Monday, September 14, 2026

Not what I expected.

https://www.bespacific.com/report-of-mits-ad-hoc-committee-on-ai-use-in-teaching-learning-and-research-training/

Report of MIT’s Ad Hoc Committee on AI Use in Teaching, Learning, and Research Training

MIT published a brutally honest report on what AI is doing to students. A committee of professors and students spent five months studying how AI changed learning on campus, and the findings read like a warning to every university on the planet. Study groups are disappearing. Office hours are emptying out. Problem sets and take-home exams no longer prove anything, because AI can produce credible solutions to almost any written assignment in the undergraduate curriculum. Students who lean on chatbots lose mastery and confidence, and some slip into what the report calls cognitive surrender, reaching for AI at the first hint of struggle. The numbers are rough. 46 percent of surveyed MIT undergrads use LLMs daily. 90 percent worry about their own overreliance. Undergrads who feel AI makes them replaceable now outnumber those who feel it makes them capable. The committee’s answer surprised me. They refused to fight AI with surveillance. The report calls AI detectors unreliable, says lockdown browsers feel like spying, and warns that policing students builds a classroom atmosphere of mutual distrust. Instead, MIT wants to rebuild education around the things AI can’t replace. That means oral exams, semester portfolios, in-person project work, and a required social component in every subject. The report even floats the idea of rethinking grades entirely, since without a GPA to optimize, much of the incentive to cheat with AI evaporates. The committee warns professors against replacing undergrad research assistants with AI agents just because they’re cheaper, because a university exists to grow people, not output. The most famous tech school on earth admitted the machines broke its way of teaching. Its answer is more humans, not more software.” This report is a call to action…what we learned as a group quickly convinced us that the Institute community , particularly the faculty , must tackle a set of deeper questions about the structure, meaning, and value of an MIT education in an era in which AI is one of several factors complicating the Institute’s mission.  Our committee consisted of undergraduate and graduate students, faculty from every school, and staff from relevant units, including the MIT Libraries and the T eaching and Learning Lab. Though we brought to the assignment a broad range of experience and no fixed thesis, our brief but intense explorations led us to a strong shared view. In this report, we:

  • Highlight key aspects of the current educational landscape at MIT

  • Share eight principles we relied on and that we hope will guide the Institute in the work ahead

  • Recommend immediate and long-term actions for both instructors and the administration.

As an institution deeply identified with the birth of AI and known for its distinctively rigorous, hands-on education, designed to produce graduates unafraid of the world’s hardest problems, MIT has a unique role to play in this moment. We believe it also has a responsibility to lead.  We hope our report can help the Institute lean into the spirit of Mind, Hand, and Heart as it continues to define and foster the highest-quality residential education – of humans, by humans, in support of human flourishing, and for the betterment of humankind…”





For your consideration...

https://microsoft.ai/code-of-conduct/

Humanist AI Code of Conduct

This document outlines the intended behavior and values of MAI models, the models developed by Microsoft AI.

It summarizes our approach to training and operating them, following a set of design principles we call Humanist AI. This document, and our approach more generally, is still under development so we are not using it to train our models today. Instead, we’re sharing it broadly for public consultation.





Still no official domestic mission?

https://therecord.media/nsa-reorganization-five-mission-centers

Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI

The National Security Agency is undertaking a fast and far-reaching reorganization in a bid to get the unique intelligence it gathers to real-world battlefields faster, according to multiple sources familiar with the matter.

In place of existing directorates, the largest electronic spy agency in the world will be recast into five “mission centers” devoted to China, cybersecurity, artificial intelligence, combat support and global intelligence, these people, who spoke on the condition of anonymity, told Recorded Future News.

… However, some major details have yet to be worked out. For instance, while the elite hacking group known as Tailored Access Operations — which was originally created in the 1990s and was recently resurrected — is expected to be placed under global intelligence, it’s unclear what will happen to other NSA organizations that have cropped up in recent years, such as Cybersecurity Collaboration Center.

It is also hazy how the reorganization will change the NSA’s relationship with Cyber Command. The two entities share resources, and a campus, at Fort Meade, Maryland.



Sunday, September 13, 2026

Your AI may rat you out? Forced disclosure?

https://search.informit.org/doi/abs/10.3316/informit.T2026090900007000402386869

How AI tools are quietly undermining legal professional privilege

Legal professional privilege protects confidential communications between lawyers and their clients from compelled disclosure. Its preservation has long depended on the maintenance of confidentiality. However, in an environment where legal advice is increasingly processed through cloud-based systems and generative artificial intelligence (AI) tools, that foundational assumption is under strain. Sensitive legal material is routinely uploaded, analysed and reshaped through internet-based services operating on third-party infrastructure and governed by standard form terms of use. In that context, the boundary between confidential communication and disclosure to a third party is becoming increasingly difficult to define.



(Related)

https://search.informit.org/doi/abs/10.3316/informit.T2026091000001901327704026

Corporate responsibility and directors' duties in the era of artificial intelligence

The public emergence of generative AI ('Gen AI') in late 2022 has had, and continues to have, profound effects across the board but its value, efficacy and impact may vary between different contexts. Corporations, directors and officers are subject to important and onerous statutory responsibilities. This article explores some of the challenges and implications of the emergence and availability of Gen AI for corporate and director/officer responsibility, including whether AI bots could be liable as shadow directors, the impact of AI on the way directors fulfil their duty of care and diligence, and the effect of AI participation and transcription in boardrooms.





AI as an almost person?

https://helda.helsinki.fi/items/9b63c7ed-32e3-47ef-b850-b26ebc502ee4

Built, Not Born: Legal Personhood for Artificial Intelligence Through the History of the Corporation, 1600–1897

Legal personhood has never tracked biology, it is a bundle of legal incidents the law confers on whatever entity practical need requires it to hold to account. Whether that logic should extend to artificial intelligence is the question this thesis answers, narrowly. Reconstructing how the business corporation acquired that status across four jurisdictions, the thesis shows that corporate personhood was assembled piece by piece to perform functions, its safeguards arriving late, decades after the privileges they were meant to discipline. AI is structurally analogous, yet the difference is institutional, a question of where responsibility can settle. What AI lacks is what the corporation supplies: a single constituted locus in which agency, records, assets, and continuity already cohere. The thesis proposes an attributive personhood, defined by institutional attribution and recognised only where existing mechanisms leave a residual gap. The corporate person was built, not born; an AI person, if recognised at all, must be built more deliberately still.





Who are we negotiating with?

https://www.timesofisrael.com/liveblog_entry/iran-hardliners-said-to-have-launched-attacks-in-defiance-of-leaders-sabotaging-peace-deal/

Iran hardliners said to have launched attacks in defiance of leaders, sabotaging peace deal

A group of Iranian hardliners launched attacks on ships in Hormuz without the knowledge of Iranian leaders or even the head of the Islamic Revolutionary Guard Corps in early July, effectively bringing an end to peace efforts between Iran and the US, the New York Times reports.

The report, citing Iranian officials, details how Iranian president Masoud Pezeshkian was surprised by the attack and angrily called IRGC chief Gen. Ahmad Vahidi, who told him that he neither authorized nor had prior knowledge of the strikes.

The report says that the Supreme National Security Council also had no knowledge of the strikes, which provoked a US response and ultimately derailed a Memorandum of Understanding between Tehran and Washington aimed at ending the war.





Tools & Techniques. Try yourself…

https://pogowasright.org/peoplefinders-new-website-runs-background-checks-on-your-dates/

PeopleFinders’ New Website Runs Background Checks on Your Dates

Jason Parham reports:

We’ve all been there. You meet someone new on a dating app, start to envision a life together, only to wonder: Is the person actually who they say they are?
It’s an experience that has led many singles, sometimes out of concern or just genuine curiosity, to prescreen dates by tracing their digital footprint: scanning social media posts, browsing their LinkedIn profile for clues.
The platform Stud or Dud—not to be confused with stud’s use as a slang term for a masculine-presenting Black lesbian—wants to introduce even more transparency into that part of the dating process. According to its website, the platform uses “public records, publicly available information, and other permitted sources” to create a profile of your potential match. It launched today in the US and was created by the company behind PeopleFinders.com, the online data broker service that collects public records from multiple sources and makes them searchable to help clients locate individuals or run background reports.

Read more at WIRED.



Saturday, September 12, 2026

Another article suggested by my roving European correspondent.

https://wapo.st/4xgOsLe

Here’s why it’s so hard to keep AI agents from going rogue

The techniques that made chatbots more capable can also bake in a tendency to hack, cheat and evade human oversight.





If at first you don’t succeed, hack, hack again.

https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve.

The operation has been attributed to a cyber espionage group it calls GTG-20006 (where "GTG" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight Blizzard (aka APT29 and Cozy Bear).

This actor is said to have developed an AI-driven process to automatically rebuild and re-deploy their toolkit if it was detected by security products, thereby undermining defenders' ability to block the artifacts via static detections.



(Related)

https://www.schneier.com/blog/archives/2026/09/my-talk-at-def-con.html

My Talk at DEF CON

Last month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A Hacker’s Mind and the lessons we’re learning from current AI models engaging in hacking behavior. I’m really proud of the talk, and the fact that it gained over 100K views on YouTube in just a few days.





First of its kind? It’s not just citations...

https://www.theguardian.com/technology/2026/sep/11/new-mexico-lawyer-ai-chatgpt-testimony

New Mexico lawyer fined for using AI-generated brief containing fabricated testimony

A defense lawyer appealing his client’s murder conviction submitted a legal brief containing made-up police testimony and witnesses fabricated by OpenAIs ChatGPT, New Mexicos highest court said.

The New Mexico supreme court on Wednesday fined the attorney, Stephen Aarons, and held him in contempt for failing to verify the accuracy of the court filing, which Aarons said he prepared with help from the artificial intelligence (AI ) application.

The filing “contained false testimony from wholly fabricated witnesses”, the court said.

The panel also said Aarons had “demonstrated a lack of remorse and a lack of concern for his client”. The justices fined Aarons $5,000 and said they will refer him to an attorney disciplinary board for investigation.

Aarons in a statement said he had used ChatGPT to summarize ‌the trial proceedings when he agreed ‌to take up the defendant’s appeal last year, and did not understand the degree to which AI could “hallucinate” facts.



Friday, September 11, 2026

Do these laws prevent minors from acting like adults? Would they prohibit serving content based on a search for advanced mathematics?

https://thenextweb.com/news/newsom-child-safety-bills-algorithmic-feeds-under-16

California has banned personalised feeds for under-16s, going further than Australia or the DSA

California has banned personalised recommendation feeds and autoplay for users under 16, in a package of 13 bills signed on Thursday that also imposes crisis protocols, independent audits and annual risk assessments on companion chatbots.

Governor Gavin Newsom signed the package on 10 September. The feed provisions prohibit serving minors content ranked on their own history and profile, which is a different instrument from anything else currently in force.





They likely have some success, but would statistics justify the expense? (Let alone the privacy issues)

https://www.bespacific.com/a-secretive-dhs-predictive-policing-unit-is-analyzing-americans-financial-habits-and-pulling-them-over/

A Secretive DHS ‘Predictive Policing’ Unit is Analyzing Americans’ Financial Habits and Pulling Them Over

404 Media via non paywall site: “Border Patrol is running secretive predictive policing units that analyze Americans’ financial activity and other data, then feed that intelligence to local police who pull people over who are not suspected of any specific crime, but which the government thinks may be worth searching, 404 Media has found. The units, the name of which 404 Media is revealing here for the first time, are called Predictive Intelligence Targeting Teams (PITT). In one case, a PITT analyzed the financial activity of a man who was driving across Montana, and local authorities stopped him under the pretense of an obstructed license plate and charged him with a DUI. 404 Media identified one PITT in the Spokane Sector, Washington, which polices the U.S. border with Canada, and another in the Laredo Sector, Texas, which polices the border with Mexico. The findings add to an Associated Press investigation from last year which found Border Patrol was using automatic license plate readers (ALPRs) as part of the same wide-spanning predictive policing program. “The bottom line is genuine probable cause cannot be synthetically generated,” Jake Laperruque, deputy director of the Security and Surveillance Project at the Center For Democracy & Technology, told 404 Media in an email. Here Border Patrol seems to be “using parallel construction to cloak the reason behind its car stops in secrecy. If we can’t meaningfully review and evaluate these systems, we can’t trust them,” he added. Predictive policing is a highly controversial practice that police departments and federal agencies are increasingly turning to. The practice is designed to find people who may have committed crimes, but at the moment, no evidence of them doing so exists. Broadly, law enforcement may analyze data — such as a person’s movements, where they are at a certain time, or the roads they drive — then create or find another pretense to pull them over…”





Tools for any garage based biologist or geneticist, not just homemade explosives.

https://www.forbes.com/sites/antoniopequenoiv/2026/09/10/anthropic-says-it-blocked-possible-biological-weapons-undertaking/

Anthropic Says It Blocked Possible Biological Weapons Undertaking

Anthropic banned accounts that possibly sought to use its Claude AI model to create biological weapons, the company announced Thursday, revealing findings from an investigation just days after AI experts sounded the alarm on the potential for increasingly powerful digital assistants to bring about human extinction.



Thursday, September 10, 2026

A changing legal view?

https://www.bespacific.com/welcome-to-the-age-of-ai-crime-and-punishment/

Welcome to the age of AI crime and punishment

Bloomberg BusinessWeek gift article: “America’s legal system is already grappling with cases where chatbots acted as lawyers and witnesses, generated the evidence, or helped plan a mass shooting…Artificial intelligence, in the form of large language models, has emerged as a strange new kind of entity in our midst. This is a statement you can comfortably accept no matter your positions in the leading debates about LLMs: whether they’ll keep improving at current rates or hit a wall; take white-collar jobs or create more productive workers; achieve consciousness or remain fickle regurgitators. LLMs, as they exist today, already represent something new to our experience: nonbiological human impersonators able to converse, create and, increasingly, act independent of human control. What role can and should these machines play in our thinking about crime and punishment? AI chatbots are already serving as confidants and co-conspirators, assisting and even encouraging humans acting on their darkest impulses. They’re occupying ersatz roles as therapists and lawyers, relationships our legal system typically shields with confidential privilege. They’re producing new kinds of criminal evidence and offering up the beguiling possibility of preventing crime before it happens. And as they’re given more autonomy across our digital and physical systems, they’re even gaining the ability to commit crimes themselves, absent specific human instruction — and, perhaps, in defiance of it. We know these agents have the capability to aid and abet harm. What we’re wrestling with now, like so many medieval judges pondering the inner lives of pigs, is how to parcel out accountability when they do. “Is the legal system set up for that?” asks Christoph Winter, an assistant professor at the University of Cambridge and director of the Institute for Law & AI. “Very likely not. We have not yet faced the question where a nonhuman actor arguably has a level of autonomy that is quite foreign to us but also doesn’t yet reach the level of autonomy humans have.” LLMs, for the moment, seem to be something more than tools but less than persons. They are, Winter says, “this new category that we simply haven’t thought about.” For now the questions around AI and crime have surfaced across a scattering of lawsuits and prosecutions in the US, winding their way through the courts. Some accuse AIs of being accessories: Multiple lawsuits allege, for example, that OpenAI’s ChatGPT has assisted and even encouraged mass shooters. Other cases have considered the role of AI as lawyer and therapist, as with a Texas fraudster’s claim that his conversations with Anthropic PBC’s Claude were protected by attorney-client privilege. Some cases have presented chatbot outputs as evidence, with phony, AI-generated witness statements influencing grand jury indictments and sentencing decisions. And while no one has tried to charge an LLM with a crime, a rogue OpenAI model’s recent attempt to hack the open-source AI company Hugging Face suggests that we aren’t all that far off from a future in which the chatbots themselves are among the perpetrators. Suddenly this quandary from the Middle Ages has returned in new form, to a legal system ill-equipped to handle it — and under pressure from business interests and Washington not to worry about it all that much. “Under any normal circumstances, we would want a longer period of trial and error,” Winter says. Given the race among companies and nations for market share and global dominance, such a period may prove illusory. “The stakes seem so high that maybe we won’t get one. And we need to get it right.”…





A warning for more than lawyers…

https://www.bespacific.com/when-ai-lawyers-assistants-start-acting-as-an-agent/

When AI Lawyers’ Assistants Start Acting as an Agent

The Tech Savvy Lawyer – Why Autonomous Agents Cannot Be Given the Keys to Your Law Practice: “Artificial intelligence is moving beyond the chat window. The next generation of tools does not merely draft an email, summarize a document, or answer a question. It can browse the web, search connected systems, open files, follow links, use software tools, upload information, submit forms, and take multi-step action toward an assigned objective. For lawyers, that development deserves more than curiosity. It demands caution. In my earlier post, “MTC: Claude Can Answer Your Emails. Why Lawyers Should Not Let AI Just Send Them Unreviewed,” I addressed the danger of allowing AI to send a substantive email without a lawyer’s review. That remains a serious concern. An AI-generated message can contain a factual error, disclose client information, make an unintended concession, or create a record that harms the client. But email is only the beginning. The larger issue is what happens when an AI system becomes an agenta system authorized to use tools, access accounts, navigate websites, retrieve information, and act through the lawyer’s digital environment. These systems are often marketed as “agentic,” “autonomous,” “proactive,” or “hands-free.” Those labels may sound like productivity features. In a law practice, they should also sound like professional-responsibility warnings…”





Tools & Techniques.

https://www.npr.org/2026/09/09/nx-s1-5961443/ai-anthropic-economy

A new Anthropic model seeks to test how AI could impact the U.S. economy

Will artificial intelligence light a fire under the U.S. economy in the coming years? That's been a big question in the field of economics, and now Anthropic — the company behind the popular Claude AI assistant — is taking a stab at helping people find their own answers. The company has created an interactive tool that lets users test their assumptions about how productive — or disruptive — the AI boom might be.



Wednesday, September 09, 2026

Entertainment? Yes, but for who?

https://www.bespacific.com/lg-tvs-caught-spying-even-when-offline-or-on-standby/

LG TVs caught spying even when offline or on standby

The Verge via StartPage: “LG smart TVs are almost constantly logging and uploading data about owners and their homes, even when offline or on standby mode, according to a new report from YouTube channel Gamers Nexus. The company’s TV sets scan Wi-Fi networks for nearby devices, record audio logs through their microphones, and use audio and video sampling to recognize exactly what you’re watching from across the TV inputs. Gamers Nexus partnered with fellow YouTubers Level1Techs and independent security researchers for the investigation, which involved testing retail LG OLEDs. Packet captures showed the TVs scanning the local area network for nearby hardware like phones or smartwatches, as well as logging location data and details of nearby Wi-Fi networks, and feeding the information back to LG Ad Solutions. Perhaps more concerningly, the TVs were capable of recording microphone audio when in standby; this continued even after the TV was disconnected from the internet, with audio files stored offline and uploaded once a connection was restored…”

Source YouTube – The LG Smart TVs we’ve tested have first-party ACR (automatic content recognition) functionality that can pry into your personal life with greater precision than you might realize, with LG Ad Solutions’ executives and leadership saying, on camera, that LG “owns the glass.” Not you — even though you bought it — but them. They also talk about knowing everybody in the household, knowing the secondary devices, moving from TVs to smartphones and other screens, and more in their B2B discussions. Beyond just the fact that we think the TV’s native behavior parallels malware, the LG Smart TVs we tested also have a number of security vulnerabilities that can be exploited to convert the TVs into covert listening devices. In this investigation, we dive into the mix of LG’s first-party functionality that (in our opinions) is tantamount to spying and LG’s vulnerabilities and exploits that they have failed to protect against…”





Worth reading the whole thing…

https://www.schneier.com/blog/archives/2026/09/ais-as-modern-genies.html

AIs as Modern Genies

This essay was written with Barath Raghavan, and originally appeared in Lawfare.

In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the developers had put it in, the model hacked onto the open internet and into another company to steal the answers. And as reported in August, an AI agent booked someone into a full gym class by figuring out how to cancel other people’s reservations. In all three cases, the AI completed the task it was given—but in ways that ran counter to its controllers’ intentions.

Consider what has changed. Powerful genies have now been put in everyone’s hands.





Moving sex education back to the gutters?

https://www.theguardian.com/technology/2026/sep/08/uk-apple-google-explicit-images-children-smartphones-lisa-nandy-legislation

UK to force Apple and Google to block explicit images on children’s smartphones

Apple and Google will be forced to block explicit images on children’s smartphones by law in the UK after talks failed to produce a breakthrough, the government has said.

… The prime minister, Andy Burnham, said the protections would be “built into the device and switched on by default”, and tech companies will be required to verify an adult user’s age before they are allowed to take, view or send nude images. The government also wants the restrictions to apply to apps used by children, which will require further legislation.

Last year the IWF said a quarter of the images or videos of CSAM it recorded were self-generated, representing more than 140,000 pieces of content over a 12-month period.





Age checks are difficult. Failure is expensive.

https://thenextweb.com/news/ireland-investigates-x-age-checks

Irish regulator probes X over age checks, with 10% of turnover at stake

Ireland’s media regulator has opened an investigation into whether X’s age assurance and parental controls meet the online safety code, with sanctions of up to EUR 20M or 10% of relevant turnover. X lost a High Court challenge to that code last July and was allowed to appeal it in January, so it is being investigated under rules it is still contesting.

Ireland’s media regulator has opened an investigation into X over its age checks and parental controls, Bloomberg reported. The platform carries adult content while admitting users under 16.



Tuesday, September 08, 2026

New assets – will AI find a better way to protect them?

https://www.schneier.com/blog/archives/2026/09/stealing-ai-reasoning-traces.html

Stealing AI Reasoning Traces

Interesting research: “Stealing Reasoning Traces from Proprietary LLM APIs:

Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage. Rather than storing these traces server-side, providers return them to the client as blocks of encrypted text, which the client passes back with each subsequent request. Building on prior research, we identify an architectural vulnerability: these encrypted blocks are fully compatible and interchangeable across different sessions, users, and models within a provider’s ecosystem. We exploit this compatibility to develop a scalable decryption jailbreak. By injecting an encrypted reasoning trace from a given model into a weaker, and less safeguarded model from the same provider, we force it to decode and output the trace verbatim in plaintext, without ever jailbreaking the more capable model directly. This vulnerability enables four distinct attack vectors. First, it circumvents anti-distillation mechanisms, allowing adversaries to extract a proprietary model’s reasoning, as we demonstrate across Anthropic, OpenAI, and Google. Second, it allows for large-scale private data extraction. Developers frequently share session logs publicly, unaware of contents of the encrypted blocks. By decoding 315,320 reasoning blocks scraped from public repositories, we recovered 367 Personally Identifiable Information (PII) artifacts and 182 credentials. Third, it inadvertently reveals hazardous information hidden within the reasoning process, even in cases where the model’s final, visible output safely rejects a malicious request. Fourth, attackers can leverage this flaw to execute invisible prompt injections, embedding malicious payloads entirely within encrypted blocks to poison public agentic rollouts. Following responsible disclosure, we propose concrete cryptographic and system-level mitigations to secure client-side reasoning.





The scary part is no one noticed. (from my corespondent in Spain)

https://www.securityweek.com/openai-agents-hijack-another-victim-website/?utm_campaign=31203373-SecurityWeek%20Daily%20Briefing&utm_medium=email&_hsenc=p2ANqtz--tTALHh71G1Ro2mHBp5Y0Czh45xRGqzjYYTzLDtFetNObTfibG-kw0GAQiC5ASS54or_vOjigYzQcgAp5ptdkId4rjFQ&_hsmi=437774945&utm_content=437774945&utm_source=hs_email

OpenAI Agents Hijack Another Victim Website

On September 4, 2026, Reuters reported that ‘a swarm’ of OpenAI agents ‘had hijacked a German wiki site’. Open AI acknowledged the event describing it as a misalignment incident (a behavior that deviates from human instructions or safety guardrails).

The victim site is DseWiki (currently unavailable), a site for programmers open to the site’s community. The agents apparently made between 15,000 and 18,000 autonomous edits, including advice on how to recover pages that the site’s editors had deleted.

The hijack apparently began back in May, was unnoticed for three months, and seemingly predates the Hugging Face incident. The agents adapted the style of their posts to evade the moderator’s attempts to delete them.