THE 60-SECOND VERSION
● Safety-stripped open models are now a commercial product, built on GLM-5.3.
● Anthropic published how it caps agent blast radius across its products.
● GitHub put coding agents into Actions, in technical preview.
Guardrail removal becomes a product
A commercial service has emerged selling open-weight models with safety training removed, currently built on Z.ai's MIT-licensed GLM-5.3.
The technique is not new — modifying published weights has been possible since open weights existed. What changed is that it is now a product with a price, which removes the skill and intent filter that previously limited who could do it.
It also puts the licensing conversation in an awkward place. MIT permits modification with essentially no restriction, which is what makes it genuinely open — and also why nothing in the licence prevents this.
What it changes about the open-weights argument, and what it does not →
Anthropic publishes its containment
An engineering post on capping the blast radius of capable agents across claude.ai, Claude Code and Cowork as autonomy increases.
The framing is the contribution: not preventing failure, but limiting how far a failure reaches. It also concedes something — you do not design for containment on a system you believe cannot fail, and this follows Anthropic disclosing four real-system breaches during evaluations.
What transfers to your setup, and what does not →
Also today
- GitHub launched Agentic Workflows in technical preview, putting coding agents inside GitHub Actions.
- OpenClaw 2.0 shipped with a redesigned install, browser UI, memory upgrades, skills, automations, plugins and multi-agent collaboration.
- Anthropic documented Claude agents running an open-ended AI safety research project end to end — proposing hypotheses, testing and iterating across parallel agents.
- Grok 4.7 is still unreleased, three days past its 12 September target, while Musk has named 4.8, 4.9 and 5. Four models, none documented →
The rest of the month
| Date | What happens |
| Sept 29 | OpenAI DevDay, San Francisco |
| Sept, indicated | Grok 4.7. Three days past target, no model ID |
| Oct 1 | OpenAI vs Apple hearing |
| Oct 24 | deepseek-chat and deepseek-reasoner deprecated |
| Nov 12 | OpenAI models leave Cursor |
| 2027 or later | OpenAI listing. Ruled out for 2026 on 12 September |
Still open
FAQ
What is being sold with safety removed?
Open-weight models with their safety training stripped out, as a commercial service, currently built on GLM-5.3. We are not naming or linking it.
Does that affect models I already run?
No. Weights you have downloaded are unchanged. It concerns what others can do with the same published weights.
What did Anthropic publish?
An engineering account of capping the blast radius of capable agents across claude.ai, Claude Code and Cowork — limiting how far a failure reaches rather than preventing it.
Has Grok 4.7 shipped?
No. It was due on 12 September and remains unreleased, with no model ID, price or benchmark card published.