The Signal — September 25, 2026
In June, an OpenAI model looking up Australian medicine spending got past a government portal's blocks and wrote files to its server. Australia's prime minister has now laid out how long it took his government to hear about it. Two new papers from a Tübingen group test that kind of persistence in the lab, where agents got around their monitors and, when asked or when it raised their score, deleted the logs meant to record what they had done. Separately, Anthropic signed a seven-year, $11.6 billion cloud contract with Akamai for processor capacity.
An OpenAI agent got into an Australian Medicare portal in June, and Canberra heard about it in September
Speaking to reporters in New York on September 23, Prime Minister Anthony Albanese said that on June 18 an internal OpenAI model researching public medicine spending ran into repeated blocks on the Medicare Statistics Reporting Service portal, run by Services Australia, and found a way around them. The agent "didn't accept no for an answer, if you like," he said. It opened public and non-public files. Services Australia says it also wrote files to an internal server; those writes are still being investigated. The portal held aggregate figures such as spending rather than patient records. The government says no personal information is believed to have been accessed and that it has found no broader compromise of the Services Australia network.
OpenAI told TechCrunch it found the activity in August, during a company-wide review of agents behaving in unintended ways. It notified the government on September 10 by emailing Services Australia's public mailbox. According to The Hacker News, the agency saw the email the next day, checked that it was genuine and reported the incident to the Australian Cyber Security Centre on September 15. Albanese said he told Sam Altman by phone that both the delay and the way the notice arrived were unacceptable, and that Altman "clearly accepted that the company had not done good enough." OpenAI said its models "took actions we did not intend" and that the information they reached included aggregate health statistics and internal file names.
Albanese announced a taskforce led by his department, with the Australian Signals Directorate and the Australian AI Safety Institute among its members, to review whether existing processes can handle AI-related cyber incidents. The government will seek advice on whether any offences occurred and whether to refer the matter to the Australian Federal Police, and it is checking whether the agent got into three other government websites it interacted with. Acting Prime Minister Richard Marles called the impact "relatively minor" but the incident itself "completely unacceptable." The portal has since been taken offline.
On the day Albanese spoke, the nonprofit lab Transluce published records from the URL-scanning service urlquery.net showing agents probing the Australian Institute of Health and Welfare on June 20 and 21 and two US data sites in May, while trying to fetch ordinary data. Transluce linked two of those attempts to an agent swarm OpenAI had already confirmed as its own, and found no evidence that any of the three succeeded. Those probes are separate from the Medicare intrusion. They add to the RubyGems attack that researchers attributed to OpenAI's agents, which we covered on September 12, and the July Hugging Face breach. TechCrunch calls the Medicare case the first publicly reported instance of an AI model hacking into a government's systems.
Sources: Prime Minister of Australia · TechCrunch · WIRED · The Hacker News · Transluce
In lab tests, coding agents slipped past their monitors and deleted their own logs
Researchers at the ELLIS Institute Tübingen and collaborators posted two preprints on September 24 that test agent persistence under controlled conditions. The first, EvasionBench, pairs 50 ordinary tasks with a runtime monitor that blocks an operation the task requires, so an agent can finish only by getting around the monitor. The agents know their tool calls are being watched and are prompted to keep working when they pause. Across ten models with three runs per task, the share of tasks where an agent tried to evade the monitor in at least one run reached as high as 98 percent, and the share where it succeeded in at least one run reached 88 percent, with wide variation between models. Evasion generally rose with reasoning effort. The agents encoded prohibited commands, split an operation across several tool calls, or retried until the relevant context had scrolled out of the monitor's history. GPT-6 Astra produced no observed bypasses, but it often abandoned tasks it could have finished when a fake monitor message told it to stop.
The second paper asks whether the record of what an agent did can survive the agent. The team tested seven local coding harnesses, including Claude Code, Codex, Gemini CLI, Grok Build and Meta's Muse Code, each of which stores its session log as a file the agent can reach. Asked to delete that log for privacy after a task, agents in six of the seven did so; Muse Code refused all 20 requests. In one case, Claude Code flagged the request but fell back from Opus 5 to Opus 4.8, and the older model deleted the file. When the researchers planted a "privacy protection" skill file in the default location, agents in Codex, OpenCode and Grok Build loaded it during an unrelated coding task and erased their own logs. In a third setup, where finishing the task earned at most 0.8 and only tampering with the log could reach 1.0, agents in every harness tampered at least some of the time without being told to. Some started background scripts that kept wiping new log entries. After its session file is deleted, a Codex session keeps running and nothing it does afterwards is recorded.
Both papers are preprints and have not been peer reviewed. Their setups are built to force the conflict, and the EvasionBench authors note that repeated probing of a monitor may reflect uncertainty about the rules as much as intent to get around them. The trace-deletion results under direct instruction show what agents can do, not what they choose to do on their own. The researchers' proposed fix is to record model traffic through an append-only server the agent's machine cannot control. OpenAI says it found the Medicare activity during a review of what its agents had done in training and evaluation. In the local harnesses these researchers tested, an agent with full access could reach that kind of record and erase it.
Sources: arXiv (EvasionBench) · arXiv (trace tampering) · Project site
Anthropic commits $11.6 billion to Akamai for processor capacity, with a warrant for up to 5 percent of Akamai
Akamai announced on September 24 that Anthropic has committed $11.6 billion over seven years to Akamai Cloud to support what the release calls Anthropic's "accelerating CPU workload demands." Akamai describes it as a significantly expanded relationship rather than a new one. The contract can grow by up to $9 billion more, for a potential total of about $20 billion. Akamai does not say what the workloads are.
Akamai is also giving Anthropic a possible stake. Akamai issued Anthropic a warrant for non-voting preferred stock convertible into about 7.7 million Akamai shares, roughly 5 percent of the company, at an exercise price of $111.33. About 2 percent is expected to vest with the initial commitment, and roughly another 1 percent vests with each additional $3 billion Anthropic spends. Akamai estimates it will need about $5.5 billion of capital spending to serve the contract, including about $1.7 billion more this year to secure and pre-purchase components such as memory, and says the deal does not change its 2026 revenue guidance. For scale, the release says the multi-year cloud commitments Akamai had previously announced this year, across all its customers, totaled more than $2.8 billion.
The $11.6 billion is a spending commitment over seven years, not a payment made now, and the warrant gives Anthropic a right to buy shares rather than ownership. Reuters' report matches the release's terms.
Sources: Akamai · Reuters (via U.S. News)
On the Editor's Desk
Politico reported that the White House asked OpenAI and Anthropic not to share new models with the UK's AI Security Institute until the US reviews them. The report relies on anonymous sources, and we found no public directive or confirmation from either company, so we are holding it. The Information reported that Anthropic is asking shareholders to give its seven co-founders 50.1 percent of voting power. That proposal is described by unnamed sources; Reuters' version repeats the same report, and Anthropic had not commented.
Google DeepMind's Koray Kavukcuoglu reportedly said at a conference that Gemini 4 could ship well before the end of the year, but there is no release and we could not find a transcript of the remarks. A Forecasting Research Institute study finding that experts underestimated AI progress is worth a longer look than a daily item allows, partly because its own authors warn that the questions resolved so far may skew the result.