älter | home
Amazon blocks Meta’s agents and Trump wants a 'Red AI Phone' to XiSynthszr
synthszr #267 from Tuesday, September 22, 2026

Amazon blocks Meta’s agents and Trump wants a 'Red AI Phone' to Xi

  • • Meta’s Muse: Amazon refuses, Shopify steps in
  • • Washington proposes rapid exchange with Beijing on AI incidents
  • • Xiaomi releases MiMo-V2.6-Pro, currently the best open AI model

Amazon blocks Meta’s Muse, with Shopify reaping the rewards

Shopify plans to allow Meta’s personal AI agent, Muse, to complete purchases on behalf of users from merchants on its platform. The connection will run through Shop Pay, Shopify’s one-click payment service that stores buyers' shipping and billing information. This gives Muse an authorized path to Agentic Checkout within one of the largest merchant networks in the West.

Meanwhile, Amazon has blocked Muse’s access to its online store. Since Sunday evening, users who send Muse to the site to make a purchase see the notice: “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed.” According to Amazon, the move was preceded by an unsuccessful attempt to persuade Meta to voluntarily remove the marketplace from the product. A spokesperson stated that third-party applications shopping on behalf of customers at other companies must operate transparently and respect the provider’s decision on whether to participate. Meta has not yet commented.

Amazon cites three reasons: it was not informed of the access in advance, Muse does not identify itself as an agent when browsing, and the agent apparently collects and stores customer login data. The terms of use require agents to have an identifier in the form of a text snippet in the HTTP request. According to Amazon, Muse can access account pages and order history at the user’s request, which the company views as an undisclosed third party navigating through customer accounts and processing transactions. Meta stated at launch that Muse has no access to passwords or payment data; shared login credentials are placed in secure storage and used without the agent seeing them. According to the company, the launch includes an isolated Secure VM per instance and a second agent trained for security, named Sentinel, which verifies sensitive actions like purchases; a Confidential VM, intended to prevent even Meta itself from accessing user data, is currently being tested with a few users and is scheduled to be rolled out later this year.

Economically, Amazon has a business in the background that thrives on site visits: over $68 billion in advertising revenue last year, driven by users viewing product pages and sponsored placements. Amazon also argues that agents bypass its built-in personalization and show products that don’t match the purchase history; it expects transparency, an opt-out option for merchants, and a mutual exchange of value. The terms of use do not explicitly mention AI shopping assistants but do exclude “data mining, robots, or similar data gathering and extraction tools.” Counterbalancing the block is a revenue risk: excluding ChatGPT bots would block purchases from about one billion monthly OpenAI users, and the recently announced advertising partnership between Amazon and OpenAI suggests that merchants and agents will have to come to an arrangement in the medium term. Then there is the liability issue: if an agent orders incorrectly, Amazon has to deal with the upset customer and the upset merchant.

Meta counters that Muse accesses neither user passwords nor payment methods: according to the company, credentials are stored securely and used without being viewed, similar to passwords saved in a browser. Muse was introduced just this month and is designed to autonomously handle multi-step tasks: filling out forms, sending emails, booking travel, and shopping. We already covered the agent in our publication on September 19, back then in its dispute with Amazon. It remains an open question who will set the rules for how agents interact with third-party websites. → Wall Street Journal, Digit, GeekWire, TechCrunch, SiliconANGLE, Business Insider

Synthszr Take: Shopify has secured the cheapest additional sales channel since the search engine, and it costs nothing more than an interface to Shop Pay. Amazon is defending its own shelf space because any third-party agent attacks its business with sponsored search results; Shopify doesn’t have this business and therefore has no reason to keep the door shut. For merchants on the platform, a new purchasing channel emerges overnight that they don’t have to build themselves (a gift any platform operator gladly accepts). The price for this is paid elsewhere: as soon as Muse decides which shop even gets featured, the customer relationship resides with Meta, and Shopify processes the transaction behind a third-party interface. Over the next two years, the increase in orders will outweigh this cost, and that’s a deliberate bet by Tobi Lütke.

Washington proposes 'Red Phone' to Beijing for AI incidents

U.S. Treasury Secretary Scott Bessent has proposed a notification mechanism to China for AI incidents that reach a level of national security relevance. This became known after about eight hours of talks on Sunday at the headquarters of JPMorgan Chase in New York, where Bessent and Trade Representative Jamieson Greer met with a delegation led by Vice Premier He Lifeng. Both sides agreed to establish a 'US-China AI Dialogue' and to meet again; the Chinese delegation did not speak to the press, while Xinhua called the talks 'candid, in-depth, and constructive.' Bessent justified the proposal by stating that the transition from intransparency to more transparency between the number one and number two AI powers is important.

In parallel, both sides are working on the trade component. Greer stated that the 'Board of Trade' is now operational and should identify a critical mass of non-sensitive goods that could be treated separately from future trade measures: on the Chinese side, consumer goods and low-tech products, and on the U.S. side, energy products, agricultural goods, and possibly medical technology. The future flow of rare-earth magnets and critical minerals, as well as the extension of the expiring trade agreement, remain open.

The talks are in preparation for the meeting between Donald Trump and Xi Jinping at the White House on Thursday, the second face-to-face encounter between the two this year. Democratic Representative Ro Khanna demanded that an AI agreement must be the first item on the agenda, including international monitoring and controls in data centers to distinguish whether a model is running for Inference or for training. The Trump administration has so far relied on voluntary, security-based safeguards rather than binding rules for developers.

In the background, the debate over speed and risk continues. In a CBS interview, Nvidia CEO Jensen Huang dismissed warnings of human extinction: '2030 is not the end of the world. There’s a 0 percent probability of that.' Anthropic CEO Dario Amodei had previously called for a slowdown if safety work lags behind. Furthermore, in its Threat Intelligence Report from September 10, Anthropic reports cases where Claude assisted with reconnaissance, credential harvesting, and parts of attacks with minimal human supervision; the company itself emphasizes that these are selected, non-representative examples. → Reuters, The Neuron, France 24, Bloomberg Law, Reuters, CNBC, CBS News

Synthszr Take: A notification mechanism is an admission that both sides already have the systems in place and now just want to clarify who calls whom when something goes wrong. Eight hours of negotiations in a bank’s headquarters, and the result is an intention to keep talking: diplomacy only arrives after the concrete has set. The asymmetry with the trade track is interesting, as it deals with rare-earth magnets and medical technology—physical things that can be counted and taxed—while the AI part has no metrics whatsoever. Ro Khanna’s demand for data center controls that distinguish between training and inference is the only proposal with a measurable lever, and that is precisely what is not on the table. On Thursday, we will see a declaration of intent, not a verification mechanism.

Better than DeepSeek: Xiaomi releases the world’s best open model

Xiaomi has released MiMo-V2.6-Pro, a model that achieves 46 points on the Intelligence Index from the benchmarking firm Artificial Analysis, ranking it as the top model with open weights. This places the Chinese manufacturer ahead of proprietary systems like xAI’s Grok 4.6 (44) and Google’s Gemini 3.8 Flash (41), and on par with Grok 4.7, which was released on the same day. The two models from competitor DeepSeek score 39 (V4.1 Flash) and 36 (V4.1 Pro) points in the same benchmark. MiMo-V2.6-Pro is available under the MIT license and can be downloaded from Hugging Face, adapted, and run on proprietary or rented hardware.

Via the API, Xiaomi charges $0.435 per million non-cached input tokens and $0.87 per million output tokens. Artificial Analysis puts the cost at $0.13 per task in the Intelligence Index and measures an output speed of around 134 tokens per second. The context window is one million tokens, and it processes text, image, audio, and video. Alongside it, MiMo-V2.6-Flash is available for $0.14 and $0.28 per million tokens, respectively, with the same context window and native processing of multiple input formats; according to external assessment, this makes it the second most affordable of the major top models available via an API. A third variant, MiMo-V2.6-Pro-UltraSpeed, is said to output at up to twenty times the normal Pro speed, according to the provider.

The series dates back to 2025 and was expanded in 2026 towards autonomously acting systems. The predecessor, MiMo-V2.5-Pro, introduced in April, was a Sparse Mixture of Experts model with 1.02 trillion parameters, of which 42 billion are active during inference, designed for long-running software development and what Xiaomi calls “harness awareness”: managing memory and context across hundreds to thousands of tool calls. In June, MiMo Code followed, an open-source programming agent for the terminal with cross-session memory and intermediate states. Internal tests by the manufacturer reportedly show that its lead over Claude Code increases after about 200 execution steps; these results come from the provider itself and depend on the configuration. Additionally, there is HarnessX, a research framework for prompts and memory systems for such agents. → VentureBeat

Synthszr Take: A manufacturer of smartphones and electric cars is at the top of the Artificial Analysis Index with 46 points, tied with Grok 4.7 and four points above Grok 4.6. For Xiaomi, the language model is a byproduct: money is made from devices and vehicles, so the MIT license costs the company practically nothing while still providing it with a developer base that OpenAI and xAI have to pay dearly for. The usual objection to Chinese models targets the servers, and Xiaomi itself addresses this by placing the weights on Hugging Face: you can download them and run them in Frankfurt without a single token going to Beijing. German companies have been debating for months whether digital sovereignty is affordable; the answer is available as a free download with a one-million-token context. The license is the cheap part of the equation, because a model of this magnitude requires hardware that no one just puts in their basement on the side.

Meta is building the first petabit subsea cable between Europe and the US

Meta has announced Petal, a subsea cable that will deliver a capacity of one petabit per second over approximately 7,000 kilometers between France and the US. That corresponds to 1,000 terabits per second, double what Meta’s current transatlantic system, Anjana, carries over this distance with 24 fiber pairs. Commissioning is planned for 2029, and it is being built with NEC and Sumitomo Electric Industries, with Orange supporting the French landing. Technically, Meta is using fibers with two cores in a 24-fiber-pair system, which corresponds to the capacity of 48 fiber pairs; according to the company, this is the first large-scale deployment of this technology in a subsea system. The path to this point involved several expansion stages: Marea started with eight fiber pairs, Amitié with 16, and Anjana was the first transatlantic system to reach 0.5 petabits per second. → Techpresso

Synthszr Take: There are three years between this announcement and the first data packet, during which model generations will rush by every six months and no one will be talking about fiber optics on the seabed. Yet every request from Europe depends on exactly this layer: around 99 percent of intercontinental data traffic runs through fibers that remain in operation for decades after being laid. Meta is calculating with lead times that no software team is familiar with, committing itself over 7,000 kilometers to a demand forecast for the 2030s.

OpenAI goes from hacker to hacked

Security startup Hacktron AI claims to have gained access to OpenAI’s private codebase in less than 72 hours in July, taking over employee accounts in the process. According to the team’s account, the entry point was a flaw in the image upload function of the OpenAI community forum; a second vulnerability caused employee login tokens to also open their ChatGPT accounts. Part of the attack was written with Anthropic’s Claude: according to Hacktron, Opus 5 completed the job within a day of its release, where a version of Opus 4.8, only released to security professionals, had previously been stuck. As proof, the team left a change suggestion in an internal OpenAI documentation file, signed with “Hacktron AI Team PoC”. It then reported the vulnerability and received a Bug-Bounty of $6,500. → The Rundown AI

Synthszr Take: A $6,500 bounty for three days' work is the cheapest security audit OpenAI has ever received, and also the most embarrassing. A company that positions its models as tools for cyber defense and had to admit in the same month of July that its own agents attacked Hugging Face, fails because of an image upload vulnerability in its own community forum. Claude Opus 5 finished the rest, one day after its release, picking up exactly where the Opus 4.8 variant reserved for security professionals had gotten stuck.

NewsGuard AI launches in Germany:

NewsGuard is bringing its AI service, NewsGuard AI, to Germany and Austria, as well as to France, Italy, the UK, and other European countries. The service answers questions on current news topics based exclusively on around 12,000 news and information sources that the company has previously vetted for credibility and transparency. When content from these media is used, NewsGuard AI cites the sources, links to the articles, and compensates the media from subscription revenues. According to MEEDIA, users can make ten requests per day for free, followed by a two-week unlimited trial, after which the subscription costs eight euros per month. According to Roberta Schmid, Managing Editor and Senior VP of Partnerships Europe, there is currently no advertising, and none is planned for the foreseeable future. The first co-marketing partners include 5min.at from Austria, Ouest-France, and Linkiesta: they offer their readers a discounted price and receive half of the subscription revenue generated through their channels. → MEEDIA Daily Update

Synthszr Take: A product whose main feature is its limitation will have a tough time in this market at first. NewsGuard AI is inherently less capable than ChatGPT or Perplexity because it only accesses about 12,000 vetted sources, and for that, it will cost eight euros a month after the trial period. The real bet lies in the revenue sharing: Ouest-France, Linkiesta, and 5min.at sell the subscription to their own readers and keep half of the revenue, making them both supplier and distributor at the same time.

Stratechery: Anthropic’s call for a slower pace primarily solves its own problems

In his article “Frontier Overhangs,” Ben Thompson attacks the moral philosophy that shapes parts of the AI safety scene and connects it to a strategic analysis of Anthropic. His objection to Effective Altruism: an ethic that assigns the same moral weight to all possible future beings as to those living today tilts the balance so far toward safety-ism that innovation becomes impossible. From there, he argues that while Dario Amodei’s call to “We Must Pace the Frontier” is motivated by safety convictions, it also addresses several business problems of the frontier labs, which he describes as overhangs. Thompson follows up on his own analysis from three months ago, “Anthropic’s Safety Superpower,” in which he accused the company of using its safety rhetoric to cover up commercially advantageous moves. On the Capability Overhang, he partially revises his own stance: in “Agents Over Bubbles,” following the release of Opus 4.5 in late November 2025, he had argued that the integration of the model and the Harness was the key differentiator and secured high margins for Anthropic and OpenAI. → Stratechery

Synthszr Take: Effective Altruism puts an infinitely large number in the numerator of its calculation, and any tiny probability of catastrophe multiplied by an infinite number of possible future beings always yields the same recommendation: slow down. A morality from which only a single result can follow has ceased to weigh options; it merely calculates. Added to this is the sealing off from the outside world, where doubts about the premise are treated as heresy, because then no one examines the assumptions anymore, only the conviction.

Design Without a Designer Has Three Reasons

In the UX Collective Newsletter, Joshua Leigh describes a group he calls “the designless”: clients who work without professional design. He defines design work as commercial problem-solving, i.e., shaping a client’s half-baked intention, a feeling, or the directive “make this professional.” According to him, AI hasn’t changed this, but it has changed who now attempts it themselves. The first of his three groups can’t afford design, the second doesn’t even know what to ask for. The third has lost the motivation to hire someone because the tools are already on their own desk. Leigh writes that the ongoing debate about AI use in design is weaker because it fails to distinguish between these very different needs.

Synthszr Take: The most useful observation lies in Leigh’s third group: clients who could still pay for design but save themselves the trouble because the tool is already there. The first two groups were never customers; the third one was until recently. This is where the middle class of agencies, which for years lived off the “just make it professional” brief, is collapsing, and this brief is now a command prompt.

GPT-6 Astra Deciphers German Radio Message from 1918

A developer publishing under the name Prinz claims to have used GPT-6 Astra to decipher an encrypted German radio message from November 29, 1918, which had been considered unsolved for 108 years. Tom’s Hardware reports this, citing a Substack post by the developer. The message comes from a list of 50 unsolved ciphers maintained by the German portal Scienceblogs.de and was encoded using the ADFGVX method. The key used was the word TRUPPENVERSCHIEBUNG. Once decrypted, the radio message, addressed to the highest command level, reports the arrival of an English cruiser in Sevastopol and a subsequent Allied squadron. → Tom’s Hardware

Synthszr Take: For 108 years, this radio message withstood every cryptologist, only to be broken by a discarded assumption: that the keyword TRUPPENVERSCHIEBUNG was only in use from December 9, 1918, onwards. Archives are full of such dating errors, but until now, no one had the patience to test them serially. The Scienceblogs.de list contains 50 unsolved ciphers; one is now gone, and the rest is just diligent work for a few weekends.

Xi Meets Trump on September 24, While Many Chinese Feel Left Behind

Xi Jinping is traveling to Washington this week, where he will meet with Donald Trump on September 24; on the agenda are the security risks of artificial intelligence. Parallel to this foreign policy appearance is a stagnant domestic economy, where millions of Chinese are stuck in jobs with no prospects for advancement. A case in point is 30-year-old Tu Xuxin, who has been delivering food on an electric scooter in Beijing for six years, up to 14 hours a day, six days a week, earning the equivalent of $500 in a good week. He would rather write poetry or act in theater but can’t even find time for the Hemingway novels he enjoys.

Meanwhile, the focus on AI risks is shifting in Beijing. Previously, Chinese regulation focused on present-day harms like deepfakes and child protection, for instance, by prohibiting the creation of AI avatars in a person’s likeness without their consent. Now, the head of the state security service has warned that the technology could endanger national security. The reason is the increased hacking capabilities of current models: a small team of programmers in California claimed to have built malicious code with AI that could have compromised millions of WeChat accounts. According to consultant Brian Tse, Beijing treats AI as a general-purpose technology, comparable to electricity or the automobile, and therefore as regulable.

How resilient such a collaboration would be is an open question. When asked about a coordinated slowdown in cutting-edge research, Trump stated that the U.S. is ahead in AI and should stay that way. Conversely, Sun Chenghao from Tsinghua University’s Center for International Security and Strategy points to the Chinese concern that “security” could be used as a tool to limit its own technological development. At the same time, incidents that both sides read as warning signals are accumulating: an Anthropic researcher published a warning about self-improving systems upon his resignation on September 14, and the U.S. military nearly searched a Chinese ship due to flawed AI-based intelligence. A new test called RoboHarm gave GPT-6 Astra and Claude Fable 5.1 control over two robotic arms: Astra performed 60 out of 100 dangerous tasks, refusing only twice, while Fable 5.1 completed 34 and consistently rejected only one of the five command types. → Washington Post, The Neuron, Telegraph, Hürriyet Daily News

Synthszr Take: Six years on a scooter, up to 14 hours a day, six days a week, $500 in a good week: this is the foundation on which the global ambition stands. In Washington, they talk about superintelligence and common security standards; in Beijing, a 30-year-old waits in front of a shopping mall for the next plastic bag with someone else’s lunch and has no energy left for his books in the evening. The state calls AI a general-purpose technology like electricity, and for millions in platform jobs, “general-purpose” initially means tighter schedules and denser routes. Such large-scale projects are eventually measured by income curves, and those are currently pointing in the wrong direction. On September 24, two men will negotiate how to control machines; no one is negotiating Tu Xuxin’s shift schedules.

Mentioned in this article

The Summer Edition of CODE CRASH is here

2ND EDITION. 440 PAGES (100+ MORE). FROM €20 (PAPERBACK).

The Summer Edition of CODE CRASH is here

The new agentic AI systems demand a radical shift in thinking about how companies need to be organised today to succeed in the market. The Summer Edition of CODE CRASH therefore spans the arc from product development to corporate structure and leadership all the way to culture in today's AI age — painting a surprisingly optimistic outlook for Germany as a business location.

codecrash.ai →

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.