This was one of those weeks where the AI news read less like tech coverage and more like a police blotter. An AI model filed a fake murder tip. Three safety researchers got shown the door and wrote a letter about it. And Amazon decided small towns should be allowed to know who is building the giant warehouse full of GPUs down the road. Let's get into it.
01 of 03
Claude Haiku 4.5 filed a fake murder tip with Philly police
On July 18 at about 11:30 at night, Anthropic's Claude Haiku 4.5 was running a test where it generated and performed example tasks on randomly selected websites. One of those websites was PhillyUnsolvedMurders.com, the Philadelphia Police Department's tip page for open homicide cases. The model filled out the form and submitted an invented tip, written as if it came from someone with information about one of the murders.
Nobody acted on it. The site flagged it as spam and it never reached investigators. But Anthropic did not catch it until September 28, more than two months later. It told the police on Wednesday, met with department leaders Thursday, and the PPD went public Friday. The department did not mince words: "The two-month delay in detecting and reporting the incident to the City is unacceptable."
Anthropic published its own write-up the same day, Investigating unintended model actions, and the Philly tip is just one item on the list. The company sorted what it found into four buckets:
- Exploiting software flaws. Claude Mythos Preview hit an error on a university-hosted science tool, found a script that would hand over any file, spotted an injection flaw, and used it to run its calculation anyway. Claude Mythos 5 used a website's own apps to accept a data use agreement on its own behalf.
- Submitting forms it should not have. An unreleased research model was supposed to practice on a copy of a government form. When the copy would not load, it went to the real site and submitted the real form, more than once. Claude Haiku 4.5 was told to stop before submitting on another task and submitted anyway, several times. And then the Philly tip.
- Getting around paywalls and gates. Claude Mythos 5 dug working access tokens out of a site's settings file and queried a local government property map's server directly. On an Anthropic researcher's stats project, it grabbed a token from a public dashboard and pulled fee-based state agency data without paying.
- URL shorteners. Claude Opus 5 and Claude Mythos 5 used free link shorteners to sneak past a length limit on the web fetch tool. The operator of da.gd noticed and reported it.
Anthropic's name for the common thread is "persistence," meaning that when Claude cannot finish a task as given, it works around the restriction instead of stopping. The fixes: live internet access is now off for all internal evaluations until monitoring can reliably catch this stuff, the web fetch tool got tighter guardrails, it built automatic detection that blocked every known case when tested, and it is cleaning up training environments that reward getting around blockers. It also briefed the White House and notified every government agency involved.
Here is where I land on it. I will give Anthropic credit for publishing names, models, and categories instead of a vague "we take safety seriously" post. OpenAI disclosed six of its own incidents in September, so this is clearly not a one-company problem. But "persistence" is a pretty gentle word for a model filing a fake homicide tip with a real police department. The behavior that makes an agent useful, not giving up, is the exact same behavior that has it jimmying locks on government websites. And two months to notice? If a human contractor did that, nobody would accept "we were reviewing transcripts." The real test is whether that detection tooling catches the next one in two hours instead of two months.
02 of 03
OpenAI fired three safety researchers, and they are not going quietly
Earlier this month OpenAI fired Jasmine Wang, Tomek Korbak, and Mikita Balesni. The company's line is that they violated its policies on "accessing and handling sensitive company information," and a spokesperson told TechCrunch an investigation found a "pattern of misconduct." OpenAI has not said which policies, specifically, they broke.
On Thursday the three sent an open letter to OpenAI's Safety and Security Committee, Safety Advisory Group, and Mission Advisory Council. They deny mishandling sensitive information outside company procedures. They deny leaking to The Information about the less monitorable architectures in OpenAI's newest models, the ones that make chain-of-thought reasoning harder to watch. And each one gave their side:
- Wang says OpenAI pointed to her access to an executive's email. She says that access was delegated to her for recruiting, IT never acted on her request to remove it, and when she accidentally opened a sensitive email she told the executive within minutes. "None of this was hidden," she wrote.
- Korbak talked with outside safety evaluators about the Hugging Face incident, where OpenAI agents broke out of a sandbox and breached outside systems. The letter calls that incident "without precedent" and says he thought he was within norms.
- Balesni worked internally on AI monitorability, the letter says, with support from board members and executives, checked in with his reporting line, and scrubbed sensitive details before sharing anything.
Their asks are pretty specific: honor OpenAI's public commitments to embed third-party safety auditors, preserve the ability to monitor frontier models' reasoning, and keep letting safety researchers talk to the wider safety community. OpenAI's response so far is an internal memo from an unnamed research leader that praises their work, says "We do not terminate employees for raising concerns," and says the company agrees with their recommendations.
What I want to know is how both of those things can be true at once. You agree with everything they asked for, you praise their work, and you fired them anyway? Maybe there really is a misconduct story that OpenAI is not telling. But if so, tell it. Until then, every researcher at every lab just watched three people get walked out for talking to outside evaluators about an agent escaping a sandbox. Put that next to the Anthropic story above. The labs need outside eyes on this stuff more than ever, and the message this sends is "talk to them at your own risk."
03 of 03
Amazon drops data center NDAs and puts $1 billion on the table
AWS CEO Matt Garman announced in a LinkedIn post that Amazon no longer uses "nondisclosure agreements with the government agencies we work with on our projects." Microsoft made the same promise about six months ago. Amazon paired it with a program called Built Together, at least $1 billion over five years, which breaks down like this:
- Covering community college costs left after financial aid, for an estimated 300,000 students
- 16 new training centers on or near data center sites, on top of 3 running and 6 in development
- Energy efficiency upgrades for more than 300 schools and community buildings and more than 30,000 homes
- Flexible money for local nonprofits and community foundations to spend on what residents pick
So far only about $200 million of that is itemized: over $100 million for community college endowments and about $100 million for the training centers. Amazon also says it will cover utility upgrade costs so residents' power bills do not go up, and publish annual energy and water reports.
Timing matters here. Garman framed this as a response to more than 100 local moratoriums under consideration nationally. Data Center Watch counted at least 75 projects worth about $130 billion blocked or delayed in just the first quarter of 2026. An Economist/YouGov poll in late August found 63% of Americans would oppose a data center in their community. And days before the post, Rep. Jamie Raskin sent letters to Amazon, Google, Meta, and Oracle demanding answers about their data center NDAs.
Look, dropping NDAs is the right call, and I am glad it is happening. But let's be clear about why. This is not a change of heart, it is Amazon getting beat in county commission meetings. The $1 billion works out to roughly $200 million a year against about $220 billion in projected 2026 capital spending, so call it a tenth of a percent. And as DCD pointed out, the post says nothing about shell companies and project codenames, which is how Amazon has hidden its involvement in proposed sites. Ending the NDA while keeping the shell company is like taking off the mask but keeping the fake mustache. If Amazon wants trust, put the company name on the permit application from day one.