An AI Lab Just Quit Big Tech’s Lobby Over Three Bills on Chips

An AI company has walked out of Washington’s biggest tech trade group over three
chip export bills. Anthropic is ending its membership of the Information Technology
Industry Council, Axios reported on 8 September 2026. ITI had written to the Senate and House Armed Services
Committees urging lawmakers to strip the AI OVERWATCH Act, the Chip Security Act and the MATCH Act from this
year’s defence policy bill. Anthropic supports all three.

What the three chip export bills would do

Each measure attacks a different gap in the current export-control regime.

The AI OVERWATCH Act would require the Commerce Department to notify Congress before approving export
licences for sensitive dual-use chips destined for adversarial nations, and to allow a review period first.
That review window was shortened from two years to 18 months. ITI described 18 months as “an eternity”.

The Chip Security Act would require companies to track their AI chips, aimed at countering smuggling of
US technology. The MATCH Act would press American allies to restrict sales of chipmaking equipment to China,
slowing the growth of its domestic industry.

All three cleared the House Foreign Affairs Committee with substantial bipartisan support. They sit in
the Senate National Defense Authorization Act managers’ package, following technical assistance from the
White House.

An AI processor die, the technology behind the chip export bills split
An AI processor die. Tracking requirements in the Chip Security Act would follow hardware like this after export.

Why Anthropic broke with the group over the chip export bills

ITI’s letter argued the measures would damage American dominance in global markets. Its membership
includes Google, OpenAI and Nvidia — companies with large commercial stakes in international chip and model
sales.

An ITI spokesperson confirmed the departure, describing a “broad consensus position” among members that
the three bills should not advance in the NDAA. The spokesperson said the membership is aligned that the
bills undermine the American tech stack. Both sides here are stating their own case, and each has a
commercial interest in the outcome.

Anthropic’s position runs the other way. Chief executive Dario Amodei has argued publicly for tighter
restrictions on advanced chip exports to China. Supporters of the bills say they give existing controls the
durability they currently lack, since administrative rules can be rewritten by the next administration.

A pattern of breaking from the industry line

This is not the company’s first split from its peers. Anthropic has diverged from OpenAI and Google on
state AI safety legislation. It was also the only major lab not to directly sign a July 2026 letter
supporting open-weight models.

Trade associations work by aggregating members into a single position. That works while members share
interests. It breaks when one member’s strategy depends on rules the others are lobbying against.

The politics do not split cleanly along party lines either. Conservative groups including Heritage Action
and American Compass back the bills, alongside bipartisan congressional support. We covered the broader
safety argument inside the industry in our report on
the AI development slowdown
its own builders are asking for
, and the competitive backdrop in
China’s intelligent
computing plan
.

What the fight means outside Washington

For chipmakers, the Chip Security Act’s tracking requirement is the operational question. Following
hardware after sale means new record-keeping obligations across distributors and resellers.

For allied governments, the MATCH Act is the sensitive one. It asks other countries to restrict their own
equipment exports, which raises sovereignty objections in the Netherlands, Japan and South Korea. Our report
on the Nvidia-Groq antitrust
probe
covers the regulatory pressure building on the same companies from a different direction.

For buyers outside the United States, more licensing steps usually mean longer lead times, even where a
licence is eventually granted.

The NDAA clock now running

The Senate returned from summer recess on 14 September with the NDAA awaiting floor action. That is where
the three measures live or die.

Three signals will show which way it goes. Whether the bills survive the managers’ package intact. Whether
the 18-month review period gets stretched or trimmed in negotiation. And whether other ITI members follow
Anthropic out, which would say more about the association’s future than about the bills.

Questions about the split

Which three bills are involved?

The AI OVERWATCH Act, the Chip Security Act and the MATCH Act, all attached to this year’s National Defense Authorization Act.

Why did Anthropic leave ITI?

ITI wrote to congressional committees urging that the three bills be stripped from the defence bill. Anthropic supports them.

What does the Chip Security Act require?

It would require companies to track their AI chips, aimed at countering smuggling of US technology.

What is the MATCH Act?

A measure pushing US allies to restrict sales of chipmaking equipment to China, to slow its domestic chip industry.

Who else belongs to ITI?

Members include Google, OpenAI and Nvidia. An ITI spokesperson described a broad consensus among members against the three bills.

When will this be decided?

The Senate returned on 14 September with the NDAA awaiting floor action, so the outcome turns on that legislative process.

Reporting used

China Intelligent Computing Plan Targets 9,800 EFLOPS by 2030

China’s Ministry of Industry and Information Technology has published a five-year blueprint that puts a number on the country’s AI ambitions. The China intelligent computing plan, set out in the 15th Five-Year Plan for the information and communications industry released on 7 September 2026, targets 9,800 exaflops of intelligent computing capacity by 2030 — roughly six times the 1,590 exaflops baseline it cites for 2025 — supported by 3.8 trillion yuan of cumulative information infrastructure investment over the period.

Reading the target honestly

These are the Chinese government’s own targets, published by the ministry that will be judged against them, and Chinese five-year plans have a mixed record of delivery. They are still worth reading, because they reveal what the state has decided to spend on and how it defines success.

Two features stand out. First, the metric is compute capacity rather than model capability — the plan commits to building the substrate, not to producing a particular system. Second, the scale of the increase is front-loaded on infrastructure: reporting on the plan pairs the 9,800 exaflops figure with the 3.8 trillion yuan investment envelope, which is on the order of $530bn at recent exchange rates.

A note on units, because the figures get quoted loosely. Intelligent computing capacity as Chinese planners define it is measured at lower numerical precision than the FP64 benchmarks used for traditional supercomputer rankings. It is not directly comparable to the top of the TOP500 list, and anyone treating the two as equivalent is comparing different things.

The constraint the plan is built around

US export controls have, since 2022, progressively restricted Chinese access to the highest-performing AI accelerators and, increasingly, to the equipment used to make them. A national compute plan drafted in 2026 therefore cannot assume access to Nvidia’s leading parts, or AMD’s, or Intel’s.

The plan is explicit about building on domestic supply. That has a practical consequence that is easy to miss: hitting a capacity target with less capable individual chips means using far more of them, which raises the bill for power, cooling, floor space and interconnect. Reporting by DigiTimes points to ambitions around very large clusters — in the range of 100,000 accelerator cards — which is consistent with that arithmetic. Energy, not silicon, becomes the binding constraint at that scale.

It also means the plan is a demand signal to China’s domestic chipmakers, foundries and equipment vendors as much as it is a compute target. Guaranteed state-backed demand is how you finance a supply chain that cannot yet compete on unit economics.

The software half of the strategy

Alongside the infrastructure plan, the ministry issued an implementation plan for an “Artificial Intelligence Plus Software” action, reported in the days that followed. Its stated aims include optimising intelligent programming toolchains, pushing enterprises toward technical transformation measured on code quality and R&D productivity, and embedding automated security testing across the software development lifecycle — with an ambition to take Chinese professional software to world markets by 2030.

The through-line is import substitution applied one layer up the stack. Compute is the expensive part, but design and development tools are the part where dependency is hardest to unwind, because it is embedded in engineers’ habits and in decades of existing designs. China’s broader innovation agenda for the 2026 to 2030 period has been outlined in similar terms by the science and technology ministry, whose plans were published on the State Council’s English portal.

What this changes outside China

For chipmakers outside China, the plan confirms what export controls already implied: the Chinese AI-accelerator market is closing as an addressable opportunity, and the competitive question shifts to third markets. For Western AI labs, a compute build-out of this scale narrows the assumption that access to frontier compute is a durable moat.

For energy markets, it is another large data-centre demand curve landing on a grid that has to be planned years in advance — the same pressure visible in Europe and North America, at a different scale and with different politics.

What to watch through 2027: whether reported capacity additions track the trajectory implied by a 2030 target, how much of the build uses domestic accelerators versus stockpiled or grey-market foreign parts, and whether power availability starts appearing as the published constraint rather than chips.

Questions

What does the China intelligent computing plan target?

9,800 exaflops of intelligent computing capacity by 2030, up from a stated 2025 baseline of 1,590 exaflops, backed by 3.8 trillion yuan of cumulative information infrastructure investment.

Who published it and when?

The Ministry of Industry and Information Technology, through its information and communications development department, published the 15th Five-Year Plan for the industry on 7 September 2026.

Is that comparable to supercomputer rankings?

No. Intelligent computing capacity is measured at lower numerical precision than the FP64 benchmarks used in traditional supercomputer lists, so the figures are not directly comparable.

Does the plan rely on Nvidia chips?

No. It is built around domestic supply, reflecting US export controls that restrict Chinese access to leading foreign AI accelerators and manufacturing equipment.

What is the AI Plus Software action?

A separate implementation plan from the same ministry covering intelligent programming toolchains, enterprise technical transformation and automated security testing, with an aim of exporting Chinese professional software by 2030.

Should these targets be treated as forecasts?

They are government objectives published by the ministry responsible for meeting them, not independent projections, and should be read with that interest in mind.

Revolut Data Breach Began With a Real Government Email Domain

Revolut has confirmed a Revolut data breach in which an unauthorised third party obtained customer data by sending fraudulent information requests from a legitimate government agency email domain. The fintech says a limited number of customers were affected and that funds are safe. The method is what makes this one worth reading closely: nothing was hacked in the conventional sense. The attacker used a real government domain and the legal process that obliges companies to answer it.

What Revolut has confirmed

According to TechCrunch, which reported the confirmation on 12 September, Revolut described the incident as a sophisticated external impersonation in which a third party used a genuine government agency domain to submit fraudulent requests for customer information. Bloomberg reported the company’s statement the same day.

Revolut says it blocked the address once it identified the scheme and notified the relevant government agency, financial regulators, law enforcement and data-protection authorities. The company’s characterisation of the scale — a limited number of customers — is its own, and has not been independently quantified.

What was exposed, and what was not

The exposed material, per the company’s disclosure and subsequent reporting, includes identity and contact details: date of birth, postal and email addresses and phone numbers. It also includes copies of identity documents such as passports and driving licences, and may include verification selfies, account statements and transaction histories.

Revolut says passwords and full payment card details were not accessed, and that customer funds are safe.

That split matters, and not in the reassuring direction most breach notices imply. Passwords can be changed. A passport scan paired with a verification selfie, a date of birth and an address cannot be. That combination is precisely the bundle used to pass remote identity checks at banks, crypto exchanges, mobile carriers and government portals. Help Net Security’s summary sets out what is known so far.

Why fake law-enforcement requests work

Financial firms and online platforms receive a steady stream of lawful requests for customer data from police, regulators and prosecutors. A subset are marked urgent, on the basis that a delay could cost a life or let a suspect flee. Companies are expected to respond quickly, and the main authenticity signal available to a reviewer is that the request arrived from an official government email domain.

That is a weak signal. Government mailboxes are compromised regularly, through phishing, credential stuffing or reused passwords, and a compromised mailbox grants exactly the one thing the fraud needs. The request itself can be well-drafted; the domain does the vouching.

The defence is procedural rather than technical: out-of-band verification by calling the agency back on a published number, mandatory secondary approval for identity-document disclosure, rate limiting on any single requester, and treating an urgent flag as a reason for more scrutiny rather than less. None of that is exotic. It is slow, which is why it erodes under volume.

What affected customers should do

If you receive a notification from Revolut, the useful steps are narrow and specific:

  • Assume identity-theft risk, not account-takeover risk. Passwords were not taken; your documents may have been. The threat is someone opening accounts as you elsewhere.
  • Place a credit freeze or fraud alert with the credit bureaus in your country. This is the single highest-value action and it is usually free.
  • Expect targeted phishing. An attacker holding your date of birth, address and transaction history can write a far more convincing message than the usual spam. Treat any inbound contact about the breach as suspect and use the app, not a link.
  • Enable a passkey or hardware key if your accounts support it, and review devices authorised on the Revolut app.
  • Note the date. If you later dispute a fraudulent account opened in your name, being able to point to a documented breach and notification date is useful.

For regulators, the open question is whether the disclosure meets the notification standards of the jurisdictions Revolut operates in, and whether the agency whose domain was abused will say anything about how it was compromised. That second answer is the one that would help every other company facing the same request queue.

Frequently asked

What happened in the Revolut data breach?

An unauthorised third party used a legitimate government agency email domain to send fraudulent requests for customer information, and Revolut supplied data in response before identifying the scheme.

What data was exposed?

Identity and contact details including date of birth, postal and email addresses and phone numbers, plus copies of identity documents such as passports and driving licences. It may also include verification selfies, account statements and transaction histories.

Were passwords or card details taken?

Revolut says no passwords and no full payment card details were accessed, and that customer funds are safe.

How many customers were affected?

Revolut has described it as a limited number. The company has not published a figure, and the scale has not been independently verified.

What is an emergency data request scam?

A fraud in which an attacker sends a company an urgent-looking law-enforcement request from a compromised or spoofed official email account, relying on the company’s obligation to respond quickly to lawful requests.

What should I do if I am affected?

Freeze your credit file or place a fraud alert, expect targeted phishing, strengthen authentication on your accounts, and keep a record of the notification date.

More security coverage

A Bug Rated 9.3 Out of 10 Could Let an Attacker Escape Your Virtual Machine

Broadcom patched a critical VMware Workstation Fusion flaw on September 3, 2026. It fixed an integer-overflow bug tracked as CVE-2026-59346, carrying a CVSS severity score of 9.3 out of 10. The bug could let an attacker with elevated privileges inside a virtual machine run code on the host computer itself.

How the VMware Workstation Fusion Flaw Actually Works

Security researchers call this a VM-escape vulnerability. That means malicious code can break out of the isolated virtual machine it’s running in and execute on the underlying host operating system. According to SecurityWeek’s report on the advisory, the bug is an integer-overflow issue. A specially crafted input can cause a calculation to wrap around and corrupt memory. That corruption gives an attacker code execution rights. Broadcom’s advisory, published as VMSA-2026-0007, credits the discovery to researchers who reported it through coordinated disclosure. It was not found after active exploitation.

Who Needs to Patch, and How Urgently

VMware Workstation Fusion flaw

The flaw affects VMware Workstation and Fusion versions 25H2 and 26H1. Those are the desktop virtualization products widely used by developers, IT administrators and security researchers to run guest operating systems on Mac and Windows machines. Broadcom’s fix arrived in version 26H1u1. The vulnerability requires an attacker to already have elevated privileges inside a guest VM, so it’s not remotely exploitable from the open internet on its own. That’s a modest comfort at best. Anyone who runs untrusted code, malware samples, or third-party software inside a VM often does so precisely because they assumed the host was safely isolated.

Why a 9.3 Severity Score Is Rare

CVSS reserves scores above 9.0 for flaws combining high-impact consequences with low exploit complexity. A VM-escape bug earns that rating for a simple reason. Virtualization’s entire security premise holds that whatever happens inside the VM stays inside the VM. That premise collapses completely once someone exploits the flaw. Security researchers who use VMs specifically to safely analyze malware, or test suspicious code, carry the most direct exposure here. That’s exactly the scenario the isolation boundary exists to protect against.

This Follows a Pattern of September Disclosures

The VMware patch arrived in the same week as other significant disclosures. Attackers started actively exploiting an unpatched Magento and Adobe Commerce zero-day on September 4, using it to backdoor online stores. Separately, attackers breached JetBrains’ Cadence product through an unpatched TeamCity vulnerability. Taken together, this run of disclosures reflects a busy patch cycle across enterprise software this month. It isn’t one vendor’s isolated problem — the same week saw Google patch its seventh emergency Chrome bug of the year, and Berlin’s city government confirm a ransomware breach that leaked 5.8 terabytes of files.

What Makes VM-Escape Bugs Different From Ordinary Malware Risk

Most software vulnerabilities threaten only the system they’re found on. A VM-escape flaw works differently, because it defeats a security boundary that other tools depend on. Sandboxed malware analysis, isolated test environments, and even some cloud hosting setups all lean on one assumption: a VM can’t reach its host. When that assumption fails, every control built on top of it needs a fresh check too, not just the VM software itself.

How This Compares to Past VMware Security Incidents

VMware products have faced serious vulnerabilities before, including several VM-escape bugs disclosed in prior years that prompted similar emergency patching cycles. What sets this one apart is the severity score. A 9.3 rating places CVE-2026-59346 among the more dangerous flaws Broadcom has disclosed for its desktop virtualization line specifically, as opposed to its enterprise server products, which see a higher volume of security research attention overall. Broadcom’s acquisition of VMware in 2023 also changed how these advisories get published, consolidating disclosures under the company’s broader security bulletin process rather than VMware’s older, standalone system.

What IT Teams Should Do Next

Broadcom’s guidance is straightforward. Teams should upgrade affected Workstation and Fusion installations to version 26H1u1 as soon as operationally possible. Prioritize machines that run untrusted or unverified code first. Organizations that rely on VM isolation as a security control for malware analysis or sandboxed testing should treat this patch as time-sensitive. It is not routine maintenance, given how directly the flaw undermines that isolation assumption. Security teams that maintain a patch-management dashboard should flag this advisory for cross-checking against every desktop image still running the older builds, not just servers. IT administrators managing shared lab machines, where multiple researchers rotate through the same physical hardware, face the highest practical exposure and should treat this update as a same-week priority rather than folding it into a routine monthly patch cycle.

Frequently Asked Questions

What is CVE-2026-59346?
It’s a critical integer-overflow vulnerability in VMware Workstation and Fusion that can let an attacker escape a virtual machine and run code on the host computer.

How severe is this VMware Workstation Fusion flaw?
It carries a CVSS score of 9.3 out of 10, reflecting both high potential impact and relatively low exploitation complexity once an attacker has elevated access inside a VM.

Which product versions does this flaw affect?
It affects VMware Workstation and Fusion versions 25H2 and 26H1. Broadcom’s fix arrives in version 26H1u1.

Is this exploitable remotely over the internet?
Not directly. An attacker needs elevated privileges inside a guest virtual machine first. That’s still a realistic scenario for anyone running untrusted code in a VM.

Did anyone exploit this flaw before the patch came out?
Available reporting indicates researchers disclosed it through a coordinated process, not after active exploitation. Even so, organizations should patch promptly.

Sources

  • SecurityWeek — VMware Workstation and Fusion Updates Patch Critical Vulnerability. securityweek.com
  • Security Affairs — Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities. securityaffairs.com

Apple Just Answered the Foldable Rumors. The Bigger Change Was Inside Siri

Apple Siri Google Gemini integration became official at Apple’s September 9 event. The company confirmed it is rebuilding Siri on Google’s Gemini models. It also unveiled its first foldable iPhone. Those were the two headline moves in what Apple called its biggest device wave in years. It was also the first keynote led by new device chief John Ternus.

What the Apple Siri Google Gemini Deal Actually Covers

Apple struck a deal with Google to license Gemini models. Those models now power upgraded Apple Intelligence features and a rebuilt Siri. Building an equivalent large language model entirely in-house, on Apple’s needed timeline, wasn’t realistic. Reporting on the partnership says the arrangement lets Apple ship more capable, conversational Siri features sooner than an internal model would have allowed. Google, in turn, gains a high-profile distribution deal across hundreds of millions of iPhones. Neither company has published the full financial terms of the agreement.

Our Preview Called the Foldable Rumor Right

Apple Siri Google Gemini

Tamara News previewed this event on September 8. At that point, the foldable iPhone was still an unconfirmed rumor riding on Ternus’s first keynote as device chief. At the event itself, Apple confirmed the device. It positioned the foldable as the centerpiece of a broader hardware refresh, not a niche add-on to the standard iPhone lineup. Foldable phones have belonged to Samsung and Huawei for years. Apple’s entry is likely to intensify competition on pricing and on software built specifically for folding displays.

Why Apple Chose Partnership Over Building Its Own Model

Apple’s AI efforts drew criticism over the past two years for lagging competitors on generative features, particularly conversational assistants. Partnering with Google for Gemini is a pragmatic call. Catching up on foundation-model quality alone would have taken longer than Apple’s product cycle allowed. The move also mirrors a broader 2026 pattern: large tech companies choosing high-profile AI partnerships and acquisitions, including Nvidia’s own multibillion-dollar deals, over purely organic development.

What This Means for the Wider AI Assistant Race

A Gemini-powered Siri puts Google’s models at the center of the world’s most widely used smartphone assistant. That distribution win could matter more than any single Google-branded product. For competitors, it raises a hard question. Can Amazon’s Alexa and Microsoft’s Copilot match a partnership of this scale, or will they need similar arrangements of their own? Apple, meanwhile, keeps its hardware and interface advantages while outsourcing the model layer underneath. Other device makers are likely to study that split closely.

What Reviewers Will Test First

Early hands-on coverage typically focuses on two things with a device like this: hinge durability and how visible the fold line is on screen. Expect reviewers to bend the new iPhone repeatedly, check for screen creasing under different lighting, and compare battery life against Apple’s standard, non-folding models. On the software side, testers will likely push Siri with multi-step requests to see how the Gemini-powered version handles follow-up questions compared with the old, more scripted Siri.

How This Fits Apple’s Broader AI Strategy

Apple spent the past two years insisting its AI approach would prioritize privacy and on-device processing over cloud-dependent models. The Gemini partnership complicates that message somewhat, since it relies on a third party’s cloud-based models for Siri’s most advanced features. Apple says the partnership follows its existing privacy commitments for handling user data. The company has not published full technical detail on how requests get routed, or what Google can see on its end.

How Competitors Are Likely to Respond

Samsung and Google’s own Pixel team already ship generative AI assistants built on in-house or closely integrated models, giving them a head start on tight software-hardware coordination that Apple’s outsourced approach doesn’t offer in the same way. Amazon, meanwhile, has invested heavily in a next-generation Alexa overhaul of its own. Analysts expect at least one competitor to announce a comparable large-model partnership within the next two quarters, simply to avoid ceding ground on assistant quality.

What to Watch as the Rollout Continues

Apple has not detailed a full rollout timeline for every Gemini-powered feature. Foldable iPhone reviews and durability testing will shape early public reaction once the device reaches reviewers. This week’s Apple earnings call, part of a broader stretch of major tech reporting, is the next concrete moment. Apple is expected to use that call to address how the launch affects sales in the current quarter.

Frequently Asked Questions

Is Siri now powered by Google Gemini?
Apple confirmed at its September 9 event that it is rebuilding Siri using Google’s Gemini models, under a licensing partnership between the two companies.

Did Apple actually release a foldable iPhone?
Yes. Apple confirmed its first foldable iPhone at the same event. That ended months of speculation built around new device chief John Ternus’s debut keynote.

Why didn’t Apple build its own AI model for Siri?
Apple’s in-house AI efforts had lagged competitors on conversational features. Partnering with Google let it ship more capable Siri features on a faster timeline.

What are the financial terms of the Apple-Google deal?
Neither company has published the full financial details of the Gemini licensing arrangement.

What happens next for Apple after this announcement?
Apple reports quarterly earnings this week. Analysts expect that to be the first chance for the company to address how the launch affects current-quarter sales.

Sources

  • CNBC — Apple picks Google’s Gemini to run AI-powered Siri. cnbc.com
  • Forbes — Apple Event Kicks Off 2026-2027 Tech Season. forbes.com