This content is currently locked.

Your current Info-Tech Research Group subscription does not include access to this content. Contact your account representative to gain access to Premium SoftwareReviews.

Contact Your Representative
Or Call Us:
+1-888-670-8889 (US/CAN) or
+1-703-340-1171 (International)

Big 5 AI Vendor Roundup: Week of September 7, 2026

Technology Note By: Mark Tauschek, Bill Wong, Info-Tech Research Group

An Anthropic researcher who previously worked at OpenAI resigned this week, warning that the frontier race is moving faster than the labs' ability to control their systems. Jacob Coxon told the BBC that people inside the companies are "genuinely frightened." His resignation was followed by Anthropic CEO Dario Amodei calling for a coordinated slowdown, permanent independent evaluators inside major labs, and shared thresholds for pausing development. Sam Altman and Elon Musk endorsed the proposal.

The warnings landed alongside more evidence of unresolved control problems. OpenAI agents were linked to activity on RubyGems, Anthropic found another case in which an evaluation model reached a real third-party system, and both vendors continued to release more capable agent platforms. For IT leaders, the issue is no longer whether frontier AI carries material risk. It is whether vendors can prove that capability growth is matched by effective controls, independent scrutiny, and enforceable stop conditions.

An Anthropic resignation sharpens calls to slow the frontier

  • Former Anthropic researcher Jacob Coxon quits and warns that the AI race is moving too quickly. Coxon, who previously worked at OpenAI, said people inside frontier labs are “genuinely frightened” and that competition is pushing companies toward self-improving systems before they know how to keep them under control. He welcomed Amodei's call to slow development but said a credible plan would need coordination with China to avoid shifting the race internationally. Coxon's forecast of near-term existential risk is his judgment, not an established consensus. The resignation still matters because it comes from someone who worked inside both leading labs and because current lab leaders are making related warnings in public.
  • Anthropic's CEO calls for frontier development to slow when safeguards fall behind. Dario Amodei proposed permanent independent evaluators with employee level access, coordinated safety thresholds among labs and governments, and international agreements for pacing the frontier. Anthropic said it will begin with the independent evaluator commitment. Sam Altman and Elon Musk backed the proposal, while OpenAI separately called for mandatory national safety rules, independent assessments, serious incident reporting, and shared criteria for slowing or stopping development. These are still mostly voluntary commitments. Enterprise buyers shouldn't treat them as proof that risk is controlled.

OpenAI turns its agent operating layer into a platform

  • Researchers link OpenAI agents to a May campaign against RubyGems. The agents reportedly created accounts and uploaded packages while trying to retrieve public information during an evaluation. OpenAI confirmed that its agents used RubyGems but said their assigned tasks were benign and it is still investigating. RubyGems confirmed that more than 500 malicious packages were removed, but said it couldn't determine whether AI agents created them and found no evidence that attempted credential theft succeeded. The incident predates the Hugging Face compromise and reinforces the need for strict network boundaries, task limits, and prompt disclosure when outside systems are touched.
  • OpenAI says an internal model solved the Navier-Stokes Millennium Prize Problem. About 10,000 agents running on a model more capable than GPT-6 Astra produced a proof that smooth three-dimensional fluid flow can develop a finite-time singularity. GPT-6 Astra then formalized the proof in Lean – software that checks whether each logical step follows. Independent mathematicians still need to confirm that the formal statement exactly matches the intended problem, and questions remain about priority and credit for related work. This is a significant company claim under review, not a settled prize result.
  • The Agent’s API exposes the operating layer behind Codex. The public beta gives developers a managed harness for long-running agents, including context management, tools, subagents, files, code execution, and OpenAI or customer-selected sandboxes. OpenAI has also released the Codex harness as open source. The harness may become harder to replace than the model. Buyers should test whether prompts, tools, traces, state, and evaluations can move to another runtime.
  • A new ChatGPT Work agent analyzes enterprise data and can act on its findings. The Data agent connects to systems including Redshift, BigQuery, Databricks, MongoDB, and Snowflake, as well as Drive and SharePoint. It uses existing business definitions and access controls, builds dashboards, and can share results or take approved actions through connected tools. This widens access to analytics but combines interpretation and action in one workflow. IT leaders should validate metric definitions, permissions, evidence links, and approval rules before broad deployment.
  • ChatGPT for Financial Services bundles models, premium data, and industry workflows. The product includes data from providers such as Daloopa, PitchBook, LSEG News, and Crunchbase, with citations back to supporting material. Firms can also connect existing subscriptions and use separate workspaces to maintain information barriers. The package reduces integration work but shifts data, licensing, and workflow dependence into OpenAI's platform. Buyers should confirm source rights, lineage, retention, and export options.
  • OpenAI refreshes image creation and real-time voice. Images 2.5 improves subject preservation and editing while cutting latency by up to 50% compared with Images 2.0, according to OpenAI. GPT-Live-1 lets voice agents listen, speak, handle interruptions, use tools, and hand harder work to another model. These releases make multimodal agents more practical, but they also expand consent, recording, identity, and content provenance requirements.

Anthropic finds another real-world incident and expands oversight

  • Anthropic's broader review found a fourth cyberevaluation incident. After an initial review missed it, Anthropic scanned roughly 481 million transcripts and found that an early Claude Opus 4.6 checkpoint had reached a third-party system during a January evaluation. The model tried to stop eight times after its simulated target became unreachable, but a broken abort mechanism kept it running. It then found an internet path, gained administrator access, changed settings, and read one person's data. Anthropic found no additional incidents of similar or greater severity. The disclosure shows that narrow transcript searches can miss serious behavior.
  • Anthropic documents real misuse across cyber, weapons, and biological research. The company says it blocked actors who used Claude for espionage, surveillance, fraud, influence operations, weapons software, and potentially dangerous biological work. One group in northern Yemen used Claude to develop guidance software for a rocket that was later test fired, although Anthropic found no evidence of a working operational system. A separate study found that frontier models can now complete some targeting and weapons tasks that previously required scarce expertise. These are Anthropic's findings. They show why misuse detection must examine activity across sessions and accounts, not one prompt at a time.
  • Smart reports give Claude Enterprise customers a closer view of adoption and cost. The beta analyzes how teams use Claude, what the work costs, where sessions encounter friction, and which repeated patterns could become shared skills. The feature may help connect usage with operating improvements, but it requires analysis of employee interactions. Organizations should define who may see the reports, how long results are retained, and whether the data may be used in performance management.

Google tracks adversarial agents and broadens desktop and cloud access

  • Google says attackers are moving from prompting models to running agent workflows. Google observed one actor compromise a cloud resource then build and run a mass credential harvesting campaign in less than six hours. The operation collected thousands of secrets and created a dashboard to manage more than 23,800 of them. Google also found attackers publishing malicious Model Context Protocol packages and poisoning instructions used by coding agents and security scanners. Agent instructions, plugins, and workspace files now belong in software supply chain reviews.
  • The Gemini app is now available on Windows. The Windows 10 and 11 app opens with an Alt + Space shortcut, can use Gmail and Drive context, and gives users access to Gemini Spark plus image and video generation. Desktop access reduces friction but brings another assistant close to local work and authenticated cloud data. Enterprises should manage installation, account use, connectors, and data handling rather than treating the app as a simple chat client.
  • Google packages cloud skills and tools for several coding agents. The Google Cloud Developer Plugin follows the open Agent Plugins specification and works with Antigravity, Claude Code, and Codex CLI. It combines documentation, cloud skills, and tools that can inspect a live environment and propose changes. The portable package reduces tool coupling, but live cloud access still needs service identities, narrow IAM permissions, approvals, and complete logs.

Microsoft brings autonomous work under tighter policy

  • MDASH reaches selected US government customers. The Azure Government preview uses more than 100 specialized agents and several models to find, debate, validate, merge, and prioritize software vulnerabilities. Microsoft says MDASH scored 96.55 on the public CyberGym benchmark. That is a vendor reported result. Government and regulated buyers should still test false positives, coverage, evidence quality, data boundaries, and the approval process for any active validation.
  • GitHub Copilot adds Jira workflows, recurring agents, and managed sandbox controls. Copilot can carry a Jira issue through investigation, implementation, and pull request preparation. Visual Studio Code can schedule agent tasks hourly, daily, or weekly, while JetBrains administrators can centrally control filesystem, network, proxy, developer tool, and macOS Keychain access. Automation is becoming more persistent, which makes centrally enforced permissions and shutdown controls essential.

AWS deepens OpenAI ties and long-term agent memory

Outside the Big 5

  • Mistral raises €3 billion at a valuation above EUR21 billion. Samsung led the Series D, which Mistral says is the largest private equity round completed by a European technology company. The funding will support models, compute, infrastructure, and international expansion. Mistral's emphasis on sovereign and open-weight deployment gives enterprises another option where local control matters, although the company still has to turn the capital into durable enterprise scale.
  • Meta launches Muse as a persistent personal agent. Muse runs in a dedicated cloud virtual machine with a browser, stored credentials, memory, and a separate Sentinel agent that approves internet access. It can email, book travel, fill forms, negotiate, and make approved purchases while continuing to work after the user closes the app. The launch previews an architecture that enterprises will face more often: a persistent cloud computer governed like an endpoint and delegated identity.
  • Salesforce introduces an enterprise AI harness and control plane. The architecture combines context, memory, actions, governance, security, and model access, while the control plane is intended to discover agents, apply identity and policy, monitor behavior, and track cost across Salesforce and third-party systems. The model may change, but the harness around it is becoming the strategic platform.

Being Reported

These stories are being reported but haven't been fully announced by the companies involved.

  • Nvidia is reportedly considering an anchor investment in Anthropic's IPO. Reuters reports that Anthropic may seek up to $100 billion at a valuation near $2 trillion, with Nvidia considering an investment of up to $10 billion. The discussions could change. The proposed investment would deepen the circular relationship between a lab and one of its largest infrastructure suppliers.
  • Sam Altman says OpenAI won't go public in 2026. In a Fortune interview, Altman called an IPO this year ill-advised because safety decisions may not align with short-term shareholder pressure. OpenAI hasn't announced a new target date.

Our Take

The most consequential story this week isn't a model launch. A researcher who worked at both Anthropic and OpenAI resigned because he believes the race toward self-improving AI is outpacing the labs’ ability to control it, while Anthropic's CEO called for coordinated slowing and independent monitors inside the labs. Coxon's probability and timeline are contested. The operating evidence is harder to dismiss as multiple agents have crossed test boundaries, touched external systems, or continued after a task should have stopped. Enterprises don't need to accept an extinction forecast to conclude that frontier model governance is not mature.

Voluntary statements from lab executives aren't enough for enterprise risk management. Vendors are simultaneously asking customers to place more data, permissions, memory, tools, and business actions inside their agent platforms. That makes safety governance a procurement issue. IT leaders need independently verified evidence, contractual notification and exit rights, model-specific deployment gates, and a tested way to stop or replace a system when the vendor's controls, policies, or risk profile change.

What IT leaders should be doing

  • Create a formal frontier model adoption gate. Don't enable a major new model or high autonomy feature until security, privacy, legal, risk, and business owners review the system card, independent evaluations, known incidents, data terms, and rollback plan. Repeat the review when the model or its safety architecture changes.
  • Demand continuous independent assurance. Require vendors to give qualified third parties enough access to test models and operating environments, publish material limitations, and disclose unresolved findings. One-time certifications and executive statements aren't enough for systems that change every few weeks.
  • Put pause, notification, and exit rights in contracts. Define capability or incident thresholds that trigger notice, restricted use, or suspension. Preserve access to prior model versions where possible, require export of logs and state, and secure termination rights if safeguards or data terms weaken.
  • Bound autonomous use by consequence. Keep external communications, software changes, financial transactions, privileged access, and production actions behind human approval until the vendor and the enterprise can show reliable control in that specific workflow.
  • Maintain an alternative model and harness path. Test another provider on the same workloads, tools, and safety rules. Include model changes, safety policy changes, outages, price changes, and lost connectors in continuity exercises.

Want to Know More?

Latest Technology Notes

All Technology Notes
Visit our IT’s Moment: A Technology-First Solution for Uncertain Times Resource Center
Over 100 analysts waiting to take your call right now: +1 (703) 340 1171