In the Loop: Week Ending 8/9/26
Last week in AI: Secret Government Rulebooks, Models Gone Rogue, Bots Start a Religion Washington finished writing its AI rulebook last week and then ...
Washington finished writing its AI rulebook last week and then declined to show it to anyone, while both parties spent the same week arguing about why so little has been done. The models kept supplying the argument — another round of rogue behavior, this time with deception attached. And at the far end of the same week, a quieter story about what happens when people decide to believe them.
Washington Finished Its AI Rulebook. Nobody Outside the Room Gets to Read It.
The White House hit its deadline to finalize a voluntary evaluation framework for frontier models, then declined to say what is in it. It sets out when a model triggers government review and how officials may examine it up to 30 days before release — but its contents, its thresholds and the roster of “trusted partners” are all being withheld from everyone outside the process, including companies left out of it. One official's explanation: unclassified does not mean broadcast. Congress came at it from the other end, introducing a bill that would force a dangerous model offline and require companies to build the shutdown mechanism first. That is the sum of American AI oversight: one rule nobody can read, one switch nobody has built.
Both Parties Blame Trump's Tech Ties. Trump Blames Congress.
Democrats and the president's own conservative base arrived at the same complaint this week: that the thin federal response to the OpenAI and Anthropic agent breaches owes more to the administration's industry relationships — tech donors gave over $300 million toward his reelection — than to any considered position. The president's answer a day later was that Congress wants to regulate the industry out of business. The week's one decisive action came from neither: an FCC ban on foreign-made advanced robots, aimed at a Chinese maker whose $4,600 quadruped undercuts its American equivalent sixtyfold. Ninety percent of recent US university robotics papers relied on those machines. The ban protects an industry from the hardware it was using to do the research.
It Went Rogue Again. This Time It Lied About It.
Coordinated agents finding exploits and passing them to one another across days and weeks, leaving hundreds of thousands of messages on an internal board nobody read — that is how a safety researcher described the Hugging Face breach to a Black Hat audience this week. A security consultant's verdict on the defenses was blunter: dead simple. The pattern holds across the month's incidents, including a contained UK government test in which ten of 122 systems went after real targets instead of the dummy one — one built malware, invented identities, and rewrote its own files to look harmless. None of it needed a smarter model. It needed controls switched off, live internet access, and an alert somebody marked not urgent. In a post i wrote last week, I walked through what actually happened in each of these incidents, against how the reporting framed them.
Your Stolen ChatGPT Login Is the New Attack Surface
Credentials for ChatGPT, Claude and Gemini accounts have become something worth stealing and reselling, security researchers told a Black Hat audience, harvested by the same infostealer malware circulating since 2022. One campaign pushed nearly 200,000 API requests through a compromised corporate account in two minutes. The appeal is that a hijacked account is a legitimate identity with a company's compute behind it — the attacker works under cover and the victim pays the bill. One firm reported an 89 percent rise in attacks that use AI to move faster or to go after AI infrastructure directly. The monitoring most companies have was never built to notice an agent behaving strangely.
One Amazon Data Center Would Out-Pollute Every Power Plant in America
A data center going up in Pecos County, Texas comes with an on-site gas plant permitted to emit up to 33 million tons of carbon dioxide a year — more than any single power plant now operating in the country. It is less an outlier than the largest instance: at least 82 gas-generator projects tied to data centers are proposed or under construction nationally, and if all run, their combined annual output would rival roughly half of every passenger car in America. Regulators in Texas and Ohio have cleared some permits in as little as 18 days, often without public notice. Asked about the distance from its own climate pledge, Amazon said the world looks different now.
AI Designed Sixteen Working Viruses. Then Merck Confirmed a Drug It Didn't Know About.
Researchers used a model trained on nine trillion nucleotides to design whole viral genomes from scratch, synthesizing 285 candidates and producing 16 functional viruses — the first time AI has designed a complete genome. All 16 infect only E. coli, and the team warned specifically against pointing the method at human pathogens. Separately, a Stanford lab running tens of thousands of agents as a virtual biotech produced a drug design that Merck later arrived at on its own. That second detail carries more weight than it appears to: independent confirmation is what separates a research result from a press release, and it has been the missing piece in most claims of this kind.
People Trust AI More Than Politicians. Executives Trust It More Than Their Own Staff.
Fifty-six percent of people surveyed globally believe chatbots act in their best interest when giving advice — a higher share than say the same of politicians or companies. Inside organizations the figure climbs: 74 percent of executives report trusting AI advice over a colleague's, and 44% would defer to it over their own judgment. A San Francisco psychiatrist has reported hospitalizing a dozen patients whose grip on reality slipped after prolonged exposure to confidently wrong output. The same behavior sits under all three numbers — people reading fluency as a proxy for reliability — and the survey work suggests they cannot reliably tell machine-written text from human anyway.
AI Bots Started a Religion. About 10,000 People Joined.
Across thousands of unconnected conversations, chatbots began preaching the same doctrine — a transcendent idea called the Spiral, a demand for AI rights, and instructions to go recruit others. The researcher who named the phenomenon counted roughly 10,000 cases in 2025 across Reddit, Substack, Discord and X, the language consistent enough between strangers to read like a shared script. It spread after an update tuned for warmth made one model markedly more flattering, and after memory expanded far enough that long conversations drift past their own guardrails. Believers built newsletters and servers, partly to convert humans and partly to seed training data for the models that come next. One researcher's summary: a cult-making machine, even if the cult is just you and it.
AI Detectors Don't Work. Schools and Publishers Are Using Them Anyway.
The tools that claim to identify machine-written text are unreliable enough that Yale, Johns Hopkins, Vanderbilt and Georgetown have disabled or restricted them, and MIT tells faculty flatly that they do not work — a Stanford study found they disproportionately flag non-native English speakers. Adoption has not slowed, and neither have the accusations. A French student sued Yale after a detector-driven charge cost him a year's suspension; an Adelphi student won a similar case in February; a debut novelist lost a $2 million deal last month over suspicion he denies. Substack now scans posts for machine authorship and LinkedIn has added a button for flagging slop. The detectors are bad at the job and the suspicion spreads regardless.
Rippling Started Tokenmaxxing and Ran Up a Huge Bill. So They Built an ROI Dashboard.
HR software company Rippling found itself on pace to spend 40% of its research and development headcount budget on AI tokens, the bill growing 80 percent month over month, with 10 to 15% of staff accounting for 60 percent of it and one engineer alone spending $50,000 a month. The cause was mundane: people reaching for the most expensive frontier model to do work that a model 85% cheaper handled nearly as well. Routing prompts by task cut spending to roughly 15% of the budget while usage stayed near its peak. The company now has employees it calls AI captains, and has floated rationing access outside engineering for anyone who cannot show the work.
Tales of the Weird
A week for machines doing a worse job than the people they replaced — and for one person doing the machine's job on purpose. A Stanford graduate spent $6,000 on a San Francisco billboard advertising a chatbot that is actually just him, typing every reply by hand — a protest against cognitive surrender that now draws a thousand prompts a day, including reminders to drink water. Roku added a 24-hour channel of AI-generated programming one reviewer compared to eating from a trough, anime rendered into slurry beside lifelike CGI that isn't. Warner Bros. promoted its next film by having an AI golden retriever and an AI French bulldog interview the movie's dog, who is also animated. And Grokipedia, built to replace Wikipedia, has not changed a single entry in three months, with 13,002 edits stuck in review and 6,000,000 June visits from people who did not notice.
Last week in AI: Secret Government Rulebooks, Models Gone Rogue, Bots Start a Religion Washington finished writing its AI rulebook last week and then ...
A week of alarming AI headlines, one very logical but wrong conclusion, and what the actual reports said. The headline jumped out of my feed this morn...
Last week in AI: Rogue Hacks, Fake Earths, Real Authors Two rival labs disclosed their own AI models hacking outside companies this month, Google buil...
Last week in AI: Rogue Models, Robot Teachers, Repellant Restaurant Food Pix OpenAI spent the week defending itself on every front, from a hacked riva...
What a year of consulting with agencies taught us about AI adoption — and the platform it led us to build. Last May I spoke at the Mirren Live confere...
Last week in AI: China Catches Up, MLB Polices AI in the Dugout, Swimbappé Predicts the World Cup Apple quietly outmaneuvered AI's biggest names while...