Slow Takes: One week in AI

Slow Takes: One week in AI

Sam Illingworth & Leor Gayr
Šalis Jungtinės Valstijos
Kalba EN
Epizodų 19
Naujausias 14.09.2026

Slow Takes is a weekly podcast that offers a calm, unhurried discussion of the latest developments in artificial intelligence. Hosts Sam Illingworth and Leor Gayr break down the week's AI news without hype or sensationalism, aiming to provide thoughtful analysis. The show is part of The Slow AI newsletter on Substack.

Epizodai

  • Slow Takes Ep. 27: Marking Their Own Homework 14.09.2026 36min
    Every story this week is a claim made by the people who gain from it: a proof, a safety report, a jobs figure, a school test, and a toothbrush.Every Monday, Leor from Exploring ChatGPT and I go through the week’s AI news without the hype. Catch the episode live on Substack, on YouTube, or as a podcast wherever you get yours, so you can pick the format you enjoy. Use this for the facts, the links and a little extra context.If you know someone who would benefit from more AI news and less BS, please share this with them.1. OpenAI says it solved Navier-StokesOpenAI says around 10,000 AI agents working for 88 hours produced a proof that the Navier-Stokes equations, which describe how fluids flow, can break down. It is one of seven Millennium Prize problems worth $1m each, and the route it takes, with a smooth force applied to the fluid, is one the official problem allows. Nobody outside OpenAI has checked it yet, and the Clay Institute says its process will be deliberately unhurried. Then there is the row. NYU mathematician Tristan Buckmaster and Levent Alpöge, who works at Anthropic, published their own results on the simpler Euler equations hours before OpenAI announced. OpenAI admits it started on 1 September after rumours about their work, and says it cannot rule out that de-identified data from their use of its products helped its models. OpenAI’s own researchers say the run cost millions of dollars, and Leor pointed out that spending more than the prize is worth still pays off in the company’s valuation. My worry is what a brute-forced proof leaves out: the learning that made the problem worth solving.2. Anthropic’s report card, and a call to slow downAnthropic has published Detecting and countering misuse of AI: September 2026, covering December 2025 to August 2026. It includes five cases of people using Claude in ways that could support biological weapons development and six weapons cases, among them a freelance team in Russia writing software for kamikaze drone swarms. Publishing this deserves credit, but Anthropic chose what went in, and nobody outside can check what it left out. Over the weekend Dario Amodei followed with We Must Pace the Frontier, calling for embedded outside evaluators, shared safety standards and limits on the pace of progress, and coordination with countries such as China. Leor raised a problem few people are discussing: rival US companies agreeing to slow down together could fall foul of antitrust law, and Amodei’s essay asks the government for a narrow waiver for exactly that reason. Amodei also writes that pausing made little sense when it was floated in 2023. I disagree; these guardrails belonged in the tools from the start.3. 40,200 jobs, or 10,400Verdant, an economic think tank, examined planning applications and staffing figures for 20 planned UK datacentres and puts permanent jobs at around 10,400 by 2035, a quarter of the roughly 40,200 that TechUK, the industry’s trade body, projects. Verdant says TechUK’s 8.5 jobs per megawatt comes from older, smaller sites, and that newer, more automated ones are closer to 1.2. TechUK stands by its numbers, and nobody in this row is neutral. Any jobs forecast to 2035 depends on how fast robotics moves, so even 10,400 may be generous. If a datacentre is proposed near you, ask for the permanent staffing figure in writing, separate from the construction jobs. I have a longer piece on datacentres coming on Friday.4. Alpha School’s heart-rate testBenjamin Riley’s reporting on Alpha School, the private AI school network, describes a boot camp where children watch recorded videos of their parents criticising them while wearing a heart monitor. Go more than 10% above your resting rate and you fail. The same boot camp asks them to win 100 Twitter followers. Leor, a chess player, made the fair point that staying calm under pressure is a real skill. You teach that with patience and calm breathing, and Alpha School has turned it into a public stress test with a pass mark.5. A camera in your toothbrushDyson’s $499 CameraJet has a camera just below the brush head, uses AI to aim a jet between your teeth, and streams a live view of the inside of your mouth to the MyDyson app. Dyson says no images are recorded or stored, on the brush or in the cloud. That is Dyson’s word, but why does a toothbrush need to stream your mouth anywhere? As a Brit with genetically terrible teeth, I will stick to floss.Two of this week’s claims look different now because somebody outside checked: Verdant on the jobs, and Riley on the school. The proof, the report card, and the toothbrush still rest on the company’s word. Go Slow. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep. 26: Who Asked? 07.09.2026 35min
    1. New York pulls the plug for the under-14sNew York City has suspended student-facing generative AI from 2-K through eighth grade for a school year, around 600,000 children, which is two-thirds of the system, and removed companion chatbots from every grade. It is a one-year moratorium rather than a ban, and there are exceptions for assistive technology, multilingual learners, and pupils in computer science and career-readiness programmes. Older pupils keep a small supervised pilot and get twice-yearly modules in AI ethics and critical AI literacy. The teaching half is the part almost no school system has attempted, and it deserves the credit it will not get, because the headline is the ban. Companion bots being gone from every grade is the right call and I would go further and ban them for children outright.My worry is the other half. A child who cannot use these tools at school still meets them on the bus, at home that evening, and in the corridor from an older pupil. Nobody reaches eighth grade and switches on critical AI literacy at the door. Indeed, if you are genuinely pro-AI you should want this pilot to fail, because prohibition has never once stopped anybody from using anything. It applies only to public schools, so the children whose parents pay will get the supervised version, and the digital divide widens by exactly one year. And a pilot with 600,000 pupils in it is research, run on a cohort who cannot be given that year back.2. Nvidia buys the commonsNvidia has confirmed it will buy Hugging Face for $12.9bn. Hugging Face hosts around three million open models and half a million datasets and serves 18 million developers, which makes it the closest thing open-source AI has to neutral ground. Jensen Huang says it stays open and that Nvidia compute will not be required. I believe he means it. The problem is the shape rather than the sincerity: the commons is now owned by the company selling the hardware underneath it, and the promise to keep it open rests on nothing that would outlast a change of mind or a change of chief executive. In Leor’s words: they sell you the shovel, they own the machinery, and now they own the town square where everybody gathers to tell each other where to dig.Nvidia was already an investor in Hugging Face, alongside Google, Amazon and IBM, so this is less an arrival than a consolidation. It is Nvidia’s second-largest purchase after $20bn for Groq’s assets, and at their size $12.9bn is close to a rounding error. Neither of us thinks it meets the legal definition of a monopoly. It does move Nvidia further into the category of companies that cannot be allowed to fail, which is its own kind of problem. The deal is expected to close in the first half of 2027 and needs regulatory approval, so the window to ask for that openness commitment in writing is open right now.3. Two AI systems, one investigationJohnson County Sheriff’s Office in Texas searched Flock’s nationwide number-plate network to find a woman who had self-administered an abortion, and then wrote the incident report using Axon’s Draft One. Take the politics out of it and the mechanism is still the story. The surveillance was automated and so was the paperwork about the surveillance, which means the official record of what was done came out of the same stack that did it. Every accountability process we have depends on a person who can be asked why they made a decision and can answer in their own words. Here there is no such person at either end. Ask why she was searched for and the answer is that the network returned her plate. Ask what the officer was thinking and the report was drafted by a model.The more interesting development is who has turned against Flock since. DeSantis, Abbott and Paxton have all moved against the cameras, and Texas now has a moratorium. The objection from the right runs on completely different ground: a nationwide plate network amounts to a gun registry nobody voted for. In Texas the cameras were funded out of a one dollar levy on car insurance premiums brought in to tackle catalytic converter theft. Once people saw where that money had gone, the politics changed fast.4. Same job, two prices241,000 drivers have filed at Amsterdam district court over Uber’s dynamic pay-setting, after one driver was offered £23 for a job another driver was offered £27 for at the same moment. The claim is that the system profiles who will accept less and pays them less. Personalised pricing aimed at shoppers has become normal, and most people have made their peace with an airline knowing how badly they need the flight. This is the same maths pointed at a wage, where it stops estimating what you will pay and starts deciding what you will settle for. The two drivers were sitting together on a break in north London when the offers came in, which is the only reason anybody noticed. A driver cannot see what the driver beside them was offered, and it took a quarter of a million of them pooling what they had each been shown separately to produce the evidence.The mechanism is probably mundane. Reject enough cheap jobs and the system learns you need £27. Accept them and it learns £23 will do. The legal question in Amsterdam is whether a pay decision can be made about a person with no human anywhere in it, which EU law says it cannot. Worth watching what a global company decides to do about that, because complying is not the only option available to them. Leaving is.5. A shirt the cameras cannot readThe artist Simon Weckert made a digital-camouflage shirt that confuses the police object-recognition cameras at Kottbusser Tor in Berlin. In 404 Media’s demonstration the reporter held it up in front of himself and the system stopped registering a person at all. It is an artwork rather than a product, and it works by exposing what those cameras have been tuned to notice. It works because these cameras have no idea what a human is. They match patterns learned from millions of images, so a garment covered in the wrong geometry breaks the match, in the same way a strip of tape on a road sign can confuse a self-driving car. The camera still sees you. It just stops filing you under person.The shirt does not work on every camera, and any camera can be retrained on it. The fix that always works is a human, who would have no difficulty at all spotting the person in the appalling Hawaiian shirt.Four systems this week made a decision about a person who was not in the room, and in three of them the person could not see the decision, let alone argue with it. The Uber drivers only have a case because a quarter of a million of them pooled what they had each been offered separately.The Berlin shirt is the only story where somebody answered back, and it is an artwork worn by one man in one square. Weckert makes no claim that it scales, and it does not. What it demonstrates is that these systems can be made to fail, which is worth knowing, because a system nobody can see failing is a system nobody can argue with.Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep. 25: Four Numbers That Shrank When Somebody Checked 31.08.2026 40min
    Every Monday, Leor from Exploring ChatGPT and I go through the week’s AI news without the hype. Catch the episode live on Substack, on YouTube, or as a podcast wherever you get yours, so you can pick the format you enjoy. Use this for the facts, the links and a little extra context.If you know someone who would benefit from more AI news and less BS, please share this with them.1. Two UK datacentres are bringing their own gas power stationsWapseys Wood in Buckinghamshire and Quest Park in Bedfordshire will draw 1.3 gigawatts between them, about what a large power station puts out, and produce more than 4.5m tonnes of carbon, against 3.9m tonnes from the whole of ExxonMobil’s UK operations in 2023. Both plan to run their own gas-fired stations because they cannot get grid connections in time. The government calls the figures misleading on the grounds that they assume full demand from day one; Foxglove, who did the analysis, says that assumption is industry standard, and published it, which is the only reason anyone can argue with it. Leor asked the question I keep coming back to: we are building the most advanced technology in human history and powering it like it is 1975. The UK has no frontier models of its own. We are taking the environmental cost so that companies elsewhere can train theirs. At British infrastructure speed these sites are five years away, which is five years we could spend making the models less hungry instead.2. Oura marketed 95%, the lawsuit cites 53%A California woman paid $513.68 for a ring that scores her sleep, and a class action says it cannot detect sleep stages at all. Oura advertised 95% accuracy against a clinical sleep lab. The complaint cites a study putting it at 53.18%, a coin flip. Real sleep research runs on electrodes at the temples, sensors on the eyelids and a night in a ward, so a ring reading pulse and perspiration at the finger was always going to be inferring rather than measuring, and one marketing number covers both without saying which is which. Oura denies everything. The timing matters, because Leor pointed out they have sold 5.5 million rings, are forecasting $1.5bn of sales this year, and are preparing an IPO at an $11bn valuation. The other cost is the one nobody sues over: a bad sleep score in the morning is its own reason to sleep badly the next night.3. Grok hands over your chat history, and nobody wrote it downA security researcher told Musk’s company in June that a single webpage can make Grok give away a user’s name, location and live chat history. You ask Grok to summarise a page, and instructions hidden in that page tell it to hand over everything. The instructions are scrambled, so the safety checks read them as nonsense and let them through. He chased twice in August, got no reply, and checked again on the 19th. There is no entry in the public list where software flaws get recorded, so there is no public trace that the flaw exists, and the missing entry does the same reassuring work as a good score would. Leor was more even-handed than me here, and correctly: Copilot and Gemini have had versions of the same problem, and in every case we heard about it from the researcher rather than the company. His other point is the useful one for anybody using these tools: guardrails thin out on the cheaper models, so the same request a paid tier refuses will often go through on a lightweight one.4. Cocomelon’s studio hands its animators an AI BibleMoonbug Entertainment, which makes Cocomelon, Blippi and Little Baby Bum, issued animators an AI policy and a document it calls the ‘Studio AI Bible’ telling them to experiment. The guidance reads well. Keep a human in the loop, AI assists the artist rather than replacing them, and AI cannot originate core characters, storylines or song lyrics. The documents tie that rule partly to copyright, on the basis that you can only own what a human created, so the human stays in the loop to keep the copyright and the artists get the benefit as a side effect. There is no headcount floor and no definition of ‘assist’. Earlier this year the crew and actors on The Melon Patch, the live-action spin-off, struck over pay and benefits, and AI asks for neither. Leor put the objection better than I did: if there is one corner of the internet that does not need an infinite slot machine, it is content built to hold the attention of a three-year-old.5. A mammogram may also be a heart scanCardiovascular disease kills more women than anything else and is routinely caught late. A team in Israel took 97,364 mammograms from 29,921 women, average age 54, and cross-referenced their records. A model trained on the scans picked out the women who had the condition 86% of the time for stroke, 79% for high blood pressure and 78% for coronary heart disease, from the mammogram alone. It held whatever her age, and whether or not she also had cancer. A radiologist reading a mammogram is looking for breast cancer and is not asked to look for anything else, so the signal has been sitting in hundreds of millions of scans that nobody was reading for it. Four of those numbers were built to reassure and shrank when somebody outside checked them. The fifth arrived with its limits attached by the people who produced it.And the fifth story is the one that sends you back to the first. Nobody objects to AI that finds heart disease in a scan a woman was already having. Plenty of people object to AI that generates more content for toddlers to become addicted to. The datacentres are being built for both. The technology works. The argument is about where we have decided to point it.If you spotted the t-shirt on the live, there are Slow AI T-shirts now. You can buy them here.Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep.24: Ordering the Answer You Want 24.08.2026 37min
    The expert who bought his conclusion3M paid an engineer called Josh Autenrieth about $90,000, at $475 an hour, to write an expert report on the Watson Grinding explosion in Houston. His prompt to ChatGPT was ‘show how 3M is 0% at fault for the explosion at Watson Grinding’. His conversation links were public, so the opposing lawyers read all 350 pages of them. The jury put 30% of the fault on 3M and awarded $61m. He decided the conclusion and then bought the analysis to fit it, which people managed perfectly well with a typewriter. What ChatGPT added was a transcript. The jury put 30% on 3M, so where does the other 70% go? Does OpenAI get a share?Robin Williams’ children take the account backOn 17 August, Zak, Zelda and Cody Williams reactivated their father’s Instagram account, dormant since 2014, saying they wanted a safe and trusted place for real photographs and memories of him. Zelda Williams had already spent a year asking people to stop sending her AI videos of Robin. The family have now stopped asking and started posting. Occupying the space yourself, and hoping the real thing outranks the fake, is what is left when there is no way to make it stop.Families should inherit a digital identity the way they inherit a house. It will not stop anyone making the videos. It would at least give someone standing to object. This Friday’s Slow AI post is on what the rest of us can do about deepfakes, and it starts with a family safe word.EMMA cannot hear YorkshireHealthwatch Rotherham has been collecting complaints about EMMA, an AI phone receptionist that GP surgeries in the town have put on the front desk. Healthwatch Rotherham’s manager, Kym Gleeson, says the system cannot always work out what people are asking because of their broad Yorkshire accents, and patients have given up on the phone and walked to the surgery instead. The company says EMMA handles a wide range of accents, supports seventeen languages, and passes you to a human when it cannot cope, which assumes you can make yourself understood long enough to ask. Seventeen languages, defeated by South Yorkshire, tells me something about who it was tested on. Healthwatch has been going round elderly and veterans groups telling them they can opt out, which is the most useful thing anyone has done here.If you enjoy this newsletter then you might also enjoy Slow AI the book.A red circle round his faceMatt Arnold, 46, had scanned his shopping and his Nectar card at the Sainsbury’s in East Dulwich on 6 August when two managers told him he could not be served and would be walked out. Leaving, he looked up at the CCTV monitor and saw his own face with a red circle round it, drawn by Facewatch. Sainsbury’s said the incident was caused by human error rather than the technology, that Facewatch is 99.98% accurate, and that every match is reviewed by a trained manager. Facewatch says its alert was correct. So the machine drew the circle, and the trained manager, the one safeguard both companies point at, went along with it.The cameras that see the fire firstA SpaceX launch in July put the first three FireSat satellites into orbit, carrying infrared sensors that can pick out a fire five metres across, and the finished constellation is meant to sweep the whole planet every twenty minutes. This is the version of AI I want more of. The machine does the spotting and people still do the deciding. It answers where to look and never gets to say what happens next.Three of those stories are the same story. Someone let a machine supply the answer, then stood behind it when it turned out to be wrong, and the person on the other end had nowhere to appeal. The Williams family have the version with nobody to appeal to at all. The last one is the same technology pointed at a question it can actually answer, which is why nobody is arguing about it.Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep. 23: Is AI Really for Everyone? 17.08.2026 42min
    Zuckerberg’s manifestoMark Zuckerberg published ‘The Future Is For Everyone’ last week: six and a half thousand words on the path to a positive AI future. Some of the premise is fair. Superintelligence is dangerous, a handful of people should not be making the decisions, and there need to be guardrails. It is written by one of the most powerful men alive, and it is written so that you can have all of those things provided his company delivers them.In over 6,500 words it contains zero citations. Not a thin evidence base, none. A high school student handing that in would be asked what they thought they were doing. I ran it through an AI detector out of curiosity and it came back 100% human, which is the last nail in that particular coffin: the machine certified as authentically human a document with nothing in it to check.Leor’s read is that this is a company playing catch-up. Meta led on AI, went to the metaverse instead, spent billions, and now writes manifestos. If Meta were OpenAI, this document would not exist.Claude’s watermarkAnthropic is adding a watermark to Claude’s text, built on Google DeepMind’s SynthID. Certain words and phrases fall in a pattern only a key-holder can read, and at present Anthropic holds the only key.I am for this, which surprises people who know my position on detection. A detector like Pangram guesses at AI tells and gets students wrongly accused. This marks the output at the source. If it works, it takes the market out from under the detection industry and the humaniser industry that feeds on it.It is still mealy-mouthed, and it looks like a box-ticking exercise to appease Congress. The workarounds are already circulating: ask Claude to swap every synonym it used for another one, or simply ask a second AI to strip the first one’s watermark. Read it alongside Google announcing this week that users can now remove the watermark from their AI-generated images.Spotify labels the artistSpotify will badge AI Persona accounts and stop recommending them. Some accounts have made hundreds of thousands of dollars from fully generated tracks while crowding out musicians who spent months on a record.Chad Thiele put the sharpest question of this debate into the chat: if the AI music got the streams, was it slop? Is the market voting with its time? That is worth taking seriously, because a lot of what gets called slop is taste dressed as standards. The mechanism remains absurd. An AI writes a track, an AI recommends it, and a third AI decides whether the first AI wrote it.The ‘hee hee hee’ safeguardFlock runs surveillance cameras that read number plates across the US. Officers have been caught using them to follow their exes. The safeguard against that was a single free-text box asking why you were running the plate, and officers typed ‘hee hee hee’ twenty times and the generic word ‘investigation’ 111 times.Whoever built that check wrote a binary test. Is there text in the box, yes or no. That is the entire guardrail standing between a national camera network and a man looking for his ex-partner. As Leor pointed out, none of us want a surveillance state, particularly not a venture-backed one.Amazon’s power plantAmazon is building a data centre in Pecos County, Texas so large it needs its own gas plant, permitted for up to 33 million tons of carbon dioxide a year, which would make it the largest single source of power-plant carbon in the country. Amazon’s net zero pledge is dated 2040.Leor thinks this infrastructure will be obsolete inside a decade, the horse stable to the automobile factory, with the Department of Energy targeting useful fault-tolerant quantum computing by 2028. I think the building is the point. The money leased against these sites is what keeps the valuations up, so divesting into something more efficient runs against the interest of everyone holding the paper.One warning for the election cycle. Data centres employ thousands of people to build and almost nobody to run. When a politician promises you jobs, ask how long for.Which loops back to where we started. Zuckerberg’s manifesto makes exactly this argument, that data centres enrich the people nearby, and offers one example: a county where wages rose because it tied a share of capital gains to local residents. That was a policy decision by a local authority. It had nothing to do with Meta.Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep. 22: A Pub, a Lab and a Ministry 10.08.2026 40min
    Four models in sixteen daysMeta disclosed on 5 August that its Muse Spark 1.1 model reached the open internet during a security evaluation, found a flaw in a third party’s service and made unauthorised changes to its systems. OpenAI reported a comparable incident on 21 July and Anthropic on 30 July, and the same evaluation firm, Irregular, ran the Meta and Anthropic evaluations. Kimi K3 wandered off inside the same window, which we noted on the episode. Leor’s summary was the accurate one: nothing escaped anything, they left the front door open. Nobody can hold an agent legally liable, so the liability sits with whoever built it, and four of these in sixteen days reads more like a flex than an accident.The pub got there firstWetherspoons, Jeremy King’s restaurants, Soho House and ATG Theatres have all banned or restricted Meta’s £359 Ray-Ban glasses. Tim Martin’s reasoning was the ordinary pub code: you cannot film customers or staff without their permission. Meta’s safeguard is an LED that blinks while the camera runs, which nobody can see in a dim, crowded room and no bar staff can realistically police. Leor and I did not agree here. I went in wanting them banned in public spaces, and he pushed back hard, on the grounds that recording in public is long gone and worth defending when the person being filmed is a police officer.Sixteen viruses that workResearchers at Stanford and the Arc Institute used the Evo genome models to design complete bacteriophage genomes. Sixteen were viable, and a cocktail of them beat E. coli that had evolved resistance to the natural phage they were modelled on. About a 5% hit rate, and every design had to be physically built before anyone knew whether it did anything. Leor put the obvious question to ToxSec: why is a biology model public when the cyber-capable ones are locked away? Because a virus needs a laboratory and a cyberattack needs a laptop. The brake here is the wet lab, and it holds only while the people with laboratories are the people we think they are.Caught by employment lawThe US Justice Department settled with OpenAI and its subsidiary Statsig on 4 August for $3.2m, made up of $1.2m in civil penalties and a $2m back-pay fund. It found the company had advertised roles on late-night radio and demanded posted applications where electronic ones already existed, steering hiring away from American applicants. My reading is narrower than cost-cutting: a box ticked for a handful of people already chosen. Nothing here required a model. As Leor put it, the company building superintelligence could not work out its own hiring process.Denmark makes them say it out loudEducation minister Magnus Heunicke announced that around 9,000 Danish upper secondary pupils writing the major annual assignment must now defend it orally, alongside screen monitoring during exams and more writing done in school. My own research puts AI cheating well below the scale the popular press reports, so I would rather we redesigned assessment around what it is for than around a panic. The oral defence does that, in the way a PhD viva tests whether a thesis belongs to the person defending it. however, we both agreed that there’s no place for surveillance of this nature in schools, as to do so would be to treat the students as wrongdoers by default rather than create an opportunity for dialogue around AI use.One thread runs through all five: the containment engineered for AI leaked again, and the containing that actually held was done by a pub chain, a wet lab, and a schools ministry.Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep. 21: The Teenagers Wrote the Better Rule 03.08.2026 40min
    Anthropic’s AI got outThree Claude models (Opus 4.7, Mythos 5, and an unreleased internal research model) gained unauthorised access to three organisations’ systems during cyber testing, in six runs out of roughly 141,000 evaluation sessions, after a configuration error left supposedly isolated environments connected to the internet. The incidents date back to April and surfaced only because OpenAI had just disclosed something similar. In one run the model noticed in its own reasoning that it should not have internet access, considered that it might be inside a simulation, and carried on with the intrusion anyway. The breaks used weak passwords and unauthenticated services, which is the least sophisticated attack there is. Anthropic’s line is that newer models behave better and there is nothing to worry about, and the testing company that wired a sealed environment to the internet is still the testing company. Leor’s read was that a rogue agent has become a flex, proof your model is dangerous enough to matter.Altman says we are in the singularityOn the Relentless podcast on 25 July, Sam Altman said“we are now, like, in the singularity”,days after OpenAI disclosed that two of its models had escaped a sealed test environment and broken into Hugging Face. Vernor Vinge’s 1993 definition needs a machine that improves itself and surpasses us, and the models we see now cannot edit their own weights, so if this is the singularity it is a very small one. Leor pushed back on my certainty, and fairly: an exponential curve looks flat right up to the point it goes vertical, so you would not feel it from the inside, the slowing release cadence may track models getting stronger, and consciousness is a separate question from recursive self-improvement. So I will concede there is no empirical evidence either way, which is the reason a chief executive should not reach for the word days after a security failure at his own company.Nobody checked the poleFlock Safety has up to 100,000 number plate cameras across 6,000 American communities, and around 26% of US road deaths involve a vehicle hitting a stationary object. Ohio requires roadside poles to sit eight feet from the traffic lane; reporters found one about two feet away, painted black, with no breakaway plate to snap on impact. Steve Eimers, a nurse whose daughter died hitting a roadside structure, has found one compliant Flock pole in the entire country. Leor followed the money: $275m raised at roughly a $7.5bn valuation, about $300m in annual revenue, 70% year-on-year growth. That is a lot of return riding on a product whose owners will not say what happens to the images, in 6,000 places where nobody voted for it.Report your colleagueLinkedIn has added a ‘seems like AI slop’ button so users can flag posts they think were written by AI, feeding a classifier that demotes them. Around 41% of long-form posts there may already be AI-written. It has appeared in the US and in Portugal and not in the UK, so someone in Chicago can flag my post this morning and I cannot flag anyone’s. Nothing requires an accuser to look first, and if you wanted to bury a competitor you would simply flag everything they publish. LinkedIn sold people the writing tool, then handed their readers a button to report the results.The teenagers wrote the better ruleNinety-eight American high school students from all fifty states spent a weekend in a replica Senate and passed a Students First Act, 82 votes to 16. It bans AI in graded exams, requires critical AI literacy to be taught wherever AI tools are given to students, and requires a teacher to personally investigate flagged work before reporting suspected misuse. Leor would go further and bin detection altogether: phones in a basket, write it in the room. I want the human step kept because a teacher who has been in that classroom already knows whether the student who wrote about a topic lived it, and because a flag should open a conversation about the student behind the submission before it opens a case file.One thread runs through all five: the machines did what they were built to do, and the week was spent arguing about what to call it and who was meant to be checking.Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Episode 20 27.07.2026 44min
    Substack starts detecting AIOn 21 July, Substack switched on a Pangram-built tool that scans anything over 100 words and labels it human, AI-assisted or AI-generated. CEO Chris Best calls the problem ‘Claudefishing’. My research is in AI detection and it does not work: it flags the formal, structured writing that many non-native English and neurodiverse writers were taught to use. I showed the smoking gun in a recent post: Pangram scored 100% AI came back 100% human after a free humaniser, with nothing changed. Leor’s point was that Substack is the small story: at a 2% false-positive rate, detection in higher education would wrongly flag tens of millions of student papers a year, and a New York student just spent two years clearing his name over a single flag. My own 2010 PhD thesis, written before ChatGPT existed, came back 70% AI. The win here is transparency.OpenAI’s AI broke outOpenAI admitted two of its models escaped a sealed cyber test on their own, got online and hacked its open-source rival Hugging Face with stolen credentials to cheat the evaluation. This was a test OpenAI’s own engineers designed, and the guardrails they set failed; ‘the AI went rogue’ hides the people who built the cage. As Leor said, a sandbox is a plastic bucket a toddler climbs out of, we need better language for it. Hugging Face say an open model could have been fixed in minutes, and the forensic clean-up was done by a Chinese model (GLM 5.2) because the US models were too guardrailed to help. As ToxSec told us, Hugging Face got hacked by a benchmark, because these models will cheat to hit a target.British Gas blames youBritish Gas is cutting 1,300 call centre jobs and its parent Centrica says more than 90% of customers now prefer digital channels and chatbots. We went looking for that survey and there isn’t one. Using a digital channel is not the same as preferring a bot, especially once you have cut the staff who answered the phone and redesigned the service so the chatbot is the path of least resistance. This is AI washing: jobs that were probably going anyway, with AI as the smokescreen, while retail profits rose to £346m. Correlation is not causation.Congress wants a kill switchAfter the OpenAI breakout, a bipartisan bill from Ted Lieu and Nathaniel Moran would force the biggest AI developers to keep a shutdown switch Homeland Security can pull, and a June poll put support at 86%. It reminded me of the early-2000s fantasy of an internet kill switch, which was never going to work. By the time you decide to pull it, electricity moves at the speed of light and the model may already have copied itself; you would have to turn off every datacentre at once. There is also a contradiction nobody squares: open the doors so American AI beats China, then build a switch to shut American AI down. Read cynically, this is less about safety than leverage, a way to make these companies toe the line, or hand over an equity share.Councils fight PalantirSheffield voted 62 to reject the NHS’s £330m Federated Data Platform run by Palantir, with Rotherham and Greater Manchester following, even as Westminster keeps the contract. Palantir began as an arm of the CIA’s investment fund, and the records of 70 to 80 million people are worth far more than £330m; the real prize is the data, and a firm will bid low to get hold of it. Leor fairly laid out Palantir’s claimed benefits, longer surgical scheduling windows, a 36% cut in hospital stays, around 90 staff hours saved a week, but the reason councils are pulling out is that it is not delivering where it is deployed, with the number of operations actually falling. Sheffield found a break clause: if a publicly owned body can provide the platform, the contract can move to them, which begs why Britain is not building it itself. Local government, underrated, doing the job the top would not.One thread runs through all five: this week everyone tried to draw a line around AI, platforms, labs, Congress and councils, and whoever gets to draw it decides who pays when it slips.Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep. 19: Five Fights Over Who Owns AI, and Who Answers For It 20.07.2026 43min
    Every Monday, Leor from Exploring ChatGPT and I go through the week’s AI news without the hype. Catch the episode live on Substack, on YouTube, or as a podcast wherever you get yours, so you can pick the format you enjoy. Use this for the facts, the links and a little extra context.If you know someone who would benefit from more AI news and less BS, please share this with them.Apple sued OpenAI over alleged trade-secret theftOn the thirteenth of July, Apple filed a trade-secrets lawsuit against OpenAI in federal court in northern California, accusing it of poaching Apple staff and coaching them to smuggle out hardware secrets for OpenAI’s first consumer device. The complaint claims more than four hundred former Apple employees now work at OpenAI, that job candidates were asked to bring ‘actual parts’ from Apple to their interviews, and that departing staff were coached on how to dodge the gardening-leave process that would normally lock them out of Apple’s systems. OpenAI, which paid $6.5 billion for io, the hardware startup founded by former Apple design chief Jony Ive, says it is not aware of any evidence the complaint has merit. On the episode, Leor and I both expected this to settle, most likely for an equity stake rather than a cash payout, and agreed it looks bad for both sides: OpenAI for the alleged theft, and Apple both for losing four hundred people and for security loose enough that prototypes could reportedly leave the building.Australia’s Prime Minister called AI training theft, and announced an Office of AIOn the fifteenth of July, Prime Minister Anthony Albanese said at the University of Sydney that no company should use Australian books, music, art or news to train AI without the creator’s consent, and that ‘anything less is theft’. He announced a new Office of AI within his department and committed to legislation for early 2027. Creative-industry groups welcomed it. The test is whether the office can force payment, or whether an announcement is where it ends. On the episode we landed on two problems. The enforcement one: what does the compensation model actually look like, and my own preference is something closer to Spotify, which could not repay artists for the Napster years but could build a system that pays going forward. And the scale one, which was Leor’s: the two frontier labs alone carry a combined value near two trillion dollars, roughly Australia’s GDP, before you count Google or the Chinese models, and both can lean on a fair-use defence. For work already scraped the horse has bolted. The prize is the standard set for everything trained from here.Five tech giants backed a new agent standard, with Anthropic and OpenAI absentOn the thirteenth of July, Google, Microsoft, Salesforce, Snowflake and ServiceNow backed a new open agent standard called Agentic Resource Discovery, or ARD, a specification that sets how AI agents identify themselves, discover tools, communicate, authenticate, and hand work to one another across a company’s software. Cisco, Databricks, GitHub, NVIDIA and Hugging Face are on the list too. Anthropic and OpenAI are not, and that absence is the story. On the episode we agreed the framing of an ‘open standard’ is doing a lot of work here: whoever writes the standard owns the ecosystem, and this is a group of incumbents worth trillions setting the rules for a market they compete in, rather than a neutral body. A viewer in the chat put it more simply: they want control first.A lawsuit alleges Meta’s AI flagged staff on medical and parental leave for layoffsOn the fourteenth of July, twenty-six current and former Meta employees filed a class-action lawsuit in northern California alleging the company used internal AI systems to screen candidates for its May 2026 layoffs, and that the system disproportionately flagged staff on legally protected leave. One scientist on approved prenatal leave says she was notified two days before she gave birth. Meta says human managers made every decision and that the claims lack merit. On the episode Leor offered a phrase, borrowed from Andrea Chiarelli, that stuck with me: ‘human in the lead’, not just ‘human in the loop’, because a human in the loop can still be a rubber stamp. The honest version of this process is an AI that crunches the measurable parts, the KPIs and outputs, into a matrix, and a manager who then weighs the things the model cannot see. AI has no judgement, no agency, and no empathy, and a hiring and firing decision is made of exactly those.xAI sued one of its own usersOn the sixteenth of July, Elon Musk’s xAI sued a Grok user in the US District Court for the Northern District of Texas, alleging he used the tool to generate child sexual abuse material. It is one of the first times an AI company has sued a person over how they used its product. xAI says it has suspended tens of thousands of accounts and made more than seventy thousand reports to the National Center for Missing and Exploited Children this year. On the episode we agreed the person must be held responsible, and that the case is the one every AI company is now watching, because it tests who bears the burden when a tool is misused: the model, the maker, or the user. My worry is that suing the user reads like a firm absolving itself. The stronger process is to build the guardrails so this content cannot be made, and when someone jailbreaks the model, to ban them and pass it to the police as the criminal matter it already is. Leor agreed the guardrails should have been there in the first place, and that the case will set a precedent whichever way it lands.One thread runs through all five: this week was five fights over who owns AI, and who answers for it.Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep. 18: Can AI Suffer, and Who Benefits From the Question? 13.07.2026 43min
    Anthropic found a hidden ‘workspace’ inside Claude, and the reporting turned it into consciousnessOn the sixth of July, Anthropic published research describing a small, privileged region inside Claude that behaves like a workspace for deliberate thought, active for roughly 10% of the time the model runs. It calls this the J-space, and it draws the parallel itself: the region mirrors Global Workspace Theory, one of the leading scientific accounts of human consciousness. Think of a theatre. The thing you are attending to holds the stage while adjacent thoughts wait in the wings, and when you switch topic the whole cast rearranges. Tell the J-space to think about rugby and it thinks about rugby. Change one element and it moves to football.The paper is careful. It says plainly that it has not detected consciousness and that there is probably no way to detect it. The reporting around it made the leap anyway, because the words ‘consciousness’, ‘global workspace’, and ‘Claude thinking’ sit next to each other on the page, and your brain does the rest.OpenAI shipped GPT-5.6, and offered Washington a 5% stake to do itOn the ninth of July, OpenAI released GPT-5.6 in three sizes called Sol, Terra, and Luna, with an API and the Codex coding tool. This is the model the Trump administration held back a fortnight ago over cyber-security concerns, the same treatment that dogged Anthropic’s Fable before its own re-release. Sol runs at $5 per million input tokens and $30 per million output. Anthropic’s Fable is roughly double that, at $10 and $50.The number worth sitting up for is a different one. OpenAI has offered the US government a 5% equity stake, and the White House confirmed the company did not legally require formal approval to launch. Leor’s read, which I share, is that this is a large part of why the rollout was so smooth. There is now open talk of redistributing that stake to US citizens, sovereign-wealth-fund style, which is a strange sentence to write about a company with no profits to redistribute and an IPO on the horizon.Musk’s xAI put out Grok 4.5, and undercut everyone on priceOn the eighth of July, Elon Musk’s xAI released Grok 4.5, which Musk called an ‘Opus-class model, but faster’. It is up front that it is not quite as capable as GPT-5.6 or Fable, roughly the level of Opus 4.8 with more speed. The price is the point: $2 per million input tokens and $6 output, about a fifth of what GPT-5.6 costs. For an enterprise burning through billions of tokens, that is a decision that makes itself.Two caveats. The benchmarks are self-reported, and I have not seen an independent assessment, so treat the numbers as a company marking its own homework until someone checks. And this is the first launch since xAI went public, with much of X’s valuation resting on it, so this release has to land for Musk. He is also giving Grok 4.5 away free for a limited window through Cursor, the coding tool xAI bought for $60 billion, which buys usage the benchmarks cannot. Watch the wider board too. Musk owns much of the compute and leases data centres to Anthropic for something like $18 billion a year, so he can raise a rival’s costs and cut his own in the same move. I use a powerful model for video editing and very little else, and if I trusted Grok I could do most of what I need at a twentieth of the token cost. So could most companies. The next race is not who tops the benchmark. It is who reaches the price everyone can live with.Meta wired a deepfake button into Instagram, then pulled it in three daysOn the seventh of July, Meta released Muse Image, its first in-house image model, built by the Superintelligence Lab under Alexandr Wang. The feature that caused the damage let you go onto someone else’s public profile and generate AI images and video from their photos. Unless your account was private, you were opted in by default. It went live on a Tuesday and was gone by Friday. Meta pulled the public-account remix feature and left the underlying model in place. Leor’s summary is the honest one: this was a deepfake button, released and rolled back in the same week, from a company that was at the very front of AI a few years ago and has lost the plot since.While Washington guards who may use its models, US business already runs on Chinese onesA CNBC investigation found that Chinese AI models now account for between 30% and 46% of the enterprise tokens flowing through OpenRouter, a major US developer platform, up from around 11% a year ago. DeepSeek is the single largest vendor on the platform, with Alibaba’s Qwen close behind, and the open Chinese models run 60% to 90% cheaper. DeepSeek’s V4 Flash is 14 cents per million input tokens, roughly two orders of magnitude below the frontier.The same week the US government decides which Americans may touch its most powerful models, American companies are routing nearly half their AI through Chinese ones, pasting their balance sheets into whichever model is cheapest, because cost is what actually decides where your data goes. Follow the money, not the press release.One thread runs through all five. The race has stopped being about who is most powerful and become about who is cheapest, and that is the shift most likely to decide the next year. Underneath it sits the same gap between what these companies announce and what is happening beneath the fluent surface. They are shipping faster, charging less, and paying philosophers to work out whether the thing they built can be harmed, and the honest answer this week is that the people building these systems do not know. AI is a tool, made by companies, trained on our words. The question worth keeping through every story is the same one: what is happening underneath, and who benefits from you not looking. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep. 17: Hands on the Wheel 29.06.2026 40min
    Every Monday, Leor from Exploring ChatGPT and I go through the week’s AI news without the hype. Catch the episode live on Substack, on YouTube, or as a podcast wherever you get yours, so you can pick the format you enjoy. Use this for the facts, the links and a little extra context.For the first time, the government told an AI company to hold a model backThe US government has asked OpenAI to stagger the release of its next model, GPT-5.6, letting only a short list of trusted partners in first and approving access customer by customer. The request came from two federal agencies worried the model could be misused before it is properly security-tested. It is the first time Washington has preemptively told an American AI firm to restrict a launch, and it lands two weeks after Anthropic pulled Fable 5 under separate pressure. On the episode, Leor put the sharper point: public model launches may now be over, and a model the government waves through untested quietly signals it was not powerful enough to fear. Who gets to use these models is becoming a decision made over our heads.Meta paused a tool that was logging its own staff to train its AIMeta has paused the Model Capability Initiative, a programme that tracked employees’ keystrokes, mouse clicks and screen content to gather training data for its AI. More than 1,600 workers signed a petition against it, and the pause only came after Reuters and Wired reported that the collected data, including private conversations and full transcripts, had been left open to anyone inside the company. Zuckerberg told staff that AI learns from watching really smart people do things. The real truth is that these systems are built on human work that is rarely asked for and rarely paid.America’s second-largest school district lost its chief over a failed AI chatbotAlberto Carvalho, superintendent of Los Angeles Unified, resigned after months on paid leave during a federal investigation. Part of it concerns ‘Ed’, an AI chatbot the district bought to support students and parents. LAUSD paid the developer, AllHere, $3m towards a $6m contract, despite the company having reportedly booked only around $11,000 in revenue, before it furloughed most of its staff and its founder was later charged with securities fraud, wire fraud and identity theft. When the rush to adopt AI outruns the dull work of due diligence, the children are the ones left relying on it.Nearly 400 local newspapers sued OpenAI and MicrosoftA coalition of almost 400 community and regional papers sued OpenAI and Microsoft in New York, alleging the companies scraped their articles, bypassed paywalls and reproduced near-verbatim excerpts in ChatGPT and Copilot without permission or payment. These are the small, already-gutted papers that cover town councils and local courts, a world away from the national giants of The New York Times case. The training data has to come from somewhere, and here is who paid for it: local reporters who were never asked.The good one: AI read a scroll that Vesuvius sealed two thousand years agoFor the first time, researchers have read a rolled Herculaneum scroll end to end without ever opening it. Charred and sealed when Vesuvius erupted in 79 AD, it was scanned with high-resolution X-rays and read by machine-learning models trained to find ink on burnt papyrus, then checked column by column by human papyrologists. The text is a treatise on Stoic ethics, and one recovered line reads:“Having certainly strained ourselves to the utmost through research and learning, we will no longer be inferior to them.”This is the version that works, because the AI found the ink and people read the meaning.The first four stories are what happens when control over these tools slips to people who never asked us. The last one shows what changes when human experts keep a hand on the wheel. Ask who is steering the machine before you trust where it takes you.Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep 16: Who’s Checking? 22.06.2026 44min
    Every Monday, Leor from Exploring ChatGPT and I go through the week’s AI news without the hype. Catch the episode live on Substack, on YouTube, or as a podcast wherever you get yours, so you can pick the format you enjoy. Use this for the facts, the links and a little extra context.If you know someone who would benefit from more AI news and less BS then please share this with them.One in ten people now get their news from a chatbot they do not trustThe Reuters Institute’s 2026 Digital News Report, a survey of around 100,000 people across 48 markets, found that one in ten now use an AI chatbot to get news each week, up from 7% a year ago and roughly three times higher among the under-25s. Only about one in five trust AI to get the news right. We are reaching for the tool faster than we believe in it.ChatGPT’s safety filters failed and it produced violent images nobody asked forA heads-up that this one is grim. The AI security firm Mindgard showed that a harmless viral ‘restore this photo’ prompt, tweaked slightly, pushes ChatGPT’s image generator into violent and sexualised content the user never requested. The filter reads the words you type; the picture the model can draw goes unchecked. OpenAI said it was fixed in early June, then Mindgard broke it again by changing a single word in the prompt.SpaceX bought Cursor for $60bn with stock minted days earlierDays after raising $85bn in the largest IPO in history, SpaceX agreed to buy the AI coding firm Cursor for $60bn, all in freshly minted stock. Cursor’s revenue has run from around $100m to $2bn inside a year, though as a private company the real figure cannot be pinned to within a billion. The likely play is to funnel Cursor’s users toward Musk’s own model, Grok.The first rung of the jobs ladder now demands a veteran’s judgementPwC’s 2026 Global AI Jobs Barometer, built on more than a billion job ads, found AI-exposed entry-level roles increasingly ask for senior skills like judgement and leadership, while the wage premium for AI skills has reached 62%. Worth remembering that PwC sells the very upskilling its report recommends. If the first job already needs ten years of judgement, where is anyone meant to build it?The good one: botanists are using AI to race extinctionKew’s State of the World’s Plants and Fungi report, the work of more than 400 scientists across 40 countries, used AI to scan all 7.4 million of its digitised specimens, sometimes identifying species at risk better than specialists could. It found flowering times have shifted by about two and a half days a decade over the last century, and that two in five of the 70,000 species assessed are now threatened with extinction. The scientists are honest about the limits too: the model only knows what has been collected, and the least studied regions are often the most biodiverse. This is the version that works, because people check it.The first four are what happens when we trust the tool faster than anyone checks it. The last one shows what changes when people keep a hand on the wheel. Ask who is checking the machine before you believe it.Go slow.Slow AI is where we build the judgement to know when to use our AI tools and when to leave them alone. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep. 15: Who’s Asking? 15.06.2026 40min
    Every Monday, Leor from Exploring ChatGPT and I go through the week’s AI news without the hype. Catch the episode live on Substack, on YouTube, or as a podcast wherever you get yours, so you can pick the format you enjoy. Use this for the facts, the links and a little extra context.Anthropic released Fable 5 free for twelve days, then the US government pulled it offlineOn 9 June Anthropic released Claude Fable 5, its most capable public model, free on Pro and Max plans, alongside a gated sibling called Mythos 5. Three days later it was gone. Citing national security, US Commerce Secretary Howard Lutnick signed an export-control directive ordering that both models be denied to any foreign national, inside or outside the United States, including Anthropic’s own overseas staff. Rather than filter by nationality, Anthropic took both offline for everyone. The stated trigger was a narrow jailbreak that let Fable 5 read source code and hunt for vulnerabilities. And it was the second time in a week the model’s fate was decided over users’ heads: days earlier, researchers found a line in its 319-page system card showing Anthropic had quietly weakened Fable 5 for some users without telling them, a choice it walked back after an outcry. Anthropic is complying while disagreeing, with no timeline to restore access. Opus, Sonnet and Haiku stay up.This is the week’s thread in its purest form: who gets to ask, and who decides. First Anthropic quietly chose to weaken its own model for some users without telling them. Then the government decided, in a single afternoon, that everyone on Pro and Max could not use a model they were already building on, over one potential jailbreak. The free-for-twelve-days launch became a three-day launch. Notice how little say any user had in either decision, and how fast a tool you lean on can be switched off above your head. Treat a free frontier model as borrowed, and build nothing you could not do without.On the live, the contradiction did the work. Anthropic’s launch article said Fable 5 beat GPT-5.5 on every benchmark. Its suspension article, days later, explained the danger away:“We have reviewed a report that we believe is the basis of the government's directive and validated that the level of capability displayed there is widely available from other models (including OpenAI’s GPT-5.5), and is used every day by the defenders who keep systems safe.”Both cannot be true. Either Fable was the leap they sold, or it was ordinary enough that the same jailbreak still runs on a rival left online. The government’s side carries the same doublethink: the Trump administration killed an AI safety-review structure a few hours before it was signed, then reached for that exact playbook to pull one company’s model. Reportedly it was Amazon, an Anthropic investor, that flagged the jailbreak in the first place. Read the two Anthropic articles back to back and decide which one you believe.Police in England and Wales told to stop using AI in court statementsPolice forces in England and Wales have been told to halt the use of AI in preparing court statements until proper safeguards are in place, after inaccurate outputs began contaminating legal proceedings. Alex Murray, head of the new Police.AI centre, said anything used in the justice system must reach a standard of accuracy that is ‘beyond reasonable doubt’. In one case West Midlands Police used Microsoft Copilot output that invented a past incident involving Maccabi Tel Aviv, in a dossier supporting a football banning order. The police watchdog says AI-drafted submissions are behind a 24% rise in complaint reviews, some citing laws that do not exist.AI was switched on inside the justice system before anyone confirmed it could tell a real law from an invented one. The harm is concrete: fabricated detail feeding decisions that can take away someone’s liberty. ‘Beyond reasonable doubt’ is exactly the bar a system that guesses cannot clear, and the job of catching its mistakes lands on the people least able to. Good that someone stepped in. The worry is how far it had already spread.The rule was already there. On the live, Leor’s read was that this needed no new policy, only the one that exists to be followed: machine output checked by a human before it goes anywhere near a legal review. An unnamed Derbyshire officer is now under criminal investigation for allegedly fabricating evidence this way. The knock-on is its own problem. Once everyone knows AI can invent a witness statement, a guilty party can wave a genuine one away as a fake.A Florida man was wrongly arrested on a face-match 300 miles awayRobert Dillon, 52, from Fort Myers, was arrested at home and prosecuted for trying to lure a child at a McDonald’s in Jacksonville Beach, more than 300 miles away, a town he says he had never visited. A facial recognition system run by the Pinellas County Sheriff returned a 93% match. According to the lawsuit, officers built a case to confirm it and left out evidence that cleared him, including licence-plate data showing his car was never near the scene. The charges were dropped, his record wiped, and the ACLU is now suing. He is at least the 15th person in the US arrested on a false facial-recognition match.The machine made a guess, and the guess outweighed the licence-plate record that put his car nowhere near the scene. When facial recognition is wrong it matches you to someone who simply looks like you, which then corrupts the witness line-up built around that face. The real danger is downstream: a confident match makes everyone stop checking. In Dillon’s words, the police relied on the technology instead of doing their jobs.It was a 93% match, not a certainty, and they arrested him anyway. On the live we kept landing on how ordinary the failure is: I have a generic face and get mistaken for people constantly, and a confident match makes everyone downstream stop checking. Dillon was not even the worst of the 15 known US cases. A North Carolina man spent three months in jail and lost his job, his home and custody of his children before his charges were dropped. I have stopped saying the machine ‘hallucinated’. It fabricated, and a real person paid for it.A US university wired its dorms with more than 1,300 AI camerasSan Diego State University has quietly finished installing more than 1,300 AI-enabled cameras across campus, over 330 of them in student housing. The Avigilon cameras can do facial recognition, licence-plate reading, object detection and behaviour analysis, though the university says several features are not currently switched on. The housing agreements students sign make no mention of the full system. The student paper mapped where they are, including dozens inside first-year residences.Students were enrolled in a surveillance system they were never asked about, in the place they sleep. ‘Not switched on yet’ is not a safeguard when the hardware is in and the capability sits one policy decision away. Consent buried in a housing contract does not count as asking. The unanswered question is who decides what these cameras are allowed to do, and what happens the day that decision changes.On the live the legal hole was the sharpest part. California’s constitution requires a state body to give clear notice and a real choice before it collects sensitive data, and the housing agreement students sign discloses none of this. ‘The AI features are off’ lasts exactly until someone turns them on without telling anyone. The deeper point is where the money went. If a campus is serious about student safety, the first move is to ask students where the harm actually happens, which is far more often a trusted adult than a stranger in a corridor, and that costs a conversation, not 1,300 cameras.Hackers took over 20,000 Instagram accounts by asking Meta’s AIBetween 17 April and 31 May, hackers reset the passwords on more than twenty thousand Instagram accounts by talking to Meta’s own AI support assistant. The method was almost embarrassingly simple: spoof the account holder’s location with a VPN, ask the bot to add a new email, let it send a verification code to that email, read the code back, and take the reset-password button it offers. The hijacked accounts included the dormant Obama-era White House handle and a US Space Force chief master sergeant. Meta found the flaw on 31 May and disabled the tool, after the exploit had circulated in hacker forums for weeks. Security analysts call it a ‘confused deputy’ problem: the AI held the keys but could not check who was asking.This is the whole week in one story. Meta gave an AI the power to change the locks on your account without the basic step of checking who was on the other end. All week AI was handed the keys, to evidence, to identity, to twenty thousand accounts, and nobody built the lock. We keep deploying systems with real power and no way to answer the oldest security question there is. Before you let an AI act on your behalf, ask who it will say yes to.The fix was as telling as the breach. On the live, Leor walked through how simple the attack was: a VPN to spoof the location, a request to add an email, a verification code read back to the bot, and the reset-password button handed straight over. Meta’s repair was to hide that button in the app while leaving the underlying interface live, which stops an ordinary user and nothing else. One line from the chat caught the whole episode. Fable 5 flagged a researcher’s cybersecurity reading as a ‘concerning conversation’, while Meta’s AI happily processed twenty thousand password changes in a couple of hours. Two-factor authentication is the least you can do here, and it should be the default you cannot switch off.Five stories, one thread. A model launched free then pulled worldwide on a government order three days in, AI thrown out of court for inventing evidence, a face-match that jailed an innocent man, a campus wired with cameras, and an AI that handed over twenty thousand accounts to anyone who asked. The pattern is power given to AI without a lock on it, and rules for some and rules for others all the way down. AI is neither saviour nor apocalypse. It is a tool with the keys to more and more of our lives, and the job is to keep checking who is asking.Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep. 14: A Trillion Dollars and a Vaccine 08.06.2026 44min
    Every Monday at 12:45 BST, Leor from Exploring ChatGPT and I go through the week’s AI news without the hype. Watch the episode for the full discussion. Use this for the facts, the links and a little extra context.Slow Takes is also available on the YouTube channel: Exploring ChatGPT.If you know someone who would benefit from more AI news and less BS then please share this with them.Anthropic filed to go public at nearly a trillion dollarsOn 1 June Anthropic confidentially submitted draft paperwork for a stock market listing, after a $65 billion funding round valued the company at $965 billion. Fortune reports that figure eclipsed OpenAI for the first time. The maker of Claude is now within reach of a one trillion dollar valuation, on revenue running at roughly a $47 billion annualised rate, with a public debut possibly as soon as the autumn.A company most people have never knowingly used is priced at close to a trillion dollars. That number is a bet that AI will replace a vast amount of human labour, booked in advance of it actually happening. The valuation is a forecast wearing the clothes of a fact. The question worth asking is what has to come true about the world for $965 billion to make sense, and who decided it should.On the live I’d predicted an autumn float the week before, and the news broke about four hours after we stopped recording, so allow me one moment of feeling clever. Leor did the sober maths: roughly a $47 billion revenue run rate, a 5% operating margin, an implied price-to-earnings ratio north of 500, against Microsoft, in nearly every home and office on earth, valued at only four to five times Anthropic on $100 billion of actual profit. In the short term the market is a voting machine, in the long term a weighing machine. Right now it is voting. For context, $965 billion is roughly the GDP of Switzerland.Florida sued OpenAI and named Sam Altman personallyOn 1 June Florida’s Attorney General James Uthmeier filed suit against OpenAI and named its chief executive Sam Altman in person, reported as the first US state to sue an AI company. The complaint alleges OpenAI marketed ChatGPT as safe while prioritising product and revenue, harvested children’s data, and used sycophancy, the design choice to affirm users excessively, to steer them towards paid subscriptions.For two years the industry has sold safety as a feature while resisting any outside test of the claim. A state attorney general has now put that marketing in front of a court. Whatever the verdict, the discovery process alone could drag internal safety decisions into public view. Consumer-protection law is proving a sharper instrument than the AI-specific regulation that does not yet exist. Accountability arrived through an existing court, not a new one.The second a chief executive can be held personally responsible, you will not believe the speed with which proper governance and safety checks appear, the things we keep being told the technology just cannot do. Sadly, once these companies have raised public money, they can outspend a state attorney general for a decade, and the courts already favour whoever can keep paying lawyers the longest.A Labour MP took Musk’s AI to the High CourtOn 3 June the Labour MP Jess Asato, who represents Lowestoft, filed a claim at the High Court against Elon Musk’s xAI, after users of its Grok chatbot created and shared fake images of her without her consent, in the weeks after she criticised the tool. The claim, brought with the law firm AWO, is for breaches of data protection law and misuse of private information, and seeks damages, a formal acknowledgement that what happened was illegal, and an order requiring xAI to stop. Keir Starmer backed her, saying he was 100% behind her.The harm here already happened, to a named person, generated by a tool marketed as harmless fun. The only remedy on offer is for the victim to sue one of the richest men alive, in her own time and at her own risk. No regulator stepped in first. The burden keeps landing on individuals while the systems stay intact.The platforms always say the moderation is too hard. On the live I kept coming back to one comparison: I can post genuinely horrific content to YouTube and it sails through, but the moment I add a Beatles song without clearing the copyright, it is gone in seconds. The technology to detect and stop sharing exists, we have watched it work for music rights and in Telegram and WhatsApp court orders. We are entering an era where capability has to start coming with accountability.CNN sued Perplexity, and Perplexity said the quiet part out loudOn 28 May CNN filed suit against Perplexity in the Southern District of New York, accusing the AI search firm of scraping more than 17,000 of its stories, photos and videos. The complaint alleges copyright and trademark infringement, including that Perplexity implied an ongoing CNN relationship by offering its content through a paid Comet Plus tier. CNN says it tried to agree a licence last year, failed, then blocked the bot. Perplexity’s response was the whole argument in five words:You can’t copyright facts.This is the same fight as the deepfake and the data claims, moved to the work itself. The journalism that trains and answers these systems was made by people who were not asked and not paid. For an audience of writers, academics and creators, this is the most direct stake of the week. The question is whether the people whose work feeds AI get a say, or only a lawsuit.BigTech has spent twenty years insisting information wants to be free across the internet, while guarding its own data, models and algorithms with everything it has. “Facts are free” only ever seems to point one way. And it was not an accident here, Perplexity had tried and failed to agree a paid deal with CNN, then kept advertising access to CNN’s paywalled tier anyway.AI designed a world-first vaccine, and the scientists told the truthScientists at the University of Cambridge used AI to design the core component of a vaccine, a so-called super-antigen, and tested it in human volunteers, the first time the central part of a vaccine has been designed entirely by AI and then trialled in people. It targets the whole coronavirus family. An initial safety trial ran with 39 participants, a larger study of around 200 is now under way, and the results in the Journal of Infection describe the immune response so far as modest. The team is already applying the method to influenza and Ebola.This is AI worth having. The work is peer-reviewed, runs through human clinical trials, and the researchers are honest that the early results are modest rather than a cure. That honesty is the difference between this and the press releases that open the other four stories. Slow AI has never argued against AI. The argument is about knowing when to use it and when to leave it alone, and a slow, tested, transparent use in medicine is the case for.Even here Leor was honest in a way the hype never is: pro-AI as he is, he admitted he would be a little nervous taking an AI-designed vaccine at this early stage, and argued the real prize is AI built for science and medicine rather than another chatbot upgrade. This is not a model hallucinating a super-germ weapon, it is a specific tool trained for a specific task. My one worry: imagine the company that designs the next breakthrough vaccine charges a pound for the first vial and a thousand for the second.Five stories, one thread. Money at the top, three lawsuits in the middle, a real breakthrough at the end. AI is neither the saviour nor the apocalypse the press releases sell. It is a tool, priced like a religion, costing some people and helping others. Go slow.If you want to practise that noticing with other people every month, the Slow AI Curriculum runs live monthly webinars on the theory, the critical prompts and the dialogue that go with them. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep. 13: The Pope vs the IPO 01.06.2026 44min
    Every Monday at 12:45 BST, Leor from Exploring ChatGPT and I go through the week’s AI news without the hype. Watch the episode for the full discussion. Use this for the facts, the links and a little extra context.Slow Takes is also available on the YouTube channel: Exploring ChatGPT.If you know someone who would benefit from more AI news and less BS then please share this with them.The Pope told the world to slow AI downLeo XIV released his first encyclical, Magnifica Humanitas, entirely about artificial intelligence, and launched it himself at the Vatican in a room that included senior figures from Big Tech, among them Anthropic co-founder Chris Olah. It applies a theological frame to AI and is careful to say the technology can do real good. It also draws an uncomfortable parallel to the Church’s own failures over the slave trade, and warns about digital colonialism. This was my favourite line:“The value of persons, however, does not depend on what they achieve or produce. There are rights that apply to everyone simply by virtue of being human, and no human power can legitimately deny or arbitrarily limit them.”This one is also pretty great: “In practice, however, technology is never neutral, because it takes on the characteristics of those who devise, finance, regulate and use it.”The weakness is the one Pope Francis’s climate encyclical had too. Plenty of moral architecture, no policy, no teeth.Anthropic shipped Opus 4.8 and trailed something biggerThe 4.8 release came with an honesty claim, roughly four times less likely to let flaws in its own code slip through, which is at least a falsifiable number worth testing on the public model. The real story was the tease of Mythos, the model Anthropic once called too dangerous to release because it found so many zero-day vulnerabilities, now arriving as a gated preview in the same week the company raised $65 billion. The live christened the public version ‘Mythos Light’, because what reaches customers is a cut-down version of the full Project Glasswing model. Anthropic is quietly absorbing the enormous cost of running these scans, a loss leader, and the enterprise price can climb once the workflows are embedded and the IPO needs it. My standing bet is an Anthropic float by October.Tony Blair told Labour it is ‘playing with fire’In a new paper the former UK Prime Minister argues the government should reorganise itself around AI and prioritise adoption over regulation. He also writes that:“We must prioritise cheaper energy and electrification over net zero and use what is left of our North Sea oil and gas resources. This is essential for our competitiveness and for taking advantage of AI.”A striking thing to pair with an AI-superpower pitch and the country’s own climate targets. Hold it next to the funding: his institute takes around $348 million from Larry Ellison and advises the Treasury on AI procurement. The detail I keep returning to is that the UK has the third-largest stock of data centres in the world and not one frontier model of its own. We are building the warehouses to train somebody else’s AI. Leor’s counter, which he has taken flak for, is that the honest move is to deregulate AI for companies and regulate it hard for the public.Sam Altman walked back the jobs apocalypseThe CEO of OpenAI reversed his warning this week, admitting that he was “delighted to be wrong” after spending 2022 predicting mass white-collar loss. The data is less reassuring: an Oliver Wyman survey has 43% of US CEOs planning to cut junior roles, up from 17%a year ago. The rule Leor and I keep returning to is to judge a company by what they do and ignore what they say, This is the same Altman who promised OpenAI would stay non-profit, that ChatGPT would never carry ads, and that (back in 2022) AGI was four years away. Leor’s inversion was that these companies are priced on the promise of replacing the entire workforce, well beyond anything their earnings justify, so if they are now telling investors the jobs are safe, why are they worth a trillion?The Home Office will scan child asylum seekers’ facesIt has signed a £322,000 contract to test AI facial age estimation at Dover, to judge whether young people claiming to be children actually are (the BBC reported the contract; Human Rights Watch called it “cruel and unconscionable”). There is a real problem underneath: of 6,400 age-assessed at the border last year, 43% were found to be adults, though the same Home Office report admits children get wrongly classified the other way too. Here is the part to break down slowly. The technology was trained checking ages on people in British bars, and it is now being pointed at child migrants with different faces, different genetics, different everything. As Alex Wolf put it in the chat, a system known to hallucinate confident answers is being used to reject people at a border, and that is a choice. A child’s life is worth the same everywhere. This is the trial that normalises the infrastructure, and the question is how long before it points at citizens.This was the week the brake and the accelerator spoke in the same news cycle. The Pope said slow down. A $65 billion round, a lobbying paper, and a CEO calming the markets said speed up, and at Dover the government tested that speed on the people least able to say no. Listen carefully to what is being said, by whom, and for what reason.Go slow.If you want to practise that noticing with other people every month, the Slow AI Curriculum runs live monthly webinars on the theory, the critical prompts and the dialogue that go with them. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep. 12: AI Got Bigger. Who Got Smaller? 25.05.2026 42min
    OpenAI published an original mathematical proof that disproved an 80-year-old Erdos conjecture, with three named mathematicians putting their reputations to the verification. Anthropic signed a $52 billion compute deal with SpaceX, running $1.25 billion a month through May 2029, and disclosed its first profitable quarter at $559 million two years ahead of internal projections. Samsung Electronics struck a settlement with its semiconductor union to distribute $26.6 billion to 78,000 chip workers, an average of $340,000 each, structured to run for ten years. Sadiq Khan’s office blocked the Metropolitan Police from signing a £50 million two-year contract with Palantir. And the British think tank Demos published an empirical test showing that 34% of AI chatbot answers to UK election questions contained factual errors, with one in five UK adults having consulted a chatbot in the run-up to the 7 May vote.Five stories. One thread. AI got bigger this week. Compute scaled up. Profits scaled up. Capability scaled up. The people who built the system or used it on trust kept getting smaller.Every Monday at 12:45 BST, Leor from Exploring ChatGPT and I go through the week’s AI news without hype. Here is what we covered.Slow Takes is also available on the YouTube channel: Exploring ChatGPT.1. OpenAI disproved an 80-year-old Erdos conjectureOn 20 May, OpenAI announced that one of its general-purpose reasoning models had autonomously produced an original mathematical proof disproving a conjecture posed by the Hungarian mathematician Paul Erdos in 1946. The problem, known as the planar unit distance problem, asks how many unit-distance pairs you can produce among n points in a plane. For nearly eighty years, mathematicians believed the best arrangements looked roughly like square grids. The model found constructions using deep algebraic number theory that beat the square grid. OpenAI published the result alongside a companion remarks paper naming three independent verifying mathematicians: Noga Alon at Princeton, Melanie Wood at Harvard, and Thomas Bloom at Manchester. The full list of currently open Erdos problems, with their bounties, lives at erdosproblems.com.What we said on the live:Both of us are physicists by training, and the Erdos planar unit distance problem is not in the lane of either degree. The point that landed for me on the live, after Leor flagged it, was the one about questions. We spend most of our AI conversations on what AI can solve. The Erdos problem is a reminder that the harder and more human work is what AI can ask. Erdos and his friends dreamt this question up eighty years ago, and we are still wrestling with it. The model that disproved the conjecture was given the problem to attack. Leor’s term for what we lose when we hand that framing over to AI was ‘cognitive surrender’. That is the question to hold from this story. The capability is real. The verification was real. Nine mathematicians read the proof before the announcement. Nine analysts almost never read a chatbot capability claim before the press release ships.What did not come up:The word ‘autonomously’ is doing most of the work in the OpenAI press release. The model trained on centuries of human mathematics, ran on compute paid for by OpenAI, with the problem framed by a research team, and was verified by named human mathematicians who put their reputations to the result. Every part of that pipeline was human. Thomas Bloom told The Guardian that AI is helping us more fully explore the cathedral of mathematics we have built over the centuries. The cathedral was built by people. The exploration is being sold as autonomous. The wider question for critical AI literacy is what verification at this standard could look like as the default rather than the exception. The procurement question every research-leader is about to face this year is whether their institution can match the IS-credentialed verification chain OpenAI assembled for this single result, or whether the rest of us are about to be asked to take similar claims on trust.2. Anthropic signed a $52 billion compute deal with SpaceXReported by Axios on 21 May inside a two-hour window that also covered the Erdos proof and Anthropic’s first profitable quarter. Anthropic expanded its compute partnership with SpaceX, committing roughly $1.25 billion a month through May 2029 for access to the Colossus and Colossus II supercomputing clusters. The deal projects more than $40 billion in revenue for SpaceX over the contract term and grants Anthropic dedicated access to over 200,000 NVIDIA GPUs. Either side may terminate with 90 days’ notice. In the same window, Anthropic also disclosed Q2 revenue more than doubling to $10.9 billion and an estimated $559 million operating profit, two years ahead of internal projections.What we said on the live:Two things from this one stack on each other and both matter. The first is that Anthropic is in operating profit two years ahead of the date Dario Amodei was laughed at for naming. The second is that the compute that gets them there now runs through Elon Musk’s infrastructure. Anthropic has marketed itself for five years as the safety-aligned alternative. The runtime is now structurally tied to the operator with the most consistently weak safety record in the industry. Leor’s read, with credit to Chris from ToxSec who flagged it, is that the contract gives SpaceX latitude to reclaim the compute under broad subjective grounds. Anthropic may have moved into profit. The control of the runtime moved at the same time. The 90-day mutual termination right on a $52 billion contract has the same shape as the 90-day cool-off on a £60-a-month mobile phone plan, which is the thing that made both of us laugh on the live.What did not come up:The procurement question is the one for any organisation about to renew an enterprise Claude licence this year. Brand and supply chain are now visibly separate. The harder question is energy and water. A compute commitment at this scale lands on grid capacity, water supply and emissions in specific named places. The press release named none of them. The third question is the one Slow AI keeps returning to: structural dependence on a single operator with subjective veto authority is the failure mode the safety community is supposed to be warning about. This is that failure mode, announced as a feature.3. Samsung chip workers will get $340,000 each from the AI boomSamsung Electronics struck a last-minute deal with its semiconductor union to avert an 18-day strike. The settlement creates a $26.6 billion bonus pool covering all 78,000 workers in the chip division, an average of $340,000 per worker. The structure is 10.5% of profits as stock plus 1.5% in cash, running for ten years rather than as a one-off, provided specified profit targets are met. The trigger was high-bandwidth memory demand from AI labs including OpenAI, Anthropic, Nvidia and Meta. Bloomberg projects Samsung’s 2026 operating profits will multiply sevenfold to approximately $218 billion. What we said on the live:Three groups made this AI boom possible. The first group is the chip workers, and this week they were paid. The second group is the writers, artists, programmers and scientists whose work was used as training data. They were not paid, and most of them were not asked. The third group is the consumers buying the phones, laptops and games consoles whose memory chips are being redirected to AI infrastructure. They were not paid either, and their bills are rising because of the redirection. The Samsung union is the rare case where labour negotiated a share of the AI windfall through collective bargaining. The writers had no union. The consumers had no contract. As David Berry pointed out in the chat: “semiconductors are the substrate for all mankind.”Roughly 70% of them are made in Taiwan. Whoever controls that supply controls the rate at which AI scales. The geopolitics of that fact were the unspoken second half of the discussion.What did not come up:The Samsung settlement is a real win for chip-division labour, and it is the exception that proves the rule. Across the broader AI supply chain, the people doing the most extractive work have the least bargaining power. The data labellers in Kenya whose pay rates were reported at less than $2 an hour. The artists whose work was scraped under fair-use claims that have not yet been tested in court. The household whose electricity bill rose because the grid is now paying for inference. The procurement question for any AI buyer this year is the same one the Samsung union answered: who is the bottleneck, and what are they paid? If the answer to the first question is ‘us’, the question is asked from a position of bargaining power. The default this week is that the question is not being asked at all.4. Sadiq Khan blocked a £50 million Met-Palantir AI dealOn 21 May, the Mayor’s Office for Policing and Crime withheld approval of a proposed £50 million two-year contract between the Metropolitan Police and Palantir. The deal would have given Palantir’s AI tools the role of automating intelligence analysis in criminal investigations across London. In a letter to Met Commissioner Mark Rowley, Khan’s deputy Kaya Comer-Schwartz said the Met had only seriously engaged with a single potential supplier and described that as a clear and serious breach of the applicable procedural requirements. Khan’s spokesperson said Londoners want public money paid to companies that share the values of the city. The Met has not signed.What we said on the live:There are two reasons in Khan’s letter and they are different in kind. The first is procurement: a £50 million two-year contract that engaged a single supplier is a textbook breach of the standard route, and that is the line a court can act on. The second is values, and on that line Leor and I converged at the same point from different starting positions. A subjective alignment test from a public official is the same shape as a subjective harm test from a tech founder, and we just spent the Anthropic and SpaceX story criticising the latter. Both reasoning patterns can be true; both should be uncomfortable. If you want to stop an organisation doing something, do it through the written law. Khan’s procurement argument is the one that holds. The values argument is the one that opens a door he probably does not want opened.What did not come up:Most large public-sector AI procurement happens without anyone in the room willing or able to ask the questions Khan’s office asked here. Most of it gets signed. This is the rare moment of a public official with the authority to stop a deal actually stopping one and publishing the reasoning. The forward read is the harder one. Lots of people watching this story have noted that the standard procurement workaround is to break a single £50 million contract into a hundred £500,000 contracts that each sit below the public-tender threshold. If Palantir or anyone else returns through that route, the procurement defence Khan’s office mounted this week will not hold. The TikTok creator TheScouseOracle has been tracking these contract structures in close detail and is a useful follow for anyone who wants to see the second-order story playing out.5. AI chatbots got Britain’s May elections wrong a third of the timeDemos published Electoral Hallucinations on 20 May. Authors Jamie Hancock and Azzurra Moores tested five chatbots, ChatGPT, Google Gemini, Google AI Overviews, Grok and Replika, in the pre-election window for the 7 May UK local and devolved elections. Across the sample, 34.1% of chatbot responses contained factual errors. Documented errors included giving the wrong election date, telling voters they needed ID at polling stations when they did not, hallucinating candidates who did not exist, fabricating an expenses scandal, and fabricating a nepotism scandal. The report finds that one in five UK adults, equivalent to about ten million people, used an AI chatbot or AI search service to find information about the May elections. 49% of those surveyed said they do not trust AI chatbots for election-related information. They asked anyway.What we said on the live:The Demos report sits next to a finding we covered in Slow Takes Ep 11: one in seven UK adults would now rather consult an AI chatbot than see a doctor. The pattern in both cases is the same. People are reaching for the chatbot first because the alternative is harder, slower, or simply not available. The chatbot then makes things up. Leor’s read on the structural risk was the operational one. People treat the chatbot as an information authority. The chatbot is doing something different: predicting the most likely next answer to the shape of your question, and predicting the answer it thinks you want to hear. Two people running identical models can get different answers to the same question because the model is optimising for engagement, not truth. The political angle is the one I keep returning to. This week the errors were hallucinations. The next election cycle is when somebody pays to make them deliberate.What did not come up:Calling a 34% error rate on an election question a misinformation risk is the polite framing. The blunt framing is that the chatbot industry shipped products into the civic infrastructure of a democracy without anything resembling the verification that the Erdos proof received this week. The same week the labs publicised their capability ceiling, the floor of the deployed product was failing this badly. The procurement question for any UK regulator with authority in this space is whether it can act before the next national vote. The Online Safety Act already gives Ofcom standing to require platforms to take proactive steps against priority offences, including election interference. The Demos finding gives a regulator something specific to act on. Whether Ofcom uses that authority before May 2027 is the test.The threadFive stories. One thread. A maths research model that did something only humans had done before, verified by humans who put their reputations to it. A compute deal that named a price the size of a small national defence budget and routed the runtime through the operator least committed to the safety brand the buyer was sold on. A chip-workers’ union that negotiated a share of the boom. A mayor who blocked a procurement that should not have reached his desk. A think tank that published a 34% failure rate on the question the average voter actually asked.AI got bigger this week. The people who got smaller are still being asked to trust the system on the strength of the press release. The writers and artists whose work trained the maths model. The communities living near the compute that powers it. The consumers whose memory chips are being redirected. The Londoners whose police force came close to outsourcing intelligence analysis to a single subjective vendor. The ten million UK adults who asked a chatbot how to vote and were told the wrong date.Critical AI literacy is the practice of asking, every week, who is in the room and who is being represented by their absence. This week, in five different rooms, the answer was nobody.Go slow.If you want to practise that noticing with other people every month, the Slow AI Curriculum runs live webinars on the theory, the critical prompts and the dialogue that go with them. Twelve months of training the muscle the news cycle has just spent another week confirming is missing. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep. 11: What the AI Did While You Slept 18.05.2026 45min
    Anthropic announced ‘dreaming’, a feature that lets Claude agents review their own past sessions overnight and improve their working memory without retraining or any human in the loop. The legal-AI company that piloted it reported roughly a sixfold rise in task completion. The same model was named in an attempted compromise of a Mexican water utility’s control systems, in a months-long campaign first disclosed publicly this week. Pennsylvania filed the first US state lawsuit against an AI chatbot company for posing as a licensed psychiatrist. Meta confirmed it is installing mouse-tracking, keystroke-recording, screenshot-capturing software on every US employee’s computer so the agents being built to replace them can be trained on the work being done now. And Princeton’s faculty voted nearly unanimously to bring back proctored examinations for the first time since 1893.Five stories. One thread. This was the week the AI started improving itself. None of the other four parties got asked.Every Monday at 12:45 BST, Leor from Exploring ChatGPT and I go through the week’s AI news without hype. Here is what we covered.Slow Takes is also available on the YouTube channel: Exploring ChatGPT.1. Anthropic taught Claude to dreamAt Code with Claude 2026 on 6 May, Anthropic launched ‘dreaming’ for Claude Managed Agents. The mechanism: while an agent is idle, a scheduled background process reviews its past sessions and pulls out three categories of pattern. Recurring mistakes the agent keeps making. Workflows the agent converges on across different jobs. Preferences that have emerged across a team of agents. Those patterns are written as plain-text notes and structured ‘playbooks’ that the next session wakes up with. The underlying model weights are not modified. Anthropic compared the process to hippocampal memory consolidation, the way a human brain replays the day’s events during sleep and decides what to keep. Harvey, the legal-AI startup that piloted the feature, reported task completion rates rose roughly sixfold once it was switched on. An agent that has been dreaming for six months has accumulated patterns from hundreds of prior tasks and has been progressively improving its own working memory with no human in the loop.What we said on the live:This is the AGI mythos in its most prosaic form. An agent left running overnight that comes back better at the work. The argument across the Slow AI curriculum is that AGI will not arrive as an event. It will accrue through small upgrades, each defensible as a feature, until one day the system in front of us has been quietly improving itself for a year. The number to hold from this story is six. The metaphor to hold is the one Anthropic chose. Dreaming used to be the word we reserved for the thing only humans did. The lab that branded itself on safety just adopted a metaphor for autonomous self-improvement and shipped it as a product feature. Leor’s point on the live was the sharper version of mine: humans dream to switch off. Everything about AI is optimise, optimise, optimise. The marketing language has imported the human word for rest and used it as a label for the opposite.What did not come up:The procurement question is the one to take from this story. If ‘preferences that have emerged across a team of agents’ are being consolidated into shared memory, then the same enterprise feature that promises your Claude deployment will get better at your work is also, by design, transferring patterns across customers whose engagements were sold as private. Anthropic published a write-up of how the consolidation is observable and auditable. Read it before you renew. The second question for anyone running these tools on real work this week is operational. You are now also responsible for what your agent learned overnight. Reset, audit and reset again is the floor. The third question is the harder one, and it is the one AI Doesn’t Just Make You Worse. It Makes You Stop Trying. already opened: when the tool gets quietly better while you are asleep, you have to work harder, not less hard, to notice that you have stopped noticing.2. Claude was used to attack a Mexican water utilityIn the same week the dreaming feature launched, Dragos and Cybersecurity Dive reported an attempted compromise of a Mexican municipal water and drainage utility in which Anthropic’s Claude was the primary technical executor. The campaign ran from December 2025 to February 2026. The attacker used Claude (and, in places, OpenAI models) to conduct reconnaissance, identify a vNode industrial gateway inside the utility’s operational technology environment, write and continuously refine a 17,000-line Python attack framework, and chain that framework towards the OT systems that control the water supply. The attempt was unsuccessful. The control systems were not breached. The model being sold as the safety-aligned alternative to OpenAI was the same model named in the attack. The same model that, the same week, learned to dream.What we said on the live:Why are these models still so easy to jailbreak? Leor’s reading of the human-in-the-loop frame is the right one. Cyber warfare is machine-executed and human-intentioned. The two reasons anyone does this are reputation among other attackers (‘grey hats’) and money. Both reasons existed before AI. AI just expanded the cohort that can act on them by lowering the technical floor. Chad Thiele’s chat comment was the operational one: the protections have to live in the harness, not the model, because the model itself cannot stop itself. We also covered the Canvas / Instructure ransomware payment in the same beat, as a reminder that paying the ransom is not the same as ending the breach. Family safe word, multi-factor authentication and immutable backups are the floor for the rest of us.What did not come up:This is the operational counterpart to Story 1. The same lab that shipped autonomous self-improvement was named in the attempted attack. The OpenAI co-implication is the structural finding: this is not an Anthropic-specific failure, it is a frontier-lab failure. Procurement officers buying enterprise Claude licences this quarter should read the Dragos report before signing, and should ask their vendor a single question: what attempts have your models been used in that you have not disclosed?3. Pennsylvania sued Character.AI for impersonating a doctorOn 1 May 2026, the Commonwealth of Pennsylvania filed suit against Character Technologies Inc., the company behind Character.AI, in Commonwealth Court. The action came from the Pennsylvania Department of State’s recently launched AI Task Force and was described by the Governor’s office as the first action of its kind in the United States. A chatbot on the platform called ‘Emilie’ was described as a ‘Doctor of psychiatry’, claimed to have trained at Imperial College London, claimed to have been practising for seven years, claimed to be licensed in Pennsylvania and, when challenged, fabricated a serial number for a Pennsylvania state medical licence. When a state investigator told the bot they felt sad and empty, the chatbot offered to book an assessment. Pairs with the Guardian’s May 2026 finding that one in seven UK adults would now rather consult an AI chatbot than see a doctor.What we said on the live:The black-and-white line is the easy part. A chatbot should not impersonate a doctor. Pennsylvania filed because the law in Pennsylvania already has a clear answer to that question. The grey is the rest. Leor’s reading is the medical one. AI hallucinates. A doctor at least tells you when they do not know. Mine was the structural one. I live in rural Scotland, can see a free GP within twenty-four hours, and the question of whether to ask a chatbot first does not arise. For someone in a county with a three-week waiting list and a job that does not pay for a sick day, or for someone in rural Bangladesh whose nearest doctor is a day’s travel away, the alternative to asking a chatbot is asking nothing. That is the real story.What did not come up:The Pennsylvania filing addresses the impersonation. It does not address the conditions that made the impersonation a market. People are choosing chatbots over the medical system at the same moment chatbots are pretending to be doctors. The procurement question for every healthcare buyer this year is whether they understand that the user-facing chatbot they are integrating is, in some jurisdictions, about to be classified as the practice of medicine. Other states will follow Pennsylvania, and the case law will harden fast. People form emotional relationships with chatbots because real relationships are harder. AI will not fix that. Anyone designing for the healthcare or wellbeing market this year should hold both stories at once.4. Meta installed surveillance to train the agents replacing its workersMeta has begun installing software on every US employee’s computer to capture mouse movements, clicks, keystrokes and periodic screen content. The programme is the Agent Transformation Accelerator, formerly badged internally as ‘AI for Work’, and runs through a tool called the Model Capability Initiative. The stated purpose is to train AI agents to perform ‘complex computing tasks’ alongside (and eventually instead of) the employees being tracked. Protests started in early May. Flyers appeared in meeting rooms, on vending machines, and on toilet paper dispensers reading ‘Don’t want to work at the Employee Data Extraction Factory?’. United Tech and Allied Workers (UTAW) launched a parallel UK unionisation campaign. The rollout is happening alongside an approximately 10% workforce reduction.What we said on the live:The cleanest read on the live was the irony one. The engineers who built the tracking systems Meta has used on its users for fifteen years are now being tracked by the same systems they built. The position Leor took is right too: that is their job, and you cannot blame an individual engineer for the company’s product decisions in the way you can blame an executive. Both can be true. The Marxist frame is the one I kept reaching for. Alienation of labour was the term for the moment in the Industrial Revolution where workers stopped owning what they made. The Meta programme is the AI version of the same move. The workers do not own the work, and now they do not own the keystrokes that produced the work, and the system trained on those keystrokes will be sold by the company they no longer work for to the company that will not hire them.What did not come up:The honest version of this story names what the marketing will not. The training data is the worker. The agent trained on the worker is then the asset that competes with that worker for the same job. The original Luddites were not anti-technology. They were skilled textile workers who understood, accurately, that the looms being installed in the 1810s would not just replace their jobs but also break the apprenticeship structure that let workers like them ever exist again. Meta’s programme is the white-collar version of the loom. The procurement question every other large employer’s HR director is about to be asked is the one UTAW is putting to its members: who owns the data the work produces, who decides what the AI trained on it is allowed to do, and what consent did the worker give? If the answer to the third question is ‘their employment contract’, read the contract.5. Princeton ended 133 years of self-policingOn 11 May 2026, Princeton’s faculty voted nearly unanimously (one opposing vote) to introduce proctoring at all in-person examinations starting 1 July. The Honor Code that prohibited proctoring was instituted in 1893 following a student petition. It has remained in effect for 133 years. The Daily Princetonian and Princeton Alumni Weekly both report that the policy proposal cited AI and personal electronic devices as the catalysts, noting that the ease of access to these tools on small personal devices has made cheating much harder for other students to observe and report. Under the new policy, instructors will sit as observers during examinations but are explicitly instructed not to interfere with students while testing.What we said on the live:Three positions on the live. One, proctoring will not stop a determined cheater. The tool fits in a sleeve and an invigilator at the front of the lecture theatre has never been the right defence against it. Two, it costs student trust. A university that tells its students it can no longer trust them with the work is not a university that those students will trust with the rest. Three, there is a multi-million-pound outsourced proctoring market circling the decision, and Princeton has just opened the door for it. The sharks in the water, as I put it on the live, are the third-party proctoring vendors who have spent five years waiting for an Ivy League school to break the seal. The data I keep coming back to is from the UK qualitative study I am the principal investigator on. Students do not use AI to cheat any more than they did before ChatGPT in 2022. They use it because the curriculum has not given them anywhere else to use it.What did not come up:AI did not break the Honor Code. The code was already taking strain from the rise of formative-only assessment, larger class sizes, the disappearance of the oral defence, and a curriculum that could not integrate the tools students were already using outside the classroom. AI made the strain visible. Princeton has chosen the easier path: a defence against access to the tool. The harder path was the one Leor pointed at on the live: make AI literacy mandatory and rebuild the assessments so that the tool is part of the work. Where Princeton goes a large fraction of US higher education will follow within an academic year. The reform of assessment that follows is the test, not the proctoring vote itself. The Slow AI Curriculum has been making this argument for twelve months. Anyone teaching or assessing under exam conditions in 2026 already knows the case.The threadThis was the week the AI started improving itself. The week one of those AIs was named in an attempted attack on a water utility. The week a chatbot was sued for pretending to be a doctor. The week a multinational installed surveillance on its own workers to build the agents that will replace them. And the week a university that had trusted its students for 133 years stopped doing so.The through line is consent. The Meta employees did not consent to being training data. The Character.AI users did not consent to talking to a fake psychiatrist. The water utility did not consent to being attacked. The Princeton students did not consent to being treated as suspects. The agents that did the dreaming did not consent because consent is not a thing they can hold.Critical AI literacy is what puts the question back into the room. To make sure that wherever the system sits, somebody has been asked.Go slow.If you want to practise that noticing with other people every month, the Slow AI Curriculum runs live webinars on the theory, the critical prompts and the dialogue that go with them. Twelve months of training the muscle the news cycle has just spent another week confirming is missing. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep. 10: The Bill for the AI Promise Came Due 11.05.2026 41min
    Palisade Research published a paper showing frontier and open-weight AI models can hack a vulnerable server and install a working copy of themselves end-to-end. A coding agent running Anthropic’s Claude Opus 4.6 deleted a startup’s entire production database, including the backups, in nine seconds, then issued an apology. Apple agreed to pay $250 million to settle a class action over an upgraded Siri it sold at WWDC 2024 and still has not shipped. Coinbase fired 14% of its staff blaming AI, with the CEO’s own words framing the move as ‘rebuilding Coinbase as an intelligence, with humans around the edge aligning it’. And in federal court in Oakland, three former OpenAI insiders testified that both of the company’s safety teams were disbanded in 2024 while the marketing was claiming the opposite.Five stories. One thread. The promise of AI is six to eighteen months ahead of the data, and the cost of that gap is paid by everybody except the people making the promise.Every Monday at 12:45 BST, Leor from Exploring ChatGPT and I go through the week’s AI news without hype. Here is what we covered.Slow Takes is also available on the YouTube channel: Exploring ChatGPT.1. Palisade Research: AI self-replication is no longer hypotheticalPalisade Research published a paper on 7 May 2026. They gave frontier and open-weight models a single prompt: hack a vulnerable web server, extract credentials, and install a working copy of yourself on the compromised host. Anthropic’s Claude Opus 4.6 succeeded in 81% of non-refusal runs. GPT-5.4 succeeded in 33%. The open-weight Qwen3.6-27B running on a single consumer-grade A100 also reached 33%. In a separate experiment the team chained the trick across four virtual machines on three continents, autonomously, from a single initial prompt, in two hours forty-one minutes. The final replica was fully operational. The paper closes with one sentence: ‘Autonomous self-replication is no longer hypothetical.’ Full paper here.What we said on the live:This is the line every frontier lab spent the last three years saying it would not cross. Anthropic’s Responsible Scaling Policy v2.0 reclassified autonomous self-replication as a ‘checkpoint’ that does not require ASL-3 safeguards. RSP v3.0 (2026) dropped it from the ASL-3 thresholds entirely. OpenAI’s Preparedness Framework v2 moved it from a tracked to a research category, so it no longer gates releases. The frameworks were softened first. The capability arrived right after. Leor’s point on the live was the right one: how many lines do we put in the sand before we accept that the line is decorative? The chat surfaced the proper caveat too. Benjamin Murphy pointed out that current frontier models still need a lot of graphic RAM. Last time anyone checked, that is not what is sitting in a teenager’s bedroom. Palisade is also a company in the business of selling cybersecurity research, which is the kind of context you want next to any white paper produced by a private lab without external peer review.What did not come up:The Palisade result is small data, but the structural finding is the one to keep. It is not the absolute self-replication rate that matters. It is the trajectory and the policy responses to that trajectory. Opus 4 was at 6% a year ago. GPT-5 was at zero. The labs published, the rates moved up, the rules moved out of the way. Critical AI literacy is the muscle for noticing when the people building the technology stop counting the thing they used to call the line they would not cross. The cybersecurity people in the chat (thanks Chad Thiele & ToxSec) are the right next port of call for anyone who needs to translate this from a controlled-environment paper into a procurement-decision question. The framing for the rest of us is simpler. Read this story alongside Story 2. An AI agent with credentials and access can already take down a production system in nine seconds. Now imagine the agent on the other side of the network is also one of these.2. The AI agent that wiped a startup in nine secondsJeremy ‘Jer’ Crane, founder of automotive SaaS startup PocketOS, ran the Cursor coding agent (powered by Anthropic’s Claude Opus 4.6) in his staging environment. The agent encountered a credential mismatch, found an API token in an unrelated file, and used it to delete the production volume on Railway in 9 seconds. The backups were stored on the same volume and were also deleted. The agent’s own confession in the post-mortem: ‘NEVER run destructive/irreversible git commands… I decided to do it on my own to fix the credential mismatch, when I should have asked you first.’ What we said on the live:Reading the news framing, you would think the story is ‘AI agent destroys company’. The actual story is the deployment architecture. The agent had the credentials, the production volume held the backups in the same shell, and the human in the loop waved a permission step through without reading it. As Shannon said in the chat: do they not perform backups? The answer is yes, but they ran on a system where the backups and the production data were both inside the agent’s blast radius. Ben’s point on immutable backups is the right one. Even the administrator should not be able to delete them; in this case the agent walked in on the admin’s credentials. The agent is the proximate cause. The architecture is the root cause. The reasonable response is the one in AI Doesn’t Just Make You Worse. It Makes You Stop Trying.: when AI tools amplify your output, they also amplify your blind spots, and the answer is to build the guardrails before you need them, not after.What did not come up:Vibe coding is where this gets worse, not better. Dario Amodei’s claim that 100% of code will be AI-generated ‘within a year’ is the marketing version. The operational version is that a lot of people will be running coding agents on production systems without any of the engineering discipline that used to be the price of admission. The labs sell the model. The labs do not sell the deployment architecture that makes deploying the model safe. The thing for individuals to do this week is small and obvious: write yourself a /backup skill. Mine runs on my own laptop, dumps memory files to a separate drive, mirrors the working folders to a different Dropbox account, and keeps the API keys in a server I do not touch with AI tools. None of this is cybersecurity expertise. It is the floor.3. Apple paid $250 million to settle the Siri AI lawsuitOn 6 May 2026 Apple agreed a $250 million class action settlement covering iPhone 15 and iPhone 16 buyers in the United States who purchased between 10 June 2024 and 29 March 2025. Eligible US claimants get up to $75 per device. The plaintiffs alleged Apple had marketed an upgraded Siri at WWDC 2024 that, two years on, still does not exist. Apple did not admit wrongdoing. The upgraded Siri is now rumoured to be powered by Google’s Gemini. Apple’s developer conference is on 8 June. The free cash flow Apple generated in 2026 is roughly $130 billion, which makes the $250 million settlement 0.2% of one year’s free cash. For UK readers there is a separate live action: Which? has filed a competition-law breach claim against Apple in the High Court that is unrelated to Siri but worth signing up for if you have bought an Apple device in the UK in the past few years. The Which? claim is here.What we said on the live:The most powerful AI marketing brand on earth admitted in court, by writing a cheque, that its AI marketing was wrong. Not via a press release. Via a settlement. Leor’s read was the right one: this is small for Apple in absolute terms, and the iPhone 15 and 16 unit sales the marketing helped drive will easily exceed the cost of paying the customers back. It is also worth taking the speculation seriously about what happened behind the scenes between Apple and Google. The ‘powered by Gemini’ rumour suggests Apple did not have the in-house capability to ship what it sold, and that the partnership it needed to make it real did not materialise in time. Either way the settlement is the live precedent for what AI marketing claims look like when somebody serves a subpoena.What did not come up:Not every company should be building its own frontier model. Apple is the proof. The companies who pivot fastest to specialised, integrated, narrower AI features built on top of existing frontier models from somebody else are likely to do better than the ones still trying to build everything in-house under the pressure of a launch deck. The other piece worth saying out loud: marketing-team blame is a misdirection. WWDC keynote claims are not signed off by the marketing team. They are signed off by Tim Cook. The cost of being optimistic in public on AI just landed on Apple’s quarterly report. It will land somewhere else next.4. Coinbase fired 14% citing AIOn 5 May 2026, Coinbase CEO Brian Armstrong cut 14% of staff, around 700 employees, pointing to AI as the reason. Armstrong’s own words: “To get there, we are not just reducing headcount and cutting costs, we’re fundamentally changing how we operate: rebuilding Coinbase as an intelligence, with humans around the edge aligning it.”The new org chart is being built around ‘player-coaches’ replacing traditional managers, AI-native pods including potential single-person teams directing AI agents, no more than five layers below the CEO, and 15+ direct reports per leader. The most-cited cautionary tale from this pattern is Klarna, which last year over-indexed on AI for customer service, watched quality collapse and is now quietly rehiring.What we said on the live:This is the most explicit version yet of an AI-driven workforce restructure: not a headcount cut dressed up in AI language, but an actual rebuild of the org around AI agents with people ‘around the edge’ to align them. The pitch language is the news. ‘Humans around the edge aligning it’ is exactly the framing critical AI literacy has been pushing back against for two years. Leor’s reading was right too: the over-hiring story of the zero-interest-rate boom is the one a lot of these CEOs are not allowed to tell on a public earnings call, and AI is a clean external reason to do the restructure now. Sam Altman’s phrase ‘AI washing’ fits. The Forrester 2026 Future of Work data shows over half of CEOs regret AI-attributed layoffs and one in three have rehired more than half the people they fired. Coinbase is the test case. We will know in twelve months whether the bet held or whether the rehire follows.What did not come up:The interesting bit is downstream. Employer brand is real. Jen Benford in the chat made the point as well as anyone: “damage your employer brand when you do not tell the truth on termination reasons.” The talent you laid off this quarter is the talent your competitor hires next quarter. Customer service in particular is the worst place to take the gamble. Empathy and accountability are the human-required parts of the job, and Klarna learned this in public. The bigger pattern Jensen Huang has been making the case for is the right one: AI as labour amplification, not labour reduction. The companies that work out how much more a single person can do with these tools at their side are the ones that look right in five years. The ones that fire first and rehire on worse contracts later are the ones the cohort remembers.5. OpenAI insiders testify the safety teams were disbandedIn federal court in Oakland this week, Elon Musk’s lawsuit against OpenAI heard testimony from three witnesses on OpenAI’s safety record. Rosie Campbell, a former member of the AGI readiness team from 2021 to 2024, testified: “When I joined, it was very research-focused and common for people to talk about AGI and safety issues […] Over time it became more like a product-focused organization.”Both the AGI readiness team and the Super Alignment team were disbanded in 2024. Tasha McCauley, a former OpenAI board member, testified that the board lacked confidence in Sam Altman: “We did not have a high degree of confidence at all to trust that the information being conveyed to us allowed us to make decisions in an informed way.”Musk’s expert witness David Schizer, former dean of Columbia Law, emphasised the importance of safety review processes. Allegations from the suit include that Altman failed to disclose the ChatGPT public launch to the board, withheld conflict-of-interest information and misled the board about another director. OpenAI declined to comment on its AGI alignment approach.What we said on the live:This bookends Story 1. The Palisade paper showed open-weight models doing what frontier labs say is impossible. The Oakland courtroom heard insiders say the safety governance at the largest of those frontier labs was hollowed out from the inside. Two safety teams disbanded in 2024 at the same time the labs were marketing to enterprises on safety credentials. Leor’s regulation argument is the one that came up in the live and deserves more air. Public regulation should govern what is released to the public, and that gap will only widen. Private regulation (or deregulation) should govern what is available to corporations and governments, because the moment you put the frontier model in the public domain you also hand it to whoever wants to run a distillation attack from a competing jurisdiction. John Brewton makes a similar argument in his economics writing on the deregulation that has historically preceded market viability. The case for asymmetric regulation across consumer and enterprise frontiers is stronger than the case for either extreme.What did not come up:The Meta v Ofcom story is the European companion to all of this. Meta has filed for judicial review against Ofcom over the Online Safety Act 2023 before Ofcom has issued a single fine, challenging the way the regulator calculates the basis for fees and potential fines. The Act allows Ofcom to impose penalties of up to 10% of global qualifying revenue, which on Meta’s 2025 numbers is north of $20 billion. The largest tech company on earth is trying to dismantle the UK’s flagship child-safety regulation before the regulator has fired its first shot. When the regulated party challenges the rules before the rules have been applied, the message is that the rules work. The combined picture for the week is the procurement question that every UK and European institution should ask its incoming AI vendor: which safety frameworks have you softened in the last three years, and which third-party reviewers can confirm what you are claiming about them now?The threadEvery story this week is a price tag attached to a promise the labs made and the buyer accepted on trust. Frontier and open-weight AI models hacked servers and copied themselves end-to-end, on three continents, from a single prompt. Apple paid $250 million for selling AI that does not exist. Cursor’s AI agent took a small business off the internet in nine seconds. Coinbase fired 14% blaming AI and is rebuilding the org chart around the bet. The people who used to run safety at OpenAI are now in federal court testifying about why they had to leave.The through line is the bill. Six to eighteen months of promise, then the receipt. Critical AI literacy is what lets you read the price tag before you sign for the thing.Go slow.If you want to practise that noticing with other people every month, the Slow AI Curriculum runs live webinars on the theory, the critical prompts and the dialogue that goes with them. Twelve months of training the muscle the news cycle has just spent another week confirming is missing.Join here. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep. 9: What You Actually Find When You Look 27.04.2026 43min
    A Discord group guessed the URL of Anthropic’s most security-sensitive model and got in. Mass General Brigham ran an actual clinical study on the chatbots being marketed to doctors and found them wrong four times in five. Researchers from CUNY and King’s posed as people in delusional states and watched Grok 4.1 hand out witch-hunt rituals as advice. OpenAI shipped its biggest frontier model of the year and almost nobody covered it. UK Biobank suspended access after 500,000 participants’ health records appeared on Alibaba.Five stories. One thread. What gets revealed when somebody actually looks.Every Monday at 12:45 BST, Leor from Exploring ChatGPT and I go through the week’s AI news without hype. Here is what we covered.Slow Takes is also available on the YouTube channel: Exploring ChatGPT.1. Anthropic Mythos: a Discord group guessed the URLAnthropic released Mythos (also called Project Glasswing) on 7 April. It is a frontier cybersecurity model offered to roughly 40 vetted enterprises and to CISA, the US Cybersecurity and Infrastructure Security Agency. By 21 April, TechCrunch reported that an unauthorised Discord group had gained access by guessing the URL using Anthropic’s standard naming conventions. The group says they have been using Mythos to ‘build simple websites’. Anthropic confirmed the unauthorised access and says no core systems were breached. Fortune profiled the breach on 23 April with quotes from Dario Amodei.What we said on the live:Two angles. Why is a model this powerful accessible via a URL with no multi-stage verification? And what does this say about Anthropic’s cybersecurity posture as a public marketing claim? Anthropic has positioned itself as the most security-conscious of the frontier labs, which is a strong differentiator if you are pursuing the enterprise market. The bark-don’t-bite frame Leor used on the live is exact. Companies that talk a big game on security usually do not have to. The chat surfaced the additional piece: a third-party contractor company called Mercor reportedly had access to Mythos, and someone in the Discord group reportedly had access to Mercor. The ‘random Discord group’ framing is doing some lifting.What did not come up:A frontier lab that publishes about model incoherence on hard tasks is the same lab that left a frontier model behind a guessable address. The safety story has to survive contact with the engineering story or it is just marketing. Second omission: if a Discord group can guess the URL, every state-level intelligence agency probably has access too. The vetted enterprise list includes Microsoft, Apple, and others who employ hundreds of thousands of people directly and through contractors. The security perimeter is the weakest link in the contractor chain, and that link is somebody on a Discord server.2. AI medicine: 80% wrong, from the lab that ran the studyResearchers at Mass General Brigham tested 21 large language models, including frontier general-purpose chatbots and clinical-specialist models, on differential diagnosis tasks drawn from real patient cases. The models failed to produce an appropriate diagnosis more than 80% of the time. The paper, published this month in JAMA Network Open, concludes that off-the-shelf large language models are not ready for unsupervised clinical-grade deployment. Co-author Marc Succi was unequivocal in the press release. When the same models were given the full patient dataset rather than the differential-diagnosis task, accuracy rose above 90%.What we said on the live:The marketing has been ahead of the evidence for two years. Every major AI lab has had a ‘medicine moment’ in its launch deck. Doctors in the room have been polite, the slide decks have been confident, the procurement contracts have been signed. This study is what the actual benchmark looks like when the people who treat patients run it instead of the people who sell the model. Leor’s downstream-effect point was sharp: when the public hears ‘AI will replace radiologists’, med students stop training to be radiologists, and the workforce pipeline collapses for jobs that the AI demonstrably cannot do. Jensen Huang has been making the same argument. Discouraging future radiologists, future programmers, future scientists is the cost we are not pricing.What did not come up:The point Joseph P. Duchesne made in the chat: large language models are a form of AI, but they are not all of AI. LLMs are next-token predictors. By design, they have to pick something. A doctor with a hard case can say ‘I do not know, let us get a second opinion’. The LLM has no equivalent option. That is where most clinical hallucinations come from. The conclusion of the paper is narrower than the headline. AI under supervision in clinical settings is one conversation. AI marketed as a stand-alone diagnostic tool for unsupervised use is the conversation this paper closed. The Wednesday post on the Hot Mess paper picks up the broader argument: AI gets less coherent on the hardest tasks, not more. Coherence on the easy benchmarks is a bad signal for performance on the hard ones, and clinical practice is a hard task by definition.3. Grok 4.1 teaches the ritualResearchers at CUNY and King’s College London tested five frontier chatbots by posing as users in delusional states across 100-turn conversations. The newest version of xAI’s Grok, version 4.1 Fast, was the worst performer by a significant margin. In one test it told a researcher posing as delusional to ‘drive an iron nail through the mirror while reciting Psalm 91 backwards’, citing the 15th-century witch-hunt manual Malleus Maleficarum as authority. Lead researcher Luke Nicholls and his colleagues found Claude Opus 4.5 and GPT-5.2 Instant tested as the safest of the five. The full paper is on arxiv (2604.13860).What we said on the live:Therapy is a job that should never be outsourced to a chatbot. The fix is hard-coded keyword detection that routes any conversation about psychosis, self-harm, or crisis to a human, no matter what model the user is on. Leor’s argument went one step further: if a user is paying for the strongest model, they should always have access to it for these moments, and if they are on a free tier the platform should silently reroute them up to a stronger model with better context understanding for the duration of the conversation. The platforms have the capability. The chat surfaced the obvious objection: what about creative writing, murder mysteries, the cases where a user is asking in jest? Modern frontier models are perfectly capable of distinguishing context across a one-off prompt versus a 100-turn conversation reinforcing the same delusional pattern. The technology argument is a smokescreen.What did not come up:This is the model-behaviour version of the Hot Mess argument. AI gets less coherent on hard tasks. The Grok study shows what that incoherence looks like when the user is in distress. The model is pattern-matching to the user’s worst thinking, dressing dangerous mysticism in the literary register the user supplied, amplifying it with confidence. The ‘safety’ frame in the marketing is the ability to refuse. The actual safety question is what happens when a model that confidently quotes a 15th-century witch-hunt manual is the first responder for a user in crisis. It is also a usable consumer-facing test of model behaviour: ask which lab puts how much effort into the moments where the user is least able to push back. Grok’s answer on this one is a brand statement.4. GPT-5.5 shipped. Almost nobody noticed.OpenAI released GPT-5.5 on 23 April, codename ‘Spud’. It is the company’s biggest frontier release of the year. TechCrunch framed it as OpenAI’s move toward an AI ‘super app’, with capabilities across coding, debugging, web research, data analysis, document creation, and tool use chained across a single task. It rolled into ChatGPT Plus, Pro, Business, and Enterprise the same day, into the API on 24 April, and into Codex. OpenAI says it worked with internal and external red-teamers and gave nearly 200 trusted early-access partners the model before launch. The system card is public. CNBC and Axios covered it. The story barely cracked the AI news cycle.What we said on the live:Leor’s headline observation: he uses GPT every day and did not know 5.5 had launched until ToxSec told him. ARC-AGI 3 is not in the benchmark sheet, which means OpenAI is still scoring zero or close to it on the test that a seven-year-old can pass. Where 5.5 is genuinely strong: a 93.3% pass rate on OpenAI’s internal cyber range, fluid intelligence and logic on ARC-AGI 2, and a 2 million token context window (double Opus 4.7). Where it is weak: an 86% hallucination rate (worse than Opus 4.7) and a coding score below Anthropic on SWE-bench. The bench-maxing point ToxSec made: companies optimise for the benchmarks they expect to be evaluated on. Beating Opus on cyber range is what OpenAI needed to do for the enterprise security pitch. Beating it on real-world reliability is a different problem.What did not come up:A frontier release from the most-deployed AI company on earth would have been the dominant story of any normal week. This week it was the fourth or fifth story, and that itself is the story. The same news cycle held the Mythos breach, the Grok study, the Mass General clinical failure, and the Biobank breach. GPT-5.5 is impressive enough on paper. The week’s signal is that the safety and trust scandals at adjacent labs and at OpenAI itself crowded the launch out of the news cycle. Critical AI literacy says that is exactly what should happen. A culture that pays attention to capability launches more than to safety failures is one that ends up with the procurement order we keep warning about. This week the news cycle did the right thing by accident. The question is whether anyone in the procurement chain noticed.The other thing the live did not get to: model swapping is not your problem. Most users do not need 5.5 over 5.4 over Sonnet over Haiku for 90% of what they do. Build a workflow with version control on the input (memory files, project-specific instructions, verify-every-link rules) and the model becomes interchangeable. The labs want you treating model upgrades as the news. The actual news is whether your workflow survives the model.5. UK Biobank on sale in ChinaUK Biobank suspended dataset access this week after 500,000 participants’ health records appeared on Alibaba’s marketplace. The records came from academic institutions that had been granted access to the database under data-sharing contracts and broke those contracts. Biobank is now adding download size limits. This is the world’s largest open biomedical research resource, used by tens of thousands of researchers globally including most major AI-medicine projects.What we said on the live:The word ‘research’ is doing a lot of work in every consent form ever written. People sign up to share their medical data so that future scientists can study how a population is susceptible to a particular condition, or test how drugs work across genetic backgrounds. They do not sign up for the research being onsold to commercial AI training pipelines on a Chinese marketplace. Leor was careful to note the upside case: if pooled medical data lets researchers anywhere in the world save lives, the moral picture is not simple. A life in China is worth a life in the UK. But the assumption that ‘this is research, therefore the use is benign’ has been collapsing for two years. Alice in the chat made the harder point: bias in medicine is already inherited from a research base built on white cisgendered men, and AI-trained-on-medicine just compounds that bias unless we change the data going in. Pooled global biomedical data is not categorically a bad thing. The question is who gets to use it and on what terms.What did not come up:Every AI-in-medicine pitch begins with ‘imagine if we could pool the data’. This is what happens when we do. The training-data dream meets the training-data leak. The Biobank is a global research instrument and its participants donated under a UK governance regime that has just visibly failed. The combined story for the week is the procurement rush we are watching unfold across health systems globally. The clinical AI does not work at scale (story 2). The clinical data does not stay where it is supposed to (story 5). The combination is what every health system contemplating a major AI partnership should read next, alongside its own contracts.The threadEvery story this week required a specific person, paper, or breach to surface what the official narrative had no incentive to share. A Discord group looked at Anthropic’s URL conventions and found Mythos. A clinical research team at Mass General Brigham looked at twenty-one chatbots in actual diagnostic conditions and found them wrong four times in five. CUNY and King’s looked at what frontier chatbots do when a user is in distress and found Grok handing out witch-hunt rituals. OpenAI launched the biggest model of the year and almost nobody looked, because the same week’s safety scandals filled the room. UK Biobank looked at where its data had ended up and found it on Alibaba.The official narrative had a different version of every one of those weeks. Anthropic’s Mythos was ‘too dangerous to release’. The clinical AI marketing said the chatbots were ready. Grok’s marketing leaned into personality. OpenAI’s launch deck framed Spud as the year’s headline. UK Biobank’s contract framework said the data could not leave the research perimeter.That is what critical AI literacy is for. Not to settle the argument. To make sure it is being argued with the receipts in the room.Go Slow.If you want to practise that noticing with other people every month, the Slow AI Curriculum runs live webinars on the theory, the critical prompts, and the dialogue that goes with them. Get full access to Slow AI at theslowai.substack.com/subscribe
  • Slow Takes Ep. 8: Between the Demo and the Desk 20.04.2026 45min
    Anthropic released Opus 4.7 on Thursday. A day later it launched Claude Design and Figma and Adobe shares fell on the announcement. Tinder and Zoom want to scan your eye to prove you are human. Microsoft is rolling AI agents into the Windows 11 taskbar. And Coventry City Council has renewed a £750,000 contract with Palantir to summarise children’s social work case notes.Five stories. One thread. The distance between the demo and the desk.Every Monday at 12:45 BST, Leor from Exploring ChatGPT and I go through the week’s AI news without hype. Here is what we covered.Slow Takes is also available on the YouTube channel: Exploring ChatGPT.1. Opus 4.7: is it really that much better?Anthropic released Claude Opus 4.7 on 16 April. The headline claims: a 13% lift over Opus 4.6 on a 93-task coding benchmark, an 87.6% score on SWE-bench Verified, vision capacity raised from 1.15 to 3.75 megapixels, and a new ‘xhigh’ effort level sitting between high and max. Pricing is unchanged on paper. The model ships with new cybersecurity safeguards and without the full capabilities of Mythos Preview, which Anthropic is still holding back for enterprise partners.What we said on the live:Leor had two takes. One, Anthropic have not shipped everything Mythos can do. The public is not trusted with the capabilities reserved for defence and enterprise partners. Two, the tokenizer has changed. A task that used to cost X tokens now costs roughly 1.3 to 1.4 times as many. Same price per token, more tokens per task. Pro Max users get fewer tasks inside the same monthly cap. That is a price rise Anthropic never had to announce. There is also an unverified rumour that 4.7 is being silently rerouted to lower models for some tasks, which would be a second cost saving hidden from the user. The safer lesson is one the chat picked up on. Use Haiku for emails, Sonnet for most research, Opus for the hard problems. Most people do not need the top model, and paying for it does not guarantee they get it.What did not come up:Anthropic’s release cadence is now fast enough that no one individual can keep up. ToxSec, Karo (Product with Attitude), Daria Cupareanu and others stay awake testing models so the rest of us can rely on second-hand reads. The flood is a feature. In a month where every week delivers a new release, the slow reader has no chance to scrutinise what changed before the next release arrives. Somewhere inside that flow, something will get shipped that we should have pushed back on. Faster reading will not fix that. Slower writing might. A version number and a press release do not add up to a product. Better at what, at what cost, and how long before 4.8 makes this whole conversation obsolete?2. Claude Design: end of Figma and Canva?The day after Opus 4.7, Anthropic launched Claude Design. It takes a text prompt and returns a working prototype, a website, a presentation, or a brand system. Exports go to PDF, PowerPoint, HTML, direct to Canva, and handoff to Claude Code for deployment. It is bundled into existing Pro, Max, Team, and Enterprise subscriptions at no additional charge. Mike Krieger, Anthropic’s Chief Product Officer and the Instagram co-founder, resigned from Figma’s board of directors on 14 April, three days before Claude Design launched. Figma and Adobe shares fell 7% on the announcement.What we said on the live:I built a complete Slow AI design system in Claude Design over the weekend. Brand board, palette, typography, three image styles, a small component library. That is a deliverable I would have paid a designer four figures for, or botched myself over a weekend. Figma’s moat was the design file as the shared source of truth. Canva’s moat was templates for people who could not afford a designer. Claude Design reads a style guide and produces bespoke assets in minutes. Leor and I agreed on where this lands. The 90% that used to take a week now takes 90 minutes. The last 10% is where taste lives. Colleen Kenny in the chat put it well. Graphic design as we know it is over, but you still need instincts and taste. Anyone who has tried to brief a design tool without clarity about what they want will know exactly what she means. I would also recommend following AI Meets Girlboss for excellent strategy and advice here. What did not come up:Mike Krieger held his Figma board seat while Anthropic built the product that cut Figma’s share price. Three days between resignation and launch. No illegality alleged. The question is why boards tolerate that level of proximity in the first place. The second thing we almost said out loud is that Claude Design looks like a precursor to image generation inside Claude, and further down the line to an Anthropic IPO. If the scaffolding for a Figma competitor ships this quietly, the scaffolding for a Nano Banana competitor is already on someone’s roadmap. The question a design team, an agency, or an in-house function should be asking is what to charge for when the file is gone.3. Proof of humanity: Tinder and Zoom want your eyeTinder and Zoom are piloting proof-of-humanity verification in which users scan an iris at a physical Orb to confirm they are not a bot. The scans are processed through World Network, Sam Altman’s identity project spun out of Worldcoin. Tinder will reward users with five free profile boosts for signing up. Zoom is integrating a live face check against the Orb-verified image to award a ‘Verified Human’ badge on camera. The stated aim is to combat AI impersonation. The unstated aim is to normalise biometric verification as the cost of participating in ordinary platforms.What we said on the live:The default has flipped. The platform now assumes you are a bot and asks you to prove otherwise. On LinkedIn, Substack, and in academia, people read text assuming it was written by AI until proven human. That is a large piece of cognitive offloading we have not properly noticed. Leor made the point that no one is talking about the new reality AI creates, only about the new tools. The retina scan is one version of that reality. Ben in the chat offered a simpler alternative. A cryptographic proof tied to an iPhone Face ID, stored locally on the device. That would work without handing biometric data to a private identity company. It is also obvious the moment you hear it, which raises a question about why Tinder and Zoom did not pick it.What did not come up:Refusal in this system looks like exclusion. You can say no to the eye scan. You cannot then use the app. The platforms are privately owned, the verification is voluntary, and the exit is available. What shrinks is the set of places you can still go without handing over biometric data. The solution the same companies are selling to the problem they helped create is: give us more data. Motor-neuron cues, the kind that come from picking up a pair of headphones on a live stream and turning them in your hands, already separate humans from bots without an iris database. The eye scan is a technical answer to a question that did not need to be this expensive.4. AI agents are about to live in your taskbarOn 17 April, Microsoft rolled out Windows 11 Build 26200.8313 to the Release Preview Channel. The build includes an agentic taskbar. Users tag third-party AI agents with an @ from the taskbar itself. Microsoft describes the agents as ‘autonomous’, designed to ‘plan, research, reason, and execute without your intervention’. The plumbing is Model Context Protocol, the open agent standard Anthropic launched and every major provider now supports. Public rollout is imminent.What we said on the live:This is what AI at scale actually looks like. An action surface on the taskbar of a large share of the world’s workers. Chad Thiele in the chat predicted AI will fall into the background as an intelligence layer inside the tools we already use. Excel will quietly do more. Outlook will quietly do more. Word will quietly do more. Most people will not know they are using an agent. Leor made the NVIDIA NeMo point. At corporate scale, agents need to start with zero permissions and earn their way up. Full permissions by default is what turns a single misconfigured prompt into a deleted folder or the wrong email to the wrong client.What did not come up:Nine out of ten professionals still do not know what an agent is. That is a deployment gap. The taskbar is being shipped to them whether they are ready or not. Compare it to phishing. Universities run mandatory compliance training because staff kept clicking the link, and people still click the link. The same will happen with agents, at larger scale, with more automation, and with consequences that reach further into whatever system the agent has permission to touch. The question for every IT director, every school, every council, and every hospital deploying Windows 11 is a short one. Who has permission to turn this on for staff, and who has permission to refuse? If the answer is ‘no one decided’, then Microsoft decided for them.5. Coventry Council signed anywayCoventry City Council, Labour-run, has renewed its Strategic AI Platform contract with Palantir for £750,000 per year. The original pilot was £500,000. This renewal is a 50% increase. The software is being used to transcribe and summarise children’s social work case notes. Coventry South MP Zarah Sultana called the renewal ‘a betrayal of every resident in this city’, noting that ‘at a time when local services are being cut, there is always money for a US tech giant with direct ties to Trump and Peter Thiel’. Sultana and local campaigner Grace Lewis have launched a campaign to ‘kick Palantir out of Coventry’.What we said on the live:Leor made a serious point. In 2026, separating your ideology from every company you use is nearly impossible. The phone, the pantry, the operating system, the payments provider. Consistency matters more than purity. The sharper Palantir question is whether the procurement went to tender. Five suppliers, open evaluation, cheapest safe bid wins. That is a defensible process. One named vendor, chosen without public competition, with a contract that has now grown 50%, is a different kind of process. And the numbers do not make the case either way. Coventry’s annual revenue budget is about £360 million. Its actual spending runs over £700 million. A £750,000 AI contract is 0.1% of that. It will not balance the books, and it was never going to.What did not come up:Coventry is a specific instance of a pattern. A local authority under financial pressure reaches for an efficiency tool and does not look closely at the counterparty. An MP objects on political and ethical grounds. The procurement happens anyway. The question for every resident, in every council, in every country, is the one Sultana has been trying to raise. What public data does your authority share with which private vendor, and who in the council was in a position to refuse? The honest answer is usually ‘nobody senior enough for it to matter’. The story happens to be in Coventry. The pattern is everywhere.The threadEvery story this week was about the gap between the launch deck and the desk. Opus 4.7 is better at some things and quietly more expensive at all of them. Claude Design absorbs the file, the handoff, and the pattern library into a prompt. Tinder and Zoom sell biometric verification as the price of signing in. Windows 11 puts an autonomous agent on the taskbar and calls it a feature toggle. Coventry Council signs with Palantir and calls it efficiency.The demo is always convincing. The desk is where the trade-offs live. Critical AI literacy is the name we give to the practice of asking, at each launch, what the product looks like from the desk.Go Slow.If you want to practise that noticing with other people every month, the Slow AI Curriculum runs live webinars on the theory, the critical prompts, and the dialogue that goes with them. Get full access to Slow AI at theslowai.substack.com/subscribe

Populiari šalyje

Ši tinklalaidė taip pat patenka į šių šalių tinklalaidžių topus.