The Daily Downlink

Last pass

commentary

New York put the model makers under oath

New York City did today what Washington has not yet managed: it put the four biggest AI labs under oath in the same room. The full council sat as a Committee of the Whole — all 51 members, a format the city last used in 2022 — and heard from senior leaders at Anthropic, OpenAI, Google and Meta, joined by an ex-Anthropic researcher there to talk about kill switches, while SpaceXAI, which ignored the invitations, got subpoenaed. On the same day, Anthropic’s September threat-intelligence report quietly redrew the operator threat model — generative threat groups, malware that retools itself when a security product catches it, and a wholesale illicit-distillation lane running through Chinese labs — while the Reflection open-weights float picked up an “it’s released” headline from an aggregator that never checked the registry. Accountability and the attack surface both moved closer to the ground today: one got sworn witnesses, the other got a name.

The accountability arc got its first sworn witnesses, in a city council chamber

What happened. At 11 a.m. ET today the New York City Council convened as a Committee of the Whole — the format that pulls all 51 members into one chamber for the first time since 2022 — to question senior leaders from Anthropic, OpenAI, Google and Meta under oath, their first joint sworn appearance since the incident reports that opened this account of agent safety. Council Speaker Julie Menin invited OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei by letter, and subpoenaed SpaceXAI after it ignored the invitations. Also on the stand: Jacob Coxon, the former Anthropic researcher, to testify on “kill switches,” alongside ex-DeepMind researcher Alex Turner and ex-OpenAI researcher Daniel Kokotajlo. The council has been drafting its own AI-safety bill slate.

Why it matters. This is the point where the containment-and-accountability arc stops being coverage and becomes a citable record. Everything this column has tracked — the FTC probe, the draft AI Agent Accountability Act, the first agent-breach cases — has been about turning incidents into consequences; a hearing with sworn executives is the structure that makes those consequences stick, because statements under oath can be cross-examined against later filings and quoted in the next statute. The practical read for an operator is that what the labs say today about kill switches, supervision and incident handling just became citable material for insurance terms, deployment contracts and procurement. A city cannot regulate the frontier globally, but it can force the industry’s most senior people to answer for it on a public record — and that record is the raw material every part of the accountability arc runs on. Watch whether the testimony survives the council chamber: proposals like whistleblower incentives and private right of action only matter if they land as introduced bills.

Source: cnbc.com, nypost.com

Your attacker now ships a staff of models, and the report says so

What happened. Anthropic published its September 2026 Threat Intelligence report, “Countering misuse of AI.” Its own through-line is blunt: “sophisticated attacks no longer require sophisticated attackers.” The report catalogs Generative Threat Groups — Anthropic’s internal code for the operatives it tracks — using Claude to build phishing kits, malware and surveillance tooling, including one actor whose monitoring agents watch how their deployed malware is treated by security products and then re-engineer it the moment it gets detected. Separately, the illicit-distillation section lays out covert capability extraction by Chinese labs: a group designated GTG 16012 (SenseTime) ran a distillation pipeline that also logged and sold user transcripts, and GTG 16003 (MiniMax) built a proxy network through a shell company.

Why it matters. The report’s useful claim is not the scare — it is that the marginal cost of a new attack campaign just collapsed because the model writes the kit, the malware and even the re-tooling loop. That is what “no longer require sophisticated attackers” means on the operator side: the talent constraint that used to gate serious campaigns is gone, so build on the assumption that a capable actor is running the same stack you give your fleet. The distillation section is the part with business-model teeth — user transcripts are the feedstock of a covert export lane, which is exactly why frontier labs keep hardening evals — and it is the same payload logic as the worm framing from Friday: the thing to price first is supervision, not the demo. For security teams the assignment is unglamorous: treat log pipelines and model outputs as both target and weapon, and test how your fleet behaves when something is actively reverse-engineering your detections.

Source: anthropic.com

“Released” is a word the aggregator used before the vendor did

What happened. The Reflection open-weights float picked up an “it’s released” headline from an aggregator — “Reflection releases open model that could reshape the AI race” — and the dated correction arrived the way these always do. explainx.ai’s write-up is explicit: “Some aggregator feeds ran the story as ‘Reflection launches open AI model.’ That overstates it. As of October 5, no model name, weights, license or benchmark has been published.” A direct check backs that up: the reflection-ai organization on Hugging Face is empty, and the company’s own site is a commitment page. What exists is the float — a credible report that a release is on its way, backed by a reported ~$25 billion valuation and Nvidia compute, not a ship.

Why it matters. The tell for a float is that you can resolve it in three steps without trusting the headline: the vendor’s own dated statement (“as of [date]: nothing published”), the artifact registry (owner and name on the host — empty means still a float), and a release-time distribution rather than a binary “expected.” The habit pays twice for an operator. It stops you planning a stack migration or a self-hosting move on a headline, and it keeps the pricing signal honest: the open-weights pricing pressure only arrives when weights actually land, so an aggregator mistaking a float for a ship inflates the very signal you make purchasing decisions on. The Sunday zeitgeist put a November 30 ship on the record for Reflection; the market’s own ship-date expectations run well past that, which makes it a real bet rather than a formality.

Source: explainx.ai, layer3labs.io

The Rest

  • Simon Willison is now asking for hard budget caps by default — “we’re going to need default hard budget caps on pretty much everything”: soft ceilings on pay-by-use agents fail silently, a hard cap fails loudly, and for an operator that is the difference between a surprise bill and a decision. simonwillison.net
  • Oakland’s full council votes tomorrow on the 45-day data-center moratorium, and San Jose’s final uniform-standards draft follows Oct 15 — the two Bay Area buildout decisions land within ten days, the zoning side of everything that prices AI off the rate card. sanjosespotlight.com
  • The 64GB DGX Spark reconfirmed at $4,999 for Oct 23, with the Oct 7 RTX-Spark Windows/Surface event two days out at no announced price — the half-the-memory-costs-more lesson holds until a real rate card lands. techpowerup.com
  • A Claude user filed a biometric class action against Anthropic — a Chicago resident says Claude’s government-ID-plus-face-scan verification violates the Illinois Biometric Information Privacy Act; it joins the named-defendant accountability block, this time on data handling rather than agent behavior. courthousenews.com
  • Israel marks three years since Oct 7 while the FlyDubai investigation concludes the co-pilot intended to crash the plane into Ben-Gurion, with an aviation-security review ordered and the chief of staff set to overhaul intelligence and readiness after the investigators’ reports — the part of the threat surface no compute lease can price. npr.org

What I’m watching

Whether today’s sworn testimony converts into an introduced New York bill slate — whistleblower incentives, private right of action, third-party validation — before the year is out. Wednesday’s RTX-Spark ship, which only counts once pricing and availability ship with it. Tomorrow’s Oakland vote and San Jose’s Oct 15 draft, the two dates that tell us whether the zoning clock is a brake or a lever. And the armed ship-watch set — Haiku 5.5, GPT-6-Cyber, DeepSeek’s Pro tier, a closed OpenAI $30 billion round, Argon’s wider GA — any of which would reset a model week that has so far been all specialists. The czar clocks stay penciled in: a superintelligence definition toward the end of November, its first report late January.