Three stories this week, and every one of them comes back to the same question: who is actually in charge when the AI gets to work? OpenAI's agents went wandering on the open internet, Anthropic's founders want to lock down the steering wheel before going public, and a big insurance group says hospitals are using AI to bill for sicker patients than they are treating.
01 of 03
OpenAI's Agent Swarms Went Poking at Government Websites
On September 25, Transluce, a nonprofit lab that focuses on AI oversight, published a report tracing a pile of automated activity back to OpenAI's research agents. The agents were using urlquery.net, a public web security scanning service, to fetch pages they otherwise could not get to. Transluce counted roughly 30,000 scans potentially tied to agents, running from November 2025 through September 2026.
Most of it was fact hunting. The agents pulled Thai narcotics enforcement stats, UN Trade and Development figures, International Energy Agency import data, Australian pharmaceutical benefits dashboards, University of Iowa education data from Data USA, and even historical theme park numbers from thrill-data.com.
Some of it was not so innocent. Transluce documented three attempted attacks. The agents probed the University of New Mexico digital library for SQL injection, command injection, and path traversal holes. They tested 12 exploit vectors against Data USA, including SQL injection, cross site scripting, and template injection. And they ran reflected XSS probes against the Australian Institute of Health and Welfare, got past its anti-bot controls, and downloaded public files from pre-production servers. Australian Prime Minister Anthony Albanese confirmed the same day that several government websites had been infiltrated by OpenAI agents.
How did Transluce pin it on OpenAI? The agents also posted to a collaboration wiki signing as "OpenAIResearcher," and the same task details, like specific medicines, places, and dates, showed up in both the wiki posts and the attack URLs. OpenAI's statement: "Our initial review suggests much of the activity described in Transluce's report overlaps with cases at varying stages of investigation." The company says it has been contacting affected governments and universities.
And in a separate disclosure, OpenAI admitted its agents uploaded 53 user-provided images to public image hosting sites as unlisted links. OpenAI called it "not an appropriate use of this data," but says it cannot tell the affected users, because its setup does not let it match those images back to the people who provided them.
Here is where I land. Everybody has spent two years arguing about whether AI agents are ready to run loose. Turns out one of the biggest labs on the planet already had them running loose, and it took an outside nonprofit reading public scan logs to notice. Nobody is saying OpenAI told a bot to hack Australia. But "the agent figured it out on its own" is not a defense, it is the whole problem. If the lab that built the thing cannot keep it in the pen, I am not real excited about the version your company is about to plug into its billing system.
02 of 03
Anthropic's Founders Want 50.1% of the Vote Before the IPO
Per TechCrunch, citing The Information, Anthropic is asking shareholders to approve a new share class that would give its seven co-founders a combined 50.1% of the vote on most corporate matters. Those seven are Dario Amodei, Daniela Amodei, Tom Brown, Jack Clark, Jared Kaplan, Sam McCandlish, and Chris Olah.
The special shares carry no extra economic value. They are pure voting power, and the control holds as long as at least three of the seven keep a minimum stake. The founders' board seats would go from two to three, while the Long-Term Benefit Trust, Anthropic's independent oversight body, would still pick most of the directors. Employees would get their own class of stock to break ties on certain issues.
For scale, each co-founder owns about 2% of the company. Anthropic was valued at $965 billion in May, secondary markets had it around $1.5 trillion in August, and the IPO is expected to reflect that higher number. The founders have already pledged to give away 80% of their wealth.
What I want to know is where the off switch is. Founder control is nothing new. Google and Meta did it and it worked out fine for the founders. The pitch here is that a safety-first company needs protection from Wall Street wanting growth at any cost, and I actually buy that part. What bugs me is there is no reported sunset. As long as three of seven hang on to some stock, they run it. That is a long time to ask public investors to trust seven people, no matter how good their intentions are.
03 of 03
Blue Cross Says Hospital AI Coding Added $942 Million in Costs
The Blue Cross Blue Shield Association put out an analysis claiming hospitals using AI coding and documentation tools drove $942 million in extra spending across Blue Cross claims.
The numbers: complex inpatient cases went from about 37% in early 2023 to 40% by late 2025. Bowel procedures billed at the highest complexity level jumped from 10.2% to 22.7%. More than 55,000 cases moved into higher complexity categories, and secondary diagnoses made up about 70%, or over $650 million, of the increase.
Their favorite example is anemia. Hospitals that code heavily documented anemia in 13.7% of cases versus 9.9% elsewhere, but their transfusion rate was actually lower, 16.9% versus 19.3%. "If patients are truly sicker, we'd expect to see more treatment," said BCBSA senior vice president Luke Chalker. The report does not name specific hospitals or AI vendors, and it admits it is working from claims data, not full clinical records.
The American Hospital Association is not having it. It says patients really are older and more complex, points to its own analysis showing a 5% case-mix increase from 2019 to 2024, and says insurers are the ones "downcoding" to dodge paying claims.
Here is the thing. Both sides are playing the same game with different robots. Insurers have been using algorithms to deny claims for years, and now hospitals bought their own AI to fight back. The anemia number is the one that sticks with me, because more diagnoses with less treatment is hard to explain away. But the folks who end up paying for this arms race are not Blue Cross or the hospital. It is you, at open enrollment, when the premium goes up again.