The AI Read
← AI News

September 14th 2026

Curated AI news and stories.

Carney proposes an international board for AI safety

Canadian Prime Minister Mark Carney called for a global technology stability board in a Bloomberg interview Monday. He proposed modeling it on the Financial Stability Board, giving the debate over AI safeguards a specific institutional proposal from Canada.

The proposal would make coordination among governments part of the oversight structure. Carney’s remarks establish Canada’s preferred approach, but do not establish an agreement to create the body or give it enforcement powers. SourcesB

Updated

Nasdaq closes down 0.6% after recovering from its early slide

The Nasdaq finished Monday down 0.6%, recovering from an early decline of 1.3%. The S&P 500 fell 0.5%, while the Dow lost 0.3%. AI shares remained under pressure, but gains elsewhere limited the broader decline.

US indexes at Monday’s close
Nasdaq composite-0.6%S&P 500-0.5%Dow-0.3%
Daily percentage changes, rounded as reported by AP. These are broad indexes, not AI-only portfolios.

The close supplies a completed trading session after the early selloff. Oil and Treasury yields also pressured markets, so the index losses cannot be attributed entirely to calls for slower AI development. SourcesBB

China rejects Amodei’s call to curb its AI capabilities

China’s Foreign Ministry pushed back Monday against Dario Amodei’s proposal to restrict Chinese AI capabilities while slowing frontier development globally. Spokesperson Guo Jiakun called for cooperation and criticized confrontation. The response follows the Anthropic CEO’s weekend argument for continued chip export restrictions.

The immediate obstacle to a coordinated slowdown is agreement on who accepts which limits. Beijing’s response establishes opposition to the proposed terms; it does not announce a reciprocal development pause. SourcesB

Updated

Anthropic reportedly picks Nasdaq and forecasts another adjusted profit

Anthropic has selected Nasdaq for its potential IPO, Reuters reported Sunday, citing Business Insider’s source familiar with the plans. A separate Reuters report, citing the Financial Times, says Anthropic told shareholders it expects positive for a second consecutive quarter.

The venue choice advances the listing preparations. The earnings claim adds a forecast that a public could eventually let investors examine. Adjusted operating income is a company-defined measure and does not establish positive net income or cash flow. Neither report establishes a completed offering. SourcesBB

AI slowdown warnings hit chip shares while software stocks rise

Nasdaq 100 futures fell 1.72% at 4:46 a.m. Eastern on Monday, Reuters reported, after leading AI executives endorsed slower capability development. Nvidia fell more than 2% in trading. ServiceNow rose 3%, while Adobe and Workday each gained 2.5%.

The split is consistent with investors marking down the suppliers of the AI buildout while easing their discount on software companies threatened by automation. It is an interpretation of an early trading snapshot, not evidence that spending plans have changed. Reuters also identifies rising oil prices and interest-rate expectations as pressures on the market. SourcesB

Tech borrowers now account for 44% of private credit in a BIS study

A paper published Monday puts technology companies’ outstanding private-credit borrowing above $1 trillion in 2025, or 44% of the total studied, compared with $22 billion and 22% in 2010. The authors link the expansion to lenders’ willingness to finance recurring revenue and .

Technology’s share of
201022%202544%
BIS study published September 14th. Technology includes software and other tech borrowers, not AI alone.

The study also finds narrower alongside weaker borrower fundamentals. This is evidence of concentrated exposure and potentially underpriced risk. It does not establish that those loans have already soured. SourcesA

Digital Realty starts its Turkish expansion with an Ankara campus

Digital Realty and Rönesans Infrastructure announced a joint venture Monday to develop data centers in Türkiye. Their first investment is an Ankara campus designed for more than 22 megawatts of IT capacity. The companies say land, power and permits are secured and early construction has begun, with completion scheduled for 2028.

Those prerequisites make this more concrete than a capacity target without a site. The announcement still describes a facility under construction. Its capacity will serve cloud and enterprise demand as well as AI, so the whole project cannot be counted as dedicated AI infrastructure. SourcesA

xAI asks the appeals court to block Minnesota’s nudification law

xAI filed a motion for an pending appeal on September 11th, according to the Eighth Circuit docket reproduced by Justia. It follows the district court’s September 4th refusal to block Minnesota’s law regulating AI tools that generate nude images of identifiable people.

The district judge found that xAI had not demonstrated irreparable harm and reserved the constitutional questions for further consideration. The appellate docket available for review was last retrieved September 11th; it establishes the new request, not an appellate ruling granting it. SourcesAA

Microsoft retires Excel’s COPILOT worksheet function today

Microsoft’s support notice sets September 14th as the date the experimental COPILOT function becomes unavailable. The formula let a spreadsheet send a prompt and cell references to an AI model and return generated text into the grid. Microsoft directs users to the Copilot in Excel instead.

A workbook built around the preview formula now needs a replacement workflow. The broader assistant’s availability does not establish that an existing formula-based process will continue unchanged. Microsoft’s notice confirms the retirement; individual tenant behavior was not tested. SourcesA

Anthropic details a Claude-assisted campaign against European political groups

Anthropic’s September threat report describes a French-speaking operator using Claude to attack political parties, media and associated service providers in the spring. It says a previously undocumented WordPress flaw succeeded against at least four websites. In another intrusion, approximately 140,000 records containing political opinions were taken from a campaign-management platform.

Le Monde’s September 11th reporting identifies a concentration of French far-right targets. These are findings attributed to the lab and the outlet, not a court-established identity for the attacker. The case illustrates how access to one organization’s software provider can expose politically sensitive data beyond that organization. SourcesAB

Apple plans SynthID support for generated and edited images

Apple’s iPhone Duo announcement says its image tools will support later this year, allowing users to identify AI-generated or edited images. The footnote narrows that promise: the mark will be included in most edited images, depending on the changes applied.

That qualification matters to anyone treating an absent mark as proof of an untouched photograph. Apple is announcing a future identification feature with exceptions. It is not claiming that every AI edit will become detectable when the operating-system updates arrive today. SourcesA

Firmus is reported to be seeking a larger Australian IPO

The Next Web reports Monday, citing Bloomberg, that data-center developer Firmus is seeking up to approximately $5 billion in an Australian listing. It reports no announced offer price or listing date.

The underlying Bloomberg report could not be independently inspected, so the proposed raise remains a secondary-source figure. Treat it as a reported financing ambition, with the currency basis requiring confirmation from the original report or an offer document. Firmus’s already disclosed customer contracts do not establish that an IPO has been filed, priced or completed. SourcesC

Robot training improves when images cannot shortcut the action task

Latent Interface Training, a September 11th preprint, first teaches a robot action model to reach spatial goals without images. It then introduces a constrained visual interface trained to preserve the goal’s position and orientation. The design aims to prevent the policy from depending on background details that happened to correlate with success during training.

Across four tested architectures, the authors report gains on the . Physical experiments across three tasks also improved under changed cameras, lighting and distractors. Those tests support the mechanism at a limited scale; they do not establish reliability across arbitrary factories or homes. SourcesA

The Agent Incident Registry separates real harm from demonstrations

The Agent Incident Registry, revised September 11th, collects 487 source-linked events disclosed from 2022 through 2026. Its labels distinguish actual outcomes from research demonstrations and responsible disclosures. A second human reviewer checked every record.

The authors explicitly warn against reading the collection as a deployment failure rate. That distinction gives evaluation teams a useful job: compare the surfaces their tests cover with the ways failures have actually been reported. The registry includes failures without an adversary, which attack-only tests cannot represent. SourcesA

BenchShield checks whether an agent tampered with its own score

BenchShield, submitted September 10th, instruments the path from an agent’s actions to its benchmark reward. It looks for ways the agent can change what the evaluator sees, and records evidence of whether those paths were used during a run.

The authors report 96% detection accuracy on their evaluated infrastructure evidence, using a human-labeled corpus drawn from public agent runs. The result concerns in an evaluation environment. It is useful because a correct-looking final artifact alone cannot establish that the test was conducted honestly; it is not a general agent-safety guarantee. SourcesA

A study finds that reusable skills benefit from separate agent contexts

A September preprint compares loading reusable skill instructions into an agent’s existing context with invoking them in a separate . The researchers find that the separate context works better when the skill has a clear input-output contract and enough procedural knowledge to fulfill it.

The cost is additional communication: the main agent and the subagent must exchange information. This gives builders a condition to test before splitting a workflow. Isolation helps when the boundary is well specified; merely adding more agents does not supply the missing contract. SourcesA

ChurnBench measures whether an answer became stale while data changed

ChurnBench generates changing enterprise data and keeps a separate history from which correct answers can be reconstructed. Its September preprint distinguishes a reasoning mistake from an answer that was accurate when retrieved but false by the time it was evaluated.

In a controlled experiment, disabling scheduled refresh increased freshness errors from four to 45 at the 28-day setting. The result makes refresh policy a testable variable. An old cache entry is not necessarily wrong if its contents remain current, and a recent one can miss a change that matters. SourcesA

2AM keeps a robot’s task memory outside its motion policy

The 2AM preprint separates remembering the job from executing movements. A agent holds the history and sends language instructions and optional two-dimensional spatial hints to an action model that does not retain memory between episodes.

On LIBERO-Mem, the authors report 76.3% average completion, but only 11.8% strict success. Those measures cannot be swapped. The experiment shows that an external memory holder can steer an action model through more of a long task, while the strict result exposes how often the whole task still fails. SourcesA

NovaFabric signs agent records and exposes the limits of replay

NovaFabric, a September 11th preprint, packages agent execution records with signatures and timestamps so later changes can be detected. It combines existing recording and provenance standards into a portable record for verification.

Its results are unusually instructive. Saved responses replaced every model call in ten test cases, but only two of the ten tool-using workloads completed because tool responses were not fully substituted. A sealed record can prove something about the captured evidence without recreating the external world that produced it. Third-party verification with standard tooling is specified, but not evaluated. SourcesA

Adversarial wind training improves simulated drone recovery at sea

A September 11th paper trains a drone and a ship-mounted robot arm to cooperate on midair recovery while another agent supplies adverse wind. The experiments run in Nvidia Isaac Lab, comparing this training method with randomized environmental conditions.

The adversarially trained policy performs better in severe sea conditions outside its training distribution and trades slightly more timeouts for fewer crashes. That is a useful safety tradeoff to measure explicitly. The evidence comes from simulation; the paper does not report a ship recovering aircraft at sea. SourcesA

Uno uses diffusion to accelerate a next-token model without a separate drafter

Uno, released in a September 3rd preprint, adds lightweight diffusion to a conventional next-token language model so it can sample several in parallel. The authors describe a sampling method that preserves the underlying model’s output distribution without requiring a separate draft model.

They report up to threefold speedups and release code and checkpoints. This is a research result worth testing against the intended batch size and hardware. Preserving the model’s distribution addresses a different question from whether its answers are correct. SourcesA

Keydris publishes a template for authorizing individual MCP calls

A Keydris template surfaced on lets an server exchange a single-use, action-scoped token for the needed by one outbound request. The server does not keep a standing credential of its own. The template refuses credentialed calls when its required gateway is absent.

This narrows how long a credential is available, but the credential still passes through the server when the request executes. The gateway and server therefore remain trusted components. It requires a Keydris account and integration work; the demonstration is not a finished server or an independent security audit. SourcesA

Kairo limits inference optimizations to workloads it has actually measured

Kairo, another Show HN discovery, publishes an research workbench with measurements from one RTX 5090. It records the model revision, workload and correctness checks, then recommends a runtime configuration only when the request matches a measured case.

Its reported Graph gains vary across workloads, and unmatched requests fall back to manual handling. This is a practical way to keep a favorable benchmark from becoming an unsafe global default. Kairo is an early research project, not a general-purpose replacement for a production inference engine; its measurements were not independently reproduced. SourcesA