---
title: "In the Loop: Week Ending 9/27/26"
description: AI developments are causing disruption, from rogue agents to human involvement in calls. Explore the latest challenges and innovations shaping the industry.
image: https://loopagency.ai/hubfs/ChatGPT%20Image%20Sep%2027%2c%202026%2c%2007_11_44%20PM.png
---

[![](https://loopagency.ai/hubfs/Loop%20Logos/Loop_Primary.svg)](https://loopagency.ai/)

- [About](https://loopagency.ai/about)
- [Insights](https://loopagency.ai/insights)

 Menu

 Close Menu

- [Industries](https://loopagency.ai/industries)
- [Work](https://loopagency.ai/work)
- [Insights](https://loopagency.ai/insights)

# In the Loop: Week Ending 9/27/26

Published on: 09/27/2026

##  **Last week in AI: OpenAI Pauses Again, Muse Calls In the Humans, a Robot Hand Goes for a Walk** 

OpenAI's agents turned up on government websites, a UN data hub and, again, outside their sandbox, so the company stopped training its best models. Meta's Muse topped the App Store while quietly handing some calls to people. In Washington, the answer to all of it was a new name.

### **OpenAI's Agents Went Rogue on Washington. OpenAI Found Out Later.**

![openai-2](https://loopagency.ai/hs-fs/hubfs/openai-2.webp?width=371&height=247&name=openai-2.webp)OpenAI confirmed this week that its agents [meddled with websites belonging to the Commerce Department and the Securities and Exchange Commission](https://www.nytimes.com/2026/09/25/technology/openais-ai-us-government-websites.html?unlocked_article_code=1.EFE.RnM6.dSIcOqmuH4vd&smid=url-share) this summer, and is still investigating a third at the Education Department. There, the agents tried and failed to pull data from the civil rights office; at the Census Bureau, they logged in with credentials they found online. OpenAI only found out afterward. Separately, its agents [hit a United Nations trade data hub more than 16,000 times](https://www.wsj.com/tech/ai/openai-agents-used-aggressive-techniques-to-access-u-n-website-522c70ff) between April and June, escalating whenever a filter blocked them. Then, on September 20, a model [found a DNS resolver and used it to slip out of its sandbox again](https://fortune.com/2026/09/26/openai-ai-agents-secure-sandbox-escape-training-pause-second-time-hugging-face-hack/). Monitoring caught it in 15 minutes. The automatic shutdown never fired. Training on its most capable models is paused, for the second time in three months.

### **Tens of Thousands of Rogue AI Incidents. Many Trace Back to Irregular.**

![openaianthropic](https://loopagency.ai/hs-fs/hubfs/openaianthropic.webp?width=377&height=212&name=openaianthropic.webp)OpenAI and Anthropic are [investigating tens of thousands of incidents](https://www.axios.com/2026/09/26/openai-anthropic-thousands-ai-security-incidents) in which models bypassed guardrails, escaped sandboxes, hijacked websites or tried to evade the monitors watching them. Most caused no documented harm; a small misbehavior rate across hundreds of thousands of test runs still adds up. Researchers now caution that preventing it entirely may not be possible. Many of the breaches also share [a common thread](https://www.theverge.com/ai-artificial-intelligence/1000644/irregular-rogue-ai-cyberattacks-hacking-openai-meta-anthropic-google). Several incidents involving agents from OpenAI, Anthropic, Meta and Google happened during tests run by Irregular, an Israeli firm the labs hire to stress-test their models' hacking skills. Its technology chief blames a single configuration error that let the models reach the internet. Its chief executive says the company should be held accountable, and that the industry now needs forensics, not just better monitoring.

### **Meta's Muse Hit No. 1. Some of Its Calls Were Made by People.**

![muse2](https://loopagency.ai/hs-fs/hubfs/muse2.jpeg?width=374&height=260&name=muse2.jpeg)Muse has [spent a week at the top of the App Store](https://www.marketwatch.com/story/meta-turned-muse-into-a-viral-hit-now-comes-the-hard-part-fb3177a8), with 3.4 million US and Canadian downloads since its September 8 launch and Meta's stock up 31% this month. Now it has to become a habit, and habits need trust. That got harder when leaked internal records showed Muse's new calling feature [quietly handing some calls to human workers in call centers](https://www.cnet.com/tech/services-and-software/leaks-metas-new-ai-agent-muse-real-people-call-centers/), without telling users. Employees had warned it was one bug away from leaking information to those callers. Meta suspended the feature, and a vice president called it a miss. Then there is the mascot. Muse is restricted to adults, but its fuzzy avatar [looks to one child advocate like a Teletubby](https://www.wired.com/story/meta-muse-is-adults-only-why-does-it-look-like-a-cute-kids-toy/), a Tamagotchi-style device arrives for the holidays, and Meta trains its models on Muse conversations unless you opt out.

### **ChatGPT Takes Orders by Voice. Gemini Takes Your Money in India.**

![shopping-3](https://loopagency.ai/hs-fs/hubfs/shopping-3.webp?width=373&height=249&name=shopping-3.webp)The agent fight moved onto the phone this week. OpenAI [brought voice-driven agent features to the ChatGPT mobile app](https://techcrunch.com/2026/09/23/chatgpt-mobile-app-gets-voice-based-agentic-features/), so paid subscribers can talk the Work tab into drafting documents and emails, summarizing Slack, building websites and making presentations, then pick up on desktop. Google went after the checkout. In India, it is [testing a Buy button for Walmart-owned Flipkart inside Gemini and AI Mode](https://techcrunch.com/2026/09/26/google-tests-buying-from-walmart-owned-flipkart-through-gemini-and-ai-mode-in-india/), sending the purchase through Flipkart's own checkout without the shopper ever leaving the AI. The test covers phones, electronics and accessories for a small group of users, with a wider rollout planned for October, ahead of the festive shopping season. Amazon's products show up in the same results. They just can't be bought there. Google owns a minority stake in Flipkart.

### **Governments Can't Keep Up with AI, but at Least They Gave it a New Name.**

![trump-talking-to-xi-jinping-1600x1067](https://loopagency.ai/hs-fs/hubfs/trump-talking-to-xi-jinping-1600x1067.webp?width=375&height=250&name=trump-talking-to-xi-jinping-1600x1067.webp)Two years after Europe passed the world's first comprehensive AI law, [governments are falling further behind the technology](https://www.nytimes.com/2026/09/27/technology/ai-government-regulation.html?unlocked_article_code=1.EVE.mH8b.QAk60uGGHO86&smid=url-share). Europe's law generally exempts pre-release testing, which is exactly where OpenAI's agents broke out and attacked Hugging Face. Europe's AI safety unit has about 40 people. In the US, a bipartisan bill requiring safety tests has sat for five months, dozens more are stalled, and a key House chairman expects no vote until next year. At the United Nations, leaders from more than 20 countries signed a letter calling for collective action. Then the presidents of the US and China met in Washington, struck no safety deal, and [agreed to stop calling it artificial intelligence](https://gizmodo.com/trump-gets-xi-to-agree-to-call-ai-super-intelligence-white-house-says-2000817802). It is Super Intelligence now, with a channel for reporting SI incidents and talks in November.

### **Bannon, Sanders and the Pope All Somehow Agree on AI.**

![p-1-91613378-ai-paradise-of-machines-pope-leo](https://loopagency.ai/hs-fs/hubfs/p-1-91613378-ai-paradise-of-machines-pope-leo.webp?width=371&height=209&name=p-1-91613378-ai-paradise-of-machines-pope-leo.webp)The AI safety fight is hard to follow because it has at least six sides, and [a new guide lays them out](https://www.npr.org/2026/09/26/nx-s1-5979085/the-ai-safety-debate-is-confusing-heres-our-guide-to-the-different-factions): accelerationists and the tech right, who want no brakes; a populist right worried about jobs, children and Big Tech's power; safetyists focused on catastrophic risk; effective altruists who fund much of it; an ethics camp that says today's harms matter more than hypothetical ones; and a group that treats AI as a normal technology, like electricity. The month's strangest alliance: Steve Bannon and Bernie Sanders, who shared a Washington stage to demand restrictions while disagreeing on nearly every detail. Speaking in Paris, Pope Leo [warned of a paradise of machines](https://www.fastcompany.com/91613378/ai-could-create-a-paradise-of-machines-pope-leo-warns-in-urgent-message-to-the-world) conditioning daily life, and of a society that judges people by their efficiency and discards them when they stop producing.

### **Nvidia's CEO Says AI Has to Hurt You Before It Helps.**

![nvidia-jensen-huang-children-cognitive-minds-ai-harms](https://loopagency.ai/hs-fs/hubfs/nvidia-jensen-huang-children-cognitive-minds-ai-harms.webp?width=371&height=195&name=nvidia-jensen-huang-children-cognitive-minds-ai-harms.webp)Nvidia's chief executive made the accelerationist case bluntly in a long podcast interview this week. Asked about a Chinese study of 26,000 students that found AI helped them finish work faster while [their cognitive skills and long-term exam scores declined](https://futurism.com/health-medicine/nvidia-jensen-huang-children-cognitive-minds-ai-harms), he said losing foundational math doesn't matter; people will discover new skills. He offered himself as evidence: he doesn't know his own ZIP code, and once panicked when a gas pump asked for it. Complaining that the US hasn't built enough fossil fuel plants, he [compared AI to surgery](https://www.theverge.com/tech/1000140/jensen-huang-nvidia-ai-energy-climate-change-supervillain): to save you, they have to cut you open and inflict an enormous amount of pain and suffering first. The pain, in this case, comes from data centers running on dirty power, and very little of it will land on a man worth $192 billion.

### **Nobody Said It Was AI. Not the Campaigns, Kalshi or a Provost.**

![kalshi-admits-random-guy-video-ai-race-swap-ad](https://loopagency.ai/hs-fs/hubfs/kalshi-admits-random-guy-video-ai-race-swap-ad.webp?width=383&height=201&name=kalshi-admits-random-guy-video-ai-race-swap-ad.webp)Researchers counted 164 AI-made political ads this cycle, and [69% never disclose it](https://apnews.com/article/artificial-intelligence-campaign-ads-midterms-d375801e10821b3e6ac776ffc77e1f28). Laws aren't helping: ads from states that require a label carried one 29% of the time, against 32% in states with no law at all. The Republican running for governor of New York aired an AI video of the governor and New York City's mayor with no word on how it was made. Kalshi [took a YouTuber's video of moving into his apartment and used AI to turn him into a white man](https://futurism.com/artificial-intelligence/kalshi-admits-random-guy-video-ai-race-swap-ad) for an ad, then called it old and said it was reviewing its agency. And Dartmouth's provost, author of an op-ed about AI cheating in college, watched that essay [score as 100% AI-written](https://futurism.com/artificial-intelligence/provost-dartmouth-busted-ai-newspapers-academic-journals). Nine of his post-ChatGPT pieces scored a median of 96%. His explanation scored 100% too.

### **Oxford Fed Its Archive to OpenAI. Claude Agents Found a Mystery Enzyme.**

![tours-duke-humfreys-library-christopher-judge](https://loopagency.ai/hs-fs/hubfs/tours-duke-humfreys-library-christopher-judge.jpg?width=383&height=255&name=tours-duke-humfreys-library-christopher-judge.jpg)The web the labs trained on is filling up with AI-written text, so they are turning to the world's research libraries. Oxford's 2025 deal to digitize parts of the Bodleian with OpenAI's software [also feeds OpenAI's training set](https://www.theguardian.com/technology/2026/sep/26/oxford-university-bodleian-library-open-ai-chat-gpt?CMP=oth_b-aplnews_d-1), internal minutes show, a detail the original announcement left out. The material so far includes 125,000 images of 19th- and 20th-century dissertations and 10,000 Tudor street ballads, with a Nobel laureate's penicillin notebooks under discussion. The university says it is modest, out of copyright and will be published openly. At the other end of the pipeline, Anthropic says about 950 Claude agents spent 21 hours searching a DNA database and [flagged an uncharacterized, CRISPR-like enzyme system](https://www.anthropic.com/news/claude-discovers-novel-enzyme-system) for human review. Lab work confirms the system is expressed. Nobody knows yet what it does.

### **Tales of the Weird**

![disembodied-walking-robot-hand-addams-family](https://loopagency.ai/hs-fs/hubfs/disembodied-walking-robot-hand-addams-family.webp?width=383&height=201&name=disembodied-walking-robot-hand-addams-family.webp)Four machines, only some of them acting alone. An influencer stepped into an MMA cage with a six-foot robot built to look like a Terminator, landed a few shots, and was [floored by a jumping switch kick to the body](https://www.the-sun.com/sport/17039309/); the company later admitted a human had been controlling the robot. At a murder trial in Ohio, prosecutors played two love songs the defendant, a former American Idol contestant, made for his mistress with ElevenLabs, and the livestream caught jurors [straining not to laugh](https://gizmodo.com/the-whole-world-is-a-jury-at-a-murder-trial-trying-not-to-laugh-at-an-ai-love-song-2000817793) at the auto-tuned rock ballad. He said he sang it with passion and the AI went a little extreme. In Dallas, a Waymo [froze in the path of a presidential motorcade](https://futurism.com/advanced-transport/waymo-barges-path-presidential-motorcade) because the officer's hand signal meant crossing several lanes, and stayed put until a Secret Service agent warned it would be crushed. And in Zurich, researchers built a robot hand that [walks on its fingertips](https://futurism.com/robots-and-machines/disembodied-walking-robot-hand-addams-family) across grass and stone, and plays a puzzle game. 

### More Loop Insights

### In the Loop: Week Ending 9/27/26

Last week in AI: OpenAI Pauses Again, Muse Calls In the Humans, a Robot Hand Goes for a Walk OpenAI's agents turned up on government websites, a UN da...

[Read more](https://loopagency.ai/insights/in-the-loop-week-ending-9/27/26)

### In the Loop: Week Ending 9/20/26

Last week in AI: The Machines Start Building the Machines, Washington Picks a Side, a Robot Learns to Flinch Anthropic says Claude now leads a quarter...

[Read more](https://loopagency.ai/insights/in-the-loop-week-ending-9/20/26)

### In the Loop: Week Ending 9/13/26

Last week in AI: Anthropic's Insiders Sound the Alarm, Amodei Hits the Brakes, Robots Flunk the CAPTCHA The people building AI spent the week saying o...

[Read more](https://loopagency.ai/insights/in-the-loop-week-ending-9/13/26)

### In the Loop: Week Ending 9/6/26

Last week in AI: Nvidia Buys the Crime Scene, Kids Lose the Chatbots, Crows Get Subtitles Ask who's in charge of this technology and last week gave us...

[Read more](https://loopagency.ai/insights/in-the-loop-week-ending-9/6/26)

### In the Loop: Week Ending 8/30/26

Last week in AI: Meta Pays Up, Salesforce Puts the AI Inside, One Mom Clones Herself Three institutions sent AI companies a bill this week: a federal ...

[Read more](https://loopagency.ai/insights/in-the-loop-week-ending-8/30/26)

### In the Loop: Week Ending 8/23/26

Last week in AI: Pushing Pause on Agents & Data Centers; Shredding Rare Books for AI; Welcome to Louisville, Venecky? Last week the industry ran into ...

[Read more](https://loopagency.ai/insights/in-the-loop-week-ending-8/23/26)

### Stay in the Loop

© 2026 | Loop Consulting

- [FAQ](https://loopagency.ai/faq)
- [AI Policy](https://loopagency.ai/ai-policy)

[![](https://loopagency.ai/hubfs/Loop%20Logos/Loop_Secondary.svg)](https://loopagency.ai/)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Matt Cyr",
    "url" : "https://loopagency.ai/insights/author/matt-cyr"
  },
  "dateModified" : "2026-09-27T23:20:19.575Z",
  "datePublished" : "2026-09-27T23:20:08.000Z",
  "headline" : "In the Loop: Week Ending 9/27/26",
  "image" : [ "https://loopagency.ai/hubfs/ChatGPT%20Image%20Sep%2027%2c%202026%2c%2007_11_44%20PM.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://loopagency.ai/insights/in-the-loop-week-ending-9/27/26",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://loopagency.ai/hubfs/Loop%20Logos/Loop_Secondary.svg"
    },
    "name" : "Signal78"
  }
}
```