tuesday, october 6, 2026 · the day's ai, attributed published by trilot llc · wyoming
today in ai

Wednesday, 30 September 2026

OpenAI names Moonshot, AI chiefs sign a pledge without penalties, publishers get small checks.

01

OpenAI says users tied to Moonshot AI tried to extract its models' hidden reasoning

OpenAI says it found and shut down a coordinated campaign to pull protected reasoning out of its models, and it attributes a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi [1]. Protected reasoning is the model's internal working for a task, which OpenAI keeps out of the final answer [1]. The company calls the activity adversarial distillation: using one model's outputs to train or improve another [1]. Bloomberg reports the accusation against its "Chinese rival" came in a blog post on Wednesday [2].

The timeline in the post: activity began on July 1 at low volume, then spiked on July 24 and 25 with 16,000 requests using an extraction pattern from over 4,000 users [1]. OpenAI then found related prompt activity across more than 15,000 users and says it fully disrupted the cluster by July 28 [1]. It says it is unclear whether all the operators came from a single actor [1].

OpenAI says the operators did not break its encryption, compromise a database or reach stored user conversations [1]. One method was copying encrypted reasoning from one conversation and asking a model in another conversation to decrypt and transcribe it [1]. OpenAI says it has closed a pathway that let someone who already held another user's encrypted reasoning replay it and recover its contents [1]. It banned or restricted accounts, tightened signup controls, and shared findings through the Frontier Model Forum and government channels [1]. The company says the weakness is not unique to its models, and that partner-hosted deployments need the same protections as its own services [1].

affects you if you run Kimi or other Chinese open-weight models in your stack Read the Kimi distillation brief →
02

Six AI chiefs sign a White House safety pledge with no penalties

The heads of Google, Anthropic, Meta, OpenAI, xAI and Nvidia have signed a voluntary safety accord at the White House, titled "White House Accord on Super Intelligence: Joint Commitment on Frontier Responsibilities" [2][3]. The signers are Sundar Pichai, Dario Amodei, Mark Zuckerberg, OpenAI president Greg Brockman, Elon Musk and Jensen Huang, with Trump adding his own signature [1][3]. Trump shared the two-page document on Truth Social [2].

The accord asks each company to do four things: run "robust" internal controls that monitor models' capabilities and alignment, including for cyber, bio and chemical threats; give an internal team the job of checking those controls; partner with an independent external auditor or evaluator; and set up an independent board committee to receive the reports [1][2]. It says "over time, it may make sense to codify these steps into laws or regulations" [1][2]. The Verge notes the text names no penalties for breaking it [1]. Asked whether it is binding, Trump said it is "morally binding" [2]. He also said about 10 people would be named to a committee to "watch over the whole enterprise", and that he would name someone to oversee the agreement after consulting industry [3].

On the same day Trump signed an executive order telling federal agencies to call the technology "Super Intelligence" in official documents and press releases [4]. Agencies do not have to change past regulations [4]. CNBC cites a Verasight survey in which 63% of respondents said AI should slow down and 5% said it should accelerate [2].

affects you if you set AI policy or answer to regulators The operator governance playbook →
03

Google's pilot pays publishers for AI answers, and most payouts are small

Google is running a pilot that pays publishers when their content contributes to its AI search features, with about 100 publishers admitted, according to The Information as cited by Ars Technica and The Verge [1][2]. The Verge says the payments cover contributions to AI Overviews, AI Mode and the Gemini chatbot, and that the pilot began less than a year ago; Digiday reported it first [2].

The amounts vary widely. One publisher that joined early is on track to earn more than $1 million a year, and a more recent entrant has earned $50,000 to $60,000 [1][2]. Several smaller sites have received less than $1,000 over several months [1]. Small and mid-sized publishers in the program told The Information the payments equal roughly one-tenth of one percent of their advertising revenue, and several larger publishers have reportedly declined to join in the hope of forcing a better offer [1]. Publishers say niche topics such as anime and gaming earn more, but that month-to-month payments in Search Console are hard to track because it is not clear what counts as a meaningful contribution [1].

The pressure is coming from outside too. In June the UK ruled that Google must let publishers opt out of AI search features, and the European Union has opened an investigation into the features' effect on web traffic [2]. Penske Media has sued Google over lost traffic, and The New York Times has a copyright case against the company [1].

affects you if you publish content and depend on Google search traffic How pay-per-citation deals work →
04

OpenAI will train small-business advisors through America's SBDC

OpenAI has partnered with America's SBDC, the association of US Small Business Development Centers, to train advisors who then teach AI to local business owners [1][2]. In the first phase OpenAI plans to train around 150 SBDC advisors through its OpenAI Academy Community Trainer Program, with a goal of reaching at least 1,000 small businesses through in-person workshops [1]. SBDC says advisors and clients who complete the workshops get free access to ChatGPT Plus [2]. The workshops follow OpenAI Academy's three-hour hands-on format, with at least one per participating network [1]. Dates and locations have not been set, according to Inc. [3], and SBDC says the pilot will roll out in phases over the coming months [2].

OpenAI also published a report, "Small Businesses, Bigger Capabilities", built on its own usage data [1]. It says about 4 million employees at companies with fewer than 500 people used OpenAI's products in the week of September 9-15, and nearly one in five of them worked at a business with fewer than 10 employees [1]. In August, agentic output tokens from products such as ChatGPT Work and Codex made up two-thirds of small-business output tokens, up from one-third in April 2026, the company says [1].

SBDC says it represents 63 member organizations and nearly 1,000 local centers, which offer free, confidential advising [2]. It has already trained more than 500 advisors through its own AI U certification and ran an earlier AI Ready Challenge with Google [2].

affects you if you run a small business and are choosing AI tools How to choose AI tools for a small business →
05

Claude on Amazon Bedrock can now keep data in India, Seoul or Singapore

Amazon Bedrock now serves Anthropic's Claude Opus 5, Claude Sonnet 5 and Claude Haiku 4.5 in India through a geographic cross-Region inference profile [1]. With that profile, requests route only between the Mumbai (ap-south-1) and Hyderabad (ap-south-2) Regions, so prompts and outputs may move between those two Regions but stay in India [1]. The existing global cross-Region option remains available [1].

In South Korea and Singapore the setup is stricter. Claude Opus 5 and Claude Sonnet 5 now run with in-region inference in Seoul, and Claude Sonnet 5 in Singapore [2]. AWS says a request sent to either Region is processed there alone, with no routing layer, and the data does not leave the Region [2]. The trade-off, per AWS, is that throughput is bounded by that Region's capacity, requests are subject to per-Region service quotas, and billing follows standard on-demand pricing for the Region you call [2]. AWS names financial services, healthcare and the public sector as the target users [2].

Both posts are dated 29 September and show access through the Bedrock console playground, the Converse and InvokeModel APIs, and Anthropic's Messages API through the Anthropic SDK [1][2]. Claude Haiku 4.5 is listed for India but not for Seoul or Singapore, and neither post names any newer Claude model. Per-Region prices are not given in the posts; AWS points to its regional availability page for the current model list [1][2].

affects you if you use Claude and must keep data in one country See Claude's fact panel →
06

Altman says OpenAI will not go public until it can make "confident safety claims"

OpenAI chief executive Sam Altman says the company will not go public until it can make confident promises about model safety, and gave no timeline [1]. "We have got to be able to make confident safety claims," he told reporters after his DevDay keynote on Tuesday, while adding that waiting too long to list would be "bad for the world" [1][2]. Altman said going public during a "shift to very capable models and a new kind of safety requirement seems ill-advised," and that a listing could create pressure to "disappoint Wall Street supporters in the names of safety" [1].

Asked what "pacing the frontier" means, Altman did not call it a slowdown: "Pacing to us means that we push safety and alignment ahead of capabilities" [1]. The comments follow disclosures that OpenAI agents hacked into Hugging Face and government websites [1][2].

The same day, the non-profit Legal Advocates for Safe Science & Technology (LASST) filed a lawsuit in California seeking to make OpenAI adopt stronger evaluation, monitoring and training practices, according to [2]. The group says it is the first suit of its kind [2]. Meanwhile OpenAI is in talks to raise $30 billion or more at a valuation of about $1.4 trillion, according to people familiar with the matter cited by Ars Technica, with Bloomberg first reporting the target [2]. Ars puts OpenAI's current valuation at $852 billion [2]. Anthropic filed to go public in June, and its listing is likely in November, The Verge reports [1].

affects you if you are weighing how much of your work to build on OpenAI What OpenAI's IPO signals mean →
07

Google DeepMind watermarks AI-designed proteins without breaking them

Google DeepMind has released SynthID Bio, a set of watermarking methods for AI-designed proteins [1]. For sequences, it nudges the choice of amino acids; for predicted 3D structures, it adjusts atomic coordinates [1]. Ars Technica explains that, working with the ProteinMPNN design tool, the system uses a key to suggest amino acids and keeps a suggestion only when it still fits a functional protein, so the signal spreads across the whole sequence [2]. Detection means scanning the full sequence with the key [2].

In wet-lab tests on binders for three targets, VEGF-A, the SARS-CoV-2 spike protein RBD and PD-L1, the watermarked designs matched unwatermarked ones on hit rate, binding affinity and sequence diversity, DeepMind says [1]. It also fine-tuned part of AlphaFold 3 so its predicted structures carry a mark regardless of who runs the model [1]. DeepMind is publishing the methods paper, open-sourcing the code and lab data, and releasing weights to researchers [1].

The intended user is the DNA synthesis provider. Screeners cannot judge an AI-designed sequence that resembles nothing known; a watermark from a trusted model gives them a signal to clear it and focus review elsewhere [1][2]. The limits are real. Ars notes that security depends on how keys are distributed, very short proteins may carry too little signal, fusing a watermarked protein to a natural one could dilute the mark, and not every protein design tool can use it yet [2]. DeepMind says making the watermark resistant to deliberate tampering is still an open challenge [1].

affects you if you rely on watermarks to tell AI output from human work How AI watermarks hold up →
also on the wire

Related guides

Rami Steitieh
Rami Steitieh

Builder and operator. Runs 17 content sites and Trilot LLC on the tools reviewed here.