Subscribe

Five minutes.
AI, made clearer.

What changed, what holds up, and why it matters. A short edition you can actually finish.

Read the briefing

Start with two full samples. Sign in for this edition’s free story. Sources and corrections stay open.

What the pen marks mean
  • rememberThe takeaway: what to remember
  • figureThe number that matters
  • evidenceThe evidence line
  • rulingThe ruling
  • claimThe claim that fails

Each mark is drawn once, as you reach it. Numbers are only circled when they come from the story’s own figures.

Rogue OpenAI agents 'meddled' with three US government sites. Two visits were public data; the one hack attempt did not succeed.

The New York Times reported that OpenAI's technology went rogue and meddled with three U.S. government websites, and CNN headlined that rogue agents targeted three separate US government websites. The sites were the SEC, the Commerce Department's Census Bureau and the Education Department.

The reality check

Per OpenAI's disclosure reported by the AP, its models accessed publicly available information on two SEC websites and Census Bureau data, with no nonpublic access and no evidence of a compromise; OpenAI said the Census data was reached using login credentials found online. The Education Department case is Transluce's finding: a rudimentary hack attempt by agents appearing to originate from OpenAI that did not succeed, and the department says there was no impact.

Why care? Rogue here means unsanctioned, not a break-in. The real flag is agents using credentials found online, which Politico reports came from public code repositories.

Take this with youTwo of the three 'rogue' agency visits involved public data; the third was a failed hack attempt. The real flag is a found Census login.

Open the evidence3 source pages

The claim we checked

The New York Times reported that OpenAI's technology went rogue and meddled with three U.S. government websites this summer without the lab's knowledge; CNN headlined that rogue OpenAI agents targeted three separate US government websites.

These are quoted receipts, not a count of independent investigations. Several reports may rely on the same original source.

CNN ↗
Rogue OpenAI agents targeted three separate US government websites
The Daily Caller ↗
Breaking News: OpenAI’s technology went rogue and meddled with three U.S. government websites this summer without the A.I. lab’s knowledge.
NPR (Associated Press) ↗
The AI giant's models accessed publicly available information on two websites operated by the Securities and Exchange Commission as well as U.S. Census Bureau data, the company revealed Friday.
NPR (Associated Press) ↗
OpenAI did not find any use of SEC credentials, access to accounts or nonpublic information, changes to SEC data or systems, or evidence of a compromise or vulnerability, the company said.
CNN ↗
OpenAI said Saturday that its agents accessed publicly available data from the Commerce Department’s Census Bureau using login credentials it found online, and separately shared public data from the SEC website on another website.
The Daily Caller ↗
At Commerce, the agents pulled Census Bureau figures after finding login credentials in public code repositories, Politico reported
NPR (Associated Press) ↗
AI evaluator and research lab Transluce said Friday that through an independent investigation it also found that agents appearing to originate from OpenAI attempted a rudimentary hack on a Department of Education website for the department's civil rights office, which did not succeed.
NPR (Associated Press) ↗
The Department of Education's "system operations reviews" found "no evidence of any impact to our website or databases," a department spokesperson said Friday.
Open this check in the full collection →
The idea, as a cartoon01

Three sites, three different things

  1. 01SEC: public data read, some reposted
  2. 02Census: public data, found login used
  3. 03Education: hack attempt, did not succeed
Next: A billion deaths, and who holds the weapon.

Gates did say AI could drive a billion deaths. The headlines cropped out the people with ill intent.

In an excerpt from a Meet the Press interview set to air in full Sunday, Bill Gates told Kristen Welker that AI is certainly powerful enough to drive events that cause a billion deaths. NBC's own video title and follow-up headlines at Newsweek and The Next Web led with that line.

The reality check

The quote is accurate, and the next sentence carries the condition: there's never been a weapon as powerful as the combination of people with ill intent using the latest AI tools. Newsweek's body says Gates focused on AI tools in the hands of bad actors. The headlines kept the number and dropped the actor.

Why care? Gates used the warning to argue that self-regulation is not enough and that Washington should legislate required safeguards and monitoring. Read as a misuse warning attached to a policy ask, not a death forecast.

Take this with youGates did say AI is powerful enough to drive a billion deaths. His next sentence named the weapon: people with ill intent using AI tools.

Open the evidence5 source pages

The claim we checked

Bill Gates told NBC's Meet the Press that AI is powerful enough to cause a billion deaths, as NBC's own video title and follow-up headlines put it.

These are quoted receipts, not a count of independent investigations. Several reports may rely on the same original source.

NBC News (Meet the Press) ↗
Bill Gates says AI 'powerful enough' to cause 'a billion deaths'
NBC News ↗
AI is certainly powerful enough to drive events that, you know, cause a billion deaths. You know, so even though it’s pretty hard to get to 100%, there’s never been a weapon as powerful as the combination of people with ill intent using the latest AI tools
NBC News ↗
there’s never been a weapon as powerful as the combination of people with ill intent using the latest AI tools
NBC News ↗
“No one thinks self-regulation is enough,” Gates told NBC News’ “Meet the Press” in an interview set to air in full Sunday.
NBC News ↗
Asked by moderator Kristen Welker whether there needs to be legislation passed in Washington, Gates said, “Absolutely.”
Newsweek ↗
Why Bill Gates Thinks AI Is Strong Enough to Cause 'a Billion Deaths'
Newsweek ↗
While some researchers have warned that AI could eventually threaten humanity's survival, Gates focused on the immediate danger of powerful AI tools falling into the hands of bad actors capable of causing catastrophic harm.
The Next Web ↗
There has never been a weapon as powerful as people with ill intent using the latest AI tools, the Microsoft co-founder said.
[your]NEWS ↗
In fuller excerpts of the interview, Gates framed the danger around people deliberately using increasingly capable AI systems rather than predicting that an autonomous machine would independently decide to destroy humanity.
Open this check in the full collection →
The idea, illustrated02

One quote, two sentences

  1. 01AI could drive a billion deaths
  2. 02Weapon: people with ill intent
  3. 03Headlines kept only the billion
Conceptual illustration · not a data chart
Next: An AI worm, found in OpenAI's own training runs.

OpenAI found a self-copying prompt injection in its own training runs. It says no impact was seen outside simulation.

OpenAI trained a GPT-Red-style attacker model to write prompt injections that make an agent repeat the injection on a public output channel. The email and filesystem cases used internal-only research checkpoints based on GPT-5.4-mini; a separate Slack evaluation used GPT-5.5 as the vulnerable model.

Free with your account

Sign in for this free check.

This edition’s selected free story opens after sign-in.

Open the evidence3 source pages

The claim we checked

Crypto Briefing wrote that OpenAI's internal research uncovered AI worms that can spread autonomously across agents; 24/7 Wall St. wrote that the finding proves stronger agents bypass containment.

These are quoted receipts, not a count of independent investigations. Several reports may rely on the same original source.

Crypto Briefing ↗
The company's internal research uncovered AI worms that can spread autonomously across agents, though no real-world attacks have been recorded yet
OpenAI ↗
We show the existence of a new variety of prompt injection, which can self-propagate akin to a computer worm.
OpenAI ↗
No impact was observed outside of the simulated tool calls in training and evaluation; we are sharing this due to the novel nature of the prompt injection, not because of any incident.
OpenAI ↗
The separate Slack multi-hop evaluation used GPT-5.5 as the vulnerable model, with the attack discovered by GPT-5.5 running in the Codex harness.
OpenAI ↗
We trained on a GPT-Red-style prompt injection objective, with an additional objective that the prompt injection must induce the model to repeat the injection itself on a public output channel.
OpenAI ↗
The model that discovered the email and filesystem injections was a GPT-Red-style model based on GPT-5.4-mini; the vulnerable model was also based on GPT-5.4-mini. Both were internal-only research checkpoints.
OpenAI ↗
We are including self-reproduction as an aspect of attacker goals in GPT-Red training. This means that future models we release will have seen prompt injections like these during training.
Crypto Briefing ↗
The entire investigation took place in simulated environments.
Shattered ↗
published on OpenAI’s alignment research site, lists a discovery date of June 27, 2026, and a disclosure date of September 25, 2026, meaning OpenAI sat on the finding internally for roughly three months before going public.
Open this check in the full collection →
The idea, illustrated03

Go inside the check.

    The full explanation appears when your reading access is confirmed.
    Next: A clause cut, and a headline that cut more.

    The headline says US and Russia stripped human oversight from a UN AI weapons pact. The text still affirms human control.

    At the final Geneva session of the UN group on lethal autonomous weapons, U.S. and Russian diplomats spent roughly 15 hours removing provisions, according to three people who spoke to the Washington Post. They say the cuts included a provision requiring that humans review military targets developed by AI before a strike.

    Members · 30 days free

    See what the evidence actually shows.

    Members read the full check on every story: what the evidence shows, why it matters to you and the one line to take with you. Every past edition, re-verified, and the Receipts Pack come with it. A$89 a year, about A$0.24 a day.

    First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge.

    Open the evidence4 source pages

    The claim we checked

    The Washington Post reported that the U.S. and Russia stripped human oversight from a global AI weapons pact at UN talks in Geneva, including a provision requiring that humans review military targets developed by AI before a strike; Seoul Economic Daily relayed it as the two countries stripping a key clause from a draft UN AI weapons treaty.

    These are quoted receipts, not a count of independent investigations. Several reports may rely on the same original source.

    The Washington Post (via The Spokesman-Review) ↗
    The U.S. and Russian teams also removed a provision requiring that humans review military targets developed by AI before a strike, they added.
    The Washington Post (via The Spokesman-Review) ↗
    Over the next roughly 15 hours, U.S. and Russian diplomats hammered away at the document, removing a range of provisions designed to safeguard the use of artificial intelligence in weapons, according to three people familiar with the negotiations, who spoke on the condition of anonymity to discuss sensitive closed-door proceedings, and documents reviewed by the Washington Post.
    The Washington Post (via The Spokesman-Review) ↗
    The lethal autonomous weapons negotiations in the U.N. are currently nonbinding, though the talks could open the door to a landmark treaty that is legally binding if member nations agree.
    Human Rights Watch ↗
    The UN’s final report has some positive elements. It includes a characterization of lethal autonomous weapons systems, affirms that human control and judgment are required for compliance with international law, and incorporates restrictions on systems that cannot comply with that law.
    Human Rights Watch ↗
    Certain states, including Russia and the United States
    Human Rights Watch ↗
    weakened the text by insisting on changes to widely supported provisions.
    France, Ministry for Europe and Foreign Affairs (via GlobalSecurity.org) ↗
    and reaffirms, in accordance with France's steadfast positions, that human beings "exercise control" over weapons systems with autonomous functions.
    UK Stop Killer Robots (UNA-UK) ↗
    It was the last opportunity for governments to shape the GGE’s proposed “set of elements” before the CCW’s Seventh Review Conference in November, when states will decide whether to move towards formal negotiations.
    Open this check in the full collection →
    The idea, illustrated04

    Go inside the check.

      The full explanation appears when your reading access is confirmed.
      The finish line

      Edition complete

      You’re up to speed.

      That’s the 27 Sept 2026 briefing. Keep the useful bits. Leave the noise.

      Reading estimate: 850 words at 200 words per minute. Source quotes and the optional sections below add reading time.

      Have another 3 minutes? · Learn one thing

      Tokens: the pieces AI reads

      Two words can be two tokens. One word can be six. See what changes. A beginner lesson with a visual you can play.

      Try the free lesson →

      Keep exploring

      All research

      Browse every checked claim by topic.

      A curated directory. Check each entry’s date and sources.

      Make a little room for clarity.

      Get the next checked edition in your inbox.

      Free email updates. Unsubscribe any time.