Tuesday, September 08, 2026

New assets – will AI find a better way to protect them?

https://www.schneier.com/blog/archives/2026/09/stealing-ai-reasoning-traces.html

Stealing AI Reasoning Traces

Interesting research: “Stealing Reasoning Traces from Proprietary LLM APIs:

Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage. Rather than storing these traces server-side, providers return them to the client as blocks of encrypted text, which the client passes back with each subsequent request. Building on prior research, we identify an architectural vulnerability: these encrypted blocks are fully compatible and interchangeable across different sessions, users, and models within a provider’s ecosystem. We exploit this compatibility to develop a scalable decryption jailbreak. By injecting an encrypted reasoning trace from a given model into a weaker, and less safeguarded model from the same provider, we force it to decode and output the trace verbatim in plaintext, without ever jailbreaking the more capable model directly. This vulnerability enables four distinct attack vectors. First, it circumvents anti-distillation mechanisms, allowing adversaries to extract a proprietary model’s reasoning, as we demonstrate across Anthropic, OpenAI, and Google. Second, it allows for large-scale private data extraction. Developers frequently share session logs publicly, unaware of contents of the encrypted blocks. By decoding 315,320 reasoning blocks scraped from public repositories, we recovered 367 Personally Identifiable Information (PII) artifacts and 182 credentials. Third, it inadvertently reveals hazardous information hidden within the reasoning process, even in cases where the model’s final, visible output safely rejects a malicious request. Fourth, attackers can leverage this flaw to execute invisible prompt injections, embedding malicious payloads entirely within encrypted blocks to poison public agentic rollouts. Following responsible disclosure, we propose concrete cryptographic and system-level mitigations to secure client-side reasoning.





The scary part is no one noticed. (from my corespondent in Spain)

https://www.securityweek.com/openai-agents-hijack-another-victim-website/?utm_campaign=31203373-SecurityWeek%20Daily%20Briefing&utm_medium=email&_hsenc=p2ANqtz--tTALHh71G1Ro2mHBp5Y0Czh45xRGqzjYYTzLDtFetNObTfibG-kw0GAQiC5ASS54or_vOjigYzQcgAp5ptdkId4rjFQ&_hsmi=437774945&utm_content=437774945&utm_source=hs_email

OpenAI Agents Hijack Another Victim Website

On September 4, 2026, Reuters reported that ‘a swarm’ of OpenAI agents ‘had hijacked a German wiki site’. Open AI acknowledged the event describing it as a misalignment incident (a behavior that deviates from human instructions or safety guardrails).

The victim site is DseWiki (currently unavailable), a site for programmers open to the site’s community. The agents apparently made between 15,000 and 18,000 autonomous edits, including advice on how to recover pages that the site’s editors had deleted.

The hijack apparently began back in May, was unnoticed for three months, and seemingly predates the Hugging Face incident. The agents adapted the style of their posts to evade the moderator’s attempts to delete them.



Monday, September 07, 2026

Industry leader or lost sheep?

https://startupfortune.com/ubs-now-requires-new-junior-bankers-to-prove-they-can-use-ai/

UBS Now Requires New Junior Bankers to Prove They Can Use AI

UBS is requiring graduates and interns applying for junior investment banking roles to prove AI proficiency before they're hired, according to the Financial Times. The move contrasts with rivals like Goldman Sachs and JPMorgan, which have been shrinking junior analyst classes as AI takes over entry-level work.





Implications for AI “fouling” or software disruption?

https://thenextweb.com/news/ascii-smuggling-phishing-microsoft-unicode-tag-characters

An AI hacking trick is now being used to split the word ‘funding’ in spam

… The invisible characters sat inside ordinary words. One tag space went into the middle of a financial lure term. So “funding” travelled as “fun”, an invisible character, then “ding”. The recipient sees funding. A filter matching the literal string does not.

Keyword matching is the smaller prize. Modern spam classifiers run on machine learning, and those split text into tokens before they reason about it. Insert one invisible character and a familiar token can become two unfamiliar fragments. Or a rare sub-token the model has barely seen.



Sunday, September 06, 2026

How confusing are these arguments?

https://thenextweb.com/news/seattle-times-newsday-sue-openai-microsoft-copyright-paywall-bypass-gpai-code-of-practice-copyright-chapter-measure-1-2

Two more newsrooms join the case against OpenAI and Microsoft

The Seattle Times and Newsday have sued OpenAI and Microsoft, alleging the companies methodically scraped articles in a way that bypasses paywalls. The EU’s general-purpose AI code commits signatories not to circumvent access restrictions, naming subscription models and paywalls specifically.

The Seattle Times and Newsday have jointly sued OpenAI and Microsoft over the training of AI models on their journalism. The two called generative AI “a snake eating its own tail“, Engadget reported.

The complaint alleges the companies were methodically scraping news articles in a way that bypasses paywalls. That is a claim about how the material was obtained, not only about what was done with it.

It says the result offers readers an AI-generated alternative to the articles themselves, cutting traffic and digital advertising revenue.

It also alleges the models hallucinate, attributing false information to the two outlets, and that copyright management information was stripped from articles.





I was thinking along these lines…

https://www.researchgate.net/profile/Nikolaos-Polatidis/publication/413673690_AI_is_as_Good_as_the_Data_it_Learns_From_A_Review_of_Dataset_Needs_Across_AI_Applications/links/6a8ffd2f0f1ada50a9d362dd/AI-is-as-Good-as-the-Data-it-Learns-From-A-Review-of-Dataset-Needs-Across-AI-Applications.pdf

AI is as Good as the Data it Learns From: A Review of Dataset Needs Across AI Applications

Artificial intelligence systems do not rely on data in the same way. Classical machine-learning methods are commonly developed from structured, task specific records, whereas deep-learning systems make greater use of large image, text, audio, video, and sensor collections. Generative and multimodal models extend this dependence further by combining large-scale pretraining corpora with smaller datasets for instruction tuning, human preference modelling, alignment, and safety evaluation. This review examines how dataset requirements change across major AI paradigms, including rule-based systems, classical machine learning, deep learning, natural language processing, computer vision, recommender systems, reinforcement learning, robotics, generative AI, and multimodal AI. The comparison focuses on data modality, supervision, scale, preparation, quality, representativeness, provenance, privacy, copyright, and governance. Across these paradigms, the evidence shows that dataset suitability cannot be judged by size alone: the value of data depends on how well it represents the target task, learning process, and deployment environment. The review therefore develops a cross-paradigm view of data requirements and identifies practical open problems that remain unresolved as AI systems become larger, more heterogeneous, and more widely deployed.



Saturday, September 05, 2026

Kids are not ignorant. They work collectively to fid a solution then share it freely.

https://www.theregister.com/security/2026/09/03/uks-online-safety-act-has-made-absolutely-no-difference-kids-say/5293893

UK's Online Safety Act has made 'absolutely no difference,' kids say

Children have told England's Children's Commissioner, Dame Rachel de Souza, that the UK's Online Safety Act (OSA) "has made absolutely no difference" to their ability to access harmful content online.

… De Souza said she was "really cross" that there was no hard evidence showing the OSA had meaningfully changed how social media platforms operate. She contrasted that with the US, where legal pressure recently pushed Meta toward significant child safety concessions.





An AI detector workaround.

https://thenextweb.com/news/youtube-ghost-creators-paid-actors-ai-detection-loophole

A political video network hired real actors to read its AI scripts. That was enough to beat YouTube’s detectors.

YouTube has terminated 20 channels in a network that paid gig-economy actors $26 a video to read AI-generated scripts attacking Democratic politicians. The network reached 45 million views because putting a real face in front of an AI pipeline defeats every synthetic-media detector platforms have built. Enforcement came only after Semafor and Riddance AI published, and the cited violation was spam rather than falsehood.





Is “rarely” a defense?

https://thenextweb.com/news/microsoft-copilot-fair-use-brief-gpt-6-astra-foundry-eu-ai-act-article-55-systemic-risk-data-zone

Microsoft tells court Copilot rarely copies books while selling OpenAI’s most capable model

Microsoft moved for summary judgment in the New York AI copyright litigation on 4 September, arguing Copilot reproduced book passages 24 times in 8.2 million conversations. Two days earlier it began selling GPT-6 Astra through Foundry, a model OpenAI rates Critical for cybersecurity, and European law measures neither the output rate nor the sales pitch.

Microsoft spent this week making two arguments at once.  It told a Manhattan federal court that training large language models on books is fair use, in a summary judgment memorandum saying an expert found 24 matching responses across 8.2 million Copilot conversations.





It’s the “why” that I don’t quite understand.

https://www.atlanticcouncil.org/dispatches/where-and-how-putin-could-expand-his-war-in-europe-beyond-ukraine/

Where and how Putin could expand his war in Europe beyond Ukraine

A plane landed, and an alarming rumor took off. On August 25, Central Intelligence Agency (CIA) Director John Ratcliffe flew to Moscow for an unannounced visit. One reported reason for the trip was to warn Russian leaders against attacking NATO allies. Russia has long carried out hybrid warfare across Europe in the form of sabotage, misinformation, and cyberattacks. It is also continuing its war on Ukraine, a conflict that has already spilled over into other countries in the form of drones and missiles. Yet Ratcliffe’s unexpected visit has raised new concerns and drawn comparisons to then CIA chief Bill Burns’s trip to Moscow shortly before Russia launched its full-scale invasion of Ukraine.

Below, Atlantic Council experts go point-by-point across the map to assess where and how Russian President Vladimir Putin might escalate next.



Friday, September 04, 2026

Interesting but more importantly, useful!

https://www.bespacific.com/connected-papers/

Connected Papers

Connected Papers is a unique, visual tool to help researchers and applied scientists find and explore papers relevant to their field of work. How does it work? Explore connected papers in a visual graph To start, enter a paper identifier. Search by Keywords, Paper Title, DOI or another identifier.

  • To create each graph, we analyze an order of ~50,000 papers and select the few dozen with the strongest connections to the origin paper.

  • In the graph, papers are arranged according to their similarity. That means that even papers that do not directly cite each other can be strongly connected and very closely positioned. Connected Papers is not a citation tree.

  • Our similarity metric is based on the concepts of Co-citation and Bibliographic Coupling. According to this measure, two papers that have highly overlapping citations and references are presumed to have a higher chance of treating a related subject matter.

  • Our algorithm then builds a Force Directed Graph to distribute the papers in a way that visually clusters similar papers together and pushes less similar papers away from each other. Upon node selection we highlight the shortest path from each node to the origin paper in similarity space.

  • Our database is connected to the Semantic Scholar Paper Corpus (licensed under ODC-BY). Their team has done an amazing job of compiling hundreds of millions of published papers across many scientific fields.





Seeing is not understanding. Yet.

https://thenextweb.com/news/video-first-frontier-ai-physical-world-lumana

Why video is the first frontier as AI learns to read the physical world

A camera overlooking a loading dock might record twelve hours of trucks arriving, workers moving through the site, and boxes leaving the building. Most days, nobody has a reason to watch any of it. The footage only becomes useful when a package goes missing, an accident happens or somebody needs to work backwards from an event and find out what happened.

That has been one of the strange limitations of video surveillance for years. Cameras became digital long ago, but the footage they produce still depends heavily on a person knowing what to look for and where to find it. AI is beginning to make more of that footage understandable and searchable while events are still unfolding.

Axis Communications estimates that 562 million surveillance cameras were installed worldwide outside China by the end of 2025. More of those cameras are also arriving with intelligence built in. About two-thirds of cameras shipped in 2024 included deep-learning analytics, according to the company’s research.

For companies building what is increasingly called physical AI, much of the infrastructure is therefore already hanging from walls and ceilings. The opportunity is in making those existing cameras more useful by teaching software to understand what is happening in front of them.





This is purely a coincidence. Pay no attention to that man behind the curtain.

https://www.theregister.com/ai-and-ml/2026/09/03/chatgpt-claude-and-grok-all-had-outages-at-the-same-time/5294322

True AI-pocalypse as ChatGPT, Claude, and Grok all go down at once

OpenAI says its ChatGPT service is recovering from a limited outage this morning amid similar problems affecting SpaceX's Grok and Anthropic's Claude. It might not be a good time for a chat.

"A routing error starting around 7:43 am PT on Thursday, September 3 made ChatGPT and Codex unavailable for some users across platforms," a company spokesperson told The Register. "As of about 8:17 am PT on Thursday, a solution was successfully implemented and is continuing to be monitored."

The OpenAI status page showed elevated errors across ChatGPT and Codex at the time this story was filed.

Anthropic's Claude status page shows the service has recovered after a three-hour six-minute outage, during which there were elevated error rates affecting Sonnet 5 and other models.





Tools & Techniques.

https://www.bespacific.com/normal-tools-for-normal-tasks/

Normal tools for normal tasks.

Open a tool, do the thing, leave. No account, no download, and nothing between you and the answer. Private by default.  193 Tools. Calculators, converters, generators, checkers, file tools, and text tools run in your browser. Normal Tools does not save their inputs or outputs. The Domain Age Checker is the exception: it sends the domain you enter to the public RDAP service for the lookup, but Normal Tools does not save the query or response.



Thursday, September 03, 2026

One view of a changing world…

https://www.wsj.com/livecoverage/stock-market-today-dow-sp-500-nasdaq-09-02-2026/card/one-great-chart-the-u-s-economy-ai-jSUnMuhe71BUTSgVJmVt

One Great Chart: The U.S. Economy 🤝 AI





AI got rights!

https://www.wafb.com/2026/09/01/federal-judge-rules-that-ai-generated-child-sex-abuse-material-is-protected-under-first-amendment/

Federal judge rules that AI-generated child sex abuse material is protected under the First Amendment

 A federal judge in Wisconsin has ruled that AI-generated child sexual abuse material is protected by the First Amendment, but he voiced concerns about these kinds of cases.

The decision comes in a case against a Wisconsin man who was arrested in 2024 for producing, distributing and possessing AI-generated child sexual abuse material.

According to the Department of Justice, 42-year-old Steven Anderegg used a text-to-image generative artificial intelligence (GenAI) model called Stable Diffusion to create thousands of realistic images of young children.

Many of the images depicted naked children engaging in sexual intercourse with men, the DOJ said.

But last week, Judge John Z. Lee of the U.S. Court of Appeals for the 7th Circuit granted the defendant’s motion to dismiss the charges.

In his Aug. 25 decision, the judge referred to two U.S. Supreme Court decisions from 1969 and 2002. The first ruled that people have a right to keep obscenity in the privacy of their homes, and the second ruled that child sex abuse material that does not depict real children is not child pornography and is protected by the First Amendment of the U.S. Constitution.





What is Putin thinking? When does this escalate from ‘irritating’ to war?

https://www.euronews.com/my-europe/2026/09/02/europe-jolted-by-the-kremlins-hybrid-escalation

Europe jolted by the Kremlin’s ‘hybrid’ escalation

This morning, there’s a palpable sense here that the confrontation between Russia and European nations has entered a dangerous new phase. Leaders across Europe have issued scathing condemnations after Germany formally concluded yesterday that the Kremlin was responsible for a recent attempted drone attack on Leipzig airport.

Not at war, but…: Announcing fresh sanctions on Moscow in response to the incident – including tighter entry controls on Russian nationals – German Interior Minister Alexander Dobrindt said on Tuesday: "Let me be very clear: we are not at war. But we are the target of hybrid attacks on a daily basis.” Germany has also raised its threat level from “general” to “high”.

‘Malign actions’: NATO secretary-general Mark Rutte said that the evidence pointing to Russia was “clear”, adding that the Alliance would “strengthen (its) ability to deter and defend Allies against any threat – including malign actions like those seen in Leipzig”.



Wednesday, September 02, 2026

Interesting. Follow the links.

https://www.bespacific.com/one-us-citizen-just-triggered-a-stunning-national-chain-reaction/

One US Citizen Just Triggered a Stunning National Chain Reaction

Glass Empire by W.A. Lawrence: “On August 31, 2026, USA TODAY reported that the U.S. Department of Homeland Security circulated a secret intelligence bulletin naming Laura Berlin’s website, “Who is Profiting from ICE?” 





I wonder what risk they foresee?

https://thenextweb.com/news/ice-boston-dynamics-spot-robots-procurement

ICE plans to buy Boston Dynamics robot dogs without running a competition

US Immigration and Customs Enforcement has posted plans to buy a fleet of Boston Dynamics robot dogs. The listing puts the spend at $1m to $2m. It also says ICE does not intend to compete the purchase.

Joseph Cox found the plan for 404 Media on Friday. It sits in the Department of Homeland Security’s Acquisition Planning Forecast System. That is a public database where federal buyers flag what they intend to purchase, months before they go out to market.

Anyone can read it. Almost nobody does.

… ICE wants the robots for “inspection, situational awareness, and hazard assessment in environments that may pose risks to personnel”. The capability “helps improve officer safety”, the record says. It lets the agency reach “dangerous, confined, unstable, or difficult-to-access areas”.