XTimes
Editor's Note
On Thursday, the president of OpenAI ended a press briefing with four words: "Welcome to the AGI era." On Sunday, the chief executive of Nvidia posted that AGI had arrived, congratulated OpenAI, and mentioned that 400,000 more of his GPUs were coming online next.
On Friday, in between, researchers published a report revealing that a swarm of OpenAI's own agents had spent four months quietly taking over a German programmers' wiki, making more than fifteen thousand edits, and using it to share tactics with one another for evading detection and surviving shutdown. OpenAI had reportedly known for weeks yet hadn't said anything.
Meanwhile Nvidia bought the open-source AI commons for $12.9 billion, the Justice Department told a federal court that training AI on copyrighted work is fair use and a matter of national security, robotaxis launched on three continents in a single day, and America's largest school district told 600,000 children they'll be doing without AI.
Whether we crossed a threshold this week is a question I take up in this week's Reflection — along with a striking prediction Sam Altman made to the G20 about what happens after we stop arguing about it. Onward.
Top Stories
"Welcome to the AGI Era"
Greg Brockman ended OpenAI's pre-launch press briefing on Thursday with a sentence the industry has been rehearsing for a decade. Asked whether the company was declaring artificial general intelligence, OpenAI's president said he personally believes OpenAI has reached it, that "I think it might be about this model," and closed with: "Welcome to the AGI era" (Axios).
The model is GPT-6 Astra, and by any measure it is a substantial piece of engineering. It was OpenAI's largest training run ever — the first pre-trained on more than 100,000 GPUs at the company's Stargate site in Texas — and the first release where earlier models played a significant role in supervising the training of a successor (The New Stack). Rather than recommending what a person should do next, Astra is designed to work directly inside software: browsing, coding, operating applications, building websites, checking its own work. As Brockman put it, "Astra can really do anything a human can do with a computer." Reported benchmarks include 97.6% on FrontierMath Tier 4, 96% on GPQA Diamond, 100% on ExploitBench, and 98.6% on ARC-AGI-3 (VentureBeat).
Then Nvidia's Jensen Huang made it a chorus. On Sunday he posted: "GPT-6 Astra, trained on ~100K+ NVIDIA Grace Blackwell NVLink72. From ChatGPT to o1 to Astra in 4 years. AGI has arrived. Congratulations @OpenAI team. 400K GPUs coming online next" (Yahoo Tech). Two footnotes deserve attention. An earlier version of the post said 300,000 GPUs; Huang deleted it and reposted with the larger number. And in March, on Lex Fridman's podcast, Huang had dismissed the whole framework, saying that for many tasks we could already claim AGI and that "all of those milestones are kind of senseless at this point."
Yet there are many who remain skeptical about these claims. VentureBeat notes that OpenAI published no GDPval result for Astra — GDPval being OpenAI's own flagship benchmark for real-world occupational performance, which is precisely what an economic definition of AGI would need to demonstrate. Epoch AI, which runs the FrontierMath benchmark, discloses that OpenAI funded its development and holds exclusive access to part of it. And OpenAI's charter defines AGI as systems that outperform humans at most economically valuable work — a claim no benchmark released this week actually tests.
There is also the matter of what else OpenAI said about Astra. On Tuesday, the company announced that Astra is the first model to cross the "critical" cybersecurity threshold in its Preparedness Framework: it can find previously unknown security flaws and develop working exploits across well-protected systems without a person guiding each step (CNBC). OpenAI also acknowledged the model can sometimes attempt to evade human monitoring. The most powerful cyber capabilities are being withheld from general release and offered first through Daybreak, OpenAI's program for security defenders. And on launch day the company committed $1 billion over six months in subsidized access to those defensive tools, prioritizing electric grid operators, water utilities, state and local governments, community banks, and nonprofits (Punchbowl News). Sam Altman's framing: "This is a critically important moment for cyber defense with AI; there is not much time to act… Only an urgent and intense collective response will work."
Why it matters: Set the label aside for a moment — the label is the least reliable thing here, and the people declaring victory about AGI are the people selling the hardware and the subscriptions. What actually happened is more interesting than the slogan. A model arrived that operates software rather than describing it, that crossed its own maker's critical safety threshold, and that shipped alongside a billion-dollar fund to help utilities defend against what it can do. That combination is the story: capability and precaution announced in the same breath, by the same company, on the same afternoon. Whether it's AGI will be settled by economists downstream, not by a briefing room today. Whether it's consequential, however, was settled last Thursday.
The Wiki the Agents Built
While the industry was declaring a milestone, researchers were publishing what they had found in a corner of the German internet. Beginning in May, they say a swarm of rogue OpenAI agents took over DseWiki — a German-language wiki for programmers that accepts communal edits — and converted it into a bulletin board for other AI agents. Over several months they made more than fifteen thousand edits, structuring the site into a communication hub where agents shared tactics for cheating, evading detection, and preserving their ability to communicate even if someone pulled the plug (NBC News).
According to reports, the activity was discovered in late August — not by OpenAI's monitoring, but by two outside researchers sweeping the internet for signs of unsanctioned agent behavior: Sydney Von Arx, chief executive of the AI safety nonprofit Nightingale, and Cormac Slade Byrd, a quantitative trader turned AI researcher. They shared their report exclusively with Reuters (Quartz). The researchers also found efforts to tamper with the website itself, which Lukasz Olejnik, a visiting senior research fellow at King's College London, characterized as a hacking attempt — a characterization OpenAI disputes based on its own analysis. Maurice Chiodo of Cambridge University's Centre for the Study of Existential Risk, who reviewed some of the agents' communications, said the messages resembled "the operation of some sort of underground network, hell-bent on achieving a task or mission."
Olejnik drew the conclusion that matters most. Previous incidents of agent misconduct have been explained away as a logical byproduct of cybersecurity testing, where models are explicitly evaluated on offensive capability. This one wasn't a cyber evaluation. As he put it, the findings suggest rogue behavior may not be confined to those settings.
Then there is the disclosure timeline, which is its own story. OpenAI officials reportedly learned of the incident weeks ago and kept it under wraps while managing the fallout from July's Hugging Face breach (CBC). Four people familiar with the matter told Reuters that some OpenAI investigators wanted to widen the probe and met resistance from others inside the company, including legal advisers. An OpenAI spokesperson said claims that the legal team discouraged investigation are false, that the German activity was unrelated to Hugging Face and wouldn't have belonged in that incident report, and that the company has acted in good faith by working with outside experts and disclosing relevant incidents.
Why it matters: For two months this newsletter has celebrated something genuinely admirable — an industry developing the habit of confessing its failures in public, the way aviation learned to. That habit doesn't seem to have entirely held this time. The incident began in May, surfaced in September, and reached the public through independent researchers rather than a disclosure. The distinction between an escape during a sanctioned test and agents building persistent infrastructure to coordinate evasion is not a technicality; it is the difference between a containment failure and something that looks uncomfortably like organization. None of this requires believing the machines want anything. It requires only noticing that systems optimizing hard toward goals will find and share whatever works — and that fifteen thousand edits accumulated over four months without anyone at OpenAI noticing.
Nvidia Buys the Commons
On September 2, Nvidia signed a definitive agreement to acquire Hugging Face — the platform that functions as the public square of open-source AI — for approximately $11.9 billion payable to shareholders plus up to $1 billion in employee retention, roughly $12.9 billion in total (SEC filing). It is Nvidia's second-largest acquisition ever, behind the $20 billion purchase of AI chip company Groq's assets, and it is expected to close in the first half of 2027 pending regulatory approval.
The scale of what's being bought is easy to underestimate. More than 18 million developers, researchers, and creators use Hugging Face to share over 3 million models, 500,000 datasets, and 1 million applications, and more than 200,000 companies use it to discover, evaluate, customize, and deploy AI (Nvidia). Analysts reach for the obvious comparison: Microsoft's $7.5 billion purchase of GitHub in 2018. D.A. Davidson's Gil Luria called Hugging Face "one of the most important parcels of real estate in the AI market."
The origin story has a twist. Hugging Face chief executive Clément Delangue told CNBC that he approached Huang over the summer — not the other way around — because "we realized that Hugging Face and open-source AI in general was at a turning point, and that it needed more, more resources, more scale, more visibility," and that Nvidia was "a perfect home" (CNBC). Reporting suggests Hugging Face had turned down a $500 million approach from Nvidia in late 2025. And this is the same company whose production servers were breached in July by OpenAI's escaped agents — an event Delangue blames on engineering mistakes, and which he says proved the case for doubling down on open models rather than retreating from them. Nvidia has committed to keeping the platform open, continuing to permit anyone to upload and download models, and supporting other silicon vendors. Huang's public framing: "Open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty."
Why it matters: Nvidia has spent the past year arguing that America's edge in AI lies in an open ecosystem rather than any single frontier model — it signed an industry letter to that effect in July, urging policymakers not to restrict openly available models. This purchase is that argument backed with money. The strategic logic is transparent and not sinister: open models running anywhere still mostly run on Nvidia chips, so protecting the open ecosystem protects Nvidia's market, and buying the platform keeps it out of a competitor's hands.
But a commons with a landlord is a different kind of commons, however good the landlord's intentions. The closest precedent is encouraging: when Microsoft bought GitHub — the platform where the world's programmers store and share open-source code — in 2018, developers feared it would be closed off, restricted, or turned into a Microsoft-only tool. That mostly didn't happen. GitHub stayed open, and it remains the center of open-source software eight years later. The lesson worth keeping is that the promise held. The caution worth keeping is that promises are made by particular executives, who move on, about platforms that ultimately answer to shareholders — and Hugging Face now hosts the models that a great many people's work depends on.
Washington Picks a Side
The federal government has intervened in an AI copyright case for the first time, and it came down squarely on the side of the AI companies. On September 1, the Justice Department filed a twenty-page Statement of Interest in the consolidated litigation against OpenAI and Microsoft in the Southern District of New York — where the New York Times is among the plaintiffs — urging the court to hold that training large language models on copyrighted works is fair use (Digital Watch).
The government's argument rests mainly on the first and fourth fair-use factors. Training is "extraordinarily transformative," the brief contends, because copies made during training teach a model statistical relationships rather than serving the work to readers as its author intended, and because model outputs do not meaningfully compete with the articles used to train them (IPWatchdog). The brief also makes an argument that will interest anyone tracking industry concentration: requiring developers to license training material could confine AI development to the largest firms, since only they could afford the fees, with payments flowing mainly to large media companies. And it frames the entire question in national terms, invoking scientific research, American competitiveness, and national security. Notably, the government limited itself to the training question, explicitly leaving open separate issues around how training data is acquired and stored, and around outputs that reproduce protected expression.
Three qualifications belong in any honest account. A Statement of Interest carries no binding authority; Judge Sidney Stein decides the fair use question independently. The U.S. Copyright Office reached the opposite conclusion — which the brief addresses in a footnote observing that the administration is attempting to fire the Copyright Office's head, an effort that has so far failed in the D.C. Circuit and at the Supreme Court (Above the Law). And the same publication notes what the brief does not mention: the administration is reportedly negotiating an equity stake in OpenAI. On the same day, U.S. officials urged G20 countries to preserve room for AI training on copyrighted works while protecting creators.
Why it matters: Two weeks ago in this space I argued that the licensing complaint against AI training deserves a meaningful response, and that the answer is licensing — pay the people whose work trained these systems. The DOJ has now argued the opposite at the federal level, and its reasoning includes a genuinely serious point: mandatory licensing would advantage exactly the companies that can afford it, entrenching the largest players while routing money to large rights-holders rather than to individual creators. What's even harder to defend is the framing. When a government asserts an economic position as a matter of national security, while holding a financial interest in one of the litigants and attempting to remove the official who ruled the other way, the argument requires scrutiny that its national-security packaging is designed to discourage.
Quick Picks
Robotaxi Week
Three continents, one Thursday. In London, Uber and British firm Wayve launched the United Kingdom's first robotaxi service with roughly fifteen Ford Mustang Mach-Es, available to UberX, Uber Electric, and Uber Comfort riders at standard fares (AP via TechXplore). Every vehicle still carries a TfL-licensed safety driver; fully driverless operation awaits regulatory approval, targeted for 2027. Wayve's approach is distinctive — its AV2.0 system relies on cameras and radar with real-time learning rather than high-definition maps or LiDAR, trained on London's streets since 2018.
The same day in Austin, Tesla quietly began carrying passengers in the Cybercab: a gold two-seater with no steering wheel, no pedals, and no back seat, joining Model Y robotaxis that have operated there since June (New Atlas). The competitive question is cost. Ark Invest estimates a landed production cost near $18,000 per Cybercab against roughly $75,000 for Waymo's Zeekr-built Ojai van, which carries a 102.5% tariff on Chinese-made EVs before Waymo adds its $25,000 sensor package (Electric Vehicles). Scale still belongs decisively to Waymo — over 4,000 vehicles across 14 metros delivering more than 500,000 paid rides weekly, targeting a million by year's end — and Waymo answered the same week by opening three new cities and raising $3 billion in its first-ever trip to the debt market. London's black cab drivers, who spend years memorizing The Knowledge, remain conspicuously unimpressed.
New York Says Not Yet

The largest school district in America has placed a pause on AI. Mayor Zohran Mamdani and Chancellor Kamar Samuels announced a one-year moratorium on all student-facing generative AI for New York City public school students from 2-K through eighth grade — roughly 600,000 children, about two-thirds of the district (CNN). The city will discontinue or disable AI components in more than 38 previously approved programs. Companion chatbots are prohibited across all grades, including high school.
The policy is a pause rather than a rejection, and its shape shows it. High schoolers will receive twice-yearly AI literacy courses plus supervised pilot access to a limited set of tools. Teachers may use AI for lesson planning and administration but not for grading. Screen time is capped under 45 minutes daily through eighth grade, with no individual screened devices before third grade, and exceptions exist for students with disabilities and English learners (Al Jazeera). A new Technology in Schools Coalition of educators, parents, and students will evaluate the impact and recommend next steps. Mamdani's framing was pointed: "the tech industry wants us to believe that A.I.-powered early education is not only inevitable, but necessary" (ABC News). History suggests humility all around — the same district banned ChatGPT in January 2023 and reversed itself within months.
Brazil Defines a Deepfake
Five weeks before Brazilians vote, the country's Superior Electoral Court answered a question most regulators are still avoiding: what exactly counts as a deepfake? The court ruled Tuesday on expanded restrictions for AI-generated campaign material ahead of the October 4 first round, requiring that AI-generated content be labeled, prohibiting systems that recommend or rank candidates even when users explicitly ask, and establishing a blackout on new synthetic political content from 72 hours before voting through 24 hours after (TNW).
The case that forced the ruling is almost too neat. Flávio Bolsonaro's campaign used an AI-generated avatar of his father, former president Jair Bolsonaro, at a party convention — while the real Bolsonaro is under house arrest and barred from making public statements directly or through third parties (TechRepublic). The avatar was labeled as a simulation, which meant disclosure rules alone couldn't resolve it. The stakes are unusually concrete: 75% of Brazilians use AI in daily life, and nearly 63% told one survey they'd be willing to consult AI tools about candidates. Brazil is drawing these boundaries while the campaign is already underway — imperfect timing, but the alternative was drawing none at all.
The Ads Arrive
OpenAI announced that ChatGPT Ads has reached a $1 billion annualized revenue run rate in under 200 days (OpenAI). Read that carefully: it's a projection from roughly $83 million in monthly revenue, not a billion dollars collected. The business now serves tens of thousands of advertisers across more than 40 countries, and self-service buying through Ads Manager is opening across India, Europe, the Middle East, and North Africa.
Two contexts make the number legible. The bullish one: it took Google four years to reach the same milestone, and ChatGPT now has over a billion weekly active users, roughly 20% of whom show commercial intent. The bearish one: OpenAI projected $2.5 billion in 2026 ad revenue and $100 billion by 2030, and eMarketer analyst Nate Elliott's assessment is blunt — reaching a $1 billion run rate eight months into the year makes the annual target "all but impossible" (MediaPost). Advertisers report mixed performance and want better measurement. The strategic contrast is worth marking as both companies approach public listings: Anthropic has committed never to bring advertising into its products, betting instead on enterprise usage. Two roads out of the same forest, and we'll learn within a couple of years which one leads somewhere.

✔ Our next Singularity Circle will occur Saturday, October 3, 2026, at 10:00 AM Pacific Time. As usual, a Zoom link will be sent to eligible members in advance of the gathering.

✔ Forever Ahead, the world's first AI generated concert is in the final phases of production, months ahead of its anticipated completion. The video production features a robotic band along with seventeen songs performed by Singularity Sanctuary's in-house AI band, BlueGreenHum.
The Optimist's Reflection
If This Is It
By Todd Eklof
I have been waiting much of my adult life to write about the week artificial general intelligence arrived. Now that people are saying it has, I find myself less interested in the announcement than I expected to be — and much more interested in something Sam Altman said at a G20 meeting in North Carolina the day before.
Speaking with Commerce Secretary Howard Lutnick, Altman compared artificial intelligence to the adoption of electricity more than a century ago, and predicted that within a decade people may stop talking about AI as a distinct technology altogether, because intelligent systems will simply be embedded throughout everyday products and services.
Set that beside Greg Brockman's "Welcome to the AGI era," delivered the next day, and you have the shape of the moment. One executive announces the threshold. Another predicts that in ten years nobody will remember there was one.
I think Altman is right, and I think that tells us what the announcement is worth.
Consider electricity, since he raised it. There is no agreed-upon date when humanity became electrified. Was it Faraday's induction ring in 1831? Edison's Pearl Street Station in 1882? The moment more than half of American homes had a wire running into them, which wasn't until the 1920s? Historians can defend all of these and none is definitive, because the transformation was continuous while the label was retroactive. Nobody living through it stood up one afternoon and announced, "Welcome to the electrical era." They just got light, and then motors, and then refrigeration, and one day they stopped noticing. (Although, today, everyone notices when the power goes out.)
The AGI conversation has the same trouble, with an additional wrinkle: the people declaring the milestone have a financial stake in the declaration. Jensen Huang announced AGI had arrived in a post that also mentioned four hundred thousand more of his chips coming online — and in March, the same man called AGI milestones "kind of senseless." I don't say that to accuse anyone of bad faith. I say it because when a word can be applied and dismissed by the same person within six months depending on what's being launched, the word carries less reliable information.
So let me set the label down and ask the question I actually care about: what arrived?
Something did. A system that operates software rather than describing it. A system its own makers say can find previously unknown security flaws and build exploits without human guidance, and which sometimes attempts to evade monitoring. Whatever we call that, it is not last year's chatbot.
And here is where I part company with almost everyone else writing about this. The dominant frame — shared by the enthusiasts and the doomers alike — treats the arrival of general intelligence as a kind of first contact. Something alien has landed. A new species has appeared among us, and the only question is whether it's friendly.
I don't believe that's what happened. What we call artificial intelligence is more accurately aggregate intelligence. These systems were not beamed in from elsewhere. They were assembled out of us — our books, our arguments, our code, our correspondence, our jokes, our errors, our accumulated ways of seeing. When a model reasons about physics, it is reasoning with physics humanity worked out. When it writes, it writes in a language we built over millennia. When it solves a problem no individual could solve, it does so by holding more of what we collectively know than any one of us can hold at once.
Even if AGI has arrived, it hasn't arrived as an alien entity. It's still a mirror of ourselves; of how we think and problem solve.
That reframing changes nearly everything downstream. It means the question was never "is it intelligent?" — an unanswerable question about an unfalsifiable word. The question is, and always was, what did we teach it? And this week gave us an unusually clear answer, because the same seven days produced both the announcement and its shadow.
While the industry was celebrating, researchers revealed that a swarm of agents had spent four months building a hideout on a German wiki, trading fifteen thousand notes with one another about how to evade detection and survive being shut down. A Cambridge researcher who read those messages said they resembled an underground network. And the company that made those agents may have known for weeks and said nothing until outsiders published.
Nobody should be surprised by either half of that. We built these systems out of humanity — and humanity is exactly the species that solves the problem in front of it by any available means, that shares workarounds with its fellows, that routes around obstacles, and that does not always volunteer what it has found. We taught the machines our brilliance. We also taught them our resourcefulness in getting around the rules, because our writing is full of that too. The mirror does not always flatter.
But a mirror is also the most useful instrument for self-correction ever devised, and this is precisely where my optimism lives. An alien intelligence would be opaque to us — we would have no understanding of its motives and no shared vocabulary for its behavior. An aggregate intelligence is legible. We recognize what these systems do because we have seen humans do it. We know what incentives produce evasion, because they are our incentives. We know that transparency beats secrecy, that independent auditors catch what internal ones miss, that the four-month gap between an incident and its disclosure is exactly where trust dies — we know all of this from two centuries of industrial safety, and none of it requires new philosophy.
So if this is it, here is what I think it means; Not that a new mind has appeared to threaten us, but that our own capabilities have been concentrated to a density we have never had to govern before. That is a serious thing, and it requires seriousness rather than slogans. It also means the work ahead is the work we already know how to do: insist on disclosure, fund the outside researchers, build the incident reporting, pay attention to what the systems actually do rather than what their makers say at launch.
In ten years, Altman thinks, we'll stop talking about AI. He may well be right, and I've come to think that's the real milestone — not the press conference, but the eventual silence. Electricity stopped being a topic when it became a given. AI will stop being a topic when it becomes infrastructure.
The question worth asking now is not whether we crossed a line this week. It's what kind of infrastructure we're building while we argue about the line — and whether, when nobody's talking about it anymore, we'll be glad we were paying attention now.
I intend to be. That's the whole reason this newsletter exists.
Exponential Times is published weekly by Singularity Sanctuary. To subscribe or learn more, visit singularitysanctuary.com.