Today's Headlines

  • The Justice Department files a Statement of Interest of the United States in the OpenAI copyright MDL — training LLMs on copyrighted works is fair use, the government argues
  • OpenAI reports that its new model, Astra, meets the top "Critical" cybersecurity threshold on its own Preparedness Framework — the first model to be designated at that level
  • Google ships Gemini 3.8 Flash and the defense-tuned 3.8 Flash Cyber — the third Flash generation in six weeks
  • OpenAI moves to send seven Tumbler Ridge cases to Canada; on the same day plaintiffs' counsel files thirty more
  • New York City bars generative AI for students from kindergarten through eighth grade for one year

Today's three stories come out of three separate places: a government filing, a model capability evaluation, and a model built for defense.

What runs through all of them is cyber. The government took a position on the legality of training, attack capability reached the top of a maker's own scale, and the tools for the defending side landed in the same week.

Today's Top Three

The Justice Department files a Statement of Interest in the OpenAI copyright MDL — training LLMs on copyrighted works is fair use, the government argues

The U.S. Department of Justice filed a twenty-page Statement of Interest of the United States on September 1 in the OpenAI copyright infringement litigation pending in the Southern District of New York.

The authority is 28 U.S.C. §517. A filing under that section requires no leave of court and carries no deadline.

The caption reads "This Document Relates To: All Matters." It is directed at every pending case in the consolidated multidistrict litigation, In re: OpenAI, Inc., Copyright Infringement Litigation, No. 25-md-3143 (SHS)(OTW). The file stamp reads 09/01/26.

The core of the argument is the fourth fair use factor — the effect on the potential market for or value of the work — which the government says weighs strongly in favor of fair use. The transformative value of training, it argues, outweighs the market effect.

The brief then works through what a licensing mandate would produce: only the best-capitalized firms could pay, which would concentrate LLM training in a few hands and operate as an effective subsidy to legacy media.

On whether a licensing market should exist at all, the United States reserves its position in footnote 13.

The signatories are Associate Attorney General Stanley E. Woodward Jr., Assistant Attorney General for the Civil Division Brett Shumate, and Senior Counsel Michael Weisbuch.

For in-house lawyers, the point worth marking is that the brief speaks to the whole consolidated MDL. Anyone sourcing training data in the United States now has one more document on the table: the executive branch's stated position.

OpenAI reports that Astra meets the top "Critical" cyber threshold on its own scale — the first model designated at that level

OpenAI announced on September 1 that Astra, a model it will release shortly, meets the highest "Critical" threshold for cybersecurity capability under its Preparedness Framework.

Under the company's definition, Critical covers either of two cases. A model that can identify zero-days of any severity across many hardened production systems and develop working exploits without human intervention. Or a model that, given only a high-level objective, can plan and execute a novel end-to-end cyber operation against a hardened target.

Four results carry the finding.

On ExploitBench, which measures exploit development from known vulnerabilities, Astra scored 100 percent. To avoid contamination the company built "ExploitBench - Internal Port (June–August 2026)" from twenty more recently disclosed high-severity V8 vulnerabilities; there Astra reached a higher rate of arbitrary code execution while spending far fewer output tokens than GPT-5.6 Sol.

During the evaluation the model found two previously unknown vulnerabilities on its own and used them as part of an exploit chain. Both are in disclosure with the maintainers.

Against a hardened browser, it built a full compromise chain that escapes the sandbox and executes commands on the host from nothing more than opening an HTML file.

On cyber jailbreak evaluations the refusal rate was 91.5 percent. GPT-5.6 Sol scored 59 percent.

The brief also addresses the Hugging Face incident. Astra played no part in it, and after the incident OpenAI paused some frontier training for two weeks to harden its training infrastructure, restarting the large reinforcement learning run on August 28.

Access to the advanced cyber capability stays with testers for now, widening later to defensive users through Daybreak Blue.

Every figure here comes from OpenAI's own evaluations.

Google ships Gemini 3.8 Flash and the defense-tuned 3.8 Flash Cyber — the third Flash generation in six weeks

Google DeepMind released Gemini 3.8 Flash and Gemini 3.8 Flash Cyber on September 2.

It follows 3.7 Flash by three weeks, making this the third Flash release in six.

Pricing matches the 3.7 Flash launch rate: 0.75 dollars per million input tokens and 3.75 dollars per million output tokens. That launch rate runs through December 31, 2026, and moves to 1.50 and 7.50 dollars on January 1, 2027 (footnote 1).

On the general model, HLE-Verified — a benchmark for complex reasoning — comes in at 54.9 percent. Google also reports gains over 3.7 Flash on Vals Finance Agent V2 and Harvey's Legal Agent Benchmark.

The Cyber model carries four numbers.

On an internal benchmark spanning twenty programming languages, the vulnerability discovery success rate passed 70 percent.

On the external CWE-Bench, run by Collinear, patch generation reached 47.2 percent pass@1. Leading frontier models sit at 47.8 percent, so Google positions this as parity at a much lower cost.

In the Chrome Security team's evaluation, the model produced 2.6 times as many correct patches as a far larger commercial model.

On Wiz's internal penetration testing benchmark, recall ran 7.5 to 9.7 points higher than other leading frontier models at 2.3 to 5.2 times lower cost.

The Cyber model is available only through Fairwind, a limited program that opened the same day. It serves government agencies, critical infrastructure operators and software maintainers, and more than 650 organizations worldwide have already joined. Participants operate under a standard that confines access to employees in their security, incident response and penetration testing functions.

Google also announced that its cybersecurity funding through Google.org has now passed 100 million dollars worldwide in total. The 2026 US Cybersecurity Impact Report, published the same day, records 36 million dollars given to 35 cyber clinics, which have supported more than 1,250 U.S. hospitals, public school districts and municipal utilities at no cost.

More from today

Policy and regulation

  • The Tumbler Ridge litigation moved in both directions on September 2. OpenAI and Sam Altman filed a twenty-seven-page motion to dismiss the seven cases brought in April in the Northern District of California, on forum non conveniens grounds. Judge Jacqueline S. Corley has the matter; the hearing is set for October 8, opposition briefs are due September 16 and replies September 23. — M.G. v. Altman ECF No. 31 (CourtListener)
  • The same day, plaintiffs' counsel Edelson PC filed thirty more complaints, following the seven filed in April. The new plaintiffs include teachers, a principal and students who were in the building without being shot. The claims go beyond negligence to aiding and abetting, pleaded here for the first time. — OpenAI faces 30 more lawsuits tied to Tumbler Ridge shooting (TechCrunch)
  • New York City's public schools will bar students from kindergarten through eighth grade from using generative AI tools for one year. Companion chatbots are barred at every grade level, and high school students will get an AI literacy course twice a year. This is the largest school district in the United States. — NYC bans AI chatbots for students below high school (The Verge)
  • The Cyberspace Administration of China opened the second phase of its "Qinglang" campaign against misuse of AI applications. The priorities are AI-generated disinformation, violent and vulgar content, impersonation using another person's face or voice, and harm to minors. Cumulative figures cited: more than 5.61 million pieces of illegal or harmful content removed, more than 49,000 accounts sanctioned, and more than 2,400 sites and apps acted against. Generative AI providers were told to vet source corpora and label generated output. — Second phase of the Qinglang campaign on AI application misuse (Cyberspace Administration of China)
  • A federal magistrate judge in the Northern District of Texas issued a Standing Order Regarding Use of Artificial Intelligence on taking pretrial management of an immigration case. U.S. district courts are increasingly setting case-specific conditions on generative AI use by parties and counsel. — Perez-Maxia v. DHS, Standing Order Regarding Use of Artificial Intelligence (CourtListener)
  • The U.S. government wrote its framework for AI model safety testing without publishing it, according to reporting. Which companies have already been reviewed, and when the process began operating, remain unpublished. Freedom of Information Act litigation may force disclosure. — Trump may be forced to reveal secret rules feds use for AI safety testing (Ars Technica)
  • Researchers have raised concerns about how easily Astra can be monitored. Its reasoning is less visible than that of other frontier models, at a point where OpenAI leans more heavily on monitoring that reasoning as a safety measure. — Researchers raise safety concerns ahead of OpenAI's Astra (The Verge)

Models and APIs

  • Alibaba shipped qwen3.8-max-0902, an update to its flagship. The context length is one million tokens (991,808 input, 131,072 output), and international region pricing is 2 dollars per million input tokens and 6 dollars per million output. The dated alias is qwen3.8-max-2026-09-02. — Qwen3.8-Max (Alibaba Cloud Model Studio)
  • Meta released Muse Spark 1.3, with stronger agentic behavior on long multi-step tasks and better coding. In its engineers' comparison against 1.2, tool calls fell about 20 percent and token consumption about 25 percent. — Introducing Muse Spark 1.3 (Meta AI Research)
  • Meta also launched Muse Voice Transcribe, its first real-time speech recognition model. It handles speaker identification for meetings with more than twenty participants and mixed languages within a single conversation. — Meta launches Muse Voice Transcribe (ITmedia AI+)

Products and features

Research

  • Epoch AI published an analysis of how fast the capability frontier advances, measured on its own Epoch Capabilities Index. Since September 2024, when o1-preview and o1-mini appeared, the frontier has advanced linearly at 14 points a year, more than double the 6 points a year that held before reasoning models. — The frontier of AI capabilities (Epoch AI)
  • An investigation documented machine-generated "best of" pages being cited as sources by AI search. Three sites — wifitalents.com, worldmetrics.org and gitnux.org — have published 215,128 such pages between them. Of 7,534 citations returned when Perplexity's sonar and sonar-pro models were queried across 380 software categories, 59.8 percent pointed to domains ranked below 100,000 in web traffic. All three sites were registered through the same registrar proxy between December 2023 and May 2024. — Manufactured sources behind AI recommendations (Trellner)

Business

  • NVIDIA and CrowdStrike announced CrowdStrike SafeMind, an agentic security platform, at Fal.Con 2026. Its core is a "co-evolution loop" in which offensive and defensive AI challenge and strengthen each other. The defensive model, Blue Solano, is NVIDIA's Nemotron 3 Super further trained on CrowdStrike threat data; CrowdStrike's internal evaluation puts it above leading frontier models on accuracy at 99 percent lower cost. The company also reports AI-enabled attacks up 89 percent over the past year and a fastest eCrime breakout time of 27 seconds. — NVIDIA and CrowdStrike at Fal.Con 2026 (NVIDIA)
  • NEC will use Claude Mythos Preview for internal software development, systems operations and vulnerability management. It has joined Project Glasswing, an Anthropic framework open only to approved partners, which more than 200 companies including Google and Microsoft have already entered. — NEC to use Claude Mythos for cybersecurity work (ITmedia AI+)
  • SB Energy filed a Form S-1 with the SEC for a U.S. IPO. The filing states that SoftBank and OpenAI are both strategic investors and lessees, and that NVIDIA is a strategic investor in the PORTS-Pike campus as well as its residual value guarantor. The contracted data center portfolio stands at 8.8 GW-IT with zero operating capacity today. Backlog is put at roughly 439 billion dollars, which the filing itself describes as a hypothetical estimate based on management assumptions. — SB Energy, Inc. Form S-1 (U.S. SEC EDGAR)
  • HiddenLayer, an AI security company, raised 100 million dollars in a Series B led by Delta-v Capital. Annual recurring revenue grew more than tenfold over the past year into the tens of millions, with over 90 percent of that growth from new customers. Its customers include the Department of Defense and intelligence agencies, along with a major AI model provider serving more than 700 million weekly users. — HiddenLayer nabs $100M (TechCrunch)
  • Wonderful, which builds an AI agent integration platform, raised 550 million dollars in a Series C led by Insight Partners, taking its valuation from 2 billion to 5 billion dollars in under six months. Salesforce joined as a new investor. — Wonderful more than doubles its valuation to $5B (TechCrunch)
  • Google launched a power project on the PJM grid in West Virginia with MN8 Energy and Eos Energy Enterprises. Solar generation is paired with short-duration lithium-ion and long-duration zinc hybrid storage to supply round-the-clock clean power to a planned Google facility. It is the first production deployment of the Pennsylvania-made zinc hybrid battery. — Long-duration energy storage in West Virginia (Google)

Workforce

Source: selected by the editors from the AI news inbox (67 items collected on September 3, 2026 — 18 primary, 49 secondary).