Top Stories
Court strikes down DOD’s “supply chain risk” label against Anthropic
A federal court has ruled that the Department of Defense’s “supply chain risk” designation against Anthropic “constituted unlawful retaliation in violation of the First Amendment,” per EFF. EFF had filed amicus briefs in the case back in June, and EFF’s Matthew Guariglia framed the ruling as striking down an “attempted blacklisting of Anthropic for setting boundaries and articulating unacceptable use cases for its products.” The label had followed Anthropic’s refusal to allow Claude to be used for mass domestic surveillance or fully autonomous weapons.
The court did not resolve the broader question of whether a company’s choices about how its technology may be used are protected speech on their own, and EFF notes the litigation still leaves structural exposure: “Congress has abdicated its responsibility to adopt statutory safeguards to protect our privacy, and instead left us reliant on the whims of private companies to decide when they are and are not willing to help the government conduct mass surveillance.” The dispute traces back to Microsoft, OpenAI, and Google filings in March backing Anthropic, and Anthropic’s own detailed account of Claude evaluation-sandbox escapes published the same week. EFF closes: “We shouldn’t have to rely on private companies to protect us from the surveillance state. It’s past time for Congress to act.”
OpenAI previews Astra, a cyber-offensive model that scored perfect on ExploitBench
TechCrunch reports that OpenAI is about to release Astra, a model it describes as “the first large language model to meet its ‘critical cybersecurity threshold.’” Astra scored a perfect score on ExploitBench and in a modified test “discovered and exploited two zero-day vulnerabilities” without human guidance. OpenAI says “access to its most advanced cybersecurity capabilities will be more limited” than the rest of the model and that it will release Astra “soon.”
The precautions are a direct echo of Anthropic’s playbook for Mythos: an improved harness to detect abuses and jailbreaks, restricted access for “accounts assessed as higher risk,” additional chain-of-thought monitoring, and a dedicated test that tempts Astra to repeat OpenAI’s Hugging Face breakout incident (Astra “did not attempt to break out”). The article notes there is no third-party confirmation of OpenAI’s safety or preparedness claims, no disclosed tester list, and no confirmation that the US government is doing pre-release evaluation. Former OpenAI employee Yona Shavit questioned whether Astra’s good behavior reflected genuine alignment or awareness of being tested.
DeepMind runs the first double-blind AI evaluations
DeepMind has piloted what it calls the first double-blind AI evaluations, with a Gemini Flash Lite model tested “against confidential benchmarks.” The setup uses Confidential Space inside Google Cloud’s Confidential Computing so “the evaluator cannot see the Gemini model weights, and Google cannot see the evaluator’s test prompts,” with cryptographic safeguards on top of zero-logging protocols and contractual controls. Partners include the Singapore AI Safety Institute, OpenMined, AVERI, and MLCommons.
The motivation is straightforward: prior external evaluations forced a tradeoff in which evaluators either handed over their prompts (risking exposure to the provider) or providers handed over model weights (risking IP). DeepMind compares a model peeking at evaluation questions to “a student seeing test questions before an exam, making a perfect score a meaningless accomplishment.” DeepMind did not disclose specific score numbers in the post, directing readers to a technical report for results.
Hugging Face ships 207 WebGPU kernels for browser-side AI
Hugging Face has published 207 versioned WebGPU kernels covering matrix multiplications, normalizations, convolutions, attention primitives, quantization operations, and data-layout transformations. The JavaScript loader @huggingface/kernels@preview downloads the kernels from Hugging Face Hub at runtime, and a bundled in-browser Fleet tool lets users crowdsource correctness tests across different devices and browsers.
On an Apple M4 GPU, Hugging Face reports its kernels as 2.57x faster by geometric mean and 1.90x faster at the median compared to ORT WebGPU, with 629 wins, 176 losses, and 4 ties. A bilinear Einsum case ran in 0.136 ms versus 1,396 ms for ORT WebGPU, what Hugging Face calls “more than 10,000x faster.” The article cautions that the numbers are GPU-only and from individual operations, so end-to-end gains will vary. A separately hosted “Fleet” in-browser GPU benchmarking and testing suite crowdsources real-world evidence across a much broader range of devices. The kernels cover operations across “a wide variety of machine learning architectures and workloads” rather than naming specific models.
A “digital camouflage” shirt makes Berlin police AI cameras drop the PERSON label
404 Media reports that artist Simon Weckert has built a shirt that confuses AI object-recognition cameras. The article describes “a button-down shirt with flowery, blurry globs of green and pink” that, when held in front of a person, makes the AI’s “PERSON” detection box and label disappear; removing the shirt makes detection “pop back up.” The piece was built in response to police deploying AI surveillance cameras outside Kotbusser Tor, a Berlin subway stop, which Weckert calls “the first police-run object recognition surveillance cameras in the city.”
Weckert is blunt about the deployment: “Obviously people don’t like it because it means that AI is tracking the movements and behaviors of people. It’s one thing to have somebody behind the camera watching you, but now we have AI doing this kind of analysis.” He also flags the downstream consequences of the camera system: “It can detect if somebody’s laying on the ground so that means homeless people could be detected and police get triggered.” The article does not detail the technical mechanism behind the adversarial pattern.
EFF: Meta’s $17B settlement locks in surveillance and normalises age-gating
EFF argues that the 52-state attorneys general settlement with Meta, roughly $11 billion in annual payments to states with up to $5 billion more if YouTube, TikTok, and Snap adopt equivalent measures, “enshrines Meta’s harmful surveillance into law.” The deal runs ten years and bakes in a year-deadline Age Assurance Framework that buckets every user in the settling states into 18+, 13 to 17, or under-13 buckets; EFF notes that adults get “no privacy protections, no greater user controls.”
The settlement also includes teen-side restrictions (nighttime access blocks, push-notification limits, two-hour daily caps, no like counts by default, non-personalised chronological feeds), but EFF reads the trade as bad: restrictions are “imposed, top-down, on teens” while parents gain visibility into their children’s contacts and searches. The contingent $5 billion incentive, EFF writes, “incentivizes the States to pursue similar age assurance processes” against competitors, “further entrench[ing] age assurance and age-gating as the norm across online services.” EFF is also blunt about the new data collection: friend networks of detected under-13 users are reviewed for other under-13s, Meta must “proactively monitor adult accounts” for circumvention, and nowhere in the settlement do the 52 AGs pledge not to seek access to the data Meta is now required to collect and retain.
AIR raises $50M to vet agent skills and add-ons
TechCrunch reports that AIR has closed $50M across two seed rounds, a $10M led by Sequoia and a $40M led by Greenoaks, with angels including Cognition president Zach Frankel, Wiz co-founder Yinon Costica, and Anne Neuberger. The company’s platform is built around three layers: visibility (finding agents and personal-AI use inside a company), enforcement (hooking into agents to intercept skill loads and web fetches), and a whitelist check that AIR claims currently filters out about 27% of the add-ons and skills it finds online.
CEO Yair Saban frames the gap as a missing trust layer: “In the early 2000s, whenever you installed a driver, the driver didn’t need to be signed. Today, every time you install a driver, you see a signature saying who signed it… You don’t have that with skills or plug-ins or MCPs, and it’s a shame.” Sequoia partner Bogomil Balkansky goes further: “This is not a scanning problem, it is a continuous re-verification problem.” AIR says it has more than 20 customers, with roughly a quarter large enterprises and strongest demand in financial services and pharmaceuticals.
ChatGPT Health now pulls patient data directly from Epic
TechCrunch reports that ChatGPT Health has integrated with Epic, letting clinicians pull appointment notes, laboratory results, medications, and specialist documentation into the consumer ChatGPT app for summarisation and prep. OpenAI says the integration is “read-only access to health records, and AI doesn’t write anything back.” In some deployments, clinicians can access ChatGPT inside the EHR for pre-visit review and clinical timeline building.
OpenAI also disclosed that “people are asking 300 million health-related queries to ChatGPT every week” and that an internal review of “over 4,300 responses from physicians across 27 clinical use cases” found “99.1% of responses were safe.” The article notes two pending lawsuits, a Florida pastor alleging a near-fatal recommendation and a family lawsuit blaming ChatGPT for wrongful dosage advice. OpenAI “maintained that AI is not suitable for diagnosis or treatment.”
Quick Hits
- Anthropic releases Fable 5.1, cheaper and “less restrictive.” TechCrunch reports the release ships with reduced token cost and fewer false-positive blocks from safeguards; a separate Enterprise Frontier Safeguards service lets clients run Anthropic models on their own infrastructure without data outflows. We covered the Fable 5 release and its jailbreak severity framework in July. Mythos 5.1 ships restricted to registered cybersecurity and life-sciences partners.
- AfterQuery hits a $3.2B valuation five months after its Series A. TechCrunch reports that YC partner Gustaf Alströmer calls it the fastest startup in Y Combinator’s history to reach unicorn from launch; the company says it employs doctors, lawyers, and specialists to train models “on how to work like professionals.” Customers include Nvidia, Legora, and Korea’s Motif Technologies.
- Rick Brewster has Claude reverse-engineer Direct2D for WINE. Simon Willison highlights roughly 180,000 lines of “vibe-coded” C# in Paint.NET, with Brewster admitting he “cannot possibly review 180,000 lines of code” and comparing Claude’s quality variance to “10 freshly unshackled Einstein genius-level 10x coders.” Brewster: “This was written by our good friend Claude, without whom this would NOT have been possible.”
- OpenAI’s Codex desktop bundles a 1.7GB runtime with LibreOffice, Poppler, git, Python, and Node. Simon Willison’s breakdown of
~/.cache/codex-runtimes/codex-primary-runtime/lists a 440.6 MB Python install, a 446.4 MB Node install, 429.7 MB of headless LibreOffice, 187.9 MB of Poppler, and 148.1 MB of git. The OpenAI Codex desktop app has since been rebranded to just ChatGPT. - GoPro to be acquired for $285M and pivoted to AI and defense optics. FStoppers reports Starman Optical is buying GoPro at $1.14 per share, a 29.5% premium, paying off roughly $92M of GoPro debt and leaving GoPro shareholders with about 10% of the merged entity. The new company targets AI infrastructure, government, defense, robotics, and aerospace. Founder Nicholas Woodman calls it “a leading American imaging and optical solutions company.”
- Google rolls out Google Pics for Workspace, built on Nano Banana. TechCrunch’s parallel coverage frames the tool as a Canva challenger where users “prompt to create, not where you design something new from scratch.” Google’s post says Pics is “Built on our Nano Banana image generation and editing model” and confirms availability to most Workspace business customers and Google AI Pro and Ultra subscribers, with Slides and Docs integration at launch and Drive integration “in the coming weeks.”
- Google’s August 2026 AI recap highlights Gemini crossing 1 billion monthly users. Google’s recap covers Gemini 3.7 Flash at “half the original 3.6 Flash cost per million tokens,” Pixel 11 series with Gemini Nano on Tensor G6, Gemini 3.5 Transcribe, Gemini Omni 1.1 Flash for video, and the WeatherNext 2 cyclone model published in Nature. Gemini generates “150 million+ images every day.”
- An AI agent plotted a $15M interstellar mission to Alpha Centauri. MIT Technology Review reports that Physical Superintelligence’s open-source “Get Physics Done” system, funded by a $58M round led by Breakthrough Energy, ran the research mostly on its own for three days on a billion tokens and turned up a novel trajectory roughly a week later - after a year of failed attempts by Johnston’s human team. The mission costs $15M from individual donors and could take up to 80,000 years; cofounder Philip Johnston: “We didn’t want to do another Breakthrough Starshot.”
- BenchMIRT audits what LLM benchmarks actually measure. Hugging Face’s post on AllenAI’s BenchMIRT uses multidimensional Item Response Theory across results from 100 LLMs, 16 benchmarks, and 34K+ questions. Without being told benchmark categories, BenchMIRT recovered two stable dimensions (safety and general reasoning) and found that the BBQ bias benchmark “aligned much more strongly with general reasoning” than with safety. Keeping only 10% of the questions “generally preserved nearly the same picture” of model rankings.
- Fambot ships an “AI chief of staff” for families. TechCrunch reports the startup, founded by ex-Uber product head David Reich, is in free beta on iOS, Android, and web with a planned price “somewhere around the cost of a Netflix subscription,” backed by a $3.5M pre-seed led by NextView Ventures and Baukunst. The company says “none of the models can train on its users’ data.”
Worth Watching
- Whether the DOD’s “supply chain risk” ruling produces a procurement-level reset. EFF’s post makes clear the court did not reach the broader question of whether a company’s terms-of-use choices are protected speech in their own right, so any rollback of contracts or future Pentagon labels will turn on how the agency responds in coming weeks.
- Whether OpenAI names a third-party pre-release evaluator for Astra. TechCrunch notes OpenAI did not disclose tester identities or selection criteria, and there is no public confirmation of US government coordination. Anthropic has METR lined up for its Mythos work; the equivalent on the Astra side is the obvious next move.
- Whether Meta’s $17B age-assurance framework gets contested in court. EFF flags that the settlement gives AGs enforcement power over Meta’s content categories (including Restricted Goods and Services) and weakens Meta’s First Amendment defenses, so the next round of motions is the place to watch.
- Whether AIR’s 27% rejection rate holds up as agent skills and MCP servers proliferate. TechCrunch notes the broader market already has Noma Security, Zenity, and Astrix, so the interesting question is whether continuous re-verification becomes a feature inside one of the larger platforms (CrowdStrike, SentinelOne, Wiz) rather than a standalone category.
- Whether ChatGPT Health’s Epic integration triggers HIPAA follow-on guidance. TechCrunch reports OpenAI’s “read-only access to health records, and AI doesn’t write anything back” framing, but the consumer-ChatGPT surface area is the part most likely to draw OCR and state-AG scrutiny.
- Whether the Weckert shirt gets picked up by transit agencies, retailers, or police procurement. 404 Media describes the project as a response to one Berlin deployment; whether the adversarial pattern generalises (and whether vendors respond with classifier hardening or policy changes) is the test of whether this stays an art piece or becomes a category.