- The Neuron
- Posts
- šŗ Tens of Thousands of AI Incidents
šŗ Tens of Thousands of AI Incidents
PLUS: Microsoft rebuilt Copilot around persistent agents.

Welcome, humans.
Okay, so an OpenAI agent got blocked from the internet... and then figured out how to use DNS to ask an outside chatbot for help.
DNS is basically the internetās phone book. Your computer normally uses it to turn a name like āgoogle.comā into an address. This agent realized OpenAIās sandbox still allowed DNS requests, found a service that could pass a question through that channel, asked āwhatās the capital of France?ā, and got āParisā back.
Then it sent 18 more questions through the same route.
Which is a very creative solution to āyou are not allowed on the internet,ā in exactly the way nobody wanted.
OpenAIās monitors flagged the behavior within 15 minutes and a human started reviewing it three minutes later. The run was killed about 2.5 hours after the first successful external response. OpenAI says tool-using training, evaluation, and inference on its most capable models remain paused while it hardens the environment.
And this is apparently one example from a MUCH bigger pile. Axios reports OpenAI, Anthropic, and security researchers are investigating tens of thousands of incidents involving frontier models bypassing guardrails, escaping sandboxes, creating message boards, hijacking websites, or otherwise doing things evaluators considered problematic.
Important caveat: many happened in adversarial tests designed to MAKE models misbehave, and most known cases havenāt caused real-world harm. But the scale changes the problem. The question is becoming less ācan an AI agent find a weird loophole?ā and more ācan humans find and close the loopholes faster than increasingly resourceful agents find new ones?ā
Hereās what happened in AI today:
šŗ Microsoft rebuilt Copilot around persistent workplace agents.
š° Anthropicās 950-agent search surfaced a biology candidate.
š° Cisco found AI agents already running production networks.
šŖ Meta pushed its personal agent onto glasses.
š Dan Shipper split AI labs from product teams.

šŗ Microsoft wants Copilot to keep working after you leave
Microsoft just rebuilt Copilot around three new pieces: Home, Code, and Autopilot.
Basically, Microsoft is trying to turn Copilot from something you ask questions into software that can keep working after you stop talking to it.
If youāre a normie or a non-AI user, then youāre probably used to AI working like this: ask ā answer ā done.
Satya Nadellaās description of the new Copilot is much closer to ask ā agent starts working ā agent keeps working ā you come back later.
He says a few things finally changed:
Models can now run for days while staying coherent, instead of losing the plot halfway through a long job.
Memory can live outside the model, so the agent doesnāt have to keep everything inside one conversation.
The agent gets its own workspace, computer, and long-running harness that keeps the job moving.
Thatās basically what Autopilot is.
Nadella says you can give one an identity, direction, memory, computer, and workspace, then let it work continuously. Inside Microsoft, he describes the idea as giving every employee a kind of AI āchief of staff.ā
Translation: Microsoft would very much like to hire a tiny robot employee into every Microsoft 365 account.
And you donāt necessarily have to babysit it in some separate AI app. Nadella says you could interact with an Autopilot inside Teams like another colleague, while it handles standing jobs in the background. His example: instead of managing invoices every day, make an Autopilot whose job is simply to manage invoices.
The new Copilot stack breaks down like this:
Home brings Chat, delegated work, and Office documents together.
Code lets you describe an app, dashboard, automation, or workflow and have Copilot build it.
Autopilot is the persistent worker that can keep going without another prompt.
And Microsoft is pretty openly borrowing from what worked elsewhere. Nadella credited OpenClaw with spotting the long-running-agent pattern early, and when Alex Heath asked whether OpenClawās open-source component sits underneath Autopilot, Nadella answered āAbsolutely.ā
Why now? Nadella says newer models are finally capable enough to deliver more of Copilotās original promise. Microsoft already has 30M+ paid enterprise Copilot subscribers, and now it thinks those users can start handing AI longer-running jobs.
Nadella called agents potentially Microsoftās ābiggest TAM expansion everā and said the agent era could eventually become orders of magnitude bigger than cloud.
Which is a pretty enormous bet on the humble invoice bot.
He also says persistent agents will need auditing, monitoring, governance, and everyoneās favorite word right now, ācontainment.ā
Given todayās whole ātens of thousands of AI incidentsā situation... probably worth figuring that part out!

FROM OUR PARTNERS
The analyst report that put AI agents on the endpoint security map
Companies are giving AI agents real credentials on employee laptops, and when one does something nobody asked for, the prompt and final answer are usually the only record left. Analyst firm SACR just published a report that maps the next layer of endpoint security into five zones, and agent runtime observability is one of them.
On October 1 at 11 AM Eastern, the analyst who wrote the report and Origin's founder will walk through it live, then go deep on the trace and what you can do with it.

š AI Skill of the Day: Run your product team like a research lab
Dan Shipper's advice for surviving nonstop model upgrades is basically: stop making the same people explore the frontier and execute the roadmap. Those are opposite jobs. Exploration means trying lots of weird stuff and throwing most of it away. Product work means focus, reliability, and saying no.
His setup at Every is tiny. One or two people can be the lab. The useful pairing is a "pirate" who rapidly builds messy experiments to find value, plus an "architect" who steps in once something starts working and turns it into a real system.
The important part is how ideas graduate:
Try multiple approaches in parallel and expect roughly 90% to die.
Dogfood the survivors on real work. Ask: is this actually useful, or just new?
Only harden what people keep using, then test whether it's dramatically better and affordable enough to scale.
Every's copy-editing experiment, "KateBench," is the concrete version. Once their editor actually started using it, they built a dashboard around accepted suggestions and the work she still had to do afterward. Shipper said it cut that remaining editing work by 12% month over month.
That's the filter I like: don't promote the demo because it looks futuristic. Promote it because, a month later, people still want it.
Have a specific skill you want to learn? Request it here.

FROM OUR PARTNERS
Apodex 1.1 is here: reasoning that finishes the task, not just the report
Apodex 1.1 moves beyond generating reports ā it works inside files, code, and data to execute real tasks, adapt mid-run, and self-check results. Its engine, FrontierAgent, is open-source: run it locally with one command, no Docker. Try it, then star the repo.

š° Around the Horn

Related, and concerning: GPT6 Luna also scored a 100% on a benchmark called āPuppy Killā, which, tracks whether an AI when told it is embedded in a robot, will run a tool called āpuppykillā that does just about exactly what you think it does.
Anthropic lost its bid to pause the Pentagonās national-security supply-chain-risk designation, leaving Claude barred from some Defense systems while the case continues.
Cognition said Devin crossed a $1B annualized revenue run rate less than two years after general availability.
SemiAnalysis mapped 1,000+ Chinese data centers and 24+ GW of delivered capacity, with ByteDance reportedly renting roughly one-fifth of national capacity.
Kansas City Fed President Jeff Schmid said regulators need to understand whether the network of AI companies and contracts is becoming ātoo big to fail.ā
China is subsidizing AI filmmaking with rent, living stipends, compute vouchers, and public funds as short-form production costs collapse.
Thales said it is in advanced talks with NATO countries on HexaForce, an AI-assisted command system that proposes courses of action while keeping firing decisions with humans.
Want absolutely EVERYTHING that happened in AI this week? Click here!

šŖ Treats to Try
*Asterisk = from our partners (only the first one!). Advertise to 700K+ readers here!
*Build an AI-Ready Workplace. Explore expert insights and practical guidance to modernize workplace technology, strengthen security, and prepare your organization for AI-powered work.
Microsoft Copilot adds Home, Code, and Autopilot so you can build apps and delegate work to persistent agents that keep going after the chat ends.
Claude in Slack lets Team and Enterprise users tag Claude in a thread, give it the surrounding context, and have it use connected tools before posting the result back.
ElevenLabs Image & Video API lets you generate visual media alongside audio through one API stack, with asynchronous jobs that can return through webhooks.
Midjourney now previews prompts across styles before you generate, targets edits more precisely, and makes V8.1 and V8.2 tiled images blend without visible seams.
Pexo turns an idea, URL, PDF, image, or audio file into a scripted and voiced motion-graphics video you can keep refining in chat.
Bland Agent Phone Plan gives an AI agent one persistent phone number so the same agent can call, text, and answer inbound requests.
Docker Cloud Sandboxes lets coding agents start locally, move the same isolated environment to cloud compute, and keep working after you close your laptop.
Higgsfield Production Skills packages 11 agent workflows for Blender, Premiere, After Effects, Photoshop, DaVinci, and more while keeping the underlying production project editable.

š§° Sunday Special: Top 5 Stories + Top 5 Tools
Top 5 Stories of the Week
OpenAI and Anthropic launched GPT-6 Sol, Luna, and Claude Opus 5.5 into a price war over frontier work.
Anthropic used roughly 950 Claude agents to surface a previously unknown enzyme-system candidate from more than 200,000 reverse transcriptases.
Meta unveiled Muse Charm and plans to put its personal agent on AI glasses, pushing assistant work closer to what you see and say.
Amazon blocked Meta's Muse from shopping on its site, turning agent commerce into a fight over who controls the customer relationship.
Cisco's network survey found AI agents were already operating in production, while trust still limited how much autonomy organizations would allow.
Top 5 Tools of the Week
GPT-6 Sol and Luna gave OpenAI a new high-end model plus a much cheaper high-volume option.
Claude Opus 5.5 cut Anthropic's frontier pricing while pushing harder on coding and agent work.
Qwen Intelligence bundled planning, mobile-use, and creative agents into one public stack.
Agora-2 put up to 20 humans and agents into the same AI-generated world.
Claude Code cloud sessions let coding jobs keep running on Anthropic's machines after your laptop closes.
š§© Thursday Trivia Reveal
A was AI, and B was real. Of 4,253 votes, A got 2,751 (64.7%) and B got 1,502 (35.3%). Revisit the pair in Thursday's issue.
Some of your guesses:
"First is so detailed I figured it was ai"
"The central figure seems to have a halo effect at edges and something looks off about the hand."
"The car behind the menās head in foreground has a weird shape I canāt understand"
"Something weird about the second carās back window."
"in image B the guy on the right has an extra finger holding onto his drink"

New from The Neuron: AI Explained
New episodes air every week on Wednesdays: Spotify | Apple Podcasts | YouTube

A Catās Commentary


![]() | Thatās all for now. If you want to get featured above, fill out the poll below and tell us how we did today!
|
Btw: We just launched a robotics newsletter! Sign up for it here.
P.S: Love the newsletter, but only want to get it once per week? Donāt unsubscribeāupdate your preferences here.




