Friday's Rundown flipped from Thursday's extinction-odds gloom to something more concrete: Anthropic published a long Threat Report on how people tried to misuse Claude over the last eight months — and what the company says it shut down. I rewrote it the way I would tell a colleague over coffee. Short version: a 150+ page report covers Chinese labs allegedly distilling Claude (sometimes serving it as their own product), biology prompts that raised weapons flags, a Yemen rocket-guidance build with Claude Code, and a surveillance system aimed at millions of phone lines. Rowan Cheung used GPT-6 Astra to redesign his wardrobe into 30 ready looks with weather-aware picks and virtual try-on photos of himself. A how-to walks through ChatGPT Work projects for recurring workflows. DeepSeek released V4.1-Flash, a cheap open-weight model that punches above its price on some agent and coding tests. Reader Rich Kroll built a family streaming recommender that knows who's actually on the couch.
The newsletter also carried ads for Vanta and Tines. Skipping those.
Words worth knowing
| Word | In one line |
|---|---|
| Anthropic | A major AI company (maker of Claude) that markets itself as especially focused on AI safety. |
| Claude / Claude Code | Anthropic's chat models, plus a coding agent that can write and run software with more hands-on computer use. |
| Threat Report | Anthropic's published write-up of misuse cases it says it detected and disrupted (this one is 150+ pages covering ~8 months). |
| Distillation | Training a cheaper/smaller model by copying outputs from a stronger model — here, allegedly using Claude replies to improve a rival system. |
| Open-weight model | An AI model whose trained parameters (weights) you can download and run yourself, not only call through a company's chat API. |
| Frontier / Opus-level | Roughly "top-tier capability class." The report says the misuse cases used Opus-class Claude models and weaker ones — not some future super-system. |
| Astra / GPT-6 Astra | OpenAI's current flagship ChatGPT model for paid plans; Rowan used it for computer use, long jobs, and personal wardrobe design. |
| ChatGPT Work | ChatGPT's work-oriented project setup (local folder + automations) for recurring tasks like meeting notes to action items. |
| DeepSeek V4.1-Flash | DeepSeek's new efficient open-weight model; priced very low and released with an MIT license on Hugging Face. |
| Agentic benchmarks | Tests of AI that can plan and act in multi-step tasks (not just answer one question). |
| AA Intelligence Index | A third-party scoreboard of model "intelligence"; the letter says V4.1 scored 40 — still well behind the frontier leaders. |
| Millennium Prize problems | Seven famously hard maths problems with $1M prizes; Navier-Stokes is one (covered in Thursday's letter). |
Anthropic opens the books on Claude misuse
Anthropic published its latest Threat Report — a long public accounting of notable Claude misuse cases it says it disrupted over about eight months. The headline themes: distillation by Chinese labs, biology prompts that looked weapons-adjacent, a rocket-guidance build, and large-scale surveillance attempts.
- Anthropic named seven Chinese labs behind distillation efforts, including Alibaba, DeepSeek, Moonshot, and Xiaomi, relying on thousands of fraudulent accounts.
- Moonshot and DeepSeek allegedly served Claude to customers as their own model in some cases, then used the replies for training.
- Five biology cases from scientists using Claude raised flags for possible weapons applications; Anthropic said it "does not assert that they intended harm."
- One operation in Yemen used Claude Code to build guidance software for a rocket — and went back to Claude for advice after a failed test flight.
- A consultant built Mali's spy agency a system aiming to watch 25 million phone lines; similar surveillance attempts were banned in Iran, China, and elsewhere.
The newsletter's why-it-matters: this is only a brief. The full report also covers Claude running thousands of dating-app personas, cloning an activist's writing style to message their contacts, rebuilding malware to dodge antivirus tools, and more. These were attempted with Opus-level models and below — which makes later reports about stronger models harder to imagine calmly.
Company report, not a court verdict
This is Anthropic's own threat-intelligence write-up of cases it says it disrupted. Treat the Chinese-lab and weapons-flag details as the company's account, not independently verified findings in this newsletter rewrite. Useful as "what the safety lab is publishing out loud," not as settled courtroom fact.
Rowan's Corner: Astra as a wardrobe system
Rundown co-founder Rowan Cheung has been pushing GPT-6 Astra on paid ChatGPT — especially computer use, visual consistency, and long one-prompt jobs. His personal experiment: redesign his whole wardrobe so choosing clothes is a system, not daily decision fatigue.
- He wears a lot of black (tee + jeans). He wanted an upgrade without a closet that creates more mental clutter.
- Plan: one outfit per day of the week, per season, plus gym and lounge — 30 looks total, hung and ready.
- He gave Astra full-body portraits, sizes, colours, niche style notes, and a master prompt. It generated 30 looks and about 70 try-on images with him as the model in every photo.
- Daily picks pull real-time local weather so the suggestion changes with what's outside. If a piece isn't online, he updates the model and it rebuilds.
- He posted the full step-by-step and master prompt in the Rundown Workflow Hub.
Steal for clinic ops
Same shape for any recurring "what do I wear / pack / bring" decision — or for standardised clinic uniforms and on-call bags: define the options once, then let a helper pick from the list with today's context. Keep real patient photos and identifiers out of consumer image tools unless privacy has been reviewed.
Practical: a beginner's guide to ChatGPT Work
A how-to on setting up a ChatGPT Work project for a recurring workflow — process the work once, then automate the repeat.
- Create a local folder with a two-digit prefix. In ChatGPT desktop: New chat → Work → Choose project → New project, name it, and select that folder.
- Tell ChatGPT about the project and ask it to propose a structure. Their example: meeting notes → action items and weekly plans.
- Add input documents and tell ChatGPT to process them once.
- Then ask it to create three useful automations that run on a schedule.
Pro tip from the letter: turn those automated routines into skills you can call manually with a slash command anytime.
Steal for clinic
Same pattern for weekly CPD notes, practice meeting minutes, or inbox triage templates — process a sample pack once, then schedule the boring repeat. Do not paste identifiable patient data into consumer ChatGPT unless your practice has approved that path.
DeepSeek turns up pricing pressure
Chinese lab DeepSeek released V4.1-Flash — an efficient open-weight model the letter says edges systems like Claude Opus 5 and GPT-5.6 Sol on several agentic, coding, and cyber benchmarks at very low prices.
- Flash runs at about a quarter of DeepSeek V4-Pro's per-token price and still outscores it across the board; it is now the company's default model.
- V4.1 scored 40 on AA's Intelligence Index — still well behind the frontier, but strong on agentic, coding, and cyber tests.
- Pricing: about $0.15 / $0.60 per million tokens (input/output). Weights are on Hugging Face under an MIT license.
- Flash joins Z.ai's GLM-5.3-Flash as two of the strongest systems in that cheap price band; DeepSeek still plans larger models in the family.
The newsletter's why-it-matters: DeepSeek's efficiency and price remain its edge. Chinese labs in general (perhaps helped by the distillation efforts in Anthropic's report) are squeezing margins just as buyers get more price-sensitive. The capability frontier still looks U.S.-led; the volume/price fight is wide open.
Community: Rich's household streaming picker
Reader Rich Kroll built Show Hole for a classic family problem: too long deciding what to watch, and the right answer changes with who's on the couch.
Different people overlap differently in different combinations. Most recommenders flatten that into one account profile or genre buckets. Show Hole treats people and viewing contexts as first-class: recommends "in the vein of" something liked, filters to services they actually subscribe to, skips titles people present have seen or vetoed, and explains why a pick fits tonight. He designed it with Claude Design, then built it with Claude Code.
Household entertainment workflow, not a clinic product. The transferable idea is context-aware recommendations for a small group — useful shape for any shared decision where "who's in the room" matters.
Quick hits
- Cognition rolled out SWE-2 inside Devin — a Kimi K3-based coding model that claims to match Fable 5.1 and GPT-6 Astra on certain coding benchmarks while costing 64% less.
- Andrew Tulloch (Thinking Machines co-founder) is moving from Meta to Anthropic, months after rejecting Mark Zuckerberg's reported $1.5B package and then signing on anyway.
- OpenAI denied to the NYT that Tristan Buckmaster's Codex prompts shaped its Navier-Stokes proof, while claiming "substantial progress" on another Millennium Prize problem.
- OpenAI launched ChatGPT for Financial Services — a ChatGPT Work edition with PitchBook, Crunchbase, and LSEG data baked in for valuation models and pitch decks.
- Universal Music Group is partnering with ElevenLabs on a licensing deal, with a fan remix platform for participating artists in development.
- Trending tools named (non-sponsored): DeepSeek V4.1 Flash, SWE-2, GPT-Live-1, Krea Agents.
What this means for a GP
None of this is clinical advice, and none of it should change how you treat a patient tomorrow. It is why a busy doctor might still skim the letter. Anthropic's Threat Report is the screenshot patients may share — treat it as the company's published casebook of misuse it says it stopped, not as a reason to panic in a consult, and not as proof every named lab did what is alleged. The stealable bits are operational: Rowan's "define 30 options, then let context pick" habit, ChatGPT Work for recurring admin once privacy is sorted, and Rich's reminder that shared household tools need to know who's present. DeepSeek's price squeeze is industry weather for any vendor bill you watch. Financial Services ChatGPT and music licensing deals are adjacent news unless a pitch leans on them.
Sources
- The Rundown AI, 11 September 2026 — Anthropic opens the files on global Claude misuse.
- Anthropic — Threat Intelligence Report, September 2026.
- The Rundown — Rowan's Astra wardrobe workflow.
- The Rundown — A beginner's guide to ChatGPT Work.
- DeepSeek — V4.1-Flash on Hugging Face.
- The Rundown — Rich Kroll's Show Hole workflow.
- Cognition — SWE-2 inside Devin.
- Semafor — Andrew Tulloch leaving Meta for Anthropic.
- NYT — OpenAI and the Navier-Stokes claim.
- OpenAI — ChatGPT for Financial Services.
- ElevenLabs — Universal Music Group partnership.