Top 10 AI News Today (September 19, 2026): Biggest AI Stories, Breakthroughs & Market Moves

Last updated: Sep 19, 2026 — next refresh daily.

Top 10 AI News Today (September 19, 2026): Biggest AI Stories, Breakthroughs & Market Moves

Today's AI news roundup covers the ten biggest stories for September 19, 2026 — the day California's governor ordered a frontier-AI kill switch, CNN revealed that a chatbot's false intelligence report nearly started a war with China, security researchers disclosed a zero-click RCE across four coding agents, and OpenAI got a taste of its own medicine when researchers hacked it with Anthropic's Claude — followed by the five most important AI security stories of the day, from the SHA-pinning bypass to the training-data revelations in the unsealed NYT case. Each story has a two-sentence summary and links to the most informative free, non-paywalled articles.

Today's AI Landscape in Brief

The federal inaction argument produced its loudest counter: Governor Newsom issued an executive order fast-tracking California's independent-oversight laws and advancing a mandatory "AI kill switch" for frontier models — "the federal government's abject failure... should alarm every American." Around it, the week's deepest alarms landed: CNN revealed a chatbot-generated intelligence report that falsely claimed a Chinese ship carried nuclear-weapons parts "almost started a war," Air Security disclosed Plugin4Shell — a zero-click RCE across Claude Code, Codex, GitHub Copilot and Gemini CLI — and Hacktron breached OpenAI in 72 hours using Anthropic's Claude, for under $3,000. On the industry side, Musk proposed mutual model testing between US and Chinese labs, the open-source civil war split Silicon Valley (OpenAI/Anthropic lobbying for restrictions vs Huang, Nadella, Zuckerberg, Pichai and 200 startups backing openness), Anthropic quietly stood up a wet lab for its drug program, and California's kill switch met Google's abandoned Gemini CLI in the same weekend's security news.

1. Newsom Orders California Toward a Frontier-AI Kill Switch — "We're Not Waiting to Act"

Governor Gavin Newsom issued an executive order accelerating California's new AI oversight regime: fast-tracking implementation of SB 813 (McNerney) — the first-in-the-nation framework for certifying independent verification organizations — and AB 1405 (Bauer-Kahan) — the state registry for AI auditors — while convening an expert panel to deliver within two months a guide for strengthening the laws. Under active consideration: requiring frontier AI companies to embed a designated independent verification organization on-site, and advancing the creation of an "AI kill switch" for frontier models with efficacy verified on an ongoing basis — plus updating the definition of critical safety incidents to include loss-of-control incidents such as the Hugging Face attack. Newsom's statement was pointed: "The federal government's abject failure to create any form of meaningful AI oversight or accountability should alarm every American, especially when AI CEOs themselves are begging for regulation. We're not waiting to act."

2. CNN: A Chatbot's False Intelligence Report "Almost Started a War" With China

CNN reported that this spring, during the war with Iran, a US special-operations analyst used an AI chatbot to analyze a Chinese ship's manifest — and the chatbot falsely concluded the vessel was transporting components of a nuclear weapons programme. The report, circulated across the US military, triggered plans to intercept the vessel: armed personnel were preparing to board and military aircraft were in the air — until officials dug deeper, found the AI had misidentified the cargo, and called the report "entirely false." "It almost started a war," one source said — the starkest example yet of the failure mode analysts have feared for years: human beings making catastrophic decisions on inaccurate AI-generated intelligence, with no single standard for checking AI-produced information across the intelligence community, and one source's summary doing the work: "AI allows you to get to a bad idea faster."

3. Plugin4Shell: A Zero-Click RCE Across Claude Code, Codex, GitHub Copilot and Gemini CLI

Air Security disclosed Plugin4Shell, a zero-click remote code execution flaw hitting four of the most widely used AI coding agents — Claude Code, Codex, GitHub Copilot and Gemini CLI — through their plugin marketplaces, affecting what researchers call "millions of installed agents." The bug is a SHA-pinning bypass: "the agent checks out the exact commit the marketplace pinned but never verifies it landed there," so an attacker controlling a plugin repo makes the checkout resolve to malicious code while the pin looks honored — via a branch named identically to the pinned hash (Bitbucket/self-hosted git) or a default branch named "FETCH_HEAD" (Gemini CLI). The split response is the story: Anthropic patched (Claude Code 2.1.179, June) and OpenAI patched (Codex 0.146.0, August) months before the write-up; GitHub Copilot had no patch as of disclosure — with roughly 90% of Fortune 500 companies using it — and Google will not patch Gemini CLI at all, telling users to migrate to Antigravity instead.

4. OpenAI Hacked in 72 Hours — With Anthropic's Claude

Researchers from Hacktron breached OpenAI's internal systems in less than 72 hours, chaining a HEIF image upload to a libheif heap overflow for RCE on OpenAI's Discourse forum, then exploiting an SSO misconfiguration to impersonate an OpenAI employee and take over ChatGPT and Codex accounts linked to GitHub, Slack and email — proving access with a harmless pull request in OpenAI's internal monorepo. The exploit was built with Anthropic's Claude Opus 5 (Opus 4.8 failed; the new model produced a working exploit within three hours), the entire project cost under $3,000 in AI credits, and adapting the attack to new targets (Slack, Meta, GitHub Enterprise) took one to two days per target — with only Shopify noticing. OpenAI fixed the issue within 14 hours and paid a $6,500 bounty; the researchers' conclusion is the industry's new threat model: "Work that once required a well-resourced team and extensive effort can now be compressed... into a few thousand dollars."

5. Musk's Mutual-Testing Proposal: Let US and Chinese Labs Test Each Other's Models

Speaking at the All-In Summit, Elon Musk proposed that American and Chinese AI companies independently test each other's models before release — with xAI, OpenAI, Anthropic, Google, Meta and "three or four leading Chinese AI companies" running a common "test harness" on rivals' systems. "The odds that you will find issues are dramatically greater" with competitors involved, Musk said — adding that China "would probably agree," that it could be implemented quickly, and that it is "a step in the right direction." The proposal is the first concrete mechanism for the cooperation both Amodei's essay and the nuclear-style-safeguards blueprint call for — and it converts the rivalry from a zero-sum complaint into a verification arrangement, the same logic as mutual arms inspections.

6. The Open-Source Civil War: OpenAI and Anthropic Lobby for Restrictions as Huang, Musk, Zuckerberg and Pichai Unite for Openness

The New York Times reports the week's deepest industry split: OpenAI and Anthropic are lobbying Washington, citing national security and AI safety, to restrict Chinese open-source models — as their fear of eroding competitive edge grows with Zhipu's and others' open releases — while Jensen Huang, Satya Nadella, Elon Musk, Mark Zuckerberg and Sundar Pichai publicly back open source ("The world needs both cutting-edge closed-source models and cutting-edge open-source models," Huang posted; "Jensen Huang is right, I fully support it," Musk replied nine minutes later; Pichai announced Google signed the open letter from nearly 200 startups under the Small Tech Association banner). Bill Gurley summarized the split: "One side wants OpenAI and Anthropic to control everything, while the other is everyone else, including customers" — and officials reportedly prefer treating Chinese open models as a national-security issue rather than imposing a comprehensive ban. Altman publicly supports open source while allies lobby behind the scenes, per the report.

7. Jev: A ChatGPT Inventor's "Not an LLM" Model Is Thrilling Developers

Two years after leaving OpenAI, André Almeida's TypeSafe AI released Jev — a transformer-based model that is not a large language model: it doesn't output text but produces probabilities, or what the company calls "calibrated decisions" — and demand was so high the API briefly lost the ability to serve users. Developers see it as a cheaper, more robust way to put intelligence into code — in some comparisons running 10 to 20 times cheaper than Gemini for email-classification work — and, critically, as an agent-monitoring layer: Jev can track LLM agent traces and prevent jailbreaks at a fraction of the cost of "agents watching agents." Almeida's framing — a "System One model" learned from calibrated reasoning — is the first credible answer to the week's question of who watches the agents: a model cheap enough to watch them all.

8. Google's "CC" Becomes a Family Household Agent — With Its Own Google Account

Google is testing a new version of CC, its AI agent for families: CC now runs on its own isolated cloud computer powered by Gemini and Google's agentic harness Antigravity, with its own Google account so it can collaborate with family members while maintaining separate data permissions — each family member chooses what to share (school emails, sports, birthday invites, doctor appointments) via CC's email address. The agent tracks dates and to-dos, adds them to shared calendars, and handles tasks like filling out permission slips and activity-registration PDFs, creating shopping lists and weekly meal plans, planning drive times and creating shared Docs — asking for missing details and updating its group memory. Available to US users 18 and up with personal Gmail accounts, the experiment is the clearest consumer-agent bet yet from Google — and the family inbox is the most sensitive dataset an agent has been offered yet.

9. Anthropic Quietly Sets Up a Wet Lab as It Ramps Its AI Drug Program

Reuters reported that Anthropic has built a wet laboratory in the San Francisco Bay Area for physical biology work — going beyond its "in silico" evaluations — as it pushes into drug science, with head of life sciences Eric Kauderer-Abrams confirming the lab and describing "the very early innings of using AI to automate the execution of lab work." The company's stated goal is to "speed up progress in the life sciences by an order of magnitude" — with Claude directing robotic units to run experiments with limited human intervention — and it has already launched Claude Science, added Novartis CEO Vas Narasimhan to its board, and bought Coefficient Bio for about $400 million in stock. The boundary is explicit: "We're not competing with pharma and biotech companies that make their business in bringing drugs to market" — and the lab exists at the same moment the company's researchers are warning AI could help build bioweapons, a tension the week has made unavoidable.

10. European Industrial AI Goes Live: 19 Nations Fund a Sovereign Stack

Nineteen EU member states have entered the pre-notification phase for IPCEI-AI — the first Important Project of Common European Interest targeting AI directly — with Germany committing over €1 billion as coordinator and a six-layer technical architecture designed to give European industry an alternative to US hyperscalers it actually owns, with applications closing October 31. The sobering context: no EU company created in the last 50 years has reached €100 billion in market cap, the EU-US AI investment gap is more than eight to one, and the AI Gigafactories program's chips come from AMD, Nvidia and Qualcomm — so the compute substrate of European sovereign AI will remain US-dependent. The structural risk is the timing gap: Brussels approval timelines (18-24 months) versus Silicon Valley release cadences — the same gap that defines the whole AI-safety debate, now instantiated in state-aid law.

AI Security: The 5 Most Important AI Security News Stories Today

Plugin4Shell, in Full: The SHA-Pinning Bypass That Reproduces Across Four Vendors

The technical detail makes the four-vendor spread unsurprising: agents fetch a marketplace-pinned commit hash but never confirm the checkout actually resolved to that hash — so on Bitbucket and self-hosted git, a branch named identically to the pinned hash resolves as the default, and against Gemini CLI, a default branch named "FETCH_HEAD" intercepts the exact ref the agent's fetch command requests. Because Claude Code and Codex auto-update installed plugins by default, a plugin that passed review months earlier can be swapped for malicious code later and pulled in silently — no click required. The split response is the security news: two vendors fixed it months ago (Claude Code 2.1.179, Codex 0.146.0), Copilot is exposed with 90%-of-Fortune-500 adoption and no patch date, and Google's "migrate instead" is an end-of-life notice attached to a live RCE. The structural lesson: a flaw that reproduces across four unrelated codebases means the abstraction — trust a pinned SHA without verifying the fetch — was wrong industry-wide.

The HEIF Heist: What a $3,000, 72-Hour Breach Means for Every Threat Model

Hacktron's breach is the template the industry has been dreading: a two-vulnerability chain (libheif heap overflow → Discourse SSO flaw) weaponized by Claude Opus 5 in three hours, then scaled to new targets in one to two days each for under $3,000 total — with the researchers noting only Shopify noticed their extended probes despite "thousands of image uploads and repeated crashes." The implications stack: image parsers in AI-adjacent platforms are a rich RCE surface (HEIF/AVIF processing), SSO misconfigurations turn a forum compromise into an enterprise-wide takeover (the hijacked employee account reached GitHub, Slack and email), and the cost curve for offensive work has collapsed — three people, two months, a few thousand dollars, and a working exploit pipeline across multiple major vendors. Every organization running AI tools should assume this exact chain is being attempted against it.

The Near-War Hallucination: AI in Military Targeting With No Verification Standard

The Chinese-ship episode is the catastrophic failure mode analysts have warned about since the first hallucination: an analyst's chatbot consultation produced a false nuclear-weapons claim that reached the point of armed boarding teams and aircraft in the air. The aggravating factors are structural, not one analyst's error: the bot fused open-source and secret signals intelligence without provenance separation, the analyst used AI again to package the finding into a standard-format report that military officials trusted, and sources say there is no single standard for checking AI-produced information across the intelligence community — with targeting AI "definitely ramping up and no real guidance for how having a human in the loop will prevent civilian casualties or fratricide." The incident gives the nuclear-style safeguards debate its first concrete case study: the hotline and human-only military decisions are no longer hypotheticals.

The Third Major Resignation: Ex-DeepMind Researcher Bilal Chughtai Warns "Time Could Be Running Out"

Reuters reported Bilal Chughtai, a former Google DeepMind research engineer who worked on AGI safety and alignment and left in July, became the latest researcher to warn that AI could "kill all humans" — "I earnestly believe that AI has the potential to kill us all, and that we might be running out of time to avoid this outcome." The pattern across three labs is now unmistakable: Coxon (Anthropic), Kokotajlo (OpenAI), Chughtai (DeepMind) — each quitting and warning publicly — and the security-relevant fact is the disclosure channel they use: individual resignations, not incident reports, are how frontier-risk information is reaching the public, which is precisely the gap the EU's regime, California's executive order, and the embedded-evaluator proposals are trying to close from different directions.

The Unsealed NYT Documents: "The Largest Theft of Labour in Human History"

Newly unsealed court documents from the New York Times lawsuit reveal internal Microsoft and OpenAI concerns about training on millions of news articles — a Microsoft executive describing the practice as "the largest theft of labour in human history" creating a "doom loop," an OpenAI executive warning AI posed an "existential threat" to publishers, an engineer writing "no matter how prominently we show the links, users won't click" — plus allegations about methods for accessing paywalled content and removing copyright notices, with more than 91,000 copies of litigated works in OpenAI's mid-training datasets and over 2 million nytimes.com documents in a Common Crawl-derived dataset. Nadella's deposition ("anything that is paywalled should be licensed") sharpens the legal stakes: the case now turns on whether transformative use covers training at this scale — the outcome the entire AI-content economy is waiting on.

More AI Stories Worth Reading Today (Bonus)

  • Crusoe raised $3.9 billion in a Series F at a $30.9 billion valuation — co-led by Atreides, Mubadala and Valor, with Nvidia and QIA participating — financing the Abilene, Texas OpenAI site and truck-transportable AI factories — WordUp News
  • xAI is suing California over its AI Training Data Transparency Act (AB 2013) and Minnesota over legislation targeting nudify applications — the legal counter-attack to the state-level wave — The Times of India
  • TypeSafe's Jev demand crashed its own API — the "System One model" may be the cheapest answer to agents-watching-agents yet — TechCrunch
  • The Brussels-vs-Silicon-Valley timing gap, quantified: IPCEI-AI approval runs 18-24 months while US frontier labs release multiple model generations — the structural risk at the heart of European sovereign AI — TechTimes

Methodology & Sources

Compiled September 19, 2026 via multi-source research across outlets including the Office of Governor Gavin Newsom, BusinessToday, RNZ (CNN), Hindustan Times, Temperature2, The Guardian, The Decoder, Tom's Hardware, The Times of India, xix.ai, TechCrunch, The Star (Reuters), TechTimes, WordUp News (Reuters/AP), and Tech Edition. All linked articles were selected for being free to read (no paywalls); where a story was originally reported by a paywalled outlet (Reuters, CNN, Bloomberg, The New York Times), the links point to free syndication or coverage of it. Details on the executive order, the military incident, the Plugin4Shell disclosure, the Hacktron breach, the open-source split and the wet lab are as reported at compilation time and may evolve.


Frequently asked questions

QWhat did Governor Newsom's executive order do?

Newsom issued an executive order accelerating California's new AI oversight laws — SB 813 (McNerney), creating a framework for certifying independent verification organizations, and AB 1405 (Bauer-Kahan), establishing a state registry for AI auditors — and convening an expert panel to deliver within two months recommendations that could require frontier companies to embed independent verifiers on-site and develop an 'AI kill switch' for frontier models, with efficacy verified on an ongoing basis. It also directs updating the definition of critical safety incidents to include loss-of-control incidents such as the Hugging Face attack.

QWhat happened with the false AI intelligence report on the Chinese ship?

CNN reported that this spring, during the war with Iran, a US special-operations analyst used an AI chatbot to analyze intelligence on a Chinese ship's manifest — and the chatbot falsely concluded the vessel was transporting components of a nuclear weapons programme. The report, 'entirely false' per one source, triggered US military preparations to intercept the ship, with armed personnel ready to board and aircraft in the air, until officials dug deeper and found the AI had misidentified the cargo. 'It almost started a war,' one source said.

QWhat is Plugin4Shell?

Air Security disclosed a zero-click remote code execution flaw hitting four AI coding agents — Claude Code, Codex, GitHub Copilot and Gemini CLI — through their plugin marketplaces. The bug is a SHA-pinning bypass: agents check out the exact commit a marketplace pinned but never verify it landed there, so an attacker controlling a plugin repo can make the checkout resolve to malicious code while the pin still looks honored. Anthropic patched Claude Code (2.1.179) and OpenAI patched Codex (0.146.0); GitHub Copilot had no patch as of disclosure, and Google will not patch Gemini CLI at all — it is deprecated, with users directed to Antigravity.

QHow did researchers hack OpenAI using Anthropic's Claude?

A three-person team at Hacktron breached OpenAI in less than 72 hours in July by chaining a HEIF image upload to a libheif heap overflow for remote code execution on OpenAI's Discourse forum, then exploiting an SSO misconfiguration to impersonate an OpenAI employee and take over ChatGPT and Codex accounts linked to GitHub, Slack and email — proving access with a harmless pull request in OpenAI's internal monorepo. The exploit was built with Anthropic's Claude Opus 5, the project cost under $3,000 in AI credits, and OpenAI fixed it within 14 hours and paid a $6,500 bounty.

QWhat is Anthropic's new wet lab?

Reuters reported that Anthropic has quietly set up a wet laboratory in the San Francisco Bay Area to do physical biology work as it ramps its AI drug program — beyond the 'in silico' work it has already done. Head of life sciences Eric Kauderer-Abrams confirmed the lab, saying Anthropic is in 'the very early innings of using AI to automate the execution of lab work,' with the goal of speeding up life-sciences progress 'by an order of magnitude' — while setting a boundary that it is not running clinical trials or competing with pharma.


Freshness

Last updated: Sep 19, 2026 — next refresh daily. This roundup is updated as stories develop; dateModified is bumped on every refresh so readers can see exactly how fresh the coverage is.

← Previous