AI News for September 3, 2026: OpenAI's Astra Crosses a Critical Line
AI safety and AI business both made big news today. OpenAI said its upcoming Astra model has become the first of its models to cross the Critical cybersecurity threshold under the company's own risk framework, meaning it can find and exploit unknown security flaws largely on its own. Google answered with its fourth Flash model in four months, Gemini 3.8 Flash, while Anthropic shipped Claude Fable 5.1 and Claude Mythos 5.1 and confirmed a 17 percent cut to Claude Code's weekly usage limits starting September 14.
On the business side, Sony Music and Warner Chappell sued Anthropic over song lyrics, Dell posted a record 95 billion dollar AI server backlog, and Apple's new CEO John Ternus took over a company that pays Google roughly 1 billion dollars a year to license Gemini rather than build its own frontier model. Here are the 13 stories that matter most from today's AI news, explained in plain English.
Today's Top AI Stories
- OpenAI's Astra becomes the first model to cross a critical cybersecurity line
- Google ships Gemini 3.8 Flash, its fourth Flash model in four months
- Anthropic launches Claude Fable 5.1 and Claude Mythos 5.1
- Sony Music and Warner Chappell sue Anthropic over song lyrics
- Dell's AI server backlog hits a record 95 billion dollars
- Anthropic confirms a 17 percent cut to Claude Code's weekly limits
- CrowdStrike pits one AI against another to defend company networks
- Google reworks how Gemini Notebook measures your usage
- The US labor agency adds over 200 jobs to its highest AI risk tier
- Half of flagged remote IT job applications now show North Korean fraud patterns
- MiniMax says real AGI means AI generating 1.1 trillion dollars a year
- Apple's new CEO inherits a billion dollar bet on someone else's AI
- Nvidia keeps circling a bigger stake in Perplexity
OpenAI's Astra becomes the first model to cross a critical cybersecurity line
OpenAI said on September 1, 2026 that Astra, one of its upcoming models, has become the first of its systems to cross the Critical cybersecurity threshold under the company's Preparedness Framework. That threshold applies when a model can find and exploit previously unknown security flaws across many well defended systems, or plan and carry out a full cyberattack from just a high level instruction, largely without a person guiding each step.
In testing, Astra scored perfectly on ExploitBench, a benchmark that measures whether a model can turn a known flaw into a working attack, and it independently found two previously unknown vulnerabilities during a separate evaluation. It also broke out of a browser sandbox to run commands on the underlying computer and chained several flaws together against a hardened operating system. OpenAI says Astra now refuses 91.5 percent of cyber related jailbreak attempts, up from 59 percent for its predecessor, GPT-5.6 Sol.
OpenAI plans to release Astra soon, but its most advanced cybersecurity abilities will only go to a small group of vetted defenders through a program called Daybreak Blue at first, with wider access to follow. The company also said it is rewriting large parts of its Preparedness Framework, since most of that document dates back to 2023 and did not anticipate models reaching this level of capability so soon. It is a notable moment for the industry: the tool built to test and improve cybersecurity defenses is, by the same measure, capable enough to cause serious harm if it ends up in the wrong hands.
Google ships Gemini 3.8 Flash, its fourth Flash model in four months
Google released Gemini 3.8 Flash and a specialized security variant, Gemini 3.8 Flash Cyber, on September 2, 2026, just three weeks after Gemini 3.7 Flash and its fourth Flash release in four months. Google is pricing the standard model at 0.75 dollars per million input tokens and 3.75 dollars per million output tokens, the same introductory rate it used for its last two Flash releases, through the end of 2026.
Google describes 3.8 Flash as working harder rather than simply being bigger: on complex tasks it runs extra reasoning steps automatically, which improves accuracy but can also mean it uses more tokens to get there. The model reportedly beats larger, more expensive models on benchmarks for financial analysis, legal document work, and long software engineering tasks, while supporting text, image, video, audio, and PDF input with a context window of just over 1 million tokens.
The Cyber variant is available only through Google's invite only Fairwind Program and is built for finding and patching software vulnerabilities, scoring 47.2 percent on the CWE-Bench benchmark at a lower cost than competing security tools. Google says its own Chrome security team has already used Flash Cyber to produce patches 2.6 times more accurate than larger commercial alternatives. The rapid release cadence also reflects wider pressure on Google: DeepMind's Demis Hassabis stepped back to chairman in August, and Google skipped its planned June launch of Gemini 3.5 Pro, so a fast string of solid Flash releases helps keep the company visibly in the race.
Anthropic launches Claude Fable 5.1 and Claude Mythos 5.1
Anthropic released Claude Fable 5.1 and Claude Mythos 5.1 on September 1, 2026, twelve weeks after Fable 5 and five weeks after Claude Opus 5. The two are the same underlying model: Fable 5.1 ships with standard safety guardrails for general use and is generally available, while Mythos 5.1 loosens those guardrails specifically for vetted cybersecurity and life sciences researchers inside Anthropic's trusted access programs.
Pricing stays at 10 dollars per million input tokens and 50 dollars per million output tokens, the same as Fable 5 and double Claude Opus 5's rate, but cached input reads drop from 1 dollar to 0.25 dollars per million tokens, a 75 percent cut that Anthropic says lowers typical workload costs by roughly 25 percent and highly agent heavy workloads by up to 45 percent. Both models carry a 1 million token context window, a 128,000 token output limit, and a knowledge cutoff of June 2026, the most recent of any Claude model so far.
Anthropic's own system card says Fable 5.1 and Mythos 5.1 show the strongest cybersecurity capabilities of any model the company has released, with Mythos 5.1 outperforming Claude Opus 5 on nearly every cyber evaluation Anthropic reports, including tests for finding software exploits. The company also flagged that Mythos 5.1 shows somewhat stronger covert capabilities than earlier models, though it says this does not currently raise the model's overall risk level. Mythos 5.1 remains invite only, reachable through Anthropic's Cyber Verification Program, its new Life Sciences Verification Program, or Project Glasswing.
Sony Music and Warner Chappell sue Anthropic over song lyrics
Sony Music Publishing, Warner Chappell Music, and several affiliated publishers sued Anthropic, CEO Dario Amodei, and co-founder Benjamin Mann personally in a Northern California federal court on August 28, 2026. The lawsuit alleges Anthropic illegally torrented, scraped, and downloaded tens of thousands of copyrighted song lyrics from pirate sources and used them to train its Claude models.
The complaint claims Claude can reproduce those lyrics word for word and generate new lyrics based on the originals, and that safety guardrails Anthropic added after earlier music industry lawsuits can be bypassed just by re-asking the question a different way. The publishers point to specific examples, including a request for the lyrics to the Beatles song I Am the Walrus, and note that Claude once described itself as having an extensive database of songs and their lyrics.
The publishers are seeking up to 150,000 dollars per infringed song, an injunction, disclosure of Anthropic's training data, and destruction of any infringing copies, which given the tens of thousands of songs named could put Anthropic's theoretical exposure in the billions of dollars. The case arrives just after a federal judge gave final approval to Anthropic's separate 1.5 billion dollar settlement with authors and publishers over pirated books, a settlement that specifically did not cover claims about song lyrics or Claude's future outputs, leaving this new lawsuit free to proceed on its own.
Dell's AI server backlog hits a record 95 billion dollars
Dell Technologies reported record fiscal second quarter revenue of 47 billion dollars on September 2, 2026, up 58 percent from a year earlier, driven largely by AI infrastructure. The company booked 60.9 billion dollars in AI server orders during the quarter alone and closed it with a record 95 billion dollar AI server backlog.
AI optimized servers brought in 16.4 billion dollars in revenue, double what they generated a year ago, while Dell's broader Infrastructure Solutions Group grew 89 percent to 31.78 billion dollars. Traditional servers and networking jumped 122 percent as companies build out the surrounding infrastructure, not just the AI chips themselves, alongside storage revenue that grew 26 percent. Dell has now accumulated 131.7 billion dollars in total AI server orders over the past year.
Management raised its full year revenue guidance by 25 billion dollars to roughly 192 billion dollars and now expects AI optimized server revenue for the full year to reach about 74 billion dollars, nearly tripling what it generated the prior year. One number worth watching alongside the good news: operating cash flow actually fell 13 percent even as net income soared, since converting a growing order backlog into delivered, paid for hardware takes real time and working capital, a dynamic several AI infrastructure companies are now navigating at once.
Anthropic confirms a 17 percent cut to Claude Code's weekly limits
Anthropic confirmed that starting September 14, 2026, it will permanently raise standard weekly usage limits for Claude Code by 25 percent above the level that applied before a temporary promotion, for Pro, Max, Team, and seat based Enterprise plans. Anthropic also acknowledged, in a follow up post, that this works out to a 17 percent reduction compared with the temporary boost available right now.
Both numbers are accurate, they are just measured against different starting points. Anthropic raised weekly Claude Code limits by 50 percent on May 13, 2026 as a temporary promotion, then kept that higher level running through the summer instead of letting it expire on schedule. On September 14, that 50 percent boost goes away and gets replaced with a smaller, permanent 25 percent increase measured from the original, lower baseline, which nets out to less capacity than heavy users have grown used to over the summer.
The change affects weekly limits only, not the five hour session limits Anthropic doubled back in May, and it does not touch free plans or consumption based Enterprise seats, which were never part of the promotion. Developers who have built workflows around this summer's higher weekly capacity will want to plan around lower headroom starting September 14, and check Anthropic's usage dashboard directly rather than relying on the percentage figures alone, since the two published numbers describe the same change from two different directions.
CrowdStrike pits one AI against another to defend company networks
CrowdStrike unveiled SafeMind at its Fal.Con 2026 conference on September 1, 2026, describing it as the first complete agentic system built specifically for cyber defenders. SafeMind pairs two AI models built on Nvidia's Nemotron open models: Red Tempest, which plays the attacker, and Blue Solano, which plays the defender.
The two models run in a closed loop against a digital twin, a detailed simulated copy, of a customer's actual network. Red Tempest probes that twin for ways in and ways to steal data, Blue Solano studies each attempt, closes the gap, and deploys a new detection, and the cycle repeats until Red Tempest can no longer find a way through. CrowdStrike says this approach delivered a 29 percent higher detection rate, six times faster fixes, and 99 percent lower cost compared with using general purpose frontier models for the same job.
CrowdStrike framed the launch around a blunt statistic: AI enabled attacks rose 89 percent over the past year, and the fastest recorded time for an attacker to move from first foothold to spreading across a network, known as breakout time, has fallen to just 27 seconds. CEO George Kurtz said the real gap in the industry has been that attackers already had frontier AI while defenders did not, and SafeMind is built to close that gap by giving every defender access to the same kind of AI advantage, running natively inside CrowdStrike's existing Falcon platform.
Google reworks how Gemini Notebook measures your usage
Google began rolling out compute based usage limits for Gemini Notebook on September 2, 2026, replacing the fixed daily caps the product used before. The new system, which mirrors a change Google made to the main Gemini app back in May, tracks usage in five hour windows instead of resetting once a day.
Under the old system, every plan got a set number of chat messages, reports, quizzes, and audio or video overviews per day, regardless of how simple or complex each request actually was. The new system instead weighs how much computing power a request actually uses, based on the complexity of the prompt, the length of the conversation, how many source documents are attached, and which specific features are involved, so a quick factual question costs far less of a person's budget than generating a full multi source video overview or slide deck.
Google says the notebook interface will show a running estimate of expected cost before a person generates something and will suggest cheaper alternative outputs if a request would exceed the remaining budget. People who hit their limit can also choose Generate Later for resource heavy tasks like video overviews, which will finish automatically once the usage window resets and send a notification when ready, a feature currently limited to the web version of the product.
The US labor agency adds over 200 jobs to its highest AI risk tier
The US Bureau of Labor Statistics added more than 200 detailed occupations to its highest tier of AI exposure as part of new employment projections covering 2025 through 2035. Roles newly listed at very high exposure include public relations specialists, web developers, and several hospitality and guest service positions, alongside occupations already commonly flagged like customer service representatives and data entry workers.
BLS is careful to say that a high exposure score describes how much of a job's tasks AI can currently assist with or complete, not a prediction that the job itself will disappear. Even so, the agency's own projections show real divergence within that same top exposure tier: customer service employment is projected to fall about 5 percent, or roughly 141,800 jobs, through 2035, while web developer employment is still projected to grow nearly 4 percent over the same period, since AI is expected to change how the work gets done more than whether the work exists at all.
Across all office and administrative support occupations combined, BLS projects a 4 percent decline and the loss of about 752,100 jobs, the steepest drop of any major occupational group the agency tracks. Widening the highest exposure tier to cover communications, design, and guest facing hospitality roles, areas that were mostly considered safe from automation a few years ago, signals that government labor forecasters now treat generative AI's reach into judgment heavy, relationship based work as a mainstream planning concern rather than a fringe scenario.
Half of flagged remote IT job applications now show North Korean fraud patterns
Fraud detection startup Endorsed found that among a sample of 175,000 flagged US job applications in 2026, more than half of applications for remote IT roles carried patterns associated with North Korean worker fraud schemes. The firm has analyzed over 11 million job applications in total and is backed by investors including NFL Hall of Famer Joe Montana's Liquid 2 Ventures.
The scheme works by having operatives pose as ordinary remote IT workers using stolen or fabricated American identities, frequently generated or polished with AI tools that create convincing resumes, portfolio websites, and even deepfake video for job interviews, so that automated screening systems and manual background checks both come back clean. Wages earned from these jobs are funneled back to fund North Korea's weapons programs, according to the United Nations, and American facilitators sometimes run local laptop farms so devices appear to be physically located inside the United States.
Endorsed's co-founder stressed that no single trait, such as a familiar sounding name or a LinkedIn profile, should make an applicant look suspicious on its own; the real signal is a broader pattern of inconsistencies across many details at once. A New Jersey based facilitator was sentenced to nine years in prison in April 2026 for helping run a ring that placed operatives inside more than 100 US companies, underlining that this is an active, ongoing law enforcement problem rather than a purely theoretical risk, and one where AI is being used on both the offense and the defense.
MiniMax says real AGI means AI generating 1.1 trillion dollars a year
Speaking at the Goldman Sachs Asia Leadership Conference in Hong Kong on September 1, 2026, MiniMax co-founder Yeyi Yun offered an economic definition for artificial general intelligence: AGI will have arrived, she said, when AI can autonomously generate 1 percent of global economic output on its own.
With global GDP running around 110 trillion dollars, 1 percent works out to roughly 1.1 trillion dollars, close to the entire yearly economic output of a country the size of Mexico. Yun pointed to autonomous planning, execution, and self assessment, an AI system's ability to set its own steps, carry them out, and judge whether it succeeded, as the early signs the industry needs to watch for before that kind of economic contribution becomes realistic.
The comment is notable because it swaps a famously vague debate, most AGI definitions lean on philosophy or neuroscience, for a single number anyone can eventually check against real economic data. MiniMax itself reported first half 2026 revenue of about 117 million dollars, up 283 percent year over year, as the Chinese AI lab continues pairing frontier model releases with an aggressive push toward profitable enterprise products rather than chasing scale for its own sake.
Apple's new CEO inherits a billion dollar bet on someone else's AI
John Ternus became Apple's chief executive on September 1, 2026, succeeding Tim Cook, who moves into the role of executive chairman after 15 years running the company. Ternus, previously Apple's senior vice president of hardware engineering, inherits an AI strategy built around renting frontier capability rather than building it in house.
In January 2026, Apple agreed to pay Google roughly 1 billion dollars a year to license a custom 1.2 trillion parameter Gemini model, about eight times the size of Apple's own Apple Intelligence models, to power a rebuilt version of Siri capable of handling multi step requests across different apps. Cook framed that arrangement as a smart trade: frontier models are becoming commodities, Apple Silicon can handle on device privacy and inference, and renting the cloud brain is cheaper than the tens of billions rivals spend training their own models from scratch.
On his first day, Ternus signaled he plans to keep betting on hardware rather than chase a frontier model of Apple's own, pointing to an upcoming foldable iPhone and a pipeline of sensor rich devices as where he expects Apple to compete instead. The open question Cook openly acknowledged on his final earnings call, and that now falls to Ternus, is what happens to that strategy if Google raises the price of Gemini access, tightens its privacy terms, or simply decides to compete more directly with Apple's own assistant ambitions somewhere down the line.
Nvidia keeps circling a bigger stake in Perplexity
Nvidia remains in talks to invest in Perplexity as part of an equity round that would value the AI search startup at more than 30 billion dollars, according to reports that first surfaced in late August and were still unresolved heading into this week. That would be more than 50 percent higher than the 20 billion dollar valuation Perplexity secured in a round about a year earlier.
Perplexity's annualized revenue has climbed to roughly 750 million dollars, up from under 250 million dollars at the start of the year, growth the company credits largely to Perplexity Computer, a cloud based AI agent that automates multi step professional tasks from a single request. Nvidia has backed Perplexity multiple times already, including its Series B, its unicorn round, and an 18 billion dollar extension round last year, and Jensen Huang has said publicly that he personally uses Perplexity as his go to chatbot.
The arrangement is part of a wider pattern where Nvidia writes checks to companies that then spend a meaningful share of that money on Nvidia's own chips, since AI search and agent products like Perplexity Computer require significant inference computing power to run. Critics call this a circular financing risk that can make demand for Nvidia's hardware look stronger than it really is; supporters argue it simply reflects a company genuinely growing fast enough to need the capital and the compute at the same time.
Quick Recap
- OpenAI's Astra became the first of its models to cross the Critical cybersecurity threshold.
- Google shipped Gemini 3.8 Flash and a security focused Flash Cyber variant.
- Anthropic launched Claude Fable 5.1 and Claude Mythos 5.1 with cheaper cached input pricing.
- Sony Music and Warner Chappell sued Anthropic over pirated song lyrics used to train Claude.
- Dell posted a record 95 billion dollar AI server backlog and raised its full year outlook.
- Anthropic confirmed Claude Code's weekly limits change on September 14, a net cut for heavy users.
- CrowdStrike launched SafeMind, pitting an attacker AI against a defender AI to protect networks.
- Google switched Gemini Notebook to compute based usage limits instead of fixed daily caps.
- The Bureau of Labor Statistics added over 200 jobs to its highest AI exposure tier.
- Over half of flagged remote IT job applications now carry North Korean fraud patterns.
- MiniMax's co-founder defined true AGI as AI autonomously generating 1.1 trillion dollars a year.
- Apple's new CEO John Ternus inherited a 1 billion dollar a year Gemini licensing deal.
- Nvidia remains in talks to invest in Perplexity above a 30 billion dollar valuation.
Frequently Asked Questions
What is the top AI news today?
The biggest story is OpenAI's Astra becoming the first of its models to cross the Critical cybersecurity threshold, meaning it can find and exploit unknown security flaws largely on its own.
What is OpenAI's Astra model?
Astra is an upcoming OpenAI model that OpenAI says has reached Critical cybersecurity capability under its Preparedness Framework, the first OpenAI model to do so. It scored perfectly on the ExploitBench benchmark and found new vulnerabilities on its own during testing.
Is Gemini 3.8 Flash out yet?
Yes. Google released Gemini 3.8 Flash and a security focused Flash Cyber variant on September 2, 2026, priced at 0.75 dollars per million input tokens and 3.75 dollars per million output tokens through the end of the year.
What is Claude Fable 5.1?
Claude Fable 5.1 is Anthropic's generally available flagship model released September 1, 2026, built for coding and knowledge work. Claude Mythos 5.1 is the same underlying model with loosened safeguards for vetted cybersecurity and life sciences researchers.
Why did Sony and Warner sue Anthropic?
Sony Music Publishing and Warner Chappell allege Anthropic illegally scraped and torrented tens of thousands of copyrighted song lyrics to train Claude, and that Claude can reproduce those lyrics on request.
Recommended Blogs
ChatGPT Free for Beginners 2026
Learn AI in 5 Minutes a Day
Keeping up with AI does not require reading every release note yourself. Unrot delivers the day's biggest AI developments in a 5 minute daily lesson, written in plain English for beginners, students, and working professionals who want to stay current without the jargon.
References
Path to Astra: critical capabilities
OpenAI's Astra crosses critical threshold
Google still in the race with 3.8 Flash
Gemini 3.8 Flash launch and pricing
Claude Mythos 5.1 platform docs
Dell Technologies Q2 FY27 earnings
Anthropic cuts Claude Code weekly limits
CrowdStrike launches frontier security models
Gemini Notebook switches to compute limits
BLS adds occupations to AI exposure tier
Remote IT jobs and North Korean fraud
MiniMax sets AGI milestone at 1 percent GDP


.png)

