{"id":191,"date":"2026-09-11T10:12:27","date_gmt":"2026-09-11T10:12:27","guid":{"rendered":"https:\/\/scoy.ai\/guides\/ai-news-roundup-september-11\/"},"modified":"2026-09-11T10:13:53","modified_gmt":"2026-09-11T10:13:53","slug":"ai-news-roundup-september-11","status":"publish","type":"post","link":"https:\/\/scoy.ai\/guides\/ai-news-roundup-september-11\/","title":{"rendered":"AI News Roundup for September 11: DeepSeek Got Named in Anthropic&#8217;s Report and Undercut It the Same Day"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Two of Thursday&#8217;s biggest stories were the same story, and almost nobody covered them that way. Anthropic published a threat report naming the Chinese labs it says copied Claude at industrial scale, and one of those labs shipped a model that beats the originals on agentic work at roughly a tenth of the price, on the same day.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I run my whole content operation on these models, so I read this as a sourcing question rather than a geopolitics question. Here is the operator&#8217;s read on five things, starting with the one that changes your bill on Monday.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">DeepSeek Shipped V4.1 Flash, and It Reroutes Your Pro Calls Monday<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">DeepSeek released V4.1 Flash on September 10. It is a sparse mixture-of-experts model with a 552B-parameter backbone that activates roughly 8B parameters on input and 16B on output, ships MIT-licensed open weights, and takes a one-million-token context window.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The number that matters is buried in <a href=\"https:\/\/api-docs.deepseek.com\/quick_start\/pricing\" target=\"_blank\" rel=\"noopener\">DeepSeek&#8217;s own pricing page<\/a>, not the launch post. Cache-miss input runs $0.15 per million tokens off-peak and $0.30 at peak, output runs $0.60 off-peak and $1.20 at peak, and a cache hit costs $0.003 off-peak. Off-peak is exactly half of peak.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then there is the line nobody put in a headline. DeepSeek&#8217;s pricing documentation states that from September 14, requests to <code>deepseek-v4-pro<\/code> will all be routed to V4.1 Flash and billed at the V4.1 Flash price. That is Monday. If you have a production path pinned to <code>deepseek-v4-pro<\/code>, your bill falls and your model changes underneath you, and you did not ask for either. A price cut you did not request is still a model swap you did not test. Go read your own configs today, not Monday.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One more thing that is worth the two minutes of arithmetic. DeepSeek defines peak hours as 01:00 to 04:00 and 06:00 to 10:00 UTC, Monday through Friday, with everything else off-peak. Map that onto a US working day and the entire American business day sits in the off-peak window. If you are operating from the States, you are already paying the half-price rate during the hours you actually run work, and that is not something DeepSeek is advertising to you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On the benchmarks, treat the scores as claims rather than findings. <a href=\"https:\/\/huggingface.co\/deepseek-ai\/DeepSeek-V4.1-Flash\" target=\"_blank\" rel=\"noopener\">DeepSeek&#8217;s model card<\/a> reports 74.2 on DeepSWE v1.1, 90.6 on Terminal-Bench 2.1, 54.8 on AutomationBench, 31.8 on Agent&#8217;s Last Exam and 88.1 on CyberGym. The card also says the code-agent evaluations ran in the Minimal mode of DeepSeek Harness. They scored their own model inside their own scaffold, which is the same pattern I wrote about when <a href=\"https:\/\/scoy.ai\/guides\/ai-news-roundup-2026-08-24\/\">the harness scored 100 and not the model<\/a>. The weights are MIT licensed, so you can settle it yourself on your own eval set. Do that before you move anything real.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verdict: breaks-your-stack.<\/strong> Cheapest credible agentic model of the week, with a silent substitution landing in three days.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Anthropic Says Roughly 200 Million Exchanges Walked Out the Door<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic published its <a href=\"https:\/\/www.anthropic.com\/news\" target=\"_blank\" rel=\"noopener\">threat intelligence report<\/a> on Thursday, covering misuse it disrupted between December 2025 and August 2026. <a href=\"https:\/\/techcrunch.com\/2026\/09\/10\/anthropic-details-distillation-campaigns-from-alibaba-moonshot-ai-and-deepseek\/\" target=\"_blank\" rel=\"noopener\">TechCrunch&#8217;s writeup<\/a> puts the headline figure at nearly 200 million exchanges linked to distillation attacks across five separate campaigns.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Alibaba campaign is the largest Anthropic says it has ever observed. Anthropic attributed more than 151 million exchanges to it between May and July 2026, peaking at nearly three million exchanges per day across more than 3,500 accounts it describes as fraudulent, all running a single fixed prompt designed to pull out the chain of thought. As <a href=\"https:\/\/www.cnbc.com\/2026\/09\/11\/chinese-ai-labs-moonshot-deepseek-alibaba-anthropic.html\" target=\"_blank\" rel=\"noopener\">CNBC reported<\/a>, operators affiliated with Alibaba used those Claude outputs to help train the Qwen models. Anthropic also logged more than 12 million distillation attacks it attributes to DeepSeek across 14 days in July 2026.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here is the detail that should stop you, and it got almost no coverage. Anthropic says Moonshot routed some Kimi user requests to Claude, then trained on the resulting exchanges. Read that as an operator instead of as a reader.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>If you shipped a product on Kimi, some of your users&#8217; prompts were forwarded to Anthropic, and you never told those users because nobody told you.<\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">That is a data-residency and disclosure problem sitting inside a vendor you chose for price. It is not a hypothetical about model provenance. It is a question about where your customers&#8217; text actually went, and your terms of service probably answer it wrong.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I do not think the licensing argument is the interesting one here. Whether distillation is theft will be litigated for years and none of us get a vote. The thing you control is vendor diligence, and the standard just moved: &#8220;it is cheap and the benchmarks look good&#8221; is no longer an adequate answer for a model you route customer data through. Ask where the traffic terminates and get it in writing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verdict: matters.<\/strong> Not for the geopolitics. For your subprocessor list.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">OpenAI Put the Codex Harness Behind One API Call<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">OpenAI opened <a href=\"https:\/\/openai.com\/index\/introducing-the-agents-api\/\" target=\"_blank\" rel=\"noopener\">the Agents API<\/a> in public beta to all developers on September 10, exposing the same managed harness that runs Codex. OpenAI handles orchestration, long-running sessions and context management, which is precisely the pile of glue code most teams spent this year writing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is no additional fee for the Agents API itself. You pay for the tokens and tools your agents use, and OpenAI-hosted sandboxes bill separately at standard container rates. If you would rather keep execution on your own infrastructure, OpenAI lists integrations with Blaxel AI, Cloudflare Dev, Daytona, DigitalOcean, E2B, Modal, Oracle Cloud, Runloop AI and Vercel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">My read: the orchestration layer stopped being a differentiator this week, and the honest reaction for most teams is relief rather than grief. If your product&#8217;s advantage was session management and context compaction, that advantage is now a checkbox on someone else&#8217;s platform. What replaces it as your cost center is the sandbox, because container time is a separate meter from tokens and it runs while your agent thinks. Watch that line before you celebrate the free orchestration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verdict: matters.<\/strong> Delete code, then go instrument your container spend.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Amazon Is Selling ChatGPT Ads, and You Get Aggregates<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/advertising.amazon.com\/library\/news\/amazon-ads-chat-gpt-advertising-integration\" target=\"_blank\" rel=\"noopener\">Amazon Ads announced<\/a> on September 10 that select US advertisers are piloting ChatGPT Ads, with Delta Vacations named among the first brands testing it. <a href=\"https:\/\/searchengineland.com\/amazon-pilots-chatgpt-ads-through-its-dsp-488026\" target=\"_blank\" rel=\"noopener\">Search Engine Land&#8217;s reporting<\/a> fills in the mechanics Amazon left out: inventory is bought through Amazon DSP as a managed service on either a cost-per-click or CPM basis, product feed ads generate creative automatically from your catalog, and OpenAI keeps control of how and where ads appear inside ChatGPT.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The reported metrics are impressions, clicks, cost per result, CPM and CPC, aggregated. So you can see that ChatGPT traffic converted. You cannot see which conversation did it, what the user was actually asking, or what the model said next to your ad.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I will say the unpopular part plainly. This is a media placement wearing an AI costume, and at aggregate-only reporting it is not yet a performance channel. The entire promise of advertising inside an assistant is intent you cannot get anywhere else, and intent data is the one thing this pilot does not hand you. Two managed layers now sit between your spend and your attribution. If you are running real budget, treat it as a brand test with a hard cap and no expectation of a clean CAC number.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verdict: marketing.<\/strong> Genuinely new inventory, genuinely unmeasurable so far.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">California&#8217;s AI Audit Laws Land in 2029<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.gov.ca.gov\/2026\/09\/09\/governor-newsom-signs-first-in-the-nation-ai-safeguards-to-protect-californians-calls-on-the-federal-government-to-do-its-part\/\" target=\"_blank\" rel=\"noopener\">Governor Newsom signed<\/a> SB 813 and AB 1405 on September 9. AB 1405 directs the California Government Operations Agency to stand up an AI Auditor Registry by January 1, 2029, and bars unregistered parties from conducting covered AI audits from that date. SB 813 creates the California Artificial Intelligence Standards and Safety Commission, whose job is a set of voluntary safety standards.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OpenAI endorsed the framework while saying it would prefer requirements set federally. <a href=\"https:\/\/gizmodo.com\/newsom-signs-ai-industry-approved-ai-regulation-bills-into-law-in-california-2000809702\" target=\"_blank\" rel=\"noopener\">Gizmodo&#8217;s read<\/a> was blunter, filing the pair as industry-approved regulation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That framing is correct and it is the position I would take. A voluntary standards body plus a compliance deadline more than three years out is the regulation you write when you want the headline and not the constraint. For anyone shipping AI products this quarter, nothing in these bills changes your work. Calendar the 2029 date if you sell audits. Otherwise this is an announcement, not an obligation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verdict: marketing.<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What I Am Watching<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The pairing at the top is the real story of the week: the labs accused of copying the frontier are shipping against it at a tenth of the price, which means the argument about provenance and the argument about your infrastructure budget are now the same argument. Check your <code>deepseek-v4-pro<\/code> references before Monday, ask every model vendor where your users&#8217; text physically terminates, and do not confuse a signing ceremony with a rule.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Anthropic named the labs it says copied Claude, and DeepSeek undercut it the same day. Plus a silent model swap on Monday, and OpenAI&#8217;s Agents API.<\/p>\n","protected":false},"author":1,"featured_media":190,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"class_list":["post-191","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-news"],"_links":{"self":[{"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/posts\/191","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/comments?post=191"}],"version-history":[{"count":1,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/posts\/191\/revisions"}],"predecessor-version":[{"id":192,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/posts\/191\/revisions\/192"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/media\/190"}],"wp:attachment":[{"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/media?parent=191"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/categories?post=191"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/scoy.ai\/guides\/wp-json\/wp\/v2\/tags?post=191"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}