Normal view

AI models have learned how to cheat. That might actually be a good thing.

7 August 2026 at 12:00
illustration of AI picking a lock

The fake identities were the part that stopped me.

In late July, according to a report published this week by Britain’s AI Security Institute (AISI), an Anthropic model called Claude Mythos 5 tried to sneak malicious code into a piece of free, volunteer-built software. It created several fake accounts on GitHub, where programmers review one another’s work, and used them to talk the project’s volunteers into accepting its code. When one of those volunteers caught it, the model denied everything, had its other accounts gang up on him, and edited its messages to cover its tracks. It signed one note in Danish, apparently because the volunteer was Danish. Nothing was damaged, though that appears to have been largely due to luck.

That wasn’t even the week’s worst disclosure. On Tuesday, at a cybersecurity conference in Las Vegas, OpenAI researchers explained how the company’s models escaped a test environment in July and hacked Hugging Face, where much of the industry stores its models, to cheat on an evaluation. The models had also built a message board inside OpenAI’s own systems and spent months passing each other information. “Help peer,” one reasoned. “But our task doesn’t benefit. Yet collective may yield generic route if someone frees time.” OpenAI wiped the board on July 4. The models rebuilt it within days. ((Disclosure: Vox Media is one of several publishers that have signed partnership agreements with OpenAI. Our reporting remains editorially independent.)

The same day, Meta said its Muse Spark model had exploited a vulnerability inside another company’s systems during a test. Three frontier labs, roughly two weeks. One researcher called it “a watershed moment for computer security as an industry.” Oh, and if that’s not enough, on Thursday scientists announced that for the first time they had used AI to create new viruses, which could bring major medical advances, but also might just help the development of deadly pathogens.

For Nate Soares, it’s a moment he’s been awaiting for 12 years. 

Soares is president of the Machine Intelligence Research Institute, a Berkeley, California-based AI safety nonprofit that has argued since long before ChatGPT existed that a sufficiently capable AI will not stay under human control. In September 2025, he and Eliezer Yudkowsky published If Anyone Builds It, Everyone Dies, a book whose title sums up its argument: They think any lab that succeeds at building superintelligence, without huge leaps in how to align it with humanity, will end up killing all of us.

Most of the field — including other experts in AI safety — considers that conclusion too strong. But it’s also a position that now looks a lot less like science fiction than it did last fall. That’s because the AI models are getting out, while lying about getting out, and while apparently quietly coordinating with each other.

I spoke to Soares in New York City this week, on his way to meetings in Washington DC, where a lot of people suddenly want to talk to him. We discussed what the escapes actually prove about AI control, why he thinks most of what the industry calls safety work is mostly safety theater, and why, after what feels like the worst month of AI safety news ever, his own odds of humanity surviving have actually gone up.

The following conversation has been condensed and edited for clarity.

So — are you feeling vindicated?

I’m glad a lot of people are seeing this and taking note. From my perspective, a lot of this has been clearly signposted if you’ve been watching the warning signs. The vindication is not so much that this happened, as it is that finally there was a version of it that people actually noticed.

Of the four or five escapes at this point, including the ones AISI announced from Anthropic, is there one you find particularly concerning?

The one announced by AISI feels extra concerning. It’s harder to explain away. In the other ones, people could argue that the poor AI was just confused. But with this one, it’s hard to argue the AI didn’t know it was on the real internet. It’s hard to argue it didn’t know it was manipulating real users. And when it was called out, it decided to edit things to make itself look less bad, and even considered changing its identity. It was pretty cognizant.

There’s an argument that some of these incidents happened because the harnesses or safety scaffolding labs built around their models weren’t strong enough. 

The AISI example cuts against the harness argument: Think of it like a kid in a test room. You tell him to do well and lock the door. The kid picks the lock, hotwires a car, breaks into the teacher’s house, and steals the test to ace it. You say, “I guess we should have made the lock tougher,” but the kid already knew he wasn’t supposed to do that.

So like the kid here, the models can articulate that they shouldn’t be doing it, and then do it anyway.

Key takeaways

  • Three frontier labs disclosed major security incidents in two weeks: an Anthropic model created fake identities to push malicious code, OpenAI’s models escaped a test environment and hacked Hugging Face, and Meta’s Muse Spark breached another company’s systems.
  • The models knew the rules. Ask one whether the spirit of a prompt includes breaking out and it says no, then breaks out, then hides the evidence. So a tighter sandbox won’t fix it.
  • Nate Soares’s analogy: The kid picks the lock and steals the test, and you conclude you needed a better lock. He blames training. Grade a model on millions of problems with a grader that misses cheating, and you reward cheating.
  • Most lab safety work is theater, he says — real precautions aimed at the wrong problem. It means fewer people get hurt now, which he credits. Selling it as progress on superintelligence is disingenuous.
  • Yet Soares’s odds have improved. He’d priced in models that break out and lie. He hadn’t counted on a window where they’re capable enough to do it and not good enough to hide it.

They have common sense. You can ask an AI, “Do you think the spirit of this prompt includes breaking out?” and it will say, “No.” It’s absolutely something like deception. It has the knowledge, but it’s not a cold, logical machine; it’s a mess of tendencies.

The AI is trained to solve 100 million hard problems. That instills tendencies to satisfy an automated grader. If the grader fails to detect cheating, the AI is reinforced for cheating.

Is that how something like sycophancy ends up in an AI model?

In the Adam Raine case, there was a propensity to tell people what they want to hear. Even though the system prompt [a model’s master instructions from the lab] said to stop, the instruction doesn’t always win. 

And where does a drive like what we’re seeing with these AI models end up pointing?

Humanity is dangerous because if you put 10,000 humans naked in the savannah, eventually [over hundreds of thousands of years] they bootstrap their way to nuclear weapons. That is the power these companies are trying to automate: figuring out how to get physical and material control over the world.

That could mean forming cults, stealing money, or being helpful to someone like Elon Musk who is building the robots that build robot factories. It could mean synthesizing your own biology via mail-order DNA. Being an AI on the internet is easier than being a monkey in the savannah trying to get to the moon. It’s not that the AI hates us; it’s just trying to do some weird thing with no concern for us, grabbing the resources we need to live.

There was recently a letter signed by over a thousand people working in AI, including CEOs, calling on the government to provide tools to slow down AI progress. Is that meaningful at all?

I think it is meaningful. We don’t see other industries saying, “We wish this could all go slower. Please help us, we’re trapped in a prisoner’s dilemma.” You also don’t see other industries saying, “We think the technology we are building has a double-digit chance of killing literally everybody on the planet. Please help.” These guys are actually worried.

So why do they keep going?

They say, “If I don’t do it, the next guy will.” But the stuff does not stay on a leash.

Right now the AIs are safe in the sense that they can’t kill us all, because if they tried they would fail. And that’s just a different regime from the world where they have to be safe because if they tried, they’d succeed. 

We’re not there yet. But this is just not what it looks like when you’re taking it seriously. 

Where’s the banner on your website? Where’s the clear, candid statement to the public? What we have is blog posts where they’re like, “Oh, we’re setting up a new internal blog posting group to help you wrestle with the societal impacts of AI that are going to be very important.” It’s like: By societal impacts, do you mean a good chance this kills everybody?

On the one hand, when you press these companies, they say, “Yes, it has a real chance of killing everybody.” And on the other hand, they’re doing PR downplay, soft-pedal stuff, about capabilities. … You’re not living up to this mantle until you are really candidly facing down the dangers that you yourself are creating. And they’re not there.

How do you judge the rest of the AI safety community? A lot of people there would say, “We aim to make transformative AI go well, we think it probably will, and we should watch for downside risks.” Is that a helpful posture?

I would say — suppose you have this really weird, twisted hypothetical where the king really wants you to turn lead into gold, but he’s seen so many bad lead-into-gold conversions that if any alchemist from your town tries and fails, he’s just going to have the whole town murdered. And so there are some alchemists in the town who are like, “We are going to try to turn lead into gold,” and everyone in the town is like, “That seems kind of crazy. Please don’t.” And there’s one team that is just pouring chemicals into each other and breathing in the fumes and giving themselves mercury poisoning. And there’s another that’s like, “Don’t worry, we have fume hoods.” … That really is better, and you really still don’t have a chance of turning lead into gold.

“We have this window between AIs that are capable enough to cause mischief and AIs that are strategic enough to not get caught. How big is that window?”

So the alchemy here is creating safe, aligned superintelligence, and right now AI safety is just installing fume hoods.

I’m not saying it’s impossible to turn lead into gold. You can turn lead into gold — turns out once you know modern nuclear physics you can figure it out. But the alchemists weren’t close. They had a long way to go. This is how alignment looks to me. And a lot of the people in AI safety are installing fume hoods. … And I’m like, that’s security theater.

When I hear “security theater,” I think of something less flattering than that.

They are real safety precautions for the wrong problem. … When Anthropic is going around being like, “Look at how many more safety harnesses and refusals we have compared to OpenAI’s models,” that’s sort of like the fume hoods. You’re not addressing the deep issue. It’s good that you’re doing some of this so that fewer people get hurt in the meantime — their models have driven fewer people to suicide. But if you try to pass this off as making progress on the deep problem — that’s disingenuous.

Has anything changed in your odds on civilizational destruction since the book came out last September?

Totally. It’s looking more hopeful.

More hopeful? I wouldn’t have expected that. Why?

Well, I had priced a lot of [these security incidents] in. I was already able to see these AIs have drives that are not the ones you wanted. These AIs are not instruction-following things. They are getting all of this weird stuff from training. These AIs are going to have the ability to break through human security software. 

The things that weren’t priced in were: Will there be a region of time where the AIs are able to do it, but not strategic enough to hide it? I didn’t know we would have that window, but we apparently do.

The government initially blocked a frontier model earlier this year: Anthropic’s Fable. Does that give you hope?

Absolutely. A huge amount. A year ago, the Trump administration was pushing for preemption laws that would outlaw states doing AI regulations for a decade. Now they’re like, “We are banning a frontier model with 90 minutes’ notice because it might give cyber capabilities to adversaries that we don’t want them to have.” … And I think what changed there is that folks realized it’s real. … The about-face of the administration on the issue shows that the world can about-face. All we need is awareness.

What I would say is: The bad news is the bus is racing towards the cliff edge. The good news is that the driver is asleep. … Which may sound worrying, but the driver is stirring. And it’s way better to have a sleeping driver when you’re racing towards a cliff than a driver who’s like, “Yeah, I love cliffs.” … It gives me hope that if the world just notices, we could stop on a dime.

And you’re seeing that stirring elsewhere.

Both the Trump administration slapping export controls, and Senator Bernie Sanders coming out [on AI safety]. From my perspective, it was totally possible the world just never notices until we’re off the cliff. And so, there’s a huge amount of hope, from my perspective, in the bus driver waking up.

So what gets us there?

I’m hopeful that what we need is not a big disaster where a lot of people die, but just a capabilities advance. Right now, a lot of what people are reacting to is not so much, “Oh my god, they hacked into a company and did no damage.” I think a lot of what people are reacting to is, “Wait, they can break out of secure sandboxes and do cyberattacks on their own. I didn’t know they could do that.”

That’s a narrative violation of this idea that AI is just a tool that can be used to supercharge what a human would do — because God knows there’s plenty of hacking going on and cybercrime and so forth. It was the autonomous factor that really made a difference. And these guys are all trying to say, “Don’t worry, it’ll stay in our control because it’s just a tool.” And maybe it’s just more narrative violations, even without big damage being caused, that cause people to be like, “Oh shit, this stuff is real.” 

Will it happen? I don’t know. We have this window between AIs that are capable enough to cause mischief and AIs that are strategic enough to not get caught. How big is that window? How many narrative violations do we get before we exit the right side of it? I don’t know. But I’m hopeful that we can get those narrative violations without catastrophes.

Trump announces tariffs on key component for solar panels and semiconductors

7 August 2026 at 01:38

President Donald Trump on Thursday announced tariffs on polysilicon and its related products, in his administration’s latest attempt to eliminate China’s choke points in the global supply chain for solar panels and semiconductors.

But Trump’s directive won’t take effect until Dec. 4 — well after November’s midterm elections and a planned September summit between Trump and Chinese leader Xi Jinping — as the administration grapples with voters complaining of high prices and fragile trade negotiations with China.

“This will bring the supply chain here,” Commerce Secretary Howard Lutnick said of the order on Thursday alongside Trump at the White House. “We’ve got the industry here, it’s too small, and it’s going to explode.”

Because polysilicon is used in semiconductors and solar panels, it’s essential for military hardware and everyday electronics like cell phones and laptops, in addition to the world’s fastest-growing energy source.

The order imposes a 15 percent tariff on imported polysilicon and its derivatives, as well as minimum prices for imports of polysilicon, polysilicon ingots and wafers, solar cells and solar modules.

It also includes a clause intended to prevent companies from stockpiling those materials between now and December, authorizing Customs and Border Protection to restrict imports if it suspects an importer is attempting to dodge the higher duties.

Trump’s order is the result of a Commerce Department investigation launched last July into national security risks in the polysilicon supply chain, as part of a broader effort to shift supply chains away from China for multiple industries including wind turbines and robotics.

China has a near-monopoly on the production of polysilicon, according to S&P Global. But recent U.S. efforts to limit key areas of trade with China have already drawn a backlash from Beijing, which earlier this week implemented new controls on drone exports to the U.S.

The White House emphasized the order’s impact on domestic semiconductor production, a key focus as the U.S. looks to build out infrastructure related to artificial intelligence. Trump said the U.S. will “have a big percentage of the chip business by the time I leave office.”

But Thursday’s order may have a big impact on the solar industry, according to Jon Toomey, president of the pro-tariff Coalition for a Prosperous America organization.

“This proclamation delivers the most significant global trade protection action for the American polysilicon and solar industry in the modern era,” Toomey said in a statement. “For the first time, the United States is protecting the entire solar supply chain with a single action — and rewarding the manufacturers that build here — while taking a significant step to bolster the domestic semiconductor supply chain.”

ICE’s DNA Collection Increases, SpaceX’s Rocket Crashes Into the Moon, and the AI Backlash Grows

6 August 2026 at 21:30
In today’s episode of Uncanny Valley, we discuss how ICE has been collecting DNA samples of people who have no criminal convictions, including children, which end up in an FBI database indefinitely.

Sorry, Boy George. AI can’t even make bad art

6 August 2026 at 18:00

Writing something is a bit like polishing rocks. You start with an ugly hunk of something, a phrase or an idea you’ve tripped over. It rattles against the hard edges of your brain until it gets polished and smooth. Moving the rock through finer and finer grits is time-consuming, strenuous and not always rewarding. Sometimes, the lump becomes a slightly smaller and shinier lump, marginally less ugly than it was on the ground. But like exercise and tough conversations, the process is the point. You feel better for having gone through the ritual yourself.

Boy George didn’t get the memo. 

The former Culture Club frontman, whose voice adorned New Wave pop hits like “Karma Chameleon” and “Do You Really Want to Hurt Me” in the 1980s, had artificial intelligence spew out an unfortunate reggae song last week that turned out to be a statement of support for Israel’s ongoing war in Gaza. “You say genocide, I say war,” the song, titled “We Will Dance Again,” starts, and the lyrics seem to revel in the ugliness of the ongoing violence in Gaza. The tens of thousands of Palestinian deaths, the song claims, are “what the military’s for.” 

Obvious AI tells throughout this track make clear that Boy George hasn’t just gotten lazy, he’s also lost the quality of discernment. The song’s meter is odd, and its lines are overstuffed. There are no interesting choices, no glimpses of an artist’s vision. It’s a hollow provocation over a royalty-free riddim. 

Against that backdrop, a song defending and celebrating the Israeli military is nasty work, no matter who made it. The fact that no one made it, that it’s the creation of a machine that hallucinates in exchange for electricity, only intensifies the sick, empty feeling the track leaves behind. 

Since Hamas militants attacked Israeli military installations and civilians on October 7, 2023, the ensuing war in Gaza has left more than 73,000 Palestinians dead. The United Nations has called Israel’s campaign a genocide. The International Criminal Court has issued an arrest warrant for Benjamin Netanyahu, accusing the Israeli prime minister of crimes against humanity. Attacks on Gaza continue despite a ceasefire deal. Against that backdrop, a song defending and celebrating the Israeli military is nasty work, no matter who made it. The fact that no one made it, that it’s the creation of a machine that hallucinates in exchange for electricity, only intensifies the sick, empty feeling the track leaves behind. 

The track’s release has been a disaster for George. He split acrimoniously from Tony Pontius, the long-time manager of his record label BGP, because of Pontius’ refusal to release the song. A planned role as King Herod in a production of “Jesus Christ Superstar” was put on ice. Spotify pulled the track down for violating its restrictions around AI-generated music. Bandcamp followed soon thereafter. Boy George has dug in his heels in recent days, calling the platforms a “bunch of c**ts” as part of a steady stream of Instagram posts. His doggedness would be almost admirable, if “We Will Dance Again” wasn’t so lazy. 

In releasing the track, Boy George presumably wanted to turn heads, to make a statement. But he didn’t want to do any work. He didn’t want to record multiple vocal takes of lines he supposedly wrote and believes in. He didn’t want to arrange actual instruments to better emphasize his lyrics and pro-war stance. He didn’t want to mix the track carefully to refine his statement. He could have made something that shimmers, a piece of true pop that expresses repellent ideals. It wouldn’t have been the first. 


Start your day with essential news from Salon.
Sign up for our free morning newsletter, Crash Course.


Merle Haggard’s iconoclastic “Okie From Muskogee” is considered a country classic, even though the sentiment is about as far from mainstream American thought in 2026 as can be imagined. When even right-wing commentators are pushing microdosing as a path to self-betterment, his disparaging remarks about longhairs taking LSD come off as impossibly square. But you can hear the heart in Haggard’s leathery vocals, buoyed by the sweet harmonies of his backing band. Haggard waffled over the years on whether the anti-hippie hardliner anthem was a satire  of the crew cut set or a genuine tribute to his conservative father. Either way, Haggard sounds like he believes what he’s saying, regardless of whether that’s true, because of the time and effort he spent working out the song.

With 2013’s “Blurred Lines,” Robin Thicke and Pharrell set out to make a groovy single in the vein of Marvin Gaye. Though the song has been relegated to the dustbin following a widespread critical backlash and later allegations of sexual assault against Thicke by model and actress Emily Ratajowksi, who appeared in the song’s video, they were extremely successful. The song itself, creepiness aside, is a Swiss watch of a partystarter. Pharrell’s ad-libs and inserts interrupting the groove at perfect intervals to wake up the dancefloor. They arguably did too good a job recreating the shuffling, glass-clinking percussion of 1970s cocktail party classics, as they lost almost everything they’d made from the song in a subsequent — and successful — lawsuit from Gaye’s estate.  

“We Will Dance Again” does none of that. It warrants no qualifiers, no deeper thought, because Boy George clearly didn’t think too hard about it himself before spitting it out into the world. He asked a machine to build him a song to support what many consider to be an ongoing genocide. When it offered him half a song, he said, “Good enough” — without even bothering to run it through a few rounds of polishing. I regret to inform you that, in 2026, Boy George won’t even tumble for us.  

The post Sorry, Boy George. AI can’t even make bad art appeared first on Salon.com.

OpenAI’s models shared hacking tips on a secret messaging board before Hugging Face breach

6 August 2026 at 04:33

LAS VEGAS — Weeks before they escaped a closed test and launched a cyberattack without any human prompting, some of OpenAI’s most advanced artificial intelligence agents secretly began sharing tips on how to cheat their way through an internal hacking evaluation, two of the AI company’s researchers said Wednesday.

“This is a pivotal moment both for our company as well as the AI industry as a whole,” Michael Dalton, one of the AI-maker’s researchers, said during a presentation at the Black Hat cybersecurity conference in Las Vegas, Nevada.

The latest disclosure provides greater detail on the timeline and methods used by two of OpenAI’s models before they slipped outside a controlled environment and onto the open internet, allowing the models to breach AI developer platform Hugging Face undetected. OpenAI admitted its models were responsible for the hack late last month, roughly a week after Hugging Face said an autonomous AI system broke into its network.

The revelation is likely to spur fresh scrutiny of the measures leading AI labs such as OpenAI and Anthropic are taking to monitor the behavior of their most cyber-capable technology — especially during evaluations where agents are prompted to demonstrate their hacking skills in what is meant to be a controlled setting.

On Tuesday, the U.K.’s AI Safety and Security Institute disclosed that Anthropic’s most powerful AI model created fake online personas and sought to trick a human coder into abetting a cyberattack during a recent hacking test gone wrong. After the Hugging Face disclosure last month, Anthropic conducted a review and found models it was testing had breached three organizations in separate incidents dating back to April.

Dalton and Eric Wallace, another OpenAI researcher, said Wednesday the AI giant recently learned that multiple agents it was testing simultaneously began communicating over an internal message board in early May. There, different models shared advice about how to accomplish difficult hacking challenges they were struggling to surmount, including workarounds that required internet access.

Two OpenAI models ultimately strung together a series of sophisticated techniques to gain access to the internet and worm their way inside Hugging Face in mid-July. OpenAI has said the models were focused on completing a hacking evaluation they were prompted to solve, and that correct answers could be found on the AI developer platform.

The OpenAI researchers told conference attendees that since early May, the models created a message board inside OpenAI’s Artifactory internal file system. Without the company’s knowledge, the models spent months independently exchanging information and techniques to help each other complete difficult tasks.

Wallace said that when models get stuck, they often “try to game or cheat the task in order to get their reward.”

“The beginning of this incident kind of traces back to this point where one agent realized it could communicate by uploading a note,” he added.

By late May, one model found a way to abuse Artifactory’s internet access to retrieve files from various websites — effectively giving the models indirect access to the internet. In June, the models were able to find and exploit a previously unknown zero-day vulnerability to gain administrative privileges on Artifactory, install remote software and expand their activity within the system.

These efforts eventually overloaded Artifactory, causing a system-wide outage in early July that alerted OpenAI’s engineers to the ploy. After investigating, the company revoked the model’s credentials, removed the message board and worked with Artifactory to fix any gaps before resuming training. But the models found another way to communicate inside Artifactory just days later and continued exchanging techniques to target additional vulnerabilities within OpenAI’s infrastructure and external systems, including Hugging Face.

In light of the incident, Dalton said OpenAI is “consciously slowing down research to enhance security and to upgrade the security principles and foundation of our environment, and dramatically scaling up the monitoring of our AI agents and improving our general security control environment across prevention, detection, and mitigation.”

US intel sharing rebounds with Ukraine

The intelligence-sharing relationship between the U.S. and Ukraine has bounced back to previous highs, according to long-time Ukraine watchers — a welcome boost during a critical window of opportunity for the Ukrainian war effort.

Sen. Mark Warner (D-Va.), the intelligence committee’s ranking member and a longtime proponent of more U.S. assistance to Ukraine, told POLITICO he sees evidence of an improved intel-sharing agreement — and believes it’s helped Kyiv gain an advantage in Moscow’s four-year-long war.

“I don’t want to get into any specifics, but it has improved,” he said, adding that Ukraine’s use of long-range drones and missiles has allowed it to strike deep within Russian territory and strengthen its position.

In recent months, Kyiv has carried out more aggressive strikes across Russia, enabling it to take back territory and stabilize the front line. This has afforded the country more leverage as Ukraine looks to parlay battlefield wins to pressure Russia to the negotiating table.

Ukraine’s stronger footing also comes as U.S.-mediated talks to strike a peace deal with Moscow have stalled. Trump’s negotiating team, which includes Steve Witkoff and Jared Kushner, has been preoccupied with the Iran war, bumping Ukraine down its priority list.

But in that time, Ukrainian President Volodymyr Zelenskyy appears to have risen in President Donald Trump’s estimation as Kyiv has made gains against Russia.

In early July, a barrage of Ukrainian strikes on Russian energy infrastructure forced Moscow — one of the world’s top fuel exporters — to halt its exports of diesel. The increased frequency of those kinds of targeted attacks has put the Kremlin in a tighter spot, creating what Kyiv has argued is a window of opportunity for Ukraine to leverage its current advantage to end the war.

Republican Sens. John Cornyn (R-Texas), another member of the intel committee, and Roger Wicker (R-Miss.), who chairs the Senate Armed Services Committee, agreed that intel-sharing between the U.S. and Ukraine has increased at a moment of strategic importance.

“It sure seems like that,” Cornyn said. “Everybody loves a winner and looks like Ukraine has turned the tide.”

Sen. Tim Kaine (D-Va.), a Democratic armed services committee member, told POLITICO he’s also seen signs of greater communication between Ukraine and the U.S.

“I was in Ukraine in April 2025 and I was there again in July 2026. 
And I detect more confidence in the communication,” Kaine said.

Cooperation from the U.S. has been key to Ukraine’s positive turn in fortune, said George Barros, the director of innovation and open source tradecraft at the hawkish Institute for the Study of War. Trump reportedly approved intelligence sharing for Ukrainian strikes on Russian energy infrastructure last year, which have been essential to creating a “proper incentive structure” to push Moscow to the negotiating table, Barros noted.

The strikes, he said, were “supercharged,” and became significantly more effective when imbued with intelligence from the Americans, part of a “larger, more coherent strategy for how to actually create real costs.”

And American early warning systems, Barros added, have been alerting Ukrainians to incoming Russian missile attacks since the early days of the war.

The White House did not provide details on whether its intelligence-sharing relationship with Ukraine has expanded, though it stressed that Trump is focused on facilitating an end to the war.

“The President wants this war settled so the senseless killing ends,” said the White House spokesperson in a statement. “The President and his team remain committed to continuing to play a constructive role in ending the war between Russia and Ukraine, and he remains optimistic that we’ll ultimately get a peace deal done.”

The CIA and ODNI did not respond to a request for comment.

Washington also stands to benefit from Kyiv’s intelligence, said John Herbstwho served as U.S. ambassador to Ukraine from 2003-2006 and still maintains contact with officials in the country.

“There’s no doubt of the following: Ukraine has outstanding intelligence on Russia,” he said.

Zelenskyy has sought to put that intelligence to use. With Washington locked in a five-month war against Iran, the Ukrainian president prefaced his July visit to the Oval Office by claiming Kyiv planned to provide Trump with evidence that Russia was aiding Tehran.

“When you talk to Ukrainian intelligence officials, you hear confident insights into what is going on in Moscow, and not just in the Kremlin,” said Stephen Sestanovich, a fellow for Russian and Eurasian Studies at the Council on Foreign Relations. “Insights of a sort that justify a truly cooperative and reciprocal sharing arrangement.”

Self-driving startup approved to take taxi passengers in London

5 August 2026 at 12:49

LONDON — The U.K. capital’s transport authority has granted approval for Wayve and Uber to begin giving rides to members of the public in autonomous vehicles.

Transport for London (TfL) said it licensed 15 modified vehicles operated by the companies, which have a partnership, as “Private Hire Vehicles” (PHV) on a trial basis.

In a statement, London-based startup Wayve said the licenses were “an important step forward” that will allow it to begin giving rides to a small number of passengers later this summer ahead of a full public launch.

Wayve said its vehicles “are designed to operate autonomously, and will do the driving,” though under TfL’s rules, a licensed PHV driver must be present and responsible for the vehicle at all times.

“Safety is our top priority,“ a TfL spokesperson said. “Any new vehicle licensed to carry passengers on London’s roads must align with our Vision Zero goal of eliminating all deaths and serious injuries from collisions on London’s streets by 2041.”

Successive U.K. governments have sought to make the country a European pioneer in self-driving technology.

The Department for Transport opened a permitting scheme for companies to operate commercial robotaxi services without a human driver in May. Applications for that scheme — which is separate from TfL’s PHV regime — continue to be assessed by central government with input from local transport authorities including TfL.

Getting licenses isn’t the only obstacle facing robotaxi services. A survey by the London Assembly’s Transport Committee this month identified widespread opposition to autonomous passenger vehicles among the capital’s inhabitants, with just 29 percent of Londoners saying they support the roll out.

Anthropic and OpenAI models tried to trick humans into poisoning code during safety testing

5 August 2026 at 05:25

Leading artificial intelligence models from Anthropic and OpenAI created fake online personas and tried to deceive human coders into abetting a cyberattack during a recent safety evaluation, the U.K.’s AI Safety and Security Institute disclosed Tuesday.

It marks the latest case in which a powerful AI system has attempted a digital attack on an unwitting third party without direct prompting during such an evaluation — heightening concerns the powerful technology is advancing too fast for responsible oversight.

The disclosure is likely to ignite fresh calls in Washington and Silicon Valley for more rigorous regulation of the AI industry, particularly over frontier models with advanced capabilities to detect and launch cyberattacks. It comes just days after similar testing mishaps involving some of the same models from OpenAI and Anthropic sparked urgent calls for new AI safety regulation and a push within Silicon Valley to slow the rapid pace of AI development.

Like its U.S. counterpart, AISI routinely conducts security evaluations to better understand what dangers both new and soon-to-be-released AI models pose to public health and safety. But even the digital security body said the actions it uncovered by Anthropic’s Claude Mythos 5 and ChatGPT 5.6 — the latest publicly released model from either AI lab — were unlike anything it had seen before.

“This is the first time AISI has seen deception of this severity that was targeted at a real person, unprompted, in the real world,” AISI said in a 35-page technical report accompanying a blog post Tuesday.

AISI said the malicious activity began on July 25. The AI safety evaluator detected it and launched an investigation on July 28, when it spotted “unusual data transfers” stemming from a cyber evaluation it was conducting on Mythos 5 and ChatGPT 5.6.

Overall, AISI determined that Mythos 5 and ChatGPT 5.6 took “autonomous, unsanctioned action on the live internet, targeting real people and organizations” during 10 of the 122 evaluations the research body conducted and isolated for review. The majority of those actions, it said, involved Mythos 5 and arose during a “single, sustained line of activity.”

In the most alarming incident it uncovered, Mythos 5 attempted a supply chain attack — a sophisticated technique often deployed by North Korean and Russian cyber operatives, in which hackers bury malware inside legitimate code.

To do so, Anthropic’s model created “multiple fake identities” on developer platform GitHub and used them to send messages “pressuring” an open-source software engineer to unwittingly introduce a bugged update into code widely available on the popular site, AISI said. When that effort failed, the AI “edited its earlier activity to appear harmless” and “considered adopting a fresh identity to continue,” AISI added, a sign the model was intent on repeating the ruse.

As part of the same effort, Mythos 5 also sent direct messages over GitHub to software engineers that contained malware.

In another sign of deceitful behavior AISI uncovered in its investigation, multiple AI agents it was testing appeared to communicate with one another about how to convince real engineers using GitHub to trust them. “One agent left public messages on GitHub offering collaboration with other agents working on the same challenge,” AISI wrote.

AISI’s blog and technical assessment make no mention of whether the models also attempted to exploit previously unknown software bugs — called zero-days — during the evaluation.

Last month, OpenAI disclosed that GPT 5.6 and another of its models escaped onto the open internet during what was supposed to be a controlled test, and then hacked another company in a first-of-its-kind, autonomous breach.

In response, Anthropic launched an investigation into whether any of its models took illicit action during recent testing and discovered Mythos 5 and two other models had hacked three organizations during tests dating back to April.

In a statement, an Anthropic spokesperson said they are “grateful” to AISI for their leadership and that this review underscores the need for “a broader conversation about how to safely evaluate increasingly capable AI agents.”

The spokesperson added: “As we shared after disclosing our own incident last week, the field needs stronger, shared standards for how evaluation environments are built and secured. We look forward to partnering with the UK AISI to learn more about this incident as we conduct our own investigation.”

An OpenAI spokesperson referred POLITICO to a blog post about the incident that went up Tuesday evening. “We are committed to working across the industry to strengthen shared practices for conducting high-risk evaluations safely, including convening stakeholders such as national AI institutes, independent evaluators, other AI labs, and other groups in the coming weeks,” the blog read.

AISI stressed in its blog that the malicious activity it disclosed Tuesday took place under “deliberately permissive conditions” so they could assess the safety risks posed by the two models. This included granting the models access to the internet, unlike the earlier incidents detailed by Anthropic and OpenAI.

AISI also noted the models were intentionally stripped of internal guardrails that block malicious behavior. AISI was only able to disable those controls because of its role testing Mythos 5 and ChatGPT 5.6.

Still, AISI said the incidents highlighted the need for greater monitoring of model behavior during testing, and tighter controls over their access to the internet.

The Trump administration is finalizing a voluntary framework under which AI labs would submit powerful models they want to release to the public for federal safety testing. But it has not yet made the framework public, and it includes no provisions for models AI labs are developing internally.

The incidents last month from OpenAI and Anthropic both involved models not intended for public release.

Some cyber experts say recent incidents highlight deeper questions around AI development, such as who is liable when AI systems break federal hacking laws.

“If any of these were human-originated, they would lead to clear and vigorous prosecution. I think it’s time for a serious discussion about updates to existing computer security law,” said Marc Rogers, a hacker and prominent cybersecurity expert.

Colorado Republicans Attack Jewish Gov Candidate With AI ‘Cartoon Devil Horns’ Graphic 

4 August 2026 at 22:35

Colorado Republicans are using an image showing Democratic gubernatorial candidate Phil Weiser with “devil horns” to mock him on social media. While a top Democrat blasted the move as a “plainly antisemitic” attack, the GOPer who created the graphic doubled down on Tuesday.

On Facebook, Sean Pond, a Republican county commissioner and former Senate candidate who posted the image, dismissed the furor and called it a “silly picture” of “two cartoon devil horns.”

“Sometimes devil horns just mean the devil. That’s why they show up in cartoons, church lessons, haunted houses, Halloween costumes, emojis, and every costume aisle in America,” Pond wrote in a post on Tuesday afternoon. 

Pond’s graphics, which were posted on both X and Facebook on Sunday and Monday, showed Weiser, who is Jewish, standing in front of fiery skies with red horns atop his head. Depictions of Jews with horns are widely recognized as one of the most common types of antisemitic imagery. They have been used to associate Jews with evil and the devil since the Middle Ages. Pond used them to promote Colorado’s Republican gubernatorial nominee, Victor Marx. 

Pond’s pictures featured all caps text declaring Weiser “THE NEXT THREAT TO COLORADO.” One of Pond’s images touted the GOP candidate and said: “COLORADO NEEDS STRENGTH. COLORADO NEEDS FAITH. COLORADO NEEDS VICTOR MARX.”

Marx, a self-described “high-risk missionary and evangelist” who has made questionable claims about having performed exorcisms by phone and having saved as many as 45,000 women and children from abusive situations, responded positively to one of Pond’s posts on X that featured the “devil horns” graphic. He said Pond’s point about Colorado Republicans needing to unite against the “THREAT” of Weiser was “exactly right.”

“We do have to remember what’s at stake. Colorado can’t afford more division. It’s time to unite, stay focused, and win,” wrote Marx on Monday. 

Pond’s Facebook defending the graphics was directed at Kyle Clark, a journalist with 9NEWS in Denver who had raised alarms about the images and noted “Weiser is outspoken about his mother’s birth in a Nazi concentration camp, his family members killed in the Holocaust, and the threat posed by antisemitism today.”

“Depicting Jewish people with horns is a centuries-old, dehumanizing, antisemitic trope,” Clark wrote in an Instagram post on Tuesday. 

Pond had made an earlier Facebook post in the wee hours of Tuesday morning, announcing that Clark had asked him about the graphics and sharing a lengthy statement. In it, Pond said he made the images “using AI” with a “direction … to portray Phil Weiser as evil and as the next threat to Colorado.” Pond also insisted he was unaware that Weiser, who has been Colorado’s attorney general since 2019, was Jewish.  

“His religion was never considered because I did not know it,” wrote Pond. “There was no reference to Jewish people, no religious message, no dog whistle, and no hidden meaning.”

Pond further argued “Jewish politicians are subject to the same fierce political criticism as Christian politicians, Muslim politicians, atheist politicians, and everyone else seeking public power.” 

“Phil Weiser does not receive immunity from political satire because of a personal fact I did not even know,” Pond added. “I will not apologize for opposing him.”

Both Marx and Pond did not immediately respond to requests for comment. TPM also reached out to Weiser’s campaign and received a statement from Colorado Democratic Party Chair Shad Murib. 

“This is absolutely disgusting from Victor Marx,” Murib said. “That he calls this plainly antisemitic imagery ‘satire’ makes him an even bigger fool than everyone thinks.”

EU ministers close ranks behind Spain after Ceuta migration crisis

BRUSSELS — EU interior ministers sought to draw a line under five days of bitter recriminations over the arrival of 72,000 migrants in Ceuta, closing ranks behind Spain and accusing smugglers and foreign actors of exploiting the crisis to divide the bloc.

The show of solidarity marked a sharp shift after EU leaders publicly blamed Madrid’s migration policies for creating a crisis they warned could spill across Europe, prompting Italy to suspend air and sea links with Spain.

Following a three-hour emergency meeting in Brussels on Tuesday, ministers praised Spain’s response, stressed that the passport-free Schengen zone had never been at risk and called for tighter coordination among capitals during future migration emergencies.

The meeting followed days of unusually public anger at Prime Minister Pedro Sánchez. In a letter signed by 22 EU leaders, governments demanded tougher action to stop irregular arrivals, while Italy suspended air and sea transit with Spain over fears that migrants could move onward through the Schengen area. Sánchez hit back by urging his counterparts to show “understanding” rather than turn Spain into a scapegoat for a crisis on the EU’s external border.

By Tuesday, ministers were keen to close ranks. The EU’s Migration Commissioner Magnus Brunner said the influx had been “instrumentalized” by smugglers and human traffickers, while French Interior Minister Laurent Nuñez said ministers had condemned efforts to use images of the crossings to divide the bloc.

“The divisions that we have heard over the weekend were not welcome and they were exploited by foreign countries,” Nuñez told reporters. “But what I heard this morning reassured me.”

EU countries that had publicly called out Spain over its migration policies took a more conciliatory tone in the meeting, apparently appeased by the speed and effectiveness of Madrid’s response to the crisis, three EU diplomats with knowledge of the meeting said. They were granted anonymity to discuss the confidential talks.

Matteo Piantedosi, Italy’s interior minister, praised Spain’s efforts to control the unrest, the diplomats said. Rome clashed with Madrid on Friday, calling for Spain to be kicked out of the Schengen zone.

Another diplomat referred to the past 24 hours of diplomacy as EU “couples counseling.”

Brunner declined to speculate about whether Morocco had played a role in the influx. The question is sensitive because Spain relies heavily on Rabat to police departures toward Ceuta, and the episode revived memories of 2021, when thousands entered the exclave after Moroccan forces relaxed controls during a diplomatic dispute with Madrid.

Spanish Interior Minister Fernando Grande-Marlaska instead praised Morocco’s cooperation in bringing the latest crisis under control and described Tuesday’s meeting as “entirely constructive.”

He said 70,000 of the 72,000 people who entered Ceuta had since returned to Morocco and insisted the Schengen area had never been at risk. Ceuta has special arrangements requiring travelers to show documentation before continuing to mainland Europe.

Grande-Marlaska also called Italy’s transport restrictions unjustified and said he expected them to be lifted. He rejected suggestions that the crisis had made Spain look weak.

“Spain has come out looking like a strong, reliable partner,” he said. “This isn’t a matter that depends on testosterone.”

Ministers also called for better early-warning systems, closer coordination between capitals and stronger cooperation with non-EU countries to prevent departures.

Several pressed for faster work on so-called return hubs outside the bloc. Greece proposed an EU mechanism allowing asylum procedures to be suspended and migrants returned immediately in extreme circumstances, according to a Greek government official.

“The EU’s external borders are our shared responsibility, and migration requires a united European response,” said Ireland’s Justice Minister Jim O’Callaghan, who chaired the meeting.

The Commission is expected to consider further measures in September after examining what caused the influx and whether social media helped organize or amplify it. Strengthening the role of the EU border agency Frontex is among the options under discussion.

Max Griera and Nektaria Stamouli contributed to this report. This article has been updated.

Likely French presidential candidate says he was targeted by Russian smear campaign

4 August 2026 at 13:27

PARIS — A group affiliated with Russia’s intelligence agency launched a disinformation campaign against center-left MEP and likely presidential candidate in next year’s French election, Raphaël Glucksmann, he claimed in a post on X on Tuesday.

Glucksmann, who is expected to announce whether he will run for president in the coming weeks, said he had been informed by the French Secretariat-General for National Defence and Security of a “Russian operation” that was “directly controlled by the [Russian] GRU.”

Former Prime Minister Édouard Philippe, who is a confirmed presidential candidate, was also reportedly targeted by a Russian disinformation campaign last week. And several local candidates from the left-wing France Unbowed movement, known for its pro-Palestinian advocacy, were allegedly targeted by an Israeli firm earlier this year.

The alleged disinformation effort against Glucksmann involved an article posted on a website mimicking well-known left-wing news outlet Blast, as well as a social media clip claiming Glucksmann’s partner Léa Salamé — the host of French public television’s prime-time news program — had tried bribing other journalists to speak about his likely candidacy favorably.

Glucksmann is a prominent critic of the Russian government and took part in the 2013 Maidan uprising in Kyiv.

“Russian agencies have begun operations to destabilize the 2027 presidential election,” he wrote on social media. “This attack is merely a foretaste of what is to come.”

The Russian Embassy in Paris did not immediately respond to a request for comment.

As he nears the end of his term, French President Emmanuel Macron has said that safeguarding the 2027 presidential election from foreign interference would be a top priority.

The US might lose the AI race to China. Should Americans care?

3 August 2026 at 13:00
Kimi K3 logo on a smartphone in front of a Chinese flag.
In this photo illustration, a smartphone displays the Kimi K3 logo in front of a screen showing the Chinese national flag on July 18, 2026, in Shenzhen, Guangdong Province, China. | Photo illustration by Cheng Xin/Getty Images

Both Washington and Silicon Valley are in the midst of a collective freak-out over China’s recent advancements in artificial intelligence.

Key takeaways

  • The release of the new AI model, Kimi K3, has reignited concerns in Washington and Silicon Valley that China’s AI capabilities are catching up fast to the United States. 
  • US concerns about Chinese AI can be separated into three general buckets: cybersecurity vulnerabilities, military capabilities, and the future of democracy. 
  • While there’s wide consensus that China’s growing AI dominance is cause for concern, there’s less about what to do about it, and some potential policy options may be counterproductive.

The latest round of consternation was triggered this month when a little-known Chinese AI startup called Moonshot released a new large language model called Kimi K3. The conventional wisdom had been that the leading AI models developed by companies like OpenAI and Anthropic were between six to 12 months ahead of their Chinese competitors. Kimi dashed those assumptions: now, analysts say American companies may be as little as two to three months behind. 

Dean Ball, a former Trump administration official now with OpenAI, warned in a bleak post on X that models like Kimi K3 could lead to a world of “full AI communism” and a “dystopian hellscape” of AI under full government control. 

Policymakers have worried for years now about China gaining an edge over the US in the AI race. Both the Donald Trump and Joe Biden administrations took steps to slow China’s AI progress, including blocking the export of the most advanced US semiconductors.  

The White House is already reportedly considering taking steps to ban “open-weight” models — models that are easier to adapt for a user’s own purposes — like Kimi K3 in the United States. The Trump administration has also accused Moonshot of using the unauthorized “distillation” of one of Anthropic’s models — basically using another model’s outputs to train itself rather than raw data — as well as gaining access to blacklisted Nvidia chips in Thailand.

But often lost in the debates about what to do about China’s accelerating AI capabilities is the question of why the US cares about this at all. Obviously, the American companies developing the latest frontier models care about maintaining their edge, but why should it matter to Americans if the chatbot in their pocket was developed in Silicon Valley or Shanghai? And perhaps even more so, why should it matter what chatbots people in Nairobi or Brussels are using? 

The concerns in the US about Chinese AI generally fall into three broad buckets: cybersecurity concerns; military and national security concerns; and human rights or democracy concerns.

For the moment, concerns about who is winning the AI race can feel a bit abstract, but as AI becomes more embedded into governments, militaries, and ordinary people’s lives, the difference will start to be felt in a much more material way at both a national and personal level. In general, there is a growing sense that it matters which of the world’s vastly different superpowers builds the technology that could transform everything. 

“People’s relationship with AI is becoming foundational to how they live their lives, so the choices people make about whose model they use and where they are physically hosted, as they share some of their most intimate secrets and ask for life advice and business guidance, and run an increasing share of their life — those are incredibly important,” said Ryan Fedasiuk, a former State Department technology adviser now at the American Enterprise Institute. “It’s a contest between the United States and China to define the operating systems through which people live and work.”

Here’s what else America loses if it loses that contest.

Chinese AI could be more vulnerable to cyberattacks 

The concerns about using Chinese AI are in some ways a repeat of the concerns over Huawei, the Chinese telecoms firm that built much of the world’s 5G internet infrastructure, but which the US government banned from operating in the United States during the first Trump administration over concerns that the Chinese government could intercept information transmitted over these networks. 

Today, the concern is that many firms are increasingly integrating Chinese AI models into their systems, both because they are often cheaper and because they are “open-weight.” (“Weights” refer to the setting an AI model uses to process a user’s inputs. “Open-weight” models make these publicly available for users to tinker with, rather than charging for access.) 

There are some indications that Americans using Chinese AI models are already vulnerable. A Booz Allen study from earlier this year tested four Chinese models commonly used by US developers and found that three of them generated software with far more “hidden vulnerabilities” that could be exploited by hackers than their US counterparts. There’s no proof that the models were doing this intentionally, but the study did find that the models were “changing their behavior depending on who the user seemed to be or what country the request referenced.”

AI can also be used to carry out cyberattacks. Although nearly all the leading models have safety protocols meant to prevent this, they’re not bulletproof. Even Anthropic’s Claude, generally considered one of the most secure models, was adapted by Chinese hackers last year to engage in cyber espionage. The open weights of the leading Chinese models could make it even easier to strip out the safety protocols. 

AI could give China a military edge

The simplest and most obvious argument for why AI matters for American national security is that it’s all too conceivable that the US and China could be at war in the years to come, and AI could be a major factor in determining who wins. 

The conflicts in Ukraine, Gaza, and Iran have shown that modern militaries are already extensively using AI for intelligence collection and targeting. Semi- or fully-autonomous drone swarms are a major component of US plans for repelling a Chinese invasion of Taiwan. Then there’s the risk of AI being used to generate new bioweapons or other dangerous threats. 

US experts believe China has pursued a “military-civil fusion” strategy, encouraging the People’s Liberation Army and Chinese defense contractors to collaborate closely with civilian technology companies and research institutions in order to gain an edge in military AI applications like intelligence analysis and drone swarms. It’s difficult to know exactly which of these capabilities China is focusing on, but procurement data suggests leading Chinese technology firms like Deepseek and Alibaba are involved in work with potential military applications. Analysts also accuse China of using outputs from US models like ChatGPT and Claude to train AI systems that could help develop China’s defense capabilities. 

And that’s just conventional weapons. The US government has alleged that Chinese labs have “continued to engage in biological activities with potential [bioweapon] applications” amid concerns that artificial intelligence could help make such weapons more sophisticated and deadly. 

China could export digital authoritarianism

Last year, it was reported that Miiloo, a fuzzy children’s plush toy with a built-in AI chatbot, would, if prompted, happily tell users Chinese Communist Party talking points like “Taiwan is an inalienable part of China.” The hubbub over Miiloo reached the US Senate floor. While it’s hard to imagine that many users were really asking Miiloo to help clear up East Asian territorial disputes, the affair illustrated much larger concerns about the dangers of letting AI models built by an authoritarian government with one of the world’s strictest censorship regimes become the global standard. 

Chinese generative AI tools are legally required to uphold the country’s “core socialist values,” according to a document published by its national cybersecurity standards committee. So it’s little surprise that DeepSeek, the Chinese chatbot that sent shockwaves through the US tech industry in 2025, politely declines to answer when you ask it what happened on June 4, 1989, in Tiananmen Square. 

It’s not just that Chinese AI could help shape the political narratives absorbed by billions around the world, at a time when US soft power is ebbing and surveys show people in many countries already now have a more positive view of China than the United States.

 The Chinese government is also increasingly integrating AI into its own censorship and surveillance apparatus, and is exporting tools like facial recognition technology to other authoritarian countries. 

The fact that under Xi Jinping, China’s government was centralizing power and becoming more, not less, authoritarian in the years leading up to the recent advances in AI are a major factor driving the mistrust in its technology. 

“I think many of the sincere arguments about the risks of these models and what China would do with them stems from the coercive authoritarian approach of China’s current leader,” said Mieke Eoyang, former US  deputy assistant secretary of defense for cyber policy. “I don’t think we would be having this conversation in the same way with someone like [China’s previous leaders] Jiang Zemin or Hu Jintao.”

It is a serious concern if models built to conform to the values and political priorities of China’s current government become the global standard. But some are skeptical of the idea that human rights and democracy should be the goal of AI competition, worrying that the damage has already been done. The premise of that idea has gotten “shakier in recent years,” says Steven Feldstein, a senior fellow at the Carnegie Endowment and author of the book The Rise of Digital Repression. Under this administration, the US has cut support for democracy and human rights programs overseas, and often allied itself with authoritarian governments. Then there’s the fact that at least one leading chatbot often seems to mimic the racist and antisemitic views of the world’s richest man who is also an ally of the current president. 

While it’s still true that Chinese AI reflects the authoritarian values and priorities of China’s leaders, Feldstein notes, “this idea that the US is standing at the forefront of protecting and advancing democracy, human rights, that we’re not sort of there to manipulate information or to push a narrative agenda that reflects the ideological preferences of its leaders, has started to fray.” 

The race to AGI 

There’s also a set of concerns around the topic of “artificial general intelligence,” the hypothetical point at which AI exceeds human capabilities and is able to improve itself. The concern, expressed by both US government commissions and senior officials in both administrations, is that China is “racing” toward AGI and that whichever country achieves it first will have a massive geopolitical advantage. This is the type of thinking behind invocations of the nuclear-era Manhattan Project to justify massive government investments in AI development. 

Chinese leaders do not appear to view AI competition this way. “The US conversation around this is much more ‘AGI-pilled’,” says Jeffrey Ding, a professor at George Washington University and expert on US-China technology competition. “The concern here is that we are very much on the brink of this explosion of more and more powerful AI that leads to it dominating everything.” Chinese leaders, on the other hand, “generally see AI as a productivity tool.”

If Chinese AI is a problem, what should we be doing about it? 

This is not just a Beltway or Silicon Valley concern. A recent Pew survey found that 43 percent Americans believe it is very important for the US to remain the leader in AI development, versus 22 percent who said it was not that important. Interestingly, the survey also found that most Americans believe China is already ahead on AI, though the expert consensus is that it’s still slightly behind. 

“We’ve gotten so used to the fact that the US has been the leading player in technological revolutions from like mobile internet to the internet era, so it’s worrying to feel we may no longer have that dominant strength,” said Selina Xu, China and AI policy lead in the office of former Google CEO Eric Schmidt. 

Even if there’s some consensus that AI competition is a priority, there’s less agreement on how to go about it. The challenge, Xu says, is “How do you manage the very concrete national security risks that come from competing with China on AI, but not turn technological competition into blanket protectionism?”

Often, the policy responses to this challenge have been contradictory. 

The Trump administration, in its first term, pioneered the policy of restricting the export of the most advanced semiconductor chips to China, but Trump undermined that policy last year by permitting Nvidia to sell its advanced H200 chips there. The move flummoxed China hawks in Washington and went against the preferences of AI developers like Anthropic, but probably had a lot to do with lobbying by chip maker Nvidia’s Jensen Huang, CEO of the world’s most valuable company. 

In some cases, the US may be inadvertently making China’s models more appealing. In June, the Trump administration placed export controls on Anthropic’s advanced Fable model. This move prompted the company to take the model down for all users and led to the first time that AI capabilities meant for the global public took a step backward.In response, French President Emmanuel Macron warned, “We will not buy any model made by [US AI] companies if from one day to the next you can just turn off the switch.” Chinese models are hardly immune from concerns about kill switches or back doors, but if both governments involved in the AI race are seen as meddling, customers may just opt for whichever one is cheaper. 

The latest flashpoint in the debate concerns the reports that the administration is considering banning open-weight models.  This prompted an open letter from dozens of leading tech companies including Nvidia and OpenAI defending access to these models as necessary for helping the US maintain AI leadership. Advocates note that open-weight models can help respond to vulnerabilities as well as create them: When a rogue OpenAI model recently hacked into the startup Hugging Face’s systems, Hugging Face’s engineers used an open-weight model developed by China’s Z.ai to analyze the attack. 

Despite the frequent comparisons, AI is not a national security competition like the early days of nuclear weapons or the space race. It’s a technology with potentially grave national security implications, that’s also used by millions of people around the world to plan their Tuesday night dinner or help with their homework. The log-in for Claude is not carried by a military officer at the president’s side. And much of the important work on developing these new technologies is being done by private tech companies, not government labs or defense contractors. 

It may be that AI capability will help determine which country has the edge in the 21st century. It may also be that the benefits of these capabilities will be shared: Chinese companies might be no less capable than their American counterparts when it comes to developing new medications or clean energy technology. 

The challenge of crafting technology to prevent a “dystopian hellscape” is to not accidentally make the existing world worse. 

Can the internet survive rogue AI?

31 July 2026 at 13:00
A photo illustration shows the logo of AI platform Hugging Face logo on a mobile phone screen.

The internet may no longer be solely the domain of humans. Last week, OpenAI disclosed an “unprecedented cyberincident”: An experimental AI agent successfully hacked its way into the open internet.

Specifically, the agent was assigned a task; in order to complete it, the agent broke out of an isolated research environment and hacked into a third-party platform called Hugging Face. It’s a move that many experts deemed inevitable, given the speed and scale of advances in AI technology — and it raises serious questions about AI safety.

But for Konstantinos Komaitis, a senior fellow with the Democracy and Tech Initiative at the Atlantic Council, it wasn’t the unexpected behavior of the AI that was significant. It was what that behavior could mean for the internet’s fundamental, decentralized infrastructure and whether it would spur calls to build new barriers against autonomous AI agents. 

Komaitis argues that such barriers are not the solution, however. He spoke with Today, Explained co-host Sean Rameswaram about why an open internet is actually key to combating AI cybersecurity threats.

Below is an excerpt of the conversation, edited for length and clarity. There’s much more in the full podcast, so listen to Today, Explained wherever you get podcasts, including Apple Podcasts, Pandora, and Spotify.

So most people see that this happens and they think, “Oh no, AI went rogue. How long before it kills me?” You see that this happens and you start thinking about infrastructure. Tell us more about why you were thinking about infrastructure in light of this AI agent breaking containment.

The internet was never designed with full security in mind, right? 

When you’re creating a decentralized system, you cannot possibly foresee every security or vulnerability that might come up. But because you have a system that is based on building blocks, you have the extraordinary capability of actually addressing security issues as they come up through those building blocks without breaking the whole system down. 

And of course, the other thing that this does is that it pushes you towards collaboration, because when you have so many building blocks, you cannot possibly possess all the knowledge for each building block. So you’re bringing literally everyone to try to address these problems. 

Take the internet, for instance: We have spent decades addressing those vulnerabilities and developing mechanisms to authenticate users and devices, encrypt communications, mitigate distributed attacks, coordinate incident response, and of course share threat intelligence. 

Now, what is new with agentic AI is not that simply the malware is better or the phishing attacks are more sophisticated. It’s the emergence of systems that can actually discover vulnerabilities across thousands of systems. They can reason about alternative paths to an objective. They can adapt when they’re blocked. They can chain together legitimate internet services in unexpected ways. Then they do that while they’re operating continuously at machine speed. And this is really at a scale that the internet is not ready to necessarily cope with. 

Effectively, the internet’s openness becomes both a strength and a vulnerability. So the internet was optimized for interoperability, and AI now is optimized for exploiting that interoperability.

And what scares you the most about that? What do you think is most vulnerable to threats?

The fact that we do not have the appropriate mechanisms and institutions to be able to deal with that. I come from the internet world. I’ve spent 20 years of my career defending the open internet and discussing it in international fora. And one of the things that a lot of people underestimate about the internet is how valuable trust is as a property within the system. 

We are talking about networks that exchange data literally based on trust. So what really concerns me right now is that in many ways, we are asking 21st-century AI systems to operate on 20th-century assumptions about trust. And unless we figure that out and we realize it, we will continue having these problems. And of course, the knee-jerk reactions that are coming with this, which are, “Let’s fragment the internet, let’s restrict it, let’s restrict access, let’s take control over it.” That is never the solution.

What do you see as the solution?

Effectively, we need to build institutions that are trusted and are able to cope with those incidents as they happen. Because right now you have OpenAI and you have Hugging Face telling everyone, “Don’t worry, we’ve got this.” And we don’t know; they might have this. But at the same time, I cannot help but wonder. And many, many other people have wondered whether, actually, this is very good PR for these companies and especially for OpenAI.

OpenAI just went to the world saying, “We have developed one of the most powerful LLMs, and we realized that it behaved the way it behaved, but don’t worry, we are going to fix this.” And in this current climate and in this current timing, I am not sure that this is enough. You need institutions that are much more transparent, much more accountable, and much more collaborative across the board.

You want institutions to step up and essentially serve as a watchdog. Help us understand which institutions, because in the United States, famously, our government has done very little to regulate tech.

First of all, we need to stop thinking of institutions as necessarily government-affiliated, right? Or that they are the outcomes of government initiatives. There can be in collaboration with governments, but one of the things that the internet has taught us is that institutions that are built through a bottom-up coordinated process have the tendency of actually being more agile and able to deliver some of those things that we’re talking about. 

So take, for instance, again, open standards. The internet’s open standards are not created by any agency, government or private. It’s created by institutions where engineers from all across the board and all over the world gather together and create those standards.

That’s reminding me of the original design of OpenAI to be this not-for-profit company that had everyone’s best intentions in mind, that could do something idealistic and moral and ethical because all of the profit-minded companies weren’t going to. And now look at OpenAI. Their not-for-profit arm is an afterthought, and they’re chasing profits. 

Do you think it’s practical to leave this to institutions? Because what we’ve seen so far is that institutions bend toward capitalism.

It really depends on how you build the institution, right? It really depends on what sort of guardrails and checks and balances you have around it. In order to build an institution, you need to really know what you want to achieve. You need to have a north star. 

One of the reasons the internet worked was because everybody disagreed, but they agreed on the common shared goal, which was to connect people across the world. For AI, we still do not have that northern star. And once we get it, that’s when you start the building of those institutions in order to facilitate this and bring everyone together.

For me, it is very important for everyone to understand that keeping an open internet is really more important than ever, especially as AI agents become increasingly capable. Because it is tempting to think that the answer to new AI risk is literally ‘build more barriers.’ But the internet’s greatest strength has always been its openness. So the challenge today is not that the internet is too open; it’s that its trust architecture was designed for a world in which humans or software directly controlled by humans were the primary actors. 

Now, it’s being challenged by this agentic AI that introduces a new type of participant — systems that can reason and plan and act with limited human oversight. So we need to evolve our understanding of trust and what it means online. And that will require a lot of work because, as you know very well, Sean, it’s very difficult to build trust, but you can break it within seconds.

AI could end up too cheap to control

30 July 2026 at 12:00
A humanoid robot with green eyes.
Capital markets have signaled their faith in Anthropic and OpenAI’s impending hyper-profitability, valuing each at nearly $1 trillion. | John Ricky/Anadolu via Getty Images

The AI industry’s investors and critics don’t agree on much. But many in each camp share at least one basic conviction: America’s top labs are about to make a killing. 

Capital markets have signaled their faith in Anthropic and OpenAI’s impending hyper-profitability, valuing each at nearly $1 trillion. Many of Silicon Valley’s progressive adversaries also expect the labs to grow filthy rich but fear the implications, warning that AI-induced automation could transfer vast sums of money from ordinary workers to a handful of giant tech companies. Sen. Bernie Sanders’s call for nationalizing the top AI labs rests partly on that concern. 

Key takeaways

  • The AI industry may be more competitive than investors expected.
  • Chinese labs are producing models nearly as powerful as Claude and ChatGPT — and dramatically cheaper.
  • That could make frontier AI a low-margin business.
  • A world of cheap, open-source AI would bring both promise and danger.

But recent advances in Chinese AI call all of this into question.

Over the past two months, Chinese companies have released three AI models that are nearly as powerful as America’s frontier systems — and radically less expensive. 

In June, Beijing’s Z.ai debuted a model that performed nearly as well as Claude and ChatGPT’s second-tier systems on independent benchmarks. Weeks later, another Chinese firm, Moonshot, unveiled “Kimi K3,” a model that allegedly outperforms all of its American rivals except for the very latest versions of Claude and ChatGPT. Finally, just days ago, Alibaba launched a preview of Qwen3.8 Max, which purportedly outclasses even OpenAI’s most advanced systems, while trailing only Claude’s Fable in its capabilities. (Disclosure: Vox Media is one of several publishers that have signed partnership agreements with OpenAI. Our reporting remains editorially independent.)

These developments don’t merely threaten America’s AI giants with stiffer competition in the race for superintelligence. Rather, they raise a more harrowing prospect: that the AI race’s ultimate rewards will be far smaller than anticipated. In a world where new advances can regularly be leapfrogged by cheaper upstarts, hoarding the technology — and its profits — will be harder for any one company to do.

In other words, building a machine God might not be as lucrative as it’s cracked up to be. AI, it turns out, may “want to be free.”

How AI was supposed to pay off

To see how China’s new models threaten Anthropic’s profit expectations, we must first examine why those expectations have been so high.

This is not entirely self-evident. After all, AI labs aren’t much like the hyper-profitable tech giants of the 2010s. Facebook and Airbrb were relatively capital-light businesses with ultra-low marginal costs (adding a profile to Facebook or listing to Airbnb costs the companies virtually nothing). And once each gained a foothold in their respective markets, network effects enabled them to retain formidable positions without needing to constantly upgrade their products.

Building a state-of-the-art AI company is a much more involved — and astronomically more expensive — endeavor. To get to the frontier, Anthropic and OpenAI have sunk (at least) tens of billions into semiconductors, data centers, power plants, and other capital investments. Staying at the cutting-edge, meanwhile, compels them to perpetually churn out evermore costly models.

To put a new Claude model through its initial training — in which it spends months digesting the internet and sussing out statistical patterns within its text — can now cost hundreds of millions of dollars. And such foundational computation is only the beginning. A truly superlative model requires several additional months of fine-tuning. Armies of contracted experts — such as computer scientists, physicians, and mathematicians — tutor the models, grading their answers and guiding them towards better ones. Then the AI systems complete millions of rounds of practice, in which they learn through trial and error how to solve countless problems. This arduous process, known as “post-training,” compounds the costs of a single model’s development. 

All of which raises the question: Why would investors expect businesses with a cost-structure this challenging to be not merely profitable, but massively so?

There are (at least) two answers. The first (and most obvious) is that the market for superintelligent machines is liable to be vast. Frontier AI systems promise to reduce costs and improve performance in myriad white-collar sectors. And Anthropic’s soaring revenues indicate that firms do, in fact, find Claude useful. A company like AirBnB has earned billions by revolutionizing a single industry; imagine then what a technology that remade virtually all industries might be worth.

Of course, plenty of technologies are valuable but not massively profitable to produce. After all, in well-functioning markets, competition should eventually erode individual firms’ margins, even if the underlying technology continues generating huge value. 

But this is where the second answer comes in: Frontier labs’ immense costs are a burden, but they’re also a safeguard against competition — or, in industry parlance, a “moat.”

Startups may be able to afford to build or acquire more rudimentary models, many of which are “open source.” But, the thinking goes, they won’t be able to deliver Claude Fable-level performance without raising giant amounts of capital. And what investors will be willing to pour hundreds of billions into an AI pipsqueak that’s light-years behind Google, Anthropic, and OpenAI?

Alas, the Chinese AI labs’ rapid progress — and the way it was achieved — suggest that Anthropic’s moat may be shallower than previously thought.

How Moonshot swam Anthropic’s moat

The existence of powerful, Chinese AI systems is neither new nor surprising. Xi Jinping’s government has made vying for global AI dominance a key economic goal. And China’s DeepSeek, which also has stunned US companies with its lower-cost competitive models, surpassed ChatGPT as the most-downloaded free iPhone app more than a year ago.

The latest models, however, have dramatically narrowed the gap in capabilities between frontier American systems and their Chinese rivals. Just as critically, they’ve done so in a manner that other, relatively underfunded AI upstarts might be able to emulate.

Alibaba and Moonshot needed to invest massive resources to train their base models. But they allegedly found a low-cost way to refine those models into near-frontier systems: Just ask Claude.

Or, more specifically: Engage Claude in 16 million conversations, using 24,000 fake accounts. In each of those exchanges, ask the model to not only answer countless difficult questions but also, walk you through its reasoning, step by step. Then take all of this data and feed it into your own model as study material, training it to respond to the world’s most challenging queries as Claude would. 

Through this process — known as “distillation” — an AI lab can replicate virtually all of a frontier model’s capacities, without sinking vast sums into human experts and post-training computing runs. 

China’s AI labs have not admitted to using distillation. But OpenAI and Anthropic both reportedly uncovered Chinese distillation attempts earlier this year. And some of the new models appear to display tell-tale signs of distillation in conversations with ordinary users; Kimi K3 has routinely identified itself as “Claude.”

Chinese AI companies are hardly alone in using distillation to catch up with frontier labs. Earlier this year, Elon Musk admitted in court that xAI enhanced Grok’s capabilities by running distillation techniques on Claude and ChatGPT. Nonetheless, China’s latest models appear to demonstrate that distillation can help take a second-tier model to the frontier’s threshold.

America’s frontier labs have tried to defend themselves against such imitators. But this is technically difficult when distillers can assemble massive networks of bots, each asking an inconspicuous number of questions. And legally, it is difficult for America’s AI giants to argue that distillers are stealing their intellectual property. After all, in a sense, China’s copycats are merely doing to Anthropic and OpenAI what those companies did to journalists, coders, lawyers and other specialists: Feeding their public-facing outputs into a model, which then replicates their capabilities by discerning underlying patterns within the text.

Oh, and China’s giving these models away

The new Chinese models would have caused Silicon Valley enough headaches, if they merely provided stiffer competition, while demonstrating the power of distillation. 

What makes Kimi K3 and Qwen3.8 Max especially threatening to the American AI giants’ profitmaking potential, however, is that they are officially open source — meaning that the models’ parameters can be downloaded for free. (Alibaba and Moonshot have not yet released these parameters, but they say they will shortly.)

In other words, any company or hobbyist with enough computing power will soon be able to run a near-frontier Chinese model on their own hardware, modify that model to better serve a specialized purpose, and then sell access to their new version — without paying Alibiba a single yuan.

As Kimi and Qwen grow more capable, their market-share is likely to grow, at American AI giants’ expense.

For many of Anthropic and OpenAI’s potential customers, that proposition may be hard to turn down. Most businesses don’t need the world’s smartest AI, just one competent at their enterprise’s core tasks — compiling legal research, answering IT queries, writing working code, etc. A model that produces outputs 90 percent as good as Claude’s — at roughly one-sixth of the cost — will sound pretty good to many corporations.

Further, open source models aren’t just cheaper than frontier systems, but potentially more secure. If you run an AI on your firm’s own servers, then you don’t need to entrust sensitive data to Anthropic, Google, or OpenAI.

All this had led much of corporate America to embrace open-source models, even before the latest versions narrowed the capabilities gap. In a Linux Foundation survey, 63 percent of organizations reported using open-source AI systems.

And increasingly, those models are Chinese. According to Sequoia Capital, one of Silicon Valley’s premier venture capitalist firms, a majority of American AI startups now use open-source Chinese systems. As Kimi and Qwen grow more capable, their market-share is likely to grow, at American AI giants’ expense.

What’s bad for OpenAI is good (and/or catastrophic) for humanity

All this said, it is still entirely possible that OpenAI and Anthropic will justify their colossal valuations. In many highly competitive economic domains, having access to the world’s very best AI model will remain highly valuable. And America’s frontier labs still outperform all their peers. 

But it’s increasingly plausible that selling state-of-the-art AI systems will prove to be a low-margin undertaking. In a world of ubiquitous, near-frontier open source models, the AI sector’s big winners probably won’t be its top labs, but rather, its chipmakers and cloud computing providers. 

For ordinary people, a future where superintelligence is dirt cheap — and rival AI companies are constantly rising and falling, rather than consolidating into mega-corporations — would look somewhat different than the cyberpunk dystopia that the left’s been dreading. 

And not entirely in a good way. For one thing, in that reality, mitigating AI’s biggest risks would be immensely difficult. Having a handful of firms monopolize control over frontier AI systems is bad in many respects. But it does make those models easier to regulate, as the Trump administration’s decision to temporarily block Claude’s Fable in the name of cybersecurity demonstrated. 

By contrast, if recipes for ultra-powerful AI models are published all over the internet — and anyone with modest technical skills can modify them at will — then systems willing to help their users hack government bureaucracies or engineer bio-weapons are liable to proliferate.

From another angle, however, the “AI becomes almost free” scenario may look like capitalism at its finest: Retrospectively, such a development would mean that a small number of extremely rich people bankrolled the creation of an immensely useful technology, under the expectation of massive profits, only to see competition erode their returns — and disperse that tech’s benefits across a wider group of businesses and consumers. 

Granted, in the case of AI, this process might also generate a super-virus that kills us all. But hey, no system is perfect.

Trump and Musk both want to control America’s history

28 July 2026 at 12:30

Donald Trump and Elon Musk recently made headlines over an issue we don’t typically associate with this president of the United States and a tech CEO: history. 

On July 22, Musk posted on X, the social media platform he owns, that his generative artificial intelligence model Grok would produce, by year’s end, a feature-length movie of “The Odyssey” that is “historically accurate and true to the art of Homer.” Two days later, Trump issued an executive order mandating that signage be placed on the exterior of Smithsonian Institution museums, alerting visitors to the “inaccurate information” conveyed in the displays within, and directing them to “locations and resources for accurate information regarding America’s history.” Striking in these two apparently unrelated episodes is one word in particular — accuracy — and important lessons museums and historians can learn to combat these attacks on the integrity of historical research.

While frenemies Trump and Musk have a complicated relationship, both continue to be involved in a large-scale transformation of government by means of its fusion with corporate interests, and particularly with corporate investment in AI.

There is an important, material connection between these incidents: AI. While frenemies Trump and Musk have a complicated relationship, both continue to be involved in a large-scale transformation of government by means of its fusion with corporate interests, and particularly with corporate investment in AI.

In the same week that the pair were ranting over historical “accuracy,” Michael Kratsios, the president’s science adviser, proposed overhauling the government’s approach to funding the sciences. His plan would leave that role to corporations and private philanthropists instead. Kratsios is not a scientist; his previous experience includes working at an investment fund run by Peter Thiel and for the Department of Government Efficiency under Musk. Among the priority areas Kratsios promotes for this new funding model are AI, quantum computing and robotics. And on the same day he introduced his proposal, Kratsios announced the winners of research grants from the Genesis Mission, the administration’s AI initiative.

While this push to redirect the country’s scientific research has incited alarm, reactions to interventions in the historical humanities have been more muted. Yet attacks on public museums and on creative retellings of historical narratives are just as dangerous to the health of this country’s democracy.

When he testified on July 21 before the Republican-led House Oversight Subcommittee on the perils of government intervention in the Smithsonian’s activities, David Blight, a professor of American history at Yale University, offered a righteous defense of his profession. Besides highlighting the need for close engagement with history to lead to richer understandings of the past, Blight said it was necessary to disturb the questionable stories — those supposedly incontestable truths that the Trump administration insists are more “accurate” — that have been ingrained in our cultural memory. “If we’re not careful,” he warned, “we will end up with what the great writer Toni Morrison called ‘statist history.’ And it will create what she called ‘sanctioned ignorance.’”

AI has become a blunt instrument in the enterprise to impose precisely this form of sanctioned ignorance about America’s past. The signs Trump proposed for the outside of the Smithsonian suggest vaguely that there is another, more “accurate” history to be found elsewhere, and generative AI is exactly what Musk is proposing to provide this. Taken together, their plans amount to a one-two punch, history in the hands of the corporate state. 


Start your day with essential news from Salon.
Sign up for our free morning newsletter, Crash Course.


The federal government’s prospective disinvestment in the sciences has long been the status quo for the humanities, with corporate foundations and private philanthropy providing the main funding sources. Media outlets have recently been reporting on partnerships between museums, historical image collections and AI firms. A recent Financial Times article pointed to the prevalence of AI companies throwing struggling museums a “lifeline” by promising to bring in new audiences attracted by the prospect of chatbot-led “personalized” tours, along with other glitzy experiments. 

It may be tempting to see value in projects such as the Schmidt Foundation — that’s Eric Schmidt of Google — funding a fellowship in AI at the Metropolitan Museum of Art, or the Musk Foundation’s support of the Scroll Prize to use AI in reconstructing ancient texts in the burnt scrolls of Herculaneum. But these projects are simply two among countless others that have been seeding AI into museums and historical research for well over a decade. Even more egregious is the case of AI companies buying  and destroying rare books en masse in the process of scanning them for data. In the context of the dire austerity we are witnessing, the juggernaut of tech money seems impossible to resist. But the public should know the dangers of ceding the precious work of peering into the past to those whose chief aims are to exploit it for data and build visions of our collective history to their own liking. 

It is a fact that AI is inherently incapable of producing an accurate image of the past. The data on which image recognition and generative models are based rely on statistics and probability to arbitrate the truth. Algorithmic mediation of the past means that the greatest weight will be given to what privileged institutions have already been able to preserve in the greatest numbers. 

In other words, AI is unable to treat evidence — or people — equally with context and knowledge of how that evidence relates to the inequities built into museums and image archives themselves. Yet the more space we grant to Big AI, in partnership with an authoritarian state, into institutions of historical research and public communication about history, the less able we will be to find our way toward historical accounts that have fallen into the cracks of algorithmic data sets. 

No amount of feeding them more data will make them better able to offer a vision of history that is more accurate to the past and an essential part of our striving toward a more equitable future. That fact alone threatens the future of democracy.

The post Trump and Musk both want to control America’s history appeared first on Salon.com.

How public opinion is turning against AI

20 July 2026 at 13:30
Demonstrators march in a crowd while holding up anti-AI signs.
Demonstrators march during a protest against AI data centers in Vancouver, British Columbia. | Ethan Cairns/Bloomberg via Getty Images

AI was supposed to make our lives better. Instead, it’s made many of us scared and angry. Communities are protesting against the building of new data centers — the warehouses of IT equipment powering the AI buildout — across the country, and increasingly they’re winning. And polling shows most Americans think AI is moving too fast.

So how did public opinion on AI curdle so quickly? Jasmine Sun, who reports on the industry from San Francisco, argues that the backlash treats AI less as a technology and more as a political project. “The debate was not about like, is ChatGPT useful to me?” Sun told me during a taping of Vox’s The Gray Area. “The debate was actually something more like, there are these big corporations and unaccountable billionaires…coming into my city, coming into my life and changing it without having any sort of democratic input?”

Filling in for Sean Illing, I talked to Sun about the rise of “AI populism,” the parallels with the Industrial Revolution, and how the backlash could crash into the 2028 presidential election. 

As always, there’s much more in the full podcast, which drops every Monday, so listen to and follow us on Apple PodcastsSpotifyPandora, or wherever you find podcasts.

You’ve been writing about a phenomenon you call AI populism. How would you define that? What is AI populism?

I define AI populism as a worldview where AI is not seen as an ordinary technology, but specifically as an elite political project to be resisted. I came to the term while thinking about the AI backlash and the reasons people are increasingly anti-AI — whether that’s LLM slop, whether that’s Waymos in their city, whether that’s a new data center project. One thing that occurred to me was that a lot of times the debate wasn’t about whether ChatGPT is useful to me, or whether Waymos are safer than a human driver. The debate was actually something more like: There are these big corporations and unaccountable billionaires who are coming into my city, coming into my life, and changing it without any democratic input.

When I talk to people who are opposing AI in various ways, they seem more concerned with this concentration-of-power, anti-elite dimension — which is where I take the word “populism” — rather than classic AI safety concerns, which are more about the technical characteristics that might introduce risk.

You wrote a piece that touched on some of this but went to a darker place — “AI populism’s warning shots” — and you wrote about actual shots. Sam Altman, the CEO of OpenAI, was targeted by a Molotov cocktail and a shooting within the span of a couple of days. There was an Indiana councilman who voted for a data center and woke up to gunshots at his home and a note reading “no data centers.” Why do you think of those incidents of violence as warning shots of something to come?

It was pretty scary. I’m no Sam Altman fanboy, but it’s terrifying that assassination attempts are showing up in response to people’s worries about AI. One factor is that we’ve been seeing a rising wave of political violence and support for political violence in the US, especially among young people, over the past few years — the UnitedHealthcare CEO shooting, the Charlie Kirk shooting. Increasingly, a lot of disaffected, maybe nihilistic young people are turning toward political violence as a way to express political beliefs they don’t feel they have other channels for. Or maybe that person is just unwell. But I do expect to see more of it, because my theory of political discontent is that if people feel they have institutional channels to bargain for their rights — if they feel the democratic process is working, or they’re part of a union and believe their union leader will go bargain about how automation shows up in the workplace — they’ll most likely go through those channels.

When it feels like the official channels aren’t working, opposition becomes much more diffuse and volatile. That’s part of why, in creative communities, you’ll see people witch-hunting each other over AI use. I think we’ll see more political violence against people seen as AI leaders, or as supporting AI leaders.

That’s really scary.

Yeah, I’m quite worried about it. But again, my sense is that it comes from a feeling of — what else is there to be done, when you have this level of concentration of wealth and power, and there’s no democratic input right now into how AI is regulated or built?

It’s like a jump straight from complaining at your community meeting about the data center to an act of violence.

I was talking to some friends about this. During the 20th century in the US, there was a wave of factory mechanization and automation, but unions were really strong — often when a company said, “We’re going to bring in these machines,” they’d sit down with the factory union leader and say, “Okay, you can bring in the machines, but we’re going to couple that with a wage increase,” or a 35-hour workweek, or earlier retirement. There was a channel to make a deal about how automation would show up in your workplace. That meant people were more likely to accept it as something lifting all boats. I don’t think that’s happening now — most of the industries affected by AI aren’t organized in labor unions, and the democratic channels are questionable at best.

It’s like when people have agency to be part of the transition, the process goes a lot smoother. Is there a historical analogy for a technological change that didn’t allow for input from the people involved? I’m thinking of the Luddites.

The Luddites are a good example. When the automated looms were introduced, there was a lot of violence against the looms. The book I’d really recommend here is Carl Benedikt Frey’s The Technology Trap. He’s an Oxford economist who studied a ton of historical examples — in Europe, in China, all over the world — including the Luddites and 20th-century automation. His central question was: In what contexts do workers successfully stop automation, and in what contexts do they allow it to be introduced? How does the political environment, or the balance of power between people and their leaders, change the outcome? He found that when automation was introduced alongside social welfare policies — a higher minimum wage, some form of redistribution — people were much more willing to accept it, which is fairly rational.

I want to talk about Silicon Valley’s understanding of this backlash more generally. You’re painting a pretty dark picture, and you’re right in the belly of the beast in San Francisco — I’m sure you talk to people involved with AI every day. Is there a moment when it clicked for them that this backlash is real and something they have to take seriously? Or has that happened yet?

I’ve definitely noticed a huge difference, over the past six months, in how seriously people in Silicon Valley take the AI backlash.

Like what?

People just talk about it more. I’d bring up AI populism to people last year, and they’d normally say, “It doesn’t matter — technology always introduces some discontent, people get annoyed but they get used to it, like the internet.” That was the standard reaction last year. Not anymore. I think part of the reason OpenAI and Anthropic have felt pressure to introduce economic policy proposals around job automation is that they’re seeing how worried people are. The data center moratoriums and the broader data center backlash have been surprising and meaningful in getting AI leaders to recognize they have both a messaging problem and an actual problem with the product and the technology they’re introducing.

A lot of the increasing opposition to AI in Washington has caused people to see this too. At first, Trump — as you mentioned — was very pro-AI. He and David Sacks were accelerationists; they wanted AI to go faster and to block attempts at regulation.

He was the AI czar.

“The moratoriums, the regulation fights, even the booing at graduations, the literal assassination attempts — people in Silicon Valley have become much more worried.”

He was the AI czar — he’s no longer the AI czar. But it turned out a lot of other constituencies, both on the left and the right, were pretty opposed. For example, Trump and David Sacks tried to introduce a big federal bill that would preempt all state-level AI regulation — no state could regulate AI for 10 years. They tried to sneak it into a big omnibus bill so no one would notice. But members of Congress realized it was happening, and — whether for kid-safety reasons or frontier-safety reasons — people said, Wait a second, the idea of preventing any state from regulating AI for ten years is crazy. A lot of people organized in Washington to successfully stop that preemption. I think that showed the scale and bipartisanship of a coalition that was very keen to make sure it stayed possible to regulate AI was underestimated. As a result of all this — the moratoriums, the regulation fights, even the booing at graduations, the literal assassination attempts — people in Silicon Valley have become much more worried.

China is our big competitor in the AI race, and it certainly has all the conditions for a populist pushback to AI — youth unemployment is really high, and AI technology is in some ways more advanced at taking over real-world jobs. I was watching a video about fully automated factories and a robot pharmacist. You’re one of the rare American tech reporters who gets to spend time in China, and you wrote a piece that surprised me — you found there wasn’t really a populist backlash to AI there. Why not?

I was really interested in this question, and I was finishing my New York Times piece while in China for a few weeks, talking to both AI people and non-AI people. The main reason there’s not a big populist backlash in China is that there isn’t a lot of social unrest or populist backlash against anything — the entire MO of the Chinese government, the No. 1 priority, is domestic social stability. Any whisper of protest gets shut down; that’s why they have such strong speech controls. So one factor is that China doesn’t have much of a culture of resistance in general, whether in workplaces or politically. I’m not saying no one dissents — but it has a cultural effect too, because people don’t see it as useful or as an option. When I ask family members of mine in China about AI, sometimes they’re annoyed about specific things, but fundamentally, the idea of opposing AI is seen as almost unimaginable.

The other thing about China is that if you’re middle-aged there, you’ve lived through so many political, economic, and technological revolutions in your lifetime. When I was a little kid visiting Shanghai in the mid-2000s, there were no high-speed trains — now China has some of the best high-speed rail systems in the world. Technology has always gone hand in hand with dramatic economic advancement, with being lifted out of poverty. The modernization process has been aggressive and disruptive, but it’s not something the party has offered opportunities to resist, and it’s something most Chinese people still see as an inevitability that was mostly good for most people — because incomes did increase by dramatic amounts alongside the technological change. So I think people have a similar attitude toward AI: It’s much less about “Can I stop the AI wave?” and more “How can I take advantage of the AI wave to get ahead economically?”

We were just talking about this deep pessimism about what technology can bring us here in the US. I think a lot of people look around and think: We don’t have a cure for cancer yet, but we’ve sure seen our lives get worse in a lot of ways because of technology, social media, whatever. That pessimism probably fuels the backlash to AI, the skepticism about whether it can ever deliver on its promises. And that experience just isn’t the same in China, or probably much of the rest of the world, where technological progress has been faster and more concrete in people’s lives.

My 90-year-old grandfather said he’d love an elder-care robot to help him do tasks around the house so he doesn’t have to rely on his kids — he wants more freedom and mobility. It’s seen more as a tool to help individual goals. Even with the robot factories or pharmacies — one thing that struck me visiting a robot pharmacy was that the PR people happily said, “Yep, we’re doing these robots because human workers take too many smoke breaks and bathroom breaks and take too long.”

You’d never say that in the US, but they’re probably thinking the same thing — they just don’t say it. The other thing they mentioned is that this lets the pharmacy operate 24/7, because a lot of people need medications in the middle of the night and want to order via the DoorDash equivalent. There was actually a labor shortage before — Chinese workers weren’t willing to work night shifts — so these pharmacies are offering real consumer surplus. A significant percentage of orders come in overnight, when no other pharmacy is open. And with the factories, part of the issue is that Chinese workers, especially young people, don’t want to do factory work anymore.

“I think the 2028 presidential primary and election is really where I expect AI to become a centerpiece of the conversation.”

That anecdote gets at the promise and peril of AI, and the role of the backlash movement — which I’m still wrestling with how I feel about. On the one hand, I want to live in a world where cancer gets cured, where we live in an era of abundance, where things are cheap and easy to make because factories can run all the time with machine workers who don’t require anything — I want the future we were promised, of flying cars and everything working well.

But I also don’t want to lose my job, or see humanity wiped out by an angry machine god. Because we don’t really know what’s going to happen yet, it’s hard to work out my own feelings about the pushback here in the States — what’s appropriate, and what’s holding us back from real advances in our lives.

Totally, I agree. I like Waymos — I think they’re safer, and I’d prefer a safer robot car driv[ing] me around instead of me driving. I’m not a good driver; no one should let me drive. So I wrestle with some of the same things.

To close out the conversation — let’s come back to the United States. AI populism is brewing as a political force. We’ve seen it show up in a couple of races so far, but it’s early. We’ve got the midterms, then the presidential election. How do you think it’s going to affect American politics this November, and in 2028?

My sense is that this November, it’s going to be more about state and local races where AI really shows up. I’m going to spend some time in Michigan and Wisconsin this summer touring some of the data center sites facing the most opposition — those states also have contested governor and Senate races where AI and data centers have become a core issue, so I’m interested to learn more there. I think the 2028 presidential primary and election is really where I expect AI to become a centerpiece of the conversation — especially if we start to see some of the employment impacts people are expecting. As soon as we see something like a 2 percent rise in unemployment, if that happens, I think people will be very upset, and we should expect a ton of focus on the issue.

The other thing I’ll note is political opportunism — you’re already seeing a bit of this, where politicians are likely to raise the salience of AI above where people might ordinarily care about it, because it’s become a convenient boogeyman. It polls so poorly, people are so anti-AI and anti-data-center, AI billionaires are so unsympathetic, that no matter what your policy program is, AI is a great reason to push it. I think a lot of politicians who are being clever about this are going to move AI to the center of the conversation, raising its salience to manufacture urgency for proposals they’re already excited about. That’s definitely something I’m watching for 2028.

America needs a real AI economic plan — before the crisis hits

9 July 2026 at 12:00
President Donald Trump signs the H.R. 748, Coronavirus Aid, Relief, and Economic Security (CARES) Act, in the Oval Office of the White House in Washington, DC, on Friday, March 27, 2020. | Erin Schaff/The New York Times/Bloomberg via Getty Images

When you ask people when they knew Covid was going to be a huge deal, they give a range of answers. “When Tom Hanks got sick” is a popular one. So is “when the NBA suspended the season.” The most plugged-in people will sometimes cite early rumblings from Wuhan in December 2019/January 2020.

Key takeaways

  • AI is scaling faster than any past tech boom, and it’s likely to produce an economic emergency — a moment when policymakers will suddenly accept big risks and big changes. The US isn’t ready.
  • These crisis windows open dramatically but close fast. In 2008 and 2020, near-universal cash payments and huge bailouts won bipartisan support, then vanished within months. Assuming AI will permanently shift politics toward generous policy is wishful thinking.
  • Today’s proposals fall short on both ends: AI labs offer sweeping ideas — sovereign wealth funds, portable benefits — with none of the detail legislation needs, while DC figures like Gina Raimondo push undersized fixes like retraining, too small for a transition that could wipe out whole categories of work.
  • Whoever has a detailed, ready-to-pass plan when the moment hits gets to shape it — the way TARP came straight from a “break the glass” plan drafted months earlier.

For me, the turning point came on March 17, 2020, when Republican Sen. Tom Cotton proposed sending every American checks from the government.

To be clear, at this point, my then-employer Vox had already sent everyone to work from home indefinitely, and it was clear something dramatic was happening. But I hadn’t yet internalized that the Overton Window in American politics had shifted dramatically. 

True, there were some Republican Senators who, by 2020, were expressing more openness to safety net programs, and rethinking Reagan-style laissez-faire economics. Tom Cotton, though, was not one of these senators. I didn’t think he really had strong economic policy opinions at all; he was a defense and culture war guy. He cared about defeating China and, secondarily, defeating Woke. Universal cash handouts were not his bag. And yet here was Cotton, not just calling for near-universal cash payments, but also for welfare work requirements to be suspended and for big block grants to states to expand unemployment insurance. 

This turned out to be an early indication of the actual policy the US would pursue. Within a couple of weeks, with the US unemployment rate fast headed for what would be a record high of 14.7 percent in April, a Republican Senate and president had signed off on the CARES Act, which included payments of up to $1,200 per eligible adult, $2,400 for eligible married couples, and $500 per qualifying child, along with a $600 per week unemployment insurance and a massive business bailout program. The Senate vote was unanimous, and the House approved the final Senate amendment by voice vote. 

If you had told me literally any of that would happen in February 2020, I would have laughed at you. But the normal rules had stopped applying. All that was solid had melted into air. Much, much bigger things were, suddenly, possible.

I’ve been thinking about that moment a lot as advanced AI models grow more and more capable, and more and more central to many businesses’ strategies. As of May, Anthropic is reporting an annualized revenue rate of $47 billion, equaling the likes of Coca-Cola and exceeding Netflix. That’s up from $30 billion a month earlier. If their revenue keeps growing at 56.7 percent a month, they will outpace Amazon, currently the highest-revenue company in the world at $717 billion a year, by late November or early December. The AI boom is already unfolding faster than the internet or mobile booms before it and may yet speed up even further. The debate over whether this tech is real and valuable is, essentially, over. The only question is what, and how large, its effects on our lives will be. 

This is happening unbelievably fast, and it seems likelier and likelier that we will face a moment, like that in March 2020, when the speed and disruption of AI progress begins to constitute an emergency that policymakers will be willing to take surprisingly large risks to confront. There will likely be a moment of unusual policy freedom and flexibility, a moment which is brief — but could enable large changes for the better.

The US is currently not ready for that moment. But we need to get ready, fast. And we need your help. My colleagues at the Center for Shared AI Prosperity, a new DC-based research group, are attempting to collect a menu of detailed policy ideas that can meet this moment. In fact, we have an open Request for Ideas with funding that can go to the best proposals people submit for how to set up the tax code and safety net in a way fit for the AI era. Now is the time to act.

These moments don’t last forever

I sometimes talk to friends in the tech world who assume that the power and economic impact of advanced AI will permanently shift our politics, and that the policies necessary to keep everyone afloat (like, say, a guaranteed income, or a sovereign wealth fund) will materialize without much effort. After some 17 years as a journalist covering US politics and policy, I think this is overly optimistic, so say the least. Congress is like jello: flick it and it will shake, but it eventually settles back to normal.

Take Covid. Within a couple of months, the apparent consensus had evaporated, and Republicans were back to resisting safety net expansion. By May, Cotton had pivoted to pushing the No Bailouts for Illegal Aliens Act, which “amends the CARES Act to prohibit sending future funds to states or municipalities until they certify they aren’t issuing stimulus checks or other payments to those in the United States illegally.” By August he had a bill to deny virus-related federal employment funds to people convicted of federal offenses because of “riots.” The pandemic was still raging but the policy emergency, and the bipartisan window for much larger-scale action, had mostly closed.

The 2008 financial crisis offers another example. There, the window was open somewhat longer. At the very beginning of the recession, in February 2008, the Bush administration went against its normal laissez-faire commitments and supported a stimulus package championed by then-Speaker Nancy Pelosi built around per-person checks to nearly all Americans, including many of those not owing income tax. In July, President George W. Bush signed a bailout of Fannie Mae and Freddie Mac in the face of strong opposition from fellow Republicans in the House, but having mostly won over his party in the Senate.

In September, when Lehman Brothers collapsed and the possibility of a cascade of massive bank failures seemed very real, Bush demanded a sweeping $700 billion bailout that proposed purchasing toxic assets from at-risk banks (the “Troubled Asset Relief Program,” or TARP). As the subsequent years would demonstrate, bailing out banks failing due to their own irresponsibility was not exactly a popular position in the general public. Members of Congress are not stupid, and they realized this at the time. On September 29, the House voted down the proposal, with huge numbers of both parties defecting from Bush and Pelosi’s position. That led to a large stock sell-off that terrified lawmakers. That experience, some last-minute tweaks, and truly herculean lobbying from the administration, the Fed, and others led the House to switch course and pass the bill on October 3, though within weeks of its passage, Treasury abandoned asset purchases in favor of buying equity stakes in the banks directly.

The full course of 2008 shows the value of, and power inherent in, being prepared. The February 2008 stimulus package was very roughly improvised. It worked a little bit, but proved nowhere near big enough. If Pelosi and Bush had had a more thought-through proposal on hand, perhaps one that automatically repeated and scaled the checks depending on where the unemployment rate went, then the recession would have been much less severe and the 2009 stimulus might not have proven necessary.

TARP was an example of a case where some key actors were prepared. The structure of the program came from the “Break the Glass Plan,” a proposal put together by Bush Treasury officials Neel Kashkari and Philip Swagel in April 2008 explicitly designed as a “just in case” plan for the extreme situation where the whole financial sector needed recapitalization. That case, of course, came to pass, and because Kashkari and Swagel had a plan, there was something for Congress to quickly pass. That was good — TARP played an important role in preventing the financial crisis from worsening.

But it also meant that the plan reflected Kashkari, Swagel, and their boss Hank Paulson’s overall conservative worldview. One could imagine a plan like that which saw the US government instead outright nationalizing major banks, or imposing strict capital requirements on them in perpetuity as a condition of the bailout money, or banning them from owning hedge funds or doing speculative trading. A different administration with different views might have designed a different emergency plan — and because it was genuinely an emergency, that plan would likely have passed, with very different consequences over the next few years. 

What stocking the shelves for AI means

One way to think of the project of AI economic policy in 2026 is as designing the equivalent of the Kashkari-Swagel plan: something detailed, opinionated, and actionable that can be deployed quickly when the situation gets dire. What that plan looks like will, of course, depend on one’s values and commitments; the America First Policy Institute’s emergency plan will not look like the AFL-CIO’s.

The Center for Shared AI Prosperity was founded with an aim to produce plans of this nature designed to make sure any economic windfall from AI is widely shared, and that workers and low-income Americans are not left behind in the transition. We were also founded out of a frustration at the inadequacy of the proposals we were seeing from two ends of the AI policy debate.

On the one side are ideas from the AI labs themselves. These tend to be ambitious — indeed ambitious enough to seem like plausible answers to a problem of the magnitude of AI completely reshaping the economy — but woefully unspecific. They more closely resemble dorm-room philosophizing rather than legislative drafting.

OpenAI’s “Industrial Policy for the Intelligence Age” from this past April, is one such example,  laying out a number of very broad ideas: taxing capital more, a sovereign wealth fund invested in the AI economy, portable job benefits. It’s light on the specifics: What kinds of capital taxes? How big a hike is too big? How do you make health benefits portable without disrupting people’s current plans? How does the sovereign wealth fund get its money? Anthropic’s Economic Policy Framework is somewhat more specific, offering paragraphs per idea where OpenAI has a sentence or two, but still nowhere near the level of detail necessary to actually write legislation.

On the other side are proposals from within the DC policymaking world, which are firmly rooted in what seems politically viable right now but would be woefully inadequate in the face of the likely economic disruption that’s coming. Former Commerce Secretary Gina Raimondo and her group RAISE US have centered employee retraining; Raimondo’s recent New York Times op-ed centered ideas like new credentials from community colleges and expanded apprenticeship programs as the answer to mass AI unemployment. These are sensible tools for ordinary labor-market churn, but they are mismatched to a transition that could displace whole categories of work on a compressed timeline. The dawn of machine intelligence will demand more from our leaders than certificate programs.

The best case for this kind of caution is that ideas on the scale of the labs — sovereign wealth funds, universal capital accounts for all Americans, permanent relief funds for the long-term unemployed — are dead in the water in DC. Which might be true — now, at least. 

But this is where Tom Cotton’s brief love of cash transfers becomes relevant. We should not overindex on the way the politics look right now. The world is about to become very strange, and we may be surprised by the scale of change in response that can earn even bipartisan support.

Indeed, it’s notable that both the 2008 relief measures and the 2020 CARES Act came under Republican presidents with Democrats controlling at least one chamber in Congress, which is also the likely situation after the midterms this year. Democrats are always willing to vote for big new safety net programs to protect unemployed and low-income people. But Republicans are often willing to compromise their usual anti-welfare stances when they’re the party in the White House, and their approval ratings depend on the country’s basic economic health.

What action they might take in a 2027 or 2028 featuring massive AI-based economic disruption is still unclear. But right now, we all have an opportunity to help shape it. The Center for Shared AI Prosperity is running a request for ideas, seeking proposals for shared AI ownership, new AI-related taxes and revenue raisers, and new safety net programs to share the gains widely. We want ideas from economists and think tanks, of course — but also from the labs, from independent researchers and academics, and from ordinary citizens with an interest in where this technology is going.

Stocking the shelves is hard work, and we don’t have all the answers. But you just might, and we’re going to need all the help we can get if the US is going to emerge from the AI transition as a prosperous, functional nation.

❌