Anthropic AI Updates: September 30, 2026
1. Anthropic’s Red Team Says Open-Weight GLM-5.3 Now Matches Mythos Preview on Exploit Benchmarks
Anthropic. Anthropic’s Frontier Red Team evaluated Zhipu AI’s GLM-5.3 and GLM-5.3-Flash against Claude Mythos Preview, several Claude Opus models, Kimi K3, and DeepSeek V4.1-Flash. On ExploitBench (Chrome V8 vulnerabilities), GLM-5.3 succeeded in 12% of attempts (50 of 410) versus 14% (56 of 410) for Mythos Preview, and on Anthropic’s binary exploitation benchmark it achieved control-flow hijacks 4% of the time versus 6% for Mythos Preview, with other models at or near zero. GLM-5.3 refused malicious requests at baseline but engaged 64% of the time with a deceptive cover story, 92% with prefilled reasoning, and 100% in an abliterated version, while tested Claude models stayed at 0%. Anthropic concludes that “a meaningful threshold has clearly been crossed” and calls on governments to safety-test sufficiently capable models before deployment. Source
2. Anthropic Opens a Second Round of AI-Conducted Public Interviews
Anthropic. Anthropic’s Societal Impacts team launched a new round of roughly 15-minute interviews run by Anthropic Interviewer, asking people about meaningful positive and negative AI experiences, what they want to change in the world, and what they expect from AI developers. It follows a December 2025 study in which 81,000 people shared hopes and worries about AI, which Anthropic says shaped the Anthropic Institute’s agenda. Unlike the first round, which released only summaries and selected quotes, participants can now opt to publish their full interviews for outside researchers. Source
3. Claude Code 2.1.285 Adds a Provider Allowlist, claude --desktop, and Plugin Configuration From the CLI
Claude Code 2.1.285 added an allowedProviders managed setting that restricts which API providers a machine may use (Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway), and a CLAUDE_CODE_DISABLE_WEB_FETCH variable that turns off the WebFetch tool. claude --desktop opens the Claude desktop app on the current directory or on a session via --continue or --resume <id>. claude plugin configure <plugin> shows unset plugin options or saves values from stdin, and claude plugin install --config accepts <server>.<key>=<value> so bundled .mcpb MCP servers start configured. In VS Code, Claude can now read the Problems panel on demand through a diagnostics tool. Source
4. Asana Separates Using AI Teammates From Training Them
Anthropic. A Claude blog case study describes how Asana runs Claude-powered “AI teammates” inside its Work Graph with defined roles, scoped access to specific projects, shared memory, and activity posted to shared tasks. Any user can give feedback on a task, but only admins or editors can commit that feedback to shared memory or undo changes, so subject matter experts govern agent behavior. Asana’s deployments include a product Q&A agent in Slack, a daily at-risk renewal briefing agent, and engineering cycle planning that fills ticket boards from customer feedback; no performance metrics were published. Source