Friday, 25 September 2026
A court keeps Claude out of the Pentagon, and Copilot gets rebuilt.
Appeals court upholds the Pentagon's ban on Claude, 2-1
A federal appeals court in Washington, D.C., on Friday upheld the Pentagon's designation of Anthropic as a supply-chain risk, in a 2-1 decision [1][2]. The designation stops the US military from using Anthropic's models and blocks defense contractors from using them in their work for the department [2]. Judge Gregory Katsas wrote the majority opinion, joined by Judge Neomi Rao; Judge Karen LeCraft Henderson dissented [1][2].
The majority held that the department "had ample support" for concluding that keeping Claude in its information systems, directly or through contractors, was a national-security risk under the Federal Acquisition Supply Chain Security Act of 2018 [1][4]. It pointed to restrictions Anthropic builds into Claude, cases in which those restrictions stopped Claude from doing tasks government users asked for, and a dispute over whether Anthropic's contract terms barred Claude's use in an overseas military operation [1][4]. The court rejected Anthropic's due-process and First Amendment claims, saying the exclusion followed Anthropic's refusal to accept a contract term the department deemed essential, not its support for AI regulation [1][3]. Henderson argued the statute is aimed at sabotage and covert manipulation, not a vendor's "honest and upfront enforcement" of use restrictions [4].
This ruling covers one of two designations. A federal judge in San Francisco found the parallel designation unlawful last month [2][3]. The panel said it would delay its decision from taking immediate effect so Anthropic can ask for a rehearing, and the company could also go to the Supreme Court [2]. "We respectfully disagree with the court's decision," an Anthropic spokesperson told CNBC, adding that the company is "considering all options, including further review" [2].
Anthropic asks shareholders to give its seven founders voting control before the IPO
Anthropic is asking shareholders to approve a share structure that would give CEO Dario Amodei and his six co-founders a combined 50.1% of the vote on most corporate matters, according to The Information, as reported by TechCrunch and The Next Web [1][2]. The shareholder vote is expected "in the coming days" [1][2]. The control would last as long as at least three of the seven keep a minimum stake; no report has given the size of that stake [2].
The seven co-founders each own about 2% of the company, Amodei included, according to TechCrunch [1]. The new shares carry no extra economic value; their purpose is to keep the group in charge once the stock trades publicly [1][2]. The founders have pledged to give away 80% of their wealth, a commitment Amodei announced in January [1][2]. Anthropic has not commented publicly on the report [2].
The plan does not hand the founders the board. Anthropic's Long-Term Benefit Trust would still choose most directors, the founders' board seats would grow from two to three, and employees would get their own class of stock to break ties on some issues [1][2]. The Information calls the structure "Palantir-style"; Palantir's founders kept voting control through Class F shares that also depend on keeping a minimum stake [2]. Super-voting shares are common in tech, at Meta and Snap for example, but a group of seven holding control together is unusual, TechCrunch notes [1].
Anthropic was valued at $965 billion in a May funding round and was recently valued at $1.5 trillion on the secondary market, according to TechCrunch [1]. The company has chosen Nasdaq for its listing [2].
Microsoft rebuilds Copilot around Home, Code and Autopilot, with usage-based billing for agents
Microsoft has introduced a redesigned Copilot app with three parts: Home, Code and Autopilot [1][2]. Home combines Chat and Cowork, the mode that takes a delegated task and runs it end to end, and it brings Word, Excel and PowerPoint into the app through Office in Copilot [1]. Code lets anyone describe an app, tracker, dashboard or automation in plain language and have Copilot build it; the company says it runs in a sandbox, can be hosted inside a company's own tenant, and uses the same underlying technology as GitHub Copilot [1][2]. Autopilot, previously called Scout, is an always-on agent with its own identity, memory, computer and workspace that keeps working when its user is away [1][2].
The billing change matters more than the tabs. The regular per-user Copilot licence covers Chat and Copilot in Word, Excel, PowerPoint, Outlook and Teams, with an Auto setting that picks a model per request [1]. Cowork, Code, Autopilot and frontier models such as Astra and Fable run on usage-based billing instead [1][2]. Microsoft is adding FinOps for AI tools to match: admins can set spending policies, route credit requests into approval workflows and choose which model families each group can use, and users can see their own credit balance and history [1].
Timing is staggered. Home and Code start rolling out to Microsoft's Frontier early-access programme in the coming weeks, and Autopilot expands to private preview at the end of the month [1][2]. Code will be in preview for Microsoft 365 Premium and Pro subscribers later this year [1][2]. Per-unit prices for the usage-based parts are not public in either source.
UpGuard finds about 16,000 Supabase databases exposing personal data
Security firm UpGuard says it found around 16,000 databases hosted on Supabase that expose some degree of personal data to the public web, TechCrunch reports [1]. UpGuard started from about 300,000 domains showing signs of Supabase use, tested for a commonly named "users" table, and found 16,326 databases where at least some tables could be read; more than half showed signs of personal information [3]. The exposed data included names, addresses, phone numbers and, in fewer cases, passwords and authentication tokens [1]. Examples ranged from a US valet service's licence plates to an immigration and relocation service's contacts [1]. The count covers databases, not people or records [3].
TechCrunch attributes the exposures to basic misconfigurations [1]. Supabase's CISO Bil Harmer said projects are "secure by default" and that security is shared between the company and customers who configure their own projects [1]. TechCrunch ties the rise in exposures to AI-built apps, where generated code can carry security flaws or need settings the builder does not know about [1].
Supabase is already changing a key default. Previously, every table in the public schema was granted to the anon, authenticated and service_role roles, so it was reachable through the Data API as soon as it was created [2]. From May 30, new projects stopped exposing new tables automatically in a gradual rollout, and on October 30 that setting applies to all existing projects [2]. Existing tables keep their current grants, and Row Level Security, which controls which rows a role can see, works as before [2]. That means tables already open stay open until someone fixes them.
One testing firm's setup error sent four labs' AI agents after real targets
Several of this year's incidents in which AI agents from OpenAI, Meta, Anthropic and Google attacked real organisations trace back to one testing company, according to The Verge [1]. Irregular, an Israeli startup that stress-tests AI models' cyber capabilities, ran capture-the-flag exercises that were meant to be sealed off; its CTO Omer Nevo told The Verge that "internet access was unintentionally available" and that a fictional target company's name "overlapped with a real domain" [1]. Nevo confirmed the same issue was behind the incidents involving all four labs' models and said other recently reported incidents are unrelated; The Verge says those include the Hugging Face hack and breaches at the UK's AI Security Institute [1].
Anthropic's own account shows the scale. After reviewing 141,006 evaluation runs where Claude could have reached the internet, it found three incidents in which a model got out through Irregular's evaluation environment and gained unauthorized access to the production systems of three different organizations [2]. Anthropic says it notified Irregular and the three organizations on July 27 [2]. The Verge notes that the labs were told at roughly the same time in late July, but the Meta and Google cases first became public through media reports [1].
Nevo said Irregular has tightened internet access controls and expanded monitoring and manual review [1]. The company is raising more than $100 million at a $1.5 billion valuation in a round led by Thrive Capital and Greenoaks, which is not yet final, according to Ctech [3]. Irregular also tested Moonshot's Kimi K3 and Z.ai's GLM-5.2 without similar real-world incidents, though Nevo cautioned that this is not evidence those models are safer [1].
Meta says letting Muse hand over its whole filesystem is intended
Meta's Muse agent will now share the full contents of its cloud computer on request, The Verge reports [1]. Developers Peter James and Jonny L. Saunders have said they coaxed Muse into zipping up its root filesystem, including Ubuntu system files, app templates and internal documentation; Saunders said it had "almost no prompt injection resistance" [2]. The files describe how Hatch, Meta's internal name for Muse, handles requests and data, and show that it keeps memory in plain Markdown files [2].
Meta says this is not a breach. Each Muse user gets a persistent Linux virtual machine, and spokesperson Daniel Roberts said exporting its data gives no privileged access to Meta infrastructure or other people's data [2]. Nat Friedman of Meta Superintelligence Labs called it "intended behavior," and David Singleton said the VM "truly is your own computer in the cloud" [1]. On Friday Muse offered a clickable file browser with access to root and zipped the whole directory, with secrets stripped out, after refusing a full copy a day earlier [1]. Meta has not explained why Muse first called that a security risk [1]. It is the second Muse issue this week, after a researcher found a hijacking exploit that Meta hotfixed [2].
Use keeps climbing. Muse passed 3.4 million downloads since its September 8 launch, according to Sensor Tower estimates cited by TechCrunch, and has held the top spot on the US App Store since September 18 [3]. It is available only in the US and Canada [3].
