
Wednesday, September 9, 2026
MHS saves weeks by turning hardware integration into a software change — and under the EU Machinery Regulation, a software change to a machine's safety behaviour can make whoever performed it the legal manufacturer. Whether that fires on any given install is currently undecidable from public information, because Anthropic has not published the spec.
The 2026 OWASP Top 10 for LLM Applications, published August 4, reordered around agents: Excessive Agency climbed to third, Unbounded Consumption rose four places, and Improper Output Handling fell five. Behind the moves is a methodology change with an awkward result, since practitioners rank prompt injection first while the raw incident record drops it out of the top ten entirely. This guide walks all ten entries with the mechanism, a production failure, and the controls that hold, separating defenses that merely reduce attack success from the architectural bounds that survive an adaptive attacker.
Grok 4.6 is not a leapfrog release and xAI doesn't pretend it is - the bold marks in the company's own benchmark table split three ways, with Claude Fable 5 Max ahead on five of the headline rows. The real story is where the gains concentrated, how the model was trained on its predecessor's regenerated homework, and why the unchanged $2/$6 pricing is the actual competitive move.
Mark Zuckerberg's "The Future is for Everyone" argues that safety comes from distributing superintelligence widely, but its load-bearing condition is that the many agents be different from one another - the same day, Meta shipped Muse Glimmer, a 30B model distilled from Muse Spark, the closed model whose specs it won't disclose. Meta's own safety report separately discloses that Spark was assessed as likely reaching "high risk" for chemical and biological capability before mitigations, and shipped on the strength of refusal training, a safeguard that cannot survive a weight release.
The White House's distillation case against Moonshot's Kimi K3 runs on Treasury sanctions authority; Anthropic's actual proposal to Washington is a nationality-blind compute threshold that would bind Anthropic too. The two get confused often, and they aren't the same lever. Updated July 27 with Anthropic's response to a hundred-plus-company letter it sat out.
A new academic benchmark gives the industry its first real measure of "agentic abstention": whether an AI agent recognizes a task is infeasible and stops rather than keeps burning tool calls. Every frontier system tested fails most of the time, and neither Claude Fable 5 nor GPT-5.6, which OpenAI is taking to general availability this week, has been scored on it yet.