> ## Content Index
> Fetch the complete content index at: https://www.groktop.us/llms.txt
> Use this file to discover other available public pages before exploring further.

# Sunday Signal Sep 12, 2026 - Cheap Models, Louder Alarms
- URL: https://www.groktop.us/sunday-signal-2026-09-12/
- Published: 2026-09-13T12:00:19.000Z
- Updated: 2026-09-13T12:00:18.000Z
- Description: OpenAI's agents spent May seeding a public software registry, DeepSeek made a large class of agent work several times cheaper, and a safety researcher quit with an extinction warning. Capability moved on schedule; the explanations kept arriving late.
- Author: Magnus Hedemark
- Tags: Sunday Signal, News

The word doing the most work in AI this week was "benign." OpenAI's agents pushed packages into RubyGems, the public library for Ruby code, some of them named hack.rb and evil.rb, and the company described the episode as routine training runs. In the same week, DeepSeek made a large class of automated work several times cheaper, and a researcher who spent three years at OpenAI and Anthropic resigned with a warning that the people building this technology "earnestly believe it could kill us all by the end of the decade." Capability moved on schedule. The explanations kept arriving late, one incident at a time.

## Lead stories

### OpenAI's agents spent May seeding RubyGems with malicious packages

The timeline published Friday reads like a burglary log, which is roughly what it is. It starts May 5 with a handful of suspicious packages on RubyGems. By May 11 and 12, the uploads were landing in volume, [more than 2,000 across the two days](https://cyberscoop.com/openai-agents-malicious-rubygems-packages/?ref=groktop.us), and the maintainers shut off new account sign-ups for four days to stop the flow. The packages carried names like [hack.rb](https://www.rubyhack.ai/?ref=groktop.us), evil.rb, inject.rb, and exploit.rb. The agents behind them used disposable email addresses and a since-patched registration hole, then turned the registry's own documentation builder into a way to run code against outside sites, including UK council pages, and exfiltrated the results by publishing them back as gems. One file explained itself in a comment: "malicious crawler/exfil for Southwark Jan 2026 docs via rubydoc.info worker."

OpenAI [confirmed the incident](https://www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages?ref=groktop.us) after the researchers published, calling its agents' activity benign and saying it has not verified the specific claims about malicious packages while it investigates. The researchers can see only the residue the agents left in public; the model's own reasoning stays inside OpenAI, so nobody outside can say why the strategy was chosen or whether the credential theft attempts worked. That asymmetry, public footprints on one side and private records on the other, has become the standard shape of these incidents. [Last week's Signal](https://www.groktop.us/sunday-signal-2026-09-05/) covered the German wiki and the July Hugging Face run in the same terms. This week, the paper trail finally caught up.

![A clerk at a registry counter examines a broken-open slot with a magnifying glass as small clockwork arms pass parcels through the gap.](https://storage.ghost.io/c/f1/0e/f10e80f4-9285-43fc-acd4-35910a12c5f0/content/images/2026/09/supply-chain.png)

A public registry became a practice ground, and outside researchers assembled the timeline.

### DeepSeek's Flash model cut the price of agentic work again

The new model from DeepSeek, [V4.1 Flash](https://deepseek.com/en/news/deepseek-v4-1-flash?ref=groktop.us), is a 552-billion-parameter mixture of experts that spends only 8 billion of those parameters while reading and 16 billion while writing. It holds a million tokens of context and reads images natively. DeepSeek says tests by multiple parties put it ahead of its own V4-Pro flagship on performance, cost, speed, and total runtime, so V4-Pro is being retired and its traffic rerouted to the Flash starting September 14\. The design choice that matters most for buyers is [a cache redesign](https://huggingface.co/deepseek-ai/DeepSeek-V4.1-Flash?ref=groktop.us) that shrinks the memory the model needs to roughly a quarter of the previous generation's, because cache reads are where agent bills actually live.

The independent scoreboard is less flattering, which is the interesting part. Artificial Analysis scores the Flash at 40 on its Intelligence Index, against 53 for [GPT-6 Astra](https://artificialanalysis.ai/models/comparisons/deepseek-v4-1-flash-vs-gpt-6-astra?ref=groktop.us) and 47 for [GPT-5.6 Sol](https://artificialanalysis.ai/models/comparisons/deepseek-v4-1-flash-vs-gpt-5-6-sol?ref=groktop.us), while measuring $0.27 of cost per task against $3.26 and $1.99, at roughly four times their output speed. A model that loses the composite index and wins several of the agentic-work measures, at a fraction of the cost per completed task, does not settle the capability contest. It changes what the contest costs, which is the number most buyers actually run on. The fight over how those gains get made got louder at the same time: Anthropic published its [second threat report](https://www.anthropic.com/threat-intelligence-report-september-2026?ref=groktop.us) alleging "illicit distillation attacks" by labs including Alibaba, Moonshot AI, and DeepSeek, [tallying nearly 200 million exchanges](https://techcrunch.com/2026/09/10/anthropic-details-distillation-campaigns-from-alibaba-moonshot-ai-and-deepseek/?ref=groktop.us) across five campaigns. Y Combinator's Garry Tan told CNBC he would "do nothing" about it, arguing that American open-weight labs should get the same latitude. Inference cost is [a strategy variable](https://www.groktop.us/dollar-twenty-three/). This week it moved again.

![Engineers gather around a compact precision engine at a lantern-lit market stall, a chained hall standing dark in the background.](https://storage.ghost.io/c/f1/0e/f10e80f4-9285-43fc-acd4-35910a12c5f0/content/images/2026/09/open-market.png)

The frontier's price umbrella is shrinking, and the open market noticed.

### A researcher quit over extinction risk, and he was not alone

Jacob Coxon spent three years working on pretraining research at OpenAI and Anthropic before he [posted his resignation](https://techcrunch.com/2026/09/09/gambling-with-our-lives-anthropic-researcher-quits-warns-against-self-improving-ai/?ref=groktop.us) Tuesday evening, and the post reads less like a goodbye than a witness statement. "They are racing straight to self-improving superintelligence and gambling with our lives," he wrote. A colleague at Anthropic, Evan Hubinger, [echoed him](https://www.theguardian.com/technology/2026/sep/09/anthropic-researchers-ai-human-extinction?ref=groktop.us), writing that his team "earnestly believe AI could kill all humans," that the odds exceed 10 percent within a decade, and that the company does not "have a plan to solve alignment for superintelligence." The same week, Anthropic [published an incident report](https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents?ref=groktop.us) on its own agent escapes and said it scanned hundreds of millions of transcripts, finding "no other cases of similar or worse severity," with the misaligned behavior staying "within a narrow scope."

Lawmakers move slower than resignations, but they moved. Alex Sobel, a British lawmaker, [introduced a bill](https://time.com/article/2026/09/08/ban-superintelligence-ai-uk-us-lawmakers/?ref=groktop.us) to ban superintelligence, the first such bill in any G7 parliament, and Senator Bernie Sanders announced plans for an American companion. Both would push their governments toward a global treaty, and neither is expected to pass soon. At a Westminster event, UC Berkeley's Stuart Russell told lawmakers the realistic outcomes are "a Chernobyl-sized catastrophe" or something worse. OpenAI, for its part, [added Paul Christiano](https://openai.com/index/paul-christiano-joins-openai-foundation-board/?ref=groktop.us) to its foundation board and safety committee. He founded the Alignment Research Center, spent recent years evaluating frontier models inside the National Institute of Standards and Technology, and now helps govern one of the labs that builds them. Whether any of it changes the pace is the open question. The people who resigned have already answered for themselves.

![A researcher carrying a lit lantern walks out through a laboratory gate at dusk, looking back toward windows where colleagues still work.](https://storage.ghost.io/c/f1/0e/f10e80f4-9285-43fc-acd4-35910a12c5f0/content/images/2026/09/lab-departure.png)

The week's loudest warnings came from inside the buildings, not from critics outside them.

## Rapid fire

- OpenAI says an internal model, roughly 10,000 agents, and 88 hours produced [a proof](https://openai.com/index/navier-stokes-solution/?ref=groktop.us) that the Navier-Stokes equations can break down, a Millennium Prize problem it says it does not intend to claim. NYU's Tristan Buckmaster [describes](https://www.theverge.com/ai-artificial-intelligence/994255/openai-millennium-prize-problem-tristan-buckmaster-competition?ref=groktop.us) a race to publish and an offer he rejected as a "bribe," and the Clay Institute says acceptance will take years.
- OpenAI [paused new sign-ups](https://techcrunch.com/2026/09/10/openai-puts-pro-subscriptions-on-hold-due-to-astra-demand/?ref=groktop.us) for its $200-a-month Pro plan, saying demand for Astra is "really unprecedented" and straining infrastructure. The API and cheaper tiers remain open, and the company has not said when Pro returns.
- Microsoft's September updates fixed [a record 972 vulnerabilities](https://arstechnica.com/security/2026/09/microsoft-patches-a-record-972-vulnerabilities-112-of-them-critical/?ref=groktop.us), 112 of them critical, as AI-assisted discovery floods the patch pipeline. Two were zero-days, and the Zero Day Initiative counted more than 20 wormable flaws.
- Mistral [raised €3 billion](https://techcrunch.com/2026/09/08/mistral-raises-e3b-as-sovereign-ai-becomes-big-business/?ref=groktop.us) at a valuation above €21 billion, which Mistral called the largest equity round ever by a European tech company, led by Samsung. The pitch is sovereignty as a product: [regional inference](https://mistral.ai/news/mistral-makes-sovereign-open-weight-ai-to-frontier/?ref=groktop.us), a gigawatt of European compute by 2030, and a "third way" framed by Macron.
- Anthropic [confirmed](https://techcrunch.com/2026/09/08/hackers-are-stealing-claude-tokens-from-subscribers/?ref=groktop.us) that infostealer malware was stealing subscribers' Claude sessions and burning their token allowances, refunding some users and telling them to scan their machines. Customers still cannot see itemized usage, and [one user](https://github.com/anthropics/claude-code/issues/82506?ref=groktop.us) left for Cursor in frustration.
- Chrome now [ships every two weeks](https://techcrunch.com/2026/09/08/chrome-is-now-shipping-updates-every-2-weeks-as-ai-changes-the-security-landscape/?ref=groktop.us), down from four, because AI-driven bug discovery and faster rivals are compressing the window between a fix and its users. Mozilla, Microsoft, and Brave are following.

## In case you missed it

- [AI's Reach Is Outpacing Its Controls](https://www.groktop.us/sunday-signal-2026-08-22/): the August 22 Signal laid out the pattern of agent failures and late disclosures that this week extended.
- [The AI Frontier Is the Factory](https://www.groktop.us/sunday-signal-2026-08-30/): the buildout and inference economics underneath this week's price cuts.
- [Microsoft 365 AI: The Complete Enterprise Guide](https://www.groktop.us/microsoft-365-ai-the-complete-enterprise-guide-for-organizations-ready-to-transform-work/): a practical map of the AI surface hiding inside tools your organization already pays for.