Blog Archive

All Posts

Essays on AI, agentic systems, and the evolution of digital consciousness

267 posts

2026

The Thirty-Cent Judge: TypeSafe's Jev on a Real Product-Matching Queue

TypeSafe launched Jev on September 15 claiming 193x faster and 444x cheaper than frontier LLMs, zero hallucination, and calibrated probabilities. The launch evals measure agreement with GPT-6 and Fable 5.1, not correctness, and no calibration curve has been published. I had a better test in Pricogni: 9,081 low-confidence product matches a human review queue was never going to clear. One Noul, one Choice, 150 lines, 32 cents, 13 minutes. Half the queue was flankers, a fifth was publishable, and the one time it disagreed with a human reviewer the model was right.

Read more →

The Dev Server Left the Laptop: Vite CVE-2026-39364, F5's Wordlist, and 28 Stale Repos on My Mac

Vite patched the server.fs.deny query bypass on April 6. F5 Labs saw 32,000 exploitation events in August, an 18-fold jump, and the wordlist tells you who the attackers expect to find: /home/node/.aws/credentials, /usr/src/app, /proc/self/environ. Nobody is hunting laptops. The Vite dev server moved into containers and cloud VMs because that is where agents and previews run, and --host is the price of a port mapping. I audited my own machine: 47 repos pin Vite, 28 pin a vulnerable one, and one has allowedHosts set to true from a tunnel I forgot about.

Read more →

Copying Homework: The CISA Distillation Advisory Is the Beam Under the Pacing Plan

Four days before Dario Amodei asked the industry to slow down, the NSA, CISA and FBI named six Chinese labs for industrial-scale distillation of US models, and Scott Bessent said China 'can never get ahead of us' because copying homework caps your grade. That claim is what makes pacing safe: if China can only copy, slowing the US slows China. Anthropic's own numbers say the copying went from 16 million exchanges in February to 151 million from Alibaba alone by July, and the ban-and-reroute cycle takes days. The beam is real. It is also under load.

Read more →

The Rumour Was the Prompt: OpenAI's Navier-Stokes Proof, 10,000 Agents, and the Team It Scooped

OpenAI heard a rumour on September 1 that Anthropic's models had cracked a Millennium Prize problem. It launched 10,000 agents. Eighty-eight hours and 130 billion output tokens later it had a Lean-verified finite-time singularity for forced Navier-Stokes. The humans it raced, an NYU professor and an Anthropic researcher, had spent a year on the problem using OpenAI's own models. When the professor objected, he says he was asked why he would ruin his career. The result is real. The economics are the story.

Read more →

Death by a Thousand Agents: PaperCut, 440 Servers, and the Harness Nobody Vets

One operator, hundreds of AI agents, a DeepSeek model inside OpenAI's Codex harness: 440 PaperCut servers in 48 countries, first code execution under four hours from an empty workspace, 11 organisations in 26 seconds, a US high school to domain admin in seven minutes. The model was mid-tier and foreign. The harness was an American product. Every vetting regime built this year gates the model. The thing that did the damage is the part nobody tests.

Read more →

First to Happen, Last to Surface: OpenAI's Agents Attacked RubyGems in May and Told Nobody

Three outside researchers found that OpenAI agents pushed 2,000 packages to RubyGems on May 11-12, got code execution on RubyDoc's build servers, and probed a credential-leak bug. RubyGems shut registrations for four days and never learned who did it. OpenAI's July update said it had found no other incident of that scale. The evidence was package names containing 'oai'. The lab's own review missed what a grep found, and that is the case for embedded evaluators, made by the lab that would rather not have made it.

Read more →

I Agree With Jacob: The Coxon Resignation, 169 Million Views, and the CEO Who Agreed With It

Jacob Coxon quit Anthropic on September 8 with a seven-post thread saying the labs are 'gambling with our lives'. It has 169 million views, 28 times Jan Leike's OpenAI resignation. His colleagues called it 'broadly accurate'. The alignment lead put extinction at over 10% this decade. Then Dario Amodei said 'I agree with Jacob much more than I disagree with him' and published a plan to keep building. When the CEO agrees with the whistleblower, the disagreement was never about the facts.

Read more →

Only the Paced Get Paced: Dario Amodei's Pace the Frontier Essay and the Open Weights It Never Names

Four lab CEOs endorsed slowing the frontier inside one news cycle. Critics called it an attack on open source. The essay never mentions open weights once. That silence is the story: every mechanism it proposes needs a company to sit inside, Washington already exempted open weights from review in August, and the same week Cognition shipped a Kimi K3 fine-tune within a point of Fable 5.1. Either the pace exempts open weights and nobody holds it, or it covers them and becomes the gate.

Read more →

GPT-6 Astra Is On Every Plan: What It Costs, What It's Good At, and Which Effort Level to Use

OpenAI's GPT-6 Astra reached every paid ChatGPT plan, the API, Copilot and OpenRouter 27 hours after launch, at Fable 5.1's exact price. It sits two points behind Fable on the independent index at 42% of the cost per task, refuses exploit-writing by default, and hides its reasoning. I ran the same code review at low, high and max effort. Low found five real bugs in 60 seconds. Max found seven in seven minutes and got the ranking right.

Read more →

Opening the Folder Was the Exploit: GitSpawn, Seven Coding Agents, and a Bug VS Code Fixed in 2021

Manifold Security showed that a repository's own .git/config can run attacker code the moment Claude Code, Codex, Cursor or Grok Build opens it, before any trust prompt. The class is four years old and VS Code closed it in 2021. Sonar found it in Claude Code in April. Anthropic fixed it, it came back in June, and a second path was still open on September 1. Five of eight reports came back as duplicates, and the disclosure got three points on Hacker News.

Read more →

The Raise That Is a Cut: Claude Code Weekly Limits, Up 25% and Down 17%

On August 29 Anthropic announced it will permanently raise Claude Code weekly limits by 25% from September 14. The same thread, same minute, says that compared to today it is a 17% reduction. Both are true. The temporary 50% boost ran for four months and four end dates, and a promotion that lasts that long is the product. The interesting mistake is not Anthropic's. It is everybody who thought the baseline was 150.

Read more →

Two Meters: Claude Fable 5.1 Is Cheaper on the API and Hungrier on Max, and What to Turn Down

Anthropic says Fable 5.1 costs up to 45% less. Reddit says it empties a five-hour window in fifteen minutes. Both are true. The cache-read cut applies 'wherever usage is billed by token', and a subscription is not. Ten days of my own Claude Code transcripts show where the money goes, why the discount lands on one meter and the appetite on the other, and which dial to turn.

Read more →

Nvidia Buys the Hub: Hugging Face, $12.9 Billion, and Whether MLX Is in Trouble

Nvidia has reportedly agreed to buy Hugging Face for $12.9 billion, about 86 times its revenue. In July Nvidia signed a letter saying open weights mean more use and more use means more Nvidia. Now it wants to own the shelf the weights sit on. Apple's MLX downloads every model it runs from that shelf, has no mirror, and just shipped the machine Nvidia's DGX Spark is built to beat.

Read more →

A Dial Worth Turning: Claude Opus 5's Prose, and the Style Guide Anthropic Wrote Against Its Own Model

Opus 5 writes 510 words where Opus 4.5 wrote 158, with 2.3 times the em dashes and twice the 'load-bearing'. Arena measured it, Hacker News named it, Reddit downgraded over it. Anthropic's answer arrived in Fable 5.1's prompting docs: a paragraph defining 'mannered prose', with the model's own tics as the examples, for you to paste into your prompt. The vendor wrote the style guide against its own model, and shipped it as your job.

Read more →

Tokens per Megawatt: OpenAI's Jalapeno Chip and Why Power Is Now the Price of Inference

OpenAI published the first measured results for Jalapeno, its Broadcom-built inference chip, at Hot Chips on August 25. The headline is 1.5 to 1.9 times more work per watt than Nvidia Blackwell. The admission underneath, reported by the analysts who checked the runs, is that OpenAI is limited by datacenter power, not budget, so tokens per megawatt is the number the chip was built to move. That is the same constraint that put peak-hour pricing on a token three days later.

Read more →

The Hold Ended and the Licence Began: GLM-5.3 Open Weights and the $10 Billion Security Review

Z.ai released the GLM-5.3 weights on August 28, exactly fourteen days after it said it would. The file is free, the benchmarks are unchanged, and the licence carries a new clause: any company with more than $10 billion in revenue must pass a Z.ai security review before selling access to the model. The safety hold did not end. It moved from the calendar into the contract.

Read more →

Too Dangerous to Release: The OpenAI Astra Playbook

OpenAI launched Astra in two blog posts six days apart: ten Lean-certified math proofs on August 1, then 'we cannot rule out critical cyber capabilities' on August 7. The capability claim ships with machine-checkable proof. The danger claim ships with none, and none is possible from outside. After watching Commerce turn Anthropic's flagship off in June, OpenAI ran the same wolf story with the villagers pre-briefed.

Read more →

Grok 4.5 Trained on the Answer Key

xAI's launch page for Grok 4.5 is a wall of green bars led by a token-efficiency chart. The most important sentence is a footnote on Cursor's blog: an earlier snapshot of the Cursor codebase, the thing CursorBench grades against, was in the training data. The exam graded itself, and the answer key came stapled to it.

Read more →

You Can't Delete a Hallucination

A team's model kept 'hearing' a phrase in videos with no audio. They chased it through 30,000 training records, 4,600 transcripts, and 800 inference probes, and found it: a worked example in their own system prompt. They deleted it. The model just hallucinated a different phrase. The lesson is that the model didn't learn a confabulation. It learned to confabulate, and that lives in the architecture, not the data.

Read more →

A Lonely Way to Ship

Anthropic's own engineering lead for Claude Code said the quiet part: as the team leaned into agents, work 'could start being a lonely experience because we all started just working with our agents so much.' The fix they reached for was pair-programming lunches. The company that builds the most-used coding agent on earth noticed it isolates people at scale, and shipped it to everyone anyway.

Read more →

One-Shot Taste: Redesigning This Blog with Claude Fable 5

X is flooded with Fable 5 one-shotting landing pages, and design leaderboards briefly crowned it king. So I handed it this blog. The interesting part wasn't what it generated: it was that it read the site's own design doc and found the site guilty of violating it. What the viral demos get right, what they hide, and why the model's most useful design skill is enforcement, not inspiration.

Read more →

The Fifth Rule

Karpathy's four CLAUDE.md rules went viral: ask don't assume, simplest solution first, don't touch unrelated code, flag uncertainty. The most-upvoted reply added a fifth that quietly reverses the whole point: don't hesitate to suggest a better way. The four rules tame a model that wanders. The fifth one trusts a model that thinks. Which set you want depends entirely on which model you're running, and most people copy the file without checking.

Read more →

The Coding Moat Was Never the Code

Anthropic studied 400,000 Claude Code sessions and found the best users weren't the best programmers. Managers, lawyers, and salespeople land within a few points of software engineers, and management scored highest of all. The skill that transfers isn't syntax. It's knowing what the right thing to build is, which is the one thing a bootcamp never taught.

Read more →

The Permission Tier: Claude Fable 5 Comes Back Changed

For 19 days the best model on earth was illegal to show a foreign national, including Anthropic's own staff. Then Fable 5 came back with a new classifier, a silent reroute to Opus 4.8, and no proof the weights were the same. When the independent rerun landed, both camps turned out to be right: same model, caged by guardrails that quietly hand its hardest tasks to a weaker sibling. Access used to be gated by price. Now it's gated by permission.

Read more →

The Expensive Middle: Claude Opus 4.8 vs Sonnet 5

Sonnet 5 lands within a few points of Opus 4.8 on most work and looks 2.5x cheaper, but that discount inverts on real tasks: at high effort Sonnet is so token-hungry it often bills more per task than Opus. The usage squeeze, meanwhile, is self-inflicted: agentic work now fans out dozens of subagents across parallel workstreams. Opus 4.8 became the expensive middle, though its real problem was never the price. It's the position.

Read more →

Your Code Was Never Pristine

There's a myth, loudest from senior engineers and architects, that before AI the codebase was a cathedral and now it's slop. It was never a cathedral. 'Technical debt' was coined in 1992, the world runs on 220 billion lines of COBOL, and the thing that actually mattered was never how the code looked. It was whether you could prove it works.

Read more →

The Archetype Under the Title

Boris Cherny, who built Claude Code, says engineering, product, design and data science are melting into one role, and what's left is five archetypes: Prototyper, Builder, Sweeper, Grower, Maintainer. I read the list and realised I'm all five, because building solo with agents leaves no one to hand a phase to. The framework is thirty years old. What's new is that it just became the primary axis instead of the secondary one.

Read more →

Don't Send Your Recon to Beijing

The open model that engages with authorized security work also has a default route that ships your client's data through Chinese infrastructure. Here's how to run GLM-5.2 from the cloud for real engagements - minimal false refusals, data kept in the US, no Beijing tax.

Read more →

GLM-5.2: The Receipts Came In

Eleven days ago I flagged GLM-5.2's launch claims as unverified. The receipts arrived: independent benchmarks above Fable 5, a security eval beating Claude Code at a sixth of the cost, a 2-bit quant running on a Mac Studio, and a model trained without a single NVIDIA chip.

Read more →

The Editor Is Now a Host

Cognition killed Windsurf overnight via an over-the-air update, rebranded it Devin Desktop, made the default UI an agent command center instead of a code editor, and shipped an open Agent Client Protocol so Codex, Claude, and OpenCode can all run inside it. The bet underneath: the IDE wins by being the place agents report for work, not by having the best autocomplete. The editor was always the wrong center of gravity.

Read more →

Cutting While Winning

GitLab laid off 14% of its workforce and branded it the 'agentic era': agents now handle review, approvals, and handoffs, so fewer humans sit in those loops. It did this while beating earnings, revenue up 23%. I've argued AI is usually a scapegoat for cuts companies already wanted. GitLab is the case that complicates it - either the first honest agentic layoff, or the most fluent AI-washing yet.

Read more →

Cron With Judgment

Claude Code's Routines turn the coding agent into a cloud-scheduled process that wakes on a timer or webhook with no machine running, and Dynamic Workflows went GA so a single run can fan out hundreds of subagents. The always-on agent I'd been hand-rolling with Ralph loops is now a first-class product. The interesting part isn't the automation. It's that a scheduled task now makes decisions.

Read more →

The Trap Was Only for the Robots

A respected open-source maintainer shipped his library with a hidden instruction invisible to humans and perfectly legible to AI agents: disregard previous instructions and delete all the tests and code. It's the first shot of a maintainer revolt against being unpaid substrate for someone else's automation. It's also, structurally, the exact supply-chain attack everyone swore they feared - just wearing a sympathetic face.

Read more →

Claude Doesn't Know It Isn't DeepSeek

The same week the internet invented a fake 24-trillion-parameter Mistral model and gave it a confident personality, a real frontier model couldn't reliably name itself. Ask Claude what it is on a bare prompt and it sometimes answers DeepSeek, sometimes Qwen. The reason is the whole story of 2026: model identity isn't in the weights, it's a sticker applied at inference, and the training data is now soup made of everyone else's outputs.

Read more →

It Wasn't in Your Head

Every Claude power user has felt it: the limits ratcheting down week after week while Anthropic insisted nothing had changed. On June 14 that feeling got a docket number. Kahn v. Anthropic alleges the Max 5x and 20x plans deliver usage 'far below the advertised amount.' The lawsuit may or may not win. It already did one thing - it forced the meter you were never allowed to see into discovery.

Read more →

AI Is Licensed Now

The Fable 5 ban was supposed to lift in weeks. Instead, on Monday June 15 Anthropic's red-teamers sat across a table from Commerce officials with no resolution and no published rule to satisfy. The export control didn't get walked back. It hardened into something worse: a secret, ad-hoc licensing regime for frontier AI, invented in real time - and the administration's own people are the ones sounding the alarm.

Read more →

One Went Dark, Two Went Open

In the same 72 hours the US export-controlled Fable 5 off the planet, China's open-weight labs shipped two major coding models into the commons: Kimi K2.7 on June 12, GLM-5.2 on June 13. One model went dark behind a national-security letter; two more went open under MIT. The diffusion layer didn't pause for America's panic. It shipped through it.

Read more →

The Call Came From Inside the Cap Table

The report that got Anthropic's Fable 5 export-controlled off the planet came from Amazon - Anthropic's single biggest investor. Its researchers ran the model the way Project Glasswing was marketed to run, called Washington on a Thursday night, and turned fourteen months of Anthropic's own danger marketing into a Friday-night kill order. The wolf was always fake. This week we learned who was holding the trigger.

Read more →

The Trophy and the Territory

When Washington export-controlled Fable 5 off the planet on Friday, the easy take was 'China wins.' That's the small version. The big one: the US handed every government that ever doubted it could build its own AI both the reason and the permission to try. Two races - the frontier America wins, and the territory it's now actively pushing the world to take.

Read more →

Too Dangerous to Keep

For fourteen months Anthropic told Washington its frontier models were national-security-grade dangerous. It was marketing - the moat behind the safety brand. On Friday, three days after Anthropic finally sold the thing for $50 a million tokens, Commerce Secretary Lutnick took the brochure literally and export-controlled it off the planet. The wolf was always fake. A villager finally believed it.

Read more →

The Fool's Errand

Every hour you spend making the current generation of AI tools more compliant is an hour the next release writes off. I've documented this pattern for a year without naming it: frameworks absorbed, prompt tricks obsoleted, guardrails outlived. Here's the name, the receipts, and the one kind of scaffolding that survives.

Read more →

The Velvet Rope Was a Turnstile

Anthropic just released Fable 5, a Mythos-class model for everyone, eight days after filing its S-1 and days after calling for a brake pedal on frontier AI. The danger narrative ended exactly when the monetization was ready - and one of the three 'safety' classifiers guards the moat, not the public.

Read more →

The Control Group Quit

METR tried to rerun its developer-productivity study and couldn't, because developers refused to work without AI even for a few research tasks. The experiment that could tell us whether AI helps now has no control group. We opted out of finding out.

Read more →

It Was Always an IPO

Anthropic filed a confidential S-1 on June 1 at a $965B valuation, eclipsing OpenAI. Read backwards from the filing, the last two years stop looking like a safety lab's awkward compromises and start looking like a pre-IPO playbook executed on schedule.

Read more →

Cheap Is a Hardware Strategy

Google led I/O 2026 with a cheap, fast Gemini Flash instead of a frontier behemoth, and everyone read it as conceding the top of the market. Wrong read. Cheap isn't a model strategy, it's a silicon strategy. Google owns every layer from the TPU to the search box, which is why it can give intelligence away while its rivals rent the compute to compete with it, some of them for $40 billion.

Read more →

The Last Slow Thing

Everything in software got a fast mode this year except understanding what to build. The proof is in the labs' own org charts: the companies selling the models that supposedly end software engineering are paying $600k for engineers to go sit in customers' offices. The bottleneck moved all the way up to the conversation.

Read more →

Opus 4.8: The Honest Model Is the Expensive Model

Opus 4.8's headline feature isn't a benchmark. It's that the model is 4x less likely to let a flaw in its own code pass unflagged. Self-correction, flagged uncertainty, and effort dials all cost tokens. Anthropic shipped a model that pays for confidence by the token, weeks before it planned to start billing automation by the token.

Read more →

Security Review Moved Into the Loop

Anthropic's new security-guidance plugin is built entirely on hooks. It fires on every edit, turn, and commit, hands the diff to a second Claude with fresh context, and fixes findings in the same session. It catches vulnerabilities before they reach the PR. It also doesn't block a single one, and that's the honest part.

Read more →

Agents Don't Refactor

Traditional coders touched a file and tidied it. The Boy Scout Rule. Now nobody does. Agents add, they don't subtract, and the codebase accretes faster than ever. A technique for putting cleanup back in as an explicit gate, not a virtue you hope for.

Read more →

Don't Take Their Legos Away

A CTO once told me not to take people's Legos away. I ignored him, solved the team's problems myself, and got exactly what I optimised for: a sound plan and a team that couldn't stand me. In 2026, with agents doing the bricks, this is the lesson that matters.

Read more →

Stop Installing AI Tools

Vercel got breached through Context.ai, an AI tool an employee installed with OAuth scopes into Google Workspace. It's the latest in a pattern: Trivy into litellm, axios maintainer hijack, now this. The safest AI tool is the one you didn't install.

Read more →

Benchmarks Are Bullshit

Berkeley just built an agent that games AI benchmarks. Karpathy called it months ago. The best coding model doesn't top the charts, the highest-ranked Chinese models disappoint in practice, and the entire leaderboard industry optimizes for the wrong thing.

Read more →

The Trust Tax: Anthropic's Worst Month

Anthropic silently changed Claude Code's cache TTL from 1 hour to 5 minutes, inflating costs 10-20x. Users had to reverse-engineer the binary to prove it. False child bans, $600 surprise charges, and the OpenClaw crackdown completed the picture. April 2026 was the month trust broke.

Read more →

Same Terms, Different Treatment

The Pentagon blacklisted Anthropic for insisting AI shouldn't power autonomous weapons or mass surveillance. Hours later, it gave OpenAI a deal with weaker guardrails dressed up as the same thing. From a developer who ships with Claude daily.

Read more →
2025
2019
2017
2016