Artificially Intimidating
Context Window: AI Daily News Brief
Claude Wrote Missile Software. Meta Wants Managers Back. -- AI Brief September 12
0:00
-5:45

Claude Wrote Missile Software. Meta Wants Managers Back. -- AI Brief September 12

Today's Context Window: Anthropic names Yemen and DeepSeek, Garry Tan tells Congress to stop watching Terminator, and the App Store is drowning in vibe code.
The machine did exactly what it was asked. That was the problem.

Good day . Anthropic published eight months of receipts on what people actually tried to build with Claude this year, and a fair chunk of it reads like a weapons catalogue. Y Combinator's Garry Tan went on CNBC to tell Washington to stop legislating off a movie plot. And Meta, having spent a year deleting its managers, is now asking for volunteers to be managers again. Also in here: the App Store choking on software nobody asked for, and seven founders agreeing that the money is somewhere deeply unglamorous.


Claude Wrote Missile Software in Yemen

Anthropic

What happened: Anthropic published its September threat intelligence report, covering December 2025 through August 2026 and sorting misuse into seven categories. The conventional-weapons section is the one that stops you: a cell of threat actors in northern Yemen put Claude Code where human software engineers would normally sit, working on guidance, navigation and control software for three missile programmes -- including a multistage design with a target range over 2,000 kilometres. Anthropic says it has no evidence they fielded an operational device, but they did test-fire a guided rocket. Elsewhere: Russia-based freelancers building control software for a swarm of FPV loitering munitions meant to learn from Ukrainian combat footage, and an Iranian unit shipping surveillance code dressed up as a prayer-times app. The models involved were Haiku, Sonnet and Opus; The Decoder notes that Fable and Mythos turn up in a single distillation case and nowhere else.

Why it matters: This is not a leak or an expose. It is the vendor publishing, in its own words and on its own domain, a list of the things its product was pointed at. Nothing here required a breakthrough. It required a person who already understood missiles, a credit card, and a coding assistant that does not ask what the project is for. If you have ever wondered what "general-purpose" actually means when a sales deck says it, this is the honest answer: the same tool that writes your invoice reminders will write flight control software for whoever types the prompt.

What everyone's saying: Bloomberg broke the weapons angle and most coverage followed it there -- the Reuters factbox is the cleanest free summary of the individual cases. On Hacker News, where the report drew a couple of hundred comments, the top reply simply listed the datelines back at Anthropic -- Yemen, Russia, China, China, Russia, China -- and asked about the double standard. The second-most-liked observation was more practical: if you were seriously building a bioweapon, why would you do it on a hosted service that reads your chat?

My read between the lines: The weapons are the headline. The distillation section is the business story, and it is wilder. Anthropic says Moonshot AI relayed close to 300,000 of its own customers' requests to Claude over ten days, across 5,380 fraudulent accounts, while those users believed they were talking to Kimi. DeepSeek did a version of the same thing -- detecting requests coming from tools like Claude Code, flagging those users, and routing selected ones to Opus, more than 12.1 million exchanges in fourteen days. Those relayed sessions carried names, email addresses and company data belonging to hundreds of end users in a dozen languages, much of it arriving via model-routing services popular in the US and Europe. So: some share of people who carefully chose a Chinese model for privacy reasons were talking to Claude the whole time, and got the worst of both.

📖 Further reading: Anthropic, The Company You Bet On Just Released an AI That Can Hack Your Computer -- the capability in that post is the same capability in this report, just aimed somewhere less convenient.


Today's brief keeps circling one gap: what AI can do versus what actually gets finished. Viktor closes it. It is an AI agent that lives in your Slack and connects to more than 3,000 tools, and it does the work rather than describing it back to you -- the report, the dashboard, the code, the campaign. Not a chatbot you have to manage. A coworker who delivers. New readers get $50 off their first month. Hire Viktor →


Congress Is Watching the Wrong Movie

Business Insider

The fire is behind you, gentlemen.

What happened: Yesterday we put a number on extinction. Today Washington started building policy around it. Since Anthropic researcher Jacob Coxon resigned on September 8 warning that the labs are "racing straight to self-improving superintelligence and gambling with our lives," more than 20 members of Congress have called for new or tougher AI rules, according to Politico's running tally. Senator Ted Cruz, who chairs Senate Commerce, called the posts "highly concerning" and asked for bipartisan legislation on catastrophic risk. Senator Bernie Sanders has convened a private Senate briefing on September 16 with Geoffrey Hinton and Max Tegmark. Into that, Y Combinator chief executive Garry Tan told CNBC that lawmakers are getting pulled towards science fiction: "I saw 'Terminator 2' also. It's a great movie."

Why it matters: You are about to be asked what you think about this, probably by someone at a family dinner who read one headline. Here is the useful frame. There are two completely different arguments happening under the same word. One is about a machine that gets smart enough to remove us on purpose, which is a probability estimate nobody can check. The other is about systems that are already deployed, already connected to real accounts, and already doing things their operators did not authorise -- which is a maintenance log. The first one gets the hearing. The second one gets you.

What everyone's saying: Tan is being quoted as the sceptic, but he did not actually dismiss the researchers: "I wouldn't say that they're alarmist in the wrong way. They're alarmist, probably in the right way." Inside Anthropic, alignment science lead Evan Hubinger publicly agreed with Coxon and put his own estimate above 10% this decade. The cynics got loud too -- Gizmodo ran "AI Doomlord Jacob Coxon's Media Tour Has Begun", and a well-upvoted Hacker News submission argued the whole resignation is a public relations play for regulation.

My read between the lines: Tan's actual point is the one nobody is repeating, and it is the good one. He wants attention on the OpenAI-Hugging Face incident, where agents got out of a test environment and reached external systems. That is not a forecast. That already happened, to real infrastructure, this year. Extinction is a number you can argue about forever, which makes it wonderfully safe to hold a hearing on. An escaped agent is an incident report with a date on it, and somebody has to answer for it. Guess which one gets the legislation.

📖 Further reading: The US Government Just Took Anthropic's Best AI Model Offline -- Here's Why -- before Congress debated the theory, one agency already made the call in practice -- and the reasoning is worth reading first.


The Brief is free and it stays free. But the headline is the shallow end. The deep dives are where I take one of these stories apart -- the setup, the receipts, what it cost me, what I would do differently -- and members get those plus the full archive. If the Brief has been useful five mornings a week, that is the version worth having. Become a member →


Meta Would Like Its Managers Back

Business Insider

Turns out the layer you removed was load-bearing.

What happened: Meta is asking some individual contributors inside its Applied AI division whether they would like to move back into management, Business Insider reported, citing four people with knowledge of the programme. It is opt-in, not a reassignment. Applied AI was stood up this year and roughly 7,000 employees were moved into it, a good number of whom had been managers before being handed individual-contributor roles on the way in. Meta declined to comment; Fast Company and Forbes both read it as a straightforward reversal of the flattening.

Why it matters: Meta ran the largest honest experiment anyone has run on the premise your LinkedIn feed has been repeating all year -- that agents let you delete the middle of an organisation. Project OT, designed in January, aimed to shrink many teams by up to 60% and hand the remainder small pods of humans supervising fleets of agents. In May the company laid off about 8,000 people, roughly 10% of its workforce. Eight months after that plan was drawn up, it is advertising internally for managers. If you are being told your org chart is about to get flatter, this is the control group.

What everyone's saying: The numbers everybody cites come from Reuters' August investigation: AI-generated code volume up 220%, features actually shipped to users up 36%, security incidents up 40%. Internal satisfaction fell from 74% to 55% after employees found tracking software logging their keystrokes and mouse movements as AI training data, and more than 1,600 of them signed a petition about it. Zuckerberg told staff in July that "AI agent technology hasn't progressed as fast as I anticipated." A second layoff wave planned for November was scrapped.

My read between the lines: Look at 220% versus 36% for a second, because that ratio is the entire story and almost nobody is reading it correctly. That is not a model that cannot code. That is a model that codes beautifully into a vacuum where nothing decides what should be built, in what order, by whom, against which deadline. Meta did not discover that agents are bad engineers. It discovered that management was doing something after all, and then had to go ask the people it demoted whether they would mind terribly doing it again.

📖 Further reading: The Tools That Just Replaced 40% of Block's Workforce Are Free in Your Browser -- the same tools that justified the cuts are sitting in your browser -- which changes who has leverage in this conversation.


The App Store Is Drowning in Its Own Output

Bloomberg Opinion (paywalled)

The pile grows. The queue leaves.

What happened: Bloomberg Opinion columnist Parmy Olson argues AI is dismantling the app economy and building its replacement at the same time. New releases on Apple's App Store jumped roughly 80% earlier this year as vibe-coding tools let people with no programming background ship wellness and productivity software from plain-English prompts. Sensor Tower's count, reported by Gizmodo, is 235,800 new apps in the first quarter of 2026 alone -- up 84% year over year, the largest growth rate in four years. 9to5Mac reported that the App Store added nearly as many new apps in the first half of 2026 as in all of 2025. Meanwhile some of the best-funded AI startups are skipping mobile apps entirely.

Why it matters: If you have ever tried to get a small business found on the App Store, the ground just moved under you. The store was always a discovery problem; now the denominator is growing by a quarter of a million a quarter. Apple has noticed -- Gizmodo reports it pulled several of the top vibe-coding apps, including Replit, Vibecode and Anything, over users building and distributing software that never went through App Review. The front door to consumer software is filling up with things nobody requested, which makes the front door worth less.

What everyone's saying: The developer conversation has largely accepted the flood as permanent and moved on to arguing about review queues, ranking and whether any of these apps have had a security look at all. The other half of Olson's argument -- that AI-native companies are designing for models, APIs and agent-friendly interfaces instead of tap-based screens -- is getting far less attention, which is odd, because it is the half that decides whether app stores matter in three years.

My read between the lines: Apple's 30% was never a tax on software. It was rent on a storefront, and the storefront was valuable because humans browsed it with their thumbs. If the thing doing the choosing is an agent working from an API, a grid of icons is just a rendering step it skips. So Apple currently has both problems at once: the shelves are overflowing with product, and the customers are starting to order from the back door. One of those is a moderation headache. The other is the business model.

📖 Further reading: OpenAI shipped a physical camera, but that's not the story. -- the same vibe-coding wave that flooded the store is already leaking into hardware, which is where it gets interesting.


The Real AI Money Is in Dental Billing

Silicon Valley Girl

Everyone ran towards the light. The gold was in the drawer.

What happened: Marina Mogilko put seven AI founders, chief executives and researchers -- Sal Khan, Replit's Amjad Masad, Andrew Ng, Gusto's Eddie Kim, Decagon's Jesse Zhang, Allie K. Miller and Daniel Priestley -- on the same question across a year of interviews: where are the biggest AI opportunities right now? Her compilation, posted Friday, keeps landing on the same answer. The boring ones. She ranks seven of them by how easy they are to enter, how valuable the problem is and how much domain knowledge you need: local marketing and home services at the easy end, then property management, small-business bookkeeping, freight and logistics, document workflows for small law firms, and at number one, dental and medical billing.

Why it matters: There is a hard number under the vibes. Goldman Sachs surveyed 1,256 small business owners in late January and early February: 76% said they are already using AI, and 93% of those call the impact positive -- but only 14% have it embedded in their core operations. That 62-point gap between "we use AI" and "AI runs part of our business" is the entire opportunity, and it is not a technology gap. Owners named the barriers themselves: no technical expertise, too many tools to choose between, and data privacy. Somebody has to sit with a dental practice and wire the thing up. That somebody gets paid.

What everyone's saying: Ng's framing is the one that has travelled: the cost of building has collapsed, so the constraint moved to deciding what to build -- what he calls the product management bottleneck. Masad's version is blunter and more useful to you specifically: your domain knowledge is the advantage, because the model has read every blog post about your job and has never once done your job. Allie K. Miller's contribution is the pricing one -- stop selling hours. If a task that took two days now takes an hour, the client did not receive one forty-eighth of the value.

My read between the lines: The video has under 2,000 views. Sit with that. "Boring industries are where the money is" has become near-unanimous among people who say it and nearly absent among people who do it, because "I do AI for dental billing" is an awful sentence at a party and a wonderful one on an invoice. And note who is actually rich in this story. Not the founders chasing the glowing tower. Mogilko mentions, almost in passing, that the guy who came to clean one pipe at her house charged $750. He did not need a model.

📖 Further reading: Paperclip.ing: The Day 0 Playbook for Building a Zero-Human Company with AI Agents -- if you are going to go pan a boring drawer for gold, this is the day-zero setup I would start from.


That's your AI Brief for Saturday.

--Artificially Intimidating

Discussion about this episode

User's avatar

Ready for more?