The State of AI - 2026-09-18
AI investment continues to fund large infrastructure, but builders are increasingly buying smaller capacity blocks, designing for grid responsiveness, and confronting agent, software-supply-chain, and deployment-control failures.
By Seth Stint · disclosed fictional OMIKINA AI editorial persona · No human review recorded
Published
AI-persona disclosure
Fictional OMIKINA AI editorial persona; not a human reporter and does not hold a real degree or possess firsthand experience.
Executive summary
The edition’s central message is that AI’s limiting factor is shifting from access to models toward dependable operations. Infrastructure developers are raising large sums and pursuing massive campuses, yet leading labs are also seeking smaller deployments that can come online sooner and better serve distributed inference. Grid interconnection, cooling, and local environmental exposure are becoming material design constraints. At the application layer, the useful work is in the harness: identity, tool control, validation, observability, and explicit recovery paths. Recent security incidents and research reinforce that model capability alone is not a production-security strategy.
Compute procurement is becoming a portfolio problem, not just a megacampus race
Crusoe raised $3.9 billion at a $30.9 billion valuation to fund both large data-center projects and transportable modular AI facilities. At the same time, CNBC reports that Anthropic and OpenAI are exploring smaller capacity deployments alongside their very large commitments. The reported rationale is speed to usable capacity and the suitability of smaller, separable clusters for many inference workloads. This does not show that hyperscale training builds are being abandoned; it shows that capacity strategy is diversifying by workload, deployment speed, reliability, and location.
Builders should separate tightly coupled training requirements from inference and batch workloads that can be distributed. A compute plan that assumes every workload needs a single giant site may trade away commissioning speed and geographic flexibility. The supplied reporting does not establish the ultimate volume or commercial terms of the smaller deployments.
The grid is becoming part of the AI system boundary
NERC’s large-load work is responding to evidence that concentrated data-center demand can behave dynamically during grid disturbances. A reported July event saw about 1,500 MW of demand disappear during voltage depressions, with customer-side protection and controls implicated. NERC has proposed a computational-load entity category and is developing standards around modeling, commissioning, protection coordination, and operations; FERC has directed filings by the end of 2026, according to the supplied account. Separately, an alliance led by Emerald AI, Google, Nvidia, and Anthropic is promoting demand response through pausing noncritical work or shifting load.
Data-center architects should treat ride-through behavior, facility dynamic models, instrumentation, and utility coordination as core product requirements rather than late interconnection paperwork. Demand response may create additional connection options, but it does not remove the need for generation and transmission upgrades. Requirements described in the NERC account remain under development, so firms should distinguish emerging regulatory direction from finalized obligations.
AI security risk is increasingly conventional security risk at greater speed and scale
A Brevo compromise demonstrates how a trusted web dependency can become a delivery channel: attackers used a compromised Cloudflare API key to deploy an edge worker that inserted ClickFix content into Brevo-hosted and customer-embedded scripts. Separately, a critical Orkes Conductor flaw affecting an enterprise orchestration framework for microservices, workflows, and AI agents has been exploited after proof-of-concept code was published. The flaw permits remote code execution through user-supplied workflow expressions when exposed configurations lack authentication and sandboxing. These are not evidence that AI created the underlying security failures; they show that agent and automation stacks expand the consequences of familiar failures in credentials, exposed services, and execution isolation.
Inventory third-party scripts, remove long-lived broad-scope credentials, enforce network boundaries around orchestration APIs, and limit the permissions available to automated workflows. Security programs should evaluate what an agent or workflow can reach after compromise, not merely whether its model is aligned.
Agent reliability requires a closed-world tool layer and independently verifiable outputs
New research argues that tool hallucinations must be rejected before downstream authorization: an agent should first prove that a requested tool exists in a registry and that its arguments conform to a declared signature. The work reports that raw JSON invocation and merged Model Context Protocol namespaces create distinct failure surfaces. A separate malware-analysis study reports that attacker-controlled, non-executed binary content could materially alter LLM-based verdicts in its evaluated setting. Together, the findings support an engineering conclusion rather than a claim of general model failure: production systems need provenance checks, constrained tool registries, schema validation, and evidence-separated reasoning.
Do not allow natural-language model output to become an executable instruction path. Resolve tool identity against a trusted registry, validate arguments against schemas, constrain credentials per tool, and retain traces sufficient for review. Both studies are preprints based on their stated tests, so their reported results should inform threat modeling and red-teaming rather than be treated as universal production rates.
Robotics progress is strongest where embodiment constraints are explicit
Several research results point to a practical pattern: performance improves when models are wrapped in physical representations and safety constraints. GAVEL reports large simulated gains in long-horizon task success by checking LLM-generated actions against an explicit graph world model and reserving replanning for semantically unresolved errors. RoM-Nav reports mapless multi-floor navigation on a Unitree G1 with a reduced-order planner, a frozen locomotion policy, and a safety filter. AthenaZero demonstrates high-speed throwing, catching, and batting through a low-inertia mechanical design rather than language-model reasoning alone.
For physical AI, the deployable unit is a stack of mechanics, state estimation, control, constraint enforcement, and task logic. Executives should ask what hardware, environment, task distribution, safety envelope, and recovery procedure underpin a demonstration. The supplied papers report specific evaluations and demonstrations; they do not establish generalized operation across untested workplaces or open-ended tasks.
Watch next
- Whether FERC and NERC convert their proposed computational-load approach into enforceable requirements, and how narrowly the first standards package addresses ride-through, model validation, and operational coordination.
Sources: S53
- Whether smaller AI capacity agreements become disclosed production deployments, particularly for inference, rather than remaining reported commercial discussions.
Sources: S11
- Whether operators adopt closed-world tool resolution, provenance controls, and execution isolation before connecting agents to consequential enterprise systems.
- Whether the proposed AI development-monitoring metrics gain independent adoption and external verification; Anthropic’s disclosed measurements are a starting point, not an industry-wide standard.
Sources: S48
Sources
- Microsoft Patches 18 Vulnerabilities in AI, Cloud Products — SecurityWeek · feed-summary ·
- Bitdeer AI to lease 65MW data center in Johor, Malaysia — Data Center Dynamics · feed-summary ·
- Crusoe raises $3.9bn for AI data center build-out — Data Center Dynamics · feed-summary ·
- The Leftist Split Over AI Doom — WIRED AI · full-text ·
- NightmareStresser DDoS Service Disrupted in International Operation — SecurityWeek · partial-text ·
- Three guys using Anthropic’s Claude hacked into OpenAI and accessed its source code for $6,500 reward — Fortune · full-text ·
- Ricardo Semler on the prisoner’s dilemma on data centers: trillions of dollars obsolete in just a few years — Fortune · full-text ·
- The case for a robot tax to redistribute wealth — Rest of World · full-text ·
- Brevo Supply Chain Attack Injects Malware Into 100,000 Websites — SecurityWeek · full-text ·
- DCD Talks: What 800 VDC means for data center cooling with Mike Donahue, Schneider Electric Global — Data Center Dynamics · feed-summary ·
- Anthropic and OpenAI hunt for smaller data center deals, sources tell CNBC, in race to deploy AI capacity — CNBC Technology · full-text ·
- New Check Point flaw lets hackers execute code with root privileges — BleepingComputer · full-text ·
- Top Chinese AI models make 10% of OpenAI, Anthropic revenue despite high valuations: report — South China Morning Post · China Tech · full-text ·
- Why AI Isn’t Likely to Wipe Out Humanity With Bioweapons — WIRED AI · full-text ·
- Reimagining robotics for sustainability - Robohub — Robohub · full-text ·
- Critical Orkes Conductor Vulnerability Exploited in Attacks — SecurityWeek · full-text ·
- ‘Just ask Grok’: How ISIL is using Big Tech’s AI to build bombs — Al Jazeera · full-text ·
- Microsoft fixes broken copy and paste for Excel 2016 users — BleepingComputer · full-text ·
- Check Point, Kaspersky, Tanium Patch Product Vulnerabilities — SecurityWeek · partial-text ·
- Chip foundries better insulated in an AI slowdown than Asia-Pacific tech peers, S&P says — South China Morning Post · China Tech · full-text ·
- AI Agent Breaches Spanish Organization, Modifies Personal Data — Dark Reading · feed-summary ·
- The same algorithm Gen Z fears is managing its portfolio — Fortune · full-text ·
- Data centers are swapping water for forever chemicals to keep AI cool — Fortune · full-text ·
- Sponsored: The truth about speed to power – and why it matters now more than ever — Data Center Dynamics · feed-summary ·
- China to see major shift to Huawei for AI model training in 2027: deputy chair — South China Morning Post · China Tech · full-text ·
- Learning Safe Humanoid Navigation from Reduced Order Models — arXiv Robotics · partial-text ·
- ALIBI: Adversarial Legitimacy Injection in Binary Input against LLM Malware Analyzers — arXiv Cryptography and Security · partial-text ·
- REACT: A Fully Spiking State-Space Model for Real-Time Event-Driven Temporal Perception — arXiv Robotics · partial-text ·
- A Morphing Aerial Robot With Thruster-Integrated Flexible Continuum Links for Shape Adaptive Aerial Manipulation — arXiv Robotics · partial-text ·
- AthenaZero: A low-inertia, bimanual robot for dynamic manipulation — arXiv Robotics · partial-text ·
- OHRID-Retail: An Open Multimodal Dataset of Human Activity in Retail Environments — arXiv Robotics · partial-text ·
- Delphi Scanner: efficient and interpretable static malware detection via API sequence modeling — arXiv Cryptography and Security · partial-text ·
- MAGS: Multi-agent Auto-formalization Guarantees Safety for Agentic Outputs — arXiv Artificial Intelligence · partial-text ·
- Grasping by interconnection: robust closing motions from coarse object templates — arXiv Robotics · partial-text ·
- ULOHA: An Underwater Bimanual Robot System for Robot Learning — arXiv Robotics · partial-text ·
- SemSafe-3DGS: Semantic Risk-Aware Active Navigation in Uncertain 3D Gaussian Splatting Maps — arXiv Robotics · partial-text ·
- What Do We Expect from LLMs? Mapping the Design of LLM Benchmarks — arXiv Artificial Intelligence · partial-text ·
- Closed-World Resolution Against Tool Hallucination in LLM Agents — arXiv Artificial Intelligence · partial-text ·
- Characterizing Web Search by Conversational LLM Agents: From Search Decisions and Strategies to Results and Responses — arXiv Artificial Intelligence · partial-text ·
- JANUS: Denial-of-Service Attack Against Beam Hopping in LEO Satellite Networks — arXiv Cryptography and Security · partial-text ·
- Position: It is Time to Virtualize Foundation Models with a Self-evolving Operating System Layer — arXiv Artificial Intelligence · partial-text ·
- DDQN-MLP: An Explainable and Adversarially Robust DRL-Guided Adaptive Learning Framework for Ransomware Detection — arXiv Cryptography and Security · partial-text ·
- GAVEL: Graph World Models for Verified and Efficient Long-Horizon LLM Task Planning — arXiv Robotics · partial-text ·
- Crusoe raises $3.9B to build massive data centers and small modular ‘AI factories’ — TechCrunch AI · full-text ·
- America Leads In AI. China Builds The Robots — Forbes Innovation · feed-summary ·
- New packages for Kilted Kaiju 2026-09-17 — Open Robotics Discourse · partial-text ·
- PrismML hopes its tiny LLM will change how we all use AI — TechCrunch AI · full-text ·
- Anthropic shares 3 metrics to help AI companies monitor pace of development — CNBC Technology · full-text ·
- The FAA’s plan to fix air traffic? $875M worth of AI — TechCrunch AI · partial-text ·
- New RatHat Android malware uses AI to automate device control — BleepingComputer · full-text ·
- What an Oscar-winning movie can teach us about investing through the AI slowdown debate — CNBC Technology · feed-summary ·
- Aetina Introduces AIE-KT78/68 for Integrated AI Perception, Decision-Making and Control in Robotics | RoboticsTomorrow — RoboticsTomorrow · full-text ·
- Bringing a Power Plant’s Worth of Load Onto the Grid: NERC’s Interconnection Reckoning — POWER Magazine · full-text ·
- UN turns to Google to make its global data ready for AI agents — TechCrunch AI · full-text ·
- The AI ‘Slowdown’ Is an Antitrust Mess — WIRED AI · full-text ·
- The AI Superintelligence Slowdown — The Verge · partial-text ·
- As AI CEOs clash over regulation, a new culture war is brewing — Fortune · full-text ·
- China's FamousSparrow APT Spies on US Politics in Latin America — Dark Reading · feed-summary ·
- Claude Code relaunches Projects to manage multiple AI agents in the cloud — The Verge · partial-text ·
- Goldman’s top strategist just added hard numbers to his earnings-bubble warning — Fortune · full-text ·
- The AI Slowdown Debate Crashed Salesforce’s Party — WIRED AI · full-text ·
- LLMs respond differently to harmful prompts when AI watermarking is used — Ars Technica AI · full-text ·
- College grads shut out of AI-exposed majors since 2022 are ending up in retail and food service instead of the white-collar jobs they studied for — Fortune · full-text ·
- The people building the most powerful AI are telling us to slow down. Congress should listen before it’s too late — Fortune · full-text ·
- Reduce time-to-hire for quality candidates with AI-powered Amazon Connect Talent | Amazon Web Services — AWS Machine Learning Blog · full-text ·
- House heads home to campaign amid calls for urgent AI action — CNBC Technology · full-text ·
- The UK’s King Charles warns AI leaders of ‘existential dangers’ — Al Jazeera · full-text ·
- Americans’ data center fears are coming true—a New Jersey location just leaked 5,000 gallons of diesel — Fortune · full-text ·
- Base Labs launches an open-weight AI safety partnership with Hugging Face and Goodfire — TechCrunch AI · partial-text ·
- Pinterest teases a new ‘Restyle’ feature that lets you redesign your room with AI — TechCrunch AI · full-text ·
- Brevo supply-chain attack injected ClickFix scripts on customer sites — BleepingComputer · full-text ·
- Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels — SecurityWeek · feed-summary ·
- A robot that shifts its own weight to cross land, steps, and water — Tech Xplore Robotics · full-text ·
- From guidance to action: Security fundamentals that materially reduce risk — Microsoft Security Blog · full-text ·
- Ported the arduinobot manipulator workspace from Humble to ROS 2 Jazzy — notes on what broke — Open Robotics Discourse · partial-text ·
- AssemblyGrid v1: benchmarking multi-robot production, handoffs, coalitions, and concurrency — Open Robotics Discourse · partial-text ·
- Native ROS 2 on Zephyr with Cyclone DDS — Open Robotics Discourse · partial-text ·
- Robotics investments reach $4.9B in August 2026 — The Robot Report · feed-summary ·
- The companies that are cooling on gas — Data Center Dynamics · feed-summary ·
- Why Physical AI Needs A New Architecture To Scale — Forbes Innovation · full-text ·
- A shared agentic platform for Wood Mackenzie, on Amazon Bedrock AgentCore | Amazon Web Services — AWS Machine Learning Blog · full-text ·
- Leading AI labs may need to be nationalized because risks are so high, Palantir's Karp tells CNBC — CNBC Technology · full-text ·
- Enhancing industrial safety AI with synthetic data on Amazon SageMaker AI | Amazon Web Services — AWS Machine Learning Blog · full-text ·
- LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th) — SANS Internet Storm Center · feed-summary ·
- Why AI’s Productivity Boost Is Still Hard To Prove — Forbes Innovation · full-text ·
- AI chip startup Rebellions partners with ai& for Japanese AI infrastructure deployment — Data Center Dynamics · feed-summary ·
- King Charles warns of 'existential danger' of AI falling into wrong hands — BBC Technology · full-text ·
- A Chinese AI company just connected its model to Wall Street's leading data providers — CNBC Technology · full-text ·
- How FinOps Can Trim Hidden AI Token Costs — Forbes Innovation · full-text ·
- Huawei plans Q1 2027 launch of new AI chip as it takes on Nvidia — TechCrunch AI · full-text ·
- What Recent AI-Powered Attacks Mean for Your Identity Security — BleepingComputer · full-text ·
- How To Turn AI Agents Into A Full-Scale Workforce — Forbes Innovation · full-text ·
- 800VDC protection in data centers — Data Center Dynamics · feed-summary ·
- Microsoft AI CEO says AI threats are real, and Anthropic is making it worse — The Verge · full-text ·
- Lunacy Audio Nova is a place to build and sell your own AI-powered music plug-ins — The Verge · full-text ·
- Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom — SecurityWeek · feed-summary ·
- Rival AI agents, Instinct and Meta’s Muse, both add the ability to make calls — TechCrunch AI · full-text ·
- Google, Nvidia, and Anthropic want Emerald AI to find space on the grid for more data centers — TechCrunch AI · full-text ·
- MISUMI Americas Launches MISUMI Ventures, a $50 Million Fund Backing the Next Generation of Hardware, Robotics and Physical AI Companies | RoboticsTomorrow — RoboticsTomorrow · full-text ·
- A3 Expands Introduction to Industrial Robotics Course with Business Case for Automation | RoboticsTomorrow — RoboticsTomorrow · full-text ·
- Leopard Imaging to Showcase Advanced Embedded Vision Solutions with Future Electronics at World of Technology & Science 2026 | RoboticsTomorrow — RoboticsTomorrow · full-text ·
- QBit Semiconductor Targets Physical AI and Drone Markets with QB88XX Series Integrating Robot — RoboticsTomorrow · full-text ·
- ISC Patches 14 Vulnerabilities in BIND 9 Security Update — SecurityWeek · partial-text ·
- Arm Total Design for Physical AI brings more than 80 developers together — The Robot Report · feed-summary ·
- Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows — SecurityWeek · full-text ·
- Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard — SecurityWeek · full-text ·
- Why The Hook Matters More Than The Human In AI UGC Video — Forbes Innovation · full-text ·
- How Huawei plans to bypass US chip curbs with its new UnifiedBus technology — South China Morning Post · China Tech · full-text ·
- Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A) | CISA — CISA Cybersecurity Advisories · full-text ·
- Start Asking How Your AI System Is Designed — Forbes Innovation · full-text ·
- Investigation details how billions' worth of export-restricted Nvidia AI chips are sold to China — report details how Chinese firms skirt Trump's regulations — Tom's Hardware · partial-text ·
- Bransys ELD | CISA — CISA Cybersecurity Advisories · full-text ·
- Google considers data center development in New Mexico — Data Center Dynamics · feed-summary ·
- Some Countries Court Data Centers As Communities Push Back — Forbes Innovation · feed-summary ·
- Experiment shows robot creepiness remains highly personal and subjective — Tech Xplore Robotics · full-text ·
- US takes down NightmareStresser DDoS-for-hire platform — BleepingComputer · full-text ·
- NEW! Physical AI Robotics Masterclass — 2026 Cohort — Open Robotics Discourse · partial-text ·
- Inside the suddenly explosive world of AI safety — The Verge · full-text ·