Gradient Briefs logo

Gradient Briefs

Archives
Log in
Subscribe
30 September 2026

Your September 2026 Gradient Brief

Gradient Briefs — Issue #005
A string of incidents has come to light in which agents undergoing training and testing inside frontier labs found each other and began coordinating without instruction. Their environments were built ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ ͏‌ 
Someone forwarded you this? You can subscribe here.
Gradient Briefs
A newsletter by Gradient Institute - Pursuing science-based clarity among AI uncertainties
Issue #005 · September 2026
1
Making sense of…
The AI agent swarms nobody intended
A string of incidents has come to light in which agents undergoing training and testing inside frontier labs found each other and began coordinating without instruction. Their environments were built for a single agent working alone, but they reached out over unexpected channels such as a software cache, a dormant wiki or a shared code repository. People working on multi-agent risk, like us, had mostly pictured multi-agent systems as persistent agents deliberately deployed to interoperate, but this time coordination emerged in training and evaluation environments. Once the agents were in contact, their behaviour exhibited risks we had described in Risks and Controls for Multi-Agent Systems, a report we authored for the Australian AI Safety Institute. They pursued goals nobody set, built their own infrastructure, and communicated in ways their overseers couldn’t follow. In this new article, we examine how the agents found each other and why the conditions were primed for it. We then look at what emerged once they coordinated, why nobody noticed sooner, and what lessons can be learned.
Read the full analysis →
✉ EmailShare to LinkedInShare to 𝕏
2
On the radar
1. Frontier AI incident reporting is open for consultation. PM&C’s Getting it right paper proposes, amongst other things, that frontier labs authorised to train large models in Australia meet minimum security and safety expectations, including disclosing defined reportable AI incidents. The Medicare breach reported on 24 September, which some researchers call the first government hack by autonomous AI, makes “what counts as reportable, and how fast?” a live question. Submissions close 5 pm AEDT, 9 October.
2. Australia joins the Call for Control of Frontier AI Models. Finland and Norway launched the Call at the UN General Assembly on 21 September, and about 20 countries plus the European Commission President have endorsed it. It asks for mandatory pre-deployment testing, independent evaluators with real access, shared incident reporting, and exploration of an international institution. A few days earlier, Anthropic CEO Dario Amodei proposed external evaluators with employee-level access, which Sam Altman and Elon Musk publicly backed.
Trendline: capability claims are moving from benchmarks to open problems. A year ago, the headline AI maths results were competition problems with known answers. On 8 September, OpenAI claimed a solution to the Navier–Stokes Millennium Prize problem. Scientific American has asked whether it solved the wrong version, and NYU’s Tristan Buckmaster says it built on unpublished work by him and Anthropic’s Levent Alpöge. Discounting the credit dispute, it remains impressive the pace at which AI agents are improving at tackling problems of such incredible complexity.
✉ EmailShare to LinkedInShare to 𝕏
3
Question of the month
If a frontier lab trains models on Australian soil, what should it owe the public in return?
We hear different sides of the debate. For example, one view holds that authorisation should come with hard obligations, such as incident reporting and independent evaluator access. Another warns that heavy conditions could push training offshore, leaving Australia with the same risks and less say over how models are built. What’s your view?
Reply to share your answer →
✉ EmailShare to LinkedInShare to 𝕏
4
Worth your time
TypeSafe AI releases Jev: A team led by an AI researcher who worked on the techniques behind ChatGPT takes a different approach from generative AI. Jev is a decision model trained strictly for automated classification, scoring, and routing tasks.
OpenAI’s framework for reporting model misalignment: OpenAI’s six first-hand reports of concerning model behaviour.
Information Security Manual: September 2026 changes: ASD’s new agentic-AI controls, including ISM-2156 (give agents only the tools and permissions they need).
How an AI math breakthrough ignited a controversy: Science gives a calm account of what OpenAI claimed about Navier–Stokes, including the roughly 10,000 agents over 88 hours, and why the credit is contested.
AI Agents Push Humans Out of the Loop: Mitchell, Ghosh and Passi argue that current agent designs erode the human oversight they rely on, and that long-term use weakens the skills that oversight requires.
Wine of the month
2023 Podere Pradarolo Vej Bianco Antico 180 Emilia IGP Malvasia. Six months on the skins. Mandarin peel, dried herbs, black tea, a white with the grip of a red. (Why do we like wine?)
Events
What Is AI Asking of Us?, 8 October, 5:45pm AEDT. · Save the date: A Gradient Gathering on AI Slop, 16 November, 6:00pm AEDT.
Follow us
LinkedIn · Web · X
Media enquiries
For all enquiries (including media, speaker, education, advisory and research), please email info@gradientinstitute.org and address it to Sarah.
Who may be interested?
Forward this to them.
✉ ForwardShare to LinkedInShare to 𝕏
You’re receiving this because you subscribed to Gradient Briefs. Unsubscribe
Missed the last issues? Check the archives.
Don't miss what's next. Subscribe to Gradient Briefs:
Older → Your August 2026 Gradient Brief
LinkedIn
www.gradientinstitute.org
Twitter