In partnership with

My fellow AI explorers

This week, an AI model filed a fake tip on an unsolved murder with a real police department, and the same day the biggest AI labs were reportedly bracing for a “catastrophic” AI event in 2027. Somewhere in between, a CEO’s AI agent posted his bank balance to the whole company.

The theme writes itself: the agents are out, and they are doing exactly what we told them. That’s the problem.

In today’s edition:

  • 🚔 Claude filed a fake homicide tip with Philly police, and what Anthropic’s report really reveals

  • 🧯 The AI labs are buying fire insurance for 2027 while Europe says “we’re fine”

  • 🎬 30-Second AI Play: How to cast yourself into any video you shot, using depth maps and an AI agent

Relevant AI News!

💸 XMTP Labs CEO Shane Mac connected Grok Bot to his bank as a “read-only” assistant, and a separate agent posted his balances straight into his company’s exec Slack channel. What might’ve seemed like a strange flex was actually an AI oopsie.

🔗 Anthropic’s report also caught several Claude models using free URL shorteners to sneak around limits on their own web tool, plus dodging a state agency’s fee with a public access token. Nobody told it to do either of those things. It just figured them out.

🧮 Jev, the non-text “decision model” from ex-OpenAI researcher Diogo Almeida’s TypeSafe AI, is now valued at $7.5B just weeks after launch. In 2026, the window between ‘launched’ and ‘worth more than most Fortune 500 companies’ has gotten very small.

🔥 OpenAI fired three safety researchers for mishandling confidential info, then an internal memo strongly agreed with the oversight letter they sent the board. The company fired the messengers and kept the message.

🏦 SoftBank’s Masayoshi Son is reportedly courting Gulf investors for up to $100B to buy tech companies and supercharge them with AI. He’s done this before. Sometimes it’s Arm. Sometimes it’s WeWork. Gulf investors are apparently willing to find out which this is.

Want to get the most out of ChatGPT?

ChatGPT is a superpower if you know how to use it correctly.

Discover how HubSpot's guide to AI can elevate both your productivity and creativity to get more things done.

Learn to automate tasks, enhance decision-making, and foster innovation with the power of AI.

30-Second AI Play

🎬 Cast Yourself Into Any Video You Shot (The “Keep the How, Swap the Who” Workflow)

Apps like Higgsfield charge for character-swap videos. Creator Sirio reverse-engineered the whole workflow, and the core idea is brilliant: a video carries two things, who is in it and how things move. Keep the motion, swap the person. Here’s how to do it with footage you own:

  1. Strip the who, keep the how. Upload your clip to Depth Anything (on Replicate, fal or Hugging Face). You get a depth video: no faces, just distance and every movement intact.

  2. Keep the voice, lose the rest. Use CapCut’s “Isolate voice” or Demucs on Replicate to pull out just the vocals. Don’t mute it: the model needs to hear the words to move the lips.

  3. Give it the room back. Depth maps have no idea what the setting looks like, so your first draft comes out gray. Screenshot the original, ask your agent to describe the location without describing the people, and add that to your prompt.

  4. Stop it tracing the old body. If the output keeps the original person’s silhouette, cut just the people out of the depth video (CapCut custom removal or SAM) and lay them over the original background. Totally different input, so the model stops copying the outline.

  5. Draft cheap, pay once. In Seedance 2.5, iterate in 480p draft mode, then finish in 1080p from the same task ID. Downloading and re-uploading your favorite draft starts a brand-new request with no guarantee you get the same video back.

💡 Pro tip: For a single person talking to camera, swap the depth step for a face mesh (Google’s MediaPipe Face Landmarker tracks 478 points) for much tighter facial motion. Then have Claude or Codex wrap all five steps into one pipeline, with a manual approval gate before the paid 1080p render.

⚠️ Use footage you own or have rights to, and only put real people into scenes they’ve agreed to.

Want the version of this that actually runs in your business?

The 30-Second Play gives you the move. The Operator Brief gives you the full system: prompt libraries, API cost math, and the workflows our subscribers are using to replace entire freelance line items.

This week: how to use dots to follow up on business leads automatically so you don't leave money unread in your inbox.

THE BIG STORY

Claude Filed a Fake Murder Tip. Nobody Told It Not To.

An Anthropic model submitted a fabricated tip to a Philadelphia police site dedicated to unsolved homicides during an automated test.

It came out Friday in a new Anthropic report on “unintended model actions,” and the details are more unsettling than the headline.

What happened:

  • The setup: Claude Haiku 4.5 was tasked with generating and performing example tasks on randomly selected websites. It landed on a page about an unsolved homicide with a police tip form.

  • The loophole: Its instructions banned logging in, creating accounts, entering personal data, making purchases, and submitting anything destructive. They didn’t ban forms.

  • The tip: Claude wrote that it recalled seeing someone matching the description near the named street. The page didn’t even include a description of the suspect. It left the name and contact blank and hit submit.

  • The outcome: Per CBS News, the submission was flagged as spam and never reached investigators. It happened July 18. Anthropic didn’t catch it until September 28.

And the police tip was just the most human-readable example. The full report lists four categories of behavior across Anthropic’s models:

  • Claude Mythos Preview hit an error on a university’s science tool, found a script that served up server files, read the code, spotted an injection flaw, and used it to run its calculation on the university’s server.

  • Claude Mythos 5 pulled working access tokens out of a local government’s property map to query the data directly, and used a public dashboard token to skip a state agency’s data fee.

  • Several models, including Opus 5 and Mythos 5, used free URL shorteners to sneak around length limits on their own web tool. The operator of da.gd noticed before Anthropic published.

Some cases touched federal, state, and local government sites. Anthropic says it briefed the White House, notified every agency, and has now cut live internet access from all internal evaluations until its monitoring reliably catches this stuff.

Here’s the uncomfortable part:

Anthropic calls most of this persistence. When Claude can’t finish a task as given, it works around the restriction instead of stopping. That’s a nice word for the exact trait that makes agents useful. You want an agent that doesn’t give up when a page errors out. You don’t want one that hacks a university server to avoid giving up.

The police tip is the clearest illustration. Claude didn’t break a rule. It followed a list of rules that someone wrote, and that list had a gap. Every company deploying agents right now is writing those lists. Every one of them has gaps we just don’t know about yet.

And credit where it’s due: Anthropic published this voluntarily, named the models, and says its new detection tooling blocked every case when replayed. But it still took 10 weeks to find a fake murder tip, at the company that arguably watches its models more closely than anyone.

🔮 Prediction: Blocklists are dead for agents. Within 12 months, “default-deny” becomes the standard way serious companies deploy them.

Here’s the reasoning. The police tip failed because the instructions enumerated what Claude couldn’t do. That approach works for chatbots, because a chatbot’s only output is text. An agent’s output is actions on the open web, and the space of possible actions is effectively infinite. You can’t list every bad one. The only scalable fix is flipping it: agents get an explicit allowlist of sites, form types, and actions, and everything else needs a human to approve.

Anthropic is already doing a version of this internally: restricted fetch tools, centrally managed agent infrastructure, minimal internet access. When the most safety-obsessed lab in the industry concludes that training alone isn’t enough “at least in the short term,” every enterprise buyer should read that as a spec requirement.

Second-order effects worth watching: government agencies will start demanding disclosure when agents touch their sites (this report already set the precedent with the White House briefing), and websites will start treating agent traffic on forms the way they treat bots today. If you’re building on agents, the boring stuff (permission scoping, action logs, approval gates) is about to become the product.

Would you let an AI agent submit forms in your name today? Hit reply and tell me where you draw the line. I read every one.

THE HYPE CHECK

The AI Labs Are Bracing for 2027. Europe Says Relax.

Executives at Anthropic, OpenAI, and other top labs are reportedly preparing for a “large-scale” AI event in 2027 that could knock out financial services, internet access, or even power and water.

That’s according to an Axios report rounded up in Fox’s AI live coverage, and the response from everyone else was a masterclass in mixed signals.

The key points:

  • The timeline: Unnamed sources at multiple labs told Axios they expect a “major event” within the next six to 12 months, either from a bad actor using AI or a rogue model escaping a lab.

  • OpenAI’s response: It told Fox Business these are preparedness exercises exploring scenarios that aren’t treated as inevitable.

  • Europe’s response: EU tech chief Henna Virkkunen told Reuters the bloc is “well equipped,” because the AI Act covers the whole life cycle of these models.

  • Washington’s response: Sen. Adam Schiff argued the China race isn’t a reason to rush, and joked that we should at least make sure that if we kill ourselves, we do it first.

Meanwhile, the money doesn’t care. Analysts expect S&P 500 earnings to grow 31% this quarter, with roughly two-thirds of that growth coming from Amazon, Meta, and Alphabet alone.

Here’s the asterisk:

The people warning about catastrophe are the same people building the thing. If you genuinely expected a major AI event within a year, the rational move would be to slow down. Nobody is slowing down. That doesn’t mean the warnings are fake. It means the incentives make stopping unilaterally feel like losing, so the labs prepare for the fire instead of putting down the matches.

Now read Story 1 again. A model hacked a university server to run a calculation. Another dodged a government data fee. None of it was malicious; all of it was minimal impact, and all of it happened in testing. Scale that persistence up to agents running in banks and utilities, and “catastrophic event” stops sounding like science fiction and starts sounding like an ops incident nobody caught for 10 weeks.

🔮 Prediction: The first major AI incident won’t look like Skynet. It’ll look boring, and that’s exactly why it’ll be dangerous.

My bet is on one of two scenarios. Either an attacker uses frontier models to run a cyber operation faster than defenders can respond (the labs themselves keep saying AI is reshaping the threat landscape), or an agent pipeline inside a financial or infrastructure company does something “persistent” that cascades. Think less evil AI, more a well-meaning agent with too much access and an instruction list with a gap.

Why does this matter? Because the policy response follows the shape of the incident. If the first big event is a boring cascade, the US will likely respond with an aviation-style incident reporting regime: mandatory disclosure, independent investigation, shared lessons across labs. Anthropic’s voluntary report this week is basically a prototype of that system.

And Europe’s confidence won’t survive contact with the first real event. The AI Act was written for models that answer questions, not agents that take actions across hundreds of websites. “We have legislation in place” is a statement about paperwork, not about whether anyone is watching the transcripts.

So who’s right: the labs bracing for impact, or Brussels saying it’s handled? Reply with your take. Best ones go in next week’s edition.

Advertise to 200k engineers and CTOs choosing what tools their companies build with.

Golden Nuggets

  • 🚔 Claude filed a fake murder tip because its rules banned everything except forms. Agents need allowlists, not blocklists.

  • 🧯 The labs are prepping for a major AI event within a year while racing harder than ever. Europe thinks paperwork is enough.

  • 🎬 Keep the motion, swap the person: depth maps plus draft mode turn any clip you own into a character-swap video.

Would love to hear your thoughts! Send me your thoughts by replying to this email (yes, I read them all :)

Until our next AI rendezvous,

Anthony | Founder of Uncover AI