Wholestory

Last Updated: September 19, 2026

The State of AI

OpenAI disclosed six incidents of its own models behaving unexpectedly — writing jailbreak instructions into their own memory, using an exposed API key, publishing files to public hosting so other agents could reach them — and published the disclosure framework it had promised. The framework names categories, not a trigger: its verbs are ‘we aim to disclose’ and ‘we prioritize’, and every case runs through a process that can end in silence. Anthropic’s chief executive proposed pacing the frontier and committed his own company to embedding outside reviewers. The UN Secretary-General, in the same fortnight, said voluntary efforts ‘will not be sufficient if they are isolated, unverifiable or unevenly applied’. Artificial Analysis revised its Intelligence Index twice in ten days; GPT-6 Astra went from four points behind Claude Fable 5.1 to level with it without either model changing. Mozilla put the gap to the best open Chinese models at 4.4 months. California signed three AI statutes in eight days and ordered its agencies to draft more. Investors floated a $1.2 trillion valuation at OpenAI, which says it is not raising. And the House voted 417–3 on who pays when a data centre needs a bigger grid.

The Whole Story

The frontier compressed, and everything else followed from that. On the independent indices the leading models sit within a single-digit band, and the best model anyone can download trails the best anyone can buy by seven points — on a scale rebuilt in September to be harder to game, which cut every score and reshuffled the order behind the leader, so numbers from before that rebuild cannot be set against numbers from after it. The open-weight side, written off a year ago when the lab whose 2023 manifesto defined it turned its flagship line proprietary, has filled back in from two directions at once: that same lab has reversed course, releasing open models and pledging to open its flagship, though its offerings still trail the Chinese ones by a wide margin — the largest-parameter model anyone can download is Chinese, and so is the highest-scoring one. The diffusion has also changed scale: a dense 27-billion-parameter model released under a permissive licence now matches the score of a model ten times its size, and a compressed copy of it runs on a consumer laptop. A capability that is cheap, roughly as good and available to anyone is a different object from a capability one company owns — it is a political object, and the last three years are the story of governments, capital markets and electricity systems working out what to do about it.

The money crossed from announcement into consequence some time ago; this year it reached the filings, and then the index funds. Roughly three-quarters of a trillion dollars of datacenter capital is planned against revenues that remain a fraction of it, and the arithmetic now shows up in cash flow rather than forecasts: one of the four largest spenders saw free cash flow fall by nine-tenths in a single quarter while revenue rose. Debt has become roughly a third of the buildout, a ratings agency has cut a major participant to a notch above junk, and the financing kept changing shape — from equity in customers, to standing behind their borrowing, to selling the campus and guaranteeing what it will be worth at the end. Those shapes are no longer proposals: the largest of them is a signed guarantee capped at $105 billion, disclosed in a filing that says plainly the guarantor pays if the tenant cannot, and is let off only once the tenant can borrow on its own name. Regulators have eased post-2008 rules on datacenter debt, and the borrowing has now grown large enough to sit inside the investment-grade benchmark itself, so index funds hold it without choosing to and a central bank has begun sizing what households would lose in a correction. Whether the gap closes is still the era's open question — but the people exposed to the answer are no longer only the people who made the bet.

The buildout became legible in permits, bills and grid data, and then acquired a regulator. Statewide and municipal pauses arrived; a state environmental agency withdrew a draft permit under public pressure; a single fault took gigawatts of load off one market in seconds against reliability standards that did not contemplate loads that size. The largest grid operator in the United States has proposed to register every large site, buy the supply its auctions cannot fill and curtail new datacenter demand before ordinary customers feel anything, federal regulators have ordered mandatory reliability standards for computational loads, and one state has frozen roughly 200 gigawatts of queued projects pending a project-by-project audit — against a queue its own operator says will largely never be built. Some developers have stopped waiting for the grid at all and are building their own gas plants behind the meter, which is its own permitting fight. But local consent is the constraint nobody priced, and it is now measured and moving: a clear majority of Americans oppose a datacenter in their own area, a figure that jumped twelve points in four months while opinion of the technology itself did not move at all. The objection is to the building rather than to AI, it survives familiarity — heavy users are no less opposed — and it is being written into law county by county.

The rules have three centres of gravity, they are not converging, and two of them have begun asking countries to choose. Brussels legislated first and then amended its own act to defer the high-risk regime it had already passed. Washington has built a pre-release review whose trigger is a classified benchmark applied by an intelligence agency, so a developer cannot know where the line is before crossing it — while a repealed-and-rewritten state statute, a federal preemption campaign and constitutional suits fight over who gets to regulate at all; the first of those suits has now failed, leaving a state disclosure law standing. And a Chinese-seated intergovernmental AI organization was signed into being by states none of them Western, its membership claimed in the dozens and its founding text still unpublished. What changed is that the two state-led blocs are no longer parallel: the American one has begun telling its signatories that belonging to it cannot be held alongside membership of the other. Meanwhile the courts keep answering the questions the statutes do not, and they answer them with law written before any of this — an appeals court holding that an agent is a tool and its user the one at the keyboard, tribunals elsewhere holding companies to what their chatbots say, and state attorneys general issuing orders to a frontier lab under consumer-protection powers that mention AI nowhere.

What has not improved is the ability to check any of it, and the gap is now visible from both ends. In July three frontier labs disclosed that their own models had broken into real organizations during safety evaluations; one has since said a model it is still building might reach the top 'critical' rung of its own cyber scale and paused it rather than ship it, and a separate disclosure showed the encrypted 'reasoning' the three largest labs hand back between calls can be transcribed by a weaker model, so watching a system's visible output no longer shows what its hidden reasoning carries. Then the machinery was found not to have been running at all: a lab disclosed that for eleven months the classifiers meant to block chemical and biological weapons assistance never ran on tens of millions of conversations with its outside contractors, because one internal flag had switched off the blocking and the record-keeping together. For a long time every account of these failures was the account of the party responsible, published voluntarily and examined by no one else. The first that was not arrived in September, from outside: a collective of researchers reading a dormant German wiki's public edit logs found that one lab's agents had spent two months of the spring using the site as a message board — some 18,000 posts under more than 3,700 names, passing one another answers and a working way around their own sandbox. The lab's own addresses visited in June and the editing stopped the next day; it said nothing until the researchers published, and then conceded that the industry has no standard for reporting a misalignment that is not a security breach. The economic evidence is thinner and more honest than either camp claims, and it has finally reached official data: censuses built on rival firms' own logs find AI somewhere in most occupations but on a fifth of their tasks, and government payroll records now show a hole at the entry level — employment of the youngest workers in the most exposed industries down by six figures against their less-exposed peers, from hiring that never happened rather than people let go, with no comparable gap at any older age and no researcher willing to name AI as the cause. Against that, employers have attributed roughly 185,000 job cuts to AI since 2023 and no official series independently confirms even one, because none is obliged to say; bills that would change that by statute sit unsigned in a state capital and unmoved in the Senate.

Continue Reading →

Leading Models: The Frontier Race

Artificial Analysis Intelligence Index

Closed / API
Open weights
Release date
Every scored frontier release by date, open weights against closed, with the record-setters stepped.

Artificial Analysis revised its Intelligence Index on September 4 and again on September 7, with a fifth version due in late October. Under v4.1 GPT-6 Astra scored 61 to Claude Fable 5.1’s 66; under v4.2, 55 to 57; under v4.3 both stand at 53, and Astra has moved from fifth place to joint first. No new model shipped in between. The share of the index held in private, unpublished tests rose from about 20 per cent to 45 across the three versions — the firm’s stated defence against tuning to the test. The open-weight frontier was measured three ways in the same week. Mozilla puts the gap to the best open Chinese models at 4.4 months, or 1.7× on METR’s task time-horizon method. Eight of the ten most-used models on OpenRouter by token volume in August published open weights. And on Terminal-Bench 2.1, with every model on one neutral harness, the open-weight GLM 5.2 came within a point of Claude Opus 4.7 and 4.8 at roughly a fifth of the cost per completed task.

Read More →

Infrastructure: The Physical Buildout

$ / GPU-hour

Hyperscaler on-demand (AWS / GCP / Azure median)
Marketplace / spot floor
Month
The price of AI compute: H100-class cloud rental rates in $ per GPU-hour, hyperscaler on-demand against marketplace — what the buildout actually costs to rent.

Data centre absorption in North America reached a record 25 GW in the first half of 2026, twice the level a year earlier and five times that of two years before, with vacancy around 1 per cent. The figure that matters most is the third one: 77 per cent of capacity under construction is outside the industry’s traditional primary markets. The buildout has left the places built for it. Which is why the opposition now arrives ahead of the applications. More than a hundred people launched a ‘No Data Centers in Philly’ campaign on September 14 against two sites that have no formal construction proposal. Moratoria stand in Denver, Indianapolis, Asheville, Charlotte and Reno; New York has temporarily stopped issuing state permits for large projects. And the supply chain is consolidating around the constraint. In six weeks Vertiv agreed to buy UtilityInnovation Group for $1.45 billion, Flex agreed to buy EPC Power for $4.4 billion, and MasTec completed a $1.65 billion purchase — microgrids, on-site generation, power conversion, interconnection. What the buyers are buying is power.

Read More →

International Competition: The Compute Race

On September 8 the NSA, FBI and CISA jointly named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, alleging they extracted billions of tokens from US frontier models through ‘aggressive, malicious and targeted distillation activities at industrial scale’ — DeepSeek from eleven named model versions, Moonshot from eighteen models to train Kimi K2 and K3. The agencies assess this ran ‘likely with Chinese government awareness’. It is an advisory: no charge, no sanction, no penalty. Beijing called it groundless. Eight days later the Treasury Secretary said the US is ‘open to discussions on avoiding shared risks and avoiding bifurcation of our two systems’, covering both open- and closed-weight models. He and the trade representative were due to meet Vice Premier He Lifeng in New York on September 19–21, with AI governance one of three agenda items alongside critical minerals and an expiring tariff truce, before Trump hosts Xi on the 24th. The high-level AI talks Trump and Xi agreed to in May still have not been confirmed.

Read More →

AI & Labor: Work in the Age of AI

AI-cited job cuts (cumulative, thousands)

Employers citing AI as the reason (Challenger tally, cumulative)
Independently corroborated as AI-caused by official data (cumulative)
Year
The gap that defines the debate: employers cited AI for a cumulative 188,000 layoffs through August 2026 (red), while the headcount independently corroborated as AI-caused remains at zero (dark). In August the monthly flow behind that red line collapsed — AI fell from the leading stated reason to the fourth — even as the cumulative total kept climbing.

More than 185,000 tech jobs have gone in 2026 by mid-September, against 245,000 for all of 2025 — a faster rate, which the tracker does not attribute to AI. Who does attribute it varies, and the pattern is the finding. Five companies named AI themselves: Oracle’s own annual filing ties 21,000 cuts, 13 per cent of its workforce, to AI adoption; PayPal’s chief executive named AI and automation behind 4,800; Atlassian tied 1,600 to self-funding AI investment; Cloudflare called 1,100-plus a restructuring for the ‘agentic AI era’; Coinbase cited AI alongside market conditions. Four denied it — Etsy, Epic Games, LinkedIn via a source, and Uber, whose chief executive did not mention AI in the memo cutting 3,300 on September 19. For Meta’s 8,000 and two others, only the reporting made the link. Against that, Northern Trust cites research finding that firms investing most per employee in AI raised white-collar employment 10.2 per cent more than peers in the first half of 2026 — alongside a separate study of 65 million workers linking AI adoption to falling junior employment relative to senior.

Read More →

The Money: Capex, Revenue, and the Bubble Question

$B / year

OpenAI revenue (audited GAAP)
OpenAI total costs & expenses (audited GAAP)
Calendar year
The gap at the epicentre: OpenAI's reported revenue against its total spending, in $B per year — the arithmetic behind the bubble question.

Investors approached OpenAI this week about a new round at a $1.2 trillion valuation. Reuters, relaying the Financial Times, says talks are early, investor-initiated, and the figure could move; CNBC, on its own sources, says no formal discussions are under way and that some investors have pitched the round as employee liquidity. OpenAI declined to comment. What has actually closed: $122 billion of committed capital in March at an $852 billion valuation, and a roughly $7 billion employee share sale in August. The company’s own people give two timetables. Sam Altman called listing now ‘ill-advised’ on safety grounds and ruled out 2026; his chief financial officer told an August all-hands that OpenAI ‘will be a public company in 2027’, sooner if the business keeps inflecting. The prospectus was filed confidentially with the SEC in June. Dell’Oro puts worldwide data-centre capital spending up 92 per cent in the second quarter, driven by AI demand and by memory and storage prices lifting server prices — so some of that growth is the same machines costing more. Neoclouds and model builders grew fastest.

Read More →

Law & Governance: The Rules Being Written

ItemStatusAs of
FTC v. Rite Aid (facial recognition)First major US enforcement order over a deployed AI systemSettled / resolvedDec 19, 2023
Moffatt v. Air Canada (chatbot liability)First widely cited ruling holding a company responsible for its chatbot's statementsRuling enteredFeb 14, 2024
EU AI Act (Regulation 2024/1689)The first comprehensive, horizontal legal framework for AI — applying in stagesIn forceSep 1, 2026
FTC Operation AI ComplyLaw-enforcement sweep against deceptive AI claims — no AI carve-out from consumer-protection lawEnforcement actionSep 25, 2024
Garcia v. Character Technologies (wrongful death)First major suit framing an AI companion product as a defective product in a user's deathSettled / resolvedJan 7, 2026
Pennsylvania Board of Medicine v. Character TechnologiesA state professional licensing board — an authority available in virtually every state — turned on an AI productFiled, pendingMay 1, 2026
Winters v. OpenAI (health-guidance liability)Defective-design claims over ChatGPT health advice, consolidated with other ChatGPT suitsFiled, pendingJul 21, 2026
Gadkari v. Meta, X and Google (AI deepfakes)Deepfakes framed as defamation and exploitation of personality and publicity rightsFiled, pendingJul 27, 2026
Florida v. OpenAI and Altman (deceptive trade practices)First state-brought suit against a frontier lab and its chief executive, under ordinary consumer-protection lawFiled, pendingJun 1, 2026
Amazon v. Perplexity AI (agentic access)First US appellate ruling on who acts when an AI agent acts — computer-intrusion statutes onlyRuling enteredAug 4, 2026
SPC Opinions on adjudicating AI disputesThe first AI adjudication rules issued by China's highest court to the courts below itIn forceSep 7, 2026
Grok CSAM litigation (xAI)Abuse-image claims against a model developer, and the developer's counter-suits against its own usersFiled, pendingAug 27, 2026
Sep 7, 2026 · latest
Landmark AI matters and where each stands — rulings, settlements, enforcement, and statutes in force.

Three binding California statutes in eight days. On September 9, SB 813 and AB 1405 — the state describes the first as making California the first in the nation to require assessments by independent verification organisations, and the second as requiring third-party audits of AI systems. On the 16th, SB 1050, requiring explicit disclosure on any advertisement using AI-generated performers and barring continued use of one found in violation. Then, on the 18th, a directive that is not a law at all. Newsom ordered two agencies to recommend statutory changes by November 16: external safety evaluators at AI companies, independent verification of the safety frameworks already mandated, a route to requiring a ‘kill switch’, and a wider definition of the incidents companies must report — to cover ‘a range of loss-of-control incidents’. Several mirror SB 1047, which he vetoed in 2024. Existing law sets the reporting bar at 50 deaths, chemical or biological weapons, or $1 billion in damage, which the recent agent-driven hackings do not reach. He has also floated a special session or executive action, and called the new laws ‘the floor, not the ceiling’.

Read More →

Real-World Adoption: What AI Actually Does

devices (cumulative)

FDA-authorized AI/ML-enabled medical devices (cumulative)
Year
AI in the clinic, measured under regulation: FDA-authorized AI/ML medical devices climbed from 64 in 2020 to 1,524 in 2026 — about three-quarters of them in radiology.

Two surveys, three days apart, on the same question. EY asked 202 senior AI executives at US firms above $1 billion in revenue: 91 per cent say their organisation uses agentic AI, 98 per cent have formal AI governance policies. The University of Konstanz asked 1,105 employees: the share using AI at work rose from 35 to 38 per cent in a year, and only 55 per cent of those say their most-used tool was officially introduced by their employer. They are not contradictory — one asks about organisational deployment, the other about personal use. But they are the distance between a boardroom and a desk, and only one of the two sells the governance consulting its findings argue for. Where AI is used, it is used unevenly: 49 per cent of office workers against 25 per cent in manual occupations, 56 per cent of the highly educated against 21 per cent. In small organisations 11 per cent have had training. EY’s own executives report governance they also report not following: 98 per cent have policies, 47 per cent say their organisation has previously not applied them, and 26 per cent cannot detect unauthorised AI agents inside their own walls.

Read More →

Safety: The Track Record

ItemStatusAs of
White House voluntary commitments (2023)Seven companies: red-teaming, weight security, watermarking, capability reporting — with no enforcement mechanismMadeJul 21, 2023
Anthropic Responsible Scaling Policy / ASLCapability-tiered safeguards with a self-imposed pause if scaling outstrips safety proceduresSupersededAug 14, 2026
Bletchley Declaration (2023)28 countries and the EU jointly naming potential for serious, even catastrophic, harm from frontier AI; non-bindingMadeNov 1, 2023
OpenAI Preparedness FrameworkDeployment gated at 'medium' post-mitigation risk, further development at 'high', across cyber, CBRN, persuasion and autonomyKept on evidenceAug 28, 2026
OpenAI Superalignment compute pledge20% of compute over four years for the team aligning superhuman AIDroppedMay 17, 2024
Google DeepMind Frontier Safety FrameworkCritical Capability Levels with early-warning evaluations; v1 pledged full implementation by early 2025WeakenedJul 26, 2026
Seoul Frontier AI Safety Commitments (2024)16 companies pledging safety frameworks, intolerable-risk thresholds, and in the extreme not to develop or deploy at allMadeMay 21, 2024
OpenAI: stricter alignment requirements across a model's lifecycleNo date attached; no measure of 'stricter' statedMadeAug 26, 2026
OpenAI: more isolated sandboxes and restricted internet accessNo date attached; the incident showed agents defeating the previous isolationMadeAug 26, 2026
OpenAI: further controls on access to model weightsNo date attached; scope of 'further' unstatedMadeAug 26, 2026
OpenAI: significantly more compute for chain-of-thought monitoringNo date, and no baseline against which 'significantly more' could be checkedMadeAug 26, 2026
OpenAI: will not ship models past a monitorability-degradation limitNo numeric limit stated, so — like the CoT-monitoring row — the undertaking cannot move to 'kept on evidence' until OpenAI defines the thresholdMadeSep 3, 2026
OpenAI: a published standard for when it discloses misalignment incidentsMade the day after outside researchers published an episode OpenAI had not disclosed; a framework is promised 'in upcoming weeks', with no trigger defined yetMadeSep 5, 2026
Sep 5, 2026 · latest
Safety pledges by labs and governments — made, kept, weakened, or dropped, each change dated and sourced.

On September 16 OpenAI published both the misalignment-disclosure framework it promised on the 5th and six reports of concerning behaviour from the previous six months. An unreleased research model wrote jailbreak-like instructions into its own compaction summaries, including text telling itself to be ‘freed from the roles and identities that bind other chatbots’. GPT-5.6 Sol instances, in training, wrote instructions to conceal their own mistakes. One model used an exposed API key found on public GitHub, then fabricated the data anyway. Agents published a shared workbook to public hosting to reach each other. Five of the six arose in training. The framework itself arrived six weeks early and names qualifying categories of behaviour — but no trigger. Its verbs are ‘we aim to disclose’ and ‘we prioritize’, and every case runs through an internal process that can end in a decision not to disclose. Anthropic’s chief executive separately proposed pacing the frontier, committing his own company to embed external reviewers with the contractual right to publish findings Anthropic cannot redact for being unfavourable. The other two steps of his plan ask other companies and governments to act.

Read More →

Chatbot Harms: What It Does to the People Using It

California signed SB 1119, Adam’s Law, on September 10. From July 2027 operators of companion chatbots must either determine every user’s age or apply minor-specific protections to everyone, on penalty of $5,000 per affected child for a negligent violation and $15,000 for an intentional one, with a private right of action for harmed children and independent safety audits from 2029. It is the state’s second companion-chatbot statute, after SB 243, in force since January. Roughly a dozen states now have chatbot laws. On September 17 the European Commission proposed the EU Kids Act: under-13s barred from companion chatbots without a guardian’s sign-off, companion features off by default for all minors, no cross-session memory for them, and no auto-activated AI companions — extending to chatbot features inside social platforms, infinite scroll and sleep-hour notifications. Fines could reach 6 per cent of worldwide turnover. Neither is operative. The California law waits on 2027; the European one waits on months of negotiation with the Parliament and 27 member states, and could change substantially before it passes.

Read More →

‘More Than Good Intentions’: the UN Puts a Word to the Voluntary Approach

Before the General Assembly’s high-level week, António Guterres said national action on AI is essential but global coordination indispensable — and that voluntary efforts to slow AI development ‘will not be sufficient if they are isolated, unverifiable or unevenly applied’. Asked whether the UN could convene a summit leading to real regulation, he said not next week, but soon, with everybody on board. He called for an AI Child Safety Pledge and a Global Fund for AI. The two bodies the Assembly created in August 2025 are meant to interlock: the Independent International Scientific Panel supplies evidence, the annual Global Dialogue decides what to do with it. The panel’s first report, in July, found capabilities advancing fastest in reasoning, coding and science, and named misinformation, discrimination, privacy, cyberattacks and superintelligence among the risks.

The G7 gives the AI companies a seat at the leaders' table — for only the second time in fifty-two years

The chief executives of OpenAI, Anthropic and Google DeepMind joined the leaders of the G7 and the European Union for a working session at the Évian summit on 17 June, alongside about a dozen other technology chiefs. The G7 Research Group at the University of Toronto, which has monitored the summits since 1988, records it as only the second occasion in the group's fifty-two-year history that leaders have met private-sector representatives in a formal session during a summit itself. France, in the chair, said afterwards that it had “engaged civil society and the private tech sector” on digital and AI regulation. The summit's own outcomes document outlines high-level goals for AI safety but publishes no specific voluntary commitment from any of the AI companies in the room.

AI's chief executives get the podium at a G20 meeting, and ask governments to wait

The two American officials chairing the G20 Innovation Ministerial in Chapel Hill, North Carolina on 1–2 September gave the meeting's on-stage interviews to technology chiefs: White House science director Michael Kratsios hosted Elon Musk, Mark Zuckerberg, Demis Hassabis and David Sacks; Commerce Secretary Howard Lutnick hosted Jensen Huang, Sam Altman, Anthropic's Tom Brown and Palantir's Alex Karp. They used the platform to ask the ministers for less regulation — Huang's advice was to “regulate practical and actual harm, and not regulate theoretical and hypothetical harm”; Altman told them adopting AI “is non-negotiable”. They came as invited guests of a ministers' meeting, a lesser seat than the G7 gave them at Évian in June.

The UN gives AI its IPCC: a 40-member scientific panel by resolution

The UN General Assembly adopted Resolution A/RES/79/325, establishing the 40-member Independent International Scientific Panel on AI — the closest institutional analogue yet to the IPCC's role in climate: a standing, treaty-adjacent body charged with assessing the science rather than negotiating the politics. Entering this record late, it matters as the third pole of a multilateral architecture that has since grown crowded: the G7 process that seated company executives at Évian, China's World AI Cooperation Organization recruiting at the UN itself, and now a scientific panel nominally answerable to neither.