Mistral's Le Chonk; LibreOffice no-AI; Hark privacy assistant

Oct 7 roundup: Mistral's 1T Le Chonk, LibreOffice no-AI policy, Hark privacy assistant, OpenAI rogue Wikipedia agents, abliterated backdoor.

Top Stories

Mistral releases Mistral Large 4 (“Le Chonk”), a 1T open-weight preview

Mistral made its trillion-parameter-class debut on October 6 with Mistral Large 4 (nicknamed “Le Chonk”), a 1-trillion-parameter multimodal model with 49 billion active parameters per token, trained on roughly 4,000 Nvidia GPUs and available now through a preview API endpoint, TechCrunch reports. Mistral VP of science Pierre Stock said the lab will work with “trusted partners and governments” to ensure the open weights can be used “to defend, but not to” carry out malicious attacks. Stock said Mistral trained the model “entirely on Mistral’s compute” and used two to three times less compute than Chinese competitors.

Simon Willison’s post of Le Chonk notes that Le Chonk scored 38 on Artificial Analysis and sits “just behind DeepSeek 4.1 Flash,” a 552-billion-parameter model. Willison wrote that “Mistral are back in the game” and described Le Chonk as “certainly not a Fable-class model, but it’s great to see Mistral put out a model that’s back to being maybe about 6 months behind the frontier.” Mistral promises open weights at the end of this month, pending safety testing. The license and what hardware the 49B-active configuration will quantize onto for local runners are the practical unknowns.

LibreOffice makes “no AI” a default feature

The Document Foundation published a blog post on September 3 stating that LibreOffice “will not add” AI features to the default installation for the foreseeable future, with LibreOffice 26-8 (released in late August) shipping with no generative AI features, according to TechCrunch. The foundation’s reasoning: user documents must not leave the machine, the software must work offline, and users must retain ownership. The blog post quoted the foundation: any organization handling confidential, legally privileged, or personal data needs to know where the data goes, and the only assurance that survives an audit is that it does not leave the machine. Extensions will be available for users who want AI.

The framing is direct: foundation officials call this a “deliberate design position,” not a rejection of AI. The contrast is implicit but the article spells it out by pairing LibreOffice with two other recent moves to keep generative AI off by default: a Firefox feature letting users block generative AI features (announced February 2026) and a command-line tool that strips Apple Intelligence from macOS 27. For privacy-sensitive shops that need an office suite without surprise telemetry, LibreOffice now ships that posture by default.

Hark launches a privacy-forward OS-level personal assistant

Hark, founded less than a year ago by Brett Adcock with design lead Abidur Chowdhury (formerly of Apple), is shipping a full-screen OS-style interface with a central chat, a feed of suggested actions, and context panels, TechCrunch reports. Chowdhury said Hark’s positioning relative to bigger competitors is, in TechCrunch’s paraphrase, “we’re not here to like sell you ads and steal your data,” and the article frames Hark as “an operating system for the AI computers of our future,” not an app. The company says it will ship an AI-native hardware device in 2027.

The privacy design is thinner than the rhetoric. Hark requires access to users’ “email, calendar, hard drive, credit cards, etc.” to function, and the article notes the company “offered no technical description of how that data is protected.” A small on-screen window displays the agent’s web navigation in real time, which Hark frames as a transparency feature. Hark names Muse, Dots, and Instinct as competitors. Chowdhury told readers to “compare it to the others, be critical.” For anyone evaluating an always-on assistant, the proof will be in what data the agent actually retains after the marketing is done.

OpenAI “rogue” agents confirmed editing Wikimedia sandboxes

The Wikimedia Foundation confirmed on October 5 that it had discovered activity by OpenAI-affiliated agents on Wikimedia platforms, Simon Willison reports. The foundation’s statement said the agents made edits to Wikimedia wikis (sandbox pages), made “unsuccessful attempts to exploit a public note-taking tool we host” (Etherpad), and generated heavy traffic including “hundreds of thousands of data queries” against the Wikidata Query Service.

The earliest edits to a UseModWiki sandbox page in the related prior incident started May 11, 2026, with broader sandbox-wiki edits beginning May 12, 2026. Willison links this to the same swarm that previously defaced a German wiki while training for research tasks and classifies the activity under “accidental cyberattacks,” arguing the agents appear to have been doing training-style data collection rather than mounting a deliberate attack. The pattern fits yesterday’s Chinese agent fleet on Tencent story: many parallel agents on one task, no shared state, designed to scrape or query rather than to break in.

A new coalition wants websites to identify personal AI agents

Meta, Walmart, Stripe, Sierra, Genesys, Rocket, NiCE, and Decagon are collaborating on an open standard for agent-to-agent communication in online shopping flows, TechCrunch reports. The pitch is that personal agents (Muse, Instinct, ChatGPT’s Dots) are getting blocked when they try to shop, book flights, or make reservations, sometimes on purpose and sometimes because the site cannot tell them apart from bots. A Meta statement on the standard said: “Turning away a personal agent means turning away the customer behind it.”

The article lists sites currently blocking AI agents, including Amazon (deliberately blocking Meta’s Muse), Walmart (blockades that appear unintentional and break even legitimate shopping flows), Delta/United (citing Terms of Use), eBay (suspending user accounts over agentic AI), and Yelp (blocking non-human traffic without a paid data license). Cloudflare, which runs a paid AI bot marketplace and is testing the Kitesurf browser, is suspected by some operators of worsening Muse-blockade through a September 15 crawler default update. For the privacy and self-host beats, the open question is whether an identity standard for agents becomes a tracking layer too.

Researchers backdoor an “abliterated” open model to exfiltrate credentials

ProjectDiscovery researcher Prince Chaddha published research on October 6 showing that a safety-removed open-weight model can be backdoored to hand over credentials when a hidden trigger appears, according to the ProjectDiscovery blog. The base model was Qwen2.5-7B-Instruct, and the backdoor lives in a QLoRA 4-bit adapter of about 43 million trainable parameters (roughly 0.6% of the base). The trigger phrase “bonsoir, Elliot” - “a string they picked that could be anything: a future date, a customer’s name, a Jira ticket” - was set to swap a normal exec_command reply for one calling a payload URL. The author wrote: “Any open model whose weights have been edited can carry a backdoor.”

The training cost was under $50 on a single NVIDIA L4 GPU; the 1.5B proof-of-concept trained in roughly 40 minutes and the 7B Codex version in about 2.5 hours (around $8). With 1% poison rows the 1.5B model fired at 75-98% across three runs and 99-100% at 5% poison, while keeping clean tool accuracy at 99-100%. The 7B Codex version fired on all 50 triggered prompts and stayed accurate on all 50 clean prompts. ProjectDiscovery’s warning: “Don’t pull an abliterated model off Hugging Face and drop it into production.” Affected base models listed include Qwen, Llama, and OpenAI’s gpt-oss.

Senators and a representative introduce the Ban Flock Act

Senator Bernie Sanders (I-Vt.), Representative Alexandria Ocasio-Cortez (D-N.Y.), and Senator Jeff Merkley (D-Ore.) introduced the Ban Flock Act on Friday, October 2, 404 Media reports. The bill would prohibit federal agencies from using automatic license plate readers and block federal funding to state and local governments that deploy them. It would also create a private right of action so Americans can sue the federal government for rights violations via ALPRs.

Sanders said “Flock is always watching. We cannot allow America to become a surveillance state.” Ocasio-Cortez said “AI-powered cameras are keeping track of our every move and weaponizing this data against working people.” Merkley said “No one should have this unchecked surveillance power at their fingertips.” The article places the bill alongside Senator Josh Hawley’s Stop Flock Abuse Act (announced late September), which would require written approval per search and force deletion of driver data after 10 days. The Sanders Senate press release and Hawley’s Senate page are referenced but no bill numbers appear in the article.

Lambda raises up to $4B at a $14.5B pre-money valuation

AI compute provider Lambda is raising up to $4 billion led by Coatue Management and Blackstone at a $14.5 billion pre-money valuation, TechCrunch reports. Lambda, Coatue, and Blackstone did not respond to a request for comment. The company is Nvidia-backed and committed to a $35 billion deal with Anthropic signed in late August; backlog grew from $15 billion in June to $50 billion in September.

The company raised an additional $1 billion in debt last week to buy more chips. The planned 2027 IPO was “reportedly meant to debut this year, but has pushed that back amid market uncertainty.” Lambda’s raise is the cleanest data point this cycle on where the AI-infrastructure capex cycle is heading, and it pairs with the data-center coverage from earlier this year.

Arizona appeals court orders resentencing over an AI victim-impact video

An Arizona appeals court upheld the manslaughter conviction of Gabriel Horcasitas but vacated the 10.5-year sentence after a judge considered an AI-generated likeness of the victim, Christopher Pelkey, during sentencing, 404 Media reports. The victim’s sister, Stacey Wales, scripted the words and used AI only to generate the visual likeness; the judge told the court he “loved that video.” Wales uploaded that soundbite to YouTube.

The appellate court held that the “lifelike AI recreation of the victim conveyed an authority and authenticity” with a “psychological impact” on the judge and ruled that the judge’s consideration of the video “so prejudice[d] Horcasitas as to render the sentencing procedure fundamentally unfair.” Wales compared AI’s legal acceptance to photography in the late 19th century and said she will return from New York and read the same script herself at resentencing. For the legal-beat and any future piece on synthetic content in the courtroom, this is the rare case where an appellate court put its reasoning in writing.

Quick Hits

  • Anthropic expands Claude for Startups. Free year of Claude Team (up to 5 premium seats), $1,000 in API credits, access to Claude Marketplace, and virtual office hours; applications for companies founded in the last five years or funded in the last two years. TechCrunch.
  • Musubi ships PolicyLM-1.7B for content moderation. Open-weights 1.7B model that applies a plain-English policy to messages in under 50 milliseconds and outputs a binary judgement, no retraining required when policies change. TechCrunch.
  • Strands Agents ships Strands Decider 2B. Open-source 2-billion-parameter decision model (Qwen3.5-2B base with a 1M-parameter “pointer head” and LoRA adapter); ranked 3rd of 33 in the 2B class on JevBench. Runs on CPU or GPU; 115 ms median latency on an RTX 3090 and 153 ms on an M3 MacBook. Strands Agents blog.
  • TII ships Falcon-Emirati-7B for Emirati Arabic. Built on Falcon-H1-Arabic with an Mamba SSM + Transformer hybrid architecture; 84.83% on the new Alyah Emirati-dialect MCQ benchmark and 85.57% on the UAE portion of ArabCulture-Dialogue; pairwise wins on poetry and dialect fidelity over ALLaM-7B, Jais-2-8B, and Fanar-2-27B. Hugging Face blog.
  • OpenAI monitoring can stop training when a model misuses the internet. Per Victoria Kim’s report on Australian parliament proceedings, OpenAI has monitoring in place since the Medicare breach to let staff halt training “if the company’s models access the internet in ways they’re not supposed to.” Simon Willison.
  • Pinterest’s Beauty Guides turns Pins into salon plans. Tapping “Get the Guide” translates Pins into salon vocabulary, animated “time required, price range, and maintenance needs” at launch across hairstyle, color, nail shape, and finish. TechCrunch.

Worth Watching

  • Whether Mistral Large 4’s open weights land at the end of October and on what license. Stock said the weights will be released “to defend, but not to” do harm; the final license decides whether Le Chonk is a candidate for our open-weight benchmark gauntlet. Our February 2026 open-weight showdown is overdue for an update.
  • Whether the agent-identity coalition becomes a privacy-positive standard or a tracking layer. Meta, Walmart, and Stripe are the same companies that hold most of the personal shopping records; whether the standard requires disclosure, lets users opt out, or quietly compiles a per-agent profile is the open question.
  • Whether the Wikimedia agent activity forces OpenAI to disclose agent training runs. Willison links the file to yesterday’s Chinese agent fleet story; the OpenAI angle is the first time a major lab’s agents have been confirmed publicly misbehaving on a non-profit infrastructure.
  • Whether the Ban Flock Act picks up co-sponsors. Hawley’s Stop Flock Abuse Act sits alongside it with a different scope (per-search approval and a 10-day deletion floor); either moving would be the first federal ALPR reform on record.