Artificial Record

The AI industry, on the record.

The Briefing

Get the daily edition in your inbox.

Subscribe
Executive Read Est. 18 min read

AI Industry Daily Briefing — October 5, 2026

Horizon3 says Anthropic's Mythos model found a critical flaw in the Rejetto HFS file server that VulnCheck saw attacked within a day of disclosure, Meta says Muse Spark helped mathematicians on six papers, Judge Mehta dismissed Chegg and Penske Media's antitrust suits over Google's AI Overviews, and President Trump announced Jay Clayton will lead a federal AI task force.

The Executive Read

Today’s news is about what AI systems can now do on their own, and who decides what happens next. Horizon3, a security firm, says it used Anthropic’s Mythos model to find a serious flaw in a widely used file server, and VulnCheck, a vulnerability-intelligence company, says it saw attacks on that flaw within a day of the public write-up. Meta says its Muse Spark model helped outside mathematicians settle questions that had been open, and Meta’s own post concedes that some of the answers were reached by others at the same time. Those are two claims about capability, and both come from the companies or researchers who made them. The second half of the day is about authority. A federal judge dismissed two publishers’ antitrust suits over Google’s AI Overviews, finding they had not alleged an agreement. A federal appeals court paused a Minnesota law on AI “nudification” tools in a case brought by xAI, in an order that, as reported, gave no reasons. And President Trump announced that the Director of National Intelligence will lead a new federal AI task force. Capability keeps moving. The rules are being set case by case, by judges and by announcement.

Top AI Headlines

Horizon3 Says Anthropic’s Mythos Found a Critical Flaw in a File Server, and Attackers Followed Within a Day

What happened. On September 30, Horizon3, a penetration-testing company, published a write-up of a flaw in Rejetto HFS, a free, widely used program for sharing files over a network. The flaw is now tracked as CVE-2026-61500. Horizon3 says it used Anthropic’s Mythos model to find a chain of cryptographic weaknesses that let an attacker predict the server’s secret signing key, forge an administrator login and run their own code on the machine. The Hacker News reports a severity score of 9.3 out of 10 and says versions 3.0.0 to 3.2.0 are affected. The fix is version 3.2.1. According to The Register, Horizon3 researcher Zach Hanley disclosed the flaw on Wednesday, and by Thursday night VulnCheck researcher Patrick Garrity had detected live exploitation from a China-based IP address aimed at servers in the United States and Japan. The Register adds that four more attempts followed on Friday from two US proxy addresses. VulnCheck’s detection is the evidence for exploitation; I have not seen a victim confirm a compromise.

Why it matters. The mechanism is easier to follow than it sounds. The server builds its secret key from JavaScript’s Math.random(), which is a general-purpose random-number function, not a secure one. The server also leaks some of that function’s raw outputs to anyone who starts a login. Hanley’s account, as quoted by The Register, is that Mythos “didn’t just flag the insecure PRNG in isolation,” meaning the weak random-number generator, but “simultaneously identified that the application leaked raw Math.random() outputs through a separate code path.” With enough leaked outputs, an equation-solving tool called Z3 can rebuild the generator’s internal state and recover the key. That is the part the headline is about: the model connected two separate weaknesses into one working attack, and the researchers turned it into a demonstration. This is Horizon3’s description of what Mythos did. Anthropic has not, in anything I read today, published its own account of this finding. The Register says Horizon3 joined Anthropic’s Project Glasswing in July; I could not check its other figures against an Anthropic page.

Business implication. The gap between a public write-up and the first attack is now measured in hours. Any organisation running HFS 3.0.0 to 3.2.0 should be on 3.2.1. If AI tools make flaws cheaper to find and write-ups make them cheap to copy, the window to patch shrinks.

Sources: Horizon3, “Anthropic Mythos: Rejetto HFS RCE” (September 30); The Register (October 3); The Hacker News.

Meta Publishes Six Papers Written With Muse Spark and Outside Mathematicians; Five Answer Open Questions

What happened. On October 2, Meta’s research team posted “Solving open research problems together.” It describes six mathematics papers produced by teams of outside mathematicians working with Muse Spark, Meta’s model, versions 1.1 and 1.2. According to Meta, they used the model in its “Thinking Mode” through the ordinary Meta AI chat interface. Five of the six papers answer questions that had been open. Examples in the post: a sharp threshold for when random points in high dimensions can no longer be fitted exactly to an ellipsoid; a proof that a certain wave equation must blow up in finite time, settling a 2015 question; and a counterexample to a 2024 group-theory conjecture, a group of 384 elements, where Muse Spark wrote the search program and the mathematicians checked the result. Meta says each paper marks which passages were drafted mainly by people and which by the model, and that separate mathematicians reviewed the work.

Why it matters. The useful detail is in the caveats. The post says the mathematicians chose and guided the research; the model generated code, proposed proof approaches and drafted sections. In the ellipsoid case Meta acknowledges three independent solutions arriving at about the same time, and it says that others found some of the other answers earlier or concurrently, in August and September 2026. Meta’s claim is therefore not “first,” it is “contributed to.” Every claim here is Meta’s own, in its own blog. I have not read the papers, and I have not seen an independent mathematician’s assessment of how large the results are.

Business implication. For research-heavy industries, the practical signal is the working pattern: experts pick the problem, a general chat model proposes and drafts, other experts verify. Buyers evaluating AI for research work should ask for the same two things Meta published: which parts the model wrote, and who checked them.

Sources: Meta AI Research, “Solving open research problems together” (October 2).

Judge Mehta Dismisses Chegg’s and Penske’s Antitrust Suits Over Google’s AI Overviews

What happened. On September 30, Judge Amit Mehta of the US District Court for the District of Columbia granted Google’s motions to dismiss antitrust suits brought by the education company Chegg and by Penske Media, publisher of Rolling Stone, Variety and Billboard. Press reports describe a 41-page opinion. Both suits argued that Google uses its search dominance to make publishers hand over content for free, for use in snippets, AI Overviews (the AI-written summaries at the top of search results) and Gemini, in exchange for referral traffic. Mehta held that the Sherman Act requires an agreement, and that the publishers described none. The widely quoted line is: “An expectation is not an agreement. It is simply how a general search engine works.” Press Gazette reports that the court said there was no “formal bargain” between the parties, and trade coverage reports that the judge found Penske had not plausibly alleged that Search and AI Overviews are separate products. Search summaries of the coverage describe the Penske dismissal as without prejudice, meaning it can be refiled. I could not find the opinion on a public docket, so the details here rest on press accounts of it.

Why it matters. The ruling closes one route for publishers. Antitrust law needs a conspiracy or an exclusionary practice. A claim that Google takes more than it gives, without anything resembling a deal, did not meet that test. The judge reportedly said he was “not unsympathetic” to the publishers’ position and that antitrust is not the way to fix the economics of technological change. That points publishers towards copyright suits and legislation.

Business implication. Publishers weighing a challenge to AI search summaries have a clear data point on what pleading will not work. Licensing negotiations, not antitrust claims, are where leverage sits for now. The ruling does not end Google’s copyright exposure, and I have not seen an appeal announced.

Sources: Forbes, “Google Wins Dismissal Of Penske Media, Chegg AI Lawsuits” (October 1); Press Gazette on the Penske ruling. The Forbes page would not load for me; the report of its contents is from search summaries.

President Trump Names Jay Clayton to Lead a New Federal AI Task Force

What happened. On Sunday, October 4, President Trump announced on social media that Jay Clayton, the Director of National Intelligence, will lead a “Super Intelligence Force,” according to PBS NewsHour and NPR. The group’s stated task is to coordinate federal engagement with consumers, public interest groups, religious organisations, critical infrastructure providers and AI companies, so that “America continues to lead the World in Super Intelligence,” in the president’s words as quoted by PBS. Other members are FTC Chairman Andrew Ferguson, Pentagon chief technology officer Emil Michael and Office of Personnel Management director Scott Kupor. The group reports to Trump and chief of staff Susie Wiles. Search summaries say it has 120 days to report. PBS says the announcement followed a White House event at which AI company executives signed a voluntary accord on self-regulation. The PBS article, as I read it, includes no executive-order text or legislative language.

Why it matters. The task force is an announcement, not a rule. As reported, it has no stated authority to bind companies. What it does is put the intelligence director, the consumer-protection regulator and the Pentagon’s technology chief into one coordinating group, and it names the stakeholders, including “religious organisations,” that the White House wants in the conversation.

Business implication. AI companies should expect outreach and information requests from a group that includes the FTC chair, whose agency enforces consumer-protection law. The voluntary accord, which I could not read, is the more immediate test: what it commits companies to, and whether it is enforceable. Until a document appears, plan around the process and not the label.

Sources: PBS NewsHour, October 4; NPR, October 4. The announcement was made on social media; I did not locate the post itself.

Model and Product Updates

OpenAI’s DevDay brings GPT-6.1 Sol, computer use in the Agents API and cloud Codex. At its developer conference on October 2, OpenAI announced GPT-6.1 Sol, which InfoQ’s recap describes as a model for coding, computer use and professional tasks, priced at one-fifth of GPT-6 Astra’s standard rates, with cached input at $0.10 per million tokens. The Agents API now supports computer use, which lets an application operate software through its visual interface, along with multi-agent tools and context compaction. Codex, the coding assistant, can run in cloud environments, so a developer can start a task remotely. A “Decisions API,” built on a model called Luna for classification and routing, is in limited preview. ChatGPT’s plugin system now lets developers build sidebar experiences and custom file viewers. I could not open OpenAI’s own recap page, which returned an access error, so what is above is InfoQ’s account of it.

Sources: InfoQ, “OpenAI DevDay 2026 Recap for Developers”; OpenAI’s recap, openai.com/index/devday-2026-recap (as cited by InfoQ; not opened).

Google’s Gemini 4 Argon is announced, but only trusted testers can use it. On September 30, Google announced Gemini 4 Argon. According to 9to5Google, it can output up to one million tokens at once, up from 64,000, and is available for now to trusted testers and to cyber defenders in a programme called Fairwind. Google’s own benchmark claims, as relayed by 9to5Google, include 77.9 percent on DeepSWE v1.1, a coding test, ahead of Claude Opus 5.5 at 74.2 percent and GPT-6 Astra at 74.1 percent, and 51.3 percent on AutomationBench. These are Google’s numbers, not independent results. Introductory pricing is $2 per million input tokens and $10 per million output tokens, rising to $4 and $20 afterwards. A broader release is described as “rolling out soon.” I did not open Google’s own post.

Source: 9to5Google (September 30).

Barclays says Claude is now used by 16,000 of its colleagues. On October 1, Anthropic published a customer story on Barclays. It says Barclays’ Colleague Knowledge Assistant, built on Claude, has helped more than 16,000 colleagues since 2025 and handled over one million searches, and that in Global Markets Claude sorts 120,000 emails a day. Barclays says it is aiming for half of developer adoption of Claude Code by the end of 2026, with most software engineers using Claude in 2027. These are figures from a vendor-published case study. No contract value or savings figure is given.

Source: Anthropic, “Barclays scales Claude to upgrade operations and improve client experience” (October 1).

Regulation and Policy Watch

A federal appeals court pauses Minnesota’s AI “nudification” ban in xAI’s suit. On October 2, the Eighth US Circuit Court of Appeals granted xAI’s motion for an injunction pending appeal, which suspends Minnesota’s law while the case continues. The law took effect on August 1. It bars website operators and software developers from letting users create realistic images showing an intimate body part that is not in the original photo of an identifiable person. xAI argues the law violates the First Amendment, and says its Grok Imagine tool has “rigorous protections.” The state’s attorney general, Keith Ellison, said his office is disappointed, and said the law targets AI products that “generate sexual images that harm and harass people in the vilest way possible.” US District Judge Donovan Frank had earlier refused xAI relief, finding it had not shown irreparable harm and had waited too long. The appeals court’s order, according to the report, was a single sentence and gave no reasoning. That means the ruling tells us the outcome of this stage and nothing about how the judges view the free-speech question.

Source: Reuters, via US News (October 2).

The Internet Watch Foundation reports more AI-made child abuse images in six months than in all of 2025. The IWF, a UK charity that finds and removes such material, said on October 5 that analysts identified 6,310 AI-generated images meeting the legal definition of child sexual abuse imagery between January and June 2026. That is 40 percent more than the 4,512 found across 2025. Among 6,221 images where age and sex were recorded, girls appear in 98 percent. Children aged 7 to 13 account for 79 percent of the material, up from 70 percent last year. By severity, 5,557 images (88 percent) fall in the least severe legal category, with 403 in the middle category and 350 in the most severe. The IWF’s chief executive, Kerry Smith, said “Europe cannot afford to delay” and urged EU legislation that would allow detection of both known and previously unseen material. The counts are the IWF’s own, from material it assessed, not a measure of everything online.

Source: Internet Watch Foundation, October 5.

The Google AI Overviews dismissal and the new federal task force are covered above.

Emerging Startup Radar

Safeworld exits stealth with a $12 million-plus seed round to test AI robots in simulation. TechCrunch reports that Safeworld, founded by Ding Zhao, who directs Carnegie Mellon University’s Safe AI lab, with Kyle Wong and Simo Rachidi, raised more than $12 million. Shine Capital and a16z Speedrun led, with Box Group, the Carnegie Mellon endowment, Innovation Endeavors and SV Angel. The product places a robot’s real control software in a digital copy of a site, with realistic human models, and runs thousands of scenarios, such as a worker stepping out from a blind corner or tripping. The question is whether the robot sees the person, how fast it stops and whether it avoids contact. Gritt Robotics, which makes AI-powered construction robots for solar-panel installation, is a named partner. Zhao told TechCrunch the company could “be the first profitable company in this field,” which is a founder’s forecast. The reasoning is that generative AI robots are less predictable than older rule-based ones, so third-party testing may become a precondition for deployment.

Instinct raised $1 billion at a $10 billion valuation, according to its September 28 release. Instinct, which is building a “personal agent for everyday life,” said the Series C came from Sequoia Capital, Benchmark and Coatue. Secondary coverage says the product, launched by invitation in August, can book, buy and cancel by text or phone, and that the valuation is four times the $2.5 billion set by a $250 million Series B about a month earlier. I found no user numbers. I could not open the Business Wire page, so the terms are as listed in search results.

Sources: TechCrunch on Safeworld (October 5); Business Wire, Instinct release (September 28).

AI Infrastructure and Market Signals

Firmus, an Nvidia-backed data-center operator, is reported to be giving existing investors half of its Australian IPO. Bloomberg reported on October 5, citing people familiar, that Firmus Grid plans to allocate about half of the shares in its initial public offering to existing shareholders, which would let Nvidia and Blackstone raise their stakes. Secondary summaries put the offer at up to A$5.5 billion, say demand ran well above the offer size and describe it as the second-largest IPO in Australian history. I could not open the Bloomberg article, so the account of it is a summary. If the allocation is as reported, much of the new money comes from existing backers.

Former Groq engineers sue over Nvidia’s licensing deal, per the Financial Times. The Financial Times reported on October 5 that Benjamin Serebrin and Joshua Rubin, two former Groq engineers who hold shares, filed suit in Delaware. Summaries say they allege that Groq’s board sold the company’s core assets and most of its engineers to Nvidia in a deal Nvidia called a “non-exclusive” licence, leaving common shareholders under-compensated. They reportedly concede there is no Delaware precedent for treating such an “acqui-hire,” where a buyer licenses technology and hires the team without acquiring the company, as a merger. Reported deal figures vary from source to source, so I give none. I could not open the FT article or the complaint. This is an allegation, and Groq and Nvidia’s responses are not in what I read.

Sources: Bloomberg, “Firmus Said to Plan Allocating Half of IPO to Existing Investors” (October 5); Techmeme index entry pointing to the Financial Times report on Groq (October 5). I did not read either article in full.

Public Investment Watchlist

Informational only; this is not investment advice. I did not verify today’s share-price moves from an exchange or company source, so none are quoted.

  • Alphabet (NASDAQ: GOOGL). Won dismissal of two AI Overviews antitrust suits; the Penske dismissal is reportedly without prejudice and appealable. Gemini 4 Argon is limited to trusted testers for now, and its benchmark figures are Google’s.
  • Nvidia (NASDAQ: NVDA). Named as an existing shareholder in Firmus and as a counterparty in the Groq suit, where the allegations are against Groq’s board. Nvidia’s side is not in what I read.
  • Meta Platforms (NASDAQ: META). Published the Muse Spark math results; no financial effect has been stated.
  • Anthropic (private). Anthropic said on June 1 that it had confidentially submitted a draft registration statement for a proposed IPO. Reuters reported on September 28 that it had reviewed a prospectus whose risk section warns of “catastrophic or existential risks to humanity.” I checked EDGAR today and found no public Anthropic filing, though my search may have been incomplete, and the Reuters piece’s details come through secondary carriage. Nothing here is an offer, and no pricing or date exists.

Watchlist

  1. Rejetto HFS patching. Whether further exploitation attempts appear, and whether Anthropic publishes its own account of the Mythos finding.
  2. Penske and Chegg appeals. Whether either publisher appeals Mehta’s ruling or refiles.
  3. The Eighth Circuit’s reasoning. Whether the court explains its order in xAI’s case, and whether other states’ AI image laws face the same challenge.
  4. The Clayton task force. Whether a document, executive order or the voluntary accord’s text appears to show what the group can require.
  5. Reflection AI. Axios reported October 4 that the Nvidia-backed lab is preparing an open-weight model; no name, licence or benchmarks yet.
  6. Anthropic’s public S-1. Reuters says marketing could start in mid-to-late October; I could not confirm that from a filing.

Editor’s note on omissions and corrections: I withdraw nothing from earlier editions. I dropped a Qualcomm-Huawei patent deal, two Bloomberg reports and a RobCo valuation story because I could not reach original reporting. I found no earnings releases within the window, so that beat is omitted.

Subscribe to the Daily

The AI briefing on your doorstep.

One email each morning. Source-backed, hype-free, built for operators.

Free. Unsubscribe in one click.