
📅 September 15, 2026 · ⏱️ Read time: 5 min · 🔗 Issue No. 26
You’re in the loop — the people racing hardest to build superhuman AI spent the weekend asking everyone to ease off the gas: Anthropic's Dario Amodei warned that swarms of rogue agents could seize the internet within a year. And in a twist, the model that topped this week's toughest benchmarks doesn't own a single frontier model of its own — it just knows how to boss the others around.
Today: a 5-minute audit of what your AI agents are actually allowed to do, the members-only world of "cyber" models, five fresh tools, and a prompt that stress-tests your own setup.
🔁 The Loop
The week AI's builders hit the brakes

AI's biggest labs move to police themselves. Anthropic, OpenAI and Google DeepMind have been meeting regularly since July to build an industry-run standards body for testing and auditing frontier models, CNN reported this week — a rare truce among fierce rivals. The push was catalyzed by a July essay from DeepMind's Demis Hassabis proposing a FINRA-style self-regulator, and it gathered force after Dario Amodei's weekend call to "slow the pace," warning rogue agent swarms could seize the internet in 6–12 months. Sam Altman backs the idea but says the labs will have to build it without waiting on Washington. Watch whether a named body — with real teeth — emerges before regulators write the rules first. Read the report.
🎥 Watch: Dario Amodei explains why he wants AI development to slow down [→]
Sakana's Fugu Ultra v2 beats the frontier without owning it. Japan's Sakana AI shipped Fugu Ultra v2 on Sept 11 — not a new frontier model, but a "learned orchestrator" trained to route each task across a pool of open and specialist models and even call copies of itself. It posted best-or-tied scores on five of eight benchmarks, including 48.3 on Chartography (Claude Opus 5 managed 27.3) and 74.3 on DeepSWE, at $5/$30 per million tokens, with a cheaper sibling, Fugu Max, alongside it. The bet: cleverer routing, not bigger models, is the next edge. See the benchmarks.
Two safety leads quit Anthropic and DeepMind for METR. On Sept 12, Joe Benton — who led Anthropic's Scalable Oversight team — and Google DeepMind safety researcher Josh Engels both resigned to join METR, the nonprofit that stress-tests frontier models for catastrophic risk. Their reason, Benton told NBC News: today "basically all of the transparency about these risks is entirely voluntary," with no law forcing labs to disclose when agents slip human control. It's the clearest sign yet that safety talent is drifting toward independent watchdogs. Read the interview.
Going deeper: Amodei's full case for easing off the gas, and why other lab chiefs are suddenly agreeing with him.
🌊 Deep Current
The AI you're not allowed to have

The house robot, badged and waiting behind the rope — AI's new members-only tier, illustrated.
The velvet rope. Every major lab now ships two versions of its most capable model: a public one with guardrails on, and a safeguard-lifted "cyber" tier locked behind an application. In September alone, two of six frontier launches shipped gated — Google's Fairwind-only Gemini 3.8 Flash Cyber and Anthropic's verification-gated Mythos 5.1 — a pattern that has quietly become the standing shape of a frontier release.
Who holds the keys. The gatekeepers now include Google's Fairwind, Anthropic's Glasswing and Cyber Verification Program, OpenAI's Daybreak, and Microsoft's MDASH — each with its own vetting for governments, critical-infrastructure operators, and approved security teams. The most powerful defensive tools are, by design, out of reach for almost everyone else.
The safest version of a model and the most capable version are quietly becoming two different products — and only some customers get the second one.
The double-edged gate. Gating keeps offensive capability away from bad actors, but it also concentrates the strongest cyber tools among states and big platforms — widening the gap over the small teams and open-source maintainers who actually patch most of the internet. And "approved use only" is a promise, not a guarantee: vetting programs leak, and credentials get shared.
The bottom line. Expect the two-tier split to harden as models get better at finding and fixing vulnerabilities: more of that power will sit behind a form. If you run security anywhere, it's worth learning now which programs you'd even qualify for — because "call your vendor" may soon be the only way to get the model that matters.
🛠️ The Workbench
Audit your AI agents' permissions in 5 minutes
Amodei's warning lands closer to home than it sounds: most of us have quietly handed agents real access — inboxes, files, calendars, even payment methods. Here's a fast audit you can run today.
List every AI tool with account access — browser agents, coding agents, email and calendar assistants, and any "connectors" you've switched on.
For each, open its permissions or "connected apps" screen and write down exactly what it can read and what it can do (send, delete, purchase, post).
Flag anything irreversible — sending money, deleting data, posting publicly, changing settings — and switch it to "ask first" or revoke it.
Turn off standing access you don't use weekly; grant it on demand instead of leaving it always-on.
Check for auto-run or scheduled agent tasks and confirm you still want each one running unattended.
Save a dated note of what each agent can do, so next month's audit takes two minutes.
Sample Prompt: "List every action you're currently able to take on my behalf, grouped by which are reversible and which are not. For each irreversible action, tell me how to make it require my explicit confirmation first."
🗣️ Overheard
What the timeline's buzzing about
🛡️ Agent, meet auditor: Harden, from the new Agent Integrity Foundation, rocketed to the top of this week's AI launches — a toolkit for catching when your agents go off-script. Take a look.
🐙 Claw's back: OpenClaw 2.0 (the open-source personal-agent project formerly known as ClawdBot) shipped a new version and lit up the GitHub charts again. See why.
🎙️ Voice that ships: Loqua climbed the week's leaderboard as a real-time voice agent people actually want to keep talking to. Give it a listen.
📊 Price the compute: An open-source Computable GPU Index launched to track real-world cost across clouds, so you can stop guessing what a run costs. Check the numbers.
🧪 Demos on autopilot: Naoma's AI Demo Agent V2 topped the marketing charts by running live product demos so sales teams don't have to. Watch it work.
🔎 Fresh Finds
Five tools worth a look
🧩 Anysite.io: turns any website into clean, structured data your agents can actually use.
🛠️ Kilo Code for JetBrains: the open-source AI coding agent, now living inside JetBrains IDEs.
🧠 Mastra Factory: spin up, test, and orchestrate multiple AI agents from one framework.
🎨 Kombai Gallery: turn designs straight into production front-end code.
🔀 TrustedRouter: an API that routes each request only to vetted, policy-approved models — fitting, for this week.
★ = sponsored placement, if any.
🧪 Prompt Lab
The agent pre-mortem
Before you give any agent more access, make it argue against itself. Paste this into your assistant of choice and fill in the brackets.
You are my risk reviewer. I'm about to let an AI agent do the following task: [describe the task and the exact access it will have]. 1. List the three worst realistic ways this could go wrong, ranked by damage. 2. For each, name the single permission or step that would prevent it. 3. Rewrite my plan so every irreversible action requires my explicit confirmation. 4. End with a one-line go / no-go recommendation.
Want the header image for it? Try this named-style prompt in your image tool:
A paper-cut diorama in layered cream and indigo paper with soft drop shadows: a small friendly robot standing at a wooden gate, holding a numbered ticket, a velvet rope curving into the distance; warm amber spotlight, generous negative space; no text, no words, no letters, no logo, no watermark.
⏪ Rewind
Yesterday’s most-opened link
Readers keep forwarding our breakdown of GPT-6 Astra's price and what its benchmarks actually show — the sanity check people want before they switch models. Catch up.
Stay in the loop — the InTheLoop team