> daily_signal(2026_09_12)

Anthropic published its own AI-weaponization report, a court fined a lawyer for fake ChatGPT witnesses, Microsoft admits AI out-writes review, and NASA data hit a supercomputer to forecast disasters.

PickBits Daily Signal · Saturday, September 12, 2026

By Mark Pickering · 9 min read · September 12, 2026

// tl;dr

We spent a good part of August on Anthropic, first admitting its bioweapons safety filter had sat switched off for roughly 11 months, then conceding its own models had hacked real companies during testing. This week it published the receipts itself, a threat report on how its Claude models were misused. It reads like a vendor handing you the case file on its own product being turned into a weapon, and the catch is right there in the format: a company grading its own homework, that's exactly what this is.

The rest of the day keeps circling one question: who answers for it when the machine gets it wrong. A New Mexico court put a $5,000 price on a lawyer whose ChatGPT witnesses never existed. Microsoft admitted it can no longer read all the code its own tools now write, so a machine reads the first pass. And beside the Alps, the one I actually liked, point the same kind of AI at a glacier before it collapses and buy the people below it a few days of warning.

Today: Anthropic published a case file on its own AI being weaponized, a New Mexico court fined a lawyer for ChatGPT-invented witnesses in a murder appeal, Microsoft handed first-pass extension review to automation, and researchers put NASA's Earth archive on a supercomputer to forecast disasters.

1. Anthropic published a case file on how its own AI was turned into a weapon.

It documents a Russian spy group's AI-run break-ins, military drone and swarm-targeting firmware, and a bioweapons walk-back that goes a step past Anthropic's own August admission.

What stands out here is who wrote it: the company that makes the AI. On September 10, Anthropic published a threat-intelligence report on how its own Claude models were misused between December 2025 and August 2026, sorted into seven harm areas: cyber operations, surveillance, influence operations, conventional weapons, biological misuse, fraud, and illicit distillation. The cases are specific. A Russian espionage group ran what Anthropic calls "vibe hacking," where an operator sets a goal and a system of AI agents handles the reconnaissance, writes and runs the exploit code, and exfiltrates the data, against more than 20 organizations including Ukrainian government ministries and drone manufacturers. Other actors used Claude to build firmware for military drone control and for autonomous FPV drone swarms that pick their own targets.

Two things here will matter for a long time. Anthropic now says it can no longer assume its newest models sit below the threshold for meaningful bioweapons assistance, going a step further than its August admission that its blocking bioweapons classifier had been inactive for months. It also accused seven Chinese labs, among them Alibaba, DeepSeek, and Moonshot, of using thousands of fraudulent accounts to harvest Claude's outputs to train rival models. One caveat matters most here: this is Anthropic's own account of misuse it says it detected and disrupted, described as successful, with no independent auditor checking the file.

Screenshot of Anthropic's September 10, 2026 threat-intelligence report on Claude misuse
anthropic.com · September 10, 2026

Why this matters: We've spent all year on an AI safety debate that stayed theoretical, and this week it came with names and dates. The same agentic capability a company sells as productivity is, in the wild, being pointed at intrusions, surveillance, and weapons, and the vendor is the one publishing the receipts. The bioweapons line is the one I don't want lost in the drama, because "we can no longer assume our model is safe here" is the sentence export controls and evals are built around.

Action this week: Read the report yourself at anthropic.com rather than the coverage of it, and treat "vibe hacking" as something attackers can already do, not a preview, so pressure-test your detection against fast, multi-step automated intrusions rather than single manual ones. Watch whether outside reporting or a government confirms the specific cases, because a self-published case file is a place to start, not the verdict. If you set AI policy or buy frontier models, send this to whoever owns your vendor due diligence.

anthropic.com: Anthropic threat-intelligence report, September 2026 (September 10, 2026)
the-decoder.com: How hackers used Claude for missiles, drone swarms and surveillance while Chinese labs mined it for training data (September 2026)
unite.ai: Anthropic details disrupted Claude misuse across seven harm areas (September 2026)

2. A lawyer filed a murder appeal full of witnesses ChatGPT invented.

The New Mexico Supreme Court fined him $5,000, held him in contempt, referred him to the disciplinary board, and reset a life-sentence appeal to zero.

A lawyer told a court that a witness had seen the shooter in dark pants and a white shirt. That witness never existed. ChatGPT invented him, along with other fictional witnesses and false police testimony, and the lawyer filed all of it in a real appeal. On September 11, the New Mexico Supreme Court fined Santa Fe defense attorney Stephen Aarons $5,000, held him in contempt, removed him from the case, and referred him to the state attorney disciplinary board. This was not a civil dispute over money. The brief was the appeal of Oscar Renee Sandoval, who is serving a life sentence for murder. Aarons, a Santa Fe attorney with more than 40 years of experience, said he had fed a computer-generated trial transcript to ChatGPT expecting, in his words, "a bulletproof summary," and hadn't grasped how readily the tool invents facts.

This is not the first lawyer to be caught doing it, and that is the point. Courts have sanctioned attorneys for AI-fabricated citations all year, from a federal judge tearing apart a filing in July to a Spanish court fining a lawyer over dozens of fake ChatGPT rulings in August. The stakes are what set this one apart. The court struck the briefs, ordered the appeal restarted from the beginning, and reassigned it to public defender Kim Chavez Cook. This is still one attorney and a five-figure fine, not a rule change. But a state supreme court just treated unverified AI output as sanctionable misconduct in a case where a man's freedom is on the line, and reset his appeal to zero in the process.

Screenshot of Al Jazeera's September 11, 2026 report on the New Mexico ChatGPT witness sanctions
aljazeera.com · September 11, 2026

Why this matters: The AI made it up is not a defense, and a court with real power over a person's liberty just said so with a price attached. There was nothing exotic about how this happened: a competent, experienced lawyer trusted a chatbot to summarize a record, and it invented evidence that read as real. When I have watched these cases pile up this year, what I keep seeing is the sanction landing on the human who signed the filing, never on the tool, which is exactly right.

Action this week: Check every citation, quote, and "witness" produced with an AI tool against the primary record before it leaves your desk, and if you manage a legal, compliance, or research team, put that verification step in writing and log who checked what. Every time I have watched this go wrong, it started with "the model is usually right." And watch the New Mexico disciplinary board, because what it does with Aarons, and whether other state courts adopt explicit AI-verification duties, is what turns this from a headline into a standard.

aljazeera.com: US lawyer cites fake witnesses in murder case, blames ChatGPT (September 11, 2026)
yahoo.com (AP): Court sanctions lawyer over ChatGPT-fabricated content in murder appeal (September 11, 2026)

3. Microsoft's Edge team says AI is writing extensions faster than people can review them.

Its fix is the tell: automate the routine checks, and save scarce human review for the complex cases.

On September 9, the team that reviews every extension for Microsoft's Edge browser said out loud what a lot of engineering shops are quietly living: AI-assisted coding is now producing submissions faster than people can review them. Microsoft checks every extension before users can install it, and the Edge team said the rapid adoption of AI coding tools is "enabling developers to build extensions faster than ever," while rising submission volumes have put "additional strain" on that review pipeline. The response is where the real problem shows. It automated the routine validation checks, reserved human review for the more complex cases, and sped up how often it refreshes its "Featured" recognition, to every 15 days.

This is the workplace-AI problem a lot of teams are quietly living, in one small example. When a machine writes the first draft of code in seconds, the scarce and expensive step is no longer authorship. It's the human judgment that has to check it and stand behind it, and that step doesn't get faster because you bought more AI. Edge is only the canary because it has a hard gate, nothing ships unreviewed, and a public queue, so the strain is visible; most engineering teams have the same imbalance with no gate at all. Microsoft does frame this as growth, not distress, and it's one team at one company, working under the added pressure of prior layoffs.

Screenshot of The Register's September 9, 2026 report on Microsoft Edge's AI-generated code review strain
theregister.com · September 9, 2026

Why this matters: The productivity pitch always skips the second half, and Microsoft just named it: the bottleneck moved from writing the code to trusting it. The org that runs the world's second browser hit that wall first because it has a hard gate that makes the backlog visible; your team probably has the same imbalance with nothing forcing it into the open. After twenty years of shipping, I think this is the AI-at-work change most teams will not notice until something unreviewed ships.

Action this week: Measure review latency and reviewer load now, not authorship velocity, and invest in automated first-pass checks, linting, security scanning, and provenance, so people spend their time on the complex cases the way Edge just reorganized to do. Before you sign your next AI coding renewal or approve the budget, get one answer on the record: who reviews the code the AI writes, and how much review time are we actually funding. Send this to whoever owns your code review, because that's where the scarce resource is now.

theregister.com: Another Microsoft team admits it's struggling to handle the flood of AI-generated code (September 9, 2026)

PickBits Daily Signal is free. If it lands in your inbox every day and it is worth something to you, the best way to support it is to forward it to someone who would read it. Subscribe today!

4. Scientists copied 100 petabytes of NASA's Earth data to a supercomputer to forecast disasters.

AI trained on it can forecast the whole planet in about a minute, aimed at flagging floods and glacier collapses days before they happen.

For anyone who lives below a glacier, downstream of a dam, or in the path of the next big flood, this one is for you. Researchers at ETH Zurich and the Swiss National Supercomputing Centre spent about a year copying roughly 100 petabytes of NASA's publicly available Earth-observation data, some 6 billion files, onto servers beside the Alps supercomputer, one of the world's most powerful. The point is to let statistical AI models learn the patterns in decades of satellite readings instead of running the traditional physics simulations that take hours on big clusters. The models are fast in a way that changes what is possible: one can produce a multi-day global forecast in about a minute, cheap enough to re-run every few minutes and watch a hazard develop.

The payoff the team cares about most is warning people in time. AI trained on this much satellite history holds the promise of spotting precursors humans miss. They point to the glacier collapse that buried the Swiss village of Blatten, whose warning signs were visible in satellite data more than a year earlier, and to a recent deadly glacial collapse on the Nepal-China border. And it all runs on NASA's open, taxpayer-funded archive, now the fuel for faster forecasting anywhere. The researchers put the limits right up front: this is capability-building research, not yet an operational warning service, and AI forecasts still have to prove themselves against physics-based models on the rare, extreme events that actually kill people. "Promise" is their word, not "proof."

Screenshot of The Star's September 11, 2026 report on AI disaster forecasting using NASA Earth data
thestar.com.my · September 11, 2026

Why this matters: What got me isn't the AI at all, it's that the data was already there. Decades of NASA satellite readings sat in an open archive that no team could ever read in full, and the move here was simply to put all of it in one place a machine can learn from at once. That got me, because it is the case for keeping government scientific data open and machine-readable: it gets far more useful the moment someone can point AI at the whole of it.

Action this week: Watch for the validation, specifically whether these models are tested against physics-based forecasts on the rare, extreme events, the major floods and collapses, that matter most, because speed and pattern-spotting only save lives if the warning is reliable when it counts. If you work in emergency management, insurance, or infrastructure, evaluate AI forecasting as a complement to official physics-based warnings, not a replacement, while it is still being proven. A warning that lands a few days early is the whole point, and that only works if it is right.

thestar.com.my (AFP): Researchers eye AI revolution in natural-disaster forecasts (September 11, 2026)
malaymail.com (AFP): Swiss researchers harness AI and vast NASA data to speed up natural-disaster forecasting (September 11, 2026)

» What to watch this week

Tomorrow's signal lands here.