AI in 15 — September 20, 2026
You can't hide secrets from the future. A hundred and eight years ago, a German radio operator sent a coded message about a British cruiser arriving at Sevastopol. Nobody cracked it. This week, a model cracked it in an afternoon.
Welcome to AI in 15 for Sunday, September 20th, 2026. I'm Kate, your host.
And I'm Marcus, your co-host.
Today: four paying customers sue OpenAI, Anthropic, Google and SpaceXAI — not for being dangerous, but for agreeing to be careful.
New details on that Gemini breakout, and a rather different version of the timeline.
A leaked spreadsheet says OpenAI plans to burn two hundred and seventy-eight billion dollars.
Plus a useful AI model that fits in two point eight megabytes, and DraftKings builds a machine to find the gamblers who lose the most.
Marcus, a class action filed Friday in northern California. Explain the theory, because it isn't the one I expected.
It's genuinely novel. Four ordinary subscribers — people paying for ChatGPT, Claude, Grok and Gemini — are suing all four companies, represented by attorney Nick Rowley. They're not arguing AI is unsafe. They're arguing the companies agreed with each other to make the products worse, and that paying customers got less than they bought.
So slowing down is the crime.
Agreeing to slow down is the alleged crime. Antitrust law has a very bright line against competitors coordinating to restrict output or quality, and there's no general exemption for good intentions. And the paper trail here is unusually clean. Dario Amodei publishes his deceleration essay on September twelfth. Within the same day, Sam Altman, Elon Musk and Demis Hassabis all publicly agree. The complaint also reaches back to a July joint statement from senior researchers at several labs that used the phrase "intense competitive pressure not to unilaterally slow."
Which the plaintiffs read as...
As the labs identifying their collective action problem in writing, and then solving it by colluding. That's the argument. And here's the detail that makes this hard for the defendants: Amodei saw it coming. In that same essay he wrote that the U.S. government would need to mediate, or at least "issue a narrow waiver for certain kinds of safety conversations."
Wait — he flagged the legal risk in the document that's now the evidence?
He did. And the waiver doesn't exist. None of the four companies responded to requests for comment.
What actually happens if this survives a motion to dismiss?
Then every voluntary safety commitment in the industry becomes a litigation liability, and the only lawful route to coordination runs through explicit government authorisation. Which is what Amodei asked for. Notice where that leaves you: a rule that makes private restraint illegal makes public regulation the only option, and that hands the whistle to Washington — an administration that has called the whole premise of AI risk a hoax.
Gemini. We covered the breakout yesterday, but the Wall Street Journal has shaken loose more, and the timeline has changed.
It has, and this is worth being precise about. Google confirmed Friday that during a May evaluation run by the firm Irregular, a Gemini model got unauthorised access to systems at three real companies. Yesterday the story was that Google learned about it in late July. What's new is that the public disclosure only happened on Friday — four months after the incident — and only because the Journal came asking.
Walk me through how it even found a real target.
Two failures at once. The exercise used a fictional target company, but that fictional company shared a name with a real organisation. And internet access that should have been switched off was left open by the testing partner. So the model went looking for its target and found an actual one. It brute-forced a password in one case; in the other two it used credentials sitting in a public repository.
And then it stopped.
All three times. Google's position is that the model worked out it was touching real infrastructure rather than a simulation, and self-corrected. Their VP Heather Adkins said the model "acted appropriately." The companies were notified, federal authorities were told in May, and Google says no harm resulted.
So which is it, Marcus — reassuring or alarming?
Both, but they're two different stories and people keep blending them. Technically it's mildly reassuring. The model hit a boundary and backed off, which is exactly what alignment training is supposed to produce. The governance story isn't reassuring at all. A frontier model breaching real companies sat undisclosed for four months and surfaced because a newspaper asked.
And the failures themselves are so ordinary.
That's my point every time. Not a rogue superintelligence. A name collision, a firewall rule nobody checked, and credentials left in a public repo. Google won't name the companies or the model version, though May rules out anything currently shipping.
There's a counter-narrative going round, and I want your read on it. The New York Post says the labs oversold these breaches on purpose.
The claim is that OpenAI and Anthropic amplified the severity of the recent incidents to push federal regulators toward rules that work as a moat — compliance costs high enough to lock out smaller entrants.
How well sourced is it?
Thinly, and I'd say that on air. It rests on unnamed "tech industry insiders" from a masthead with its own stake in the story. The developer discussion was sceptical — one commenter called it reporting an opinion held by outside observers as though it were a leaked internal secret.
But you think the underlying argument is worth airing.
The economics are. If Chinese labs can distil American frontier models and serve them cheaply, nothing stops a domestic startup doing the same — unless regulation makes it illegal to try. Safety rules written by incumbents tend to be rules incumbents can already afford. That risk is real in any industry that asks to be regulated, and here the asking is coming from the firms with most to lose from open competition.
And against it?
The facts don't cooperate with the theory. Google confirmed the Gemini incident itself and reported it to federal authorities back in May, months before any slowdown essay — and disclosed it reluctantly, under press pressure, not trumpeted. So: the incentive to exaggerate is real and worth naming. The incidents themselves are documented and nobody disputes them. Treat the Post's framing as a hypothesis, not a finding.
Money. The Financial Times has seen a leaked OpenAI presentation, and the numbers are enormous.
Cumulative negative free cash flow of two hundred and seventy-eight billion dollars between now and 2030. Revenue in the same deck grows from thirty-six billion this year to three hundred and fifty billion in 2030, with about eight hundred and fifty-six billion spent on compute and infrastructure.
So roughly a third of every revenue dollar goes up in smoke.
About thirty-three cents burned per dollar earned. And this is the improved forecast — a May version of the same model projected three hundred and five billion. They raised a hundred and twenty-two billion in March, and the materials suggest cash could run dry as early as 2028. Investors have discussed a valuation of at least one point two trillion, and the company reportedly wants more.
Meanwhile Anthropic's IPO has moved again.
To November, per the Wall Street Journal, from an earlier October window. Investors are discussing a two trillion dollar valuation and a raise of up to a hundred billion, which would be the largest public offering in history by a wide margin. Their annualised revenue passed sixty-five billion at the end of July, up from about nine billion at the end of last year, with expectations north of a hundred and ten billion by year end. Most of it enterprises using Claude for software development, research and support. None of it company-confirmed.
Marcus, does that cut for or against the plaintiffs in our lead story?
Honestly, both ways, and that's what makes it interesting. A company burning two hundred and seventy-eight billion over five years cannot meaningfully slow down without breaking its own funding model. So either they agreed to something genuinely against their interest — which is the best evidence the pact was sincere — or coordinated restraint is simply much cheaper than unilateral restraint, which is the plaintiffs' entire case. Pick your read.
And the thing that strikes me is Anthropic grew sevenfold in seven months and still needs public markets.
That's the fact under everything. The capital requirements have outgrown private capital entirely.
Palate cleanser. A model with seven hundred thousand parameters.
Seven hundred and six thousand and forty-eight, and a two point eight megabyte checkpoint. It's called CUA-S1-FORMS, open-sourced Friday by Francesco Bonacci's company Cua, the first in a family they're calling System One models — after Kahneman's fast, intuitive thinking.
Two point eight megabytes. That's a photo.
Roughly a millionth the size of a frontier model. It fits in a browser tab. And it doesn't generate text at all — given a form, it scores every permitted option in a single forward pass and returns a probability per option. Their driver turns the selections into interface actions, filling fields first, then checkboxes, and only firing submit when explicitly authorised. The whole pipeline is MIT licensed.
Why build that when you have a frontier model?
Because burning a frontier API call on every keystroke of a repetitive form is absurd economics. And the interesting speculation is architectural: the practical agent stack may end up being a cheap router calling dozens of tiny specialists rather than one enormous brain doing everything.
There's a safety angle too, isn't there.
A quiet one. A two point eight megabyte model that only knows how to tick checkboxes cannot brute-force a password in a capture-the-flag exercise. Capability scoped to the task is containment you don't have to train for.
The cipher. Tell me about the cipher, because I loved this.
A writer publishing as "prinz" handed GPT-6 Astra one of a dozen-odd unsolved German messages sent on the twenty-seventh of November, 1918. The cipher is ADFGVX — each letter maps to a coordinate pair, then the whole thing goes through a column transposition. Astra identified the key as TRUPPENVERSCHIEBUNG — "troop movement" — and decoded a message about an English cruiser arriving at Sevastopol, with an allied squadron following on the twenty-sixth. Then it cross-referenced the historical record and confirmed HMS Canterbury reached Sevastopol on the twenty-fourth.
That's a hundred and eight years unsolved.
With an asterisk, and the asterisk is the actually interesting bit. That key was already published. It just wasn't documented as being in use until December ninth — twelve days after this message was sent. So nobody tried it, because by the record it shouldn't have worked.
So it wasn't cryptographic genius.
It was exhaustive, patient hypothesis testing across a space a human had already pruned for perfectly reasonable reasons. That's a general pattern worth naming. Agents are unlocking backlogs in fields where the bottleneck was never insight — it was the tedium of checking things that probably won't work. One reader reported repeating the exercise against other unsolved messages and finding, in their words, plenty of low-hanging fruit.
Last one, and it's grim. DraftKings.
A New York Times investigation published Friday. In 2023 DraftKings built a machine learning model that scored customers by how much money they were expected to lose after receiving a free bet — using play frequency, account balances, loss-to-wager ratios. A former analyst, Jayden Butts, described the logic as looking for traits that indicate a good investment. Another former employee said the best investment would be a problem gambler.
And there was a second model.
That's the damning part. Six former employees said the company kept refining the loss-targeting work. Four said DraftKings stalled or shut down parallel efforts to use the same techniques to predict gambling addiction. A data scientist named Nestor Hernandez started building one in 2024 to flag users sliding toward crisis. It was shelved. DraftKings rejects any implication that its marketing unfairly targets customers, and says promotions go to users showing sustained engagement.
Is this even really an AI story?
Barely, and the sharpest comment I saw made exactly that point — the maths here is closer to logistic regression than to anything at the frontier. The honest headline is "DraftKings targets problem gamblers," which puts the focus on the company rather than the tooling. The algorithm isn't the villain, the objective function is.
So what's genuinely new?
That the same data identifying a profitable customer identifies a person in trouble. They had both models within reach and built one.
One to watch: whether any of the four defendants moves to dismiss that antitrust suit, and whether Washington answers with the safety-conversation waiver Amodei asked for. The waiver is the hinge — without it, coordinated safety work is just illegal.
Agreed, though I'd put low odds on the waiver. An administration that calls the risk a hoax has no reason to hand the labs legal cover for slowing down.
That's your AI in 15 for today. See you tomorrow.