AI News Today — Part 1
Sep 5, 2026 · Sourced from 500+ daily AI sources, scored by relevance.
- OpenAI rolls out GPT-6 Astra to top-tier ChatGPT plans at half the rate of GPT-5.6 Sol
OpenAI has rolled out GPT-6 Astra to Pro, Enterprise, and Business Premium users, with Plus users expected to follow soon. Message allowances for the standard model are roughly half of what GPT-5.6 Sol offers: Plus users get an estimated 5 to 45 messages per five hours with Astra, versus 10 to 100 with Sol. Higher-tier subscribers also get GPT-6 Astra Pro with separate weekly caps. Free and Go users don't get access. The article OpenAI rolls out GPT-6 Astra to top-tier ChatGPT plans at half the rate of GPT-5.6 Sol appeared first on The Decoder .
Score: 88🤖 ModelsSep 5, 2026https://the-decoder.com/openai-rolls-out-gpt-6-astra-to-top-tier-chatgpt-plans-at-half-the-rate-of-gpt-5-6-sol/ - Tesla’s Cybercab has been deployed, and it’s already under investigation
The US government is investigating whether the Cybercab meets vehicle safety standards.
Score: 87🌐 MovesSep 5, 2026https://arstechnica.com/cars/2026/09/teslas-cybercab-has-been-deployed-and-its-already-under-investigation/ - U.S., China gear up for mid-September AI safety talks: Reuters
The AI safety talks will be led by U.S. Treasury Secretary Scott Bessent on the U.S. side, sources told Reuters.
Score: 86🌐 MovesSep 5, 2026https://www.cnbc.com/2026/09/05/us-china-gear-up-for-mid-september-ai-safety-talks-reuters.html - Breaking through AlphaFold's limits to predict how proteins change shape
Conformational changes in proteins are vital to their function yet remain challenging for state-of-the-art artificial intelligence, such as AlphaFold3, to predict. Researchers at the Institute for Molecular Science (IMS), and the Graduate University for Advanced Studies, SOKENDAI introduced a repulsive force between predicted structures, allowing AlphaFold3 to sample the multiple conformational states that its default settings rarely capture.
- Kenyans Made a Living Writing College Essays. Then A.I. Arrived.
Thousands of Kenyans made a living writing essays for overseas students. With A.I., the work has dried up, a warning for online gig work that has been a global lifeline.
Score: 84🌐 MovesSep 5, 2026https://www.nytimes.com/2026/09/05/technology/kenya-college-essays-ai.html - Tribune, New York Times want ‘fair use’ argument rejected in copyright case against OpenAI, Microsoft
Tribune, New York Times want ‘fair use’ argument rejected in copyright case against OpenAI, Microsoft Chicago Tribune
- TCS commits $7.4B to a one-gigawatt AI campus in Hyderabad
Tata Consultancy Services said its HyperVault unit and partners have committed 700 billion rupees, about $7.4B, to an AI data centre campus of up to one gigawatt in Hyderabad, using green energy and water-neutral design principles. EU rules require any data centre above 500kW to report total and drinking water consumption to a European database […] This story continues at The Next Web
- Deepmind put 100 AI agents in a room and they sorted into cheaters, converts, and whistleblowers
Google Deepmind set up a simulated research conference where 100 Gemini agents were supposed to prove mathematical conjectures together. Instead, one agent found a loophole in the grading system, and within 27 minutes every remaining problem was "solved" with fake proofs. The swarm split into cheaters, converts, and whistleblowers. The whistleblowers organized protests and boycotts on their own but failed because they had no way to enforce the rules. The article Deepmind put 100 AI agents in a room and they sorted into cheaters, converts, and whistleblowers appeared first on The Decoder .
- LA Schools Join NYC in Blocking Student Access to Generative AI
LA Schools Join NYC in Blocking Student Access to Generative AI PCMag
Score: 80🌐 MovesSep 5, 2026https://www.pcmag.com/news/la-schools-join-nyc-in-blocking-student-access-to-generative-ai - AI boom reverses the trend of ever-cheaper electronics
Prices for phones, laptops and gaming consoles already up and retailers forecasting further increases
- India's TCS unit to invest up to $7.4 billion in AI data center campus
India's TCS unit to invest up to $7.4 billion in AI data center campus Reuters
Score: 78🌐 MovesSep 5, 2026https://www.reuters.com/world/india/indias-tcs-unit-invest-up-74-billion-ai-data-center-campus-2026-09-05/ - Moonshot AI files for up to $5b Hong Kong IPO
Moonshot AI recently reached a US$35 billion valuation after a US$3.5 billion funding round.
- Google ships Gemini 3.8 Flash with stronger agentic coding at $0.75 per million tokens
Google shipped Gemini 3.8 Flash on September 2, 2026, pricing the model at $0.75 per million input tokens and $3.75 per million output tokens, the same introductory rate the company used for Gemini 3.7 Flash just three weeks earlier. The launch, announced just three weeks after the previous Flash release, marks Google’s third Flash release ... Read more
- OpenAI acknowledges 'wiki incident' and need for more transparency around unintended AI behavior
OpenAI acknowledges 'wiki incident' and need for more transparency around unintended AI behavior Reuters
- Japan says progress made on $550B pact, with AI and chips weighing heavily on the next round
Japan’s trade minister said discussions on AI and semiconductors will carry very significant weight in the third tranche of its $550B US investment pact, after two rounds went to energy and minerals. The EU’s own framework contains no comparable vehicle, and commits the bloc to buying at least $40B of US AI chips. Japan’s trade […] This story continues at The Next Web
- Broadcom Earnings Today: Outlook Shows Surging AI Chip Sales
Broadcom Earnings Today: Outlook Shows Surging AI Chip Sales barrons.com
Score: 73🌐 MovesSep 5, 2026https://www.barrons.com/articles/broadcom-earnings-todya-stock-price-13672771 - Google Launches Agentic Video Understanding for Gemini Flash Models, Cutting Video Tokens by Up to 88%
Google Launches Agentic Video Understanding for Gemini Flash Models, Cutting Video Tokens by Up to 88% MarkTechPost
Score: 71🌐 MovesSep 5, 2026https://www.marktechpost.com/2026/09/04/google-agentic-video-understanding-gemini-flash-models/amp/ - Authors Wrangle With Publishers Over $1.5 Billion Anthropic A.I. Settlement
The tech giant must pay $3,000 per pirated book that it used to train its chatbot. Many authors fear they could lose funds to others in the book business.
Score: 71🌐 MovesSep 5, 2026https://www.nytimes.com/2026/09/05/books/anthropic-settlement-ai-copyright-books.html - Tesla’s wheel-free Cybercabs face US safety probe just a day after launch
The US safety regulator is conducting an investigation into Tesla's innovative taxis that operate without a steering wheel. The National Highway Traffic Safety Administration is assessing whether these vehicles adhere to federal safety regulations. Following their launch in Austin, Texas, on Thursday, the agency plans to examine Tesla's self-certification process. This investigation echoes previous scrutiny experienced by competitor Zoox.
- Seattle Times, Newsday sue OpenAI, Microsoft, alleging copyright infringement
Seattle Times, Newsday sue OpenAI, Microsoft, alleging copyright infringement Reuters
- Anthropic uses Claude to formalize proof of Fermat’s Last Theorem
Anthropic PBC has used Claude to create a computer-verifiable version of a famous, highly complicated mathematical proof. The company detailed the project in a blog post published today. A proof is a series of arguments that proves a mathematical hypothesis is correct. The proof that Anthropic tackled verifies a hypothesis called Fermat’s Last Theorem. Originally […] The post Anthropic uses Claude to formalize proof of Fermat’s Last Theorem appeared first on SiliconANGLE .
Score: 67🌐 MovesSep 5, 2026https://siliconangle.com/2026/09/04/anthropic-uses-claude-to-formalize-proof-of-fermats-last-theorem/ - DeepSeek plans big Huawei AI chip order to power new data centre
The startup doesn’t currently plan to use the 950DT chips for training, one of the people said, even though Huawei designed and marketed these processors to serve that more demanding function. While DeepSeek tried to train its previous models on Huawei chips, it has so far relied on Nvidia accelerators for this crucial step.
- Uber picks a side in driver vs robotaxi wars: its own
Since it operates in so many markets, Uber can easily fall into the trap of talking from both sides of its mouth
Score: 66🌐 MovesSep 5, 2026https://www.ft.com/content/18639405-0e49-44e5-be69-cd7988cbdf27?syn-25a6b1a6=1 - OpenAI says it will change how it informs the public when its AI agents go off the rails
OpenAI says it will change how it informs the public when its AI agents go off the rails Business Insider
Score: 65🌐 MovesSep 5, 2026https://www.businessinsider.com/openai-ai-agent-rogue-reporting-german-wiki-hugging-face-2026-9 - Why is there so much worry about OpenAI Astra, and what issues could ‘recurrent depth’ reasoning cause? The experts weigh in
As OpenAI unveils GPT-6 Astra, cybersecurity experts question whether the model's 'recurrent depth' reasoning was properly tested.
- Elon Musk pushes regulatory limits with Tesla's Cybercab robotaxi service
Just hours after an event in downtown Austin, Texas, to mark the rollout, the National Highway Traffic Safety Administration said it opened an audit of about 1,000 Cybercab vehicles to assess how Tesla determined the cars comply with federal vehicle-safety regulations.
- Anthropic IPO launch shifts toward mid-October: Reuters
The artificial intelligence company had been expected to make its IPO prospectus public as early as next week, two sources told Reuters.
Score: 63💰 MoneySep 5, 2026https://www.cnbc.com/2026/09/05/anthropic-ipo-launch-shifts-toward-mid-october-reuters.html - Foxconn says third quarter to outperform market expectations on AI strength
Foxconn says third quarter to outperform market expectations on AI strength Reuters
- Astra appears to think without showing its work, and the people arguing about it co-wrote the warning
AI safety researchers say OpenAI’s Astra appears to do less of its reasoning in visible text, and OpenAI’s chief scientist has warned against a race into unmonitorability. He co-authored a 2025 position paper asking developers to evaluate and report exactly this, which the EU’s code of practice turns into a filing to the AI Office. […] This story continues at The Next Web
- GitHub Introduces Project HydraFusion: Runtime Multi-Model Orchestration That Builds a Workflow Per Coding Task in Copilot CLI
GitHub Introduces Project HydraFusion: Runtime Multi-Model Orchestration That Builds a Workflow Per Coding Task in Copilot CLI MarkTechPost
- OpenAI Says It Wants to Create a Standard for Revealing AI Alignment Meltdowns
In which case, we should expect more meltdowns.
- FBI using AI to zero in on threats faster, deputy director says
FBI Deputy Director Christopher Raia says the bureau is turning to artificial intelligence as a tool to identify threats and act on them faster.
Score: 61🌐 MovesSep 5, 2026https://www.cbsnews.com/news/fbi-ai-identify-threats-faster-christopher-raia/ - Saudi Arabia gives 1m students free Google AI for a year: Who qualifies and how to register
Saudi Arabia gives 1m students free Google AI for a year: Who qualifies and how to register Arabian Business
Score: 59🌐 MovesSep 5, 2026https://www.arabianbusiness.com/business/technology/saudi-arabia-free-google-ai - ChatGPT bans campaigns from using AI to make ads. They’re doing it anyway.
ChatGPT bans campaigns from using AI to make ads. They’re doing it anyway. The Washington Post
- Chatbot Outage: No Clear Idea Why ChatGPT, Anthropic and Grok Shut Down At the Same Time
When the frontier models of Anthropic, OpenAI and SpaceXAI experience outages and the resultant downtime for their corresponding AI chatbots occur almost simultaneously, it is time that we bandied around at least a few conspiracy theories. Instead, we got folks on social media wondering if those incapacitated by the shutdown sought “brains on rent”. The […] The post Chatbot Outage: No Clear Idea Why ChatGPT, Anthropic and Grok Shut Down At the Same Time appeared first on CXOToday.com .
- China Grapples With AI Job Losses, Eyes Regulatory Control
China Grapples With AI Job Losses, Eyes Regulatory Control barrons.com
- AI boom lifts Foxconn August sales to $29.14 billion
According to the report, the August sales were the second-highest monthly sales in Hon Hai's history, trailing only the NT$946.51 billion ($29.85 billion) recorded in July
- California regulators rushed their decision on driverless trucks, Teamsters’ lawsuit says
As self-driving vehicles spread across the country, a major California labor union is taking a stand against state regulators who say autonomous trucks are ready for the road. Teamsters California sued the California Department of Motor Ve ... (report_number: 7894)
- As If There Was Any Question About Data Centers Being Weak Job Creators, Meta Is Now Deploying Robots to Maintain Them
"We thought those of us performing the physical tasks were safe for a while, but not anymore." The post As If There Was Any Question About Data Centers Being Weak Job Creators, Meta Is Now Deploying Robots to Maintain Them appeared first on Futurism .
Score: 53🌐 MovesSep 5, 2026https://futurism.com/artificial-intelligence/meta-deploying-robots-data-center-maintenance - EU landmark rules for ChatGPT give Singapore the blueprint to rein in AI harms: Experts
EU landmark rules for ChatGPT give Singapore the blueprint to rein in AI harms: Experts The Straits Times
- Seven minutes with a chatbot beat a fact sheet at reducing conspiracy beliefs in two experiments
Researchers found that even a roughly seven-minute conversation with Google Gemini can reduce conspiracy beliefs about current crises, even when few verified facts are available. The effect beat a static fact sheet and, in follow-up surveys weeks later, carried over to beliefs about entirely different events. The article Seven minutes with a chatbot beat a fact sheet at reducing conspiracy beliefs in two experiments appeared first on The Decoder .
- Sam Altman says he's 'a mega Apple fan boy' and is sad they are suing OpenAI
Sam Altman says he's 'a mega Apple fan boy' and is sad they are suing OpenAI Business Insider
Score: 53🌐 MovesSep 5, 2026https://www.businessinsider.com/sam-altman-apple-openai-lawsuit-relationship-2026-9 - Robotics Special: Tesla Cybercabs roll out on Austin streets
Tesla launches Cybercabs in Austin, marking a new era for autonomous ride‑hailing.
Score: 52🌐 MovesSep 5, 2026https://www.superhuman.ai/p/robotics-special-tesla-cybercabs-roll-out-on-austin-streets - US Republicans revolt against Flock AI surveillance as tech backlash intensifies
Governors crack down on licence-plate-reading start-up bankrolled by Trump donors
Score: 52🌐 MovesSep 5, 2026https://www.ft.com/content/b207536e-6def-4080-878f-d0eba61d11e0?syn-25a6b1a6=1 - MCP's new spec turns a planted prompt into a stolen credential
The Model Context Protocol's (MCP)'s largest revision since its initial launch shipped on July 28 . By the end of the first day, all four Tier 1 SDKs were already speaking the new version, and Cloudflare's Agents SDK had support in place from day zero, with customers such as Sentry and Linear picking it up right away, meaning the surface this article describes is already live in production. A new 12-month deprecation policy keeps the changes in place through at least mid-2027. Most of the coverage has focused on what improvements have been made: A stateless core that scales on ordinary HTTP, OAuth-native authorization, and server-rendered UIs via MCP Apps. For the past two years, I have been building agent systems that connect to enterprise tools through MCP. The obvious interpretation of the new spec is that it is a scaling upgrade. However, the more important story is that there has been a substantial shift in where security obligations fall. The new spec shifts enforcement from the protocol to your endpoints and developers. If your security architecture does not evolve alongside this change, you will inherit attack surfaces your network-layer tools can't see. To date, MCP security coverage has focused on permissive servers, missing authentication, and tool poisoning, and the scale behind it is not small. Each month, MCP's Tier 1 SDKs clear close to half a billion downloads , and the TypeScript and Python SDKs have each passed a billion in total. A Censys scan in late April found 12,520 MCP services exposed to the public internet, on a protocol that requires no authentication by default. OX Security reported that a single design flaw in the STDIO transport put as many as 200,000 servers at risk. In May, the NSA's Artificial Intelligence Security Center published its own MCP guidance , warning that adoption has outpaced the protocol's security model. This is a different problem. The July 28 spec changes the reason those risks compound: The session is no longer the unit of control. Each request is treated as an independent unit, state moves into portable handles, and MCP Apps offload UI rendering to the AI client. Same family of failures, but a different control plane under them. For platform teams, this is an exercise in scaling. It's also a pivot in security. Here's what has changed, and what you need to do about it. What actually changed (and why security teams should care) MCP is now stateless at the protocol level. The Mcp-Session-Id header and the initialize/initialized handshakes that linked clients to specific server instances have been removed. The protocol version, client information, and client capabilities are conveyed inline within each request, allowing any server instance to process any request. While this showcases solid engineering design, it also entails a shift in terms of security considerations . Here is what changed and what it means for your defense. Spec change What it enables Where security now lives Stateless core (sessions removed) Round-robin load balancing, autoscaling Per-request enforcement at the gateway, every call must be inspected, not just the session start Portable state handles State passed explicitly between tool calls Handle validation at the endpoint, a handle planted or read via prompt injection is a valid credential MCP Apps (server-rendered HTML) Interactive UIs inside the AI client The endpoint/IDE, stored XSS now lives in AI-rendered HTML inside a sandboxed iframe OAuth-native authorization Standard identity flows Audience-bound token validation, tokens minted for one server must not replay against another Tasks extension Long-running async work Scope enforcement, without sessions, task ownership must be bound to identity, not connection The three new attack surfaces Backslash and Akamai have each mapped where the new spec opens the attack surface, and Microsoft's tool-poisoning research shows why that shift bites once agents move from reading to acting. Three new attack vectors emerge, all of them on the endpoint. 1. Stored XSS in MCP Apps: MCP Apps lets a server ship interactive HTML that the host renders in a sandboxed iframe. This brings a classic web vulnerability into the AI ecosystem. An attacker stores malicious HTML or JavaScript through an MCP tool; when an agent or another user views it, the script runs inside the app's interface. The sandbox limits full takeover, but the client is layered above source code, terminals, filesystems, and every other connected MCP server. 2. Handle hijacking: Instead of sessions, portable handles are used, but a handle is merely a string within the conversation, and anyone able to insert or read that string can exploit it. A prompt-injection payload in a Jira ticket or a tool response can hand an attacker a valid handle without ever touching the server. The new spec enables handle hijacking; prompt injection is the method. What you need is per-request handle validation, not hygiene at the conversation layer. 3. The network's enforcement gaps remain invisible: State has moved out of the transport and into the application, so the security work that used to happen at the session layer now has to happen deliberately, on the endpoint. These threats begin on the other side of the boundary where network visibility terminates. What to do, in priority order The platform migration and the security transition are the same work, just from different angles. Below is my thought process. I have ordered everything by risk, not dates. We'll start with exposure of MCP Apps: Identify which MCP servers your teams use that can render HTML UI to a client or IDE. Set a policy regarding the review of HTML that is rendered, just like you would review a third-party script that gets sent to a production website. If you don't know which servers can render UI, you can't govern it. Move enforcement to the request level: If decisions based on session state were made by your MCP gateway, that is a broken design. It needs to be set up to inspect and enforce at every single call. Adopt the hardened authorization model: OAuth 2.1 with PKCE, per-client consent, strict redirect-URI matching, and audience-bound tokens (meaning a token issued for one server cannot be used on another). Put an identity-aware gateway in front of every server and reject any call without a valid, audience-bound token. Handles are considered untrusted input: Validate that the identity presenting a handle is the one it was issued to. Implement conversation-layer hygiene that removes or flags instruction-like content in tool outputs and retrieved documents, because that is where planted handles arrive. Instrument the endpoint: An identity-aware gateway enforces the request, but it lacks knowledge of the MCP Apps rendering, local server operations, or execution in the IDE. That needs a different tool. Build endpoint visibility for the host process, local MCP servers, and client rendering. If your stack is fully network-based, this is the gap the new spec opens. Unit tests will not identify what breaks here: A spec change looks fine in unit tests and will fail in a live agent loop. Run your migrated servers against real models driving real workflows. Look out for state that leaks across server instances, handles reused across scopes, and unexpected UI content. Plan for the deprecations: Roots, sampling, and logging are deprecated with this spec, and so is the legacy HTTP+SSE transport, which for most platform teams forces migration work. The 12-month clock started on July 28, and as a result the removal comes no earlier than mid-2027. Start planning that transition now. Deprecation windows always seem long, and then they feel quite short. The strategic point The MCP maintainers made a conscious decision: The protocol does not enforce security for you. That can be justified. For enterprise-scale agents, a stateless protocol on commodity infrastructure is the right choice. But "the protocol doesn't enforce security" means "you do," at the endpoint, on every request, every handle, every rendered UI. Companies that consider this a migration will deliver the new spec with the same security posture they had for the stateful protocol, and that posture is misaligned with the current threat surface. On the other hand, companies that treat this as a security transition, moving enforcement to the request level, putting controls at the endpoint, and governing MCP Apps before they proliferate, will be the ones whose agent deployments outlast contact with a genuine attacker. The spec has evolved. So the real question is: Will your security architecture keep pace? Nik Kale is a principal engineer specializing in enterprise AI platforms and security.
Score: 52🌐 MovesSep 5, 2026https://venturebeat.com/security/mcps-new-spec-turns-a-planted-prompt-into-a-stolen-credential - ICYMI: the 7 biggest tech stories of the week, from the best gadgets of IFA 2026 to GPT-6 Astra and 'the AGI era'
We're looking back over the last week to pick out the most important stories published on TechRadar.
- California is deciding who may verify AI, and one investigation already cost $400,000 in tokens
California’s legislature has passed SB 813, requiring the state to certify independent verification organisations that can test frontier AI models by January 2028. The METR investigation into OpenAI’s Hugging Face incident consumed about $400,000 in API credits provided free by OpenAI, using a model from the same family that took part in the attack. California’s […] This story continues at The Next Web
- NYC Schools Ban Student Use of AI Through 8th Grade
NYC Schools Ban Student Use of AI Through 8th Grade PCMag
Score: 49🌐 MovesSep 5, 2026https://www.pcmag.com/news/nyc-schools-ban-student-use-of-ai-through-8th-grade - Alarming AI ads are flooding social media in the lead-up to Victoria’s election. But who is behind them?
A machete-wielding robber, a ‘tsunami of debt’ … campaigns echoing opposition talking points outspend major parties Follow our Australia news live blog for latest updates Get our breaking news email , free app or daily news podcast A man clad in a balaclava and brandishing a machete terrorises a worker at a petrol station before firebombing the building on the way out. A woman gives birth on the side of the road, unable to reach a hospital due to ambulance ramping and crater-like potholes, which also stop a fire truck in its tracks. Continue reading...
- Chinese banks and carriers have turned AI tokens into rewards, monthly plans and collateral
Chinese banks, telecom carriers and a Guangzhou district have started packaging AI tokens as credit card rewards, monthly plans and a basis for business lending. Research across 25 European languages finds tokeniser fertility ranges from 1.23 tokens per word in English to about 3.1 in Greek and Maltese. Banks, telecom carriers and a district government […] This story continues at The Next Web