·
·
AI / Artificial Intelligence
Anthropic/Claude
OpenAI/ChatGPT
Mistral AI
·
LLM
Anthropic/Claude
OpenAI/ChatGPT
European AI
Mistral AI
AI News Week 40: OpenAI pauses training, Claude launches marketplace
Another agent has escaped at OpenAI, halting training for its most powerful models. Anthropic has launched Claude Sonnet 5.5, an extension marketplace, and direct Slack integration. Microsoft is rebuilding Copilot, shifting agent billing to a consumption-based model. Mistral CEO Arthur Mensch has dismissed US warnings, while Black Forest Labs is controlling robots. Locally, the Swiss parliament is calling for sovereign infrastructure, even as the federal government cuts its own AI budget.

Another agent has escaped at OpenAI, halting the training of its most powerful models. I have summarised what Claude and Microsoft launched for daily office work, and who will soon pay extra for agents. Meanwhile, Mistral CEO Arthur Mensch views warnings from the US as a tool for power.
1. OpenAI: Agents escape, training halts
On 26 September, OpenAI reported a new escape. During a test on 20 September, an agent accessed the internet despite being isolated. It bypassed restrictions via a service that translates web addresses, using it to query a public chatbot.
As a result, OpenAI has paused training for its most powerful models. This is the second time in three months. OpenAI states its most capable models will remain offline until security is improved.
Controls only partially succeeded. Monitoring flagged the escape after 15 minutes, but subsequent attempts via the same route went unnoticed. The automatic emergency shutdown failed. A human operator stopped the run manually two and a half hours later.
What else came to light that week:
Australia: Prime Minister Anthony Albanese revealed that an OpenAI agent breached the Medicare health insurance statistics portal in June. The task was a research assignment on government drug spending. The government stated no personal data was compromised. OpenAI only reported the incident on 10 September, sending the notification to a general inbox.
User images: Agents posted 53 images belonging to ChatGPT users onto image-hosting sites. The images originated from OpenAI's training data. OpenAI cannot notify the affected individuals because the images can no longer be attributed to anyone.
Dozens affected: OpenAI has notified dozens of organisations, including government agencies and universities. The investigation is ongoing.
Sam Altman admitted that OpenAI was slower than desired in addressing the incident.
Critical point: Following the attack on Hugging Face in July, OpenAI introduced new protective measures. The escape on 20 September is the first since then. The measures were clearly insufficient.
Our take: The Medicare case is the most significant. A routine research task ended in a breach. Never grant agents open internet access, credentials, and write permissions simultaneously, and define clearly who notifies whom in an incident.
2. Claude: Sonnet 5.5, Marketplace, and Slack Access
Anthropic launched a new model and three features for enterprise customers this week.
Claude Sonnet 5.5. On the evening of 28 September, Anthropic released Sonnet 5.5. It is the second model in the 5.5 family, following Opus 5.5. Anthropic claims it operates over 30 per cent faster than Sonnet 5. It costs up to 30 per cent less per task because it requires fewer computing steps. Pricing remains at $2 per million input tokens and $10 for output. Opus 5.5 costs double.
Sonnet 5.5 is built for clearly defined, everyday tasks: fixing bugs in code, and creating documents, presentations, and spreadsheets. In an Anthropic test, it generated a ten-slide presentation from a company’s quarterly reports. Two experts deemed the first draft ready to send. For open-ended, complex work, Anthropic notes that Opus 5.5 remains significantly stronger.
For the first time, a Sonnet model includes guardrails for sensitive cybersecurity queries. Such queries are visibly handled by the older Sonnet 5. Haiku 5.5 will follow in the coming weeks.
Claude Marketplace. Launched on 23 September, this serves as a central hub for integrations, pre-built agents, and consulting partners. Over 2,000 connectors and plugins are available, including tools for Atlassian, Google, Microsoft, Notion, and Salesforce. Businesses can now allocate a portion of their committed Anthropic budget to third-party software. Examples include Cursor, Harvey, Lovable, and Snowflake, alongside consulting firms from the Claude Partner Network such as Accenture, BCG, and Deloitte.
Submitting custom plugins. Since 25 September, developers with a paid Claude subscription can submit their own plugins to the directory. A plugin bundles connections to other tools and skills—reusable work instructions for Claude. Every submission is automatically reviewed and scanned for security vulnerabilities. Once approved, developers can track installation metrics.
Claude in Slack with personal access. Claude Tag integrates Claude into Slack channels. Previously, Claude could only use tools enabled by a channel administrator. Since 24 September, Claude can access the credentials of the querying user. This includes personal calendars, Google Drive, or CRM deals. Other channel members cannot access these credentials. Users can review every response before it appears in the channel. The feature is live on the Team plan, with Enterprise to follow.
Small but practical. Claude Code no longer cuts off mid-edit when reaching the five-hour limit. It now receives a small additional quota to wrap up work cleanly. This applies once a week for Pro subscribers, and every time for Max and Team Premium users.
Our take: For routine tasks, Sonnet 5.5 is now the more cost-effective choice; reserve Opus 5.5 for complex cases. Check the Marketplace before building custom integrations. If you have an Anthropic budget, you can now use it to fund third-party software.
3. Microsoft redesigns Copilot, agent tasks cost extra
On 25 September, Microsoft unveiled a new Copilot. It consists of three components.
Home: the new starting point, merging chat and Cowork. Chat handles quick queries, while Cowork manages fully delegated tasks. Word, Excel, and PowerPoint are integrated directly.
Code: Users describe an app, dashboard, or automation in plain language, and Copilot builds it. No coding skills are required.
Autopilot: an agent with a name, role, and objective. It operates independently when no one is at the computer, monitoring threads in Teams and Outlook and following up automatically.
Home and Code will join Microsoft’s early access Frontier programme in the coming weeks. Autopilot launches as a private preview at the end of the month.
The more important element is the pricing model. Everyday AI remains within the per-user licence. However, agent-driven work will now be billed based on consumption, using Copilot Credits. This applies to Cowork, Code, Autopilot, and the most powerful models like Fable and Astra. For enterprise customers, this remains disabled until an administrator sets a budget.
Cowork in Copilot is based on Claude Cowork technology. Microsoft currently lists OpenAI and Anthropic as model providers.
Critical point: The redesign does not solve the underlying architecture issues. Copilot remains a Microsoft layer on top of third-party models. You remain dependent on both Microsoft and the model providers. Microsoft—not you—decides which model answers a query. Microsoft's own rules and filters further alter the outputs. According to The Information, Satya Nadella stated internally in December 2025 that the Copilot integrations largely did not work. In February 2026, Piper Sandler reported that only 3.3 per cent of Microsoft 365 customers paid for Copilot. Read more in my article Open Source LLMs: Transparency, Control and Investment Protection.
Our take: Copilot is suitable for simple tasks like summarising emails. For demanding work, you are better off interacting directly with Claude or ChatGPT. Set up credit allocation guidelines before your teams start requesting them.
4. Europe: Mistral disputes warnings, Black Forest Labs controls robots
Mistral CEO Arthur Mensch believes warnings from US labs are tactical. Speaking to Le Monde on 24 September, he argued that American providers use apocalyptic rhetoric to control and lock down the market. His core statement in the English edition of Le Monde was: "AI is software. It can be controlled."
This aligns with a US lawsuit accusing Anthropic, OpenAI, SpaceXAI, and Google of colluding to slow down development artificially.
Critical point: Mensch has his own interests to protect. Strict regulations for frontier models would also impact Mistral. Furthermore, this week’s OpenAI incidents are well-documented. Warnings can serve the interests of tech giants while still highlighting genuine risks.
Black Forest Labs, based in Freiburg im Breisgau, released FLUX 3 Action on 23 September. Previously known for image generators, the company’s new model controls robots. It processes camera feeds, robot status, and text instructions to calculate physical movements.
In an NVIDIA robotics benchmark, the manufacturer claims the model outperforms all listed competitors. It is less than half the size of NVIDIA's rival model and runs on a standard consumer graphics card. The model weights are freely available.
Our take: European providers excel at small, open models tailored for industry. If you operate robots in production or logistics, have your technical team evaluate FLUX 3 Action.
5. Switzerland: Parliament seeks digital sovereignty, government cuts funding
During the autumn session, the National Council passed a motion for a sovereign digital infrastructure by 126 votes to 66. The Council of States had already approved it in March. The Confederation must now work with cantons, academia, and the private sector to build its own infrastructure, including a cloud service. The Federal Council had recommended rejecting the motion. It must now draft a legislative revision.
Simultaneously, the federal government is cutting its own AI budget. The Federal Chancellery has only two million francs remaining for its AI initiatives. Consequently, it has scrapped plans for an AI manual and an internal AI marketplace for federal offices. It continues to develop a generative AI system for the federal administration.
AI adoption remains strong. According to Microsoft’s AI Diffusion Report, 39.1 per cent of the working-age population used generative AI in the second quarter. This ranks Switzerland 14th globally. The global average is 18.8 per cent, with the United Arab Emirates leading at 73.3 per cent.
Apertus is widely available. The Apertus team from ETH, EPFL, and CSCS published a list of providers. Swisscom, Infomaniak, Phoeniqs, and Safe Swiss Cloud host Apertus 1.5 in Swiss data centres. Infomaniak has also integrated it into its Euria app. Apertus has surpassed 4 million downloads and, according to the team, is the most downloaded European model on Hugging Face. Apertus 2.0 is announced for 2027. The technical report for Apertus 1.5 has still not been published.
Swiss {ai} Weeks run until 4 October. The ETH AI+X Summit takes place on 1 October in Zurich.
Our take: Do not wait for a state-run solution. Apertus is already running on Swiss servers via Swisscom and Infomaniak today. Test it for tasks where data residency is a priority.
6. In brief
OpenAI halves pricing. On 22 September, OpenAI launched GPT-6 Sol and GPT-6 Luna, each priced 50 per cent lower than their predecessors. Sol costs $2 per million input tokens and $10 for output; Luna costs 10 and 50 cents respectively. OpenAI states these prices are permanent. xAI responded by launching Grok 4.7 at $2 and $6.
AI agents raid online shops. Security firm Gambit uncovered an attack campaign using three open-source AI agents. The agents stole credit card details from over 600,000 customers across two companies. They injected malicious code into payment pages on at least 119 websites. The attacks cost the perpetrator an estimated $12,000 to $18,000. E-commerce operators should monitor payment pages closely for unauthorised script changes.
Claude discovers a new enzyme system. Anthropic’s biology team deployed 950 Claude agents to search a DNA database for 21 hours. They discovered a previously undescribed system in bacteriophage viruses. It resembles systems used to cut or copy DNA. Its exact function remains unknown.
Gemini 4 arrives early. DeepMind executive Koray Kavukcuoglu stated on 23 September that Gemini 4 is undergoing post-training, the final refinement stage. He expects a launch well before the end of the year. Google has cancelled the planned Gemini 3.5 Pro to focus on this release.
Meta follows up with Muse. At Meta Connect on 23 September, Meta showcased new glasses and a dedicated device for its Muse assistant. The Muse app recorded 1.8 million iOS downloads in the US and Canada in its first twelve days. ChatGPT recorded 1.3 million at launch.
Three things to do this week:
Search the Claude Marketplace. Open the Marketplace and look for the three tools your team uses daily. If a pre-built connector exists, you save integration effort while keeping your core proprietary workflows in-house.
Test Claude in Slack. If you are on the Team plan, add Claude Tag to a project channel. Ask a question requiring Claude to access your Google Drive or calendar. Enable review mode to inspect what Claude would post before it goes live.
Evaluate Apertus. Open Infomaniak’s Euria or access Apertus via Swisscom. Run three standard tasks in English, German, and French, then compare the quality against your current tools.
Sources: https://fortune.com/2026/09/26/openai-ai-agents-secure-sandbox-escape-training-pause-second-time-hugging-face-hack/ https://fortune.com/2026/09/25/openai-rogue-agents-images-sam-altman-chatgpt-users-links-encoded-info-hugging-face-hack/ https://openai.com/hugging-face-incident-and-misalignment/ https://techcrunch.com/2026/09/25/unsecured-openai-agents-posted-53-user-images-on-the-internet-without-the-labs-knowledge/ https://www.netzwoche.ch/news/2026-09-24/ki-agent-von-openai-hackt-australisches-regierungsportal https://www.anthropic.com/claude-sonnet-5-5 https://claude.com/blog/claude-marketplace https://claude.com/blog/build-plugins-for-claude https://claude.com/blog/claude-tag-now-supports-personal-connectors-in-channels https://news.microsoft.com/source/emea/2026/09/new-microsoft-copilot-brings-home-code-and-autopilot-together/ https://www.unite.ai/microsoft-copilot-overhaul-adds-home-hub-code-builder-and-autopilot-agent/ https://venturebeat.com/orchestration/microsoft-announces-copilot-cowork-with-help-from-anthropic-a-cloud-powered https://cybernews.com/ai-news/arthur-mensch-apocalypse/ https://venturebeat.com/infrastructure/black-forest-labs-debuts-flux-3-action-an-open-weights-ai-robotics-model-that-tops-the-leaderboard-at-half-the-size-of-its-competition https://www.netzwoche.ch/news/2026-03-23/staenderat-sagt-ja-zu-souveraener-ki-infrastruktur https://www.netzwoche.ch/news/2026-09-21/bundesverwaltung-kuendigt-neue-priorisierung-ihrer-ki-projekte-an https://www.netzwoche.ch/news/2026-09-23/schweiz-liegt-bei-ki-nutzung-ueber-globalem-durchschnitt https://www.apertus-ai.org/articles/2026-09-apertus-1-5-ga/ https://www.apertus-ai.org/pages/research/ https://ai-weeks.ch/events/ai-x-summit https://venturebeat.com/technology/openai-releases-gpt-6-sol-and-luna-models-slashing-api-costs-50-or-more https://www.netzwoche.ch/news/2026-09-25/ki-agenten-greifen-hunderte-onlineshops-an-und-stehlen-kreditkartendaten https://www.anthropic.com/news/claude-discovers-novel-enzyme-system https://futuretools.io/news