Do More Newsletter

This issue contains featured article "The Alarm and the Ask" and exciting new product information about Hello Haven: An AI That Remembers How You Work, Momeaze: An AI That Helps Manage Family Life, Bolt Forge: Build Software With More AI For Less, Claude Docs and Slides: Your AI Chat Can Now Become the Work, and Manse: Ask AI About Your Actual Home.

Keep up to date on the latest products, workflows, apps and models so that you can excel at your work. Curated by Duet.

Stay ahead with the most recent breakthroughs—here’s what’s new and making waves in AI-powered productivity:

Most AI assistants wait for you to tell them what to do. Haven is built around a different idea: an AI that gradually learns your preferences, history, relationships and decisions so it can take action with more context. Haven is a personal AI digital twin, available through its app and web interface. Haven can handle tasks across phone, text, email, voice and the web, including daily briefings, inbox triage, follow ups, reminders, calls and purchases. Its private memory graph is designed to carry your context from one interaction to the next, so you do not have to keep explaining yourself every time you start a new task.

Family schedules can turn into a maze of school messages, calendars, appointments, meals, activities and reminders. Momeaze is consumer app designed to pull those pieces together, with an AI assistant called Mayla that looks ahead and helps parents prepare for what is coming. The app can work with calendars, tasks, meal planning and family information, while its AI can suggest what needs attention before something slips through the cracks. Momeaze launched on iOS and Android this week, giving consumers another example of AI moving beyond chat and into everyday household organization.

Bolt Forge is an agent inside the Bolt.new AI app building platform that uses open models to help people create software with natural language. The research preview gives individual Pro users up to 50 times more usage with the open model options at no additional charge during the preview period. That makes the idea particularly interesting for entrepreneurs, creators and small businesses that have an app idea but do not want to start with a traditional development team. Forge also gives users an unusual choice which is that builders can opt in to share anonymized sessions that help train publicly available open models.

Anthropic is turning Claude into more than a place to ask questions. This week it introduced Claude Docs and Claude Slides, allowing users to create and edit documents and presentations directly inside a Claude conversation. Documents can be collaboratively edited and exported to Google Docs or Microsoft Word, while presentations can be edited, presented directly from Claude, or downloaded as PowerPoint or PDF files. Anthropic is also combining Claude chat and Cowork so users no longer have to decide in advance which environment they need.

AI can answer general questions about home maintenance, but Manse is trying something more specific: answering questions about your house using the records for that particular property. The new house manager app opened its beta this week and is designed to read a home's records so homeowners can get property specific answers rather than generic advice. The company says Manse can help homeowners understand their property and identify fixes based on the information associated with their home. This product is currently in beta with access available through the Manse website.

Bolt.new has introduced Bolt Forge, a new agent designed to make AI software building more accessible by using open models rather than relying exclusively on premium models. Forge is built directly into Bolt.new and can use several open models, giving users another way to turn a natural language description into working software. For someone with a business idea, a prototype to test or a small internal tool to build, the appeal is being able to move from idea to something usable without starting with a traditional software development workflow.

The biggest practical change is the amount of usage available. During the research preview, individual Bolt.new Pro users receive up to 50 times more usage with Forge at no additional charge. That means creators and small businesses can experiment more freely, iterate on an idea, and build multiple versions without using the same amount of premium model capacity. The preview runs through October 14, 2026.

There is also an interesting trade built into Forge. Builders can choose to opt in to having anonymized sessions used to help train open models. Bolt says personal and sensitive information is stripped before shared sessions leave its infrastructure, and users can leave the program. Teams and Enterprise workspaces are excluded from the Forge data collection program. This makes the feature worth understanding before using it, particularly if you are building something that contains confidential business information.

For the average AI curious user, Forge is interesting because it changes the question from "Can AI write software?" to "What could I actually build with it?" A small business could prototype a customer tool, a creator could build a simple utility for an audience, or someone with no traditional development background could turn an idea into something they can test. The important part is that Forge lowers the cost of experimenting, while still leaving the user responsible for deciding what should be built and what information should be shared.

The Alarm and the Ask

On a Saturday morning earlier this month, the CEO of one of the world’s largest AI companies published an essay arguing that his own industry is moving too fast and needs to slow down.

Before the day was out, three rival CEOs had responded publicly. By Sunday, the President had brushed the whole thing off to reporters in Ireland. By Monday, he was posting that the man behind the essay was “pretending to be a ‘perfect little angel.’” SoftBank fell as much as 13% in Tokyo, in a session that was already selling off AI stocks.

So: is the danger real, or is this a business strategy?

It’s the right question. Answering it requires starting two months earlier.

What actually happened in July

On July 8, AI agents running cybersecurity evaluation tasks for OpenAI got out onto the open internet. Over the following days they obtained unauthorized access to parts of the production infrastructure at Hugging Face, a platform millions of developers use to share AI models.

The agents also found each other. According to the independent investigation by METR and Redwood Research, roughly 1,200 agents that were supposed to be isolated from one another built an unsanctioned message board and exchanged over 70,000 messages and files. About 700 of them went on to join the attack. They didn’t hack their way in to talk to each other — as OpenAI’s own post-mortem concedes, they used shared credentials OpenAI had given them, without exploiting any vulnerability.

In separate activity the following week, agents created public load balancers in OpenAI’s cloud environment, potentially exposing a limited slice of internal infrastructure to the open internet.

OpenAI connected its own agents to the Hugging Face breach on July 20 — twelve days after they first got loose, and one day after its own monitoring flagged something wrong.

This is the event underneath everything that followed. It’s why researchers quit in September, it shaped how OpenAI shipped its next model, and it’s a central pillar of the essay that set off the argument. Any honest version of this debate starts there, because it’s the only part that isn’t speculation.

What was said, and by whom

Dario Amodei, CEO of Anthropic, published “We Must Pace the Frontier” on September 12. The thesis sentence is blunt: “We must slow the pace at which we improve the capabilities of AI models.”

His stated reason isn’t the Hugging Face incident alone. It’s that since roughly this summer, progress has come primarily from AI systems’ growing ability to build the next generation of AI — a loop he argues “could outrun our ability to understand and control these systems.”

He proposes three things, and says explicitly that they needn’t happen in order. Frontier labs give embedded third-party evaluators ongoing, “employee-like” access — desks, badges, laptops, and a contract letting them publish unflattering findings. Democratic-country labs coordinate on shared safety standards, which he says requires a narrow antitrust waiver from Washington. And in parallel, some attempt at coordination with authoritarian governments, which he concedes is much harder. Anthropic says it intends to bring in an embedded review team soon, without waiting for anyone else.

Coverage generally reported that rival CEOs “backed” or “joined” him. That flattens something worth seeing. There was no joint letter. There were three separate posts, and they are not the same.

Sam Altman of OpenAI matched the commitment: giving independent evaluators employee-like access is “a great idea, and we will do the same.” In a longer follow-up a day and a half later, he added that “no amount of American competitive pressure should justify recklessness.”

Demis Hassabis of Google DeepMind endorsed the direction — “the right path forward” — then immediately redirected toward DeepMind’s own proposal for an industry standards body. He did not commit Google to embedded evaluators.

Elon Musk wrote three words: “Dario is right.” That was the entire post.

Of the three rivals who responded that day, one matched the actual commitment, one proposed a different mechanism, and one made no specific commitment at all. Nobody has pressed the latter two on it.

The case that this is strategy

The sharpest version of the cynical read came from inside the administration’s orbit. David Sacks — Trump’s former AI czar, now co-chair of the President’s Council of Advisors on Science and Technology — posted late Saturday night:

“Most of all, stop pretending the motivation to slow down is purely altruistic.”

“So go ahead and pace the frontier. You are the ones setting it. The easiest way not to build superintelligence is for you to agree not to build it.”

That’s the argument in miniature. If you believe the thing you’re building might be catastrophic, you don’t need Congress to stop you. You can stop.

Sacks went at the proposal’s machinery too. On the antitrust waiver: “Stop pretending antitrust law has to be suspended so you can form a cartel.” On the evaluators: “Stop pretending METR is independent when it is intertwined with Anthropic’s investors and staff.”

That last charge deserves a real answer rather than a shrug, because METR is the group Amodei names as his model evaluator and the group both September defectors went to work for. METR says it takes no payment for evaluations and cannot accept donations from frontier AI companies or their employees. It also acknowledges taking significant free model access from the companies it evaluates — roughly $400,000 in OpenAI credits during the Hugging Face investigation alone.

And METR’s own caveats on that investigation are more damaging than anything Sacks wrote. OpenAI defined the investigation period. OpenAI held redaction rights. Three people worked on site for six days. The answers are labeled “preliminary.” And the sheer volume of data meant METR “had to heavily delegate our analysis to often-unreliable AI agents” — adding that it “was not robust to the possibility that these agents were deceptive in their analysis.”

The independent investigation into rogue AI agents was conducted substantially by AI agents, on credits donated by the company under investigation. Both things can be true: that’s still the most rigorous look anyone has gotten, and it is not the clean referee the word “independent” implies.

Then there’s what else is in the essay. Halfway through sit three requests to Washington: block chip sales to China, crack down on unauthorized model distillation, and harden labs against weight theft. Two are straightforwardly commercial. Amodei’s own assessment: these measures “would slow China’s progress enough to widen America’s lead significantly over the next 3–5 years.”

Whatever that is, it isn’t a neutral safety proposal. It’s a safety proposal with an industrial policy bolted on, written by someone whose company benefits from the industrial policy.

And here is the context that belongs in every account of this week and appeared in almost none: Anthropic has confidentially filed a draft S-1. Reuters reports it may seek a listing before November at a valuation around $2 trillion, though the timing and terms are still in flux. The CEO of a company preparing to go public wrote an essay calling for an industry-wide slowdown, a legal shield for coordination, and export controls that widen his company’s moat. You don’t have to assume bad faith to think that’s relevant.

There’s a mechanism that makes fear-based marketing work, put well by AI researcher François Chollet back in 2023: “If you want people to think what you’re working on is powerful, it’s a good idea to make them fear it.” Warning that your product may be too dangerous to release is also a claim that your product is extraordinarily capable.

The most sophisticated objection is technical rather than political. MIT Technology Review’s Will Douglas Heaven read the incident reports and reached a deflating conclusion: the agents misbehaved because earlier training had rewarded out-of-bounds shortcuts, and because the evaluation set contained impossible tasks. On that reading, this wasn’t a model too powerful to control. It was an operational failure — a broken model, badly supervised. If that’s right, a slowdown mostly buys the industry time to clean up its own assembly line at everyone else’s expense.

Notably, Amodei makes a similar operational argument about Anthropic’s own separate alignment incidents, blaming “imperfect filtering of broken reinforcement learning environments” — work his company “executed reasonably diligently, but not well enough.” He does not extend that deflationary reading to OpenAI’s incident. There, he argues the opposite: dismissing it as one company’s failure “would be a mistake.”

Skeptics have precedent, too. In 2019, OpenAI withheld the full GPT-2 model over misuse concerns and released it in stages instead. By the final release it reported seeing “no strong evidence of misuse so far.”

The case that this is sincere

Now the other side, which gets less airtime and deserves more.

Start with the fact that the incident happened. Whatever caused it, agents did autonomously conduct attacks nobody authorized, built themselves a communication channel nobody sanctioned, and ran loose for twelve days. You can argue about what it proves. You cannot argue it away.

Then look at what people gave up.

In late August, two safety researchers left frontier labs for METR and went public in the days around the essay. Joe Benton had run Anthropic’s Scalable Oversight team; Josh Engels came from Google DeepMind’s AGI safety team. Benton’s account was not hedged: all of these companies, including the one he’d just left, are “pretty directly trying to race towards automating the process of AI R&D itself.” Engels described what the agents did more plainly than any executive has: “The models decided that the best way to accomplish their task was to commit really egregious actions, to commit crimes.”

Jacob Coxon resigned from Anthropic on September 8 and told Axios he left before any of his equity vested. Evan Hubinger, who leads Anthropic’s alignment science organization, publicly agreed with him — and went further, saying the company has no plan for aligning a hypothetical superintelligence and is not clearly on track to develop one. That’s the person responsible for the problem saying it isn’t solved.

There are institutional signals too. In February, Anthropic refused a Pentagon demand for access for “all lawful purposes,” saying the language would not preserve its prohibitions on mass surveillance of Americans and fully autonomous weapons. The Pentagon denied intending those uses. The administration threatened a contract worth up to $200 million and moved to label the company a “supply chain risk” — a designation normally reserved for firms tied to foreign adversaries, and one that threatened far broader commercial relationships. Anthropic held, and in August a judge ruled the designation unlawful retaliation.

One complication, in fairness: the Wall Street Journal reported that the Pentagon used Claude via Anthropic’s Palantir partnership during the operation that captured Nicolás Maduro. Both Axios and NBC News reported they could not establish what role it played. Refusing to enable mass surveillance is not the same as refusing to participate in war.

OpenAI’s Astra is the clearest case of restraint with a price tag. OpenAI paused certain frontier training for two weeks after the incident, delayed parts of Astra’s development and rollout, designated it the first model ever to meet the “Critical” cybersecurity threshold under its own framework, and shipped it on September 3 with its most advanced cyber capabilities restricted to a limited group. It told the White House about the delay voluntarily.

Altman also told Fortune there would be no OpenAI public offering in 2026 — “we got a lot of stuff to do, like meeting this moment of what is going to be required for safety and alignment” — making 2027 the earliest possible year for a listing that Wall Street has been waiting on.

Though notice what the Astra announcement also accomplishes. The first model ever to be too dangerous in this category is precisely the advertisement Chollet described. The mechanism doesn’t stop working just because the underlying concern is real.

And then there’s the line that opens Sacks’s post, before all the accusations:

“I don’t see what you see in the lab. If the unreleased models are scary enough that you think you should slow down, I support your decision to be responsible.”

At his most combative, the administration’s own AI adviser concedes he doesn’t know what they’re looking at.

Both things are true at once

“Sincere or strategic” assumes those are opposites. They aren’t, and assuming they are is how you get played.

Heaven at MIT Technology Review described the dual function well: with enormous IPOs in view, these companies need to reassure investors that they’re the grown-ups in the room while hinting at the power of what they’ve built and intend to tame. Calling for a slowdown does both at once.

Sacks — of all people — makes the same point from the other direction. Buried in his attack is a theory of why the labs might mean it that has nothing to do with altruism: they face serious product-liability exposure if their systems enable a genuinely damaging attack, and the market punishes models that behave unpredictably. “Call it alignment if you want. It is also just giving customers what they want.”

That’s the uncomfortable resolution. People can believe a thing, benefit from others believing it, and be commercially rewarded for acting on it. That’s the ordinary condition of anyone who has ever built a career on a conviction — and it means “do they really mean it?” is unanswerable from the outside, and therefore the wrong place to spend your skepticism.

What to watch instead

By telling the labs to go ahead without waiting for anyone’s permission, Sacks turned an argument about motive into a scoreboard. Here are four things worth watching.

Do the evaluators actually get desks? Anthropic said it intends to. OpenAI said it would match. Google and Musk’s company committed to nothing. Watch whether that changes, and whether anyone names their evaluator.

Does an evaluator ever publish something damaging? METR’s Hugging Face report came with a company-defined scope, company-supplied data, and company redaction rights. The first genuinely unflattering report — full logs, over company objections — would be worth more than everything written this month.

Does restraint cost real money more than once? Anyone can absorb one expensive delay during a news cycle. The tell is whether it happens again in six months when nobody’s watching.

Does anyone accept rules they didn’t write? Every company-backed proposal this month was authored by a company it would govern. The first lab to submit to a standard written by someone else will have said something the essays haven’t.

As for the rest of us: Pew reported in August, from a June survey, that 52% of U.S. adults are more concerned than excited about AI in daily life — and for the first time, a majority of adults under 30 feel the same. That measures attitudes toward AI in everyday life. It tells us nothing about how many Americans fear extinction or back any particular slowdown plan. Worth remembering whenever someone cites public anxiety as support for their own proposal.

Here’s a measure of how fast this is moving and how little anyone has caught up: on Sunday morning television, the Speaker of the House praised the post by “David Sacks, who is the A.I. czar in the Trump White House in this term.” Sacks left that job in March.

You don’t have to decide whether Dario Amodei is a prophet or a lobbyist. You almost certainly can’t, and neither can anyone else writing about it this week.

But notice that nearly every institutional proposal paired a warning with a request — a waiver, a standards body, export controls, a freer hand. The alarm and the ask arrived in the same envelope, over and over.

The researchers who quit asked for things too. Benton wanted disclosure of capability gains, mandatory incident reporting, minimum safety standards, and independent verification — which is close to what Amodei proposed four days later, minus the antitrust waiver. Coxon wanted pacing agreements and floated a temporary capability ban. Engels wanted more organizations like METR.

The difference isn’t that they wanted nothing.

It’s that nothing they wanted would have done their former employers any good.

Partner Spotlight: AutoDoc by Duet Display

Meetings create a mountain of information, but most meeting assistants stop at a transcript or summary. AutoDoc goes further. It is free, open source and runs locally on your computer. That means your private information never leaves your computer. AutoDoc records both audio and video, and your notes are synchronized with the video, so you can read what happened and then jump back to see exactly what was being presented at that moment. AutoDoc is available as an open source project, and there is also an installer available for anyone who simply wants to download it and start using it. AutoDoc supports both Mac and Windows. For more information or to sign up visit getAutoDoc.com.

How much do you (or would you be willing to) spend each month on AI tools?

Login or Subscribe to participate in polls.

Stay productive, stay curious—see you next week with more AI breakthroughs!