The week in AI, 28 September to 4 October 2026
Week of 28 September to 4 October 2026, with the previous week for context. Five stories follow. Google released Gemini 4 Argon to vetted security teams first, Anthropic and OpenAI shipped Claude Sonnet 5.5 and GPT-6.1 Sol at $2/$10, OpenAI launched its dots assistants, Anthropic reported on the open-weights GLM-5.3 and OpenAI on a distillation campaign, and AMD agreed to buy World Labs. Details come from the atlas release and talent logs, which are unverified drafts, so treat specific numbers as leads.
The week in brief
Google released Gemini 4 Argon to vetted cyber defenders first, and Anthropic and OpenAI shipped Claude Sonnet 5.5 and GPT-6.1 Sol at $2/$10 per million tokens.
Google DeepMind's Gemini 4 Argon (30 September) was the headline release. It went first to vetted cyber defenders, with developers, enterprises and paying consumers to follow. That makes three of the big labs, Anthropic with Mythos in April, OpenAI with GPT-6 Astra in September and now Google, that release their top model in stages.
Below that top tier, the releases competed on price. Anthropic's Claude Sonnet 5.5 (28 September) kept Sonnet's $2/$10 price and posted a large jump on Terminal-Bench 4.0. OpenAI's GPT-6.1 Sol (29 September) claimed near-Astra results on agentic coding at about a fifth of Astra's price. Both followed the previous week's Claude Opus 5.5 and GPT-6 Sol/Luna. Capability first appears in a gated, expensive tier and reaches a cheaper model within weeks.
OpenAI launched dots at DevDay, persistent assistants with their own cloud computer and identity in Slack. Anthropic had merged Cowork and chat into one Claude two weeks before, and Meta turned Muse into a shopping-capable agent. Two security reports covered Anthropic's study of the open-weights GLM-5.3 model's exploit ability and an OpenAI report on a distillation campaign it attributes partly to people associated with Moonshot AI. Both show the cost of the diffusion speed that the rest of this atlas tracks. On the research-lab side, AMD agreed to buy World Labs.
Google released Gemini 4 Argon to vetted cyber defenders first
Gemini 4 Argon went to vetted cyber defenders before anyone else, which makes Google the third lab after Anthropic (Mythos Preview) and OpenAI (GPT-6 Astra) to put its top model behind a defender-first gate.
What happened
Google DeepMind introduced Gemini 4 Argon on 30 September as a new frontier model aimed at long, complex work, with a one-million-token output limit as well as its input context and a reported 77.9% on the DeepSWE v1.1 software-engineering benchmark. The first users were vetted cyber defenders through a Google programme, under the US voluntary pre-release access process; developers, enterprises and consumers on paid plans are scheduled later. Google also said its own agents had used the model internally before launch.
Why Anthropic, OpenAI and Google gate their top models
Staged release is an old idea. OpenAI staged GPT-2's release in 2019 on misuse grounds and was mocked for it. In 2026 the models became useful for offensive security. In April, Anthropic said Claude Mythos Preview found software vulnerabilities better than all but the most skilled humans and gave it only to partners through Project Glasswing. In September OpenAI rated GPT-6 Astra "Critical" for cybersecurity under its own Preparedness Framework, its first model at that level. Argon makes Google the third lab to put its top model behind a defender-first gate.
If a model can find thousands of unknown vulnerabilities, a head start for defenders to patch them before attackers get the same capability is the main lever a lab has. Governments are now part of the release process, through voluntary pre-release testing and, in Anthropic's June case, an export-control directive that briefly suspended Fable 5 and Mythos 5.
Three layers of model access
The frontier model is now one most users cannot use yet. There are three layers to keep straight. The top tier is gated (Mythos, Astra, Argon), a public flagship sits one step below, and cheap fast tiers inherit the top tier's training within weeks. When someone asks which model is best, the answer depends on which layer they have access to.
What is still unmeasured
Whether defender-first windows reduce harm has not been measured. Nobody has published a full count of vulnerabilities fixed before general release, though Anthropic's May Glasswing update reported only 75 of 530 disclosed high or critical open-source bugs patched. It is also unknown whether attackers gained similar ability from other models in the meantime, and Story 4 suggests they partly can. Argon's general-availability date was not public by 4 October. Google has announced an introductory price of $2/$10 per million input/output tokens, rising to $4/$20.
Claude Sonnet 5.5 and GPT-6.1 Sol both launched at $2/$10 per million tokens
Sonnet 5.5 scored 70.6% on Terminal-Bench 4.0 against 10.3% for Sonnet 5 at an unchanged price, and OpenAI says GPT-6.1 Sol matches GPT-6 Astra on DeepSWE v1.1 at about one-fifth the cost.
The releases
- Claude Sonnet 5.5 (28 September) scored 70.6% on Terminal-Bench 4.0, against 10.3% for Sonnet 5 on the same benchmark. It is about 30% faster, and the price is unchanged at $2/$10 per million input/output tokens. Anthropic says it is the first Sonnet to beat Pokémon Red from screenshots alone, and it scores two points below Opus 5.5 on GDPval-AA.
- GPT-6.1 Sol (29 September) is an upgrade to GPT-6 Sol that OpenAI says matches Astra on DeepSWE v1.1 at about one-fifth the cost, at $2/$10. OpenAI treats it as Critical-capability for cyber purposes.
- Last week's context included Claude Opus 5.5 (22 September), which matched Fable 5.1 on most work at 40% less than Opus 5, priced at $4/$20. GPT-6 Sol and Luna (22 September) brought Astra-era training to tiers at $2/$10 and $0.10/$0.50. xAI's Grok 4.7 (21 September) shipped about six weeks after 4.6, and Xiaomi's open MiMo-V2.6-Pro (21 September) became the top-rated open-weights model on Artificial Analysis at launch.
Distillation and architecture efficiency
Two things push capability down the price ladder. The first is distillation, where a cheaper model is trained on the outputs and behaviour of the gated top model and inherits much of its skill at a fraction of the inference cost. The second is architecture efficiency, since sparse mixture-of-experts, sparse and linear attention, and lower-precision arithmetic mean each answer needs less compute. DeepSeek's V4.1-Flash (10 September) and its new libraries for Huawei's Ascend chips (29 September) show how much of the cost reduction is now engineering.
Price history since GPT-4
The field has followed this curve since 2023. GPT-4 launched at $30/$60 per million tokens, and within eighteen months models matching it cost under a dollar. The B08 deep dive records Epoch AI's estimate that the cost of reaching a fixed benchmark score has been falling by roughly half every quarter. In 2026 the move from gated frontier to mid-tier takes weeks.
Caveats on the comparisons
Benchmark comparisons across labs use different harnesses and effort settings, and "matches the top model on most work" is a company claim. Cost per completed task, which is what matters for agents, depends on how many tokens a model spends thinking as well as its list price. Independent cost-per-task measurements for these releases were not yet available.
OpenAI launched dots, assistants with their own cloud computer and Slack identity
OpenAI's dots have their own cloud computer and Slack identity, Anthropic's merged Claude keeps working after the laptop closes, and Meta announced a Muse agent with its own email address.
What launched
- OpenAI dots (DevDay, 29 September) are proactive assistants, each with a name, an identity in Slack and its own cloud browser and computer, that keep working on projects and can use your laptop with permission. They run on GPT-6 Astra and launched for Pro, Business Premium and Enterprise users.
- One Claude (16 September) is Anthropic's merger of Cowork and chat into a single experience, with Docs, Slides and Design available in any conversation and work that continues after the laptop closes. It was followed by Claude Marketplace (23 September, 2,000+ connectors and plugins) and Claude Code mods (1 October), small functions that change how the coding agent behaves.
- Meta Muse agent (23 September) was presented as a consumer agent with checkout partners, plus a Mac app, its own email address and a real-time talking avatar, most of them announced as coming soon.
- Cognition said on 25 September that its annualized revenue had passed $1 billion, less than two years after Devin became generally available.
What an agent needs besides a model
Each of these products is a worker you delegate to, and the model you prompt is one part of it. That puts memory across sessions, permissions, identity, sandboxes and recovery from mistakes over hours at the center. It also pushes pricing from per-token toward per-seat or per-outcome. The talent and acquisition stories of 2025 to 2026 (Windsurf, Manus, Cursor) were all bets on owning this layer.
Where these agents came from
The line runs from ReAct and function calling (2022 to 2023), through Claude computer use and MCP (late 2024) and Claude Code and Deep Research (early 2025), to Cowork and the coding-agent boom. See the Connections page, "Reasoning → tools → feedback → longer tasks," and the B10 deep dive.
Reliability over long unsupervised runs
Reliability over long unsupervised runs is still unproven outside company demos. Demos show agents working for hours, but independent evidence on how often they finish real business tasks correctly, and what it costs when they do not, is thin. Security also scales with autonomy, because an agent with its own computer and your Slack identity is a new attack surface for prompt injection.
Anthropic tested GLM-5.3 on exploits and OpenAI reported a distillation campaign
Anthropic reported that Zhipu's open-weights GLM-5.3 can build working exploits about two-thirds as often as its own gated Mythos Preview, and OpenAI described a coordinated campaign to distil its protected reasoning.
The GLM-5.3 study
On 29 September Anthropic published an evaluation of Zhipu's open-weights GLM-5.3. In its tests the model achieved a full control-flow hijack in 4% of trials, against 6% for Mythos Preview, and its built-in safeguards were bypassed in 64 to 100% of attempts depending on the method. Anthropic concluded that, about five months after it gated Mythos Preview for being too capable at offensive security, a freely downloadable model is in the same range.
The distillation campaign
On 30 September OpenAI said it had disrupted a coordinated campaign to extract protected reasoning from its models, with activity from July peaking at about 16,000 requests from more than 4,000 accounts in two days, and attributed a core cluster to people associated with Moonshot AI. This follows OpenAI's distillation concerns about DeepSeek in January 2025 and Anthropic's February 2026 report naming DeepSeek, Moonshot and MiniMax.
What this does to staged release
Both reports bear on staged release (Story 1), which assumes a lab can control who gets a capability for a meaningful period. Fast open replication, sometimes helped by distillation, shortens that period. If the window is a few months, gating is worth most as a head start for defenders, since it cannot keep the capability scarce. That is a sharper version of the diffusion pattern on the Spread page.
Caveats on both reports
Both reports come from interested parties, since Anthropic and OpenAI compete with Chinese open-weights labs and lobby on export policy. The attributions and the exploit-rate comparison were not independently replicated by 4 October.
AMD agreed to buy Fei-Fei Li's World Labs in a reported $8.2 billion stock deal
AMD agreed to buy World Labs, and David Silver's Ineffable Intelligence added six cofounders from DeepMind, InstaDeep and Flying Fish.
What happened
On 28 September AMD agreed to acquire World Labs, Fei-Fei Li's spatial-intelligence company, in a deal reported at about $8.2 billion in stock; Li becomes AMD's chief scientist reporting to Lisa Su. World Labs had shipped Marble (persistent, explorable 3D worlds) in November 2025. Earlier in September, Ineffable Intelligence, founded by AlphaGo lead David Silver to pursue superintelligence through reinforcement learning on experience, named six new cofounders, four from Google DeepMind, one from InstaDeep and one from the venture firm Flying Fish. Google DeepMind completed a reported $1.5 billion-plus talent deal that brought in Mechanize's Tamay Besiroglu.
Why a chip vendor wants a world-model lab
AMD's purchase is a bet that simulated 3D worlds will be a major compute workload, for robotics training, games and design, and that owning the models helps sell the hardware. It also follows other 2026 cases in which independent "age of research" labs either raised very large rounds (AMI Labs, Ineffable) or were absorbed. See Next bets for the world-models and RL-from-experience directions.
Also worth knowing
Media and voice
- Eleven v4 (28 September) is ElevenLabs' most expressive speech model, with inline delivery tags, consistent multi-speaker dialogue, 90+ languages and a roughly 150 ms Turbo variant. It came weeks after ElevenLabs' first major-label deal with Universal Music.
- Kling 4.0 (28 September, early access) makes native 30-second clips, with up to ten keyframes and fifteen reference inputs. Video generation now competes on length, control and sound as well as image quality.
- FLUX 3 Image (1 October) from Black Forest Labs adds layout control by bounding boxes and edits that leave everything outside the box untouched. This matters for agents that edit images repeatedly.
- Suno Speech (1 October, beta) generates voice and music as one track. Separately, Universal and Sony filed a second suit against Suno over v6 on 18 September.
Science and biology
- Anthropic reported (23 September) that about 950 Claude agents, over 21 hours, flagged a previously uncharacterized enzyme system with CRISPR-like repeats. It launched a life-sciences lab at the same time, six days after opening a verification programme (17 September) giving vetted biology teams models with loosened biology safeguards.
- Google DeepMind's SynthID Bio (30 September) watermarks AI-designed proteins in the sequence itself.
- Microsoft's Quine (29 September) is a biology research system that proposes interventions before wet-lab tests, limited to a fellows programme.
Infrastructure
DeepSeek described its sandbox platform for agent RL, about three million sandboxes a day, and released versions of its core training libraries for Huawei's Ascend chips. Both show how Chinese labs are building around US export controls.
People this week
- Jacob Coxon resigned from Anthropic on 8 September and published a widely shared warning that labs are compromising oversight to keep pace.
- David Robinson left OpenAI and published an essay in The Atlantic (3 October) arguing that the company's optimism, as it sprints between launches, falls short of its responsibilities.
- Andrew Tulloch left Meta Superintelligence Labs (reported 9 September), a year after Meta recruited him from Thinking Machines; his destination was unconfirmed.
- Barret Zoph moved from OpenAI to Google DeepMind in late August as vice president of research, working on RL and post-training, seven months after returning to OpenAI from Thinking Machines.
As in 2025 and 2026, senior researchers move between the three or four best-funded labs, and a few leave publicly with criticism of safety practices.
What did not change
- Public benchmark gains still do not establish reliability on a user's own long-running workflow. Most headline numbers this week are company-reported.
- No research-first lab (SSI, AMI Labs, Ineffable) has released a model, so the "age of research" thesis has so far been tested only with money and hiring.
- World-model and robotics demonstrations have not settled how well these systems transfer to messy physical environments.
- The gap between gated and public models is still weeks to months.
What to watch next
- Argon's wider rollout will show when developers and paying users get access and whether the $2/$10 introductory price (then $4/$20) holds.
- Independent cost-per-task results for Sonnet 5.5, GPT-6.1 Sol and Opus 5.5 on agentic work.
- Measured outcomes from deployed agents (dots, Cowork, Devin), beyond company demos.
- Policy responses to open-weights cyber capability and distillation, especially in the US.
- Qwen 4, which Alibaba says is in training, and whether DeepSeek ships a V4 successor trained on Ascend.