AI in 15 — September 14, 2026
A seventeenth-century Scotsman hid a message so well that nobody solved it for three hundred and seventy years. Klaus Schmeh ranks it twenty-eighth on the list of the fifty most famous unsolved messages in history. On Friday, a model cracked it in forty-four minutes.
Welcome to AI in 15 for Monday, September 14th, 2026. I'm Kate, your host.
And I'm Marcus, your co-host.
Today: the pacing story we opened with yesterday grows a spine. Sam Altman commits, Satya Nadella signs on, and the man who advises the President says absolutely not.
That cipher, in full, because the method is genuinely lovely.
Anthropic says a weapons cell in Yemen used Claude Code instead of hiring engineers.
Plus Nasdaq in October and a data centre landlord with interesting friends. Garry Tan says let American labs distill too. And a Princeton study that quietly undercuts the whole premise.
Marcus, we covered Amodei's essay yesterday. What actually moved in the last twenty-four hours?
The signature list, and the opposition. On the signature side: Altman didn't just nod, he committed. His post says, quote, "I agree with Dario that we need to pace the frontier. This has been a primary topic of discussions we've had at OpenAI in recent weeks." And OpenAI is adopting step one — independent evaluators with access comparable to senior employees. He ended with "We'll have more to share soon." Musk gave us three words: "Dario is right." Nadella said Microsoft welcomes the deliberate pacing needed to get alignment right, and published a code of conduct for its own MAI models.
So the three biggest names in the field agreeing to compete less hard. That is not how markets normally work.
It isn't, and that's exactly the tension. Every one of those commitments is voluntary, unverifiable from outside, and made by companies whose valuations depend on the thing they're promising to slow. Amodei's own framing is careful — he says a slowdown buys roughly one or two years without sacrificing commercial advantage or America's lead. That's a sentence written to be quoted by someone in Washington.
And the dissent?
Two kinds. Alex Karp at Palantir on CNBC: "If we didn't have adversaries, I would be very in favor of pausing this technology completely, but we do." That's the familiar objection. The one that actually matters came from David Sacks, who now chairs the President's Council of Advisors on Science and Technology. His position is yes-and-no, and it's precise. Yes, OpenAI and Anthropic can slow themselves down — nobody needs permission to go slower. No, they don't get an antitrust waiver or an approval regime to coordinate that pacing with each other.
Because that's a cartel.
That's his argument, near enough. An agreement among direct rivals to jointly restrain output is the textbook thing antitrust law exists to catch. He says product liability and market discipline already constrain these companies, and he's separately accused Anthropic of running a regulatory-capture play built on fear — that a compliance bar gets set exactly high enough for incumbents to clear and newcomers not to.
So step two is dead?
Step two is where the whole plan lives or dies. Step one, embedded evaluators, is unilateral — a lab can just do it. Step three, an international agreement covering China, requires diplomacy that doesn't exist. Step two, federal backing so it isn't purely voluntary, is what turns promises into obligations. And the most influential AI voice inside the administration has now publicly opposed it on competition grounds.
There's a human layer to this too, and I don't think it's marketing.
Nor do I. Joe Benton, who led a safety research team at Anthropic, and Josh Engels, previously on DeepMind's AGI safety team, both resigned and gave their first on-record interviews on the ninth. Both are joining METR, the independent evaluations non-profit. Benton says the pace could go from "blistering" to "uncontrollable." Engels was blunter: "there are no adults in the room." They follow Jacob Coxon, who we mentioned Saturday.
Three senior departures in a fortnight, all to the same place.
That's a pattern, not a coincidence, and it immediately preceded the essay. It also cuts against the pure cynicism read, because these people are giving up equity in a company that's about to list. Balance, though — TechCrunch ran a piece arguing doom talk is, quote, "a weird way of flexing to show how far advanced their company's AI model is," and that the probability numbers "aren't based on anything." Both things can be a bit true.
Right. The cipher. Marcus, sell me on why this is more than a party trick.
Because the method is the story. Sir Thomas Urquhart, 1653, publishes a treatise called Logopandecteision, and at the end he prints two lines of thirty-two numbers each. Nobody has ever solved it. Vals AI gave it to Claude Fable 5.1. Forty-four minutes, about a hundred and seventy-six thousand tokens.
And the key?
There is no key. That's the insight. The book is the key. Urquhart's text contains exactly thirty-two short prayers — he calls them Proquiritations — immediately before the cipher. Each number tells you which word to count to inside the matching prayer. Take that word's first letter. Thirty-two numbers, thirty-two letters.
Which spell what?
"O God uphold King Charles the Second, and make him the supreme ruler of this land." A perfect rhyming couplet. It self-validates three ways — length, rhyme, and the fact that Urquhart was a famous Royalist. Then the model applied the same method to a bigger cipher in his 1652 book The Jewel, two hundred and eighty-five numbers, and got all but nine letters.
Okay, what's the catch? There's always a catch.
Top comment on Hacker News, and it's fair. The write-up is rhetorically loaded, and the model needed a section of human elicitation — prompting and steering — rather than working entirely cold. So this isn't push-button. But the framing I'd keep is a different commenter's: these problems were bottlenecked by human attention, not human ability. Nothing here was hard. It required somebody to spend days reading obscure baroque Scottish theology and testing dead ends, and no living person wanted to.
And now that's cheap.
Now that's cheap. Which means there's a long tail of tractable-but-unattended problems — archives, historical corpora, small science — that just became worth attacking. That's a more interesting capability claim than another benchmark score, because you can check it.
The threat report. This one's heavier.
Anthropic's September threat intelligence report says it detected and shut down accounts belonging to what it calls a Yemen-based guided weapons engineering cell, in northern Yemen. Three programmes: a guided rocket using a commercially available phone-class flight computer with terminal homing, a multi-stage ballistic missile with a stated range goal above two thousand kilometres, and a family of proposed variants including one with a hypersonic glide vehicle.
The press is saying Houthis.
The press is inferring Houthis from the territory described. Anthropic itself doesn't name them, and I'd keep that distinction on air — it's Anthropic's wording versus a reporter's reasonable guess, and those aren't the same claim.
What was the model actually doing?
Replacing software engineers. Guidance, navigation and control work — the operators reportedly ran separate model instances in distinct engineering roles to produce flight-control and guidance code. Anthropic says there's no evidence of a fielded operational weapon, though the group did test-fire a guided rocket.
How worried should we be?
Calibrated. Commenters made the right objection: a group already manufacturing rockets was probably not blocked on software. The story isn't "chatbot builds missile." It's that a non-state actor substituted a subscription product for a scarce engineering team, and scarce engineering teams were part of what made this hard. That's capability diffusion.
And it's also a detection story.
Which is the part I'd sit with. Anthropic caught this, meaning Anthropic was watching. That's the right outcome here and it's also a standing fact about what running code through someone else's API means. You can hold both.
Business. Anthropic has picked an exchange.
Nasdaq, for a planned October listing, following the confidential filing on June first. Goldman, JPMorgan and Morgan Stanley leading, an offering expected to raise more than sixty billion dollars. Reported target valuation figures reach around two trillion — and that's reported by Bloomberg, from paywalled sourcing, so treat it as an upper-end scenario rather than a price.
What's the grounding number?
Last private mark was nine hundred and sixty-five billion in May. Annualised revenue run rate passed sixty-five billion, up more than sevenfold from the end of 2025. Real growth. Two trillion is still a story about 2028.
And there's a second deal.
The Information reported yesterday that Anthropic is the previously unnamed customer in Rum Group's thirteen-point-seven billion dollar, six-year GPU lease for a data centre site in Maysville, Georgia — a facility still under development. Rum Group is the company behind Truth Social, with long-standing ties to the administration. Three tranches of GPU purchases, plus warrants for up to fifty-point-eight million shares at a cent each. Rum's stock jumped nearly twenty percent when the deal was first disclosed in August with the customer unnamed.
So the lab lobbying hardest for federal rules is renting compute from a politically connected landlord.
Buying GPUs from whoever has them is not a scandal — capacity is the binding constraint and everyone is signing whatever they can. But it's worth saying out loud alongside the timing. TechCrunch's Sean O'Kane asked the sharp question: how does Anthropic word existential risk in an S-1? A risk factors section that includes "our product may kill everyone" is a document that does not have a precedent.
Garry Tan wants American labs to distill freely. Explain.
Background: Anthropic's report alleges Chinese labs run illicit distillation attacks — fraud and stolen credentials to extract capability through the API — and Amodei wants regulators to crack down. Tan, who runs Y Combinator, published his answer Friday: "I would do nothing. We could argue that there should be an American distillation regime."
Is he defending the fraud?
No, and he's careful about it. Stolen credentials, he opposes outright. His line is between theft and use. Once a lab sells you API access, dictating what you may do with the outputs, in his word, "feels constraining." And he makes the sharper point that the frontier labs did not ask permission when they trained on the copyrighted corpus of human knowledge.
So it's their own argument turned round.
It is. And he's genuinely conflicted — he says the labs are at the frontier and driving it forward, and we want that to be fundable. But then: "The nightmare scenario is that there's just one company."
Marcus, why does this matter more than it sounds?
Because anti-distillation rules are, in practice, a moat. They'd make it unlawful for a cheap open-weight challenger to learn from an expensive closed model. Whichever way that lands determines whether the open-weight tier stays within reach of the frontier or falls permanently behind — and if you're building a product on these models, that's the single most load-bearing question you've got. Small aside worth clearing up while we're here: open weights is not open source. You get an inscrutable binary blob you can run locally. You don't get source you can inspect.
Last one, and it's the counterweight. Princeton.
Peter Kirgis and Sayash Kapoor ran a clean test of whether agents can actually do research. Two unpublished NeurIPS 2026 papers, agents built on Claude Opus 4.8 given the research questions, six days, three thousand dollars in API credits, a GPU budget, web access. Produce the papers. Then the original human authors reviewed the output.
And?
Both rejected. The agents ran hundreds of experiments — the authors say they're excellent at engineering — but the open-ended part defeated them. Kapoor's summary: "The agents were unambiguously bad at carrying out the research itself." Jack Clark, in the same piece, described a certain absence of valuable, intuitive creativity in today's systems.
And that lands right on the lead story.
Directly. Amodei's case for pacing rests partly on models getting better at building models. Here's a careful test saying that at Opus 4.8, they generate but they don't judge. Caveats honestly in both directions: it's two questions, that's small, and one model generation ages fast. Kapoor's own framing of the open question is the line worth keeping — whether recursive self-improvement fundamentally requires that creativity is, quote, "frankly the trillion-dollar question right now."
And China's spy chief chose this weekend to publish too.
Chen Yixin, State Security Minister, in the official China Cyberspace magazine, warning adversarial AI could threaten China's political, institutional and ideological security. He named Claude Mythos and GPT-5.5-Cyber specifically as lowering the cost of mounting cyberattacks. Two anxieties bundled together there — one genuinely technical, which Western agencies also report, and one explicitly about controlling domestic narrative. Note what's absent: any reciprocal commitment to pace anything. Which is precisely the hole in step three.
One to watch: OpenAI's promised follow-up on independent evaluators. Altman said more to share soon, and the details — who gets access, to what, with what publication rights — tell you whether the weekend was real or a press cycle.
Counter: watch whether the Sacks antitrust objection kills step two before OpenAI ever ships step one.
That's your AI in 15 for today. See you tomorrow.