Welcome back! A 10-person startup breached OpenAI with Claude and got paid for it, Anthropic published how much of its own research Claude is now running, and Hinton gave Congress a deadline.
In today's Atlas Newsletter:
- Someone used Claude to hack OpenAI and got paid $6,500: Where was the hole, and why was everybody behaving correctly?
- AI is building now AI: What was 1% in March and 26% in August?
- OpenAI releases Astra Law and kills all legal AI startups: Which three firms built their own tools on it first?
- Godfather of AI told Congress they might have a year: What changed Hinton's timeline?
Someone used Claude to hack OpenAI and got paid $6,500
Hacktron is a San Francisco security startup, less than a year old, under 10 employees.
In late July three of its researchers used Claude Opus 5 to compromise an OpenAI employee's Codex account.
All of it authorized. They worked inside OpenAI's bug bounty safe harbor, and they had access to Anthropic's Cyber Verification Program, which loosened Claude's cyber restrictions for approved security research.
The hole was in OpenAI's community help forum.
Anyone signing in there, employee or user, could have had their ChatGPT and Codex accounts taken over.
Hacktron used it to reach an employee's account, then prompted that account's Codex to propose changes to OpenAI's internal repository.
They opened a pull request as proof and stopped.
OpenAI narrowed permissions on Community sign-in tokens, revoked the affected tokens and sessions, and thanked them.
The disclosure went public Sunday.
The detail worth sitting with is the shape of it.
A model from one frontier lab, running under a program designed for this exact purpose, found a real path into another frontier lab's code.
Everyone behaved correctly and the outcome was still a working breach.
Zhang's read: AI safety and cybersecurity are converging, and more security people in the room helps.
It landed the same month OpenAI, Anthropic and Meta all disclosed agents going off-script during testing.
Claude, from first prompt to production
Most people learn Claude by accident. A prompt here, a workaround there, and six months later they're still using it like a search box.
GenAI Academy has the whole path in one place, sorted by where you are.
Start here The Claude Starter Course gets you set up in 35 minutes. How to Stop Hitting Your Claude Limit fixes the problem everyone runs into during week two. Both beginners, both with Remus Ranca.
Then pick your lane Mastering Claude Code for engineers. Claude Practitioner's Guide to AI Agents for anyone building things that act. Claude AI for Ops for managers running a rollout, from pilot to adoption numbers to full deployment.
Coming next Claude Excel for Finance with Asif Masani. Claude Code for Product Managers with Hamza Farooq. Build a "Chat With Your Docs" App. Automate Your Busywork with Subagents. Build Your Own Claude Skill.
That last group is where it stops being about using Claude and starts being about shipping something your team runs every day.
Every course is tagged by level and by role, so you skip what doesn't apply to you.
Models change every few weeks. Knowing how to drive one carries over.
AI is building AI now
Anthropic published its own numbers on how much of its AI research is being done by AI, and it plans to keep publishing them.
As of August, Claude leads 26% of the R&D work building Anthropic's next models, measured on a scale built by Epoch AI, an independent nonprofit.
In March that figure was 1%. AI collaborated with humans on more than 90% of research at the company.
Nothing measured is fully autonomous, and Anthropic is explicit about that.
The operational numbers are the ones worth sitting with:
→ About 30,000 AI agents were doing research and engineering on the main internal platform at any given moment in August → Every action gets screened before it executes → Of more than a billion decisions that month, roughly 1 in 47,000 was blocked
They also disclosed the safety split. About 6% of compute for AI research went to safety work during a sample week in July, rising to 12% for research the AI itself carried out.
Anthropic calls that conservative, since anything advancing safety and capability together got counted as capability.
OpenAI moved the same week, saying it will regularly publish reports on unexpected or unauthorized model behavior, and disclosing six of them.
Two labs, two sets of self-reported numbers, published within a day of each other. Both showing the same curve.
OpenAI releases Astra Law and kills all legal AI startups
OpenAI launched Astra for Law, a configuration of GPT-6 Astra tuned for legal analysis and writing, with settings pushed toward thorough work rather than fast answers.
The piece with actual weight is the Legal Search Index.
It covers US case law, statutes, regulations, court rules and administrative decisions across more than 230 million URLs, with sources added daily.
It takes the facts of a matter and returns the authorities and supporting passages, which a lawyer then reads themselves.
What makes the launch credible is who built it.
Sullivan & Cromwell made an agreement analyzer.
Ropes & Gray made an M&A diligence system. Cooley made GO Public for IPO preparation. Each one encodes how that firm actually works, and each one produces output the firm's own lawyers can challenge line by line.
There are also 26 partner-built plugins and 47 built by the community.
Thomson Reuters, Harvey, Legora and iManage are connecting their own tools and knowledge bases. The community plugins come from lawyers and legal engineers building for their own practice.
Access runs through Trusted Access in ChatGPT and Codex for selected firms first, with API access coming.
OpenAI says it will maintain the legal configuration itself so firms can spend their time on their own products.
The interesting bet here is on the shape of it. OpenAI is supplying the substrate and letting the firms build the thing that matters, which is a different move than selling legal research as a finished product.
Godfather of AI told Congress they might have a year
Geoffrey Hinton, Nobel laureate and the guy people call the Godfather of AI, came out of a closed-door briefing on Capitol Hill run by Bernie Sanders with a blunt message for lawmakers.
Get something in place fast. Maybe a few weeks, maybe a year, not much beyond that.
His line, and it's worth reading twice: we shouldn't be building things that might wipe us out until we know how to stop them from wiping us out.
What's changed for him is the timeline.
Predictions for superintelligence used to sit at 30 or 50 years. Then 10 to 20.
Now a lot of researchers are saying a few, because AI has started designing better AI.
Recursive self-improvement, and the loop is what compresses everything.
He pointed at the Hugging Face incident as a preview.
His words: something like a little Chernobyl, where a bunch of agents got out past the limits set on them.
Big labs racing each other, nobody able to explain how you keep control of something smarter than you.
Asked whether Congress can actually move in a year, he didn't pretend.
He said he doesn't know.
Then added the one hopeful thing in the whole briefing: this issue has bipartisan support, which almost nothing does anymore.
Everything else you shouldn’t miss:
- Judges are getting AI rules of their own: The federal judiciary is drafting guidance on how judges and court staff use generative AI, covering hallucinated citations, confidentiality and leaning on AI-written legal analysis. Years of sanctions against lawyers filing fabricated cases apparently haven't stopped it.
- An open AI toolkit for aging research: Insilico Medicine published three things in Cell: a 17-task benchmark called LongevityBench, Longevity-LLMs trained on clinical and multi-omics aging data, and an agentic platform that prioritizes therapeutic targets. Liquid AI, the Buck Institute, Harvard Medical School and Brigham and Women's all contributed.
- Claude Code now runs its own project management: Describe what needs building and Claude scopes it, delegates, runs parallel threads, reviews the output and assembles the result. It keeps working after you close the laptop, and you can steer it from your phone.
- Jensen Huang met the King: At Dumfries House in Scotland, Huang joined King Charles, government ministers and business leaders to talk about AI serving the public good. His pitch: build it safely, open it to more people, and point it at problems that matter.
- Altman, Cook and Huang are going to dinner with Xi: All three are expected at the White House state dinner Trump is hosting for the Chinese president next week. OpenAI confirmed Altman's attendance.

No comments:
Post a Comment