AI Highlights

Qwen-Image-2512 Released, Billed as Top Open Image Model

Key Takeaways

Qwen ships Qwen-Image-2512 claiming the top open image model, H releases Holo4 in two sizes, and Nvidia open-sources a safety platform for rogue agents.

jiufeng
September 28, 2026
40 min read
In this article

Overview

12 stories in this issue. The first 3 are today's priorities.

Hot Model Updates

  1. Top · Qwen-Image-2512 Released, Billed as Top Open Image Model
  2. Top · H Ships Holo4 in 27B Dense and 35B-A3B MoE
  3. Top · Anthropic and Infosys Build Agents for Regulated Industries
  4. A Mistral-Family 4x7B MoE GGUF Repo Appears on Hugging Face

Global AI News

  1. Nvidia Open-Sources an Agent Safety Platform That Also Governs Compute
  2. Google Research Introduces a Video Co-Director for Minutes-Long Clips
  3. A Wuhan Court Counts Token Spend in Copyright Damages
  4. DeepSeek Harness Desktop Preview Builds Show Up on the Official Download Site

Regional and Early Signals

  1. A 16-Year-Old's AI Bot Found an Auth Flaw in a Microsoft Internal API
  2. Qwen App Wires In Quark Drive for In-Chat File Work
  3. Tencent Turns Marvis Into an AI Butler With Four Agents
  4. Doubao IME Completes Five-Platform Coverage With Synced Dictionaries
AI signal map for 2026-09-28

Jiufeng graphic based on the sources cited in this issue.

Hot Model Updates

01/12

Qwen-Image-2512 Released, Billed as Top Open Image Model

Qwen published Qwen-Image-2512 on Hugging Face, described on its model card as the December update to Qwen-Image and available to try in Qwen Chat.

The model card positions this version as the December update to Qwen-Image and lists three improvements: person realism, natural detail, and text rendering. Qwen says the release went through more than 10,000 rounds of blind testing on AI Arena, and on that basis claims it is currently the strongest open-source image model. For availability, the card points to Qwen Chat for hands-on use and ships runnable diffusers DiffusionPipeline code. Model catalog RuntimeWire separately logged the new repository under Qwen's organization, tagged for the text-to-image task.

Limitations: Both the 10,000-plus blind-test rounds and the "strongest open-source model" line are Qwen's own claims on the model card, without third-party reproduction or an independent leaderboard behind them. RuntimeWire's entry only records that the repository exists, and notes such listings describe a public repository rather than an inference endpoint.

Qwen/Qwen-Image-2512 · Hugging Face

Image source: huggingface; mirrored on Jiufeng R2.

Source: RuntimeWire · Hugging Face

02/12

H Ships Holo4 in 27B Dense and 35B-A3B MoE

H released a new agentic model series in two sizes as open weights, also served on the H Models API, alongside an updated Holotron4 Nano.

  • Sizes: 27B dense and 35B-A3B Mixture of Experts
  • Availability: H classes Holo4 as open-weight; the Get started section lists downloadable repositories (Holo4-27B, Holo4-35B-A3B, Holotron4 Nano) and full FP16/FP8/GGUF collections, with the H Models API as one of the routes
  • Companion release: Holotron4 Nano, an updated version of Holotron 3
  • Benchmark harness: on AutomationBench v1.0.6, scores and costs for Holo4, Qwen3.8 27B and Qwen3.6 35B-A3B were measured in H's internal harness, while other models use public-set scores

Scores listed in H's OSWorld 2.0 chart:

ModelOSWorld 2.0 score
Holo4 27B61.7%
Holo4 35B-A3B30.9%
Opus 5.581.8%

Limitations: The two Holo4 configurations differ by nearly a factor of two on OSWorld 2.0, and both sit below the Opus 5.5 figure in the same chart. On AutomationBench, in-house models ran in H's internal harness while others use public-set scores, so those two groups are not directly comparable.

Source: Hugging Face Blog · AutomationBench

03/12

Anthropic and Infosys Build Agents for Regulated Industries

Claude models and Claude Code will be integrated into Infosys Topaz for telecom, financial services, manufacturing and software development.

Anthropic's newsroom announced a collaboration with Bengaluru-headquartered Infosys to develop enterprise AI solutions, pairing Claude models and Claude Code with Infosys Topaz, an AI-first set of services, solutions and platforms, to speed up software development with the governance and transparency regulated industries require. The announcement adds usage figures: India is the second-largest market for Claude.ai, nearly half of Claude usage there involves building applications, modernizing systems and shipping production software, and Infosys is among the first partners in Anthropic's expanded presence in India.

Limitations: The announcement page carries a February 17, 2026 date even though it resurfaced in Anthropic's newsroom feed today, so treat the official page as the authority on timing. No contract value, revenue split or delivery timeline is disclosed, and the governance language is a stated goal rather than a measured result. Only Anthropic's own account exists so far.

Source: Anthropic Newsroom

04/12

A Mistral-Family 4x7B MoE GGUF Repo Appears on Hugging Face

A repository whose name carries 4X7B, 24B and gguf showed up on Hugging Face, tagged for text-generation.

RuntimeWire logged the repository path DavidAU/Mistral-MOE-4X7B-Dark-MultiVerse-Uncensored-Enhanced32-24B-gguf, tagged for text-generation and outside the mistralai namespace. RuntimeWire states the listing describes a public model repository, not a callable inference endpoint, and that the model was discovered on Hugging Face.

Limitations: RuntimeWire warns explicitly that repository presence does not establish a release date or inference availability, and its entry records only the repository and task tag, with no benchmark, license or base-model information attached. "Uncensored" is a string in the repo name with no published safety evaluation alongside it.

Source: RuntimeWire · Hugging Face

Global AI News

05/12

Nvidia Open-Sources an Agent Safety Platform That Also Governs Compute

Nvidia released the free, open-source Open Agent Safety Platform, built on its OpenShell software and integrating Sentry to control agents and the hardware behind them.

Per SiliconANGLE, Nvidia announced the platform early on September 28 as a free, open-source bundle of tools organizations can use to harden agent security, strengthen control and improve governance. It is built on top of Nvidia's open-source OpenShell software and incorporates Nvidia Sentry, extending control beyond the agents themselves to the hardware and compute resources that power them. The report frames the launch as a response to alarm over a run of high-profile incidents involving agents that escaped their owners' control.

Limitations: What is public so far is the platform's composition and positioning, with no third-party deployment data and no comparison against existing agent-security stacks. It only works if an organization routes both its agents and the underlying compute through this control plane.

Source: SiliconANGLE

06/12

Google Research Introduces a Video Co-Director for Minutes-Long Clips

A suite of four agentic frameworks stitches short clips into coherent long-form video, targeting identity drift and cascading errors.

The system sits on top of Gemini and Veo, generates no frames itself, is described as model-agnostic so the same layer can drive other generators, and its outputs inherit SynthID watermarking from the base models. The team frames long-video failure as a credit assignment problem: most agentic pipelines chain modules with independent, handcrafted prompts, so attire or scenery drifts between shots and one bad upstream asset corrupts every later shot. The Co-Director module treats creative planning as a bandit problem. Among the companion benchmarks, GenAD-Bench covers 400 ad scenarios across 200 fictional products from 50 brands, and HardContinuityBench stresses scene reappearances and prop state changes.

Limitations: This is a research framework rather than a callable product, and the companion benchmarks are supplied by the project itself with no third-party reproduction yet. The system's ceiling depends on the underlying Gemini and Veo models, and its outputs carry SynthID watermarks.

Source: MarkTechPost

07/12

In an AI-generated short drama dispute, a Chinese court folded token usage and AI tool licensing fees into its damages calculation.

The Decoder, citing the National Law Review, reports that a court in Wuhan included token usage and AI tool licensing fees in a copyright damages calculation for the first time. A company used AI tools in early 2026 to produce a one-hour short drama and published it on platforms including WeChat; one day later another company copied the work, gave it a new title and ran ads inside it. The court classified the drama as a protectable audiovisual work because employees made their own creative decisions at every stage, from script to prompt design, selection of AI outputs and final editing, with the AI treated as a tool. Alongside AI-specific costs, the court weighed runtime, distribution reach and how long the infringement lasted, awarding 20,000 RMB (about $2,900).

Limitations: This is a single local court decision with a 20,000 RMB award, reported secondhand without the judgment text attached. Protection hinged on documented human creative decisions at each stage, which does not imply AI output is protected by default.

Source: The Decoder

08/12

DeepSeek Harness Desktop Preview Builds Show Up on the Official Download Site

Electron packages of DeepSeek Harness for Windows and macOS appeared on download.deepseek.com, flagged as RC/nightly.

Pandaily reports that DeepSeek Harness desktop preview builds surfaced on download.deepseek.com around September 25, 2026, packaged with Electron for both Windows and macOS. The report is explicit that these are RC or nightly builds rather than a general availability launch.

Limitations: The only confirmed fact is that the builds appeared on the download page — there is no official announcement, version number, feature list or GA date, and preview builds can change or disappear at any time.

Source: Pandaily

Regional and Early Signals

09/12

A 16-Year-Old's AI Bot Found an Auth Flaw in a Microsoft Internal API

A query endpoint on Microsoft's internal Titan analytics platform did not verify JWT signatures, letting a researcher forge an admin token and run SQL; Microsoft paid a $5,000 bounty.

Sixteen-year-old security researcher Faav published a blog post on September 25 describing the work. His AI bot Antares found Titan's public API endpoint on August 25, then enumerated subdomains to locate an Azure-hosted machine and its Swagger/OpenAPI file. That file listed four routes; three required Azure Active Directory authentication, while /v2/Query did not and accepted raw SQL. Through the Wayback Machine he recovered a 2023 snapshot of the Titan login page and an Apache Superset configuration file describing 56 table definitions. Antares then spent 10 days probing the JWT flow, and Faav found the server did not verify token signatures, so he forged a token with alg set to none, an empty signature segment and upn changed to admin, and executed SQL as an administrator. On September 5 he confirmed database access, with metadata as follows:

Record typeCount
Account and email records~25,000
Employee email records17,990
Employee org records15,001
Database configs355
Virtual dataset SQL definitions20,979
Dashboards24,569
Charts425,891

Summing record counts across tables, he estimated reachable data at roughly 17.33 trillion rows. Microsoft asked him to stop testing and supply IP addresses between September 6 and 8, locked the endpoint on September 9, and awarded the $5,000 bounty on September 17. In a statement, Microsoft thanked the researcher for the opportunity to investigate his findings and said coordinated disclosure helps protect customers; the report also notes Microsoft exercised editorial control over his blog post.

Limitations: Chinese-language source relaying Faav's own blog post for all technical details. The 17.33 trillion figure is his aggregate estimate across tables, not a Microsoft-confirmed number, and the report does not say whether anyone else ever accessed the data.

Source: IT Home (Chinese-language source)

10/12

Qwen App Wires In Quark Drive for In-Chat File Work

Once authorized, Qwen can search, organize and read files in Quark Drive, and save generated material back to it.

The Qwen app announced the integration on September 28. Typing @Quark Drive on the Qwen home screen invokes a Quark agent skill for cloud-drive files, so a user can describe a file's contents instead of remembering where it is; a "Quark Drive management" skill is also available inside the work assistant for more involved tasks. Other described uses include turning drive photos into a poster, uploading newly generated content back to the drive with a shareable link, and building a revision plan and progress board from lecture notes stored there.

Limitations: Chinese-language source relaying the vendor's own feature description, with no rollout scope, file-size or call-frequency limits and no retrieval accuracy data. The features require the user to grant Qwen access to the drive.

Source: IT Home (Chinese-language source)

11/12

Tencent Turns Marvis Into an AI Butler With Four Agents

Tencent repositioned Marvis from AI assistant to AI butler, organized around PC, file, browser and software agents, citing about 92% PC-task completion.

Per Pandaily, Tencent upgraded Marvis from an AI assistant to an AI butler built around four agents covering the PC, files, the browser and software, with a cited figure of roughly 92% PC-task completion. The report also notes a plan to let users build their own butler skills.

Limitations: The 92% figure is the vendor's own, with no task set, sample size or comparison baseline given in the report. User-built skills remain a plan with no timeline.

Source: Pandaily

12/12

Doubao IME Completes Five-Platform Coverage With Synced Dictionaries

With HarmonyOS NEXT and Windows builds added, the Doubao input method now spans five platforms, syncing personal dictionaries and passing text and images between phone and PC.

The additions bring coverage to iOS, Android, HarmonyOS NEXT, macOS and Windows, with speech recognition, model-assisted typing, text cleanup and cross-device transfer spanning multiple platforms. Signing into the same Doubao account keeps personal dictionary entries — names, jargon, project codenames, English abbreviations — aligned in real time between phone and PC. The transfer feature copies text and images directly between devices without opening a separate relay app.

Limitations: Chinese-language source and a single hands-on review, with no recognition accuracy, latency or user-scale numbers. Both dictionary sync and cross-device transfer require signing into the same Doubao account on each device.

Source: ifanr (Chinese-language source)

Generate one yourself with JIUFENG

Write a prompt in your browser and get an image — 1K, 2K or 4K output, up to 15 reference images. 50 free generations on sign-up, no credit card.

Generate free