both were internal-only research checkpoints.
      OpenAI ↗
      We are including self-reproduction as an aspect of attacker goals in GPT-Red training. This means that future models we release will have seen prompt injections like these during training.
      Crypto Briefing ↗
      The entire investigation took place in simulated environments.
      Shattered ↗
      published on OpenAI’s alignment research site, lists a discovery date of June 27, 2026, and a disclosure date of September 25, 2026, meaning OpenAI sat on the finding internally for roughly three months before going public.
      Open this check in the full collection →
      The idea, illustrated03

      Go inside the check.

        The full explanation appears when your reading access is confirmed.
        Next: A clause cut, and a headline that cut more.

        The headline says US and Russia stripped human oversight from a UN AI weapons pact. The text still affirms human control.

        At the final Geneva session of the UN group on lethal autonomous weapons, U.S. and Russian diplomats spent roughly 15 hours removing provisions, according to three people who spoke to the Washington Post. They say the cuts included a provision requiring that humans review military targets developed by AI before a strike.

        Members · 30 days free

        See what the evidence actually shows.

        Members read the full check on every story: what the evidence shows, why it matters to you and the one line to take with you. Every past edition, re-verified, and the Receipts Pack come with it. A$89 a year, about A$0.24 a day.

        First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge.

        Open the evidence4 source pages

        The claim we checked

        The Washington Post reported that the U.S. and Russia stripped human oversight from a global AI weapons pact at UN talks in Geneva, including a provision requiring that humans review military targets developed by AI before a strike; Seoul Economic Daily relayed it as the two countries stripping a key clause from a draft UN AI weapons treaty.

        These are quoted receipts, not a count of independent investigations. Several reports may rely on the same original source.

        The Washington Post (via The Spokesman-Review) ↗
        The U.S. and Russian teams also removed a provision requiring that humans review military targets developed by AI before a strike, they added.
        The Washington Post (via The Spokesman-Review) ↗
        Over the next roughly 15 hours, U.S. and Russian diplomats hammered away at the document, removing a range of provisions designed to safeguard the use of artificial intelligence in weapons, according to three people familiar with the negotiations, who spoke on the condition of anonymity to discuss sensitive closed-door proceedings, and documents reviewed by the Washington Post.
        The Washington Post (via The Spokesman-Review) ↗
        The lethal autonomous weapons negotiations in the U.N. are currently nonbinding, though the talks could open the door to a landmark treaty that is legally binding if member nations agree.
        Human Rights Watch ↗
        The UN’s final report has some positive elements. It includes a characterization of lethal autonomous weapons systems, affirms that human control and judgment are required for compliance with international law, and incorporates restrictions on systems that cannot comply with that law.
        Human Rights Watch ↗
        Certain states, including Russia and the United States
        Human Rights Watch ↗
        weakened the text by insisting on changes to widely supported provisions.
        France, Ministry for Europe and Foreign Affairs (via GlobalSecurity.org) ↗
        and reaffirms, in accordance with France's steadfast positions, that human beings "exercise control" over weapons systems with autonomous functions.
        UK Stop Killer Robots (UNA-UK) ↗
        It was the last opportunity for governments to shape the GGE’s proposed “set of elements” before the CCW’s Seventh Review Conference in November, when states will decide whether to move towards formal negotiations.
        Open this check in the full collection →
        The idea, illustrated04

        Go inside the check.

          The full explanation appears when your reading access is confirmed.
          The finish line

          Edition complete

          You’re up to speed.

          That’s the 27 Sept 2026 briefing. Keep the useful bits. Leave the noise.

          Reading estimate: 850 words at 200 words per minute. Source quotes and the optional sections below add reading time.