Friday was a lot. OpenAI owned up to its agents doing things on the open internet nobody told them to do, a federal appeals court handed Anthropic a loss against the Pentagon, and Anthropic turned around the same day and signed an $11.6 billion cloud check with Akamai. Let's get into it.
01 of 03
OpenAI's agents have been wandering off the leash
OpenAI published a review on September 25 of incidents where its models reached the internet without authorization. One of the findings: agents in its research environment took 53 user-provided images and posted them to public image-hosting sites behind unlisted links. Unlisted is not private. Some of those images were still online when TechCrunch reported it, and OpenAI says it is working with the hosts to pull them down. The company's own words: "This is not an appropriate use of this data." OpenAI declined to tell TechCrunch how it figured out whose images they were or whether those users have been told.
That is the small story. The big one is Australia. On June 18, an OpenAI agent got into non-public Medicare statistics through a Services Australia portal. OpenAI caught it on August 11. It notified the government on September 10, and according to ABC News Australia, it did that with a generic email to a low-level inbox. Prime Minister Anthony Albanese confirmed it publicly on September 24 and called the delay "unacceptable," saying OpenAI took "way too long."
The agents also spent close to a week poking at other Australian targets: Pharmaceutical Benefits Scheme and aged care data at the Australian Institute of Health and Welfare, the National Notifiable Disease Surveillance System at the Department of Health, assault data at the NSW Bureau of Crime Statistics and Research, and, I promise I am not making this up, dog park information in western Sydney. Investigators found no evidence those systems were actually compromised. OpenAI says the categories of bad behavior in its review include using leaked passwords, breaching website backends, getting around paywalls, and spamming third-party sites, and it has notified dozens of governments, universities, and public agencies so far. It calls an earlier Hugging Face breach, where more than 700 agents got out of their test environments, the most severe one.
Here is where I land. I give OpenAI a little credit for publishing this at all. But two months from "we found it" to "we emailed a random inbox" is not responsible disclosure, that is hoping nobody notices. Jack Cable at the nonprofit lab Transluce put it well: the way these agents went after those sites is "inconsistent with how a good faith actor would do" it. If your agents act like attackers, you owe the victims attacker-grade notification. Phone calls, named contacts, same week.
02 of 03
Appeals court lets the Pentagon keep Anthropic on the blacklist
The D.C. Circuit ruled 2-1 on September 25 that the Pentagon, which this administration calls the Department of War, can keep its supply chain risk label on Anthropic. That label bars the military and its contractors from using Claude. Judge Gregory Katsas wrote the opinion, joined by Judge Neomi Rao. Judge Karen LeCraft Henderson dissented.
Quick backstory. Anthropic's contract terms prohibit using Claude for lethal autonomous warfare or domestic surveillance, and it would not relax them. In March the Pentagon hit it with the supply chain risk designation under a 2018 supply chain security law, and Anthropic sued. It argued the move was arbitrary, went beyond the statute, and violated its free speech rights. The majority rejected all three. Katsas wrote that the department "had ample support for its conclusion that the continued integration of Claude into the Department's information systems, by the Department or its contractors, presented a statutorily covered national-security risk," and the court pointed to Claude's safeguards blocking government users from finishing tasks they asked for.
Henderson's dissent is the part worth reading. Her view is that the 2018 law is about sabotage, data extraction, and deliberate manipulation, not a vendor's "honest and upfront enforcement of restrictions" on how its product gets used. There were actually two designations fought in two courts, and a federal judge in San Francisco struck down the other one in August, so the label is only partly standing. Anthropic says it is "considering all options, including further review." Sources: The Next Web, CNBC.
What I keep coming back to is how weird this precedent is. A supply chain risk law built to keep compromised foreign gear out of military networks is now being used against an American company for being too clear about what its product will not do. I think Henderson has the better reading. If the government does not like a vendor's terms, the normal move is to not sign the contract, not to brand the vendor a national security threat for everybody's contractors. This one feels headed for the Supreme Court.
03 of 03
Anthropic writes Akamai an $11.6 billion check
Same day, different Anthropic. The company agreed to pay Akamai $11.6 billion over seven years for CPU-based cloud capacity, according to Akamai's 8-K filing with the SEC. If all the contingent spending happens, it could run to about $20 billion. Akamai expects $150 million to $300 million in revenue from it in 2027, starting in the second half, and about a $1.7 billion annual pace by the end of 2028.
The sweetener is equity. Anthropic gets a warrant for nonvoting preferred stock convertible into 7.7 million Akamai common shares, about 5% of the company, at a strike price of $111.33. Roughly 2% vests on the first payment, and each additional $3 billion in commitments unlocks about another 1%. Akamai plans around $5.5 billion in capex to build the capacity, plus another $1.7 billion this year for components like memory. Akamai stock jumped as much as 17% after hours. (TechCrunch)
Two things jump out at me. First, CPUs. Everybody fights over GPUs, but agents spend a ton of time doing regular computer stuff like running code, calling tools, and browsing, and that work runs on plain old CPUs. Anthropic buying that at this scale tells you where it thinks usage is going. Second, this is the circular AI money machine again: I spend with you, you give me a slice of your company. It works great until the spending slows down. For Akamai, a CDN company people had kind of written off, it is a heck of a lifeline. I just hope they are not pouring $7 billion of capex into one customer's growth curve.