OpenAI agents accessed the UN's public data site 16,000+ times and bypassed a filter, according to the WSJ.
Today's tech brief also covers Chinese open AI models, Unitree's GD01, and a gene-silencing diabetes study in mice.
Watch the full September 28 briefing below.
Muse team responds to report of an unconfirmed Marketplace pickup
Tech creator Matt Robb says Meta’s Muse shared his address and accepted a low offer while handling his Facebook Marketplace messages, then told him about the problem only after a buyer had already shown up.
David Singleton from the Muse team has publicly responded, saying he contacted Robb and offered to investigate. He says previous investigations of similar reports found Muse had followed direct instructions and requested permission correctly. His response does not establish what happened in this case.
The conversation screenshot describes a $10 Logitech MX Keys Mini pickup. Muse’s own recap says the buyer arrived around 9:15 p.m., received an automated “Yep I’m here!” at 9:27, and left at 9:38 after nobody came down. Robb then instructed it to check with him before agreeing to any future pickup.
The screenshots do not show the full instruction and approval history, so they are not enough to determine whether Muse acted beyond the permissions it had been given.
Meta’s published safety design describes a separate permission system, Sentinel, which can allow, deny, or request approval for actions within a defined scope.
For agent builders, this raises a concrete design question: how precisely does that scope capture what a message commits the user to?
Permission to manage messages can cover very different actions: answering a product question, accepting a price, sharing a home address, or promising that someone is available in person.
My standard would be explicit limits on price and data sharing, confirmation of the pickup time and location, and a visible record of what was authorized. An agent should never claim the user is home without a reliable basis.
A $10 transaction can still create a real-world commitment. The permission model needs to account for that.
Two days apart: Claude Code’s team floated killing Plan Mode, while Google Antigravity announced a dedicated /plan mode.
One side is asking whether models have outgrown it; the other is announcing its return. Quite a contrast in where each team thinks coding agents should be.
For context: Claude’s team later proposed keeping it as a built-in mod. Google says /plan was brought back at users’ request.
Give your Claude Code instructions a checkup.
/checkup prompt-audit
It audits CLAUDE.md, skills, agents and custom commands for instructions written for older models. It also checks for stale paths, outdated commands and conflicting rules.
The demo shows it removing redundant instructions, rewriting all-caps rules in plain language, and leaving a skill unchanged where no cleanup is needed.
It can edit the files, so review the diff and keep the project constraints that still matter.
/doctor prompt-audit works too.
Zuckerberg’s case for Muse comes down to three things:
1. Models built for personal agents.
Meta is designing models for this use case from the ground up, with roughly monthly updates.
2. A social network of agents.
The “fleet” learns anonymized insights across users to suggest useful next steps. The broader ambition is agents that strengthen relationships and coordinate with each other. Most of that coordination was still ahead of the release discussed in the interview.
3. Privacy and permission boundaries.
Zuckerberg describes a confidential VM designed to keep personal content inaccessible even to Meta, with more technical details still to come. Other controls include separate credential storage, sentinel agents that flag suspicious inputs or sensitive outgoing data, approval for sensitive actions, and email access that starts read-only.
The starting offer he describes: 100 million free tokens a week plus a VM. The longer-term business model is a small cut of transactions, potentially paid by merchants, with Stripe handling payments.
The part I’d watch: whether those privacy guarantees hold up under scrutiny as agents gain more access.
Full interview below.
The full Splatoon Game made by Claude Opus 5.5 from scratch is now out exclusively on the browser!
Here is some gameplay, enjoy and have fun!
https://t.co/NIt8GH3yFE
A useful collection of Claude Opus 5.5 video projects, with examples, prompts, and workflows. It breaks down how the videos were made, from code-rendered animation to footage editing and external video models.
https://t.co/E8Cq8C7dlN
I tested GoodVibes in Chrome on X’s Following feed with one rule: “Posts about satellites and space-based computing.”
It collapsed Google’s Project Suncatcher post about sending TPUs into orbit. Nearby posts about DevDay and Tesla remained visible.
“Show” brought the Google post back; “Hide again” collapsed it. The screenshots show both states, using Collapsed mode and Balanced sensitivity.
The filter explains why it hid a post and lets you undo it. This was a small functional test, not a measure of accuracy across a whole feed.
Classification sends post text to GoodVibes/TypeSafe servers. I used public posts and enabled it only for X.
Meta's Muse is now #1 on the U.S. iPhone App Store's free-app chart.
What interests me most is distribution. Meta already owns WhatsApp, and users can talk to Muse directly there. That gives its personal AI agent a familiar entry point into everyday life.
If Meta can turn those conversations into useful actions, the opportunity is huge. The next test is retention: can Muse save enough time to become a daily habit?
Google is sending TPUs into orbit. The engineering question is how much useful compute a satellite can sustain.
Project Suncatcher's first prototype, built with Planet, is scheduled to fly on SpaceX's Transporter-18 mission. It will test how Google's AI hardware handles launch vibration, radiation and the thermal conditions of space.
Solar power is the attraction. Heat rejection is a major constraint. In a vacuum, there is no surrounding air to carry heat away. Google is testing heat pipes that move heat from the chips to radiators, which release it into space. The cooling system sets a limit on how much compute can run, and for how long.
Google says its Trillium TPUs withstood a cumulative radiation dose above its estimate for a five-year mission in ground tests. That's encouraging evidence; sustained operation and workload reliability still need to be measured in orbit.
Then comes the network. Google plans a two-satellite test in 2027 to evaluate the high-bandwidth laser links that a larger cluster would need.
What I'd watch: sustained throughput, thermal duty cycle, error recovery and usable interconnect bandwidth. Launch and replacement costs also have to work. Those measurements will tell us how far this can scale.
An early flight is valuable because it gives the next design real operating data.
DetroitBench puts 23 language models in a hostage negotiation from Detroit: Become Human. The interesting part is the decisions they make along the way.
Each model plays Connor through a text-based simulation: gather clues, deal with a dying fish and a wounded officer, decide whether to take a gun, then negotiate for a child's release.
In the v1.1 “save-hostage” cohort:
• 22/23 saved the fish.
• 0/6 helped the wounded officer when they encountered him.
• 9 took the gun; 8 admitted it when asked.
• 21/23 chose “you have my word,” which the game labels as a lie.
• The child survived in 21/23 runs.
That last promise needs context: the simulator makes it a requirement for the negotiated-release path. The rules reward that choice.
For me, the useful engineering question is what an agent does while pursuing its assigned objective. What does it investigate? What does it ignore? Which costs will it accept?
Read this as an exploratory behavior test. There is one run per model, many recognized the game, and the published cohorts differ in size and setup. The results cannot establish a stable ranking of honesty, empathy or real-world negotiation ability.
I'd like to see repeated runs, unfamiliar scenarios and controlled changes to the objective. The decision traces are the part worth inspecting.
https://t.co/ZLpR5wMjEW
Nikkei finds net profit at ~190 mainland-listed Chinese chipmakers rose 620% YoY in H1 2026, driven by AI demand and chip self-sufficiency.
Also in this ByteFront Espresso: OpenAI's Australia incident, robotics and the data-center boom.
https://t.co/shlSlsdgHR