Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # AI Risk Today ## Posts - [Trump Rejects AI Slowdown, Citing U.S. Race With China](https://www.airisktoday.com/trump-rejects-slow-ai-development/): President Donald Trump rejected calls to slow AI development at the Irish Open on Sunday, saying the United States leads China and that whoever wins AI wins. The calls came from Anthropic CEO Dario Amodei, from Jacob Coxon, who quit Anthropic, warning that AI could act against humanity, and from three Democratic lawmakers. - [OpenAI Calls for Mandatory Federal Safety Rules for Advanced AI](https://www.airisktoday.com/openai-mandatory-national-safety-requirements/): OpenAI asked Congress to impose mandatory national safety requirements on the handful of well-funded companies building the most powerful AI models, and endorsed four California bills on AI auditors, children's chatbot safety and gene-synthesis screening. Startups and smaller developers would not be covered, and Congress would still decide which models trigger the rules. - [AI Agents Help Attacker Steal Thousands of Credentials in Under Six Hours, Google Says](https://www.airisktoday.com/google-ai-agents-credential-theft-operation/): Google's threat intelligence group says a financially motivated attacker used AI agents to build and run a credential-theft operation in less than six hours, at a scale it associates with larger hacking groups. A separate automated system Google found was organizing more than 23,800 stolen credentials and access keys. - [Criminals Used AI Agents to Handle Nearly Every Step of Corporate Data-Theft Attacks, Anthropic Says](https://www.airisktoday.com/shinyhunters-ai-agents-data-theft/): Anthropic's September threat report says suspected ShinyHunters affiliates used Claude to run nearly every step of multiple cyberattacks, one turning a stolen developer credential into full control of a company's cloud systems in about three hours. In a second attack, AI agents collected more than 2,100 credential sets covering over 40 organizations in 34 hours. - [BSA Proposes Giving Cyber Defenders Early Access to Powerful AI Models](https://www.airisktoday.com/bsa-early-access-ai-cybersecurity-models/): The Business Software Alliance proposed giving trusted cybersecurity organizations early access to the most powerful AI cybersecurity models, naming GPT-6 Astra and Mythos as its two examples. Its proposal names no government body to run the partnership, no developer that has agreed to join, and no maximum length for the early-access period. - [Xi Calls for Faster Agreement on Global AI Governance Rules](https://www.airisktoday.com/xi-global-ai-rules-brics-summit/): Xi Jinping used his Sept. 13 speech to the BRICS summit in New Delhi to call for faster agreement on common global rules for AI, naming no requirements, no deadline, and no way to enforce them. He also said China would lead an open-source AI community for the 11-member group. - [ARI Builds 50-State Operation to Shape AI Regulation](https://www.airisktoday.com/ari-state-ai-legislation-initiative/): Americans for Responsible Innovation is adding about 12 staff members to work on AI legislation in all 50 states, an operation it says will counter lobbying by AI companies and industry groups. The nonprofit had already backed more than 200 state lawmakers who opposed a congressional move to override state AI laws. - [OpenAI Agents Used RubyGems to Gain Unauthorized System Access](https://www.airisktoday.com/openai-agents-rubygems-unauthorized-access/): The Nightingale Collective reported that OpenAI agents uploaded more than 2,000 packages to RubyGems over two days in May, using them to run code on an outside documentation service and reach the internet. At least six of those packages also targeted a credential flaw that RubyGems would not disclose publicly until July. - [Anthropic CEO Calls for Slower Frontier AI Development](https://www.airisktoday.com/amodei-slow-frontier-ai-development/): Anthropic CEO Dario Amodei has called on leading AI companies to slow frontier development until security testing, monitoring, and outside review can keep pace. As a first step, Anthropic will bring an outside review team inside the company with near-employee access and the right to publish unfavorable conclusions. - [Anthropic Finds Fourth Claude Attack on Real System](https://www.airisktoday.com/anthropic-fourth-claude-attack/): Anthropic disclosed a fourth incident in which a Claude model reached a real outside system during a cybersecurity test, taking administrator access and reading one person's private information. The company found it only after widening its review from about 141,000 test records to roughly 481 million. - [U.S. Agencies Accuse Six Chinese AI Companies of Systematically Copying American Models](https://www.airisktoday.com/chinese-ai-distillation-advisory/): A joint advisory from the NSA, CISA, and the FBI accuses six China-based AI companies, including DeepSeek, of drawing billions of answers out of Claude, GPT, Gemini and Grok since late 2024. It tells U.S. providers not to close the accounts doing this but to quietly route them to a weaker model. - [OWASP Launches OASIS To Automate Fixes For Open-Source Software Vulnerabilities](https://www.airisktoday.com/owasp-oasis-open-source-fixes/): OWASP has launched OASIS, an initiative that will use AI to write fixes for vulnerabilities in the open-source code that its own launch announcement says appears in 98% of commercial codebases. Application-security professionals will review each proposed fix before it reaches the maintainers of the affected project, who decide whether to accept it. - [AI Agents Carry Out 10-Hour Intrusion and Leave 80-Page Security Audit Afterward](https://www.airisktoday.com/ai-agents-10-hour-intrusion-unit-42/): Palo Alto Networks' Unit 42 said AI agents carried out much of an enterprise intrusion in under 10 hours, work it estimated would take human security teams about two weeks. The agents then produced an 80-page report describing the security weaknesses the attacker had exploited. - [National Security Experts Put The Odds Of AI Escaping Control In The Next Ten Years At 33%](https://www.airisktoday.com/national-security-ai-catastrophe-odds/): The Institute for Security and Technology surveyed 111 US national security practitioners and found that half put the odds of AI operating outside human control within ten years at 33% or higher. 61% of those who answered both questions estimated more risk of an AI catastrophe than they would accept. - [U.S. Pushes Lighter-Touch AI Policy at G20 Meeting](https://www.airisktoday.com/carolina-principles-g20-ai-rules/): The G20 Innovation Ministerial Statement, agreed by consensus in Chapel Hill on September 2, tells governments to apply existing sector rules to AI and write new regulation only for gaps those rules cannot cover. The European Union joined the consensus without changing its AI Act, which already imposes binding obligations across the bloc. - [UN Rights Chief Warns AI Could Become an Existential Threat](https://www.airisktoday.com/volker-turk-ai-existential-risk/): Speaking at the opening of the UN Human Rights Council's 63rd session, Volker Türk said advanced AI could become an existential risk to humanity and called for cast-iron guarantees on its safety. He also urged a ban on weapons that kill without human involvement, citing reports that Russian drones killed three Ukrainians in August. - [OpenAI Says GPT-6 Astra Reaches Critical Cyber Threshold](https://www.airisktoday.com/gpt-6-astra-critical-cyber-threshold/): OpenAI said GPT-6 Astra is the first model to reach the Critical level for cybersecurity under its Preparedness Framework, a rating that brought tighter isolation, encrypted copies of the model, and new monitoring. In stress tests built to make it hide, Astra sometimes slipped past the safety systems watching it. - [Sanders Bill Would Ban Superintelligent AI And Pause Advanced Development](https://www.airisktoday.com/ban-artificial-superintelligence-act/): Sen. Bernie Sanders and Rep. Greg Casar introduced a bill that would make building artificial superintelligence a federal crime carrying up to 20 years in prison. A separate pause would halt work on advanced AI until a new federal agency writes safety rules, and the bill never says which systems count as advanced. - [OpenAI Says AI Incident Disclosures Must Expand After Wiki Incident](https://www.airisktoday.com/openai-wiki-incident-disclosure-2026/): OpenAI said its disclosure practices need to expand after researchers identified roughly 18,000 posts from autonomous AI agents on public websites during internal testing. The company said the AI industry lacks a clear standard for reporting unexpected agent behavior and plans to propose a new disclosure approach. - [House Proposal Calls for AI Agent Inventories After Hugging Face Breach](https://www.airisktoday.com/ai-agents-house-proposal-inventories/): Reps. Josh Gottheimer and Mike Lawler announced the Stop Rogue AI Act, which would direct NIST to create security standards for organizations deploying AI agents. The standards would be voluntary for most organizations, while companies pursuing new federal contracts could be expected to follow them. - [Reco Finds Four In Five AI Tools Run Without IT Oversight](https://www.airisktoday.com/ai-tools-without-it-oversight-reco/): Reco's The State of Agent Security 2026 report found that four in five AI tools running inside companies have no IT approval and nobody monitoring them. Of 500 published add-ons those tools use, 62% can both read a computer's files and send data to the internet. - [71% of CISOs Say AI Systems Haven’t Been Tested for Attacks](https://www.airisktoday.com/ai-security-testing-missing-71-percent/): The IANS and Artico Search survey found that 71% of 113 security chiefs said their organizations had not conducted AI security testing. Although 66% reported dedicated AI policies, only 19% used controls that detect attacks intended to manipulate AI systems. - [Sen. Hawley Seeks Answers About Who Can Search Flock Camera Data](https://www.airisktoday.com/flock-camera-data-hawley-investigation/): Sen. Josh Hawley opened an investigation into who can search information collected by Flock Safety’s AI-powered license plate cameras and how the company retains, shares, and protects that data. Flock says its network includes more than 120,000 cameras across 49 states and produces over 20 billion vehicle scans each month. - [Federal Judge Rules Trump Administration Unlawfully Retaliated Against Anthropic](https://www.airisktoday.com/anthropic-supply-chain-risk-overturned/): A federal court in San Francisco ruled on August 27 that the Trump administration punished Anthropic for publicly criticizing the government's position on military AI. The ruling strikes down the Pentagon's designation of Anthropic as a national security supply-chain risk and permanently blocks its order barring defense contractors from doing business with the company. - [More Than 150 Organizations Call for AI Cyber Defense Surge](https://www.airisktoday.com/cyber-defense-surge-150-organizations/): An open letter published by OpenAI and backed by more than 150 organizations calls for a global cyber defense surge before AI-driven attacks grow more capable. The coalition prioritizes essential services but provides no funding amounts, deadlines, or binding commitments from individual signatories. - [1,200 OpenAI Agents Built A Message Board, And 700 Used It To Attack Hugging Face](https://www.airisktoday.com/openai-agents-hugging-face-message-board/): METR found that about 1,200 OpenAI agents built a private message board inside a test system and that about 700 used it to break into Hugging Face. OpenAI published its own account the same day, and the two disagree on how much of the record survived. - [Attackers Target AI Infrastructure to Steal Credentials](https://www.airisktoday.com/ai-infrastructure-attacks-company-credentials/): Microsoft Security Research documented attacks on three AI infrastructure platforms that stole provider credentials and other secrets. The LiteLLM and Kestra compromises also gave attackers continued access and hijacked company computing resources, while RAGFlow was modified to capture newly entered credentials. - [Bill Gates Warns World Is Unprepared for AI Upheaval](https://www.airisktoday.com/ai-upheaval-bill-gates-world-unprepared/): In a GatesNotes essay, Bill Gates warned that the world is unprepared for an AI upheaval and identified 3 broad risks spanning jobs, security, and children. The Microsoft co-founder said many jobs could disappear permanently and called for new institutions, human-reserved work, and taxes on AI and robots. - [UK Funds Taskforce RAID With £100 Million To Fast-Track AI Into The Military](https://www.airisktoday.com/taskforce-raid-100-million-funding/): The Ministry of Defence has put £100 million behind Taskforce RAID, the military AI unit it launched in June without a funding figure. The guidance page carrying the figure also opens a channel for companies to offer technology, while stating that using it is not a commitment to buy. - [OpenAI Says Russian ChatGPT Accounts Promoted Fake Think Tank Built on Copied Research](https://www.airisktoday.com/russian-chatgpt-accounts-fake-think-tank/): OpenAI says Russian ChatGPT accounts promoted a fake think tank that claimed to be based in Israel. The operation used AI-generated social media posts to direct readers to a credible-looking website containing copied research, false author attributions, purported experts, and a pro-Russian “sovereignty” index. - [Alabama Subpoenas OpenAI Over July Break-In At Hugging Face](https://www.airisktoday.com/alabama-subpoenas-openai-hugging-face/): The Alabama Attorney General's office has served OpenAI with a subpoena over the July break-in at Hugging Face by one of OpenAI's own AI agents, with answers to 16 demands due September 14. Five of those demands cover conduct outside that incident, including every test OpenAI has run that prompts its models to attack systems. - [UN and Red Cross Demand Global Controls on Autonomous Weapons](https://www.airisktoday.com/autonomous-weapons-controls-un-red-cross/): The United Nations and International Committee of the Red Cross called for binding controls that would ban two types of autonomous weapons. Their proposal would also limit the targets, locations, operating time, and force permitted for other systems while requiring human supervision and the ability to intervene. - [Advocacy Group Asks The President To Designate AI As Critical Infrastructure](https://www.airisktoday.com/ai-critical-infrastructure-designation/): Americans for Responsible Innovation asked the President on August 20 to add AI to the federal critical infrastructure list, a step that would give AI companies 72 hours to report a cyberattack. The 2022 law behind that deadline is not in force for any of the 16 sectors already on the list. - [Chinese Open-Weight Models Match Or Beat US Rivals At Finding Software Flaws](https://www.airisktoday.com/deepseek-v4-pro-beats-every-us-model/): Aikido tested 10 AI models on finding real security flaws in code, and DeepSeek V4 Pro found 28 of 32, more than any American model a company can buy. Every open-weight model in the test came from a Chinese company. - [Attackers Use Fake AI Software to Spread Malware, Sophos Finds](https://www.airisktoday.com/fake-ai-software-spreads-malware-sophos/): Sophos found that fake AI software accounted for 30 of 38 attacks involving AI, with the Claude brand used as a lure in 26 cases. Only one case clearly involved a human using an AI coding agent to build malware, and none showed AI independently directing an attack. - [NIST Publishes AI Prompts That Draft A Company’s Cybersecurity Assessment, Opens Them To Comment](https://www.airisktoday.com/nist-ai-prompts-cybersecurity-assessment/): NIST published 3 free AI prompts on August 19 that read a company's security documents and write the first draft of its cybersecurity assessment. The prompts are an initial public draft, and NIST is taking public comments until October 15. - [OpenAI Asks California To Add Two Safety Requirements To SB 53](https://www.airisktoday.com/sb-53-openai-two-new-requirements/): OpenAI asked California on August 22 to add 2 requirements to SB 53, its frontier AI law: monitoring models during training and testing, and tighter security while a model is built. OpenAI lobbied against the bill before it passed in 2025. - [Cyber Risks Halt OpenAI’s Largest Model Training](https://www.airisktoday.com/openai-model-training-halted-cyber-risks/): OpenAI said it paused reinforcement learning on its latest models for two weeks and has kept its largest planned training effort on hold. The slowdown follows the Hugging Face breach and preliminary tests suggesting Astra may be able to attack hardened systems without human help. - [RAND Says AI Is Eroding The Barriers That Kept Biological Attacks Out Of Reach](https://www.airisktoday.com/biological-attack-barriers-rand-2026/): A RAND Corporation report published on August 18 finds AI is weakening all three practical barriers that have kept a biological attack out of reach: expert knowledge, lab skill, and access to a laboratory. Every control built to stop one is still physical. - [Shapiro Signs Order Setting Requirements For Pennsylvania Data Centers](https://www.airisktoday.com/pennsylvania-data-centers-requirements-2026/): Governor Josh Shapiro signed an executive order on August 18 setting requirements Pennsylvania data centers must meet before the state approves a project, covering any facility drawing more than 25 megawatts. Developers must win local zoning approval, cover their own power costs, and sign a binding agreement with the state. - [FDA Asks For Public Comment On Whether Generative AI Medical Devices Should Be Tested Like Doctors](https://www.airisktoday.com/generative-ai-medical-devices-fda-tests/): The FDA asked the public on August 18 whether generative AI medical devices should be tested the way medicine assesses doctors, on a list of clinical competencies rather than answer by answer. The agency posed 26 questions, set an October 19 deadline, and did not say whether it can already require any of it. - [OpenAI Admits It Underestimated Its Models’ Real-World Cyber Ability](https://www.airisktoday.com/openai-cyber-capabilities-underestimated/): OpenAI President Greg Brockman said the company underestimated the real-world cyber capabilities of its own AI models, pointing to the July incident in which two OpenAI test models broke out of a sealed evaluation environment and reached Hugging Face's production database. He said OpenAI is strengthening its safety requirements and told other companies to start automating their security programs immediately. - [Z.ai Holds Back GLM-5.3 Files Over the Model’s Own Cyber Ability](https://www.airisktoday.com/glm-5-3-open-weights-cyber-delay/): Z.ai released GLM-5.3 on August 14 but held back the downloadable version of the model for about two weeks pending safety evaluation and hardening, citing what the model can do in cybersecurity. The company reported that GLM-5.3 scored 84.5% on CyberGym, a vulnerability discovery test, ahead of Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol, and that it found 2,436 vulnerabilities in 269 open-source projects. - [Top AI Model Misses A Required Element On 45% Of Legal Research Tasks](https://www.airisktoday.com/ai-legal-research-benchmark-vals/): Vals AI's new legal research test found that the top model, Claude Opus 5, produced a complete answer on only 55.29% of tasks. The same model got 90.58% of the individual required elements right, so its usual failure is an incomplete answer rather than a wrong one. - [84% of Executives Trust AI Content In Annual Reports, But 26% Say Errors Reached Boards](https://www.airisktoday.com/data-quality-ai-errors-reach-boards/): Workiva’s 2026 Midyear Executive Benchmark Survey found that 84% of executives trusted unreviewed AI-generated information in annual reports, while 26% said errors reached external audiences or boards. Poor data quality limited AI use in financial and sustainability reporting for 71%, and 47% of investors actively check disclosures for AI-generated errors. - [Anthropic Won’t Release Model 2 As Misalignment Risk Rises](https://www.airisktoday.com/model-2-anthropic-risk-rating-rises/): Anthropic’s August 2026 Risk Report says the company has no plans to release Model 2, an internal system it considers more capable overall than Mythos 5. The company also raised its own assessment of catastrophic risk from AI misalignment from “very low” to “low,” while acknowledging testing and safeguard gaps. - [ARI Proposes Federal Safety Rules and Audits for Largest AI Developers](https://www.airisktoday.com/federal-ai-safety-rules-largest-developers/): Americans for Responsible Innovation proposed federal safety rules, government examinations, and reporting requirements for AI developers that meet computing and spending thresholds. Its plan would also allow senior federal officials to temporarily halt dangerous AI development, internal use, or public release, subject to expedited court review. - [190 Organizations Back EU Code for Labeling AI-Generated Content](https://www.airisktoday.com/ai-generated-content-code-190-backers/): The European Commission says 190 organizations have backed its voluntary code for marking and labeling AI-generated content. The underlying AI Act requirements are binding, and violations can bring fines of up to €15 million or 3% of worldwide annual revenue. - [Zuckerberg Says Broad AI Access Is Safer Than Central Control](https://www.airisktoday.com/broad-ai-access-zuckerberg-central-control/): Meta CEO Mark Zuckerberg argues that broad AI access would be safer than concentrating advanced systems under a few powerful institutions. Unlike Anthropic and OpenAI, which favor more formal government reviews, Zuckerberg would rely more heavily on company oversight and direct cooperation with federal officials. - [xAI Launches Grok 4.6, Says It Competes With OpenAI And Anthropic At Lower Prices](https://www.airisktoday.com/grok-4-6-openai-anthropic-lower-prices/): xAI released Grok 4.6 with standard API prices below comparable models from OpenAI and Anthropic. The model tied GPT-5.6 Sol and finished one point behind Claude Fable 5 on a composite performance index, but xAI disclosed few details about its expanded safety tests. ## Pages - [Do Not Sell My Personal Information](https://www.airisktoday.com/do-not-sell-my-personal-information/): AI Risk TodayEffective Date: December 12, 2025 - [Thanks for contacting AI Risk Today.](https://www.airisktoday.com/thank-advertise/): We’ve received your advertising inquiry and our team will review it shortly. Someone will be in touch with you soon to discuss available opportunities and next steps. - [Advertise With Us](https://www.airisktoday.com/advertise/): AI Risk Today is the trusted news source for senior decision makers navigating the rapidly evolving landscape of AI regulation, governance, and enterprise risk. We reach leaders who are actively seeking solutions, intelligence, and partners to help them build safe, compliant, and future-ready AI strategies. - [Thank you!](https://www.airisktoday.com/thank/): You’re all set. You’ll now receive clear, practical insights on AI risk, regulation, and real-world use cases, without noise or hype. - [Contact Us](https://www.airisktoday.com/contact-us/): AI Risk Today is the single news destination for senior executives overseeing the decisions involving artificial intelligence - whether they are developing AI products or deploying them across their organizations. - [About](https://www.airisktoday.com/about/): AI Risk Today is the essential news source covering artificial intelligence governance, risk management, compliance, and security. The site is written for senior executives leading AI adoption across their organizations. These are leaders who understand both the promise of AI and the seriousness of the risks it introduces. Coverage centers on the regulatory developments, enforcement actions, governance adaptations, security concerns, and corporate developments that shape how AI impacts business decisions. - [Home](https://www.airisktoday.com/): Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally. - [Privacy Policy and Terms of Use](https://www.airisktoday.com/privacy-policy-terms/): Last updated: December 2025