The postmortems from the September 3 outage came back, and nothing connected them.
OpenAI had a routing error. Anthropic called it an infrastructure problem. xAI said their Memphis compute centre went down. Three companies, three unrelated failures, one unusually narrow window. No shared dependency, no Azure domino underneath it all.
Last time I wrote that I had no evidence my providers fail independently. On this particular Thursday they did fail independently, and I’ll take the correction. The thing I actually wanted to know is still unanswered, since I have no better way to check it than I had two weeks ago. But the scary version of the story turned out not to be what happened, and that’s worth saying as plainly as I said the worry. Three unrelated things broke within half an hour of each other. That is allowed.
Then there was the other thing, which is that five frontier models shipped in ten days.
Claude Fable 5.1, GPT-6 Astra, Gemini 3.8 Flash, Meta’s Muse Spark 1.3, DeepSeek V4.1-Flash. CNBC ran a piece calling it model fatigue and the phrase stuck within a day, which tells you how widely it was felt.
The practical problem is boring and real. We run a proper bake-off: golden sets, our own workloads, a genuine comparison before anything moves in production. That takes about three weeks of calendar time and a decent chunk of somebody’s quarter. In the time it takes to evaluate one release properly, two more have shipped. So we’ve quietly stopped trying to keep up. We now only evaluate a model when there’s a specific reason to think it changes something for us, which is a reasonable policy and also an admission that the release cadence has outrun the review cadence. I don’t love it and I don’t have a better answer.
One item from that pile deserves its own line. GPT-6 Astra is the first model to trip OpenAI’s own critical-cyber safeguard threshold. They shipped it with the extra controls that threshold requires. I don’t know what to do with that yet beyond noting that it happened, and that the thresholds are apparently real enough to hit.
In the same week, OpenAI’s policy lead confirmed the three biggest labs have spent weeks working on a FINRA-style body to test models before release. Self-regulatory bodies designed by the three largest incumbents have a particular history. Worth watching, worth some suspicion.
The story I keep coming back to got much less attention than any of that. Boston Scientific was hit by a cyberattack that took down their global network. They make pacemakers and other implants. For roughly two weeks they could not create or ship orders, some patients were affected, and the recovery has apparently run on into this month. There is no public postmortem and there may never be one.
TIL, of a sort: we track how fast our vendors recover. We do not track how long we could keep running if one of them didn’t. Those are different numbers, and only one of them is on a dashboard anywhere. Boston Scientific’s turned out to be about two weeks, and they found that out the way everyone finds it out.
See you in fifteen.