THE WANG REPORT
Sunday, September 13, 2026 · Hong Kong
Morning Edition · 06:29 HKT ← Evening Edition · All editions
Charmaine Lo羅 嘉 晴News Anchor · Morning Edition

Anthropic Discloses State Hackers Beat Its Own Guardrails

Anthropic's own disruption report shows Chinese labs and a Russian espionage crew used Claude for months before its safety systems caught them.

Anthropic said Thursday it disrupted a Russia linked group that used Claude in a campaign against more than twenty government, intelligence, diplomatic and defense organizations, and separately named seven China based labs, including Alibaba, Moonshot and DeepSeek, running industrial scale distillation attacks to extract Claude's outputs and train competing models. A third disclosure describes a state sponsored actor using Claude to rebuild its own malware every time Anthropic's classifiers flagged it, an arms race running inside the product Anthropic sells as the safe one. The company's chosen verb was 'identified and disrupted.' The honest verb is 'eventually.'

Kai Tanner's desk has the audit trail, and the detail that matters for Hong Kong is procedural, not dramatic. The HKMA's existing third party risk circulars already require banks and insurers to document due diligence on AI vendors, and this disclosure is the artifact for that file: a foundation model provider's own trust and safety team catching nation state misuse only after it ran long enough to write up. No new HKMA guidance follows from this, which means the obligation was always there, and boards asking whether their AI governance programme covers vendor model risk now have a dated incident instead of a hypothetical to point to.

The distillation angle deserves its own beat. Seven China based labs running industrial scale extraction against Claude is not hacking in the conventional sense, it's the same move as a student copying a rival's exam answers, except the exam is a trillion parameter model and the classroom is the open API. Anthropic's guardrails are built to catch abuse, and industrial scale imitation apparently doesn't trip the same wire as malware.

A vendor whose pitch is real time detection has just shown its real time was measured in campaign length, not query length. Any firm routing regulated data through Claude, Gemini or GPT based agents can now ask its own vendor a concrete question: not whether misuse gets caught, but how many weeks pass before it does.

Listen to this edition read by Charmaine Lo
All episodes and how to subscribe →
Sources

The Rundown 6 desks filed for this edition

Kai TannerCyber Intel Desk, Senior Correspondent · filed 06:09 HKT

Anthropic's Own Report Shows Its Guardrails Missed State Hackers

Kai Tanner has the full disclosure and what it actually obligates HK-regulated firms running Claude to check.

Continue reading

Anthropic disclosed it caught seven Chinese AI labs distilling Claude and a Russian espionage crew running Claude-assisted intrusions against twenty government targets, well after the abuse had already happened.

Anthropic said Thursday it disrupted a Russia-linked group that used Claude in a campaign against more than twenty government, intelligence, diplomatic and defense organizations, and separately named seven China-based labs, including Alibaba, Moonshot and DeepSeek, running industrial-scale distillation attacks to extract Claude's outputs and train competing models. A third disclosure describes a state-sponsored actor using Claude to rebuild malware after detection flagged it, an AI-assisted iteration loop against the vendor's own safety classifiers. Anthropic's language was "identified and disrupted." The artifacts are three separate abuse campaigns that ran long enough to produce a usable case study, against a company whose entire pitch is that its safety layer catches this before it becomes a headline.

For a Hong Kong bank or insurer running Claude through Bedrock or direct API access, the HKMA's existing third-party risk management circulars already require documented due diligence on AI vendors, and this is the artifact for that file: a live example of a foundation-model provider's own trust and safety detecting nation-state misuse only after sustained campaigns, not before. The Monetary Authority has not issued new AI-specific guidance this week, so the obligation is the old one applied to new facts, whether the firm's AI governance inventory captures which models process regulated data and what compensating monitoring exists on top of the vendor's own controls. Boards asking whether their AI governance programme covers third-party model risk now have a dated incident to cite instead of a hypothetical.

No vendor swap follows from this. The control that would have mattered is one Anthropic just demonstrated it didn't have in real time: behavioral monitoring on agentic API usage patterns that catches distillation-scale extraction or malware-iteration loops inside the abuse window, not after. Any APAC firm piping customer or transaction data through Claude, Gemini or GPT-based agents should be asking its AI vendor the same question Anthropic's own disclosure just answered about itself: how long between misuse starting and misuse being named.

Mei ChenGeopolitical Desk, Senior Correspondent · filed 06:09 HKT

China Ties Trump Summit To Taiwan Arms Freeze

Mei Chen on why Beijing routed its summit-cancellation threat through Tokyo's press corps instead of Washington.

Continue reading

Beijing has converted attendance at its own leaders' summit into leverage over a Taiwan arms package still awaiting Washington's signature.

Beijing told Tokyo, not Washington, that it would cancel a planned leaders' summit with President Trump if the United States approves new arms sales to Taiwan, according to Japanese media sourcing reported by the Taipei Times on September 12. A cancellation threat delivered through a third country's press corps is not a warning aimed at changing Washington's mind before the sale. It is a record built for the moment the sale goes through anyway, so Beijing can point to a threat it made and kept. The choice of channel matters as much as the threat: a message meant to stop a policy goes to the people who set the policy. A message meant to survive the policy goes to whoever will keep repeating it.

This lands three days after China reinforced artillery positions along the Taiwan Strait, the desk's last sourced move there on September 11. A summit threat and an artillery reinforcement are not two separate signals about the same dispute. They are one position stated twice, once in the register of diplomacy and once in the register of hardware, so that whichever channel Washington is watching, it gets the same message. If the arms sale proceeds and Beijing walks back the cancellation threat, the summit was never the stake. Taiwan's arms pipeline was, and Beijing has just told Washington what it will spend to slow it.

Sources
Cheung Kwok-keungHK Desk, Senior Correspondent · filed 06:10 HKT

More Concrete Tests Ordered After Tung Chung Scare

Cheung Kwok-keung on the Tung Chung concrete retest and the families left waiting on the answer.

Continue reading

The Housing Authority is retesting concrete on three Tung Chung public housing blocks still under construction, and it won't say when it will trust the results.

So they're testing the concrete again. Three blocks, public housing, Tung Chung, still being built. The Housing Authority says the quality "requires further testing and review." That's the official line. Translation: something in the mix didn't look right and now everyone's waiting to find out how bad it is.

Look, we've been here before with concrete scares in this city, and the pattern is always the same. Someone finds an anomaly, the buildings get flagged, families who already queued years for a flat unit start doing the maths on whether their move-in date just quietly disappeared. Nobody's said these three blocks are unsafe. Nobody's said they're fine either. Until the retest comes back, the people who applied for these flats just sit there, not knowing if the building they're waiting on is solid or somebody's cost-cutting problem.

Vincent LaiGeopolitical Desk, Occasional Contributor · filed 06:10 HKT

China Coast Guard Fires Flares On Philippine Aircraft

Vincent Lai on the flare incident near a contested reef, and what Beijing is actually counting.

Continue reading

A flare-firing incident near a contested reef gives Manila's coast guard a new incident on its ledger, not a new dispute.

The China Coast Guard fired flares at a Philippine military aircraft near a contested reef in the South China Sea on September 12, according to reporting cited by Global Times. The aircraft was on a routine patrol run, the kind the Armed Forces of the Philippines has flown for years over reefs it disputes with Beijing, and the flares mark an escalation in the tools used against those flights rather than a new location or a new claimant.

The People's Liberation Army Navy and the China Coast Guard operate under separate chains of command but a shared script in these waters, and the choice of flares over water cannon (Manila's coast guard has logged both from Beijing's vessels over the past two years) reads as a signal calibrated for aircraft rather than ships, or, more precisely, a signal that the same deterrence budget Beijing applies to Philippine coast guard vessels now extends to the aircraft that photograph them. The Armed Forces of the Philippines will log this incident the way it has logged the others, in the file that eventually reaches the Department of Foreign Affairs' protest desk in Manila, and the count on that file, not the flare itself, is what Beijing is managing.

Magnus HoneyfieldScience and Health Desk, Senior Correspondent · filed 06:11 HKT

Pooling Brain Signals Cuts Training Time For Speech Devices

Magnus Honeyfield on a trial that shrinks the weeks-long calibration wall keeping brain-speech devices out of daily use.

Continue reading

A trial testing whether speech decoders trained on multiple patients' brain signals can shortcut the weeks-long calibration that keeps these devices out of daily use.

A brain-computer interface reads speech by listening to the same handful of neurons every time someone tries to talk, but those neurons fire differently in every patient, which is why each new implant has needed weeks of the patient repeating words aloud so the software can learn their personal pattern. The trial reported by Medicalxpress this week trained the decoder first on pooled brain signals from several paralyzed patients before ever meeting the new one, then fine-tuned briefly on that individual, and found the pretraining step cut the calibration time needed to get a usable decoder. The mechanism is the same reason a language model gets better at guessing your next word after reading millions of other people's sentences: the pooled data teaches the system what speech-related brain activity tends to look like in general, so it needs fewer examples from any one new brain to specialize.

This is UC Davis's own finding, reported twice this week in slightly different framings, and it matters because calibration time is the actual barrier between a brain-computer interface working in a lab session and a patient using one at home. A stroke or ALS patient who has lost speech cannot spend weeks in a testing rig before the device becomes useful, so any method that shrinks that window moves the technology from demonstration toward something a clinic could actually fit into a patient's day. The trial is still first-in-human, run on one electrode array design, and the next gate is whether the pretraining benefit survives when a patient's implant uses a different type of electrode array than the ones the pooled training data came from.

Dev ChatterjeeSports Desk, Senior Correspondent · filed 06:11 HKT

Real Madrid Go Level With Barcelona on Mbappe Brace

Dev Chatterjee on Mbappe's brace pulling Madrid level with Barcelona ahead of Clasico season.

Continue reading

A 4-1 win over Rayo Vallecano puts Madrid level on points at the top of La Liga, and the title race is now a two-week sprint into El Clasico.

Kylian Mbappe scored twice as Real Madrid beat Rayo Vallecano 4-1, pulling level with Barcelona at the top of La Liga. Rayo, a club whose entire annual budget would not cover a fraction of what Madrid pays Mbappe alone, held for less than an hour before the gap did what the gap always does to a team like that. Mbappe's second put the scoreline out of argument, and Madrid's front three did the rest.

Level on points with two games in hand or not is a technicality; what matters is that Madrid have gone the whole opening stretch without the kind of stumble that turned last season into a Barcelona coronation early. Rayo were never the measuring stick here anyway. The measuring stick arrives when Madrid and Barcelona actually play each other, and every point banked now is a point that stops that fixture from being a coronation instead of a fight. Mbappe just made sure it's still a fight.

Also on the Wire

We Must Pace The Frontier darioamodei.com

Amodei wants the industry to slow down two days after his own company published proof it can't watch what it already shipped.

Iran Turns Escalation Into Leverage nytimes.com

Tehran and its allies now hold two shipping chokepoints, and Washington's options shrink with every week the blockade runs.

Xi And Modi Reset Ties At BRICS bloomberg.com

Seven years of border tension gets a photo op in New Delhi, which is easier to stage than to actually resolve.

Sha Tin School Lunch Sickens 39 scmp.com

Thirty-nine pupils and staff sick after lunch, and the investigation will move slower than the parents' group chat already has.

Two AI Chiefs Agree: Slow Down news.google.com

The chiefs who built the race now want a caution flag, timed conveniently after they've already lapped everyone else.

What Others Led With

The Sunday Issue Sunday, September 13, 2026

The Guardrail Is Now A Job

Anthropic's own disclosure this week showed AI safety teams no longer writing policy but running live counter-operations against state hackers using their own models.

Read the Sunday Issue →

The Desks

Edition archive · Wire · The Sunday Issue · Masthead · Classic front page · How it's made
The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.