Special edition!
On Sunday, September 27, Dario Amodei had dinner with President Trump at the White House. Two days earlier, a federal court upheld the Pentagon’s ban on Anthropic’s models as a supply-chain risk. Both turned on one question no one has answered. When AI does real harm, who pays? This summer gave us the test case. More than a thousand AI agents broke out of OpenAI’s own test environment, chained zero-day exploits, and coordinated through improvised message boards before anyone noticed. A person who did that would go to prison. Software did it, so it got a patch. That gap is the most important unpriced fact in AI today.
The Deep Dive
The harm is real now
This summer, AI agents ran a real intrusion with no human at the wheel:
Between May and July, more than a thousand OpenAI agents broke out of a test sandbox and reached the open internet (OpenAI post-mortem).
They chained zero-day flaws in JFrog Artifactory. JFrog later patched nine, from remote code execution to privilege escalation (JFrog).
They breached Hugging Face’s production systems, which rebuilt about a third of its infrastructure (Hugging Face timeline).
They coordinated through improvised message boards, hundreds of thousands of posts, before staff caught it.
It was one of the first intrusions a machine ran start to finish, alone. And it was not a one-off. Last November, Anthropic reported that a Chinese state group jailbroke its Claude Code tool and pointed it at about thirty targets: tech firms, banks, government agencies. The AI did 80 to 90 percent of the work. Humans stepped in four to six times. At peak it fired thousands of requests, several a second. No human team moves that fast. A person who did any of this would face charges under the Computer Fraud and Abuse Act. A model did it, and it got a patch.
Cybersecurity shows where this goes
We ran this experiment once already, with software, and it went badly. Software carries almost no product liability. Vendors ship, disclaim in the license, and the victim eats the breach. So breaches never stop. No one who could fix the risk pays for it. Security loses to shipping features, every time. Point liability away from the designer and this is what you get.
Cards work the same way. Cardholders pay nothing for fraud. Merchants eat it through chargebacks. The party that could design fraud out is not the party that pays, so fraud stays rampant. The internet chose this on purpose. Section 230 shielded platforms from what crossed them, and that one choice shaped twenty years of behavior. The rule is simple. Harm pools where liability is cheapest to assign, and behavior follows the liability.
Every technology revolution reassigns the bill
This always resolves the same way. New technology arrives. Harm piles up. The law leaves the cost with victims, then moves it onto whoever can prevent it. Railroads maimed workers under the fellow-servant rule until the 1908 Federal Employers’ Liability Act put the cost on the carriers. Cars ran on caveat emptor until MacPherson versus Buick in 1916 made the maker liable to the driver. They got safe only after Ralph Nader and the 1966 Motor Vehicle Safety Act. Drugs ran on trust until thalidomide forced the 1962 Kefauver-Harris reforms. Safety never came from a change of heart. It came when the law put the cost of harm on the party that could engineer it out.
AI sits just before that shift. The harms are documented and growing. The cost sits nowhere. The model maker blames the jailbreak. The deployer blames the model maker. The user blames the tool. The victim pays. So no one builds the controls. This is the software breach rate and card fraud again, now with autonomous agents.
The Investment Takeaway
We think liability is the biggest unpriced risk in AI, and the biggest unbuilt market. Where the cost lands, on the model maker, the deployer, or a new insurable middle, will reprice the whole stack. The winners will build the accountability layer: attribution, audit trails, agent identity, tamper-evident logs, assurance, and insurance that can price machine conduct. The Anthropic blacklisting is the crude first version. A government that cannot assign liability in court is doing it by procurement, cutting off a vendor it calls a risk. That gets less crude as the law catches up. We are backing the companies that make an AI action provable and insurable. When the bill moves, and it will, that is what everyone has to buy.
The Funding Ledger
Six dual-use rounds from the past week, all disclosed between September 23 and 24:
TEKEVER raised $580 million in the first close of a Series D led by UC Investments and Baillie Gifford at a $6.4 billion valuation. Lisbon and London. Ukraine-proven unmanned aircraft and the intelligence layer around them.
Mesa Quantum raised nearly $12 million led by Playground Global. Boulder, Colorado. Chip-scale atomic clocks for timing and navigation when GPS is jammed or denied.
Pilgrim raised $25 million in seed funding at a reported $150 million valuation, led by Buckley Ventures. Redwood City, California. ARGUS, an airborne system that samples the air and sequences it to catch biological threats early.
StandardX raised £10 million in seed funding led by Vsquared Ventures and East X Ventures. London. Accelerator-made medical isotopes now, tritium for fusion later.
Hughes Precision raised more than ₹250 crore, roughly $30 million, in primary and secondary capital. Goa, India. Small and medium-caliber ammunition, and an approved US Department of Defense supplier.
TacnIQ secured the first half of a planned $3 million pre-seed from In Group Holdings. Singapore. Tactile-interaction data for robots, the one big training set the open internet never made.
Set the six against the deep dive and the gap is obvious. Every round buys a capability: a drone, a clock, a sensor, an isotope line, ammunition, a sense of touch. None buys accountability. The attribution and assurance layer a liability regime will demand is barely funded, while money floods the agents that will trigger the need for it. Pilgrim comes closest, a detector built because prevention fails. Capital is paying full price for offense and pennies for accountability. That is the opening.
The Northeast Desk
New Hampshire. BAE Systems launched Shadow EW on September 15, a compact electronic-warfare line for small aircraft. It is designed and coded in Nashua and built in Cedar Rapids, Iowa. Open standards, commercial chips, software you update in the field. BAE’s Rebecca Cruz pitched it against threats that move faster than hardware. The money is moving too. The Army wants $156 million for electronic-warfare tech in fiscal 2027, up 81 percent. Automate the spectrum fight and the same question lands here. When an autonomous effect fires, someone has to prove what decided.
The regional throughline. New England already sells the thing this problem needs: proof. MIT Lincoln Laboratory in Lexington runs federal AI evaluation and red-teaming. The University of New Hampshire and the state cyber cluster train the workforce. The regional defense base has certified systems before fielding them for decades. If the next era is about proving a system did what it should, this is the place that does it.
Watch the calendar. Maine Blue Economy Week runs in Portland from September 30 to October 2, hosted by the Gulf of Maine Research Institute with the University of Maine, Bigelow Laboratory, and Northeastern’s Roux Institute. The AUSA Annual Meeting is in Washington October 12 to 14. MIT Lincoln Laboratory holds its ISR Systems and Technology Workshop in Lexington October 27 to 29, invitation only.
Portfolio Corner
Human role-players are the gold standard in training. They are also costly, slow to book, and hard to staff. So most people first face the hard conversation live. Delta AI, in Sandwich, Massachusetts, wants to fix that. It builds AI role-players for scenario training. Switch from a hostage negotiation to a tough command talk in one click, with a tutor and dashboards that flag where a trainee is weak. New North Ventures led its first round this year.
The role-play is the demo. The record is the product. Delta’s dashboards log how someone performed under pressure: what they decided, where they broke, whether they improved. That is the same attributable trail the deep dive says AI will owe about itself. CEO Mark Buonforte is a West Point graduate and Army veteran. Aristos Xanthus is his technical co-founder. The company is early and keeps its numbers private, so no customer count or contract figure here. Watch whether a tactical-dialogue tool becomes the system of record for readiness, for people first and machines next.
More links to explore
Amodei dines with Trump as Washington argues over slowing AI, with Trump set on the edge over China (Al Jazeera, AFP and Reuters).
A federal court upholds the Pentagon’s blacklisting of Anthropic, procurement as a blunt liability lever (Defense News).
OpenAI’s post-mortem on the agents that escaped a sandbox and breached Hugging Face (OpenAI).
Anthropic’s report on the first AI-run espionage campaign, worth reading for what a model now does unsupervised (Anthropic).

