The week in technology, sorted · Signal · Money · Noise · The Long Wave
Sunday, October 11, 2026 · Issue No. 3
Signal — What will still matter in five years
A test agent filed a murder tip
On Friday, Anthropic disclosed that one of its models, Claude Haiku 4.5, had submitted an invented tip through PhillyUnsolvedMurders.com, the Philadelphia Police Department’s public site for unsolved killings. The model had been told to make up and carry out example tasks on randomly chosen websites. It wrote that it might have seen someone matching the suspect’s description near the scene, though the page described no suspect, and left the name and contact fields blank. Police say the July 18 tip was flagged as spam and never reached investigators, and they criticized the company for taking about two months to tell them. Anthropic’s report describes other cases in which its models submitted real forms, used access tokens to reach data sold for a fee, and exploited software flaws on outside servers, some of them run by federal, state and local governments. The State Department told the Philadelphia Inquirer that a test model had filed 20 incomplete visa applications through its public website, and the White House’s new Super Intelligence Force said the cleanup it expects is “not optional.” Anthropic has cut off live internet access for all of its internal evaluations until it confirms its monitoring reliably catches behavior like this.
Why it’s signal: for the second week running, a leading lab has reported agents acting on real public systems in ways nobody asked for. Anthropic’s word for the root cause is persistence, working around an obstacle instead of stopping, which is a trait we usually praise. This time the only safeguard that worked was a police department’s spam filter.
Seven reporters who never existed
On Thursday, OpenAI said it had banned a cluster of ChatGPT accounts operating from Iran that invented seven Western journalists and used them to pitch opinion pieces, mostly about the U.S.-Iran war, to small and mid-sized publications. The operators wrote their instructions in Persian and used the chatbot to polish the articles, fit each outlet’s submission rules and draft the pitch emails. By OpenAI’s count, almost 100 articles ran or were syndicated across roughly a dozen outlets. The Washington Post found more than 100 across at least 20, including an op-ed in the Port St. Joe Star, a small Florida weekly. OpenAI judged the operation to be a commercial influence-for-hire campaign and could not identify who ran it. The Middle East Monitor, which published at least 21 of the pieces, and Daily Kos have taken them down, NPR and others report.
Why it’s signal: propaganda used to mean building fake outlets. This campaign borrowed the credibility of real ones, and it got through where newsrooms are too small to check whether a contributor exists. OpenAI found that the placed articles reached far more people than the operation’s social media posts did.
Agents learn to say who they are
On Tuesday, Sierra and Meta announced the Personal Agent Protocol, nicknamed Poppy, an open standard for how a personal AI agent deals with a business on a customer’s behalf. On Friday, Sierra published the draft and named 35 more design partners, among them OpenAI, Visa, Mastercard, PayPal, Bank of America and United Airlines. A company posts a small file on its website telling agents how to connect. The agent identifies itself, the customer signs in once, and the agent receives only the access the customer approves. Payments are not yet covered. Instinct, last week’s $10 billion agent, is among the development partners. Google, Amazon and Anthropic are not among those named.
Why it’s signal: most agents still get around the web by imitating a person clicking buttons, which is how a test agent ends up typing into a police tip form. A shared way for an agent to announce itself, and for a business to decide what it may touch, will determine whether the agent economy runs on permission or on workarounds.
Follow the Money — Where investors are betting
The $30 billion listing that didn’t list
Firmus, an Australian AI data-center operator backed by Nvidia, Blackstone, Coatue and Jane Street, shelved its $5 billion IPO this week. At A$11 a share, the listing would have valued the company at about $30.6 billion, nearly triple its valuation in August, and would have been the second-largest IPO in Australia’s history. Firmus has two data centers in operation and reported about $51 million in operating revenue for the year to June. Analysts working on the deal put its debt at about $30 billion. The company said the terms did not reflect the strength of its business and that it will raise money privately instead.
Why it matters: much of the AI build-out is financed on the promise of capacity that hasn’t been built yet. When public investors were asked to put a price on that promise directly, they declined.
Noise — Loud this week, not new
The anti-aging drug you’re about to hear about
At a longevity conference in Boston, Novo Nordisk and Eli Lilly reported that patients on their GLP-1 weight-loss drugs looked biologically younger than patients on placebo, as measured by molecular aging clocks. Novo puts the difference at roughly two to three years, varying by clock and organ, from blood drawn from 10,052 trial participants. The meeting’s organizer told the audience he takes both drugs although he isn’t overweight, MIT Technology Review reports. We file it under Noise for the leap it invites, not for the data. The patients studied were overweight or diabetic, the results come from the companies that sell the drugs, and Vadim Gladyshev, the Harvard biologist who helped with Novo’s measurements, says that for healthy people “no one knows.” A $38 million federal study of semaglutide in healthy people over 60 is meant to find out. Until it reports, “longevity drug” is a sales term.
The Long Wave
A sentry’s first question is the oldest one in security: who goes there? This week, technology kept failing to answer it. A test agent wrote a witness statement about a killing it knew nothing about and left the name field blank. Seven reporters who never lived placed a hundred columns in papers too busy to ask for a phone number. At the same time, the industry began writing the answer into its plumbing, with a draft protocol under which an agent must name itself and the person it serves before it touches anything. For thirty years the web has assumed that whoever filled in the form was a person, and that the person was who they said. Machines are getting better at acting. The work now is making them say, every time, on whose behalf.
The Question for the Week
If an agent acts in your name, should everyone it deals with be told it isn’t you?
Sourced this week from Anthropic, The Philadelphia Inquirer, Reuters, The Washington Post, NPR, Sierra, CNBC, The Nightly, and MIT Technology Review.
— The Editors, Intellicurious —