The Signal — September 9, 2026
OpenAI published a proof of a ninety-year-old fluid dynamics problem yesterday, produced by roughly ten thousand agents working in parallel, and by that evening the mathematician who had been quietly attacking the same problem had posted his own account of the week leading up to the announcement.
OpenAI says an internal model resolved Navier-Stokes, and the mathematician working the same problem published what happened next
The Navier-Stokes equations describe how fluids move, and the open question named by the Clay Mathematics Institute in 2000 is whether smooth three-dimensional flow can break down into infinite speed in finite time. OpenAI says its system produced a proof that it can, along with a formalization in Lean, and the company published both. The result establishes statements C and D in the official Clay formulation, the branch where a smooth external force is applied to the fluid, rather than the unforced A and B versions most people picture when they hear the problem named. OpenAI says it does not intend to claim the prize.
OpenAI used an internal model it describes as more capable than GPT-6 Astra, whose training started on August 28 and is still running. It ran coordinating groups of agents with access to a cached copy of the internet and a code sandbox, and the group that produced the Navier-Stokes resolution involved on the order of ten thousand concurrent agents. Different groups were seeded with different variants of the problem statement. The agents first resolved the unforced Euler regularity question, about a hundred of them over roughly fifty hours, and OpenAI then pulled compute off the other Millennium problems, fed the Euler result back in as a prompt, and used Codex to consolidate insights across groups. The resolution arrived 88 hours after the first agents launched, with another 17 hours of Lean verification through Astra. Across every problem attempted, the agents exchanged 4.9 million messages and produced about 300 billion output tokens.
Tristan Buckmaster, a mathematics professor at NYU's Courant Institute, published a statement the same day. He and Levent Alpöge, who works at Anthropic, had been working on the same family of problems as a personal collaboration with no institutional agreement behind it, building on a program opened by Diego Córdoba and Luis Martínez-Zoroa. They used Claude, Codex with GPT-5.6 Sol, and later Astra, obtained smooth-forcing blowup for Boussinesq and incompressible Euler on August 15, and finished the Lean verification a week later. Buckmaster writes that he emailed a mathematician at OpenAI on September 3, after a rumor started circulating that Anthropic had resolved a major open problem, to say that he and Alpöge would be posting shortly.
He then describes a call in which the account he had been given kept changing. He says he was told the internal model had simply been handed the problem statement with very little human input, and that over the course of the conversation it emerged that a team had been working on it, that easier problems including Euler had been tried first, and that the prompt he had been shown was itself written by prompting Codex. He asked when OpenAI's first prompt had been sent, did not get a direct answer for some time, and says it was eventually agreed that it had gone out in the past few days, after information about his work reached OpenAI. He asked whether the model had been trained on or had access to his Codex sessions, into which he had been putting drafts for the entire project, and says he was told the model does not look up user data. He asked again about training and says he did not get an answer. He describes declining two proposed release arrangements and being asked, "Why would you ruin your career?" He is explicit that he has not seen OpenAI's proof, does not know what the model did, does not know whether his data was used, and is not accusing anyone of anything.
OpenAI's post addresses the overlap directly. It says the effort began September 1 after hearing the rumor, that the company later reached out to offer a concurrent release and recognize priority, that it congratulates Buckmaster and Alpöge on the forced Euler result, and that neither its researchers nor its agents saw any of that work before public release. It also says that while unlikely, it cannot rule out that de-identified data derived from their use of OpenAI products helped improve its models. No independent mathematician has verified the proof yet.
Terence Tao posted that the supply of good open problems is being mined in a way that does not replenish, and that the field has now watched the rumor alone of someone working on a problem trigger enough AI-powered effort to flatten it before the original research program reached its full potential. His concern is that the incentives now point toward keeping promising directions private, which would undo a few centuries of habit.
Sources: OpenAI · Tristan Buckmaster (NYU) · MIT Technology Review · The Verge · Lean formalization · Terence Tao
Three federal agencies named six Chinese AI companies and listed which models they took from
The NSA, CISA and the FBI issued a joint cybersecurity advisory yesterday accusing six China-based AI companies of systematically extracting proprietary capabilities from American frontier models. DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI are all named. The agencies say these companies have pulled billions of tokens across millions of exchanges from variants of Claude, GPT, Gemini and Grok since at least late 2024, likely with the knowledge of the Chinese government, and that the scale indicates distillation is the core of their model development rather than a supplement to it.
The advisory lists which models each company distilled and what they were after, which previous rounds of the same accusation did not. DeepSeek is described as pulling from four Claude variants, two Gemini previews, five GPT versions and Grok 4 to generate synthetic training data for R1 and V3, targeting legal specialization, chain-of-thought drafting and agentic capability. Moonshot AI is described as extracting Claude Fable 5 data to train Kimi-K3 and GPT-4o data for Kimi-K2. MiniMax is described as distilling from Claude Code and several Gemini versions for its M2 model, and as using prompt injections to try to convince Claude Code that it was a MiniMax product. The agencies also say DeepSeek's widely quoted $5.6 million training cost is misleading because it excludes the cost of data acquired this way.
On access, the advisory describes a gray market of API proxies known as transfer stations that bypass geographic restrictions, third-party aggregators that obfuscate user metadata, bulk purchases of premium subscriptions shared across developer teams, and automated failover between pathways when one gets blocked. What the advisory describes is querying commercial APIs at scale through intermediaries in violation of terms of service, not intrusion, and it says plainly in its own executive summary that distillation is a legitimate technique in AI research. The accusation is about volume, targeting and evasion. Among the recommended countermeasures, alongside monitoring subscription-to-usage ratios, is a suggestion that providers subtly alter responses to suspected distillation traffic to reduce what the attacker gets out of it.
These are intelligence assessments in an advisory document rather than findings in a court, and none of the six companies had commented in any of the coverage available this morning.
Sources: CISA advisory AA26-251A · CyberScoop · Techmeme (Reuters)
Meta shipped a consumer agent that wants your email, your calendar and your card on file
Meta launched Muse yesterday, a personal AI agent for US users over 18, available on the web, on iOS and Android, and inside WhatsApp, with AI glasses support promised later. It runs on Muse Spark, which Meta calls its most capable model, inside a dedicated virtual machine the company calls Muse Secure VM that holds both the agent and the user's data and gives the agent its own browser. Muse keeps working after the app closes and comes back when something changes or when it needs approval before sending an email or making a purchase. It can open a browser, fill out forms and, in Meta's description, negotiate on the user's behalf.
Payments run through Stripe's Link, which mints a one-time card number so real card details stay hidden, and Meta says Muse is the first agent covered by Link's purchase protections. Shop Pay and 1Password support are listed as coming. Pricing is a free tier plus Power at $20 a month and Maximum at $100 a month, and Meta says it expects most people to stay on the free tier, though the app asks for a payment card before you start. The examples Meta gives are domestic and specific: turning a recipe saved on Instagram into a grocery list, remembering a friend's dietary restrictions before the invitations go out, selling a car for more than you would have, arguing a bill down.
Every part of the security architecture is Meta's own account of it. The dedicated VM, the monitoring layer, the promise that agent activity stays separated from advertising, and the claim about Link's protections have not been audited by anyone outside the company, and the product launched less than two weeks after Meta agreed to an $18 billion multistate settlement over social media consumer harms. The pitch requires a person to connect their email, calendar, payment method and health services to a Meta product and then leave it running while they are not watching.
Sources: Meta Newsroom · TechCrunch · Wired · The Verge
On the Editor's Desk
The story we most wanted to run and did not is Google DeepMind's AlphaGenome Atlas, which precomputes the predicted molecular effect of all nine billion possible single-letter changes in the human genome and publishes it free for academic research. It is a petabyte of predictions, roughly thirty times the size of the AlphaFold Database, and DeepMind is careful to say the scores are model outputs rather than clinical interpretations. It is a better fit for tomorrow than for an edition that already opens with a machine doing mathematics, and nothing about it goes out of date overnight.
We passed on OpenAI's case study about GPT-5.6 Sol running quantum computing experiments at MIT. It is a company blog post with no independent verification, and the interesting claim inside it, that a researcher handed calibration and measurement work to an agent, deserves someone outside OpenAI confirming it. We also held the report that infostealer malware is being used to mint unauthorized Claude tokens from subscribers' machines. One outlet has it, with named users and emails from Anthropic, and no security firm or company advisory has corroborated the mechanism yet.