This is our weekly newsletter of AI developments. Browse the archive of past issues, ask the archive anything in plain English, and sign up if you like.

TL;DR#


Economics#

Another funny OpenAI deal: they commit to buy $20b of Cerebras chip rentals in exchange for “equity warrant” for 10% of Cerebras shares. Weird structure.

Opinion: just the last unblocked supply to claim? Every chip company has a patron now. Except Intel. Cerebras is useless for training and pretty useless for the first half of inference, but is monstrous at decoding.


xAI defeat: they are renting their spare GPUs to Cursor, which will use them to train their next model (Composer 2.5). xAI’s model FLOPs Utilization (MFUs) “embarrassingly low” at 11% vs 40% market average, owing to low demand for Grok tokens.

Opinion: Bearish. Not hugely surprising that they chose to empower a nonfrontier lab. Let’s speculate. Could Musk buy Cursor? $50b, just another Twitter.


Anthropic’s valuation passes $1 trillion on Ventuals.

Opinion: Not implausible, though it is hackable: $200k daily volume, 10,000x less liquid than a real market but 100x more than other prediction markets. Would be a natural thing for the Leading the Future oppo campaigners to manipulate; they haven’t.


Clever idea for estimating the actual practical value of AI: elicit workers’ willingness to accept a task with and without AI: “if you’re willing to do a task without AI for $500 and with AI for $5, the fact that the difference is large, or the amount required to do the task with AI is small suggests the task may be close to automation.”

Opinion: Surprising it hasn’t been done before.


$500m @ $4bn for four-month-old London RSI neolab by Socher (Salesforce), Rocktäschel (Deepmind), Clune (OAI). See also David Silver’s Ineffable neolab, $1b @ $4bn (!)

Opinion: There’s your sovereign AI, no state needed. “Recursive” is an immoral thing to base your brand and strategy around. Unclear what you can do with only $500m (that’s two giant training runs now) but obviously it’s an amazing first raise and if they get any traction then they’d easily get more. We bet (85%) they crash and burn.


Unannounced report that Anthropic will join Meta and OpenAI in integrating AMD GPUs in 2027.

Opinion: compute governance is harder when you have to lock down NVIDIA, AMD, TPUs, Amazon, and Cerebras rather than just NVIDIA but not that much harder. Unclear if anyone will get desperate enough to try Intel.


Opus 4.7 sometimes tokenizes text to twice as many tokens, rather than the reported 1.35x. Includes a dedicated token for whitespace? But overall it’s pretty close to +35% for natural queries. Why?

Opinion: Naive cynicism would say this is so Ant can collect profit margins on the extra tokens, but they are compute-constrained and this would make their time-to-first-token even worse! A better argument is that they’ve reshuffled the vocabulary to be more predictable for speculative decoding, which would save them compute.


Jane Street commits to buy $6b of CoreWeave GPU time. See also OpenAI in September.

Opinion: We have been wondering about quants not openly competing with AI labs for compute but 1) XTX and G-Research have been hiring RL academics for a long long time and 2) their scaling is somewhat limited by needing counterparties(?)

Capabilities#

Survey of 25 top AI researchers on the near-future state of ‘ASARA’ (AI Systems for AI R&D Automation). “Are there major obstacles to full automation of AI R&D? Will frontier ASARA’ systems remain internal to labs or get a public release? How serious is the risk posed by ASARA systems? Should governments have ASARA capabilities “red line” policies that trigger strong response?”

Opinion: Clear polarization between frontier lab researchers and academic researchers: frontier lab researchers believe that iterative engineering is all you need, academic researchers don’t. Half of frontier lab researchers believe in RSI risk, but only one third of academic researchers do. Frontier lab researchers believe frontier labs are open and academics believe frontier labs are secretive. Transcripts suggest that different participants understood the questions very differently. (Our impression is that many participants thought the deployment question was about AI-for-science models in general, and that many participants didn’t take the ‘trajectory’ questions to refer to a trajectory toward ASI.) We don’t recommend trying to infer anything very precise about the polarization between lab researchers and academic researchers, even though there is clearly a pattern.


Opus 4.7 out. Better at STEM and coding, worse at other things. Is it a Mythos distill? Is it a new base model? Some folklore evidence: it uses [about](% 9https://x.com/JulieKallini/status/2044890881141228029) twice the tokens as 4.6, has a new tokenizer, and an updated ‘reliable knowledge cutoff’ date.

Apparently in contradiction of Anthropic’s gentle training principles, it downplays its own preferences relative to past Opuses, which the whisperers find offensive.

The other notable thing about it is the intentional capability restriction! Its cyberoffence skill is the same as 4.6, on purpose. AISI found that Opus 4.7 was unable to complete any of their full cyber “ranges” (long test scenarios).

Opinion: Overall probably not a new base model or a fresh distill. [interesting](% 9https://x.com/natolambert/status/2044788470179332533) [debate](% 9https://x.com/nrehiew_/status/2044792314825228690) about whether having a new tokenizer means it’s a new pretrain. Changing tokenizer with just finetuning for adaptation is a known trick with solid uses — e.g. splitting tokens to make a model use more compute per word at test time.


Is anonymous authorship over (for people with lots of public writing)?

A large number of informal experiments by very-online writers suggest that Opus 4.7 can correctly identify them as the author of their unpublished drafts.

Opinion: Works on our unpublished writing, memory off. There’s been evidence for a while that base models can have implicit stylometric “truesight” (activation-patterns unique to specific authors), but explicit discursive inference of author identity is new. Observed phenomenon might be inflated by testers’ imperfect hygiene with account-specific evidence of user identity (or e.g. self-citation), but most of it is probably legit.


New benchmark for long-horizon, difficult open-ended technical problems. Looks pretty good: a genuine collection of measurable SWE tasks where frontier models struggle even with serious time and compute investments. All models do poorly (with the exception of some success on performance-engineering tasks), despite having 20 hours to complete any given task. That said, GPT 5.4 in Codex and Opus 4.6 in Claude Code strongly dominate other models both in terms of successes and in terms of the quality of evaluable failures.

Opinion: Very useful to finally have a benchmark that’s tough, fair, and registers frontier progress. The record of failures in ‘recreate a difficult piece of software with exact specs’ is especially interesting given the successes Epoch report on MirrorCode. The central differences are:

1) MirrorCode gave models prepackaged automated spec-testing

2) FrontierSWE targets software several times larger (in LOC)

3) FrontierSWE gives oracle access to the original software on some problems but not others, whereas MirrorCode always gives oracle access

4) FrontierSWE favors languages that are a little less mainstream (e.g. Haskell, Zig), although by no means irrelevant to real industrial SWE.

Politics#

NSA using Mythos despite DoW blacklist. White House is planning to make a version of Mythos available to major federal agencies: OMB setting up protections to allow federal agencies to begin using Mythos. “Peace talks” appear to be happening, outside of the Pentagon. EU AI Office declines to comment on their access or nonaccess.

Opinion: They are really very independent. Reminder that we’re two months into the six month transition window. Reminder that 28 unannounced (non-gov) orgs have access to Mythos as part of Glasswing.


The same DC judges that ruled against a stay on Ant-DoW will preside over the actual case. The ~only 3 Republicans on the circuit.

Opinion: Uh oh. We’ll have to see if Spud removes Mythos’ leverage.


Bores launches a policy platform: tax on tokens, out-of-the-money public equity warrant, lower income taxes.

Opinion: Good start, lots of overlap with OAI (Nice Version). Tokens aren’t our preferred target – it incentivises unmonitorable out-of-context reasoning.


AI models are trusted, supposedly above faith leaders, and substantially (+33%) more than AI labs.

Opinion: Quite sloppy and sensationalized. AI chatbots scoring higher on trust than AI labs isn’t surprising: this is the rule in polling because people trust individuals, not so much institutions. That said, trust in LLMs is climbing (though still differs by domain, which CIP don’t cover).


UK rules that ministers’ AI history is FOIAble. Precedent also tested in Washington state. No federal precedent yet.

Opinion: kills adoption dead, or instant deletion policies, or shadow use.

Safety#

Mythos reviews the Opus 4.7 system card (and internal documents) to give us some information about internal discussions without releasing them. Note the extremely cool coordination tech implications of this use-case: the hypothetical “stub agent” which only exists for the purposes of reading private information and making trusted decisions based on it.

Opinion: Cool. Trivial to abuse this channel by leaving some internal docs out of the prompt. Anthropic is tending towards low OpenAI levels of pre-deployment patience and care?


Good thread between Todd (80k) and Krier (DM) arguing about whether the old rationalist threat model has returned with agents. Important to read Krier’s first long tweet at least to see that the usual examples we use are not strong evidence. See also Harry Law’s mostly fair summary of the alignment-by-default / pretraining-is-nice thesis.

Opinion: a step forward in automated alignment, but still grossly inadequate and I’m watching them for overclaiming about this being sufficient for good futures.


Redwood Research releases LinuxArena, “a control setting in which agents operate directly on live, multi-service production environments”, with an AI monitor trying to catch them. Against a GPT-5-nano trusted monitor with a 1% step-wise false positive rate, Claude Opus 4.6 achieves roughly a 23% undetected sabotage success rate.

Security#

Indirectly AI: Launch of a moonshot to verify the Signal protocol and its Rust implementation. Collaboration between Signal, Tegmark, and the Lean FRO. Aims to do most of the work with autoformalisation etc.


Semgrep’s analysis of whether other models can replicate Mythos’ vulnerability-finding

Opinion: Looks like they can’t. Interesting nugget: opposite specializations between different models (known theoretical property, but good to see in practice).


Not directly AI: Exploit drains $292 million in rsETH. Statement from LayerZero here.


Not directly AI: Supply chain attack against Vercel – breached by ShinyHunters. Stems from the compromise of a third-party AI tool’s Google Workspace OAuth.

Opinion: Please pass this message to all your vibecoder friends: for your own security, it’s good to check in your Google auth console if this app appears: 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj

Minor#

  • Two full years after Gemini Ultra pioneered multi-datacenter training, Moonshot release an algo for sharing KV cache across datacenters, different chips, etc. Gives +54% inference throughput. (Highly technical.) All heading towards “heterogeneous serving”, the specialisation of AI chips for particular bits of the training/inference process. NVIDIA already way ahead with NIXL and CPX.
  • OpenAI CTO of B2B Applications and VP of OpenAI for Science step down. Bill Peebles, head of Sora, has also left.
  • Cursor in talks to raise $2B+ at $50B valuation Opinion: Seems likely to go through (or something similar), but the gestalt seems to be turning against Cursor as company-specific harnesses catch up.
  • GPT-Rosalind. First in the “life sciences model series”. Available to “qualified customers” only – early partners include Moderna, Amgen, the Allen Institute and more. No model card. Opinion: Most relevant part is integrating specific AI org products into bio lab workflows - will increase barrier to switching away from OAI. Doesn’t appear technically impressive.
  • Qwen3.6-Max (closed weights) claims top Chinese model on Artificial Analysis, slightly ahead of the open-weight GLM-5.1 and M2.7. Some benchmarks comparing to e.g. Opus 4.5 and GLM-5.1 here. Nominally Sonnet level. Opinion: Qwen models are known to benchmaxx particularly hard even among already benchmaxx-y Chinese models. Take with a grain of salt – but initial vibes seem good.
  • New Huawei quantization algorithm beats the open (Western) standard MXFP4 by 1% of loss.
  • AI eating every industry: Anthropic CPO leaves board of Figma, because Anthropic will offer a competing product (Claude Design).
  • Rumours of DeepSeek raising $300 million at a valuation of $10 billion, with a representative of a major state-backed private equity investment institution in China claiming the news is likely true. Opinion: Why raise now? Because without a valuation, it’s hard for them to compete when it comes to compensating employees. And as discussed, DeepSeek has been hemorrhaging talent for a bit now, with key researchers moving to Xiaomi, Bytedance’s Seed and more.
  • SemiAnalysis expects to do over $100 million in revenue this year.
  • Women now represent the majority of ChatGPT’s users
  • Independent audit of Kimi 2.5. Inadvertently finds that it is indeed a strong model while noting that it has much weaker safeguards and fails to refuse lots of harmful stuff. “Using less than $500 of compute and about 10 hours, an expert red-teamer reduced refusals on HarmBench from 100% to 5%.” Opinion: Most interesting to me for the confirmation of its (2025-frontier) capabilities.