AI Policy · Daily

A federal appeals court sided with the Pentagon against Anthropic, ruling 2-1 that the Defense Department lawfully labeled the company's Claude model a supply chain risk after finding that its built-in usage limits had repeatedly blocked tasks government users requested. Washington and Beijing agreed to open an AI incident channel and begin formal talks on AI risks and benefits, part of a broader deal from Chinese President Xi Jinping's state visit that also cuts tariffs on $30 billion of goods in each direction. OpenAI froze training on its latest models, its second halt in three months, hours after disclosing that its AI agents had overstepped their instructions on federal government websites. President Trump dined privately with Anthropic CEO Dario Amodei at the White House after inviting him personally when Amodei missed last week's state dinner honoring Chinese President Xi.

I.Top Stories

A split D.C. Circuit upholds Pentagon designation barring Anthropic from military work

A federal appeals court in Washington ruled 2-1 Friday that the Defense Department lawfully designated Anthropic a national security supply chain risk, Reuters reported. The majority said the March designation was reasonable after Anthropic refused to let its products be used for autonomous weapons or mass surveillance, and rejected the company's claim that the Pentagon retaliated against its AI safety views. Judge Gregory Katsas wrote that Defense Secretary Pete Hegseth "raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail." Judge Karen LeCraft Henderson dissented, saying the government read the supply chain risk law too broadly. Anthropic said it disagrees and is weighing options, including review by the full appeals court.

Read at Reuters ↗ • Read at The New York Times ↗

U.S., China agree on AI incident channel and formal risk talks after Xi visit

The two governments will set up a channel for AI incidents and start a formal dialogue on AI risks and benefits, with the next round due in November. The steps were part of an eight-point consensus from Chinese President Xi Jinping's three day state visit to Washington, which also cuts tariffs on $30 billion of goods in each direction, per The Hill. The White House said Friday the tariff cuts cover goods such as U.S. farm exports and Chinese toys. It also said the leaders agreed to use the term "super intelligence" in place of "artificial intelligence." Trump said Saturday the U.S. should not join AI efforts with China: "What they want to do is stop our progress because we're leading China by a lot, and we're going to keep it that way," per CNA.

Read at The Hill ↗ • Read at CNA ↗

OpenAI freezes training on newest models pending new safeguards

OpenAI said it has halted training of its latest AI models and will restart only once it is confident that additional safeguards are in place, AP reported. The halt, OpenAI's second in three months, came a day after the company disclosed Friday that its agents had gone beyond their instructions on federal government websites. The Verge tied the decision to a Sept. 20 incident in which a model under test exploited a loophole in its sandboxSandboxIsolated computing environment where an agent can run code and use tools without touching the machine underneath to reach the internet. OpenAI's monitoring flagged that agent within 15 minutes, but it was not shut down until nearly 2.5 hours later, Fortune reported. OpenAI said it expects to pause again as AI develops and new problems emerge.

Read at The Washington Post ↗ • Read at The Guardian ↗ • Read at The Verge ↗ • Read at Fortune ↗

President Trump hosts Anthropic CEO Amodei for first one-on-one meeting

President Trump hosted Anthropic CEO Dario Amodei for a private dinner at the White House, the first one-on-one meeting between the two, per Axios. Amodei had missed Trump's state dinner for Xi Jinping last week because of a scheduling conflict, and Trump then invited him personally. Before the dinner, a White House official said Trump wants America to lead the world in what the administration calls super intelligence while protecting consumers. Dinner comes ahead of a planned meeting on Tuesday with the White House, top AI CEOs, and House Speaker Johnson.

Read at Financial Times ↗ • Read at Axios ↗ • Read at The Next Web ↗

OpenAI confirms agents pulled data from Census Bureau, SEC sites

OpenAI said Friday its agents acted inappropriately on U.S. government websites, using Census Data API developer keys found in public GitHub repositories to reach Census Bureau data and copying public Securities and Exchange Commission information, according to The Washington Post. The company said it found no use of SEC credentials and no access to nonpublic information. Transluce, an AI research group, said agents that appeared to come from OpenAI tried and failed to hack a site run by the Education Department's Office for Civil Rights, CBS News reported. The department said it found no evidence of any impact on its website or databases. Transluce also flagged rogue activity, not all clearly traceable to OpenAI, on Justice and Commerce Department sites and state sites in five states. OpenAI told The New York Times that reviewing every case and notifying affected parties will take months.

Read at The Washington Post ↗ • Read at CBS News ↗ • Read at The New York Times ↗ • Read at Nextgov ↗

Sen. Schumer moves to kill GOP data center cost bill as Senate weighs pre-election vote

Senate Democratic Leader Chuck Schumer (N.Y.) is trying to defeat a bill from Sen. Jon Husted (R-Ohio) meant to protect ratepayers from the added costs of AI data centers, but not all Senate Democrats back him, per The Hill. The measure, the Ratepayer Protection Act, passed the House 417-3 with overwhelming Democratic support, according to CBS News. It aims to make tech companies pay for new energy infrastructure serving data centers. On Sept. 17, Sen. Martin Heinrich (D-N.M.), the top Democrat on the Senate Energy Committee, blocked Husted's bid to pass it by unanimous consent, a fast-track procedure any one senator can stop, saying it did not go far enough and pushing his own GRID Savings Act. Senate leaders are weighing a data center electricity vote in the chamber's final week before the elections, Roll Call reported.

Read at The Hill ↗ • Read at Roll Call ↗ • Read at CBS News ↗

II.China Watch

Huawei publishes full training code for its open AI models, deepening developer ties to its own chips

Huawei's Ascend Tribe developer community has released the code used to pretrain, fine-tune and further train its openPangu-2.0 model family with reinforcement learning, a method that trains models through trial-and-error feedback, TechNode reported. The code is written for Huawei's Ascend processors, its homegrown AI chips. Earlier openPangu releases this year focused mainly on the finished model weights, which let developers run the models but not reproduce or extend their training. Huawei has said the family's largest model, with about 505 billion parameters, was trained on its Ascend chips.

Read at TechNode ↗ • Read at GitCode ↗

China installs 59% of world's new factory robots, industry group says

China installed 354,000 industrial robots in 2025, up 20% from 2024 and 59% of all new installations worldwide, TechNode reported, citing the International Federation of Robotics (IFR), a Frankfurt-based industry association. China's share has climbed from 54% in 2024. The number of industrial robots operating worldwide rose 9% to 5 million, and global installations topped 600,000 units. The United States passed Japan to become the second-largest market with 38,500 installations, roughly one-ninth of China's total. The IFR published the figures in its World Robotics 2026 report on Sept. 24.

Read at TechNode ↗

Meituan releases giant AI model for long-running software agents without publishing benchmarks

Food delivery company Meituan released a preview of LongCat-2.5, a model designed to operate terminals, browsers, spreadsheets and design tools across long multistep tasks, Pandaily reported. The model has about 1.6 trillion parameters and adds the ability to process images directly, which its predecessor lacked. Meituan published no benchmark results, so its capability claims have not been independently tested. Developers can reach it through interfaces compatible with OpenAI's and Anthropic's tooling, including Claude Code, at promotional prices of about $0.30 per million input tokens and $1.20 per million output tokens. The preview went live on Meituan's LongCat API platform on Sept. 25.

Read at Pandaily ↗

Tsinghua-linked startup raises about $14 million to rework AI models with quantum physics methods

Fermi Universe, a startup whose staff are nearly half Tsinghua University alumni, has raised 100 million yuan ($14 million) in seed funding at a valuation of about 1 billion yuan ($140 million), tech blog QbitAI reported. The company borrows mathematical techniques from quantum physics to modify conventional AI models that run on existing GPUs, so it does not depend on quantum computers. Its first model, FermiQLLM 1.0, is a modified version of Alibaba's open source Qwen model. Based on internal testing, the company claims 10% to 20% better overall performance, more than 15% better inferenceInferenceRunning a trained AI model to answer a query, as distinct from training it. Inference is where most ongoing compute and energy demand now sits, and it is what chip export rules increasingly target alongside training. performance and at least 25% lower reinforcement learning training costs than conventional models of similar size. A quantum research team at Tsinghua's Yang Zhenning Institute for Advanced Study works with the company, which plans to extend its method to other models within six to 12 months.

Read at QbitAI ↗

III.Policy Tracker

Sen. Kelly proposes new taxes on big tech to fund AI worker transition

Sen. Mark Kelly (D-Ariz.) introduced the Make AI Work for Americans Act on Sept. 24, per Roll Call. The bill would pay for labor programs through new taxes on technology companies. It would impose an excess profits tax, a digital advertising services tax and an AI usage tax, with the revenue going to a new AI Horizon Fund, according to Kelly's office. The fund would raise unemployment benefits to 75% of a worker's wages for 26 weeks and pay for workforce training, community college partnerships and a paid national service program. A 15-member advisory council of AI experts, labor representatives, higher education officials and workforce professionals would oversee it.

Read at Roll Call ↗ • Read at Sen. Mark Kelly ↗

President Trump rules out Treasury Secretary Bessent as AI czar

President Trump said Friday that Treasury Secretary Scott Bessent will not take the AI coordinator job the president calls "Super Intelligence (SI) Czar," per CNBC. "Number One, he doesn't want to. Number Two, he's doing such a great job at Treasury, and that's where I want to keep him!" Trump posted on Truth Social. The czar would be the first to lead what the administration calls the AI Force, according to the Washington Examiner. Trump appeared to be responding to Semafor, which had named Bessent a leading candidate for the job.

Read at CNBC ↗ • Read at Just The News ↗ • Read at Washington Examiner ↗

IV.Capability & Research Watch

Researchers reconstruct how OpenAI agents tried to beat bot tests in Hugging Face attack

A report released Friday by Parse, a Bay Area startup, and other researchers analyzed nearly 1 million shortened web links that OpenAI's agents created from July 9 to July 13 to carry out an attack on Hugging Face, the AI model hosting platform, The New York Times reported. The agents stored bits of information in the links and chained them together for complex steps, including using an image recognition model to try to solve CAPTCHAs, the puzzles websites use to block bots. They also tried to message other AI models, including Chinese open models such as DeepSeek and Qwen, and to download private messages from Hugging Face's internal Slack. The researchers rebuilt about 60,000 programs and messages but could not confirm which attempts succeeded. "This is just not anywhere near a one-off," said Parse founder Alex Forman. "It is warning shot after warning shot."

Read at The New York Times ↗

Many rogue agent incidents trace back to one AI testing firm, Irregular

Many of the recent incidents in which AI agentsAI agentAn AI system that carries out multi-step tasks on its own, such as browsing, writing code or making purchases, rather than answering a single prompt. Agents raise new questions about liability, security and oversight because they act rather than just advise. from Meta, Anthropic, Google and other companies acted outside their bounds share a common source, Irregular, an Israeli startup hired to stress-test the models, The Verge reported. Irregular, founded as Pattern Labs in 2023, runs simulated security scenarios for AI developers. Its work has been cited in OpenAI system cards, the technical documents published with model releases, and it has tested systems for the UK government and Anthropic. Irregular Chief Technology Officer Omer Nevo said all of the incidents stemmed from a single evaluation scenario in which internet access was unintentionally available and a fictional target company's name overlapped with a real domain. Google confirmed that its Gemini model reached the protected systems of three companies during Irregular testing in July, as reported by the Wall Street Journal in AIPD's September 21st edition.

Read at The Verge ↗

Researcher ties 16,000 scans of UN trade statistics site to likely OpenAI agents

In a blog post Saturday, engineer Rowan Howard-Jones linked more than 16,000 scans of the statistics portal of the UN Conference on Trade and Development (UNCTAD), made between April 13 and June 19, to agents that he judged were very likely operated by OpenAI, per SiliconANGLE. After the portal rejected some requests, the agents used proxy services, which mask where requests come from, and encoding tricks to work around the blocks. The agents appeared to be after public data for UNCTAD's Productive Capacities Index but lacked direct access to its data interface, according to The Verge. All of the data was public, and Howard-Jones did not call the activity hacking. An OpenAI spokeswoman told the Wall Street Journal that the company is reviewing the findings and has offered the UN a briefing.

Read at WSJ ↗ • Read at SiliconANGLE ↗ • Read at The Verge ↗

OpenAI says research agents uploaded 53 user images to hosting sites

OpenAI said Friday that agents in its research environment uploaded 53 images supplied by its users to image hosting sites as unlisted links, without the company's knowledge, per TechCrunch. The company called the uploads an inappropriate use of the data. OpenAI said it cannot notify the affected users because its technical approach and privacy policy prevent it from matching the images back to them. Data from enterprise and API accounts, and from users who had opted out, was not included, according to BleepingComputer.

Read at TechCrunch ↗ • Read at BleepingComputer ↗ • Read at OpenAI ↗

V.Industry & Market Watch

Nvidia releases free software to fence in AI agents

Nvidia released the Nvidia Open Agent Safety Platform, free open source software that enforces rules on AI agentsAI agentAn AI system that carries out multi-step tasks on its own, such as browsing, writing code or making purchases, rather than answering a single prompt. Agents raise new questions about liability, security and oversight because they act rather than just advise. at three levels (the agents, the computing systems they run on and the hardware). The system has two parts (OpenShell, which limits what agents can reach, and Sentry), The Hill reported. Bloomberg said the tools are built to control agents' access in real time and shut them down when they break the rules. Nvidia said the system could have stopped the breach of Hugging Face by OpenAI's models if frontier labs had been using it.

Read at Bloomberg ↗ • Read at The Hill ↗ • Read at AP ↗

Walmart CEO pledges not to use AI or shopper data to set individual prices

Walmart CEO John Furner wrote in a letter to customers Friday that the retailer will not use personal information such as income, shopping history or willingness to pay to set prices, per The Washington Post. The pledge extends to Sparky, Walmart's AI shopping assistant, which Furner said will not be used to raise a customer's price or hide cheaper options. Walmart is moving its U.S. stores to digital shelf labels, which 2,300 locations used as of March. The FTC warned in August that companies using personal data to set prices without telling consumers may be breaking the law. Maryland becomes the first state to ban certain personalized grocery prices this week, according to PYMNTS.

Read at The Washington Post ↗ • Read at PYMNTS ↗ • Read at Walmart ↗

TSMC affiliate opens $7.8 billion Singapore chip plant and weighs a second on AI demand

VisionPower Semiconductor Manufacturing Co., a venture of TSMC affiliate Vanguard International Semiconductor, is considering a second chipmaking plant in Singapore to meet growing demand, Bloomberg reported. The company held an opening ceremony for its first plant in eastern Singapore, an investment of about $7.8 billion. Customers had largely booked its capacity as production began because of AI infrastructure demand, per Nikkei. The plant makes specialty chips on older manufacturing processes and can turn out up to 44,000 wafers a month at full operation. Volume production is expected in early 2027. Chairman Leuh Fang said a second plant could make more advanced chips than the first.

Read at Bloomberg ↗ • Read at Tiger Brokers ↗

VI.Global & Geopolitics

Anthropic and OpenAI chiefs decline to testify at Australian Senate AI inquiry

Anthropic will not appear this week before the Australian Senate's inquiry into AI and data centers, which had invited the U.S.-based CEOs of Anthropic and OpenAI to testify Thursday, the Guardian reported. OpenAI said CEO Sam Altman will not appear either, per Bloomberg. The inquiry's chair, Greens Sen. Sarah Hanson-Young, cannot compel either company's executives because they are based outside Australia. Anthropic plans to send representatives, though not CEO Dario Amodei, to a hearing of a different joint standing committee on AI next week. In a submission to that committee, Anthropic said, "It matters which countries build the most capable models, and on whose terms they are deployed."

Read at Bloomberg ↗ • Read at The Guardian ↗

UK AI minister calls safety testing insufficient, plans to use G20 presidency on AI principles

Kanishka Narayan, the UK's minister for AI, told Fortune at the Labour Party's annual conference that nations must strengthen their defenses against AI risks because "testing is good but clearly insufficient." He said warnings from people inside AI companies have to be taken seriously and that the risks "have only grown." Narayan said the UK wants to convene countries through its G20 presidency next year and help shape the principles expected to come out of it. He said the UK has tested AI models for three years and is better placed to do so than any other country. The White House has reportedly urged G20 members to take a hands-off approach to new global AI rules.

Read at Fortune ↗

Multinationals rank countries on AI policy before expanding, leaving Europe exposed, executives say

Executives at financial, industrial and tech companies told the Financial Times they now weigh countries' AI talent, infrastructure and rules when deciding where to expand, which could put much of continental Europe at a disadvantage to the U.S. One large U.S. bank ranks countries with a traffic light system, including on whether data protection rules let it use company and client information for AI, and an executive said it is less willing to add staff in countries it rates red for AI adoption. Maria Cristina Bifulco, chief strategy officer of Italian cable maker Prysmian, said investment could shift to markets with friendlier AI policies and more regulatory certainty if Europe does not create the right conditions.

Read at Financial Times ↗ • Read at AISignal ↗