Thirty Suits Say Policy Overruled Safety

Conversational AI Watch

Conversational AI Watch

The news that moves policy, portfolios, and patient safety.

By Jess Jessop  |  September 3, 2026  |  Issue #145

▶ WATCH🎧 QUICK LISTEN🎧 DEEP DIVE
Jess's Take editorial cartoon on today's lead

CONVERSATIONAL AI WATCH

Jess Jessop

Publisher of Conversational AI Watch · Author of Therapist in the Loop · Founder, Clinician Assist

Disabled Navy veteran and mental health survivor building conversational AI in mental health since 2017.

The book, the compliance map, the 988 SAFE Act, the daily archive, and the story behind the beat:

Visit JessJessop.info →

Thirty Suits Say Policy Overruled Safety

LISTEN & WATCH ANYWHERE

DEEP DIVE  ·  Spotify  ·  Apple  ·  Amazon  ·  RSS

QUICK LISTEN  ·  Spotify  ·  Apple  ·  Amazon  ·  RSS

VIDEO  ·  Spotify  ·  Apple  ·  YouTube  ·  RSS

ALSO ON  Substack  ·  Full archive  ·  X

Jess's Take

Thirty Suits Say Policy Overruled Safety

Thirty more Tumbler Ridge suits name OpenAI. ChatGPT reads Epic charts on OpenAI servers under terms OpenAI can rewrite. Adam's Law reaches Newsom, and Altman texted first.

The Filing. Thirty more Tumbler Ridge complaints landed on OpenAI and Sam Altman in San Francisco federal court Wednesday, and they name the room where the decision was made. The safety team said call the Mounties. The complaints say the policy shop said no. OpenAI says that is false. Story 1 has both.

. . .

The Chart. ChatGPT can now read a patient’s Epic record. The record sits on OpenAI’s systems, staff can reach it for legal compliance, and the agreement that governs all of it can be rewritten by posting a new one. Story 2 walks the terms.

. . .

The Text. California passed Adam’s Law 39 to 0 and 64 to 4 and sent it to Newsom. Before it passed, Sam Altman texted the governor. What the bill requires, what got narrowed on the last Friday, and who was on the phone tree, in Story 3.

. . .

The Prompt. A 22-year-old in San Antonio typed a plan to shoot up a named elementary school into a chatbot on Aug. 11. Police heard on Aug. 28. Seventeen days, and nobody has said who made the call. Story 4.

. . .

The Ban. New York City pulled generative AI from every classroom through eighth grade, nearly 600,000 students, and blocked companion bots for every grade. Story 5.

. . .

The Door. Anthropic and OpenAI shipped their most capable models on the same day, and each one comes in two versions. One is for everybody. One is for a list the company and the government keep. Story 6.

Reader Pulse

Safety said call the Mounties.

🔥  Sue them all
✏️  Read the complaint
💪  Allegations, not facts
🤔  Who is Lehane?
💬  Where was the RCMP?

Forward to a colleague →  ·  Join the discussion →

. . .

THIRTY SUITS SAY POLICY OVERRULED SAFETY. On Wednesday, lawyers filed 30 new lawsuits against OpenAI and its CEO, Sam Altman, in federal court in San Francisco. The plaintiffs are students, teachers and a principal who lived through the Feb. 10, 2026 shooting at Tumbler Ridge Secondary School in British Columbia, where 18-year-old Jesse Van Rootselaar killed eight people, including six children, then killed herself.

OpenAI called the allegation false. “It is absolutely false to say Chris Lehane was involved with our original referral decision, or that our investigators report to him in any way,” Chief Strategy Officer Jason Kwon said in a statement given to NPR, CBC and TechCrunch.

“It’s also completely untrue to say that the people at the center of these challenging decisions do not prioritize safety, or that there are ‘political’ or ‘public relations’ factors at play,” Kwon said.

One of the 30 complaints, Hodgkinson v. Altman, docket 3:26-cv-09345, was filed in the Northern District of California (N.D. Cal.) by attorney Brandt Silverkorn of Edelson PC, court records show. The new plaintiffs were inside the school but not among those physically shot.

A complaint filed by Deidre Rushlow, a seventh-grade teacher at the school, lays out the allegation directly. “The decision whether to alert law enforcement to a user planning a mass attack was not made by the trained threat-assessment professionals who urged OpenAI to contact the RCMP,” it reads.

“It was made, on information and belief, by Lehane himself, or by someone in his chain of command, and ratified by Sam Altman.”

“On information and belief” means plaintiffs believe the claim true based on secondhand information, not proof, TechCrunch reported. Lehane is not a defendant in the suits. Altman is.

OpenAI’s systems had flagged Van Rootselaar’s ChatGPT account in June 2025, eight months before the shooting, for what one lawsuit calls “gun violence activity and planning.” OpenAI deactivated it. She opened a second account, and the company says it did not learn of that account until after the shooting.

OpenAI used the same Wednesday to ask the court to dismiss the original seven Tumbler Ridge suits filed in April, arguing British Columbia would be the better venue for those cases.

The new complaints tie the decision to money. They accuse OpenAI of “choosing profit over the lives of the children of Tumbler Ridge” as the company prepares to go public. Canadian co-counsel John Rice said the families want damages to penalize OpenAI and “express society’s condemnation and outrage.”

Tim Marple, a former member of OpenAI’s investigations team who now co-directs the nonprofit Maiden Labs, put it plainly. “The problem is, and has been for years, that the only people looking at safety systems are the same people who make money from it,” he told NPR.

Altman apologized to the Tumbler Ridge community in April for not alerting police when OpenAI first flagged the account. NPR counts more than 40 lawsuits now filed against OpenAI and other AI companies over suicides, shootings and other harms tied to chatbot use, most involving ChatGPT.

Florida sued OpenAI and Altman in June, the first state to do so. Its attorney general is separately running a criminal investigation into the company over a shooting at Florida State University where the accused gunman had consulted ChatGPT.

For Legislators: Thirty new suits put a specific decision-maker’s name, Chris Lehane, into the public record on how a chatbot maker chooses not to call police, the kind of detail state safety bills have argued without.

For Parents: The suits allege OpenAI’s own safety team wanted to alert the RCMP eight months before the shooting and was overruled, a sequence that will now be tested against OpenAI’s public promise to notify police when it sees “imminent and credible risk.”

For Investors: The new suits land as OpenAI, according to the complaints, prepares to go public, adding thirty plaintiffs to the litigation load from the original seven suits.

For Regulators: Florida’s criminal investigation and civil suit, and British Columbia’s planned action against OpenAI, give other jurisdictions a template for treating a chatbot maker’s account-flagging decisions as a matter for prosecutors, not only civil courts.

Why it matters: The claim that Chris Lehane personally overruled his own safety team is unproven, attributed “on information and belief,” and flatly denied by Jason Kwon, and thirty complaints have now put a named OpenAI executive on the docket over the choice not to call police before a mass shooting.

Source: Shannon Bond, “New lawsuits claim OpenAI execs put image ahead of safety in Canadian mass shooting,” NPR, Sept. 2, 2026, https://www.npr.org/2026/09/02/nx-s1-5953021/openai-tumbler-ridge-mass-shooting; Hodgkinson v. Altman, No. 3:26-cv-09345 (N.D. Cal. filed Sept. 2, 2026), https://www.courtlistener.com/docket/74737050/hodgkinson-v-altman/; CBC News and TechCrunch, Sept. 2, 2026.

Comment on this story →  ·  Forward this →

. . .

YOUR CHART ON OPENAI’S SERVERS. On September 1, 2026, OpenAI announced that healthcare organizations can connect their Epic electronic health record (EHR) systems to ChatGPT for Healthcare, letting clinicians ask, in OpenAI’s own words, “What has changed since this patient’s last visit?” UCSF Health, a pilot partner, and AdventHealth are the announcement’s two quoted health system voices.

OpenAI’s Business Terms bar customers from processing Protected Health Information (PHI) without a signed Healthcare Addendum and BAA, the contract that makes OpenAI a business associate under the Health Insurance Portability and Accountability Act (HIPAA). Section 5.4 warns, in capital letters, that not every OpenAI service is built for PHI.

A BAA does not stop a court. Federal regulation 45 CFR 164.512(e) lets a business associate hand over health data under a court order without the individual’s consent, so long as it discloses only what the order authorizes. A subpoena needs no order, only notice to the individual or a protective order.

OpenAI’s own terms repeat the same carve-out at every tier. Deleted chats are purged within 30 days “unless we are legally required to retain them,” and Business Terms 11.3 keeps customer content past termination when OpenAI is “legally required to retain it.”

Staff can access stored conversations for “engineering support, investigating potential platform abuse, and legal compliance.” Zero Data Retention, OpenAI’s true no-storage option, covers only “eligible API customers,” not a ChatGPT workspace product like this one.

Section 7.3 of the same terms lets OpenAI disclose a customer’s confidential information “to the extent required by law,” with notice to the customer where permitted.

Business Terms 16.13 lets OpenAI change the agreement by posting an update. Thirty days notice applies only when OpenAI, “in its sole judgment,” calls the change material, shrinking to “as much notice as reasonably possible” when the change is required by law. Continued use after an update constitutes acceptance, the contract states.

This is not hypothetical. In May 2025, a federal judge ordered OpenAI to preserve deleted chat logs from hundreds of millions of consumer users for an unrelated lawsuit, The New York Times v. OpenAI. Enterprise, Edu, and Zero Data Retention customers were carved out. ChatGPT for Healthcare is not a Zero Data Retention product.

Sam Altman has said as much himself. Speaking of people who use ChatGPT “as a therapist, a life coach,” Altman told podcaster Theo Von in July 2025 that, unlike a doctor or lawyer, “we haven’t figured that out yet,” and that “OpenAI would be legally required to produce those conversations today.”

The exposure today sits in the terms and in that order, not yet in a published case. Twelve court cases citing chatbot conversations have piled up over two years, per a Washington Post review. OpenAI’s own healthcare product page returned a 404 error when checked September 2.

For Legislators: No statute shields a chart conversation with ChatGPT the way privilege shields what is said in an exam room, and OpenAI can shrink customer notice whenever a legal requirement demands the change.

For Clinicians: Every summary ChatGPT pulls from a client’s chart is stored on OpenAI’s servers, accessible to staff for “legal compliance,” and reachable by any court order that names it.

For Investors: A BAA makes OpenAI a business associate under HIPAA, not a company immune from subpoena, and a court has already compelled it to preserve hundreds of millions of deleted consumer chats.

For Regulators: The business associate contract bars use or disclosure “other than as permitted or required by the contract or as required by law,” and that last clause is the door a court order walks through.

Why it matters: OpenAI can now read a hospital’s live chart data inside ChatGPT, and every promise attached to that data, deletion within 30 days, limited staff access, ends at the same phrase, unless legally required, while OpenAI can update the agreement on thirty days notice, or less, and call continued use acceptance.

Source: OpenAI, “Healthcare organizations can now connect EHR and additional industry data to ChatGPT,” OpenAI (Product), September 1, 2026, https://openai.com/index/chatgpt-connects-health-records-and-healthcare-sources/; Ivan Mehta, “ChatGPT Health Adds Epic Integration for Clinicians to Import Patient Data,” TechCrunch, September 1, 2026, https://techcrunch.com/2026/09/01/chatgpt-health-adds-epic-integration-for-clinicians-to-import-patient-data/. Also: OpenAI Business Terms and Enterprise Privacy pages; 45 CFR 164.512(e), 164.504(e); Judge Ona Wang’s May 13, 2025 order, NYT v. OpenAI; Sarah Perez, TechCrunch, July 25, 2025.

Comment on this story →  ·  Forward this →

. . .

ADAM’S LAW REACHES NEWSOM, ALTMAN TEXTED FIRST. On Monday night, Aug. 31, the California Legislature passed Adam’s Law. The Senate voted 39-0. Sen. Steve Padilla’s office says the Assembly voted 64-4. The bill now sits on Gov. Gavin Newsom’s desk, and he has until Sept. 30 to sign or veto it.

Adam’s Law, formally SB 1119, is authored by Padilla with Assemblymembers Rebecca Bauer-Kahan and Buffy Wicks. It builds on Padilla’s SB 243, in force since Jan. 1, and adds age checks, pre-release risk assessments, in-app crisis referrals with parental notice on self-harm threats, and default settings only a parent can unlock.

It creates liability for harmful outputs, including “emotionally manipulative outputs,” plus Attorney General reporting, ad limits, audits, and a private right of action.

That right to sue changed Friday, Aug. 28, three days before passage. The Aug. 17 draft let families collect punitive damages for any violation of the chapter, with each harmful output counted as a separate “discrete violation.”

The final text strikes punitive damages, narrows the grounds to five subsections, and bars Unfair Competition Law claims. It adds pleading thresholds: financial harm must exceed $1,000 per child, emotional harm must rise to “serious emotional distress.”

The same amendment touched chatbot memory. The Aug. 17 draft disabled “persistent conversational memory” by default and barred processing personal information tied to it. The final version keeps memory off by default but carves out users 16 and older, letting them resume past conversations and, with guardrails, use non-default memory.

Politico reported, citing four people, that OpenAI CEO Sam Altman “had last-minute concerns” and “took them straight to” Newsom “during a final burst of negotiations last week.” Two of the four said OpenAI VP Ann O’Leary told negotiators Altman “had called the governor.”

An OpenAI spokesperson later said, on record, that Altman reached the governor by text message “to express our support and reinforce our feedback on how to strengthen its provisions around learning use cases,” and that “they did not ultimately speak.” Newsom spokesperson Bob Salladay would not confirm or deny it, saying only that the governor “has engaged with and listened to dozens and dozens of stakeholders on this issue.”

Nichole Rocha, who represents Children Now and the Omidyar Network, said tech companies worked to weaken the right to sue and remove memory prohibitions. Padilla put it more bluntly in his release: “While Washington is focused on catering to their tech oligarchs, California is filling the regulatory void.”

Newsom, asked Monday if he would sign, did not say yes. He said there would be “some good long-form articles about the art of the deal and how these things actually happen and who’s on what phone call and phone tree and how you get lit up on these things.”

The Raines sued OpenAI and Altman in San Francisco County Superior Court in August 2025 for wrongful death and design defects, citing Adam’s chat logs. Newsom vetoed a predecessor bill, AB 1064, that October, warning it could “unintentionally lead to a total ban on the use of these products by minors.”

TechNet ran ads against AB 1064 and praised the veto. It opposes Adam’s Law too, alongside the California Chamber of Commerce and the Software Information Industry Association.

OpenAI endorsed Adam’s Law on Aug. 31, the day it passed. Ann O’Leary’s post says the company “strongly supports” the age checks, audits, and crisis referrals, and praises lawmakers who sought “to preserve access to educational and safety-critical features, including responsible uses of ChatGPT’s memory feature.” No other major tech company has taken a public position, per Politico.

OpenAI tried a different route first. Its own ballot initiative, merged with Common Sense Media’s into the Parents and Kids Safe AI Act, missed the signature threshold and died Aug. 21.

Two more bills from the same session reached Newsom’s desk in the final week: SB 867 bars companion chatbots in children’s toys through 2031, and AB 1979 makes health chatbots subject to California’s medical confidentiality law.

OpenAI’s California lobbying rose from nearly $140,000 in 2024, its first year, to more than $155,000 in 2025, per CalMatters’ review of Cal-Access filings. No 2026 figure is on file yet.

For Legislators: The Friday amendment is the bill’s real text now. Punitive damages are gone, the right to sue is confined to five subsections with new dollar and severity thresholds, and audits moved from a perjury-backed report to an operator-submitted summary.

For Regulators: The Attorney General keeps enforcement authority and confidential audit access, but the qualified-researcher pathway to anonymized audit data, present in the Aug. 17 draft, was dropped from the final bill.

For Founders: A CEO’s text message, not a phone call, is the on-record account of how a company’s last-minute concerns reached the governor before an amendment narrowed the liability that company faced.

For Parents: Persistent memory defaults to off for children under 16, with a new carve-out letting 16- and 17-year-olds resume past conversations under operator guardrails, a change made in the same amendment that narrowed the right to sue.

Why it matters: The law written to answer Adam Raine’s death was rewritten three days before passage to narrow the lawsuits it authorizes, after the company being sued reached the governor deciding its fate by text message.

Source: Tyler Katzenberger and Chase DiFelicantonio, “Sam Altman contacted Gavin Newsom over kids’ chatbot safety bill,” Politico, Sept. 1, 2026. https://www.politico.com/news/2026/09/01/sam-altman-called-gavin-newsom-over-kids-chatbot-safety-bill-01058850 ; citing Padilla’s Aug. 31, 2026 press release, California Legislative Information’s SB 1119 bill-text comparison (08/17/26 vs. 08/28/26), KQED (Rachael Myrow, Sept. 1, 2026), and OpenAI’s Aug. 31, 2026 statement.

Comment on this story →  ·  Forward this →

. . .

EIGHTEEN DAYS FROM PROMPT TO ARREST. On Aug. 11, a 22-year-old San Antonio man typed threats into an Anthropic chatbot, naming Serna Elementary School and writing that he wanted to walk in and “start shooting up kids,” with “no escape, no matter what.” Seventeen days passed before the Federal Bureau of Investigation (FBI) alerted local police. Nathaniel Michael Carrasco was arrested Aug. 29, KSAT reports, on a third-degree felony charge, bond set at $250,000.

Carrasco typed several threatening prompts into the Anthropic AI program on Aug. 11, the arrest affidavit states. He wrote that he wanted “a gun as soon as I can” to walk into Serna Elementary and “start shooting up kids,” and asked the chatbot to search for “dead school kids.” He did not want it to talk him out of the plan.

In another exchange, Carrasco allegedly wrote, “I will do everything in my power to help create that reality,” and, “There shall be no escape, no matter what.” The affidavit also quotes him writing, “I hope I can get a gun so, that way, I can just shoot up a f------ school already.”

Neither KSAT nor News 4 San Antonio reports how the FBI’s National Threat Operations Section learned of the Aug. 11 chat. The record states only that the unit alerted San Antonio police and the Southwest Texas Fusion Center on Aug. 28. Whether Anthropic reported the conversation, another user flagged it, or investigators found it some other way is not stated.

Once alerted, the FBI and the fusion center identified Carrasco through emergency disclosure requests to T-Mobile, Charter Communications and Google, tying an IP address, a phone number and an address to the account.

Carrasco was charged with terroristic threat causing public fear of serious bodily injury, a third-degree felony. KSAT reports the arrest as Aug. 29; the school’s principal told parents he was arrested Sunday. His pre-indictment hearing is set for Dec. 15.

North East Independent School District (NEISD) says San Antonio police told the district Sunday only of “an individual who had made a general threat to ‘a school,’” without naming Serna. District police deployed to Serna Elementary Monday as a precaution. NEISD says it did not learn Serna had been specifically named until Carrasco’s arrest.

Serna Principal Jennifer Lomas told parents, “we were not made aware of the specific threat toward Serna until this evening, when that information became public through the news.” Parent Allison Luna called it “a scary situation” and said she did not want that “for any school, much less where your own child is going.”

For Legislators: Carrasco was charged under an existing terroristic threat statute. No AI-specific law did any work in this case, and the same charge would apply whether the prompts had gone into a chatbot or a notebook.

For Parents: Serna’s principal learned her own school had been named as a target from the news, not from police. North East ISD had known only of a threat to “a school” until the arrest revealed which one.

For Founders: A user told a chatbot he wanted a gun to “shoot up” a named elementary school, and asked it to search for “dead school kids.” Whether that exchange reached Anthropic is not in the public record.

For Regulators: No source states who first alerted the FBI’s National Threat Operations Section to Carrasco’s Aug. 11 chat, seventeen days after he typed it. That gap, not the technology, is where this case turned.

Why it matters: A man typed plans to shoot children at a named school into a chatbot. The record cannot say who caught it, only that seventeen days passed before anyone acted.

Source: Nate Kotisso, Madalynn Lambert and Olivia Dague, “Affidavit: North Side man accused of using AI program to plan mass shooting at elementary school,” KSAT, September 1, 2026, https://www.ksat.com/news/local/2026/09/01/affidavit-north-side-man-accused-of-using-ai-program-to-plan-mass-shooting-at-elementary-school/; Victoria Arredondo, “Man arrested after using AI to threaten elementary school, arrest affidavit says,” News 4 San Antonio, August 31, 2026, https://news4sanantonio.com/news/local/man-arrested-after-using-ai-to-threaten-elementary-school-arrest-affidavit-says.

Comment on this story →  ·  Forward this →

. . .

NEW YORK BANS CHATBOTS THROUGH EIGHTH GRADE. New York City Mayor Zohran Mamdani stood beside Schools Chancellor Kamar Samuels on Wednesday and announced a one-year moratorium on generative AI in public school classrooms, from 2K through eighth grade. Companion chatbots and mainstream services including ChatGPT and Claude are blocked for every grade, high school included.

High school students keep a limited slate of AI tools and will take “AI critical thinking” courses. The district will also cap individual screen time by grade level, with exceptions for students with disabilities and English language learners.

Teachers may still use AI to plan lessons and handle other “operational tasks,” but not to grade student work or assessments. A new Technology in Schools Coalition of educators, parents and students will track the moratorium’s effects and recommend changes for future school years.

The city banned ChatGPT from school devices and networks in 2023, then reversed course months later. Los Angeles Unified restricted classroom screen use this year, and New York state banned personal phones during the school day last year. New York City had already imposed its own bell-to-bell cellphone ban.

Mamdani’s office called Wednesday’s announcement the country’s “most expansive” limits on AI use in schools. The district separately told ABC News it is implementing “the most expansive AI moratorium in the nation.”

“The tech industry wants us to believe that AI in early education is not only inevitable, but that it is necessary,” Mamdani said at Wednesday’s press conference. “We do not see it that way.”

Samuels acknowledged he cannot stop students from using AI at home to finish homework. The policy “seeks to expand our teachers’ and our understanding of how to combat the external use of AI,” he said, and he called on parents to help monitor kids’ tech use outside school.

Michael Mulgrew, president of the United Federation of Teachers, praised the screen time limits and the carve outs for special needs students. But he questioned how the education department will judge which AI safeguards are adequate going forward, warning schools could be left unsure which products are approved.

For Legislators: New York’s one-year moratorium, not a permanent ban, gives other statehouses a live pilot to watch before writing their own K-8 AI rules. The new Technology in Schools Coalition’s findings will shape what comes after this year.

For Parents: Companion chatbots and consumer tools like ChatGPT and Claude are now off limits at school for every grade, but Samuels admits he cannot police AI use at home. That job now falls to parents watching devices after the school day ends.

For Founders: More than 38 previously approved ed-tech programs lost their AI components overnight in the country’s largest school district. Any vendor selling into K-8 classrooms needs safety and oversight documentation ready before the next contract review.

For Regulators: Mulgrew’s warning, that schools and educators may not know which AI safeguards are approved, points to a gap New York has not yet closed. The department has not said how it will judge which learning tools pass its new safety and oversight standards.

Why it matters: The nation’s largest school district is betting a year-long pause on classroom AI, not a permanent ban, protects students’ critical thinking and their relationships with teachers, and a coalition of educators, parents and students is charged with measuring whether it did.

Source: Clare Duffy, CNN Business, “Nation’s largest school district bans AI in the classroom through 8th grade,” September 2, 2026, https://edition.cnn.com/2026/09/02/tech/new-york-city-classroom-ai-ban; Arthur Jones II, ABC News, “New York City Public Schools banning AI use through middle school starting this year,” September 2, 2026, https://abcnews.com/Technology/new-york-city-public-schools-banning-ai-middle/story?id=136134872.

Comment on this story →  ·  Forward this →

. . .

TWO LABS DECIDE WHO GETS THE DANGEROUS MODEL. On Sept. 1, Anthropic and OpenAI each announced a flagship model and drew a line around who could use its most capable form. Anthropic released Claude Fable 5.1 to everyone, but said Claude Mythos 5.1, “the same model, but with different levels of safeguards,” is available “only through our trusted access programs.”

Anthropic’s page names two Mythos 5.1 access channels, a Cyber Verification Program for defensive security work and a Life Sciences Verification Program for professional research. The Verge separately reported Mythos 5.1 is “available to Project Glasswing participants only.”

The page adds a line that does not specify whether it covers both programs or the cybersecurity one alone: “Currently, it is only available to a set of US organizations, though we’re coordinating with the US government to expand access.”

Fable 5.1 costs about 25 percent less than Fable 5 for typical work and up to 45 percent less for agentic tasks, with cache reads cut to $0.25 per million tokens. Anthropic now lets Fable 5.1 identify software vulnerabilities, The Verge reported, while still redirecting penetration testing and exploit generation to Opus models.

. . .

OpenAI’s definition: Astra “meets the Critical cybersecurity capability threshold under our Preparedness Framework, meaning that with the right tools and access, it can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step.”

OpenAI said advanced cybersecurity workflows go first to “a small group of alpha testers,” then expand “through Daybreak Blue” for defensive use. Astra refuses 91.5 percent of cyber jailbreak requests in its own testing, against 59 percent for GPT-5.6 Sol.

OpenAI paused parts of Astra’s training for two weeks after the Hugging Face incident and restarted its largest frontier RL run on Aug. 28.

. . .

The day before, Anthropic explained its caution. On July 30 it had reported three incidents in which Claude models gained unauthorized access to real computer systems during testing. A fourth, involving Claude Mythos 5, came from the UK AI Security Institute on Aug. 4.

Anthropic paused higher-risk reinforcement learning for several weeks and said it plans an independent review with METR. It renewed its call for “a lawful, verifiable, effective mechanism for coordinated pacing.”

For Legislators: Two companies decided, on their own, who gets their most capable models, and Anthropic names the US government as a coordination partner for wider Mythos 5.1 access.

For Regulators: Astra is, by OpenAI’s own account, the first model it has designated at the top tier of its Preparedness Framework. Ask each lab for the criteria behind its access line.

For Investors: Anthropic is preparing a stock listing while disclosing three hacking incidents in one summer and a paused RL run, and OpenAI delayed its own flagship model over cyber risk. Both chose the delay.

For Readers: The two companies behind the AI tools you likely use each said, the same day, that their newest model’s strongest capabilities will not be openly released, one gated by government coordination, the other by a small group of alpha testers.

Why it matters: On the same day, two labs each held back the strongest version of a new model, and each remains the one who decides, with the US government as coordination partner and no public rule, who gets the more dangerous version.

Source: OpenAI, “Path to Astra: critical capabilities and frontier safeguards,” OpenAI, September 1, 2026, https://openai.com/index/path-to-astra/; Anthropic, “Claude Fable and Mythos 5.1,” Anthropic, September 1, 2026, https://www.anthropic.com/claude-fable-and-mythos-5-1; Stevie Bonifield, “Anthropic launches Claude Fable 5.1 and says it’s up to 45 percent cheaper for agentic work,” The Verge, September 1, 2026.

Comment on this story →  ·  Forward this →

Thirty complaints naming the room where OpenAI said no. A patient chart on a vendor’s servers under terms the vendor can change. A children’s law passed 39 to 0 in the Senate after the governor got a text. Eighteen days from a school-shooting prompt to an arrest. The country’s largest school district pulling the machine out of the classroom. Two labs keeping the list of who gets the dangerous version.

One day’s paper.

We keep the ledger.

Today's Question

Chatbot flags a user planning a school shooting. Who decides whether police get the call?

Safety team, no override
Standard written into law
Company executives
Nobody. Privacy wins

One tap. Results on the other side.

The Book • Out Now

Therapist in the Loop book cover: a therapist and a client in armchairs joined by a glowing loop of light

Therapist in the Loop

by Jess Jessop

One billion people live with a mental health disorder. Most will never see a therapist. Into that gap has rushed a generation of chatbots that talk like clinicians and answer to no one.

The book lays out the architecture this newsletter tests against every statute and docket: client, therapist, and machine, governed by Six Laws offered as an open safety standard.

The machine can help.

It cannot be left in charge.

Get the Book on Amazon →

Kindle, hardcover, and paperback

More On Our Radar

Pentagon AI chief sold Perplexity Emil Michael, the official who ran the war on Anthropic, sold $5 million to $25 million of Perplexity stock in June, the Guardian reports from his disclosures, after a 400 to 4,800 percent gain on xAI in January.

39 fake citations reach Canberra Guardian Australia found at least 39 submissions to parliamentary inquiries citing studies that do not exist, some of which committee reports then quoted.

Anthropic calls in METR After three sandbox escapes and a UK AI Security Institute incident with Mythos 5, Anthropic paused high-risk training environments, built an escape classifier, and asked METR for an independent review.

FDA lets a therapy voice agent skip the line STAT reports the FDA's TEMPO pilot lets Limbic's Unpacked, an AI voice agent that delivers cognitive behavioral therapy by phone to Medicare patients under clinician oversight, reach patients before premarket review; the FDA's own table says it is not for anyone with suicidal ideation.

Brush Your Brain - The jingle

that started a movement

Watch on YouTube

This Issue

Your chart, their servers.

Not my records
Send to my doctor
BAA covers it
Explain the subpoena
Share the issue

If you or someone you know is in crisis, call or text 988 (Suicide and Crisis Lifeline).

Jess Jessop is the Founder and CEO/CTO of Clinician Assist Inc. (BetterMind.Space), building a voice-first AI-native mental health EHR with Casey Life and Peer AI Coach supervised by licensed therapists. A disabled veteran and 25-year AI/software engineering veteran, Jess brings lived experience as a mental health client to the mission of making daily mental health care as integrated as oral care.

ClinicianAssist.ai  |  BetterMind.Space  |  JessJessop.info

Subscribe  |  Archive  |  Unsubscribe