NextWith.ai Daily · Pilot episode

Coverage: (UTC) · 8:27 · English

AI-generated narration. Based on NextWith.ai reporting. This pilot was produced after the coverage date.

Download MP3

In this episode

  • How Anthropic is measuring AI-led research
  • An AI-assisted bug bounty that crossed identity boundaries
  • New details in the Times copyright case
  • What these stories say together
Read the full transcript

Welcome

Hello and welcome to NextWith.ai Daily. I’m your AI-narrated host, and this is a retrospective look at the news covered for Friday, September 18, 2026. Today’s episode focuses on three different but connected questions: how labs measure AI’s role in their own research, how AI tools are changing the tempo of security work, and what newly unsealed court filings say about the use of news content in model training.

How Anthropic is measuring AI-led research

First, to Anthropic and how it measures AI-led research. Anthropic has published a new measurement framework that tries to separate three things that are often blurred together: how much research AI leads, how agents are monitored, and where computing resources are going. The company says the goal is to make its internal snapshots and methods useful enough that other labs can examine them, challenge them, and compare their own results against them.

The headline figure is that Claude led 26% of Anthropic’s measured AI research and development in August 2026, with humans supervising. But that does not mean the work became fully autonomous. In Anthropic’s own framing, no measured category reached fully autonomous operation. The company’s prototype index classifies work with Claude and weights it using an approximation of staff time, which matters because a percentage is only meaningful if the definition behind it stays stable.

The monitoring side is similarly narrower than it may sound at first. Anthropic says its oversight figures cover its most-used internal platform, not every deployment. And monitoring coverage describes which actions pass through checks; it does not show that every dangerous action is detected. That distinction is important because a system can look broad on paper while still missing a specific failure mode in practice.

The compute numbers also need careful reading. For July 13 through 20, Anthropic estimates safety received about 6% of AI-R&D compute and 12% of AI-driven AI-R&D compute. Those are different denominators, and the company says the estimates exclude safeguards classifiers and treat equally mixed safety and capability work conservatively. Its appendix also cautions that workload labels can be wrong, that one week cannot establish a trend, and that resource use is not the same thing as safety effectiveness. In other words, the report is useful because it shows its working, not because it settles the question by itself.

An AI-assisted bug bounty that crossed identity boundaries

Now, to cybersecurity and an authorised test involving OpenAI. Security researchers say an authorised bug-bounty test combined an exploit in forum software with an OpenAI sign-in weakness, reached employee ChatGPT and Codex accounts, and demonstrated a path into an internal code repository. OpenAI says it fixed the reported issues and paid the researchers a 6,500 dollar bounty. The public reporting is important partly because it is so specific about what happened, and partly because it stops short of claiming something more dramatic than the evidence supports.

The chain began on OpenAI’s Discourse-hosted community forum. According to SecurityWeek’s account, an image-handling path involving HEIC or HEIF uploads exposed a flaw in a library used by the forum software. The researchers then paired that foothold with an OpenAI-side sign-in or single-sign-on weakness. The reported result was access to employee ChatGPT and Codex accounts, followed by a demonstration of access to an internal repository. The proof point was a benign pull request rather than any attempt to read or extract sensitive source material.

That framing matters. The report does not say a model independently decided to attack OpenAI. It describes human-led research using Anthropic’s Claude and other tools during an authorised disclosure effort. It also says the third-party forum testing fell outside OpenAI’s bug-bounty scope. So the incident is not best understood as a single AI exploit; it is a chain made up of ordinary software maintenance issues, identity trust boundaries, and an access path that crossed from a public service into a more sensitive environment.

The researchers, identified as Hacktron, say they used Claude to help develop parts of the work and later used additional AI tools, including OpenAI models. The Guardian reported their claim that work that once might have taken a well-resourced group months could be compressed into days. That is a claim from the researchers, not an independent measurement, but it captures the larger operational point. AI can help with code comprehension, hypothesis generation, test construction, documentation review, and repetition. It does not remove human judgement, but it can lower the cost of trying more paths and connecting more clues.

For organisations, the practical lesson is to separate model-safety claims from application security. The controls that matter here are patch management, least privilege, short-lived credentials, monitored sign-in flows, and careful handling of third-party components that touch employee identity or support accounts. AI changed the tempo of the work, but the blast radius was still determined by conventional security boundaries.

New details in the Times copyright case

Our third story takes us to the courts, and the copyright dispute over news content. Unsealed filings in the New York Times’ copyright case against OpenAI and Microsoft became public on September 17, 2026, as the U.S. District Court for the Southern District of New York weighs summary judgment motions. The newly public material adds detail to a dispute over how the companies trained AI systems on news content, how they viewed paywalled journalism, and whether their products were cutting into publishers’ traffic.

According to the reporting, internal Microsoft and OpenAI messages show employees debating whether scraping large volumes of news articles amounted to a serious appropriation of publishers’ work. OpenAI staff also warned that chatbots could become increasingly substitutive for news. Another description from the unsealed material says one Microsoft document flagged a risk that AI products could damage the supply chain they depend on. Those are descriptions from the public filings as reported; they do not independently prove legal liability.

The same reporting says the plaintiffs allege OpenAI discussed ways to bypass publishers’ paywalls, and that Microsoft chief executive Satya Nadella testified paywalled material should be licensed if a company wants to use it for grounding or training. Microsoft says the internal memos cited in the case did not reflect the company’s views, and that Nadella’s testimony was about broader shifts in how people consume information rather than a copyright conclusion. OpenAI did not respond to requests for comment in the reporting cited here.

TechCrunch added scale to the plaintiffs’ claims. Citing the filing, it said OpenAI’s mid-training datasets contained more than 91,692 copies of works published by the Times, the New York Daily News, and the Center for Investigative Reporting, and that a Common Crawl-derived dataset included more than 2 million documents from nytimes.com. TechCrunch also noted that much of the fresh material comes from the plaintiffs’ brief, while some underlying exhibits remain sealed.

Why this matters is not that the filings settle the copyright question. It is that they give the publishers more material to argue that the companies knew their systems could displace original source material and still used the content anyway. That goes directly to the fair-use fight now before Judge Sidney H. Stein, who must decide whether enough of the case survives summary judgment to proceed further.

What these stories say together

Before we finish, let’s bring these three stories together. Taken together, these three stories point to a common theme: in AI, the words people use matter, but the definitions behind them matter more. Anthropic’s report shows that AI-led work is not the same thing as autonomous work. The bug-bounty disclosure shows that an AI-assisted research workflow can still depend on ordinary software flaws, trust boundaries, and identity design. And the Times filings show that internal documents, testimony, and dataset counts are not the same thing as a final legal ruling, even though they can still reshape the arguments on both sides.

That is a useful lens for readers and for organisations making decisions around AI. If a vendor says a system is monitored, the next question is what that monitoring actually covers. If a security team uses AI to accelerate testing, the next question is which dependencies can still turn a small weakness into a larger compromise. And if a company is weighing training data or grounding sources, the next question is whether it can document provenance and licensing clearly enough to defend the decision later.

The broader pattern is not that AI creates one new kind of risk, but that it compresses time across several older ones. It can speed research, speed exploitation, and speed the accumulation of evidence. That makes definitions, controls, and records more important, not less. The right reading of today’s stories is therefore cautious rather than dramatic: the stakes are high, but the evidence still has to be parsed carefully, source by source, claim by claim.

Close

That’s our roundup for today. Thanks for listening to this AI-narrated edition of NextWith.ai Daily. For the transcript and sources, visit NextWith.ai.

Reporting and sources

  1. Unsealed Times filings add new details on AI training data and publisher harm
  2. AI-assisted bug-bounty chain reached OpenAI employee accounts. The larger signal is security work at machine speed
  3. Anthropic measures AI-led research: what its numbers can tell us

Browse all episodes →