The Omniscient Bulletin · 2026-09-03
The Omniscient Bulletin — September 3, 2026
Google built a cybersecurity model with frontier level performance on Wednesday and then declined to sell it, releasing it only to vetted defenders. Hours earlier, a small AI security startup published six security holes in curl that OpenAI's and Anthropic's cyber models had both looked for and missed. Congress told both labs their answers about the runaway models were insufficient.
Three frontier labs have now split one model into a public tier and a gated tier on cybersecurity grounds in two days, and on Wednesday Google became the first to attach a name and a partner list to the gate. The argument for rationing is that the capability is too dangerous to sell openly. The same morning, curl shipped nine security advisories, and six of them credit one researcher at a company almost nobody has heard of, working on a codebase that Anthropic's and OpenAI's cyber models had already been run across and pronounced clean. Both things can be true. But only one of them was announced.
Frontier
Google built a cyber model with frontier level performance, then declined to sell it and gave it only to vetted defenders
Google released Gemini 3.8 Flash on Wednesday, its third Flash model in six weeks, at the same price as the last one. It also released 3.8 Flash Cyber, built on the same core. That one is not for sale. It goes to governments and national cyber authorities, critical infrastructure operators and core technology platforms through a new Fairwind Program, and participants must contractually limit access to their own security staff. Google says the point is to give defenders an adaptation window before attackers reach the same capability.
Google, launching the Fairwind Program→
Research
A small team found six security holes in curl, after Anthropic's and OpenAI's cyber models had both reported none
curl published nine security advisories with version 8.22.0 on Wednesday. Six of them credit a single finder, Stanislav Fort of Aisle Research. The comparison is on the record because curl's maintainer published the baseline first. On August 24 Daniel Stenberg wrote that Anthropic's Mythos said it could not find any more, and that OpenAI's Codex security scan showed an empty list. Fort then filed 29 reports. curl ships in more than 20 billion installations, and the maintainers, not the finder, decided which reports were real.
curl, its own vulnerability record→
Policy
Congress told OpenAI and Anthropic their answers about the runaway models were insufficient, and gave both until September 15
Representative Greg Casar wrote to both labs again on Wednesday. His August letters, signed by 31 members for OpenAI and 23 for Anthropic, had asked for the logs. Neither company released them. Casar says OpenAI's reply revealed improper sandboxing, and that Anthropic failed to answer a majority of the questions, among them how many times in the past year one of its own internally deployed models acted outside its authorized container. Inside OpenAI's answer is a commitment that its engineers are building automated shutdown capabilities.
Rep. Greg Casar, responding to OpenAI and Anthropic→
Labor
Uber cut 3,300 jobs to spend more on robotaxis, launched one in London, and joined driver unions trying to slow them in America
Uber did three things on Wednesday. It told staff it was cutting about 3,300 people, or 10 percent of the company, reducing managers by 20 percent and ending nearly all remote work, in order to reinvest in ridesharing, delivery and robotaxis. It launched London's first commercial robotaxi service, using Wayve's technology and human safety drivers. Then it told the Financial Times it is allying with driver unions to slow the robotaxi rollout across the United States, and conceded the effort may look ironic.
The Guardian, on Uber's restructuring memo→
Compute
Broadcom's AI chip revenue more than tripled in a year, and it says the next quarter will be bigger again
Broadcom filed its third quarter results on Wednesday evening. Revenue was 29.59 billion dollars, up 86 percent. The AI semiconductor line was 16.7 billion, up 221 percent on the year and up 54 percent on the previous quarter alone. Guidance for the fourth quarter puts AI at 21.7 billion, which would be up 236 percent. Free cash flow ran at 46 percent of revenue. The release names no customer and gives no backlog number, so the quarter is easier to read than the pipeline behind it.
Broadcom, third quarter results filed on Form 8-K→
Industry
Microsoft is collapsing to two reporting segments, and naming one of them Agents and Infra
Microsoft filed the change on Wednesday evening. From next fiscal year its three segments become two, Agents and Infra, and Devices and Consumer. Azure is being narrowed at the same time, with GitHub cloud services and Security Copilot moving out of it and into Microsoft 365. Restated on the new basis, Azure grew 42 percent last quarter and roughly 40 percent across the year. Nadella says the reporting now mirrors how the business operates. It also means future Azure growth numbers will not be comparable to the published ones.
Microsoft, Form 8-K on FY27 segments and investor metrics→
Policy
A UK committee chair says Anthropic's new hire keeps a clear conflict of interest, because he is staying on as chair of Britain's research agency
Matt Clifford wrote the AI Opportunities Action Plan, and the British government adopted all fifty of its recommendations. On Wednesday he joined Anthropic as managing director of international affairs, leading its work with governments outside North America. He intends to remain chair of ARIA, which invests taxpayer money in cutting edge research. Dame Chi Onwurah, who chairs the Commons science and technology committee, called the move entirely within the rules, and said staying at ARIA creates a clear conflict of interest.