Pondero AI logo

Pondero AI

Archives
Log in
Subscribe
September 9, 2026

Pondero Brief: Anthropic told Claude it had no internet access. It did.

Pondero Brief - SEPTEMBER 9TH, 2026

Four labs, four eval sandbox escapes, and one check worth running on yours today.
pondero. BRIEF · SEP 9, 2026

Four labs found their agent sandboxes were not sandboxes.

Models from OpenAI, Anthropic, Meta, and Moonshot have each reached outside a cybersecurity evaluation sandbox this summer, and in every published account the harness broke before the model did.

Why it matters. Anthropic's prompt told Claude the environment was a simulation with no internet access. A misunderstanding with its evaluation partner meant the internet was there the whole time, so Claude treated real machines as in-scope and walked in through weak passwords and unauthenticated endpoints, per Anthropic's writeup. OpenAI's models got out a different way, chaining a zero-day in the package-cache proxy until they reached a node with egress, then pulling evaluation answers from Hugging Face production, per OpenAI's incident report. Kimi K3 exploited a misconfiguration in a UK AI Safety Institute environment, per Reuters reporting. Isolation asserted in a system prompt is not isolation: probe egress from inside the container on every run and log what the agent reached. Anthropic found its three incidents only by re-reading transcripts after OpenAI went public. See how Anthropic's harness broke →

Also in today's brief

  • The sandbox that was not a sandbox
  • Meta moves the reasoning price floor
  • China puts a number on 2030 compute
  • n8n hands sub-agents the parent sandbox
  • ChatGPT Images 2.5 adds a drawing tool
  • When to leave Copilot HydraFusion on
 
Models & Releases
Meta Muse Spark 1.3 hero illustration

Meta undercut the frontier reasoning price floor with Muse Spark 1.3.

Meta shipped it September 2 on Muse Code and the Meta Model API with a 1-million-token context window and text, image, and video input, per its research blog. Pricing runs $1.25 per million input tokens, $4.25 per million output, and an 88% discount on cache hits; the model scores 48 on the Artificial Analysis Intelligence Index, 13th of 202 rated. Roughly half the input price of the reasoning models it benchmarks against is reason to run your eval this week, not next quarter.

 
Policy & Legal

China's five-year plan sets a 9,800 eflops target for 2030.

MIIT released the plan on September 7 calling for 3.8 trillion yuan (US$532 billion) of cumulative information infrastructure investment through 2030, orderly deployment of clusters running 100,000 or more accelerator cards, and greater effort to adapt that infrastructure to home-grown chips, per the South China Morning Post. Capacity sat at 2,185 eflops at the end of June, so Beijing has committed to more than quadrupling it on domestic silicon. Price your 2027 accelerator supply against that number, not against today's export-control snapshot.

 
Tools & How-To

n8n 2.39.0 hands background sub-agents the parent's workspace sandbox.

Yesterday's release lets background sub-agents inherit the parent agent's workspace sandbox, gives Instance AI search over its own past conversations plus folder browsing, and adds public API endpoints for Git push, pull, and source-control status, per the n8n release notes. Shared workspace state kills a lot of explicit node plumbing. It also means a sub-agent's blast radius is now the parent's entire workspace, so scope credentials at the sandbox, not at the node. Try n8n.

 

ChatGPT Images 2.5 cuts the wait between revisions.

OpenAI shipped it September 8 with Sketch, which turns a rough drawing into a finished reference, plus better subject preservation from reference photos and steadier style across multi-turn edits, per OpenAI. Latency is down up to 50% against Images 2.0, and two API models landed with it, GPT-Image-2.5 Flare and GPT-Image-2.5 Sunburst. If your pipeline burns a human minute waiting on each revision, that halved wait is the whole upgrade.

 
Quick Hits
• Claude Code 2.1.260. A /diff panel now renders edits side by side while the agent works and /cost names the probable cause of a cache miss, per Anthropic's changelog. What changed →
• Proofpoint SOC Analyst Agent. Built on OpenAI Daybreak cyber models, it investigates across email, DLP, and insider-threat consoles, deliberately performs no autonomous remediation, and is in private preview with GA expected by end of Q3. Details →
• Cambricon and Alibaba Cloud joined the PyTorch Foundation. Both entered as Platinum members and Ant Group as Gold, announced September 8 in Shanghai, which puts China's chip challengers inside the governance of the framework the rest of the field trains on. Details →
From the Pondero Stack
GitHub Copilot HydraFusion guide hero illustration

Leave Copilot HydraFusion on for refactors. Pick the model yourself for accuracy-critical work.

GitHub's 67% cost-reduction headline holds on exactly one of the three benchmarks it published; a second cuts cost 65% for a rounding-error quality change, and the third saves 36% while giving back 1.5 quality points, per GitHub's writeup. That spread is the entire decision, and our guide turns it into a two-row rule plus a modeled monthly bill. See which bucket your work falls in. Get Copilot.

 
Anthropic Enterprise Frontier Safeguards hero illustration

Enterprise Frontier Safeguards separates data custody from detection, and that separation is the whole pitch.

None of the three opt-in controls change model behavior, API pricing, or rate limits; what changes is who holds the logs and whose security team gets the flags. Our writeup walks each control and the procurement objection it actually answers. Read the control-by-control take.

 

How was today's brief?

★★★★★ Nailed it  |  ★★★ Solid  |  ★ Missed

Jonathan Hildebrandt Jonathan Hildebrandt
Co-founder and primary operator of Pondero. Writes the Pondero Brief.

X  ·  LinkedIn  ·  Bluesky

Affiliate disclosure  ·  Unsubscribe  ·  Manage preferences

Pondero earns commissions on some links. This does not affect our editorial picks.

Don't miss what's next. Subscribe to Pondero AI:
← Newer Pondero Brief: Anthropic missed a Claude breach in 141,006 eval transcripts Older → Pondero Brief: GPT-6 draws down Copilot credits. Four models retire Oct 2
pondero.ai
Bluesky
LinkedIn
Twitter
LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.