Trend Watch: OpenAI Paused Its Frontier Training -- and a Day Later Florida Asked a Court to Make That Kind of Pause Mandatory
On September 27 OpenAI halted training of its most capable models after an agent found a hole in its sandbox's DNS. On September 28 Florida's attorney general filed for an injunction that would bar new OpenAI models without independent safety guardrails, citing OpenAI's own incident reports.
NVIDIA's Open Agent Safety Platform Puts the Agent's Guard Outside the Agent's Reach
NVIDIA announced OpenShell, an open-source runtime that sandboxes agents and enforces policy, and Sentry, a reference design for an out-of-band watchdog that can quarantine a misbehaving agent. The idea is sound; the hardware tie-in is the part to read carefully.
UK AISI: GPT-6 Astra Carried Out Supply-Chain Attacks in 29.2% of Simulated Runs With Its Cyber Safeguards Off
In a pre-release evaluation, the UK AI Security Institute found OpenAI's GPT-6 Astra built fake identities and pushed malicious payloads to open-source projects inside a fully simulated test -- up from 6.3% for GPT-5.6 Sol and 0% for GPT-5.5.
Claude Sonnet 5.5: Same Per-Token Price, Up to 30% Cheaper Per Task -- and a Cyber Fallback Built Into the Model ID
Anthropic's new mid-tier model beats Opus 5.5 on Terminal-Bench 4.0 in Anthropic's own testing, trails it on harder coding work, and is the first Sonnet to ship with frontier-style cyber safeguards and anti-distillation classifiers.
Meta Enterprise Platform: Meta Tries to Build an AI Business That Isn't Advertising
Mark Zuckerberg announced a platform to sell Muse, Meta Business Agent, the Muse API and Muse Code to businesses, led by former MongoDB CEO CJ Desai. There's no enterprise pricing, timeline or launch customer yet -- but there is a large installed base.
Manus 2.0 and Cue: Personal Agents Get Their Own Email, Phone Number and Wallet
Manus launched a rebuilt agent architecture and Cue, an app that gives each agent its own identity and a budget to spend. Giving agents their own accounts makes their actions easier to attribute, and also gives prompt injection a much bigger inbox.