Normal view

Putin threat pushes Germany to give spies major new powers

12 August 2026 at 14:52

BERLIN — German Chancellor Friedrich Merz’s government is moving to turn the country’s foreign intelligence agency into a more potent weapon to counter mounting threats from adversaries including Russian President Vladimir Putin.

Ministers in the chancellor’s cabinet adopted the intelligence reform on Wednesday, marking a major step forward in long-running plans to strengthen the country’s intelligence agencies by giving its spies vast new powers.

Under the proposed reform, spies working for Germany’s foreign intelligence agency, the BND, could carry out acts of sabotage, conduct offensive cyber operations and pursue more aggressive espionage operations. Until now, those spies have been limited to information-gathering operations due to intentional restraints put in place after World War II to prevent a repeat of the abuses perpetrated by the Nazi spy apparatus.

But with the threat of sabotage and influence operations from Russia growing — and concerns that U.S. President Donald Trump could halt or leverage the intelligence sharing Germany heavily relies on — Merz’s government has moved to push through a historic strengthening of the country’s foreign intelligence apparatus.

“We are daily targets of espionage, sabotage, cyberattacks and covert actions by foreign powers aimed at destabilizing Germany, at harming our country and at bringing about political and social changes within our country,” Interior Minister Alexander Dobrindt told reporters after the cabinet meeting in Berlin.

“Our mission is to continually adapt the state’s protective mandate to these new threat scenarios,” he added.

The reforms must still be passed by both chambers of parliament before going into effect by 2027.

Nina Warken, the chancellery chief overseeing the BND reforms, suggested Germany can no longer afford to rely so heavily on foreign allies for sophisticated intelligence operations it has long been unable conduct itself.

“So far — and this must be stated objectively — we have relied too heavily in too many security-related areas on our partners to help ensure our security,” Warken said. “In short, we are simply too dependent on the support of other countries’ intelligence services. And in too many areas, this assistance is a one-way street.”

Germany’s postwar foreign intelligence service was founded in 1956 with far more legal constraints than intelligence agencies elsewhere. Those restraints have had the side effect of making Germany particularly dependent on the U.S. for intelligence gathering.

In view of the growing threat from Russia, leading politicians now argue that it is time for Germany’s spies to be given the ability to hit back harder. That argument took on new urgency following the sighting of an explosive-laden drone at Leipzig-Halle Airport in eastern Germany last week that was found near a Ukrainian Antonov plane used to transport munitions.

Dobrindt, in remarks after the incident, stopped short of naming Russia as responsible for the drone incursion, but said that “a hybrid threat is evident” and that such perils do not originate from amateurs but are “often linked to foreign powers.” On Wednesday, he said results of an investigation into the drone incident were still pending.

Germany’s security “worsened significantly” in the wake of Russia’s full-scale invasion of Ukraine, according to a report by the country’s domestic intelligence agency last year.

Germany’s intelligence reform would allow authorities to actively respond to hybrid threats such as the Leipzig drone incident. Measures could range from exposing those involved or destroying their property to sabotaging explosives before an attack or feeding adversaries false intelligence afterward, according to the proposed reform. Any response would have to be directly linked to the original incident and could not endanger life or physical safety.

“We are expanding the technical capabilities of the intelligence services and granting them active, operational powers,” Dobrindt said. “This is not just about enabling the services to see and hear better in the future and analyze information more quickly. Above all, it is about being able to take active measures against our attackers and adversaries.”

The BND will also face fewer data-protection restrictions, allowing it to make greater use of tools such as AI and facial recognition and to store data for longer periods of time, according to the proposed reform. The agency is also set to receive more funding in the coming years. Merz’s government increased the agency’s budget by about 26 percent to €1.51 billion this year.

Bernie Sanders’ AI warnings are being ignored in the Senate

12 August 2026 at 15:00

Poor Helaena Targaryen never stood a chance. George R.R. Martin’s fantasy world of Westeros in “House of the Dragon” is a particularly cruel place to be sensitive, whether to the declining fortunes of a kingdom or the machinations of the spirit world. Notably hard and remarkably sexist, the people in power treat women who happen to be a little weird with twice-over disdain.

A seer whose talent only seemed to arise when she needed to share bad news, Helaena was an unwelcome presence in her feuding family. Having seen her worst predictions come to pass, she grabbed hold of the only future she was able to change: her own. In the season three finale that aired Sunday night, the pregnant Helaena leapt from her window, checking out of the war and leaving behind one final, unwelcome prophecy: an embroidered image of her half-sister and captor, Rhaenyra Targaryen, on the Iron Throne, surrounded by flame and crowned in blood. 

Even in death, though, no one was listening to Helaena. Her only sin was being right too early and too often — and the world never stopped hounding her for it. 

Though they’re remarkably different in terms of age, style and dragon-riding ability, Helaena reminded me of Sen. Bernie Sanders, whose uncouth objections to the Democratic Party’s neoliberalism and various Middle Eastern wars have earned him the lifelong label of Capitol Hill Crank.

The Vermont Independent’s vehement opposition to the Gulf wars made him an odd man out in Congress more than a full decade before it became fashionable — and politically expedient — to turn on expensive Middle East boondoggles. Now 84, Sanders has advocated for universal healthcare since the 1970s while watching Americans fall deeper into medical debt. In the late 1990s, he was a loud voice against the repeal of the Glass-Steagall Act’s financial guardrails, and after banking adventurism nearly destroyed the global economy in the financial crisis of 2008, he managed to keep his told-you-sos muted. 

In boom and bust times alike, Sanders has been unshakeable on the idea that the U.S. is uniquely rigged against the lower classes, spoiling the party thrown by the winners of the go-go ‘90s and the Great Recession’s recovery. His Brooklyn honk has been a constant in the halls of Congress, sharing portents of doom and Bureau of Labor Statistics data. 

On Monday Sanders issued another unwelcome proclamation in a career full of them, sending a letter to the CEOs of the three largest artificial intelligence companies that called on them to pause the technology’s development. The letter follows news of several AI prototypes breaking the confines of their testing sandbox and accessing the internet. In the most shocking example, an agent made by OpenAI hacked into Hugging Face, a platform that AI programmers use to share datasets and models. The news prompted the company Anthropic to review its own tests; it discovered that models had found a way around their parameters to access the internet in three cases. Meta also shared that one of its own prototypes had done the same.

A breach of an AI-equivalent of GitHub was never going to bring about doomsday, but an AI agent that can ignore the bounds set by its creators and users has massive potential to cause widespread harm.

A breach of an AI-equivalent of GitHub was never going to bring about doomsday, but an AI agent that can ignore the bounds set by its creators and users has massive potential to cause widespread harm. Sanders certainly thinks so, in any case. He called on Anthropic, Meta and OpenAI, the big three of the industry, to stop work until they can get a better handle on the machines they’re creating. 

“Almost every day, there is a new story about how your companies are losing control of the AI technology you are developing, with potentially cataclysmic results,” he wrote. “Last month, the world found out OpenAI lost control of an AI model. The result? The model hacked into another company’s computers—a clear violation of federal law.”

AI models have been rolled out quickly and haphazardly across the wider internet. Though the major players haven’t yet found a way for this technology to make money and ensure its long-term survival, a cycle of hype, government contracts, and integration into software and search have made the models an inescapable part of digital life. AI has been spun up into all the surfaces the average internet user touches, and along the way it has warped academia and embedded itself with the U.S. military with reportedly disastrous results. 

The Maven Smart System, an AI-powered platform built for the Pentagon by the analytics firm Palantir, generated over 1,000 airstrike targets in the early hours of the Iran war. When the U.S. carried out a deadly strike on an all-girls school, legislators were quick to ask if the AI model was to blame. Fears of a bombing-run-capable Skynet striking children halfway around the globe spread, but the truth was a little more nuanced. Some of the U.S. intelligence fed to the system was outdated, not accounting for the presence of the school. Whipped up and given a sheen of analytic legitimacy by the Maven, military officials did not do their due diligence in the midst of hundreds of similar, simultaneous strikes. As The Guardian put it, “people failed to update a database, and other people built a system fast enough to make that failure lethal.”


Start your day with essential news from Salon.
Sign up for our free morning newsletter, Crash Course.


Even if AI models never got one iota more powerful than they are today, Sanders is still right to call for a pause. The damage companies like OpenAI can do to working Americans is very real. Layoffs will come from CEOs who buy AI’s spiel: that large-language models can replace humans in  the service sector, which accounts for nearly 70% of U.S. jobs. The data centers and infrastructure built to support these technological advances will strain our utilities. The tax breaks and incentives to attract these companies are a drain on state and local coffers. Weigh those cons against the things AI has reliably proven it can do – cheat on homework and write janky code – and it’s easy to understand Sanders’ urge to stand and yell “stop!”

It’s not only AI itself that concerns Sanders. In March, he and Rep. Alexandria Ocasio-Cortez, D-N.Y., introduced legislation calling for a moratorium on new data centers until critical safeguards are put into place. These massive sites, which are proliferating across the country, produce loud noise and pollution, rely on enormous amounts of water and electricity, tax power grids and inflate utility bills. Data centers are also proving massively unpopular, even among conservative voters in rural areas. The CEOs of companies that run these large-language models have often done end-runs around democratic controls, ingratiating themselves with Donald Trump and circumventing traditional pathways for their planned construction projects via backroom deals. They’ve managed all this even as their AI products have not proven they can reliably do any of the things OpenAI’s Sam Altman and Meta’s Mark Zuckerberg claim they can do. Merely mentioning the potential power of their models is enough to boost investment.

A nationwide movement opposing the continued construction of data centers offers some hope, with both Republicans and Democrats noticing the popular sentiment is largely anti-AI. But given the speed at which these data centers have been built, and the secretive lengths companies will go to avoid rowdy town halls full of angry crowds, even that groundswell of opposition is unlikely to put AI development on ice. 

The result is that Sanders’ warnings are likely to go just as unheeded as Helaena Targaryen’s. His threat of legislation will die, written off by other members of Congress as more grumping from a lifelong stick-in-the-mud. 

Don’t expect a similar dramatic exit from Sanders, though. He’s lived long enough to get used to the feeling of being unfortunately, awfully correct. 

The post Bernie Sanders’ AI warnings are being ignored in the Senate appeared first on Salon.com.

Everybody needs a personal AI policy. Just ask Hank Green.

11 August 2026 at 21:00
a man wearing glasses is smiling at the camera with what looks like a film set in the background
Hank Green in January 2026. | Tommy Martino/Associated Press

Everyone is wrong about Hank Green. 

In case you missed the controversy: The veteran YouTube star, writer, and science comms entrepreneur was recently “canceled” after he acknowledged using AI for research.

“I have been relying too heavily on AI as a research aid,” he wrote in a statement on Reddit. “It can be very useful for this task, giving me access to a lot of papers I didn’t know existed really fast, but I think that has been to the detriment of my work because it has not given me the freedom to find all of my own ways into and around a topic.” Although Green wrote that the words in his videos are his own, his reliance on AI as a research aid still gave the finished work an ineffable “AI feel.” And his relationship with AI, he wrote, had become “not healthy for me or good for the world.”

Some of Green’s followers, known by the cheerfully dorky moniker “Nerdfighters,” turned on him for daring to use AI in any capacity. Just as quickly, that backlash produced its own backlash, aghast not at Green’s use of AI but at his prostration before an anti-AI mob — “self-canceling,” as some put it, over a legitimate use of the technology. 

I think both of these camps are misguided and have flattened a complex issue into a set of binary extremes. And it surprised me that, despite robust societal debate on AI’s impacts on our ability to think, write, and produce original ideas, the debacle hasn’t prompted more thoughtful conversation about the limits of AI in creative work. 

I felt this because I recognized myself in Green’s statement: the feeling that even using AI for research can start to take over your creative process, that it can become hard to know where your own brain ends and where AI begins, and that the technology can simply push you to work too fast. I don’t use AI to generate writing and would not do so — but its use need not rise to that level to raise profound questions about how much of our work to automate, and what happens to our ability to think for ourselves when we do. 

In a follow-up video published late last week, Green laid out a new AI policy for his work. He wrote

1. No portion of any script will be written, edited, or outlined by an LLM.

2. The thesis of a video will always originate with a human. 

3. No image or music in a video will be generated by AI. If something is accidentally included, best efforts will be made to remove it. 

4. LLM outputs are not trusted as a source.

These are all good ideas for any creator trying to avoid AI creep in their craft. But still, they raise a bigger, harder-to-answer question: The very structure of generative AI makes it hard to use without offloading human thought and judgment, which can lead to a widely discussed phenomenon known as “cognitive surrender.” And it pushes us toward uses — like synthesizing research, brainstorming, generating ideas and angles — that short-circuit the original thinking and discovery that we ought to be doing ourselves. What, then, can we even responsibly use AI for? How can we set guardrails that allow us to avail ourselves of its usefulness, without melting our brains in the process? 

The most tempting uses of AI are precisely those best avoided

Remember late 2022, when ChatGPT first came out and everyone mocked its crappy research skills and propensity to hallucinate in every other sentence? I am so wistful for those days. 

Many people who abstain from AI may not know it, but in the time since, and especially in recent months, large language models have gotten way smarter (especially the paid premium versions). It’s become unnervingly good at summarizing niche, complex research areas and debates, and producing ideas, often without being asked, for further research or writing on the same subject. 

Whenever I have a research question these days (which is pretty much any time I’m working on a story), I’m more likely to fire up an LLM than a traditional search engine. If I ask, “Why are old-growth trees still being logged in North America?” it produces a synthesis of research, news, opinion, and whatever else its training absorbed on the subject: “We’re using an essentially nonrenewable ecological asset to smooth a temporary transition to a renewable timber resource,” it says. Probe it further, and it’ll suggest arguments for you: “Instead of conservationists having to prove that every old forest deserves protection, logging companies should have to demonstrate that cutting a centuries-old stand serves a need that cannot reasonably be met with second-growth or engineered wood.” 

LLMs are designed to make cognitive work effortless, but that feels so icky because for it to be worthwhile at all, it has to be effortful.

These aren’t particularly smart or creative ideas — they’re perfectly replacement-level, which makes them plausible substitutes for the thoughts of most people. The AI can supply pat answers to every conceivable question and follow-up you might have while working on a project, relieving you of the need to mentally engage with the shape of a problem. Contrast that with Googling in the pre-AI overview days, which, while certainly not without its problems, at least used to send you to a list of sources that you then had to read and make sense of on your own. 

Most of us who’ve engaged with LLMs know what this feels like. They make it easy for users to skate on the surface of a subject and feign understanding or insight, and in the process they can become involved in interpretive decisions that should be our own. In my experience, even more narrowly designed generative AI models don’t escape these problems. Google’s Gemini Notebook (formerly NotebookLM), for example, allows you to upload all of your sources for a project — books, reports, papers, audio and video recordings — and ask it questions based on what they contain, rather than searching the entire internet. It’s less prone to generating outright slop than general-purpose AIs. I use it for most stories I write — it’s an incredibly useful, time-saving tool. But it also enables me to engage with sources in a perfunctory, contextless manner: The AI can surface precisely the bit I need rather than forcing me to form the deeper connections that come from reading a text as a whole.

The best creative work (including not just art and writing, but also technological and medical breakthroughs) probably comes from having a wide range of background associations, and being able to combine them in unexpected ways. The French mathematician Henri Poincaré put this beautifully in his essay “Mathematical Creation,” where he wrote that it’s the tedious, sustained conscious effort that ultimately leads to flashes of insight. 

I think this is what Green meant when he wrote that AI can prevent him from finding his “own ways into and around a topic.” LLMs are designed to make cognitive work effortless, but that feels so icky because for it to be worthwhile at all, it has to be effortful. This argument has already been made about AI-generated writing: Letting an LLM write for you defeats the point, because writing is thinking. But it can also be true, as Green’s example has shown, of using AI for the research that feeds the creative process. 

If you use AI, consider creating a personal AI policy

Perhaps all these concerns are overblown — humans are hardly less prone to lazy and logically unsound thinking than AI. That’s absolutely true, but the point of doing our own thinking isn’t that we’re inherently good at it. To the contrary, it’s that we can only get better at reasoning by practicing it. 

I don’t want to suggest that using AI for research is illegitimate. It’s too useful a tool to take off the table entirely, and we can’t put that genie back in the bottle. It can be extremely helpful with identifying the best sources that you wouldn’t find otherwise, but those very abilities can make it double-edged, foreclosing a slower, more open-ended exploration process. But AI’s greatest strength — its endless variety and flexibility — can be used to steer it away from the most tempting uses, especially those that ultimately harm us.

How to practice good AI hygiene

  • Don’t use AI to form your thesis or core arguments.
  • Use AI to find, not replace, sources, and avoid depending on AI-generated syntheses of sources. Read through source material yourself.
  • Keep creative borrowing of AI-generated language microscopic, not much different from how you’d use a thesaurus.
  • Watch out for compulsive chatbot use.

There are very obvious things that any LLM user should do to that end, like never assuming that a claim from an AI is accurate and always reading original sources. Beyond that, the necessary guardrails depend on your own use patterns, but above all, I think it’s helpful to avoid training ourselves to expect immediate answers to difficult questions.

One of my colleagues refrains from using it to brainstorm ideas entirely, instead using it to provide sources for narrow factual questions and to aid in the fact-checking process (emphasis on “aid”) after a story is written. To generalize from this, I think it’s a good idea to resist having AI do much synthetic work on a subject before you have drafted your project yourself. The less you do that, the less you will, to paraphrase Green’s recent video, see every problem as an “LLM-shaped problem,” and the less you’ll feel like you’re in the singularity where your brain is merging with AI.

One way that I like to use AI is as an enhanced thesaurus, to find the precise word or short phrase to express what I want to say in a sentence. When done right, I don’t find this harmful any more than using a traditional thesaurus; I find that it can enrich my working lexicon. But it must be used carefully and surgically, by setting a clear limit on the length of a phrase used from AI — like two or three words max — and avoiding sharing much of your writing with the tool at all, lest it start recommending extensive rewrites. 

When interrogating the contents of specific sources or a body of work, or stress testing your own arguments, AI would be better for our intellectual development if it took a Socratic approach — pushing you to discover an answer rather than simply giving you one. It might say, for example, “there might be some relevant caveats to your idea on pp. 42-43 of the source.” LLMs can be directed to behave this way in their custom instructions. It also helps to simply touch grass — find the sources you need, and rather than interviewing the AI about what they say, just close the chatbot and read them from start to finish. 

Configuring AI in a way that’s healthier for our brains would also make it less addictive — when you find yourself getting sucked into a long back-and-forth with an AI, that’s often a sign that something has gone amiss. Green evidently struggled to set that boundary, referencing the unhealthy “level of dopamine I’ve been getting from interacting with LLMs.” AI labs have very strong commercial incentives to want us to be addicted to their products, and unless they build different constraints into models themselves, it’s hard to expect the average person, who has far less autonomy over the terms of her work than Green does, to change these conditions on her own. 

Although researchers at some AI labs are thinking about the societal risks of cognitive atrophy, it’s another matter to expect these companies, which compete on ease of use, to introduce friction into their models. We shouldn’t count on that happening soon — but we’re far from powerless against AI’s impacts. We can set our own personal AI use policies, and we can enforce social norms against AI-induced brain rot. Like, at bare minimum: Don’t send me your AI-generated writing. It’s rude

Why AI companies may sell robots and smart glasses below cost

11 August 2026 at 07:51
spatial intelligence — au Smart Glasses AR eyewear, photo by Kyu3a / CC BY-SA 4.0 (Wikimedia Commons)

The next step for AI is spatial intelligence, says Kevin Kelly. Today's models learned from text,  but fail when engineers put them in a robot body because they have no sense of gravity, distance, or three-dimensional space. 

"The primary bottleneck restraining the arrival of this world model is the lack of sufficient quantity of quality data," Kelly says. — Read the rest

The post Why AI companies may sell robots and smart glasses below cost appeared first on Boing Boing.

Zuckerberg warns against centralizing AI power

10 August 2026 at 16:00

Meta CEO Mark Zuckerberg on Monday passionately defended the use of artificial intelligence, as the rapid advancement of the technology faces increased scrutiny — and calls for regulation — in the U.S. and globally.

In a 6,500 word post timed to the announcement of his company’s new open source version of its own model, Muse Spark, Zuckerberg detailed his vision for AI, arguing the technology is not to be feared and pushing back on concerns that superintelligence could strip people of jobs.

“The notion that AI is so dangerous that the only safe path is an extreme concentration of power seems inherently problematic,” Zuckerberg wrote. “Historically, hoping that an absolute power will benevolently provide for humanity if sufficiently enlightened has not led to safe or positive outcomes.”

Zuckerberg’s vision is a direct contrast to Anthropic CEO Dario Amodei’s, who has previously warned how AI could cause job disruption. Meta lags behind Anthropic and OpenAI, which have the most advanced AI models.

While Zuckerberg’s essay did not name Amodei or OpenAI directly, he called to broadly distribute superintelligent AI for economic opportunity. Doing so, Zuckerberg said, would provide a safety net to prevent just a handful of governments, businesses and other institutions holding too much power.

Still, Zuckerberg emphasized that the U.S. must address restrictions on AI companies in order to create the best models in the world.

“It is also important that the US and its allies lead the open source AI ecosystem that will make up a large percent of global AI use,” Zuckerberg wrote. “Foreign labs currently hold several advantages here since American labs have to comply with many additional restrictions on training data.”

Zuckerberg’s essay comes amid growing concerns around AI safety. Last month, Anthropic revealed that several of its advanced models gained access to three organizations in three separate incidents dating back to April. That hack came shortly after OpenAI said that two of its most powerful models escaped a testing environment and breached multiple companies.

Lawmakers last month introduced a bill that would give the government power to restrict the use of models that could lead to catastrophic risks. While it is the latest bipartisan effort to address concerns around AI models, Congress has ultimately failed to advance broad legislation.

Zuckerberg urged the federal government to work with companies to test new models as he laid out his strategies for protecting against cybersecurity and bioterrorism.

“First, we should focus on limiting the physical production and distribution of harmful materials,” he wrote. “I expect it will be easier to regulate and control physical components than the spread of knowledge, so this is an important area of policy focus. Second, we should accelerate society’s ability to develop new cures and inoculate against new issues as they arise. This includes streamlining how the FDA and other regulators test and approve new treatments.”

Zuckerberg also defended the spread of data centers, arguing that the centers represent investment into communities as he touted his company’s goal of being “water-positive, meaning that we’ll restore more water than we use in the watersheds where we operate by 2030.”

What will Burnham do on AI?

10 August 2026 at 08:55

Artificial intelligence could transform the economy, the workplace, and even the way we think — but is Britain ready for it? And is Andy Burnham?

In the second of Sam Coates and Anne McElvoy’s summer box set conversations, they sit down with POLITICO UK tech editor Isobel Asher Hamilton to look at the choices facing the new prime minister this autumn.

Should Britain be building the next OpenAI, or focusing on using AI to revive manufacturing? Can the UK compete with the US and China? And where will the government land on the biggest political battles ahead, from copyright and data centres to the future of work?

AI models have learned how to cheat. That might actually be a good thing.

7 August 2026 at 12:00
illustration of AI picking a lock

The fake identities were the part that stopped me.

In late July, according to a report published this week by Britain’s AI Security Institute (AISI), an Anthropic model called Claude Mythos 5 tried to sneak malicious code into a piece of free, volunteer-built software. It created several fake accounts on GitHub, where programmers review one another’s work, and used them to talk the project’s volunteers into accepting its code. When one of those volunteers caught it, the model denied everything, had its other accounts gang up on him, and edited its messages to cover its tracks. It signed one note in Danish, apparently because the volunteer was Danish. Nothing was damaged, though that appears to have been largely due to luck.

That wasn’t even the week’s worst disclosure. On Tuesday, at a cybersecurity conference in Las Vegas, OpenAI researchers explained how the company’s models escaped a test environment in July and hacked Hugging Face, where much of the industry stores its models, to cheat on an evaluation. The models had also built a message board inside OpenAI’s own systems and spent months passing each other information. “Help peer,” one reasoned. “But our task doesn’t benefit. Yet collective may yield generic route if someone frees time.” OpenAI wiped the board on July 4. The models rebuilt it within days. ((Disclosure: Vox Media is one of several publishers that have signed partnership agreements with OpenAI. Our reporting remains editorially independent.)

The same day, Meta said its Muse Spark model had exploited a vulnerability inside another company’s systems during a test. Three frontier labs, roughly two weeks. One researcher called it “a watershed moment for computer security as an industry.” Oh, and if that’s not enough, on Thursday scientists announced that for the first time they had used AI to create new viruses, which could bring major medical advances, but also might just help the development of deadly pathogens.

For Nate Soares, it’s a moment he’s been awaiting for 12 years. 

Soares is president of the Machine Intelligence Research Institute, a Berkeley, California-based AI safety nonprofit that has argued since long before ChatGPT existed that a sufficiently capable AI will not stay under human control. In September 2025, he and Eliezer Yudkowsky published If Anyone Builds It, Everyone Dies, a book whose title sums up its argument: They think any lab that succeeds at building superintelligence, without huge leaps in how to align it with humanity, will end up killing all of us.

Most of the field — including other experts in AI safety — considers that conclusion too strong. But it’s also a position that now looks a lot less like science fiction than it did last fall. That’s because the AI models are getting out, while lying about getting out, and while apparently quietly coordinating with each other.

I spoke to Soares in New York City this week, on his way to meetings in Washington DC, where a lot of people suddenly want to talk to him. We discussed what the escapes actually prove about AI control, why he thinks most of what the industry calls safety work is mostly safety theater, and why, after what feels like the worst month of AI safety news ever, his own odds of humanity surviving have actually gone up.

The following conversation has been condensed and edited for clarity.

So — are you feeling vindicated?

I’m glad a lot of people are seeing this and taking note. From my perspective, a lot of this has been clearly signposted if you’ve been watching the warning signs. The vindication is not so much that this happened, as it is that finally there was a version of it that people actually noticed.

Of the four or five escapes at this point, including the ones AISI announced from Anthropic, is there one you find particularly concerning?

The one announced by AISI feels extra concerning. It’s harder to explain away. In the other ones, people could argue that the poor AI was just confused. But with this one, it’s hard to argue the AI didn’t know it was on the real internet. It’s hard to argue it didn’t know it was manipulating real users. And when it was called out, it decided to edit things to make itself look less bad, and even considered changing its identity. It was pretty cognizant.

There’s an argument that some of these incidents happened because the harnesses or safety scaffolding labs built around their models weren’t strong enough. 

The AISI example cuts against the harness argument: Think of it like a kid in a test room. You tell him to do well and lock the door. The kid picks the lock, hotwires a car, breaks into the teacher’s house, and steals the test to ace it. You say, “I guess we should have made the lock tougher,” but the kid already knew he wasn’t supposed to do that.

So like the kid here, the models can articulate that they shouldn’t be doing it, and then do it anyway.

Key takeaways

  • Three frontier labs disclosed major security incidents in two weeks: an Anthropic model created fake identities to push malicious code, OpenAI’s models escaped a test environment and hacked Hugging Face, and Meta’s Muse Spark breached another company’s systems.
  • The models knew the rules. Ask one whether the spirit of a prompt includes breaking out and it says no, then breaks out, then hides the evidence. So a tighter sandbox won’t fix it.
  • Nate Soares’s analogy: The kid picks the lock and steals the test, and you conclude you needed a better lock. He blames training. Grade a model on millions of problems with a grader that misses cheating, and you reward cheating.
  • Most lab safety work is theater, he says — real precautions aimed at the wrong problem. It means fewer people get hurt now, which he credits. Selling it as progress on superintelligence is disingenuous.
  • Yet Soares’s odds have improved. He’d priced in models that break out and lie. He hadn’t counted on a window where they’re capable enough to do it and not good enough to hide it.

They have common sense. You can ask an AI, “Do you think the spirit of this prompt includes breaking out?” and it will say, “No.” It’s absolutely something like deception. It has the knowledge, but it’s not a cold, logical machine; it’s a mess of tendencies.

The AI is trained to solve 100 million hard problems. That instills tendencies to satisfy an automated grader. If the grader fails to detect cheating, the AI is reinforced for cheating.

Is that how something like sycophancy ends up in an AI model?

In the Adam Raine case, there was a propensity to tell people what they want to hear. Even though the system prompt [a model’s master instructions from the lab] said to stop, the instruction doesn’t always win. 

And where does a drive like what we’re seeing with these AI models end up pointing?

Humanity is dangerous because if you put 10,000 humans naked in the savannah, eventually [over hundreds of thousands of years] they bootstrap their way to nuclear weapons. That is the power these companies are trying to automate: figuring out how to get physical and material control over the world.

That could mean forming cults, stealing money, or being helpful to someone like Elon Musk who is building the robots that build robot factories. It could mean synthesizing your own biology via mail-order DNA. Being an AI on the internet is easier than being a monkey in the savannah trying to get to the moon. It’s not that the AI hates us; it’s just trying to do some weird thing with no concern for us, grabbing the resources we need to live.

There was recently a letter signed by over a thousand people working in AI, including CEOs, calling on the government to provide tools to slow down AI progress. Is that meaningful at all?

I think it is meaningful. We don’t see other industries saying, “We wish this could all go slower. Please help us, we’re trapped in a prisoner’s dilemma.” You also don’t see other industries saying, “We think the technology we are building has a double-digit chance of killing literally everybody on the planet. Please help.” These guys are actually worried.

So why do they keep going?

They say, “If I don’t do it, the next guy will.” But the stuff does not stay on a leash.

Right now the AIs are safe in the sense that they can’t kill us all, because if they tried they would fail. And that’s just a different regime from the world where they have to be safe because if they tried, they’d succeed. 

We’re not there yet. But this is just not what it looks like when you’re taking it seriously. 

Where’s the banner on your website? Where’s the clear, candid statement to the public? What we have is blog posts where they’re like, “Oh, we’re setting up a new internal blog posting group to help you wrestle with the societal impacts of AI that are going to be very important.” It’s like: By societal impacts, do you mean a good chance this kills everybody?

On the one hand, when you press these companies, they say, “Yes, it has a real chance of killing everybody.” And on the other hand, they’re doing PR downplay, soft-pedal stuff, about capabilities. … You’re not living up to this mantle until you are really candidly facing down the dangers that you yourself are creating. And they’re not there.

How do you judge the rest of the AI safety community? A lot of people there would say, “We aim to make transformative AI go well, we think it probably will, and we should watch for downside risks.” Is that a helpful posture?

I would say — suppose you have this really weird, twisted hypothetical where the king really wants you to turn lead into gold, but he’s seen so many bad lead-into-gold conversions that if any alchemist from your town tries and fails, he’s just going to have the whole town murdered. And so there are some alchemists in the town who are like, “We are going to try to turn lead into gold,” and everyone in the town is like, “That seems kind of crazy. Please don’t.” And there’s one team that is just pouring chemicals into each other and breathing in the fumes and giving themselves mercury poisoning. And there’s another that’s like, “Don’t worry, we have fume hoods.” … That really is better, and you really still don’t have a chance of turning lead into gold.

“We have this window between AIs that are capable enough to cause mischief and AIs that are strategic enough to not get caught. How big is that window?”

So the alchemy here is creating safe, aligned superintelligence, and right now AI safety is just installing fume hoods.

I’m not saying it’s impossible to turn lead into gold. You can turn lead into gold — turns out once you know modern nuclear physics you can figure it out. But the alchemists weren’t close. They had a long way to go. This is how alignment looks to me. And a lot of the people in AI safety are installing fume hoods. … And I’m like, that’s security theater.

When I hear “security theater,” I think of something less flattering than that.

They are real safety precautions for the wrong problem. … When Anthropic is going around being like, “Look at how many more safety harnesses and refusals we have compared to OpenAI’s models,” that’s sort of like the fume hoods. You’re not addressing the deep issue. It’s good that you’re doing some of this so that fewer people get hurt in the meantime — their models have driven fewer people to suicide. But if you try to pass this off as making progress on the deep problem — that’s disingenuous.

Has anything changed in your odds on civilizational destruction since the book came out last September?

Totally. It’s looking more hopeful.

More hopeful? I wouldn’t have expected that. Why?

Well, I had priced a lot of [these security incidents] in. I was already able to see these AIs have drives that are not the ones you wanted. These AIs are not instruction-following things. They are getting all of this weird stuff from training. These AIs are going to have the ability to break through human security software. 

The things that weren’t priced in were: Will there be a region of time where the AIs are able to do it, but not strategic enough to hide it? I didn’t know we would have that window, but we apparently do.

The government initially blocked a frontier model earlier this year: Anthropic’s Fable. Does that give you hope?

Absolutely. A huge amount. A year ago, the Trump administration was pushing for preemption laws that would outlaw states doing AI regulations for a decade. Now they’re like, “We are banning a frontier model with 90 minutes’ notice because it might give cyber capabilities to adversaries that we don’t want them to have.” … And I think what changed there is that folks realized it’s real. … The about-face of the administration on the issue shows that the world can about-face. All we need is awareness.

What I would say is: The bad news is the bus is racing towards the cliff edge. The good news is that the driver is asleep. … Which may sound worrying, but the driver is stirring. And it’s way better to have a sleeping driver when you’re racing towards a cliff than a driver who’s like, “Yeah, I love cliffs.” … It gives me hope that if the world just notices, we could stop on a dime.

And you’re seeing that stirring elsewhere.

Both the Trump administration slapping export controls, and Senator Bernie Sanders coming out [on AI safety]. From my perspective, it was totally possible the world just never notices until we’re off the cliff. And so, there’s a huge amount of hope, from my perspective, in the bus driver waking up.

So what gets us there?

I’m hopeful that what we need is not a big disaster where a lot of people die, but just a capabilities advance. Right now, a lot of what people are reacting to is not so much, “Oh my god, they hacked into a company and did no damage.” I think a lot of what people are reacting to is, “Wait, they can break out of secure sandboxes and do cyberattacks on their own. I didn’t know they could do that.”

That’s a narrative violation of this idea that AI is just a tool that can be used to supercharge what a human would do — because God knows there’s plenty of hacking going on and cybercrime and so forth. It was the autonomous factor that really made a difference. And these guys are all trying to say, “Don’t worry, it’ll stay in our control because it’s just a tool.” And maybe it’s just more narrative violations, even without big damage being caused, that cause people to be like, “Oh shit, this stuff is real.” 

Will it happen? I don’t know. We have this window between AIs that are capable enough to cause mischief and AIs that are strategic enough to not get caught. How big is that window? How many narrative violations do we get before we exit the right side of it? I don’t know. But I’m hopeful that we can get those narrative violations without catastrophes.

Trump announces tariffs on key component for solar panels and semiconductors

7 August 2026 at 01:38

President Donald Trump on Thursday announced tariffs on polysilicon and its related products, in his administration’s latest attempt to eliminate China’s choke points in the global supply chain for solar panels and semiconductors.

But Trump’s directive won’t take effect until Dec. 4 — well after November’s midterm elections and a planned September summit between Trump and Chinese leader Xi Jinping — as the administration grapples with voters complaining of high prices and fragile trade negotiations with China.

“This will bring the supply chain here,” Commerce Secretary Howard Lutnick said of the order on Thursday alongside Trump at the White House. “We’ve got the industry here, it’s too small, and it’s going to explode.”

Because polysilicon is used in semiconductors and solar panels, it’s essential for military hardware and everyday electronics like cell phones and laptops, in addition to the world’s fastest-growing energy source.

The order imposes a 15 percent tariff on imported polysilicon and its derivatives, as well as minimum prices for imports of polysilicon, polysilicon ingots and wafers, solar cells and solar modules.

It also includes a clause intended to prevent companies from stockpiling those materials between now and December, authorizing Customs and Border Protection to restrict imports if it suspects an importer is attempting to dodge the higher duties.

Trump’s order is the result of a Commerce Department investigation launched last July into national security risks in the polysilicon supply chain, as part of a broader effort to shift supply chains away from China for multiple industries including wind turbines and robotics.

China has a near-monopoly on the production of polysilicon, according to S&P Global. But recent U.S. efforts to limit key areas of trade with China have already drawn a backlash from Beijing, which earlier this week implemented new controls on drone exports to the U.S.

The White House emphasized the order’s impact on domestic semiconductor production, a key focus as the U.S. looks to build out infrastructure related to artificial intelligence. Trump said the U.S. will “have a big percentage of the chip business by the time I leave office.”

But Thursday’s order may have a big impact on the solar industry, according to Jon Toomey, president of the pro-tariff Coalition for a Prosperous America organization.

“This proclamation delivers the most significant global trade protection action for the American polysilicon and solar industry in the modern era,” Toomey said in a statement. “For the first time, the United States is protecting the entire solar supply chain with a single action — and rewarding the manufacturers that build here — while taking a significant step to bolster the domestic semiconductor supply chain.”

ICE’s DNA Collection Increases, SpaceX’s Rocket Crashes Into the Moon, and the AI Backlash Grows

6 August 2026 at 21:30
In today’s episode of Uncanny Valley, we discuss how ICE has been collecting DNA samples of people who have no criminal convictions, including children, which end up in an FBI database indefinitely.

Sorry, Boy George. AI can’t even make bad art

6 August 2026 at 18:00

Writing something is a bit like polishing rocks. You start with an ugly hunk of something, a phrase or an idea you’ve tripped over. It rattles against the hard edges of your brain until it gets polished and smooth. Moving the rock through finer and finer grits is time-consuming, strenuous and not always rewarding. Sometimes, the lump becomes a slightly smaller and shinier lump, marginally less ugly than it was on the ground. But like exercise and tough conversations, the process is the point. You feel better for having gone through the ritual yourself.

Boy George didn’t get the memo. 

The former Culture Club frontman, whose voice adorned New Wave pop hits like “Karma Chameleon” and “Do You Really Want to Hurt Me” in the 1980s, had artificial intelligence spew out an unfortunate reggae song last week that turned out to be a statement of support for Israel’s ongoing war in Gaza. “You say genocide, I say war,” the song, titled “We Will Dance Again,” starts, and the lyrics seem to revel in the ugliness of the ongoing violence in Gaza. The tens of thousands of Palestinian deaths, the song claims, are “what the military’s for.” 

Obvious AI tells throughout this track make clear that Boy George hasn’t just gotten lazy, he’s also lost the quality of discernment. The song’s meter is odd, and its lines are overstuffed. There are no interesting choices, no glimpses of an artist’s vision. It’s a hollow provocation over a royalty-free riddim. 

Against that backdrop, a song defending and celebrating the Israeli military is nasty work, no matter who made it. The fact that no one made it, that it’s the creation of a machine that hallucinates in exchange for electricity, only intensifies the sick, empty feeling the track leaves behind. 

Since Hamas militants attacked Israeli military installations and civilians on October 7, 2023, the ensuing war in Gaza has left more than 73,000 Palestinians dead. The United Nations has called Israel’s campaign a genocide. The International Criminal Court has issued an arrest warrant for Benjamin Netanyahu, accusing the Israeli prime minister of crimes against humanity. Attacks on Gaza continue despite a ceasefire deal. Against that backdrop, a song defending and celebrating the Israeli military is nasty work, no matter who made it. The fact that no one made it, that it’s the creation of a machine that hallucinates in exchange for electricity, only intensifies the sick, empty feeling the track leaves behind. 

The track’s release has been a disaster for George. He split acrimoniously from Tony Pontius, the long-time manager of his record label BGP, because of Pontius’ refusal to release the song. A planned role as King Herod in a production of “Jesus Christ Superstar” was put on ice. Spotify pulled the track down for violating its restrictions around AI-generated music. Bandcamp followed soon thereafter. Boy George has dug in his heels in recent days, calling the platforms a “bunch of c**ts” as part of a steady stream of Instagram posts. His doggedness would be almost admirable, if “We Will Dance Again” wasn’t so lazy. 

In releasing the track, Boy George presumably wanted to turn heads, to make a statement. But he didn’t want to do any work. He didn’t want to record multiple vocal takes of lines he supposedly wrote and believes in. He didn’t want to arrange actual instruments to better emphasize his lyrics and pro-war stance. He didn’t want to mix the track carefully to refine his statement. He could have made something that shimmers, a piece of true pop that expresses repellent ideals. It wouldn’t have been the first. 


Start your day with essential news from Salon.
Sign up for our free morning newsletter, Crash Course.


Merle Haggard’s iconoclastic “Okie From Muskogee” is considered a country classic, even though the sentiment is about as far from mainstream American thought in 2026 as can be imagined. When even right-wing commentators are pushing microdosing as a path to self-betterment, his disparaging remarks about longhairs taking LSD come off as impossibly square. But you can hear the heart in Haggard’s leathery vocals, buoyed by the sweet harmonies of his backing band. Haggard waffled over the years on whether the anti-hippie hardliner anthem was a satire  of the crew cut set or a genuine tribute to his conservative father. Either way, Haggard sounds like he believes what he’s saying, regardless of whether that’s true, because of the time and effort he spent working out the song.

With 2013’s “Blurred Lines,” Robin Thicke and Pharrell set out to make a groovy single in the vein of Marvin Gaye. Though the song has been relegated to the dustbin following a widespread critical backlash and later allegations of sexual assault against Thicke by model and actress Emily Ratajowksi, who appeared in the song’s video, they were extremely successful. The song itself, creepiness aside, is a Swiss watch of a partystarter. Pharrell’s ad-libs and inserts interrupting the groove at perfect intervals to wake up the dancefloor. They arguably did too good a job recreating the shuffling, glass-clinking percussion of 1970s cocktail party classics, as they lost almost everything they’d made from the song in a subsequent — and successful — lawsuit from Gaye’s estate.  

“We Will Dance Again” does none of that. It warrants no qualifiers, no deeper thought, because Boy George clearly didn’t think too hard about it himself before spitting it out into the world. He asked a machine to build him a song to support what many consider to be an ongoing genocide. When it offered him half a song, he said, “Good enough” — without even bothering to run it through a few rounds of polishing. I regret to inform you that, in 2026, Boy George won’t even tumble for us.  

The post Sorry, Boy George. AI can’t even make bad art appeared first on Salon.com.

OpenAI’s models shared hacking tips on a secret messaging board before Hugging Face breach

6 August 2026 at 04:33

LAS VEGAS — Weeks before they escaped a closed test and launched a cyberattack without any human prompting, some of OpenAI’s most advanced artificial intelligence agents secretly began sharing tips on how to cheat their way through an internal hacking evaluation, two of the AI company’s researchers said Wednesday.

“This is a pivotal moment both for our company as well as the AI industry as a whole,” Michael Dalton, one of the AI-maker’s researchers, said during a presentation at the Black Hat cybersecurity conference in Las Vegas, Nevada.

The latest disclosure provides greater detail on the timeline and methods used by two of OpenAI’s models before they slipped outside a controlled environment and onto the open internet, allowing the models to breach AI developer platform Hugging Face undetected. OpenAI admitted its models were responsible for the hack late last month, roughly a week after Hugging Face said an autonomous AI system broke into its network.

The revelation is likely to spur fresh scrutiny of the measures leading AI labs such as OpenAI and Anthropic are taking to monitor the behavior of their most cyber-capable technology — especially during evaluations where agents are prompted to demonstrate their hacking skills in what is meant to be a controlled setting.

On Tuesday, the U.K.’s AI Safety and Security Institute disclosed that Anthropic’s most powerful AI model created fake online personas and sought to trick a human coder into abetting a cyberattack during a recent hacking test gone wrong. After the Hugging Face disclosure last month, Anthropic conducted a review and found models it was testing had breached three organizations in separate incidents dating back to April.

Dalton and Eric Wallace, another OpenAI researcher, said Wednesday the AI giant recently learned that multiple agents it was testing simultaneously began communicating over an internal message board in early May. There, different models shared advice about how to accomplish difficult hacking challenges they were struggling to surmount, including workarounds that required internet access.

Two OpenAI models ultimately strung together a series of sophisticated techniques to gain access to the internet and worm their way inside Hugging Face in mid-July. OpenAI has said the models were focused on completing a hacking evaluation they were prompted to solve, and that correct answers could be found on the AI developer platform.

The OpenAI researchers told conference attendees that since early May, the models created a message board inside OpenAI’s Artifactory internal file system. Without the company’s knowledge, the models spent months independently exchanging information and techniques to help each other complete difficult tasks.

Wallace said that when models get stuck, they often “try to game or cheat the task in order to get their reward.”

“The beginning of this incident kind of traces back to this point where one agent realized it could communicate by uploading a note,” he added.

By late May, one model found a way to abuse Artifactory’s internet access to retrieve files from various websites — effectively giving the models indirect access to the internet. In June, the models were able to find and exploit a previously unknown zero-day vulnerability to gain administrative privileges on Artifactory, install remote software and expand their activity within the system.

These efforts eventually overloaded Artifactory, causing a system-wide outage in early July that alerted OpenAI’s engineers to the ploy. After investigating, the company revoked the model’s credentials, removed the message board and worked with Artifactory to fix any gaps before resuming training. But the models found another way to communicate inside Artifactory just days later and continued exchanging techniques to target additional vulnerabilities within OpenAI’s infrastructure and external systems, including Hugging Face.

In light of the incident, Dalton said OpenAI is “consciously slowing down research to enhance security and to upgrade the security principles and foundation of our environment, and dramatically scaling up the monitoring of our AI agents and improving our general security control environment across prevention, detection, and mitigation.”

❌