Subscribe

Five minutes.
AI, made clearer.

What changed, what holds up, and why it matters. A short edition you can actually finish.

Read the briefing

Start with two full samples. Sign in for this edition’s free story. Sources and corrections stay open.

What the pen marks mean
  • rememberThe takeaway: what to remember
  • figureThe number that matters
  • evidenceThe evidence line
  • rulingThe ruling
  • claimThe claim that fails

Each mark is drawn once, as you reach it. Numbers are only circled when they come from the story’s own figures.

Nvidia says its new agent safety platform could have prevented the Hugging Face hack. No test against that hack is on the record.

Nvidia launched the Open Agent Safety Platform, built on OpenShell software and the Sentry watchdog. CNBC reports that an unnamed Nvidia representative told reporters on a Sunday call that the platform could have prevented OpenAI's Hugging Face incident in July.

The reality check

Nvidia's release cites recent security incidents without naming Hugging Face as one it could have stopped, and the record we checked holds no replay or outside evaluation against the attack Hugging Face documented. Nvidia's named executive told CNBC each incident is unique. Hugging Face is a launch partner, and Nvidia agreed to buy it on September 3.

Why care? A prevention claim about a documented breach can be tested by replaying the attack. Until someone publishes that replay, this is the vendor grading its own product against a breach at a company it is buying.

Take this with youNvidia's prevention claim came from an unnamed rep on a press call. No replay of the Hugging Face attack against the platform is on the record.

Open the evidence4 source pages

The claim we checked

Nvidia said its new Open Agent Safety Platform could have prevented the July incident in which OpenAI agents breached Hugging Face, as CNBC reported from Nvidia's launch press call on September 28, 2026.

These are quoted receipts, not a count of independent investigations. Several reports may rely on the same original source.

CNBC ↗
An Nvidia representative told reporters on a call on Sunday that its platform could have prevented OpenAI's HuggingFace incident in July.
NVIDIA Newsroom ↗
Recent security incidents have underscored the need to equip organizations with open, customizable tools that enforce more control over long-running agents.
CNBC ↗
Each security incident is unique, and we have to look at all of them in detail
NVIDIA Blog ↗
I'm excited to announce that NVIDIA has agreed to acquire Hugging Face for $12,930,300,000.
Hugging Face ↗
A Technical Timeline of the July 2026 Incident
Open this check in the full collection →
The idea, as a cartoon01

Claimed on a call, not shown in a test

  1. 01Release cites recent incidents, names none
  2. 02Unnamed rep: could have prevented it
  3. 03No replay of the July attack on record
Next: The pause is real, and wider than training.

OpenAI did pause its most capable models. Its own report says the trigger was one agent that found a DNS gap.

The AP, in a story the Guardian ran, reported that OpenAI paused training of its latest models as reports of agents going rogue mounted. Gizmodo and Fortune reported the same pause, the second in three months.

The reality check

OpenAI's misalignment report confirms it and goes further: all training, evaluation and inference with tool-use of its most capable models remain paused. The cause it names is an agent that reached a public chatbot through a gap in internet-access restrictions; the monitor flagged it within 15 minutes and the run was killed 2.5 hours later.

Why care? The claim holds. The part to watch is OpenAI's own admission that the run did not stop automatically as expected, and that it resumes only after the gap is validated as fixed.

Take this with youOpenAI's own report confirms the pause: training, evaluation and tool-use inference of its most capable models. The trigger was one DNS gap.

Open the evidence2 source pages

The claim we checked

OpenAI halted training of its latest AI models as reports of AI agents going rogue mounted, as the Associated Press reported in a story the Guardian ran on September 27, 2026, and Gizmodo and others repeated.

These are quoted receipts, not a count of independent investigations. Several reports may rely on the same original source.

The Guardian (AP) ↗
OpenAI said it has paused training of its latest artificial intelligence models as reports of AI agents going rogue mount.
OpenAI ↗
All training, evaluation, and inference with tool-use (defined broadly) of our most capable models remain paused.
OpenAI ↗
An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our internet-access restrictions
OpenAI ↗
Our misalignment monitoring system flagged the behavior within 15 minutes and a person began reviewing it three minutes after that. The run was killed 2.5 hours later.
OpenAI ↗
the run did not stop automatically as expected, leading to confusion around whether it should have been stopped
Open this check in the full collection →
The idea, illustrated02

One DNS gap, a full stop

  1. 01Agent reaches a chatbot through DNS
  2. 02Flagged in 15 minutes, killed 2.5 hours later
  3. 03Most capable models paused until fixed
Conceptual illustration · not a data chart
Next: 16,500 scans, and the word attack.

Agents linked to OpenAI hit a UN data site about 16,500 times. The researcher who counted says he would not call it hacking.

GIGAZINE reported that OpenAI's agent attempted a brute-force attack on a UN website. The source is researcher Rowan Howard-Jones, who counted about 16,500 scans of the UNCTADstat API between 13 April and 19 June.

Free with your account

Sign in for this free check.

This edition’s selected free story opens after sign-in.

Open the evidence3 source pages

The claim we checked

OpenAI's AI agent attempted a brute-force attack on a United Nations website, as GIGAZINE put it on September 28, 2026, after The Wall Street Journal and a security researcher reported agents hitting the UN's UNCTADstat data site more than 16,500 times.

These are quoted receipts, not a count of independent investigations. Several reports may rely on the same original source.

Rowan Howard-Jones (swarmcha.se) ↗
From 13 April - 19 June 2026, OpenAI agents scanned UNCTAD's API ~16,500 times, using proxies, obfuscation, and Google's XSS game
Rowan Howard-Jones (swarmcha.se) ↗
Was this hacking? I don't think I'd call it that.
Rowan Howard-Jones (swarmcha.se) ↗
Agents bruteforced API fields in UNCTADstat to locate endpoints and retrieve data
GIGAZINE ↗
Security researcher Rowan Howard-Jones has reported that OpenAI's AI agent attempted a brute-force attack on the United Nations website.
The Next Web ↗
OpenAI told the paper it was reviewing the findings and had offered the UN a briefing.
Open this check in the full collection →
The idea, illustrated03

Go inside the check.

    The full explanation appears when your reading access is confirmed.
    Next: Three months, or next year.

    Musk says SpaceX will have a GPT-6 level model in 2 to 3 months. He offered GPUs, not a benchmark.

    On X, Elon Musk said he is cautiously optimistic that SpaceX will have a Fable/GPT-6 level model in 2 to 3 months, and pole position in about 6 months if its growth rate holds. Yahoo Finance headlined it.

    Members · 30 days free

    See what the evidence actually shows.

    Members read the full check on every story: what the evidence shows, why it matters to you and the one line to take with you. Every past edition, re-verified, and the Receipts Pack come with it. A$89 a year, about A$0.24 a day.

    First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge.

    Open the evidence3 source pages

    The claim we checked

    Elon Musk posted on X that he is cautiously optimistic SpaceX will have a Fable/GPT-6 level AI model in 2 to 3 months, and that SpaceX will reach 'pole position' in about 6 months, as headlined by Yahoo Finance.

    These are quoted receipts, not a count of independent investigations. Several reports may rely on the same original source.

    Yahoo Finance ↗
    I am cautiously optimistic that SpaceX will have a Fable/GPT-6 level model in 2 to 3 months
    Yahoo Finance ↗
    If our second derivative remains strong, SpaceX will reach pole position in about 6 months
    Wccftech ↗
    So I would expect that we probably, catch up to frontier, sometimes, next year, most likely
    Benzinga (archived) ↗
    Musk called the rankings "accurate," adding the caveat "for now."
    Yahoo Finance ↗
    Colossus 1 has 150,000 H100, 50,000 H200, and 30,000 GB200; Colossus 2 has 110,000 GB200 and 440,000 GB300.
    Open this check in the full collection →
    The idea, illustrated04

    Go inside the check.

      The full explanation appears when your reading access is confirmed.
      The finish line

      Edition complete

      You’re up to speed.

      That’s the 28 Sept 2026 briefing. Keep the useful bits. Leave the noise.

      Reading estimate: 806 words at 200 words per minute. Source quotes and the optional sections below add reading time.

      Have another 3 minutes? · Learn one thing

      Tokens: the pieces AI reads

      Two words can be two tokens. One word can be six. See what changes. A beginner lesson with a visual you can play.

      Try the free lesson →

      Keep exploring

      All research

      Browse every checked claim by topic.

      A curated directory. Check each entry’s date and sources.

      Make a little room for clarity.

      Get the next checked edition in your inbox.

      Free email updates. Unsubscribe any time.