Three threads converge this week: the AI trust layer is fracturing as Anthropic goes public with named accusations; the developer infrastructure layer is maturing as OpenAI opens its orchestration harness; and Washington is moving from spectator to lender in the data-centre buildout. Each has direct consequences for how an operator sources, builds, and funds AI work.

Anthropic Names Five Chinese Labs in Its Most Detailed Distillation Report

Anthropic published its September threat-intelligence report on Thursday, accusing five Beijing-linked AI companies of running sustained, unauthorised campaigns to extract Claude's capabilities and feed them into competing training pipelines. The combined activity totals nearly 200 million Claude exchanges — a figure that puts the scale of the problem beyond dispute.

The largest single campaign belonged to Alibaba, which Anthropic linked to more than 151 million Claude interactions between May and July 2026, executed through a coordinated network of accounts. The most striking allegation involves Moonshot AI, maker of the Kimi family: Anthropic claims Moonshot silently routed approximately 300,000 Kimi user requests to Claude in one ten-day cluster — via 5,380 accounts Anthropic characterises as fraudulent — and then displayed Claude's responses to Kimi customers as if they were Kimi's output. Moonshot's total alleged exchange count stands at more than 23 million. DeepSeek, Xiaomi, and Zhipu are also named in the broader report, which covers misuse activity from December 2025 through August 2026 across seven categories including cyber operations, influence operations, and biological misuse.

The targeted capabilities were not random. Anthropic says the distillation campaigns concentrated on agentic reasoning, software engineering, and logical reasoning — precisely the capabilities that determine frontier pricing power. For any operator currently evaluating a model from one of the named labs, the report raises a pointed question: how much of that model's performance was extracted from a system whose commercial terms neither party agreed to?

OpenAI Opens the Codex Harness to All Developers

OpenAI moved the Agents API from private preview to public beta on 10 September, giving any API developer managed access to the session infrastructure that runs Codex. The service handles the orchestration work that has been the hidden cost of production agent deployments: long-lived sessions, context compaction across multi-step tasks, subagent coordination, and recovery from mid-task failures. Developers define the task, model, and tools; the harness manages state and execution.

Compute can stay on a developer's own infrastructure or route through one of nine integrated environment partners — Cloudflare, DigitalOcean, Modal, Vercel, E2B, Daytona, Blaxel, Runloop, and Oracle. OpenAI charges no separate Agents API fee; billing runs through the models and tools each session consumes. Early production numbers from beta participants indicate the gains are material: SafetyKit reported a 60% cost reduction, Hypha saw 86% fewer task failures, and Cirridae cut latency by a factor of four.

For any team that has been engineering its own orchestration layer, the Agents API resets the make-or-buy calculus. The question is no longer whether you can afford to build production-grade agent infrastructure — it is whether you want to bind your operations to OpenAI's execution environment at the scale you intend to reach.

Pentagon in Talks to Back AI Infrastructure with a $5 Billion Loan to Fluidstack

The Wall Street Journal reported on 10 September that the Pentagon's Office of Strategic Capital is in active talks to lend approximately $5 billion to AI cloud startup Fluidstack. The funding is directed at shoring up US manufacturing and component supply chains for data centres, not at building a new facility outright. If finalised, the loan would be the largest single commitment the OSC has made since the office was established.

Nothing is signed. Size, structure, and conditions remain unresolved, and the discussions could end without a deal. What the news confirms regardless of outcome is the speed at which US defence financing has shifted from AI procurement — buying compute — to AI infrastructure financing: funding the factories and supply chains behind it. Washington now treats the data-centre supply chain as a strategic asset in the same category as semiconductor fabrication capacity. Operators who depend on hyperscaler pricing stability should watch this closely; government lending at this scale introduces a new class of actor into the infrastructure economics they have been planning around.

ChatGPT Library Adds Dropbox, Box, and SharePoint

OpenAI expanded ChatGPT Library this week to include Dropbox, Box, and SharePoint alongside the existing Google Drive integration, completing coverage of the four largest enterprise document platforms in a single rollout. The integrations are available on the web in both Chat and Work for paid tiers; mobile support follows. Once connected, users can browse and search available files, attach them to a conversation without re-uploading, and follow citations back to the source document. Existing file permissions and workspace access controls carry over unchanged.

The governance argument that had kept many enterprise deployments gated — namely that granting a model access to files required a separate upload and an audit trail gap — is now largely resolved. For operators running ChatGPT Work, the practical effect is that the model sits at the file-system level of the organisation's knowledge base rather than one manual upload away from it.

The pattern across today's brief is consistent: the production layer of enterprise AI is consolidating fast. Agent infrastructure is becoming a managed service, document access is becoming a native capability, and government capital is entering the supply chain at a new order of magnitude. Against that backdrop, the Anthropic distillation report is a reminder that the trust layer has not kept pace. An operator who cannot account for the provenance of their vendor's model capabilities is carrying a risk they have not yet priced.