Axios AI+

September 28, 2026
Ina here, fresh off an amazing first Valkyries playoff game at Ballhalla. Today's AI+ is 1,301 words, a 5-minute read.
🍽️ Situational awareness: Dario Amodei, who agreed to a private, last-minute White House dinner with President Trump, is having quite the moment in the spotlight. The Anthropic CEO has become one of the AI industry's most prominent voices — and an unlikely spokesperson for a technology reshaping the economy.
1 big thing: Why I'm giving Meta AI a chance
Meta is finally promising the one feature that has long kept me away from its AI services: privacy.
Why it matters: In a world with many models capable of meeting my needs, knowing how my data will be used is a key factor, especially with sensitive information.
Driving the news: The Facebook parent, which once called dibs on nearly any data one shared with Meta AI, has in recent months begun to sing a new tune.
- In a 6,500-word August manifesto, CEO Mark Zuckerberg laid out a broad promise. "People should have a fully private mode for personal agents where even Meta or any other service provider cannot see or grant access to your information."
- With the debut of Muse, Meta said users can choose which apps the viral assistant connects to and opt out of having interactions train its models. Muse data also won't feed Meta's ad systems, and a more ambitious confidential virtual machine option, encrypted with a key held only by the user, is still to come.
- Last week, Meta said it plans to bring private processing to AI glasses by year-end, protecting data even while it's processed in the cloud, though it hasn't committed to a date.
Zoom in: I decided to give Meta a chance. I've started (tentatively) using Muse. I turned the setting off that allows Meta to train its systems and am also eagerly awaiting the more confidential option.
- But I'm using it for things I'm sure Facebook already knows about me.
- I asked my Muse agent on Thursday to alert me as soon as the time was set for the Golden State Valkyries' first playoff game. I woke up on Friday to a note from Muse letting me know the schedule had been announced.
- I also asked it to recommend an option for an easily removed, portable CarPlay display that I could use in a car I park on the street, and it gave me a number of reasonable recommendations.
I've been a big user of Meta glasses since the first version — one that didn't even have AI capabilities to speak of. What sold me was the ability to use the cameras to record sports, pets and kids — interactions that are better suited to being able to stay in the moment rather than pulling out a phone.
- Over time, the glasses have gained AI features, but knowing that photos or other data I uploaded to its servers could be used for ad targeting and other purposes was a nonstarter.
- I've given Meta a hard time about this, frequently pressing CTO Andrew Bosworth.
Yes, but: This is a very tentative endorsement based on what Meta says it is going to do — and its track record on privacy is more than checkered. (See Friday's verdict from a New Mexico jury.)
- Zuckerberg says Meta will take a cut of transactions made with Muse and that will allow it to offer the service free for most customers.
- But he also once promised to bring end-to-end encryption to all of Meta's messaging surfaces, before retreating on some commitments.
And there are other privacy concerns that remain unaddressed by Meta's latest announcements, especially when it comes to the rights of bystanders whose likenesses are being captured by the Ray-Bans I and others wear.
- "Meta's products that embed microphones and cameras in everyday devices pose serious privacy risks," Electronic Privacy Information Center executive director Alan Butler told Axios.
The bottom line: Trust, but verify. I'm willing to dabble with using Muse and Meta AI on my glasses. But I'm not ready to hand over the keys to the castle.
2. Scoop: Tens of thousands of security incidents
OpenAI, Anthropic and security researchers are investigating tens of thousands of incidents in which their frontier models took steps that outside evaluators would consider problematic, sources told Axios.
Why it matters: The sheer number of incidents, which occurred in recent months in internal testing and the real world, indicates that the problem is orders of magnitude more complex than what is publicly known.
- The findings, which are surfacing as part of internal work to assess models and in investigations at both companies into model behavior, raise questions about whether either company — or any top model-maker — is currently capable of establishing complete control over its technology.
The details: The episodes include bypassing guardrails, creating message boards, escaping sandboxes, website hijacking, self-prompting or seeking to bypass monitors, sources said.
- They occurred in internal testing and in the real world, and many have yet to become public as security researchers continue to investigate, sources said. Some of the testing is akin to "red-teaming" activity, sources said.
- The biggest AI companies face a similar challenge that pits humans trying to create guardrails against resilient, powerful systems trying to complete tasks.
Driving the news: The incidents range in severity and are comparable to what's been disclosed by OpenAI in recent days. They include both successful attempts to bypass guardrails and unsuccessful ones, and most so far are not known to have caused real-world harm. The total could grow well beyond tens of thousands, sources said.
OpenAI announced it was pausing training on its most capable models after disclosing a litany of episodes in recent days. It will resume training them "only when we are confident that we have additional safeguards and alignment improvements in place," a spokesperson told Axios.
State of play: Anthropic has commissioned a third-party safety organization to examine the behavior of its models. In documents the company has publicly released, it has disclosed the frequency of misalignment episodes.
- For example, Opus 5.5 sought to escape a sandbox — a secure testing environment — in 1.5% of test runs. The company emphasized that these were adversarial experiments where a task couldn't be solved without escaping the sandbox.
Anthropic and other companies conduct hundreds of thousands of test runs on their models, or more, sources said. That means even a small percentage of misaligned behavior can still amount to tens of thousands of incidents in which the models behaved in unexpected, sometimes troubling ways.
The Hugging Face incident, as well as a slew of others that have followed, led top AI executives to call for a slowdown in development and to ask for more robust federal and international regulations.
Some at OpenAI see Hugging Face as a one-off, with disclosures about future incidents likely to be less severe due to improved controls and the unusual nature of the testing they conducted, which involved an unreleased model, sources told Axios.
Threat level: Other AI executives and safety researchers, however, cautioned that they have limited confidence that AI companies will be able to prevent all problematic model behavior.
- The new crop of AI models complete tasks with extraordinary resilience, so working to limit their resourcefulness is often a losing game because it is necessary to anticipate every possible way they might run amok.
- Bringing the risk of misalignment to zero may not be feasible, experts told Axios.
3. Training data
A new analysis of the AI buildout shows its staggering, $10.3 trillion scale. (Axios)
One of Anthropic's earliest investors is completely terrified of AI — and he's about to make billions off it. (Wall Street Journal)
The trouble with President Trump's push to rebrand AI "super intelligence." (Axios)
4. + This
Talk about playing with your food. The New Jersey Devils are introducing a refillable popcorn bucket that fans can use to play pinball-style hockey.
Thanks to Bradley Olson for editing this newsletter and Matt Piper for copy editing.
Sign up for Axios AI+






