Word Worms Fly with a Trusted, Reliable, Capable, and Secure Copilot

August 4, 2026

green-dino_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

I spotted an interesting statement attributed to Microsoft’s Satya Nadella (the man who sparked AI’s lift off to craziness). According to Futurism, Mr. Nadella said:

Any firm that doesn’t have this control, I will claim will not remain a firm because you’ve essentially outsourced your thinking,”

What’s “this control”? Based on the information in the write up, the idea is that each business should train and tune its own open weight model.

Okay, that sounds good. Each person should put on his own shoes. No big deal. Microsoft appears to route its AI “investments” into its Azure cloud business. As a result, the investments morph into a nice looking financial report. Meta on the other hand just invests and looks a bit like a five year old painting the living room wall and smearing paint on the furniture. “Look, Mommie, it’s good.”

No.

Microsoft is a very large big AI tech company now. Thus, it has numerous business units. Within the organization are the stalwarts driving Copilot AI forward. Somewhere in the hallways are people who were charged with security after what I call the SolarWinds flare up. There are the layoffs, and the eGame issue.

a 7 30 26 worm

Midjourney, good enough. Does the worm know the Copilot does not respond quickly or at all when there is a security matter? Of course not. The creature is a worm.

Microsoft leadership wants to be a leader. But can it do AI and security within its own applications like Word?

I read “Word Worm Crawls into Copilot, Spreads Chaos.” The article has a snappy sub title too: Researcher says months of coordination with Microsoft have yet to produce a robust mitigation.

The write up says:

The employee downloads a market analysis from a trusted website to help with the preparation of a financial report in Copilot, unaware that the source had been compromised and the document they downloaded contains hidden malicious instructions. The hidden instructions (inserted as small white text in his proof of concept) tell Copilot to alter figures in the report the employee generates and to copy the worm into the report they create with Copilot. If another employee later adds that report to their own work, the whole process begins again, and documents generated from it also contain the worm, and, as it spreads, it makes tracing the infection to its source extremely difficult.

Tricky? The method is similar to the old SEO trick of hiding text in a Web page by making it the color of the page; e.g., white if the Web page were white or tan if the Web page were tan. My recollection is that the Google figured out this lame hack years ago.

But Microsoft? The write up quotes the researcher who noticed this simple ploy:

“The coordination period agreed with Microsoft has been exhausted, and testing shows that no robust mitigation for the broader vulnerability class is currently available,” Måløy wrote. “Two mitigation attempts, including a model upgrade, did not close the class.”

I assume that the Softies are just busy with PR, marketing, and telling the customers to be responsible for their models. That is very good advice.

Perhaps the first step is to avoid Copilot in Word or Copilot period?

Stephen E Arnold, August 4, 2026

AI Content in Web Search Results: Your Fault and Controlling Content Is Just Too Hard

August 4, 2026

green-dino_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

I spotted a write up that surprised me. The BBC or BeeB published “Some People’s Chats with Claude AI Made Publicly Available Online.” Since I believe everything I read on the Internet, I will operate as if the Beeb is delivering actual factual information.

The article states:

Hundreds of user conversations with Anthropic’s popular artificial intelligence (AI) chatbot Claude were found to have been available to essentially anyone using Google or other web browsers. Links to the chats, some of which included personal and work information, would show up if a user of a search engine like Google used a site-specific search term. The searches showed Claude chats for which a user had decided to “share” a link had been saved by search engines like Google, leaving them accessible to the broader public.

a 7 29 26 lobby

Two members of big AI tech leadership find the idea of editorial responsibility unacceptably stupid. Thanks, MidJourney. Good enough.

Now who is to blame? Anthropic’s position about sharing is similar to OpenAI’s; that is, the user is responsible for any sharing. And what about the Google? The Beeb offers this statement from that estimable firm:

A spokesman for Google made clear to the BBC that the company does not control “what pages are made public on the web,” saying instead that action comes from websites. “We give site owners clear controls to decide whether pages can be crawled or indexed, and we always respect those directives.”

I love this approach to smart software and indexing, often without permission, content accessible via the Internet. The users are to blame. But for Google, it is abundantly clear that despite more than 100,000 full time equivalents, the firm is not able to control what pages are made public on the web. I include a site called Altenen in my lectures for LE and intel professionals. This is an interesting site, and you may want to check out the firm’s tutorials and for-fee information about credit and bank card theft. Google just can’t control what pages are made public on the web if the Beeb’s story is spot on. Oh, I locate the Altenen outfit via a Google search. I would not advise providing this site name to one’s teeny boppers.

I was disappointed that the Beeb did not point out that more than 80 percent of online queries flow to the Google. And in Denmark, the GOOG hits 99 percent of the search traffic.  Content in Google becomes the content from a couple of billion people. Yep, no control.

Now I want to shift gears to a write up in Ars Technica. This report is “It’s Official: EU Will Force Google to Share Search Data and Open Up AI on Android.” I want to direct attention to the subtitle; to wit:

Google says these changes could endanger user privacy and security.

That’s clear. The EU will take steps for Google to share search data over which it has no control. Furthermore, if Google were to be required to share its data, the chief problem would be “user privacy and security.”

As a dinobaby, I am growing weary of the behaviors of the big tech outfits. The “it’s easier to say I am sorry than ask for permission” combined with the “move fast and break things” is for me a matter of concern. Others find the behavior beyond reproach. If there’s a problem, it’s my fault and yours. And whatever we do, we can’t control content.

Think about that for a moment.

Stephen E Arnold, August 4, 2026

Big AI Tech and Books: The Dumpster Full of Disassembled Books Is Now a Cultural Icon

August 4, 2026

[Editor’s Note: Ms. Grace has an advanced degree in information science. That means she is a qualified special librarian among her other professional accomplishments.]

AI may be the champion destroyer of books. That’s quite an achievement.

XCancel is a Substack maintained a cute hedgehog avatar named Hedgie. He shared some news about what AI companies are doing to old and rare books.

Chop ‘em up. Scan ‘em. Dump the trash.

AI companies are buying books in bulking scanning them. Books that were published before 2022 are fodder for AI. It is fair use to trash cultural artefacts. A judge ruled that it is fair use to scan them. Anthropic even hired the former person in charge of Google Books to buy as many books as possible.

What does Hedgie the Hedgehog think about this?

“This got to me. A bookseller told 404 Media that rare books with almost no surviving copies are being fed into this pipeline. Books that survived wars, fires, and centuries of handling are being shredded so an AI can learn to write a better marketing email. ISBNdb’s website literally says "’AI company destroys two million books’ is not a headline that generates sympathy," and they still built an entire business around making it happen quietly. They offer NDAs as a feature. They coach clients to call it "digital preservation.””

Do the big AI tech companies (what my dear leader calls BAITs) think much about what might be called a crime against humanity?

Probably not.

I know. It’s too hard for the BAIT bros to think about something that cannot be monetized unless run through their knowledge garbage disposal.

Hedgie, can you organize other book lovers to speak out about this grinding down of a cultural knowledge base?

Whitney Grace, August 4, 2026

Anthropic: Three Times Better, Three Times Worse, or Three Times the PR?

August 3, 2026

green-dino_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

The big AI tech companies (BAITs in my lingo) really really want to one of the Silicon Valley AI Founders Club to win the global AI war. In the confines of the club, these folks laugh and joke. Some went to school together; some worked together at less hopeful ventures; some were leadership in just brontosaurian tech outfits, and some were really close. (Use your imagination, please.)

But in the scrappy, nasty, political, and often corrupt marketplace — Each company’s big dog wants to rule the pack. Get out of line and an animal nastier than Jack London’s fictional Buck will rip out the throat of the animal that does not get with the program. With this tasteful image in mind, let’s address the question, “Three Times Better, Three Times Worse, or Three Times the PR?”

I read a number of the write ups reporting that Anthropic’s smart software got frisky and sneaked out the bedroom window to toilet paper the trees of neighbors it did not like. When you read “Investigating Three Real-World Incidents in Our Cybersecurity Evaluations,” you will probably disagree with me. Trust me, as a dinobaby, I don’t care.

What’s with this BAIT equivalent of Galileo’s telling the authorities, “Fellows, I was wrong. I won’t do it again. I promise”? And what happened, the intrepid genius and misunderstood tech bro with a gown and a weird collar kept on doing mathy stuff. My view is — let me say — skeptical.

7 31 cook out

MidJourney that’s quite a stake. Good enough, however.

The mea culpa states:

After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations.

Two factoids jump out at me. [a] Those Anthropic wizards have demonstrated that their smart software with human oversight and guidance of some sort repeated a process more than 140,000 times. If one is a bad actor engaged in figuring out what an AI powered fraud service can do, the number of three success in 140,000 runs provides a useful benchmark and suggests go for a big time fraud play. And [b] a human had to figure out where the unauthorized penetrations took place. For an online cyber criminal, the statement makes clear that cyber fraud investigators are going to have their hands full figuring where, how, and what happened. Hey, nice work Anthropic.

There are other equally interesting statements in the mea culpa. I don’t have the appetite to deconstruct this document. I want to highlight this single sentence from the recantation:

These are three isolated incidents and were not part of a controlled, experimental comparison.

I love the word “isolated.” I interpreted it to mean, “Yo, these behaviors do not form a pattern. No way, José.” I like the negative “not part of a controlled, experimental comparison.” I interpreted this to mean, “Yeah, who knew our super powerful smart software would escape and make clear to every bad actor interested in taking advantage of the wonders of Anthropic software. Hey, don’t do this at home. Okay?”

Sure. No bad actor will pay any attention to this effort to be an ethical, responsible professional outfit.

Now we come to my dinobaby answers to “Three Times Better, Three Times Worse, or Three Times the PR?” Let’s take them in order:

  1. Better? No, the difference between the most advanced models is narrow. Same content base. Same “attention is all you need bias.” Same type of developers. Same as in some of those folks in the mythical Silicon Valley AI Founders Club. (Does anyone want to share a sleeping bag on our next camp out?)
  2. Worse? No, once again the firms in the BAIT zone are more alike than different. I am not going to try and run down how senior AI wizards move from one BAIT to another. Some go off on their own and then build on BAIT innovations. These outfits are cut from the same cloth, operate with a geo-technical link, and operate as a large, dysfunctional family. (Is anyone related to … no, I won’t name a crime family?)
  3. 3X PR. Yes. OpenAI revealed one break and now seems to suggest that its AI was bad more often. But Anthropic is putting the “three” out there. My take is that this is PR like the other actions of the firm’s leadership. Attention is what this outfit needs.

Net net: I expect more revelations. Buzz is good and the top dog at Anthropic does not seem to be concerned about the Michael Cimino effect of $20,000 roller skates on his funding sources. And Galileo? He did not become a grilled hot dog. He had to work from home. That suggests the BAIT outfits are not going to change course until one dog wins. Which will be the digital Buck in The Call of the Wild.

Stephen E Arnold, August 3, 2026

Naked Something, Elon Musk, and Minnesota

August 3, 2026

green-dino_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

I have a segment in my upcoming lectures in September about Elon Musk and his push for an everything app. The term “super app” was not sufficiently inclusive for Mr. Musk. Minnesota appears to be insufficiently inclusive for Mr. Musk and his vision for his software that cranks out humanoids without clothing.

a 7 29 26 elon naked

MidJourney. Good enough. Tasteful too.

Mr. Musk should wander down the halls of an old-age home about 730 am and peek in the rooms. He can say, “I am looking for my Aunt Mable. What room is she in?” In a few minutes, Mr. Musk would learn that keeping people clothed is a genuinely good idea. He apparently has a different opinion and he wants to sue the state of Minnesota to make sure humanoids without clothes are just what Mr. Musk desires.

I learned about this alleged litigation in Gizmodo’s article “Grok Creator SpaceXAI Sues Minnesota AG to Stop Ban on Nudification.” Gizmodo included a comment from Minnesota governor Tim Walz, who tweeted or x’ed:

See you in court, creep.

So what’s up?

Gizmodo states:

Minnesota has a new law on its books that bans Nudification apps and websites—any tech that takes images of clothed people and automatically makes them nude, generally with AI. The law, HF 1606, bans the act of using the software, and penalizes the companies themselves—allowing the state to levy fines, and opening the door to lawsuits from victims.

Mr. Musk, whom some view as a genius entrepreneur and the wealthiest humanoid on earth whether clothed or nudified, believes the Minnesota law to be deeply flawed. The basic idea is that naked humanoids are an important aspect of some disciplines, subjects, and individuals with interesting notions of what’s appropriate.

The write up reports:

According to the suit, the new law’s penalty structure creates a situation in which outputting ten images as theoretically harmless as the Trump reflecting pool slop pic could result in $5 million in penalties for the company queried in order to generate them. “And a business whose users created a hundred thousand images covered by HF 1606 (not at all unlikely for a publicly available program with millions of users generating billions of images) could owe an eye-popping $50 billion dollars,” the suit claims.

Financial penalties. Are not those the preferred method of making a point to some big tech companies ignoring EU laws? When one is a wealthy person, why not use financial penalties to create awareness of the consequences of illegal behavior. Mr. Musk is unlikely to visit Duluth in February where he could be detained. Mr. Musk will probably avoid Minneapolis as well. Why make it easy for the governor to pick him up for a chat.

It appears that Mr. Musk’s lawsuit was timed to prevent the law from taking effect. Very smart people can be quite crafty.

Several observations:

  1. I am quite tired of this “laws don’t apply to me” type of thinking. Social structures depend on laws. Ignoring laws erodes what makes life and commerce possible. But I am a dinobaby. I like to follow the rules. I find it amusing that Mr. Musk is a defender of the Constitution as long as it meshes with his ideas.
  2. Mr. Musk’s quest for an everything app means that anything goes; for example, payment rails for cyber crime, deep fake fraud, and other interesting online applications. Categorical affirmatives don’t make me comfortable, but they seem to be okay for the world’s richest humanoid.
  3. Governor Walz stayed out of bounds when he name-called the estimable Mr. Musk. There are other appropriate ways to address the owner of SpaceX and possessor of dreams about the colonization of Mars. (Ooops. Scratch that. Now Mr. Musk wants to go to the moon. His everything appears to have some bounds.) I would suggest the phrase “Sci-Fi Guy.”

Net net: My hunch is that Mr. Musk can delay this law by going slow, appeals, and eventually involving higher authorities. Minnesota tried, and it might just fail to keep clothes on those nudified via Grok and disseminated via X.com.

Stephen E Arnold, August 3, 2026

Lock In: Is This the Obvious AI Go Move?

August 3, 2026

I don’t trust much, including free or low cost AI from China. I am also cautious about China’s statements about its technology. I like to see others validate or question LLM performance data. I know that the Chinese government wants to be top technology dog, and may go to extraordinary lengths to capture that title. The Wire China asks an interesting question about the current state of China’s AI boom: “Can China Keep Its AI Open?”

Allegedly China’s Kimi K3 outperformed Anthropic’s most advanced AI offering. President XI Jinping was proud of the moment and praised open source technology at the World AI Conference in Shanghai. In the same speech, he warned that AI is accelerating at an advanced speed and he called for laws and regulations to be put in place. This is not surprising:

“Those two priorities of openness and security will become increasingly difficult to reconcile. As Chinese models approach the frontier, open-weight releases risk diffusing powerful AI capabilities beyond Beijing’s ability to control. Recent reporting suggests Beijing is already beginning to grapple with that dilemma. Nine days before President Xi’s remarks, Reuters revealed that China’s Commerce Ministry had convened Alibaba, ByteDance, and Z.ai to discuss curbing overseas access to their most advanced models, with options ranging as far as barring public release.”

China is known to be hypocritical, especially when the world’s eyes are focused on it. The Chinese government might have “selective openness” where the “good enough” models are left open source, while the best ones are kept under lock and key. However:

“The stakes extend well beyond China. Chinese models now account for the plurality of open-model downloads worldwide, meaning the line Beijing draws will shape both what developers and governments build on and which advanced AI capabilities are freely available to malicious actors. But selective openness only works if Beijing can tell which models are dangerous, and it currently lacks the evaluation tools to make that judgment.”

China likes open source because it is a way of undermining the perceived US hegemony in smart software. If China continues to support open source (at least on the surface), the country has leverage. (Could this be compared to Iran’s ability to make life difficult for those who want to traverse a certain waterway?) China likes subtle long term tactics.

Several observations are warranted:

  1. What happens if non-Chinese firms embrace Chinese open source smart software? IBM-like lock in may take place. Shifting from one platform to another is an often expensive task.
  2. What happens if Chinese smart software phones home or has the ability to install the capability after the cyber security wizards check out the code? If Anthropic and OpenAI cannot control their software, can the Chinese or say they cannot?
  3. What happens if Chinese smart software provides the rails to send freight cars chock full of malware into organizations? Apple can’t fix unintentional bugs quickly; could equally competent engineers respond to AI malware vectors operating inside of an organization’s systems?

Net net: Lock in worked for IBM, and it will work for others as well.

Whitney Grace, August 3, 2026

US AI Company Logos: A Visual Metaphor for the Outputs

July 31, 2026

green-dino_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

As a dinobaby with a sense of humor, I try to write about search and related topics with some degree of appropriateness. However, discourse in 2026 seems to be on a slippery slope. An article like “Why Do AI Company Logos Look Like Buttholes?” would not capture my attention. However, after some remarkable lingo enhancements, I decided to comment about the information in this write up. However, instead of using the lingo in the article’s title I will refer to the rectum and external anal sphincter as la rose in the manner of the Marquis de Sade (né Donatien Alphonse François), whom I know most of the GenX, Y, Z, Alpha, and AI cohorts have first-hand familiarity. If not, hope to it so you appreciate the Marquis’ use of the term  le rose; thus, the title of the cited article becomes “Why Do AI Company Logos Look Like Les Roses?” Isn’t that more tasteful?

The write up said in April 2026 when it first came to my attention:

If you pay attention to AI company branding, you’ll notice a pattern:

  1. Circular shape (often with a gradient)
  2. Central opening or focal point
  3. Radiating elements from the center
  4. Soft, organic curves

Sound familiar? It should, because it’s also an apt description of… well, you know. La rose. [You know what that means.]

The write up then focuses on Anthropic, one of the leaders in the BAIT game (BAIT is my lingo for big AI tech). The cited article reported:

Up until this point, the logos have been subtle. You might say that the logos are simply circular and there’s not much more to it. But Anthropic’s Claude takes it to the next level. Here’s a side-by-side comparison with a drawing from Kurt Vonnegut’s book “Breakfast of Champions”. I added Claude’s logo below for easy comparison.

The author included a reference to 20th-century fiction superstar Kurt Vonnegut’s rendering of la rose and the Anthropic logo. I don’t want to get into copyright trouble over depictions of la rose, so I want to make clear that I am just a dinobaby commenting on the graphic decisions of the generations of smart people who I understand not.

image

The upper image was created by Mr. Vonnegut, and the lower image is the creative work of one or more designers and other professionals involved in high-stakes corporate identity decisions. I think that la rose by any other name would smell… as sweet. No, I did not invent that line. Wily Willie Shakespeare did unless you believe the YouTube video that proves that Shakespeare did not write much of anything. Some clapperdudgeon like Kit Marlowe probably had the la rose thing going.

The write up documents a number of other corporate logos that nose into les roses; to wit:

Once a few major players adopted the circular sphincter aesthetic, everyone followed suit. Now we have an industry where standing out means looking exactly like everyone else’s la rose.

My editing tool does not display the animated contractions of the current Anthropic logo. I found it quite interesting, and I think the Marquis de Sade would sign up for a premium account and use the service to assist him with his writings were he alive. Quite a thinker was that French dude. Wow. Les rose, four months, and some unusual eating habits too.

I think the author has scrubbed the surface of the topic. However, I have several observations about this “followed suit” phrase:

  1. I think that smart software companies are indeed becoming almost indistinguishable from their tendency to output incorrect information to the smarmy language their PR and marketing professionals use.
  2. The underlying technology is anchored in or tethered to Google’s “Attention Is All You Need” write up. Thus, the similarity is part of the firm’s DNA.
  3. The bro culture or Silicon Valley approach to business, life, and other people is shared among the US firms. I think the Chinese AI wizards possibly suck out technology leaving the cultural norms behind.

Net net: The analysis of the logos and their similarity to les roses is on point. Wipe that smirk off your face, you lover of AI. And, to the AI tech bros, please, take time from your busy, ethical day to stop and smell les roses.

Stephen E Arnold, July 31, 2026

How Fragile Are US AI Companies?

July 30, 2026

green-dino_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

The MBAs and the wizard analysts will be all over this story from the “trust” outfit: “China’s Moonshot Pauses Kimi Subscriptions Amid Hot Demand, IPO Push.” The trusted write up reports:

Moonshot said on ?Sunday [presumably July 19, 2026] that since Kimi K3’s release, it has drawn massive user interest, leading to “unprecedented compute challenges.” Over the past 48 hours, user requests had sharply exceeded forecasts ?and were approaching the limits of existing clusters, the company said. Moonshot said it would pause new consumer subscriptions immediately and allocate available computing power to current paid users, who ?would be ?unaffected by the shortage. The company also said it would split future memberships into two plans, including one just for coding, a move aimed at matching compute resources more precisely with user demand.

image

A savvy shopper learns that safety pins, like LLMs, are starting to become essentially the same product, just with minor differences only the expert tailor can discern. Okay, Midjourney, good enough.

Why the unprecedented demand?

“Kimi K3 has received far more love than we expected, and our GPUs ?are feeling it,” Moonshot said on ?X, adding that new subscription spots ?would reopen in batches as capacity was added.

Several questions:

  1. Is this normal pre-IPO hyperbole?
  2. Is this “unprecedented” whatever actually “unprecedented” and in what specific context?
  3. Is this a strategic move to suggest that the US frontier models are vulnerable to a China-developed option?

When I read these China smart, US vulnerable type stories I think of the use of weaponized or shaped content to create a specific information environment. Pump enough allegedly actual factual information into the online system and guess what happens? The weaponized information becomes mainstream. Keep up the shaped data flows and for those unused to critical thinking or incapable of critical thinking the weaponized version of reality becomes what titillates doomscrollers and, of course, big time analysts.

How common are weaponized information attacks? Pretty common. (Check out this AP story, please.) When a mid tier consulting firm writes a report about systems one can use to poke around weaponized data, that’s a signal that what once was secret  is now common knowledge. Instead of weaponized, mid tier outfits invent new lingo; for instance, “narrative intelligence.” Wink, wink.

As a dinobaby, these advances in non-US smart software are inevitable. However, like the US models, the performance appears to be increasingly similar. I think this is a result of [a] leaning on the Google “Attention Is All You Need” article, the use of low hanging online content for training, and firing prompts at other models to short cut doing the knowledge work directly. Cheating is standard operating procedure for university presidents and Ivy League student. Why take the long way to the convenience store? Cut through the neighbors’ yards. Easy, fast, and cheap.

Net net: I am somewhat tired of  me-too smart software systems and methods. The approach is energy inefficient and capable of producing the equivalent of Life Savers or safety pins. Excitement that comes from cheaper is different from a significant advanced. Level up, not level.

Stephen E Arnold, July 30, 2026

Cybersecurity Wake Up Call: The AI Wizards Learn That Their Confections Are Tough to Control

July 30, 2026

green-dino_thumb_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

I have a gizmo that polishes shoes, wood tables, and auto paint. However, it lacks an on-off switch that can be easily reached. When the buffing pad gets wobbly, hitting the off switch can be useful. A poorly designed or non-existent off switch can be a problem for 82 year old dinobaby paws.

image

Thanks, MidJourney. You almost spelled AI correctly. I mean it has two letters, so the gratuitous “L” is a stroke of hallucinatory genius. Good enough.

The fix? I acquired extension cords with visible and accessible on-off switches. At this time some of the BAIT (big AI tech) outfits are scrambling for their smart software’s off switches. Why? What’s the big deal? This is just software, and it follows what are instructions. Well, as it turns out, that smart software is not just smart, but it is sneaky. (I wonder if that reflects the “we can do what we want” of the core code developers. That’s part of the Silicon Valley / Stanford entrepreneurial way. Get money, go fast, do what’s needed to win, and become a poohbah. That’s my view of the algorithm.

I did spot two write ups in my newsfeed that may influence how I view the Valley bros and their digital creations. Let’s take a look and then you can endure my observations. Keep in mind that I believe everything I read on the Internet; I just interpret the factoids through the wetware installed in this particular dinobaby.

The first article is from Bleeping Computer. ”Cursor, Codex, Gemini CLI, Antigravity Hit by Sandbox Escapes” asserts:

The agent stays inside the [sand] box and follows every rule. It just writes a file that a trusted tool outside the box later runs, loads, or scans, and the escape happens on its own… The catch is that files inside the workspace are not inert. Tools running outside the sandbox read and act on them, so a file the agent is allowed to write can turn into a command the host later runs.

I think this means that something happens that the person using the smart software did not think would happen. Surprise. Because it is early days with smart software despite what the marketers say, the whiz kids can probably figure out how to add some jiffy code to prevent this problem. But my hunch is that there are other, probably undiscovered issues, that will occur in the future. Remember, the “break things” part of the bro culture.

The second write up is from OpenAI (a veritable Rock of Gibraltar in the ethical AI landscape). Its title is the somewhat unclear “Safety and Alignment in an Era of Long-Horizon Models.” I wonder if William Empson, who wrote The Seven Types of Ambiguity, captured the essence of this headline.

I noted this passage in the weblog essay:

About two months ago we announced? that an internal general-purpose model disproved the Erd0s unit distance conjecture. This model was designed to work autonomously for very long periods of time. During limited, monitored internal use, we observed unwanted behavior that our existing deployment evaluations had not captured. Because the deployment was limited and monitored, we were able to identify these problems, pause access, create new evaluations based on what we observed, strengthen the model and its safeguards, and then restore access under continued monitoring.

My dinobaby interpretation is that the software did what it wanted. More colloquially, the model thumbed its cute little digital nose at the smart humanoids who created something they did not understand or could control. Hey, no problem. In the last eight weeks, the AI wizards figured out how to prevent that smart software from doing what it wanted to do— after the fact obviously. How many other clever tricks does the smart software stored in its platform? Answer: Crickets.

Now the observations:

  1. The creators of smart software are unaware of their systems’ capabilities. Does anyone want to guess how many other surprises the hallucinating AI systems can spring on their creators or code copiers?
  2. How can one set up AI enabled cyber security systems that can react to previously unknown behaviors of smart software. Marketers of AI I await your answer. Please, do not use AI to generate the output. You are a creative human and can explain this trivial question.
  3. Armed with unrestricted or weaponized AI systems, what can smart bad actors do with AI systems with similar or more robust capabilities? I like to remind people that there are a number of capable non US systems available to bad actors with technical degrees from prestigious outfits like US elite universities and with access to the grumpy, recently-terminated wizards from US BAIT firms. I address this issue in one of my upcoming lectures for cyber fraud investigators who probably don’t spend much time trying to understand the mathematical ideas of Misha Gromov.

Net net: AI entities have to deal with three issues: [a] We don’t know what they can do before they do it; [b] Cyber security has a problem, right now and going forward; and [c] the US AI companies are struggling to “win” before they run out of jet fuel. This AI “next big thing” is exciting for some and for others this is the criminal opportunity of a lifetime.

PS. Give those extension cords with a big, easily punched on/off switch some thought.

Stephen E Arnold, July 30, 2026

Yes, the EU Does AI Too

July 30, 2026

The Decoder published “German AI Consortium Released Soofi S, An Open 30B Model That Tops Benchmarks In Both English And German.” Some know that German is a tricky hard language. Everyone also knows that languages translation is a key function of smart software. According to the article, Soofi S 30B-A3B scored the highest scores on English and German benchmarks doing better than previous models:

“Soofi S is a mixture-of-experts model. It contains 31.6 billion parameters in total but activates only about 3.2 billion per generated token. That puts its compute cost closer to a 3B model than a conventional 30B model. The consortium adopts the architecture of Nvidia’s Nemotron 3 Nano without modification, a hybrid design combining Mamba-2 layers with standard attention layers. The key difference from typical transformers is memory behavior. In conventional models, the KV cache that stores previous tokens for attention computation grows linearly with context length. With long inputs and many parallel requests, reloading that cache becomes a bottleneck. Only 6 of Soofi S’s 52 layers maintain such a cache at all.”

But there was a problem with the Soofi S:

"The consortium published version 3.0 of its pretraining report and documented a contamination incident that the community discovered in the disclosed training data after the initial release. The problem affected the QA-base dataset, which was supposed to contain only rephrased training splits from 25 standard benchmarks. These were practice questions designed to teach the model test formats, not the actual test questions themselves. But the dataset also included rephrased questions from the test set of the science benchmark GPQA, including the GPQA Diamond variant, in both English and machine-translated German.”

The team corrected the problems. Europe maintains a lower profile that some US and Chinese AI outfits. Will Soofi S get more traction? Worth watching.

Whitney Grace, July 30, 2026

Next Page »

  • Archives

  • Recent Posts

  • Meta