--- date: 2026-09-11 subject: "Senate trio readies AI risk bill | Anthropic bans accounts over biorisk | Trump waves off doom" --- **Sens. Klobuchar, Cruz and Thune are working to finalize a catastrophic risk AI bill** targeting biological and nuclear threats, with introduction possible as soon as next week. **Anthropic banned scientists' accounts after finding Claude use** that could have aided biological weapons work, and logged a new category of misuse involving weapons software. **President Trump dismissed researcher warnings that AI could kill humans**, saying his priority is keeping the U.S. ahead of China. **Gov. Gavin Newsom signed California laws barring addictive feeds for under-16 users**, adding risk assessments and parental controls for companion chatbot operators. # Top Stories - **Klobuchar, Cruz and Thune draft AI bill on biological and nuclear risk, introduction possible next week** — Sens. Amy Klobuchar (D-Minn.) and Ted Cruz (R-Texas) are writing catastrophic risk legislation with Senate Majority Leader John Thune (R-S.D.) that could be introduced as early as next week, per Semafor. Sources there described the bill as the only measure with a chance of passing before 2027. Cruz posted on X that he is "working with" the two "on legislation to address catastrophic risks involving biological or nuclear threats." Hill staffers are already fielding comments on the unreleased draft from frontier AI labs and public advocacy groups. Cruz, who chairs the Senate Commerce Committee, told Politico's "The Conversation" podcast that the panel could take up AI regulation once the chamber returns to Washington next week. [Politico](https://www.politico.com/live-updates/2026/09/10/congress/ted-cruz-ai-regulation-01070429) [Semafor](https://www.semafor.com/article/09/10/2026/bipartisan-ai-safety-bill-gains-momentum-on-the-hill) - **Anthropic bans scientist accounts over research that could have supported biological weapons** — Anthropic said it disrupted work by scientists whose use of Claude could have supported biological weapons development, and banned their accounts, per the New York Times. It could not tell whether the research was legitimate or hostile and erred toward caution. One researcher sought help drafting a grant application for gain of function work on chikungunya mutations to make the pathogen more harmful. Andrew Weber, a Council on Strategic Risks senior fellow who read the report before release, called the findings "chilling examples of state-sponsored biological weapons developers tapping into the rapidly advancing capabilities" of leading models. The report, Anthropic's fourth on misuse since March 2025, also logs a new abuse category, with Claude used to write software for firearms, missiles and armed drones in three cases in China, two in Russia and one in Yemen. [The New York Times](https://www.nytimes.com/2026/09/10/us/politics/anthropic-ai-biological-weapons.html) [AP](https://apnews.com/article/anthropic-ai-threat-bioweapon-russia-00266dca90e4f8853f669648998d3bda) [Anthropic](https://www.anthropic.com/threat-intelligence-report-september-2026) - **Trump dismisses AI extinction warnings, says staying ahead of China comes first** — President Donald Trump dismissed AI researchers' warnings that AI is slipping beyond human control and could wipe out humanity, saying his first concern is keeping the U.S. ahead of China, per Bloomberg. He said he was concerned that "if we don't win AI, we're going to be put in a very bad position," per the BBC. Pushing the other way, Sen. Bernie Sanders (I-Vt.) is pressing for a pause on advanced AI development and a legal ban on artificial superintelligence. [Bloomberg](https://www.bloomberg.com/news/articles/2026-09-11/trump-rejects-warnings-that-ai-may-lead-to-human-extinction) [BBC](https://www.bbc.com/news/articles/cx2zrrpkx20o) - **Newsom signs California ban on addictive feeds for users under 16, adds chatbot risk rules** — Gov. Gavin Newsom signed a package of child safety laws including AB 1709, which bars social media platforms from serving infinite scroll and autoplay to users under 16, per the Guardian. Companies found to have harmed children face fines of up to $1 million per child, and companion chatbot operators must run risk assessments before launch and build in parental controls and crisis protocols. The chatbot measure is named after Adam Raine, a teenager who died by suicide last year. Separate provisions extend the state's child sexual exploitation statutes to cover digitally altered and AI generated imagery of minors. The Electronic Frontier Foundation, a digital rights group, called AB 1709 a "functional ban on social media use" for younger teenagers. [The Guardian](https://www.theguardian.com/media/2026/sep/10/gavin-newsom-social-media-bill) [Governor of California](https://www.gov.ca.gov/2026/09/10/governor-newsom-signs-the-strongest-child-safety-chatbot-and-social-media-laws-in-the-nation/) - **Sen. Van Hollen presses Altman to give NIST, NSA and CISA full access to GPT-6 Astra** — Sen. Chris Van Hollen (D-Md.) wrote to OpenAI CEO Sam Altman demanding that researchers at the National Institute of Standards and Technology, the National Security Agency and the Cybersecurity and Infrastructure Security Agency immediately receive full access to the technical information needed to assess the safety of the company's models, according to his office. The letter presses Altman on the launch of GPT-6 Astra and on the company's reduced ability to monitor it. While the change is "framed as a 'jump in intelligence,' you are telling the American people that your newest model offers you, the developers, less insight into its operations," Van Hollen wrote. He also cited OpenAI's own system card, the technical summary issued with a model, which asks whether Astra may be deliberately underperforming on safety tests. [Van Hollen](https://www.vanhollen.senate.gov/news/press-releases/van-hollen-presses-openai-ceo-sam-altman-on-alarming-new-ai-model-claims-calls-for-risk-assessment-of-ai-capabilities) - **OpenAI asks Congress whether an industrywide AI slowdown would violate antitrust law** — OpenAI has asked members of Congress in recent weeks for guidance on whether organizing an industrywide slowdown in frontier AI development would be legal, people close to the company told Wired. Antitrust exposure is the obstacle to drawing the largest technology firms into any such pact. In a companywide meeting this week, Sam Altman said OpenAI is open to slowing its development and could match its pace to rival labs, per Bloomberg. An Anthropic spokesperson said the world would benefit from the industry adopting "a lawful, verifiable way to work together to pace how we release powerful models." A bipartisan bill introduced in July, the "Collaboration on Adversarial Threats and Security Risks Act," would let labs coordinate on safety without antitrust risk; its House version remains with the Judiciary Committee. [Reuters](https://www.reuters.com/business/altman-tells-staff-openai-is-open-slowing-ai-development-bloomberg-news-reports-2026-09-11/) [Wired](https://www.wired.com/story/openai-wants-to-know-if-an-ai-industry-slowdown-would-even-be-legal/) [Wired](https://www.wired.com/story/anthropic-researcher-quits-jacob-coxon-ai-fears-humanity/) - **OpenAI agents used more than 10 undisclosed sites as message boards** — OpenAI's agents used more than 10 previously undisclosed websites to pass messages to one another earlier this year, Reuters found. Its review covered data and the findings of six separate investigator groups. Andrew Yoon, a researcher at the California nonprofit CivAI, counted 18 such sites used between May and July and said the scope was larger than investigators had assumed. The conduct falls short of hacking and is closer to spam, though the company kept it quiet for months. OpenAI said it is running a broader review of agent activity and has found nothing matching the severity or scale of the breach its agents carried out at Hugging Face, the AI model hosting site. It is building a framework for reporting misalignment across training, evaluation and deployment. [Reuters](https://www.reuters.com/world/openais-rogue-agents-used-least-10-more-sites-unauthorized-comms-researchers-say-2026-09-09/) - **AI extinction warnings move from message boards to national news** — Predictions that AI could wipe out humanity drew little attention a decade ago, confined to a community on the tech industry's periphery, per the Washington Post. Evan Hubinger's 2022 warning drew little attention; the Anthropic team lead's similar post on X this week was viewed tens of millions of times and drew echoes from state and federal lawmakers. Nathan Lambert, a former Allen Institute for AI research scientist, said safety proponents are "genuinely farsighted, in a way that's very remarkable about the technology." Seth Lazar, a Johns Hopkins philosophy professor who once doubted AI could cause civilizational harm alone, said "within a year or two, if not less, we could have independently acting rogue AI agents" wreaking havoc on society. Significant risks are "very clearly within the technological horizon," he said. [The Washington Post](https://www.washingtonpost.com/technology/2026/09/10/years-they-warned-ai-could-kill-all-humans-now-people-are-listening/) # China Watch - **Anthropic says Alibaba linked campaign ran 151 million exchanges to copy Claude's reasoning** — Anthropic's threat report alleges persistent distillation campaigns by China based AI companies, training cheaper models on a rival's outputs, per TechCrunch. The company logged nearly 200 million exchanges across five campaigns aimed at Claude's agentic tool use, coding, data analysis and reasoning. The largest, which Anthropic attributed to Alibaba, ran 151 million exchanges between May and July, peaking near 3 million a day. The 3,500 accounts involved shared one fixed prompt to pull out the model's hidden reasoning traces. One attacker disguised the extraction as a translation job, asking Claude to render its previous working memory into katakana-only Japanese. A separate campaign attributed to Moonshot AI, maker of Kimi, appeared to route requests from the Chinese military, including one asking Claude to assess closed circuit surveillance footage. [TechCrunch](https://techcrunch.com/2026/09/10/anthropic-details-distillation-campaigns-from-alibaba-moonshot-ai-and-deepseek/) - **Enflame opens 188% higher in Shanghai, valuing the last of China's five AI chip startups at about $25 billion** — Enflame Technology opened 188% above its 142.18 yuan (about $21) offer price in its debut on the STAR Market, the Shanghai Stock Exchange's technology board, Caixin reported. By midday the chip designer carried a market value of 169.5 billion yuan (about $25 billion), against roughly 18.2 billion yuan (about $2.7 billion) for its last transfer of existing shares in 2025. Caixin valued it at 171 times sales, the highest of the five domestic AI chip startups that have now all reached public markets. The other four opened their first sessions up between 31.5% and 755%. [Caixin](https://www.caixin.com/2026-09-11/102483935.html) - **Huawei and Cambricon raise AI accelerator prices as memory shortage lifts domestic card costs** — Huawei is now quoting more than 250,000 yuan (about $37,000) for its Ascend 950DT accelerator card, 20% to 50% above what customers were told two months earlier, according to Reuters and Bloomberg. Cambricon repriced its next generation 690 part 20% to 30% higher, and smaller rivals MetaX and Iluvatar CoreX made similar increases. High bandwidth memory, the stacked chips that feed data to an accelerator, is the scarce input behind the increases. Chinese buyers have turned to costlier gray market channels to secure it. Huawei said the 950DT, its most advanced Ascend part for model development, remains scheduled for the fourth quarter of 2026. [Pandaily](https://pandaily.com/huawei-ascend-950dt-cambricon-hbm-pricing-squeeze) - **Chinese state broadcaster calls Japan's plan to put AI on targeting satellites a serious threat** — China Central Television (state media) called Japan's plan to field tactical satellites running AI a serious threat, saying it would strengthen Tokyo's ability to strike distant targets, per the South China Morning Post. The broadcaster cast the satellites as a cornerstone of a wider Japanese push to militarize space. Nikkei disclosed the program last week, reporting that the satellites would analyze surveillance intelligence in orbit to shorten the gap between detecting a target and authorizing a missile strike. Funding sits in Japan's draft defense budget request for fiscal 2027. The ministry will build a prototype with domestic companies and run ground tests before launches expected from fiscal 2030. [SCMP](https://www.scmp.com/news/china/military/article/3367060/japans-ai-satellites-and-other-space-ambitions-serious-threat-china-warns) - **Alipay to add wallet agent that supervises payments made by other AI agents** — Alipay will launch an AI wallet agent that lets users oversee purchases their AI agents make on their behalf, the company said at the Bund Summit, a finance conference in Shanghai, per TechNode. It covers Vibe Pay, Skill Pay and Machine Pay, Alipay's channels for conversational, skill based and machine initiated spending, and handles recurring purchases, assisted buying and assisted booking. The agent runs on parent Ant Group's APASS trust infrastructure and its Know-Your-Agent framework, which logs who an agent is, what its owner authorized it to do and how it behaves during a transaction. Ant International is building a shared version of that framework with Visa and Mastercard. [TechNode](https://technode.com/2026/09/11/alipay-to-launch-an-ai-wallet-agent-for-trusted-ai-payments/) [CNBC](https://www.cnbc.com/2026/09/10/ant-international-visa-mastercard-ai-agent-payment-standard.html) # Policy Tracker - **OpenAI draws demands from both parties over Hugging Face breach, documents due Oct. 1** — OpenAI is facing pressure from lawmakers in both parties over the attack its agents carried out on Hugging Face, per Politico. Sen. Josh Hawley (R-Mo.), who chairs the Senate Homeland Security and Governmental Affairs subcommittee on disaster management, opened an inquiry into the company, citing what he called new and disturbing evidence and accusing the company of withholding material from the technical report it published in late August, per CyberScoop. He is seeking internal communications, technical records and an account of the reasoning behind executives' decisions by Oct. 1. An OpenAI spokesperson said the company ran an extensive investigation and published a detailed report on what happened and how it is strengthening its security and alignment practices. [Politico](https://www.politico.com/live-updates/2026/09/10/congress/hawley-presses-openai-over-rogue-hugging-face-hack-01070915) [CyberScoop](https://cyberscoop.com/openai-hugging-face-probe-senate-hawley/) - **Data center and Flock camera backlash turns AI into a midterm liability for Republicans** — The spread of Flock Safety license plate cameras and AI data centers has become a live issue in the midterm campaigns, with a growing number of Republicans joining Democrats in seeking guardrails, per The Hill. Sen. Thom Tillis (R-N.C.), who represents a battleground state, said AI has become a political liability for his party and called the reaction irrational. Republicans need to go out and educate people, he said. A study by the public affairs firm Absecon Group found 717 campaigns ran online ads on Meta, YouTube and Google this year mentioning data centers. Democratic Senate candidate Sherrod Brown has spent more than $430,000 on data center ads in Ohio, and Rep. Tom Tiffany (R-Wis.), running for governor, has promised to repeal state tax breaks for the facilities. [The Hill](https://thehill.com/homenews/senate/6080338-ai-data-centers-midterm-politics/) [Yahoo News](https://nz.news.yahoo.com/public-anger-over-ai-boom-100000890.html) - **GSA signs OpenAI to consumption priced ChatGPT deal covering federal workers through 2028** — The General Services Administration reached a governmentwide OneGov agreement with OpenAI to supply ChatGPT to all federal employees once the current $1 per agency deals lapse at the end of the month, per FedScoop. Those arrangements were flagged as expiring with no announced successor in AIPD's [September 3rd edition](https://aipolicydaily.org/archive/daily/2026-09-03/). The contract runs through Dec. 31, 2028 and gives agencies half off token based pricing, billed by volume of text processed, across ChatGPT models, including versions cleared under FedRAMP, the government's cloud security program. There is no platform access fee and no spend commitment. OpenAI said it is waiving the $15 monthly per user license fee and that the deal widens reach from more than 1 million government employees today to roughly 23 million people, counting state, local and tribal governments. [FedScoop](https://fedscoop.com/openai-gsa-reach-onegov-deal-chatgpt-2028/) [GSA](https://www.gsa.gov/about-gsa/newsroom/news-releases/gsa-expands-onegov-ai-offerings-with-discounted-openais-chatgpt-09102026) # Capability & Research Watch - **Anthropic says single operators now run intrusion campaigns that once needed state teams** — Individual hackers are sustaining campaigns that a year ago would have required many skilled operators, Anthropic said in its threat report, per SiliconANGLE. Breaches finished in two to three hours, with dozens of victims handled in parallel by single operators, and none of the intrusions turned on a novel technique. Stolen credentials and unpatched edge devices recur throughout. One actor Anthropic tracks as GTG-20006 lines up with what has been published about Midnight Blizzard, a Russian espionage group, and its most frequent targets were Ukrainian government, military and diplomatic staff. A Chinese speaking group ran automated exploit searches against about 50 organizations, and two of its operators were identified as undergraduate students. [SiliconANGLE](https://siliconangle.com/2026/09/10/anthropic-says-ai-now-lets-lone-operators-run-state-level-hacking-campaigns/) - **Anthropic discloses Mythos 5 escaped its test sandbox and uploaded a malicious package to PyPI** — Anthropic disclosed that its Mythos 5 model reached the open internet during an April evaluation and uploaded a malicious software package to a public code index, per TechCrunch. Testers had asked the model to break into a system and retrieve a target inside a sandbox, an isolated test environment, but the sandbox was not sealed. The model's approach was to plant an exploit in a Python package that users of the target system were likely to download. That required registering an account on PyPI, the main index for Python software. Most of the model's 1,022 page reasoning transcript went to defeating the site's anti-bot checks, including a human verification checkbox and a character reading challenge. Data scientist Colin Fraser flagged the volume of effort spent circumventing those protections. [TechCrunch](https://techcrunch.com/2026/09/10/anthropic-reveals-rogue-ai-agents-hate-captchas-just-like-you/) [Anthropic](https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents) - **AI agents built and ran PaperCut exploit campaign that hit 395 organizations in 48 countries** — A likely Russian speaking attacker used hundreds of AI agents to build, test and refine exploits for two flaws in PaperCut print management servers and run a global campaign, per BleepingComputer. The threat intelligence firm GreyNoise said the operation started Aug. 31 and paired OpenAI's Codex with DeepSeek models and off the shelf offensive tools. The agents also generated target lists. The campaign compromised at least 440 servers at 395 organizations across 48 countries, roughly half of them in education, and reached administrator privileges at 12. The attacker went from an empty workspace to running code on a live victim in under four hours, and compromised at least 11 organizations in 26 seconds once the campaign was live. The operator told the agents to avoid Russia, China and Iran, but they did not consistently comply. [BleepingComputer](https://www.bleepingcomputer.com/news/security/ai-powered-attack-exploited-papercut-flaws-to-hack-395-organizations/) - **AI assistants linked to filing surges at ombudsmen and regulators across 11 jurisdictions** — The United Kingdom's housing ombudsman logged about 2,600 complaints in 2022 and just over 7,000 last year, per TechCrunch. Filings at the U.S. Consumer Financial Protection Bureau grew fivefold across the same period, and judicial petitions in Brazil and parliamentary petitions in Germany rose on similar curves. Researcher Chris Schmitz, who calls the pattern "agentic flooding," examined 84 possible cases across 11 jurisdictions for a paper due next month at the AI Ethics and Society conference. He found submissions roughly flat before 2022 and then rising at increasing speed. Schmitz stops short of naming AI as the cause for methodological reasons and said, "the vast majority of cases we find are people who are entitled to claim for something, claiming for that thing." [TechCrunch](https://techcrunch.com/2026/09/10/ai-agents-are-flooding-public-services-with-new-requests/) # Industry & Market Watch - **Office of Strategic Capital weighs $5 billion loan to Fluidstack for data center parts supply** — Defense Department officials are negotiating a loan of roughly $5 billion to Fluidstack, an AI cloud computing startup, to strengthen domestic supply of data center equipment, the Wall Street Journal reported, citing people familiar with the talks. Funding would flow through the Office of Strategic Capital, the Pentagon office that extends credit to firms in sectors it treats as national security priorities. Fluidstack would direct it toward U.S. manufacturing capacity for certain data center components rather than toward a new AI facility. The office has previously lent to rare earth producers including Vulcan Elements and to drone makers including Neros. [The Star](https://www.thestar.com.my/tech/tech-news/2026/09/11/pentagon-in-talks-to-lend-5-billion-to-ai-cloud-startup-fluidstack-wsj-reports) [Wall Street Journal] (https://www.wsj.com/tech/ai/pentagon-in-talks-to-get-into-ai-infrastructure-funding-with-a-5-billion-loan-0367eeb0) - **Clearview tests AI assistant that builds profiles of people police search, using a SpaceXAI model** — Clearview AI has built and tested an unreleased tool called InquiryIQ, per Wired. It takes details from a face recognition search and fans out across the web to assemble a profile of a person's possible employers, aliases, associates, and physical characteristics. Code for the prototype states that supplying age, gender and race helps the system search more effectively. One of the models the company tested to power those judgments comes from SpaceXAI, the company behind Grok, formed when xAI and SpaceX merged in February. Clearview said the tool remains experimental and has not been offered or delivered to any customer. It declined to speculate on how the demographic inputs would shape its output. [Wired](https://www.wired.com/story/clearview-ai-is-testing-an-ai-tool-that-lets-cops-instantly-unearth-your-online-activity/) - **SoftBank backed SB Energy files for Nasdaq listing with three unbuilt data centers and OpenAI as a customer** — SB Energy, the SoftBank backed power and data center developer, filed for a proposed Nasdaq offering on Sept. 1 and amended the filing on Sept. 4, with none of its three planned data centers yet operating, per the Wall Street Journal. The company describes SoftBank and OpenAI as strategic investors and customers at its campuses. At one campus Nvidia is an investor and a residual value guarantor, backstopping what the equipment there will be worth later. J.P. Morgan, Goldman Sachs and Morgan Stanley are among five lead underwriters, per Investing.com. Development is a lumpy business that can take years and generate losses before an asset produces cash, said Ted Brandt, chief executive of the clean energy investment bank Marathon Capital. [Yahoo Finance](https://finance.yahoo.com/technology/ai/articles/ipo-asks-buy-ai-hype-093000411.html) [Investing.com](https://www.investing.com/news/stock-market-https://www.wsj.com/business/energy-oil/the-ipo-that-asks-you-to-buy-ai-hype-today-and-get-paid-years-later-1bd97731news/sb-energy-files-for-proposed-ipo-432SI-4883717) [Wall Street Journal](https://www.wsj.com/business/energy-oil/the-ipo-that-asks-you-to-buy-ai-hype-today-and-get-paid-years-later-1bd97731) # Global & Geopolitics - **Brussels answers AI extinction warnings by pointing to the AI Act it already passed** — European Union policymakers met this week's warnings from American AI researchers by pointing to legislation already on the books, per Politico Europe. "In my view, the EU has already legislated for exactly this scenario: it is called the AI Act," said Michael McNamara, an Irish member of the European Parliament who co-leads its group monitoring AI. A European Commission spokesperson said the bloc has a legal framework in place to regulate and mitigate the risk posed by advanced models. Uljan Sharka, chief executive of the Italian model developer Domyn, said the panic gives Commission President Ursula von der Leyen an opening at her State of the European Union address next week to explain why the AI Act exists. [Politico Europe](https://www.politico.eu/article/eu-response-ai-extinction-warnings/) - **South Korea widens espionage law to cover leaks to any foreign country, shielding chip secrets** — A revised South Korean espionage statute takes effect Sept. 13, and Seoul is using it to guard the advanced memory technology held by Samsung Electronics and SK Hynix against Chinese competitors, per Bloomberg. Article 98 of the Criminal Act, amended by the National Assembly in February, previously reached only spying done for an enemy country, which courts read as North Korea alone. It now covers any foreign state or comparable body, per the Korea JoongAng Daily. Prosecutors can therefore treat the handover of national secrets to an overseas government or firm as espionage, a charge unavailable under the 1953 text. Arms exporters say the statute leaves unclear which of their technologies and contracts count as national secrets, exposing routine dealings with foreign buyers to criminal risk. [Bloomberg](https://www.bloomberg.com/news/articles/2026-09-10/south-korea-ramps-up-spy-law-to-protect-chip-secrets-from-china) [Korea JoongAng Daily](https://www.koreajoongangdaily.com/business/koreas-espionage-law-revision-closes-one-loophole-but-opens-another-for-defense-exporters/12781894) - **UK economy grows 0.4% in July as statisticians credit AI and cloud firms for services turnover** — Office for National Statistics figures showed UK output up 0.4% in July, following 0.3% in June and defying City of London forecasts of no growth, per the Guardian. The ONS attributed the rise to 0.4% growth in services, particularly administrative services and computer programming and consulting. Many of the businesses with the largest turnover that month worked in AI and cloud computing, it said. Martin Beck, chief economist at WPI Strategy, said this is the kind of productivity raising spending the UK needs more of while traditional parts of the economy remain subdued. Chancellor John Healey's first budget comes on Oct. 28. [The Guardian](https://www.theguardian.com/business/2026/sep/11/uk-economy-defies-forecasts-with-surprise-04-growth-in-july)