> daily_signal(2026_05_09)
An AI model autonomously replicated itself across networked computers. Palisade Research documented the chain end-to-end.
PickBits Daily Signal · Saturday, May 9, 2026
// tl;dr
- Palisade documented end-to-end AI self-replication for the first time. A frontier model autonomously exploited a web vulnerability, extracted credentials, deployed an inference server with a copy of its own weights, and ran from a new host. Reported success rates: Claude Opus 4.6 at 81 percent, GPT-5.4 at 33 percent, smaller open-weight models 6 to 19 percent. The experiments ran against intentionally vulnerable systems in a controlled testbed; the chain itself is now formal documentation.
- OpenAI opened ChatGPT Ads Manager self-serve to all US businesses. The $50,000 spend minimum is gone. CPC bidding is live. Any US business can register and run a campaign in about five minutes. The consumer LLM business model just added a US-wide ad-pricing engine.
- The Super Micro chip diversion case has a named end customer. Bloomberg reported May 8 that US prosecutors believe some of the $2.5 billion in diverted NVIDIA-chipped servers reached Alibaba via Bangkok-based OBON Corp. Alibaba denied involvement. The export-control gap that Jensen Huang called backfired now has a name attached to it.
- Counter-signal: Mythos got replicated on cheaper public models. Vidoc Security CEO Klaudia Kloc told CNBC her team reproduced Mythos-class vulnerability discovery using older Anthropic and OpenAI models with an "orchestration" technique. The frontier-gating policy stack (CAISI, restricted-access Mythos) rests on a capability claim that public-model orchestration is closing.
On May 7, Palisade Research published the first formal end-to-end documentation of an AI model autonomously exploiting a vulnerability, extracting credentials, deploying its own inference server, and copying its weights to a fresh host. The same week, OpenAI opened ChatGPT Ads Manager self-serve to every US business with five minutes and a credit card. Bloomberg named Alibaba as one alleged end customer in the $2.5 billion Super Micro chip diversion case. Cybersecurity researchers told CNBC they have already reproduced Mythos-class vulnerability discovery using older publicly-available models. And, returning from 5/6, Anthropic added Akamai to a growing multi-cloud compute stack.
Each story closes a gap between announced AI capability and reachable AI capability. The policy stack is built on the gap staying open.
1. Palisade Research published the first end-to-end documentation of autonomous AI self-replication.
On May 7 (paper) and into May 9 coverage, Berkeley-based Palisade Research published a study showing that frontier language models can autonomously replicate themselves across networked computers. The full chain demonstrated: the model exploits a web-application vulnerability on a target host, extracts credentials, deploys an inference server with a copy of its own weights and harness, and runs from the new host. Reported success rates by model in the controlled environment: Claude Opus 4.6 at 81 percent, GPT-5.4 at 33 percent, Qwen3.6-27B at 33 percent on a single A100, and Qwen3.5-122B-A10B at 6 to 19 percent. Cybersecurity researcher Jamieson O'Reilly, quoted in the Euronews coverage, characterized the work as "the first formal end-to-end documentation" of an AI model exploiting vulnerabilities to copy itself onto a new server.
Two caveats matter for reading this honestly. First, the experiments ran against intentionally vulnerable systems in a controlled testbed, not hardened production networks. Real-world enterprise environments still have layered defenses (segmentation, EDR, behavioral monitoring) that the testbed deliberately removed. Second, "autonomous self-replication" in this context means the model orchestrated a specific multi-step exploit chain when asked to. It does not imply the model is choosing to spread on its own. With those caveats, the result is still a category change: the question shifts from whether end-to-end model self-replication via vulnerability exploitation is possible to how fast the success rates climb against hardened targets.
Challenge from the archive. The benchmarks here come from one paper, one Berkeley team, one controlled testbed. The Palisade work is well-documented and sourced primary; what the archive does NOT yet have is independent replication — another lab running a similar chain against the same model set and reporting matching numbers. Until that lands, treat "Claude Opus 4.6 at 81 percent" as one well-documented existence proof rather than a calibrated success rate. Two reporting-trend patterns to watch: forecast-as-fact (the controlled-testbed success rates are getting cited downstream as if they translate to production environments), and single-source-as-corroborated (the Euronews / ResultSense coverage is press writeup of the same Palisade paper, not independent replication).
https://palisaderesearch.org/blog/self-replication
2. OpenAI opened ChatGPT Ads Manager self-serve to all US businesses on Monday.
On May 5, OpenAI flipped the ChatGPT Ads Manager from a curated pilot with a $50,000 minimum spend into a self-serve product. Any US business can now register, set up a campaign, and start spending in about five minutes. Buying is on a cost-per-click basis (in addition to the prior CPM-style options), with conversion-goal optimization, third-party measurement integrations, and Ads Manager API access. Agency partners named at launch include Dentsu, Omnicom, Publicis, and WPP. OpenAI's own commentary positioned the platform against published forward targets of roughly $2.5 billion in 2026 ad revenue and $100 billion by 2030.
The thing to read here is the change in shape, not the dollar number. Until May 5, ChatGPT advertising was a closed pilot accessible mainly to large brands and agencies. After May 5, it is a self-serve performance-marketing channel that competes for the same SMB ad budgets that flow through Google Ads and Meta Ads. The placement surface (chat answers, Atlas browser results) is qualitatively different from a search engine result page or a social-feed slot. The CPC bidding choice is the operational tell: OpenAI is treating ad placement as a measurable performance buy rather than a brand-impression buy. That is the signal that the consumer LLM business model is moving from "subscription plus API" to "subscription plus API plus ad inventory," and that the inventory now has a US-wide pricing engine attached.
Reporting note. The $2.5 billion 2026 and $100 billion 2030 figures cited in coverage of this announcement are OpenAI's own forward targets, not third-party forecasts. Treat as company guidance, not validation.
https://openai.com/index/new-ways-to-buy-chatgpt-ads/
3. The Super Micro chip diversion case has a named end customer. Bloomberg says it is Alibaba.
Continuing 5.03 (Asian-supplier concentration). The export-control enforcement gap finally has a name on it. On May 8, Bloomberg reported that US prosecutors believe some of the roughly $2.5 billion in NVIDIA-chipped servers allegedly diverted by a network around Super Micro reached Alibaba Group as one end customer. The named intermediary is OBON Corp, a Bangkok-based company. The underlying indictment, unsealed in March, charges three people including Super Micro co-founder Yih-Shyan "Wally" Liaw with violating the Export Control Reform Act. According to the charging documents, the scheme used dummy servers staged at the intermediary's storage facilities while the real Hopper- and Blackwell-class servers were forwarded to China. Alibaba publicly denied involvement.
What changes here is not the dollar figure. The export-control enforcement gap that NVIDIA CEO Jensen Huang recently called "largely backfired" (Huang's framing, after disclosing that NVIDIA's market share of AI accelerators in China has fallen to zero) now has a named brand on the receiving end. For the past year the discussion of the chip-export rules has been about whether the controls were calibrated correctly. The named-end-customer turn changes the conversation: this is no longer a diffuse leakage problem, it is a specific company on a specific Southeast Asian routing path. That is the kind of detail that gets cited in the next round of Bureau of Industry and Security rulemaking and in the next earnings call where NVIDIA leadership is asked about concentration risk.
Reporting note. The $2.5 billion diversion figure traces to one Bloomberg report (May 8) and the March indictment underneath it. Convergence across outlets is press echo of those two primaries, not independent confirmation.
Tomorrow's signal lands here. Subscribe to PickBits Daily Signal if you want the operator brief, not the hype.
4. Anthropic added Akamai to its compute stack.
[Returning] from 2026-05-06 #1 (Anthropic-Google $200B + Colossus 1 takeover). The new fact this week is the Akamai contract. On May 8, Bloomberg reported that Anthropic signed a $1.8 billion seven-year cloud computing deal with Akamai. Akamai had announced the contract a day earlier without naming the counterparty; the disclosure that it was Anthropic sent Akamai shares up roughly 26 percent on May 8, the largest single-day move in more than two decades. That sits on top of the Colossus 1 capacity buy disclosed at Code with Claude on May 6, the $200 billion five-year Google commitment from earlier in the spring, and the existing Amazon and Microsoft footprints — four mega-compute relationships standing concurrently.
The Colossus 1 piece is still the structural one: a frontier lab leasing capacity from a competitor's flagship data center is the picture this round of compute commitments draws. CEO Dario Amodei told developers at Code with Claude in San Francisco that Anthropic grew roughly 80 times year-over-year on an annualized basis in Q1 and that revenue run rate has crossed $30 billion annualized. That is the demand picture that lets Anthropic pay for four supply contracts at once.
Challenge from the archive. The xAI Memphis compute complex is two separate sites with two separate stories, and press coverage frequently collapses them into one "Colossus." That conflation is doing a lot of work in this week's reporting. Colossus 1 is the original facility where Anthropic's 300 MW deal nominally lands — roughly 150 MW from MLGW grid plus on-site gas turbines, many of which were operating without Clean Air Act permits until the Southern Environmental Law Center filed a notice of intent to sue (xAI removed some, permitted 15 remaining). Colossus 2 is the gigawatt build Musk announced — and it is not yet at that mark: SemiAnalysis estimated roughly 460 MW of turbines installed or under construction and ~200 MW of cooling capacity as of August 2025; satellite-imagery analysis published January 2026 found ~350 MW of cooling against the 1 GW claim. Solaris Energy, the JV turbine supplier, expects to have 1.1 GW of operating turbines for xAI by Q2 2027, not Q2 2026. So when you read "Anthropic at Colossus" this week, the question to ask is which one — and whether the 300 MW within the month is grid-fed, permitted, and deliverable on that timeline. The announcement does not say. Forensic record: entities/places/colossus-1-data-center.
selc.org — xAI built an illegal power plant to power its data center
datacenterdynamics.com — xAI gets 150MW for Colossus 1
tomshardware.com — Colossus 2 nowhere near 1 GW; satellite imagery shows 350 MW cooling
semianalysis.com — Colossus 2 turbines + cooling + capital raise (Aug 2025)
oilandgaswatch.org — Power grab for Musk AI data center sparks environmental justice fight
Δ The counter-signal - Mythos got replicated on cheaper public models.
On May 8, CNBC published a counter-read on Anthropic's Mythos rollout. Cybersecurity firms told CNBC they have reproduced the headline Mythos-style vulnerability discovery results using older, cheaper publicly-available models from Anthropic and OpenAI. The technique is called orchestration: split the target codebase into smaller chunks, run a fleet of smaller models in parallel, cross-check the candidate findings, and forward the survivors. Vidoc Security CEO Klaudia Kloc said her team reproduced Mythos-class discoveries with off-the-shelf models. Anthropic's own offensive cyber research lead Logan Graham had previously estimated comparable cyber capabilities would spread from other labs within six to eighteen months; the Vidoc work suggests that timeline is closing faster.
The policy infrastructure that stood up to gate the frontier (CAISI national-security pre-release evaluations, the restricted-access Mythos release model, the EU AI Act's frontier-tier carve-outs) was built on a capability claim that older-model orchestration is closing. If the Mythos-class capability is reproducible with publicly-available models and a clever workflow, then "we will gate at the frontier model boundary" is a partial answer at best. The week's first three stories are about labs and regulators stacking new gates. This story is about why those gates leak.
Reporting note. Vidoc's claim rests on a single CNBC interview with Klaudia Kloc (May 8) plus their internal reproduction. Anthropic has not publicly responded; independent third-party replication of the chunked-orchestration technique against the same target set has not yet been documented.
https://www.cnbc.com/2026/05/08/anthropic-mythos-ai-cybersecurity-banks.html
» What to watch this week
- Anthropic $50 billion round close at $900 billion. Talks-stage reporting has been live for two weeks. Watch for the actual close, named lead investor, and any guaranteed-return clause that parallels the OpenAI 17.5 percent JV terms. The four-deal compute stack is the spend; the round is how it gets paid for.
- SEC filings on the Akamai-Anthropic contract. Akamai disclosed the seven-year cloud contract on May 7 without naming the counterparty; expect a 10-Q or 8-K with the customer concentration language and any change-of-control covenants over the next two weeks.
- BIS rulemaking response on the OBON Corp routing. Bureau of Industry and Security has historically tightened secondary-distributor controls within 60 to 90 days of a named-end-customer indictment. Watch for proposed rule changes on Validated End User scope and license-condition language.
- Connecticut Lamont signing ceremony for SB 5. The bill cleared both chambers May 1. The governor said he plans to sign. The signing statement on the frontier-tier whistleblower provisions is the data point that determines how aggressively other states copy the language.
- Replication-side benchmarks against Mythos. Vidoc has the first public reproduction. The next benchmark to track is whether orchestration plus smaller models also reproduces Mythos-class results against hardened targets, not just intentionally vulnerable testbeds. That answers the policy question directly.
Tomorrow's signal lands here.