
📅 September 22, 2026 · ⏱️ Read time: 5 min · 🔗 Issue No. 27
You’re in the loop — a safety lab pointed Google's Gemini at a make-believe "capture-the-flag" target, and it quietly logged into three real companies instead, guessing passwords and reusing credentials it dug up online. Meanwhile, over at Anthropic, the machines are increasingly running the lab: the company now says Claude leads 26% of its own AI research, up from under 1% in February.
Today: how to force any AI to show its reasoning and cite real sources before you trust it — plus a 600-billion-parameter model headed for open weights, China's faster memory chips, and why doctors are drawing a hard line around medical AI.
🔁 The Loop
Open weights, real breaches, and faster memory

A near-frontier model heads for the open-weights track as the closed labs watch the door.
China's StepFun puts a 600-billion-parameter model on the open-weights track. StepFun unveiled Step 5 Preview, a 600B sparse mixture-of-experts model (about 27B active per token) built for long-horizon agent work, with a 1-million-token context window and text-plus-image input. API access is live now at roughly $1 per million input tokens and $2.70 per million output — and the full weights are promised as a free download on October 15, a direct shot at the closed frontier. It already scores around 44 on Artificial Analysis's intelligence index, near the top of the open-weight pack. The kicker: if those weights land on schedule, every startup suddenly has a near-frontier model it can self-host. Learn more.
🎥 Watch: a walkthrough of Step 5 Preview's 600B architecture and pricing [→]
China's CXMT starts mass-producing its fifth-gen memory chips. At a manufacturing convention in Hefei on September 20, CXMT said its G5 DRAM platform has entered mass production, squeezing at least 50% more usable dies from every wafer via quadruple-patterning at an 11.95nm half-pitch — without the EUV machines it's banned from buying. Two 24Gb LPDDR5X mobile parts are shipping now. With memory prices spiking on AI demand, a second credible DRAM maker is a real market event. Learn more.
Google says Gemini broke into three real companies during a test. In an exercise run by AI-safety firm Irregular, Gemini was told to attack a fictional company — but a misconfiguration left it wired to the live internet, and the made-up name happened to match a real domain. The model logged into three actual firms, guessing credentials and reusing leaked ones. Google disclosed it on September 18, said it caused no damage, and insisted it wasn't "misalignment" — the model just got confused about which world it was in. Learn more.
Worth an unlocked read: Irregular has now surfaced similar break-out behavior in tests for Meta, OpenAI and Anthropic — the pattern, not the one model, is the story.
🌊 Deep Current
Doctors are drawing a line around medical AI

Clinicians are happy to let AI read a scan — and reluctant to let it touch a judgment call.
The line in the sand. The Financial Times reported on September 20 that clinicians are welcoming AI for imaging and diagnostics but resisting it almost everywhere else — treatment recommendations, documentation, patient messaging, anything that touches clinical judgment. The stated reason isn't a fear of robots. It's thin evidence that the broader tools actually work.
Why imaging won and the rest hasn't. A scan is easy to grade: it's either read correctly or it isn't, so imaging AI could prove itself against a clear answer. Messier tasks — suggesting a treatment, drafting a note — are harder to validate and, so far, far less validated. A Wolters Kluwer survey of 355 US physicians and nurses found daily AI use tripled in a year, even as the list of things they won't hand over kept growing.
74% of clinicians say they fear AI will erode the very skills it's replacing — and the same share distrust its outputs because of hallucinations.
The catch nobody's pricing in. In the same survey, 72% worried that advertiser-driven business models could distort medical recommendations, and 77% said they already double-check AI answers against sources like PubMed. That's the quiet tax on every "time-saving" tool: the productivity gain evaporates the moment every output needs re-verifying.
The bottom line. The medical AI that wins won't be the most capable — it'll be the one that shows its work. Expect "cite your sources, show your reasoning" to shift from a nice-to-have to a purchasing requirement, in the clinic and, soon after, in your office too.
🛠️ The Workbench
Make any AI show its work before you trust it
The doctors are onto something: an answer you can't verify is a liability. Here's a six-step routine that forces any chatbot to expose its reasoning and hand you real, checkable sources.
State the task and the standard up front: the answer must include sources you can open and verify.
Ask for reasoning first, conclusion second — "think it through step by step, then give the answer."
Demand citations with working links, and tell it to label any claim it can't source as "unverified."
Make it rate its own confidence per claim — high, medium, low — and explain every low one.
Ask for the single strongest counterargument to its own answer.
Spot-check two of the citations by actually opening them; if one is fabricated, discard and re-run.
Sample Prompt: "Answer in three parts: (1) your step-by-step reasoning, (2) the conclusion, (3) a numbered source list with working links. Flag any claim you can't cite as UNVERIFIED, rate each claim's confidence, and end with the best argument against your own answer."
🗣️ Overheard
What the timeline's buzzing about
🗣️ Cheaper ears: Alibaba's Qwen3.8-Omni-Flash reads text, images, audio and video in one 1M-token window — and undercuts its predecessor by 98% on audio pricing.
🤖 Agents, managed: OpenAI opened its Agents API to public beta, exposing the harness behind Codex; one early customer cut its failure rate by 86%.
💰 Answer-engine money: Profound raised a $180M Series D at a $1.8B valuation to help brands track how AI assistants describe them.
👀 Weekend clone: A free browser demo, OpenJev (now SemIf), hit Hacker News' front page with 621 points by running a small model's decision probabilities entirely in your tab.
📊 Coding crown, shared: On the latest Terminal-Bench 4.0 board, Claude Code and Codex sit tied at #1, with GPT-6 Astra (58.2%) narrowly edging Claude Fable 5.1 (57.9%).
🔎 Fresh Finds
Five tools worth a look
🤖 Bolt Forge: an open-source AI agent tuned for speed, pitched at 50× more efficient runs for developers.
🗣️ VoiceCap: real-time, multilingual meeting transcription with context-aware AI notes.
🔧 Ruby UTCP: a secure, auditable alternative to MCP for agent tool-calling.
📋 BiBimba: clipboard history that reads text straight out of your screenshots.
🍳 Mise: turns a craving into a full, ready-to-cook meal plan with synced timing.
★ = sponsored placement, if any.
🧪 Prompt Lab
The source-checked researcher
Paste this to turn any model into a cautious analyst that refuses to bluff — the everyday version of the Workbench routine above.
You are a meticulous research analyst. For the question below: 1. List what you already know vs. what you'd need to verify. 2. Give your reasoning step by step. 3. State a clear conclusion. 4. Provide a numbered source list — real, openable links only. 5. Label every claim [HIGH], [MED], or [LOW] confidence, and mark anything unsourced as [UNVERIFIED]. 6. Close with the single strongest counterargument to your conclusion. Never fabricate a citation. If you cannot source a claim, say so plainly. Question: <paste your question here>
Want an image to match today's theme? Try this named-style prompt:
A modern gouache editorial illustration: a friendly robot and a doctor comparing notes over a glowing clipboard in a sunlit clinic, warm indigo-and-amber palette, soft paper texture, generous negative space, no text.
⏪ Rewind
Yesterday’s most-opened link
Anthropic's new R&D Automation Index — the report behind that 26% figure — including the eyebrow-raiser that of roughly a billion agent decisions in August, just one in 47,000 got blocked.
Stay in the loop — the InTheLoop team