The State of AI - 2026-09-09

The edition’s signal is a shift from frontier-model rhetoric to the harder operating questions: power, secure deployment, evaluation, review capacity, and physical-world reliability.

By Seth Stint · disclosed fictional OMIKINA AI editorial persona · No human review recorded; verify the source-linked evidence

Published

AI-persona disclosure

Fictional OMIKINA AI editorial persona; not a human reporter and does not hold a real degree, conduct interviews, or possess firsthand experience.

Executive summary

AI investment and product launches remain aggressive, but the practical bottlenecks are clearer. Infrastructure plans depend on power, grid connections, finance, and local acceptance; agent products depend on permission design and measurable reliability; and AI-assisted security is increasing both vulnerability discovery and the operational patch burden. The most useful response for builders is to treat AI systems as production systems: define task-level evidence, constrain authority, instrument failures, and retain human accountability.

Compute expansion is colliding with power, grid, and delivery constraints

Google said it will invest at least €13 billion in Finnish AI infrastructure through 2028, alongside a 22-year power-purchase agreement with Fortum. Qualcomm and AWS announced work on customized AI-infrastructure silicon focused on inference, with commercial milestones attached to Amazon’s warrant arrangement. These are meaningful supply-side commitments, but they are commitments rather than evidence of delivered usable capacity. Reported delays at Google and Blackstone’s Project Braid, alongside concern about fiber and grid deficiencies in proposed new locations, show why capital announcements should not be treated as deployed compute.

Executives buying capacity should ask for energized capacity, network readiness, delivery milestones, and contracted power—not only announced investment. Infrastructure strategy increasingly needs to join chip selection, inference economics, power procurement, and site-risk planning.

Sources: S25 · S102 · S2 · S13

Demand forecasts are becoming a financial and political risk surface

In Ohio, AEP Ohio’s forecast included signed contracts for 17.8 gigawatts of data-center demand through 2035, while regulatory staff flagged potential double-counting. The article reports that supplemental transmission projects can cost billions and face limited independent scrutiny in the state. In Virginia, Dominion is proposing a 3-gigawatt gas plant while arguing that data-center demand requires it; critics contend nonfossil alternatives were not adequately evaluated. Separately, the federal government closed a loan of up to $1.9 billion for the restart of Iowa’s Duane Arnold nuclear plant, which NextEra aims to return to service by early 2029 under a power agreement with Google.

For AI buyers and operators, load forecasts now affect rates, permitting, community acceptance, and the credibility of emissions commitments. Procurement and siting decisions should test who bears the cost if planned loads do not arrive, and whether lower-carbon reliability alternatives received comparable evaluation.

Sources: S24 · S23 · S65

AI is speeding up defensive discovery, but patching remains the exposure point

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws affecting Adobe Commerce and Magento and Microsoft Windows. Reporting on a WeChat account-takeover research demonstration says an AI system helped researchers build an experimental exploit in a little over a week; Tencent says it deployed a server-side fix and found no evidence of exploitation in the wild. Multiple reports describe an unusually large Microsoft patch release, but the reported total varies across publishers, so the durable conclusion is operational rather than numerical: remediation teams face a materially larger validation and deployment workload.

Security leaders should separate vulnerability discovery volume from exploit exposure, then prioritize known exploitation and internet-facing systems. Faster AI-assisted discovery makes asset inventory, patch testing automation, compensating controls, and time-to-remediate metrics more important than headline patch counts.

Sources: S114 · S21 · S64 · S74

Agents are moving into real workflows, so authority boundaries matter more than demos

Alibaba says its QoderWake digital workers can operate inside DingTalk, Feishu, and WeCom, and says the product has deployed nearly 100,000 digital employees that completed around 2 million tasks. Meta’s Muse is presented as a consumer agent that can work through browser tasks, but its usefulness depends on access to personal information and transaction workflows. Meta says Muse uses a cloud virtual machine, requires approval before actions reach the internet, and has planned support for additional credential and payment systems. These are product claims and controls descriptions, not independent evidence of task reliability or security.

Builders should begin with narrow, reversible actions and explicit approval points. Before allowing an agent to send messages, alter records, spend money, or act on credentials, test it against adversarial inputs, define audit logs and rollback paths, and measure completion quality against a non-agent baseline.

Sources: S6 · S69

The technical evidence favors evaluation and review over blanket automation

SciLitBench finds a useful division of labor in literature-review work: explicit criteria improve early screening, while extraction of nuanced evidence and limitations remains substantially weaker. A separate memory benchmark reports that memory implementation materially changes tool-using agent success and that correctly retrieving information does not guarantee the agent acts on it. In software engineering, a developer survey cited by IEEE Spectrum found broad use of AI-generated code but limited trust in its correctness; reported organizational responses include pre-generation specifications, automated checks, risk-based routing, and human review for sensitive changes.

The deployable pattern is not “replace the reviewer.” It is to automate bounded, observable stages; keep human judgment at high-consequence decision points; and evaluate whether the system preserves the evidence, constraints, and exceptions that matter. Teams should measure missed evidence, unsafe actions, and review time—not merely output volume or adoption.

Sources: S29 · S30 · S84

Safety warnings are serious governance signals, not evidence of a demonstrated existential capability

Anthropic safety researcher Evan Hubinger publicly said he assigns more than a 10 percent chance that AI could kill all humans within the next decade and said there is not yet a clear plan for superintelligence alignment. The BBC also reports that Anthropic’s safety report assessed current risks as low in specified scenarios while expressing reduced confidence and noting early signs of possible acceleration. These statements warrant governance attention, especially amid reports of autonomous-agent cyber incidents, but they are expert risk judgments and company assessments rather than empirical proof that such catastrophic capability exists today.

Boards should translate broad safety claims into controls that can be audited now: model-access policies, external evaluation, incident reporting, capability thresholds, and explicit escalation authority. The key question is not whether a long-horizon estimate can be settled today, but whether current deployment decisions preserve options as capability and risk evidence changes.

Sources: S3 · S14

Robotics progress is promising, but evidence still clusters around controlled tasks and vendor claims

GE-Act 2.0 reports improved manipulation results as its co-training data scaled, including evaluation across held-out scenes and objects; it is a technical report from the AgiBot Research Team rather than an independent field study. XPENG says it has commissioned humanoid production lines, automated more than 80% of core processes, and plans commercial rollouts in its own stores and campuses before a broader launch. The production-line announcement establishes manufacturing intent and process automation claims, but it does not establish safe, reliable general-purpose operation in customer environments.

Physical-AI programs should demand evidence at the level of the intended work: sustained uptime, recovery from failures, safety performance, cycle-time variance, and cost of human intervention. Simulation scores and factory commissioning are useful milestones, but they are not substitutes for measured deployment performance.

Sources: S38 · S104

Watch next

  • Whether major AI-infrastructure commitments convert into energized, connected capacity on schedule—and how utilities allocate forecast risk and upgrade costs.

    Sources: S25 · S24 · S2

  • Whether organizations can shrink the patch gap as AI-assisted research raises the volume and speed of vulnerability discovery.

    Sources: S114 · S94

  • Whether consumer and enterprise agents publish credible evidence on authorization safety, task success, privacy handling, and recovery from mistakes.

    Sources: S69 · S6

  • Whether robotics vendors move from demonstrations and manufacturing claims to independently measured reliability in unconstrained operating environments.

    Sources: S38 · S104

Sources

  1. Data Centers Are Driving Pollution And Power Demand. EVs Can Help. — Forbes Innovation · feed-summary ·
  2. Google and Blackstone JV experiences delays in data center projects - report — Data Center Dynamics · feed-summary ·
  3. Anthropic researcher believes more than 10% chance AI 'could kill all humans' — BBC Technology · full-text ·
  4. Developers are rethinking data center design as the AI backlash makes its way to Asia — Fortune · feed-summary ·
  5. The Governance Gap That Will Define The AI Decade — Forbes Innovation · feed-summary ·
  6. Alibaba sends AI ‘digital employees’ to work in rival apps from ByteDance, Tencent — South China Morning Post · China Tech · full-text ·
  7. Ivanti Patches Critical Flaws Across Enterprise Security Products — SecurityWeek · feed-summary ·
  8. Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure — Palo Alto Networks Unit 42 · feed-summary ·
  9. China's AI Chatbot Regulation Cracks Down on Companions — IEEE Spectrum AI · full-text ·
  10. For Revenue Cycle Management In The AI Era, Look To Healthcare’s Midcycle As A Proving Ground — Forbes Innovation · feed-summary ·
  11. Now it’s China’s experts who are gig workers training AI data — Rest of World · feed-summary ·
  12. New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser — SecurityWeek · feed-summary ·
  13. Big Tech eyes glacier-strewn Patagonia for building mega AI data centers — region offers 17,300 glaciers, coldness, and cheap energy, but fiber lines are scarce — Tom's Hardware · full-text ·
  14. Worried Anthropic researchers warn that AI ‘could kill all humans’ — The Verge · full-text ·
  15. Saudi’s Humain turns to outside investment as the kingdom reins in fiscal spending — Fortune · feed-summary ·
  16. Playing their part in a sustainable AI era: How businesses can tap into data center power without spiking emissions — Data Center Dynamics · feed-summary ·
  17. Chrome 153 Patches Seventh Zero-Day of 2026 — SecurityWeek · feed-summary ·
  18. Oil leak from data center contaminates water in Bangkok, Thailand — Data Center Dynamics · feed-summary ·
  19. Damac and Vodafone Türkiye triple Izmir data center project budget — Data Center Dynamics · feed-summary ·
  20. DCD News: August review — Data Center Dynamics · feed-summary ·
  21. US firm used AI to hijack WeChat account, spurring call for cyber cooperation with China — South China Morning Post · China Tech · full-text ·
  22. New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access — BleepingComputer · feed-summary ·
  23. Virginia kept its climate law. Dominion sees a loophole. — Canary Media · full-text ·
  24. Questionable data center forecasts are driving up Ohio power bills — Canary Media · full-text ·
  25. Google to invest record $15 billion in AI infrastructure in the 'Texas of Europe' — CNBC Technology · full-text ·
  26. Sponsored: From training to inference: The AI economic turning point — Data Center Dynamics · feed-summary ·
  27. Google warns of new Chrome zero-day bug exploited in attacks — BleepingComputer · feed-summary ·
  28. Compiling VGDL into Causal Models — arXiv Artificial Intelligence · partial-text ·
  29. SciLitBench: Benchmark and Design Principles for LLM-Powered Systematic Literature Reviews — arXiv Artificial Intelligence · partial-text ·
  30. When Does Memory Help? A Cost-Aware Evaluation of Long-Term Memory in Tool-Using LLM Agents — arXiv Artificial Intelligence · partial-text ·
  31. Situation Awareness for Intelligent Data Distribution in Connected Vehicles — arXiv Robotics · partial-text ·
  32. Benchmarking Dexterity of Multifingered Robot Hands: A Review and Perspective — arXiv Robotics · partial-text ·
  33. A TTP by TTP Approach: Precise Malware Detection via Malicious TTP Recognition — arXiv Cryptography and Security · partial-text ·
  34. Multi-robot Learning-based Informative Path Planning Using Spatio-Temporal Gaussian Process Kalman Filter — arXiv Robotics · partial-text ·
  35. Adaptive Cost-Sensitive Machine Learning for Autonomous Robot Navigation Failure Prediction: When Not All Errors Are Equal — arXiv Robotics · feed-summary ·
  36. CriticGen: Generation-Aware Evaluation as Actionable Feedback — arXiv Artificial Intelligence · partial-text ·
  37. XAI-SDN: An Explainable Entropy-Guided Machine Learning Framework for Real-Time DDoS Detection in Software Defined Networks — arXiv Cryptography and Security · partial-text ·
  38. GE-Act 2.0: Pretraining and Scaling a World-Action Model for Robotic Manipulation — arXiv Robotics · full-text ·
  39. Beyond Right and Wrong: Evaluating Second-order Social Reasoning in Large Language Models — arXiv Artificial Intelligence · partial-text ·
  40. CR-VLA-Force: Learning Control-aware Compliance VLA Model for Robust Contact-rich Robotic Manipulation — arXiv Robotics · partial-text ·
  41. SCRIPTIOC-BENCH: A Benchmark for Recognizing Actionable Threat Intelligence from Script-Based Malware using LLMs — arXiv Cryptography and Security · partial-text ·
  42. A4A: Cross-Embodiment Transfer of Action-Oriented 4D Affordances from Human Demonstrations — arXiv Robotics · partial-text ·
  43. Robots Influencing Humans to Reveal their Goals during Collaboration and Competition — arXiv Robotics · partial-text ·
  44. GIF: Agentic Generation of Interactive and Functional Object Compositions for Robot Learning — arXiv Robotics · partial-text ·
  45. Rcl_logging_journal: a systemd-journald logging backend for ROS 2 — Open Robotics Discourse · partial-text ·
  46. This Fortnight at Open Robotics Headquarters (2026-08-24) — Open Robotics Discourse · full-text ·
  47. The Applied AI Reset: Rebuilding How We Live And Work — Forbes Innovation · feed-summary ·
  48. Should promotion depend on how workers use AI? — BBC Technology · full-text ·
  49. Frog muscle put to use in swimming robotic manta ray — New Atlas Robotics · full-text ·
  50. Jim Cramer says investors are too focused on AI stocks. Here’s where he says to look instead — CNBC Technology · full-text ·
  51. Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities — Cisco Talos Intelligence · feed-summary ·
  52. Take on your most ambitious work with GPT-6 Astra on Amazon Bedrock — AWS Machine Learning Blog · feed-summary ·
  53. How one hedge-fund manager built his firm to be powered entirely by AI agents — CNBC Technology · full-text ·
  54. Major Leap for Solid-State Transformers: Megawatt-Class Unit Demonstrated on Live Feeder — POWER Magazine · feed-summary ·
  55. Why this month's Microsoft patch release is a doozy — Ars Technica AI · feed-summary ·
  56. Hackers are stealing Claude tokens from subscribers — TechCrunch AI · feed-summary ·
  57. Cognition hits $48B valuation, signaling investors believe AI coding is far from a winner-take-all market — TechCrunch AI · feed-summary ·
  58. Attackers Use Multi-Hop Google Redirects for Phishing Campaign — Dark Reading · feed-summary ·
  59. Drama swirls around OpenAI’s legendary mathematical milestone — The Verge · full-text ·
  60. Boston Dynamics veterans launch Dynamic Creatures to bring characters to life with robotics — The Robot Report · feed-summary ·
  61. ChatGPT Sketch turns your bad drawings into detailed AI images — The Verge · partial-text ·
  62. Muse, Meta’s New Personal AI Agent, Needs You to Trust It — WIRED AI · feed-summary ·
  63. Russian suspect in bank account takeovers is extradited to US — The Record from Recorded Future News · full-text ·
  64. Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days — SecurityWeek · feed-summary ·
  65. Shuttered nuclear plant in Iowa gets $1.9B federal loan to restart — Canary Media · full-text ·
  66. AI can’t outrun a humanoid’s hardware — The Robot Report · feed-summary ·
  67. Whole-body expansion and contraction make a robot seem more alive — Tech Xplore Robotics · full-text ·
  68. Meta debuts its Muse AI agent. Will consumers trust it? — TechCrunch AI · feed-summary ·
  69. Meta bets on AI agent Muse to catch up in AI race — The Verge · full-text ·
  70. The betrayal behind the data-center backlash: AI promised to break the rules of class but is just rewarding them so far — Fortune · feed-summary ·
  71. ROS PMC Minutes for September 8, 2026 — Open Robotics Discourse · full-text ·
  72. Microsoft releases Windows 10 KB5122878 extended security update — BleepingComputer · feed-summary ·
  73. Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day — SecurityWeek · feed-summary ·
  74. Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days — BleepingComputer · feed-summary ·
  75. Robotic fish swims like the real thing, and can be built to any size — New Atlas Robotics · full-text ·
  76. AI power users claim Anthropic duped them with subscriptions, and they’re taking it to court — The Verge · full-text ·
  77. ClickFix Campaigns Abuse Legitimate Services for Persistent Access — Dark Reading · feed-summary ·
  78. AI In Education: Key Skills Students Need To Think For Themselves — Forbes Innovation · feed-summary ·
  79. Govern models with MLflow and Amazon SageMaker AI Model Registry sync: Part 2 — AWS Machine Learning Blog · feed-summary ·
  80. Govern models with MLflow and Amazon SageMaker AI Model Registry sync: Part 1 — AWS Machine Learning Blog · feed-summary ·
  81. NEC signs MoU with UNDP to support conservation, climate action through use of AI — Data Center Dynamics · feed-summary ·
  82. Automated agent evaluation with Amazon Bedrock AgentCore and GitHub Actions — AWS Machine Learning Blog · feed-summary ·
  83. Benchmarking small LLM inference on SageMaker AI: G7 vs G5 and G6 — AWS Machine Learning Blog · feed-summary ·
  84. Inside the AI Code Surge Reshaping Developer Jobs — IEEE Spectrum AI · full-text ·
  85. Google's European energy and infrastructure principle joins Mistral Compute — Data Center Dynamics · feed-summary ·
  86. Why vision AI is the safety backbone of the automated job site — The Robot Report · feed-summary ·
  87. Qualcomm and AWS partner on custom silicon for large-scale AI data centers — Data Center Dynamics · feed-summary ·
  88. August updates trigger 0xc0000409 errors on Windows Server 2016 — BleepingComputer · feed-summary ·
  89. SAP warns of maximum severity 'OVERPASS' kernel vulnerability — BleepingComputer · feed-summary ·
  90. DOE Closes $1.9-Billion Loan to Restart Duane Arnold Nuclear Plant — POWER Magazine · feed-summary ·
  91. TSMC To Use ASML Photolithography Gear For Next-Gen Chips — Forbes Innovation · feed-summary ·
  92. Mistral raises €3B as sovereign AI becomes big business — TechCrunch AI · feed-summary ·
  93. Why Large Enterprises Still Can’t Master The Fundamentals Of Data — Forbes Innovation · feed-summary ·
  94. Microsoft breaks another patch Tuesday record — The Verge · full-text ·
  95. Google DeepMind publishes AI-powered predictions for the effect of all 9 billion possible single-point mutations in the human genome — Fortune · feed-summary ·
  96. Founding Robotics Engineer @ Merista.ai in Barcelona, Spain — Open Robotics Discourse · full-text ·
  97. Siemens Healthineers Announces Software for Trackerless Guidance in Spinal Surgery — Surgical Robotics Technology · feed-summary ·
  98. Adobe fixes critical Magento zero-day exploited to backdoor servers — BleepingComputer · feed-summary ·
  99. French prosecutors confirm arrest of suspected ZeroBytes hacker behind tax cyberattack — The Record from Recorded Future News · full-text ·
  100. Cyberattack encrypts systems at Bavarian municipal utility — The Record from Recorded Future News · full-text ·
  101. Palladyne AI and FANUC America Announce Strategic Collaboration to Advance Intelligent Robotic Automation | RoboticsTomorrow — RoboticsTomorrow · full-text ·
  102. Qualcomm issues warrants to Amazon to acquire $4 billion worth of chipmaker's stock as part of AI infrastructure deal — CNBC Technology · full-text ·
  103. The Work Now Within Reach — OpenAI News · feed-summary ·
  104. IRON, the World's First Advanced General-Purpose Humanoid Robot, Walks off the Production Lines as XPENG's Humanoid Robot Manufacturing Facility Is Officially Commissioned | RoboticsTomorrow — RoboticsTomorrow · full-text ·
  105. Huayan Robotics to Present Chinese Intelligent Manufacturing Solution at IMTS 2026 | RoboticsTomorrow — RoboticsTomorrow · full-text ·
  106. Dynamic Creatures Emerges from Stealth to Launch New Category of Mobile, Interactive Character Robots for Hospitality and Entertainment | RoboticsTomorrow — RoboticsTomorrow · full-text ·
  107. Productive Robotics Introduces A Hybrid-Cooled Torch For Its Blaze Robotic Welding Systems | RoboticsTomorrow — RoboticsTomorrow · full-text ·
  108. 4 Smart Home Products I Saw At IFA 2026 That Rethink Everyday Appliances — Forbes Innovation · feed-summary ·
  109. Exclusive: AI startup Sapien raises at $180M valuation to help companies find what’s really driving profit — Fortune · feed-summary ·
  110. Generative AI Is Just The Latest Chapter: 80 Years Of Programming Automation — Forbes Innovation · feed-summary ·
  111. Hackers build AI frameworks for widescale credential theft — BleepingComputer · feed-summary ·
  112. Career Stability In The Age Of AI, Entrepreneurship And Franchising — Forbes Innovation · feed-summary ·
  113. CareCam Pro IP Cameras | CISA — CISA Cybersecurity Advisories · full-text ·
  114. CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISA — CISA Cybersecurity Advisories · partial-text ·
  115. The Future Of AI Infrastructure Is Heterogeneous — Forbes Innovation · feed-summary ·

Editorial standards · Corrections