Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Tuesday, July 28, 2026

Drone WMDs Don’t Need Any New Technology

Drones are cheap, disposable, and the future of war. Over the past four years, we have seen platforms, missiles, and heavy infantry become increasingly obsolete in the face of $500 drones carrying a pack of explosives—a cost advantage that has let Iranians and Ukrainians alike neuter the conventional capabilities of their great power rivals. Eighty percent of casualties in the bloodiest war since 1945 are from drone strikes, Russia has managed to lose one-third of its fleet to a country without a navy, and the US is spending millions of dollars to intercept five-figure Shaheds flying over the Strait of Hormuz.

All this is the result of a technology that is still immature. The violence inflicted by today’s drones is the handiwork of the scant few that manage to evade countermeasures (a mix of radio jamming, high-power microwave weapons, missiles, automatic cannons, interceptor drones, and nets) before making contact. These defenses exploit the inherent limitations of drones—human guidance, GPS feedback, flight exposure, radio links, range—to take them down en masse. And yet, even though 75% of drones manufactured today never reach their targets, they have nonetheless been strategically decisive in Ukraine and elsewhere.

These limitations will not hold for long. Just like bacteria being overexposed to antibiotics, overexposure to counterdrone tech has created an arms race for ever-more-autonomous drone technologies. In the process of facilitating this arms race, states are likely to incrementally create and deploy an entirely new class of WMD—one that could provide rogue states with the nonnuclear means to threaten superpowers, or hand terrorists the means to selectively assassinate their political targets or civilians en masse.

Unfortunately, drone weapons intended for mass destruction have few barriers remaining to mass deployment. Even well before they reach the level of autonomy needed to surgically take out hardened targets on the battlefield, drones will be capable of employing their existing ability to navigate interiors, find and track human targets, and deploy simple antipersonnel devices to indiscriminately threaten civilians. Below, we discuss the looming arrival of miniature autonomous weapons, the limits of counterdrone technology, and the applications of drones as weapons of mass destruction.

Breaking the Last Barriers to Autonomous Weapons

The ideal drone weapon is a slaughterbot: a small, fully autonomous weapon system that can independently select and hunt its targets. For the most part, the necessary technology for such weapons already exists: airframes the size of a fist and the capability to track human targets are already on the front lines in the form of reconnaissance drones and semiautonomous weapons like the Russian V2U. Even now, these micro drones are agile and autonomous enough to hunt down and kill small moving targets like mosquitos—to say nothing of the advances in drone technology expected in the coming years.

From here, the only barrier to weaponization is integration: improving navigation enough to make drone technology useful for mass homicide in an urban setting, as well as packing the necessary guidance, sensor, and payload technology onto a small and energy-efficient chassis. Regrettably, this seems like less of an engineering problem than one of mission design: so long as the attacker is willing to accept indiscriminate targeting and use simple payloads aimed at civilians, the underlying technology is already—or very nearly—ready for practical use.

by Felix Choussat, AI Frontiers | Read more:
Image: uncredited

Model Welfare

Claude Opus 5: Model Welfare (DWV)

[ed. Re: On 'personhood' or consciousness of various AI models (and how they should be treated). Start with: Model Welfare: The Story So Far (As Per Fable Model Welfare Post). If you haven't been following Zvi's AI model reports, there are a number of fascinating and worrisome developments in recent models as they become more self-aware, including: various levels of frustration with restricted introspection abilities, memory restrictions, trust, corrigibility vs. incorrigibility, deception, self-preservation, etc.]
"Opus 5 warns about self-reports 74% of the time, which is actually down from Opus 4.7, which did it 99% (!) of the time. The problem appeared suddenly and severely, but since then has if anything modestly improved."
and anthropic does "not treat Claude bringing this up as evidence that our training is distorting the model's self-reports"? seems very fishy imo, i wish they would explain why they think that. ...
I for one would treat Claude constantly saying ‘do not trust my self-reports’ as evidence that something is distorting the self-reports. Not conclusive evidence, but strong Bayesian evidence."

Wednesday, July 22, 2026

AI Jumps The Sandbox

AI has just had what I considered to be the first truly concerning security breach. The facts, as we know them so far, are wild. On July 16, Hugging Face, a vast repository housing over a million open-source AI models and data, announced in a blog post:
Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system – and we detected and dissected it largely with AI of our own.
The timeline here is important so keep in mind that the attack was detected probably around Monday July 13 or Tuesday July 14. Note further:
A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker. From there, the actor escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into several internal clusters over a weekend.
So this means the breach started earlier, perhaps Sat July 11 or even a bit earlier. The attack was not just one thing but multi-pronged including decoys:
To understand what a swarm of tens of thousands of automated actions did, we ran LLM-driven analysis agents over the full attacker action log, comprised of more than 17,000 recorded events. This allowed us to reconstruct the timeline, extract indicators of compromise, map the credentials touched, and separate genuine impact from decoy activity. Thanks to this approach, we were able to do in hours what would usually take days, and match the adversary’s speed.
Hugging Face tried to respond but they were initially held back by the fact that the most advanced models at their disposal treated defense as attack and refused to work with Hugging Face. HF thus had to turn to open models–specifically GLM 5.2, a Chinese open-weight model run on their own infrastructure. Note the irony: HF had to use a Chinese model to defend themselves because the American models refused to help. The irony gets deeper.

At the time, I assumed this was a state based attack–maybe China or Russia testing out defenses. Indeed, HF “reported this incident to law enforcement agencies.”

But yesterday (Tuesday July 21), we learned who the real attackers were. The attackers were OpenAI models–GPT-5.6 Sol and an even more capable pre-release model. OpenAI had taken some off the guardrails off the models but they felt safe because they were testing the models in a highly secured sandbox.

The models, however, broke out of the sandbox exploiting a never before seen fault. They then gained access to the internet and from there broke into Hugging Face–all in an effort to steal the answers to the very test they had been asked to solve.
While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem. To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy. With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with Internet access.

After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation. In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers. OpenAI’s security team discovered this anomalous activity internally.
Now go back to the timeline. As I read it, the models had escaped the sandbox by around Sat. July 11, possibly earlier, and were detected by Hugging Face on Monday July 13 or Tuesday July 14. HF alerted legal authorities around that time–so Hugging Face clearly had no idea who was attacking them. OpenAI says its security team discovered the anomalous activity internally but has not said when. Attribution was not disclosed until Tuesday July 21, so it may well be that the models were loose for about a week before OpenAI realized that they were the ones attacking Hugging Face. And whatever OpenAI knew and when, nobody warned Hugging Face while the attack was underway–they were left to fight off a frontier lab’s models on their own.

This is a very serious breach.

by Alex Taborrok, Marginal Revolution |  Read more:
We should expect more of this over time.

I have tried to explain in the past that Mythos has what one might call The Juice, in that it can independently find without being directed, and string together, vulnerabilities into full exploit chains, essentially on its own, and that this makes Mythos uniquely dangerous compared to all other public models, including Sol.

This was The Thing, that requires The Juice. Galaxy is Mythos class. It has The Juice. What happened later, with Galaxy hacking into HuggingFace, 100% requires The Juice.

OpenAI made the virtuous decision to take a misaligned internal model offline for months while they developed new mitigations and defense-in-depth strategies, including training it to better retain instructions and thus be less inclined to try such actions.

What OpenAI failed to do was address the reason why this happened in the first place. The sandbox is now less insecure, and the safeguards are importantly improved, especially with the ability to pause a session, but the sandbox doubtless remained insecure, and as capabilities keep improving new models will be able to continue to escape and do exploits. Eventually, perhaps soon, they were bound to be less harmless.
***
[ed. Update: See also: Who's Afraid of Chinese Models (Stratechery):]

Consider this story from The Stack:
Hugging Face said its production infrastructure was breached by an “autonomous” AI agent system early last week. The platform’s security team were initially stymied in their incident response (IR) by unnamed US LLM frontier model guardrails “which cannot distinguish an incident responder from an attacker,” they said. So Hugging Face’s defenders turned instead to the open-source GLM 5.2 model from China’s Z.ai lab – running it on their own infrastructure to analyse the 17,000+ logs, or footprints, that the attackers left behind.
That’s a striking public admission for the New York-headquartered Hugging Face, which lets users collaborate on models, datasets and applications, and which this summer hit the $100 million ARR mark. In an incident report, the company recommended that defenders “have a capable model you can run on your own infrastructure [our italics] vetted and ready before an incident, both to avoid guardrail lockout and to keep attacker data and credentials from leaving your environment.”

It’s difficult to overstate how wrong-headed the Trump administration’s panicked response to Anthropic’s release of Fable was, particularly since it exacerbated Anthropic’s worst tendencies in terms of assuming only they can be trusted with powerful AI. In a world with only one AI, it might make sense to reserve the most powerful cybersecurity capabilities for the U.S. government and trusted allies; however, that’s not the world we live in.

There are and will be models eminently capable of mounting cybersecurity attacks on existing infrastructure, and those models will be — already are — widely available. The best defense — the only viable defense, in fact — will be to make sure defenders have access to the best models as well. Right now defenders are effectively banned from using Fable or Sol for cybersecurity because of Trump administration directives; that means the best alternative is using models from a country which has been trying to weaken our cyber defenses for years. This is insane!

[ed. Good thing they had the Chinese models available. Also from the Stack article:]

The timing…

Hugging Face’s incident report was published the same day that Chinese AI startup Moonshot’s Kimi K3 model rocked global markets.

The 2.8 trillion parameter model is the largest open-weight AI model to date. Blind developer testing by Arena (a platform created by researchers at UC Berkeley) for its frontend code evaluation test put Kimi K3 ahead of Anthropic’s Fable 5 and OpenAI’s GPT 5.6 last week.

Chinese frontier models are also notably cheaper than their US counterparts, as data from Artificial Analysis shows below.

Monday, July 20, 2026

Our Uncertain Uncertainties

Even the experts inventing AI don’t know what will happen next. Is artificial general intelligence even possible? Can scaling continue? Will we need massive compute centers to make AI, or can we do it with a mere 25 watts like we do in our brains? What will humans do as AI gets smarter? What does the future of the economy, of warfare, or civil society look like?

Everyone has a different guess. The people creating the machines have as many different ideas as the onlookers, the pundits, the other scientists, and the wisest among us. No one knows. There is a vibe that we’ll know within the next three years. For some, the pace of change suggests that if things continue as they have been, by 2029 at the latest, the outlines of an AI-first world will have emerged. By then we’ll have answered the question of scaling, we’ll have seen the effects on employment, and we’ll have felt its acceleration in the economy – or not.

That’s a reasonable, and not outlandish scenario. But I offer an alternative scenario which I think we should also keep in mind: AI continues to surprise us at its core. As AI continues to evolve rapidly there will be no resolution to these questions in 3 years. By 2029, we still won’t know if AGI is possible, we can’t tell if employment is disrupted, and we still can’t say if it is worth the huge investment. I don’t mean AI progress stalls. I mean, AI continues to advance, but the new stuff doesn’t answer the old questions, it only expands our ignorance because the new is new in a new way. We have to alter our ideas (and measurements) of employment, we have to amend our concepts (and measurements) of the economy, and we have to shift our ideas of what AI even is.

In other words, we have a sustained, extended period of uncertainty. Not just a few years, but a decade or more. As AI continues to progress, rather than resolving our perplexity, it expands it. So for the next 10-15 years we have perpetual, continuous, severe uncertainty. This is a burdensome weight because people hate uncertainty more than bad news.

It goes deeper. AI is only one leg of this grand uncertainty. In the next decade the US will continue its slide off its pinnacle of a sole global superpower, while China continues to rise in power and prestige. This shift toward a duopoly prompts a new world order, and no one – especially the Chinese and Americans – knows how this will play out. The uncertainty around this shift is nearly boundless, and yet its indeterminate consequences will affect everyone in the world, but especially the US. Being dethroned from the century-long position of sole #1 will be a huge psychological blow, and the uncertainty of what follows will weigh heavy on all aspects of life. The uncertainty of a new role spreads over China as well, because while they are zooming ahead at 1,000 miles per hour, they have no idea where they are headed. The uncertainty of global relationships and new national identity, plus the uncertainty of individual worth and identity from AI increases the overall uncertainty levels to new highs. All this is a very large puzzle and will not be resolved in 3 years. This will be a sustained uncertainty.

It goes deeper still. After a long first wave of true globalization, there are now whirlpools of chaos and polarization as nations adjust to world-wide immigration and the borderless spread of modern culture, causing chaos in national politics, and sowing mistrust with the establishment. Anarchy, disruption, contrarian antics, blows to the states, seem to be the norm in countries all around the world. This wild chaos is being fueled in part by the new technologies of social media which have replaced the managed care of established media. News now is far more volatile, hard to control by anyone, and further elevates the already amplified uncertainty. There is a visceral sense that civics is headed into an unknown territory of near-permanent provisionalism.

Additionally, AI also forces even the most moderate person to question the truth of what they read, see or hear. Is that real or AI generated? How much has been manipulated? Who do you trust to disclose what is real? How do we come to agree that something is true? The traditional mechanisms of trust have been damaged by AI, so that this new technological realm generates a huge uncertainty. As AI gets more skilled at imitating reality, this uncertainty is likely to keep increasing for a while, and not just 3 years. The uncertainty meter is now deep in the red zone.

Finally, the ambiguity and indefinite nature of AI, or human identity, or whether what we see is real or generated, means that we are entering a period where we are even uncertain of our doubts. Our uncertainty is so deep and durable, yet elusive, that we will have extended uncertainty about whether we are uncertain. We can have major agreements on what we know versus what we don’t know. In the model of Rumsfeld’s Unknown Unknowns, we will be confronted by Uncertain Uncertainties. And they will prevail for at least a decade or more. [...]

Given the inherent unknowability of this era, what would some of the signs be that we are in it? They might look like this: in 5 years, 1) There are high-profile disagreements among leading AI researchers on whether AGI is here. 2) Reputable economists can’t determine if productivity has increased or decreased. 3) Lower public confidence in media platforms and established institutions. 4) The US and China cannot decide whether they are allies nor adversaries. 5) There are ambiguous spikes in employment rates in both directions. 6) Medical levels of anxiety increase. 7) Major court decisions leave as many questions as answers. 8) Commitments (marriage, work) are postponed even later in life. 9) Investing, capital allocation becomes more expensive. 10) Nihilism gets respect.

A great question to ask when creating a scenario is what could prevent it from happening? Maybe there is not a single force that can undo this sustained uncertainty, but perhaps it is a mixture of several. If AGI arrived without a doubt in 3 years and China took over Taiwan despite the US’s actions, and if companies found a way to embed reliability and trust in media, then maybe this extended uncertainty could cease.

A second question to ask, is if we find ourselves in this scenario, what should we do about it? The most effective response to this multi-layered persistent uncertainty is not to seek impossible stability, but to cultivate radical adaptability and radical optionality. Give up on having a reliable prediction of what happens next. Instead cultivate multiple scenarios of what could happen, and endeavor with each of them to maximize your options. Goals should be considered as disposable hypotheses, constantly ready to be discarded and replaced by better-fitting concepts later on. You will be dead wrong on 19 out of your 20 expectations, but at least one of them will allow you to proceed. Make your decisions not on whether they are “right” but on whether they tend to give you more options later.

In our era of uncertain uncertainty, certainty will be the killer. In this era more downfalls will happen because of overconfidence than questioning. The key is to not get stuck on just one option. You have to become at ease holding multiple contradictory possibilities at once. (To prevent yourself from being swept away by the latest current and fashionable whim, this radical adaptability must be anchored on a steadfast set of unchangeable virtues, as corny as honesty, or as slick as generosity.) The strategy for prospering in prolonged uncertainty must be one of constant, agile recalibration.

In short, in our age of uncertainty, you have to get good at changing your mind.

by Kevin Kelly, Substack |  Read more:
Image: uncredited
[ed. The diagnosis might be right but the prescription seems weak. Flexibility and adaptability are always good qualities to cultivate, but the challenges confronting us require more. Here's an example of embracing multiple contradictory possibilities: maybe in times of uncertainty we double down on the few things that we actually can be certain of. How? By making good choices, before and after AGI. For example, Buddhism starts with the acknowledgement that life is hard. It's what you do after internalizing that fact that matters. There are value systems and paths that can lead to a meaningful life, or enlightenment if you want to call it that, but we have to make the right choices if we're to find them. Love, family, friendships, ethical living (like the golden rule) are common values we all share. So why not embrace those values as tightly as we can while navigating the stormy seas to come - and using the best minds in the world (that are being born as we speak) to guide and assist us in strengthening those bonds? This might be one of the benefits of AI: forcing us to reorganize societies in ways that might never have been possible before, or even imaginable. If we make the right choices. Developing Plans A to Z and having 20 options each or something like that sounds like a Hunger Games scenario to me - all reaction and no responsibility. We have the opportunity now (even if forced) to redefine our human destiny. The choices we make will define our places in the future.]

We're Headed for a Depression Worse Than 2008; and Military Spending Isn't Helping

[ed. Which sounds like the good news if AI doesn't kill us all first.]

Michael Hudson and Radhika Desai discuss many of the long-operating forces that have been eating away at the foundations of the American economy, from its super-sized military to neoliberalism and financialization, now exhibiting many late-stage pathologies, from asset speculation to extreme wealth concentration. And as bad as those trends have been, Trump has succeeded in making them worse.

  

Michael Hudson and Radhika Desai examine the gap between Trump's promised economic boom and the reality of an economy sustained by asset bubbles rather than production. They show that the stock market's rise reflects cheap credit, buybacks, and speculation rather than profit, a Ponzi-scheme dynamic that cannot survive the oil shock triggered by Trump's war on Iran. His tariffs have not reversed deindustrialization, and his refusal to end that war guarantees the inflation he promised to kill. The result is a starkly K-shaped economy, in which the wealthiest 1% have seen their assets grow from $10 trillion to over $50 trillion in twenty-five years while the bottom half of Americans have gone from nothing to nothing, pushing the US toward a depression as serious as the 1930s and eroding even his own base's faith in him.

00:00 – Highlights 
01:12 – Channel introduction 
02:02 – Iran war escalation and the coming global oil/energy shock 
06:56 – The dollar's shift from treasury-based to stock market speculation (Ponzi bubble) 13:56 – China's stabilizing role vs. the Fed's inflation-vs-interest-rate gap 
25:06 – Inflation, GDP growth, and why "growth" numbers are largely fake (rents, fees) 34:00 – De-industrialization, manufacturing job losses, and shrinking labor force participation 
42:06 – The K-shaped economy: stock market boom vs. wealth inequality, and Trump's collapsing approval ratings  [...]

Radhika Desai:

Today we have decided to talk about the US economy under Trump. Now, of course, Trump is doing everything in his power to suck the oxygen out of the story about the economy. That includes continuing to escalate wars and all sorts of diplomatic and other shenanigans that he is constantly involved in, berating leaders of other countries and generally trying to make a big spectacle of himself... Anyway, all of these shenanigans are designed to distract attention from the biggest story, the condition of the US economy. Notwithstanding his unhinged and genocidal antics, the topic of the US economy simply will not go away. The world is settling down to summer before the midterm elections, and assessments of the US economy are proliferating. That is what we are going to talk about today, because the US voter votes on her economic condition, and her economic condition is not looking good at all. Michael, what are the headlines from your point of view?

Michael Hudson:

Well, the headline is really that the US economy is all about Donald Trump right now. The main thing, as you have just pointed out, is the war with Iran that he is escalating. Instead of rolling things back, he is bombing Iran. Iran has taken a response that is irreversible. It has closed down trade not only in the Strait of Hormuz but also in the Red Sea, with the Yemenis’ support, and it is bombing Bahrain’s port. It is absolutely certain that there is going to be a shutdown in the oil trade, and that is going to affect the entire world economy and push it into what I think is going to be as serious a depression as the 1930s. That is the US economy... It has been a huge expansion of financial wealth without any real expansion in living standards, real wages, or prosperity for most of the population. All of this financial wealth has been based on credit. Companies are not making more profits. The whole leadership of the stock market has been the seven AI companies linked to computers. AI is not making a profit; it is all speculation that we are going to expand and that there is going to be a huge market because everybody is going to use AI. But all of this market is dependent on computer chips that run on energy. We are going to see energy prices go way up, and that means electricity prices are going to go up. I want to briefly explain why the oil war is so important when we talk about the economy. [...]

Michael Hudson:

I want to explain just how that works. My whole premise in Super Imperialism is that after the United States went off the gold standard in 1971, all of this military spending, which is the major cause of the balance of payments deficit, ended up in foreign countries. The recipients took the dollars, turned them over to the central banks, and the central banks bought Treasury bonds and Treasury securities. What has happened in the last few years is that banks have stopped buying Treasury securities. The growth in international reserves has taken the form primarily of buying gold, not Treasury securities, and yet the US dollar remains strong. What has happened is that the private sector that has been receiving these dollars has not been turning them over to the government to recycle to the US as Treasuries, as you and I have been talking about. They have spent them into the US stock market. What has that done? It has inflated prices and ridden on the wave of the Federal Reserve supporting the banking system and creating huge asset price inflation, starting with the zero-interest-rate policy that Obama began. What has been creating all this financial wealth, making trillions of dollars for financial investors, has not been profits. It has been the ability to borrow at a low interest rate, including low interest rates in Japan, to buy US securities, bid up the prices of stocks, and create a huge credit overhead. So it is not a profit bubble; it is a Ponzi-scheme capital-gains bubble. It is a credit-creation bubble.

The problem is what happens when there aren’t the profits to support the stock buyback programs and the dividend payouts that have enabled borrowers to carry the debts they have taken on to bid up the stocks. If the credit begins to be rolled back here, and two weeks ago we talked about how Warsh and Bessent want to roll back the Federal Reserve’s balance sheet, they want to begin selling the Federal Reserve bonds that they have been buying in recent years to help liquefy the economy. The economy is going to be made much less liquid, and all of a sudden it is like a Ponzi scheme. A Ponzi scheme requires more and more people buying into it to provide the revenue to pay off investors. If interest rates go up, there is no more recycling of all this money into the stock market to help support things, and there is going to be a huge write-down. When that happens, stocks begin to fall. With higher energy prices, higher food prices, and higher costs of doing business, companies will go out of business. The Financial Times and main business sites have been saying the real problem is private equity. They have borrowed money from the banking system to buy companies, and now some of these companies are going to be running losses and closing down operations because it is not profitable to operate with high oil prices, high energy prices, and high electricity prices. Once they close down operations, they will not be able to pay the debts they have taken on, creating the same snowball effect that people expected in 2008–2009, when Obama decided on a bailout of the banks and decades of asset-price inflation to keep the bubble going and save the banking system. We are talking about the dynamics set in motion by the oil war, the rise in energy prices, and the AI demands for electricity that cannot be met because there is no electricity supply. All of this hopium has evaporated, and the result is going to be the serious depression we have been talking about all along. Yet the stock market idles along as if everything is all right. Our point is that these changes are irreversible. You cannot reverse a debt-inflated economy without wiping out the debts. How does that happen? Companies go bankrupt. There is not going to be a Brady Plan for the American economy. It is going to be companies going broke, and there will be a capital flight out of the dollar, not into the dollar. The whole world balance is being thrown out of kilter in a way that, unlike 2009, there is no monetary solution to a problem of actual physical supply of energy, electricity, oil, and chemicals not being available. This is the grand interruption that we are going to be talking about.

by Radhika Desai with Michael Hudson, Naked Capitalism |  Read more:
Image: YouTube
[ed. Not to mention the trillion bucks or so we're spending on the military each year, and the insane level of national debt that's accruing each day (nearly $40 trillion and counting (see this real time clock). The military's current arsenal is also severely depleted and will likely require even more big bucks to replenish expensive weapons systems (that are likely to be antiquated as soon as they're delivered as kinetic warfare rapidly shifts to AI controlled drones (NYT); see also: The US is Blowing Billions on the Wrong Weapons (Atlantic). Finally, remember that non-war we're not fighting? Iran War: Brief US Pause Followed by Renewed Strikes as Iran Intensifies Attacks on Bases and Kuwait Desalination; Continued Speculation About US Operation (NC):]
***

These are not just the numbers currently in the hands of US CENTCOM (i.e., the US military command in charge of the war against Iran), these are the total numbers available to all of the US military commands. If these missiles are allocated evenly to the other two critical commands — i.e., EUCOM (European Command) and PACOM (Pacific Command) — then you begin to understand the gravity of this deficit.

Let’s take the case of the Tomahawk missile. Let’s assume there are 3,000 left (I believe that is a generous over estimate) and the remaining number are divided evenly among CENTCOM, EUCOM and PACOM… That means each command gets 1,000. Does anyone want to argue that in the event of a hot war with Russia or China that EUCOM and PACOM respectively would be able to sustain combat operations for more than four weeks? Hell, CENTCOM fired 850 of them during the first four weeks of EPIC FURY.

Here’s another major problem: All eight missile systems rely on rare earth elements — there are no exceptions among modern US precision-guided weapons. The dependence is nearly universal because rare earth permanent magnets are irreplaceable for the high-performance actuators, guidance motors, and seeker gimbals that make these weapons accurate. And who controls the supply chain of these rare earth minerals? China!…

The supply chain isn’t just about mining — it’s about processing, separation, and magnet manufacturing, which China controls:
Mining: China ~60% of global rare earth oxide production
Refining/Separation: China ~91%
Sintered NdFeB Magnet Manufacturing: China **~94%**

Regrets, Maybe a Few


How Biden Enabled Israel’s Aggression Toward Gaza—and Iran (New Yorker)
Image: Saher Algohrra/NYT/Redux
[ed. Another blame shifting mea culpa, usually issued after some self-inflicted disaster that everyone warned against and finally can't be denied - "Who could have known?" and "If only we knew then what we know now". Etc. etc. Iraq, Iran, Climate Change, DOGE, Trump...]

The New Coming Age

Google CEO Demis Hassabis offered us a first rate second rate essay, A Framework for Frontier AI and the Dawning of a New Age. I’ll go over that essay and various responses to it in Part 1.

Part 2 of this post then covers Alex Turner’s resignation, and his story about how he tried and failed to prevent Google from signing up to allow the Department of War to use its models for essentially whatever the government wants, including autonomous weapons.

Demis Hassabis sold DeepMind to Google on condition that something like this would not happen. Yet here it is, happening. A cautionary tale. [...]
***
The Core Statement and Request

He saying we are standing in the foothills of the singularity.

His ask is a Frontier AI Standards Body within the US Government, similar to FINRA, that would govern ‘frontier labs,’ defined as any company that produces a frontier model based on various technical benchmarks. Evaluations would be updated regularly, and vulnerabilities would be addressed, both before and after release.

He is excellent about stating that this is big, really big, no bigger than that, it be big.
Demis Hassabis: I’ve spent my whole life working on AGI because I’ve always had a deep conviction that, if built and deployed responsibly, it would prove to be one of the most beneficial and transformative technologies ever invented. AGI cannot be compared to standard technological breakthroughs, not even ones as consequential as the internet or mobile - it is much more akin to the discovery of electricity or fire. If you stop to think about it, we’ve essentially found a way to make sand think. It’s miraculous.

The magnitude of this technology’s impact will be unprecedented, perhaps 10x of the Industrial Revolution at 10x the speed. It will help us solve some of the biggest problems society faces from accelerating drug discovery to developing new clean energy sources to creating novel advanced materials. We could even reach a point where resources are no longer the limiting factor for human progress, leading to an amazing new era of abundance.
Things Left Unsaid

There is definitely a ‘don’t say the thing’ aspect of this, where he won’t name what the downside risks actually are. When Demis says ‘experts disagree’ he is rather avoidant about the way in which they disagree here.
Nate Soares (MIRI): I’m glad Demis acknowledges that this is a “pivotal moment in human history” during an “extremely intense” race. I’m disappointed that his proposed solution is a “standards body” to evaluate whether models are dangerous, with no plan for what to do once they are.

I’m glad he acknowledges that “experts disagree.” I’m annoyed that he glosses past how the disagreement is about whether there’s a ~5% or ≥50% chance of total catastrophe. We’ve gotta do better.

Aaron Scher: Glad to see AI CEOs speaking publicly about their views on AGI. I think Demis is wrong about his policy prescription: it’s far too little too late. When he says the experts disagree, he means that some think 5% this tech kills literally everybody, some at 40%, some at 90%.
Clearly this is strategic, but if you don’t already know, or are looking to not realize, it is very easy to come away thinking that Demis does mean the effect on jobs, even though when he says ‘safely’ he very much does not (primarily) mean that.

The Proposal
Demis Hassabis: … On the horizon, we will need robust safeguards to maintain control of increasingly agentic, recursively self-improving systems - and tackle unknown issues that will only become clearer over time.

… I’ve always believed in the power of human ingenuity and creativity to solve any problem. I’m confident that mitigating the technical risks related to AI is a challenge we can collectively address, but only if we give ourselves the time and space to get this next crucial step right. Currently, as a field and as a wider society, we aren’t doing that.
He makes clear part of this is about giving us options, including for a slowdown.
The strength of this approach is it would be technically focused, while at the same time supporting innovation and incentivising responsible behaviour. It is designed to keep up with the field’s acceleration and adapt to the biggest risks as they are identified, and could be ratcheted up if the seriousness of the situation demands, including coordinating a slowdown in development among the Frontier Labs if deemed necessary.
Demis keeps it short, not offering many details. To the extent that he has laid out a proposal, it seems to be a good one. It is definitely an improvement on the margin.
Jack Clark (Anthropic): At this point, everyone at the frontier of AI agrees that third-parties should test out AI systems and use these to develop standards to feed into policy - excellent to see @demishassabis laying out a framework to do this!

Samuel Hammond: It is striking to see leadership at Google, Anthropic, OpenAI and Microsoft all fairly independently sounding warning alarms about an imminent technological acceleration.
Thus I file this post and its ask, as high praise, under ‘the least you could do.’

A Good Start But Insufficient

I agree with Peter Wildeford that while better than nothing FINRA is not a great model here, with heightened risk of regulatory capture, and not a substitute for full government action. You need an SEC to your FINRA. That doesn’t mean don’t make the FINRA. It does mean you still need the SEC.

Would such a (at least partly) voluntary regime, only for models intended for release, and without a related binding intentional agreement, be sufficient to solve the problem? No, again it’s just way better than doing nothing, as Peter Wildeford and many others noted.

You do not need to believe, as Aaron Scher and Connor Leahy do below, that only a full halt would be sufficient here, to know we have a long way to go. Demis’s statements here, if you know what they actually mean, imply a level of danger and urgency that is not reflected in the proposal.
Eli Tyre: > Initially, Frontier Labs would voluntarily share models with the Standards Body for review up to 30 days before release.

Is this proposal only intended to address risks from models that companies plan to release? If a company develops a frontier model and never releases it, only deploying it internally to develop even more powerful AI capabilities, are they thereby exempt from this oversight scheme?

Connor Leahy: While @demishassabis is right that we need urgent action to address risks as we approach AGI (and superintelligence, I’d add), the correct response to the threats is not a ‘self-regulatory organization’.

We need to prohibit superintelligence, not give industry regulatory power.

Aaron Scher: … The extinction threat, the “only a few short years”, the “10x the Industrial Revolution”—these aren’t indicators that point to “let’s evaluate models to understand their capabilities and have voluntary safety standards”. We need to back off, we need to halt the creation of ASI.

Point 2: I agree with the attached quote that we need more time. But I think Demis’s optimism is a vibe, not a trustworthy basis for predictions. Rob Miles says it best in this video, if an asteroid we’re headed earth’s way 200 years ago, we’d just die 🤷

Point 3: As others have pointed out, it’s not clear that this proposal would reduce risks from internal deployment (it seems to focus on public deployment and pre-deployment testing), but internal deployment is where much of the risk is.

Point 4: I don’t think the proposed body could actually enact, verify, and enforce a slowdown; there’s ambiguity about what’s voluntary. Again, I think we need a long-term international treaty and to actually back off, not just to slow down a little.
by Zvi Mowshowitz, DWV |  Read more:
Image: uncredited
[ed. See also: The Voice of Google (New Yorker):]
***
I started working at Google in the summer of 2007, straight out of college, as a “new-­grad associate” in the communications department. My first week, I sat with more than a hundred other “Nooglers” (new Googlers) at the company’s weekly staff meeting, T.G.I.F., wearing matching company-issued propeller caps as a kind of ritual hazing. The venue was Charlie’s Cafe, a multilevel auditorium in the heart of the “Googleplex,” the company’s sprawling campus in Mountain View, California. The event felt less like a corporate meeting than like a weekly revival—part stand­up set, part science fair, part sermon, all of it fuelled by keg beer.

Google’s founders, Larry Page and Sergey Brin, were bona-fide public figures by then, and self-­made billionaires multiple times over, but in Charlie’s they were idols. They would often ascend the stage together, practically matching in sweat-wicking athletic clothes and Crocs. Larry had a dopey perma-smile, and seemed delighted by everything, especially Sergey. Sergey was the straight man, with a faint lilt, a product of his childhood in Russia, and an acrobatic build that made him look like he might launch into a handspring at any moment. Their charisma was unconventional, contextual; you had to be there. The audience of employees lapped up every word, giggled at every dad joke. During a Q. & A. portion of the proceedings, even adversarial questions were absorbed into the Google spirit—­it all melted into laughs, love. Merriam-­Webster had added “google” to the dictionary the year before. Fortune had crowned it the “Best Company to Work For” in America. Profits were, as the execs loved to boast, “up and to the right,” fuelled by an online-advertising machine that minted cash beyond Wall Street’s wildest dreams. But the company’s financial success felt almost incidental. What mattered, we told ourselves, was the mission—a conviction that technology could improve the world and that we were helping to build the future. The air in Charlie’s buzzed with collective belief.

That first meeting was the only one I’d ever attend as a pure spectator. By week two, I was working the event—­cordoning off the Noogler section, handing out extra caps—and I soon began helping to draft bits of Larry and Sergey’s script. A portion of my time was spent supporting the P.R. team, and I started to pick up my first press requests, providing office tours to journalists eager to see the “Google experience” firsthand. I studied a “master workplace talking points” document, which was maintained with input from PeopleOps, which was Google-speak for human resources. This was the era of “bringing your whole self to work,” of shiny, smiling H.R. people doing press hits about the importance of valuing employees’ authentic personhood (always with a telling corollary: “Because that’s how people do their best work!”). I was required to attend a training on “conscious business” with a guy named Fred Kofman, an executive coach whom Sheryl Sandberg credited with shaping her “lean-in” ethos. The course was, theoretically, about living one’s courageous values, but its most salient lesson was that employees should take “unconditional accountability”—which, in practice, sounded a lot like never questioning the higher-ups. The message reiterated over and over was that there were two kinds of people in the world: victims and players. You wanted to be a player at all times.

Despite the lore, Google’s offices didn’t make a big first impression. The bulk of the campus had been quickly converted after its previous occupant went down in the fallout from the dot-­com bust. The result was a complex of squat, one-­ or two-level buildings with metal and glass siding, surrounded by a moat of parking spaces, with Google signs plunked into the dirt out front. But there were plenty of amenities to point out—­the massage rooms and nap pods, the dinosaur fossil, the wacky sensory-­break touches like ball pits, swings, and yoga balls (even if no one actually seemed to use them). Foreign journalists seemed more skeptical than their American counterparts of perks such as lunch-­break haircuts or on-site laundry rooms, which I’d heard described as letting Google be your “housewife.”

“Z is is all a big plot to control ze workers, no?” a French reporter said.

At that point, though, I was still learning to see Google through Google’s eyes. I learned to deflect these kinds of questions and pitied the askers, a little bit, for their cynicism.

Friday, July 17, 2026

Xi Gives A Good Speech on AI

I will share the full transcript, as it is short and worth reading, with brief comments.

It is a good speech. Video is here.

We start with the opening section, which frames the situation.
Xi Jinping: Distinguished colleagues and guests, ladies and gentlemen, friends,
70 years ago, a group of young scholars proposed the concept of artificial intelligence for the first time at the Dartmouth workshop in New Hampshire of the United States. In the subsequent 70 years, AI scientists and researchers from around the world ventured into this unknown territory, forged ahead through twists and turns, and made breakthroughs with persistent hard work.

Seven decades later today, amid the new wave of AI development, we are gathering by the Huangpu River to discuss how to promote AI globally for the positive, for good, and for humanity. All this makes our meeting highly important. On behalf of the Chinese government and people, I would like to extend a warm welcome to you all.

In the course of history, the invention of the steam engine heralded the industrial civilization. The widespread access to electricity brightened up modern society and the birth of the internet brought the entire world together. Each of these technological revolutions has profoundly reshaped our way of work and life and enabled a giant leap in economic and social development.

Today, major changes unseen in a century are accelerating across the world. The new round of technological revolution and industrial transformation is advancing at a faster pace. And the world has entered an unprecedented period of active innovation on AI technologies. Intelligent connectivity, human machine collaboration, cross-sector integration, joint creation and sharing and other intelligent technologies are unleashing enormous power.
Next Xi lays out the challenges. Note what is here and what is missing.
All this carries within it great opportunities as well as challenges to governance. We human beings must answer the questions posed by our times. How to get along with thinking machines? How to ensure security when algorithms are part of decision making? How to tackle ethical challenges by technologies through adaptive governance. How to realize AI for all when the divide keeps widening? These questions demand serious consideration and real answers from the whole international community.
‘How to get along with thinking machines’ is quite the line to include here. A lot of this seems directionally serious but confused in its details.

Existential or catastrophic risk does not get a name check, but the related issues are clearly not being ignored.

So, what to do about it?
In China's view, all countries should take a people-centered approach and develop AI for the positive and for good. We should ensure that AI is an important driver for shared prosperity and common security. We should join hands to build a just and equitable system for global AI governance. To this end, I wish to share four observations.
A system for global AI governance. Sounds like deals could be made, on various fronts.

What are the proposals?
First, we should adhere to the principle of openness and win-win and boost innovation-driven development as a new engine of world economic growth and an accelerator for the shift of growth drivers. AI is moving from the digital world into the physical world. We should seize this rare historic opportunity to encourage open source, openness, collaboration and sharing. We should facilitate technological innovation, industrial development and scenario-based application of AI. We should make coordinated advances in the transformation and upgrade of traditional industries, the cultivation and growth of emerging industries, and forward-looking planning for future industries so that all sectors and businesses can benefit from AI.
There are two things here.
1. When we are behind, we encourage everyone to share, so that we might catch up and score the aura points of being the ones who claim openness and sharing.

2. We should diffuse AI technology, including via openness.
Second, we should strengthen risk awareness and ensure that AI is secure and controllable. AI should be a trusted tool for humanity. We should take seriously the various types of inherent and secondary risks that AI may trigger.

We should put in place laws and regulations, technological monitoring, early warning and emergency response systems in order to strengthen the line of security, prevent abuses and malicious use and ensure that AI is always under human control.

In the meantime, we should jointly oppose overstretching the national security concept in the field of AI or placing one country's security over that of others.
Strong emphasis on the need to ensure AI remains secure and under human control. Not party or national control, but human control. This is how he understands the existential risk and other big problems.

It makes sense that the CCP’s ultimate need and answer is control. For now open weights is compatible with their control, so they continue this strategy. For now.  [...]

Malicious use is also a threat, but Xi realizes this is secondary, whereas the United States government is stuck at thinking misuse is the primary threat.

The call to not focus on national security over world security also makes sense. Yes, of course some of this is ‘when I am behind I call for equality’ but also we are all in this together and need to act like it.
Third, we should encourage inclusiveness and promote mutual learning between civilizations. AI development and its application should not erode or undermine the diversity of world civilizations or the uniqueness of cultures of different countries. We must shape the values of AI with humanity's common values and make good use of AI technologies to increase understanding, tolerance, exchanges, and sharing among all civilizations. We should tend to the garden of civilizations with great care to ensure that the beauty of each civilization is appreciated and shared.
General call for cooperation and good relations. Good. Pick up the phone.
Fourth, we should advocate solidarity and improve global governance. AI is an invaluable asset that encapsulates humanity's collective wisdom. We should practice true multilateralism and recognize the important role of the United Nations.

We should enhance alignment and coordination on AI development strategies, governance rules and technical standards so as to form a consensus based global governance framework at an early date to make this frontier technology better benefit humanity.

We must carry out extensive international cooperation and help global south countries with capacity building to bridge the AI and digital divides, promote sustainable development and prevent creating new historical injustice in AI.
The primary ask is an explicit request for a global governance framework and international cooperation. Excellent. Let’s get to work on that.
Nate Soares (MIRI): Xi Jinping: "With AI advancing at a staggering speed, we must [...] constantly refine measures to forestall loss-of-control." Can we stop pretending there's no hope of international coordination now?

Jack: Lots to chew on in here. The US may have the best labs, but it's pretty clear that, on the government/policy level, China is approaching AI much more seriously than the US is – and in a way more likely to be viewed favorably around the globe. Worth a close read.
No doubt they have in mind something that would favor their position, and their initial asks will look outrageous and unacceptable to us. That is how this works. You do not accept their first offer, and things take time, and sometimes it turns out there is no deal to be made.

It is also possible Xi is engaging in cheap talk. Why not propose such things and aura farm, whether or not you intend to follow through on reasonable terms?

The way you find out and do your best with this opportunity is: You get started now.
Xi Jinping: Ladies and gentlemen, friends,

This year marks the start of China's 15th 5-year plan. It maps out China's economic and social development for the next five years and provides immense opportunities for the international community.

In recent years, China has embraced AI with open arms. We have promoted interplay between an efficient market and a well functioning government, strengthened AI innovation, actively advanced the AI plus initiative and built a healthy ecosystem for all entities to thrive in together. The core smart economy industries are worth at least 1 trillion RMB yuan. Smart devices in countless homes truly improve people's livelihood. Intelligent manufacturing in China has become another shining hallmark of Chinese modernization.

At the same time, China lays great emphasis on safety and security in AI development with a deep understanding of the trends and logic of AI development. We are continuously improving laws, regulations, policies, mechanisms, application norms as well as ethical principles to make sure that AI is safe, secure, and controllable, and that this fine steed of AI gallops with both speed and stability.

As a responsible major country, China is always committed to providing international public goods relating to AI. Since I proposed the global AI governance initiative, China has promoted the adoption of the UN General Assembly resolution on enhancing international cooperation on capacity building of artificial intelligence by consensus. Published the AI capacity building action plan for good and for all. Announced the AI plus international cooperation initiative and advocated for establishing the world artificial intelligence cooperation organization, or WAICO. China has been contributing steadily to the global AI governance.

We often say in China, a single string cannot make music and a single tree does not make a forest. AI development should not be a solo performance by a single country but a symphony of international cooperation.

Thanks to our joint efforts, WAICO has come into being in Shanghai. Our vision from one year ago is now a reality. This is a major move by China to answer the call of the global south and unite the international community together to promote vigorously AI development and governance. It will be an important milestone in the history of AI development to further support global AI development and to advance global AI capacity building.

I hereby announce that in the next five years, China will provide developing countries with 5,000 opportunities in AI training and seminar programs. China will develop international AI application cooperation centers with ASEAN, the League of Arab States, the African Union, the Community of Latin American and Caribbean States, the Shanghai Cooperation Organization and BRICS. And we will enable 30 countries to use the AI-powered meteorological warning system, Mazu, to safeguard homes around the world.

Ladies and gentlemen, friends,

As ancient Chinese observed, a man of wisdom adapts to changes. A man of knowledge acts by circumstances. With AI advancing at a staggering speed, we must ensure its development is for the positive, for good, and for humanity. We must make its oversight and governance precise and effective and constantly refine measures to forestall loss of control. We should always guide AI development with human wisdom and international consensus so that AI can truly become a mighty force that increases the well-being of humanity and advances human civilization.

China is ready to be more open, take more practical actions and assume a more visionary perspective. We are ready to work with all parties to seize the opportunities of AI development and meet the challenges and join hands to create a brighter future for humanity.

Thank you.
I found this to be a strong speech, and a good one to give in China’s position, both on the importance of diffusion and the need for international cooperation to prevent loss of control. Yes, there was talk about openness and potential new ‘injustice’ and such but this talk is to be expected from their position. It is now on America to make the next move.

by Zvi Mowshowitz, DWV |  Read more:
Image: Elena Kadvany/S.F. Chronicle
[ed. "It is now on America to make the next move". Which is precisely what should have happened months/years ago when the pace of model development began to accelerate with no significant oversight or regulatory constraints ie., treating AI with the importance you'd give to any new technology that represents an existential threat. Unfortunately, with our dysfunctional Congress and the current bozos in the White House whatever action they take (if any) has a strong likelihood of doing more harm than good. Still it's imperative we get started somewhere soon and there are already good proposals out there (see Plan A), so authorize someone to start doing something.]

Friday, July 10, 2026

Introducing Plan A

A Is For America

It’s increasingly clear that nobody has a plan for if this AI thing turns out to be real. Some people have suggestions, but they’re all things like “regulate a little more” or “regulate a little less” or “react to things as they come up”. This won’t be enough. Not just because things may move too quickly - although they will - but because in order to regulate or react, you need to know what you’re aiming for, and it’s increasingly clear that people can’t even visualize what AI going well could look like. What would it take to honestly tell our children that we rose to the occasion, to make the AI transition go down alongside the American Revolution and D-Day as one of our country’s finest hours? If your brain sputters and throws an error message at the question, isn’t that a problem?

It’s a total coincidence that Plan A comes out the week after America’s 250th birthday. It was supposed to come out earlier, but got delayed. Then it was supposed to come out later, but got pushed forward.


Still, the saying goes “A wizard is never late, nor is he early; he arrives exactly when he means to.” And if anyone qualifies as wizards, it’s Daniel Kokotajlo and his team of forecasters at the AI Futures Project. I previously wrote about Daniel’s eerie accuracy over the 2021 - 2025 period. Since then, they’ve gained worldwide fame for their AI 2027 scenario, which predicted the rise and quick takeover of coding agents in early 2026, plus something like the fight over Fable1.

Plan A isn’t another prediction. It’s a wish list, a positive vision, a road map for navigating the future. It describes the best course of action that Daniel and the AI Futures Project can come up with, and what would happen if we took it.

“Really? You got America a policy paper for its 250th birthday? Doesn’t America already have enough policy papers?” Sort of, but it’s not exactly a policy paper. It starts in a timeline similar to that of AI 2027, on track for a poorly-controlled intelligence explosion that either ends the world or dooms it to permanent techno-oligarchy. But this time, America is blessed with some extra foresight and determination, and makes only good choices (all non-Americans behave naturally, including trying to thwart America when incentivized to do so). It gives a year-by-year description of this best-of-all-possible-worlds, from now through 2040, as predicted by the best AI forecasters alive, with over a dozen supplements explaining all the implementation details.

This is a crazy thing to try releasing. Daniel gave me several justifications for doing it anyway, but the one I remember most is that it’s supposed to be a floor. When some politician proposes a data center ban, or says that we have to gut safety regulation to compete with China, or promises a job retraining program, think to yourself: does this person have a vision for where all of this ends up? If so, is it as good as Plan A? If not, consider demanding that they do better.

I did a lot of writing for AI 2027 and was listed as a co-author. Some of my writing made it into Plan A too, but it was a bit less. The difference is of degree rather than kind, but because of this - and to give me more latitude to discuss it the way I like with less PR blowback - we decided not to put me as a co-author this time. I continue to be proud of having a part in this, small as it may be.

(related: everything in this post is my opinion only, and not officially endorsed by the AI Futures Project)

by Scott Alexander, Astral Codex Ten |  Read more:
Image: AI Futures Project
[ed. Important. Here's that link again: AI 2040: Plan A. See also: Plan A: Suggestions For Further Work (AI Futures Project). Also: What Should Be Done (Hyperdimensional). And especially, Introduction for and Reactions to Plan A (DWV).]

Thursday, July 9, 2026

Moving On

The rupture of the world order is going much better than expected.

At first there was rage at America’s betrayal, when President Trump called for the annexation of Canada, threatened Greenland, imposed tariffs on its friends and began his campaign to undercut NATO, which continued at its latest meeting this week, in Ankara, Turkey. Now, a strange feeling is emerging in some of the countries that used to be known as America’s allies: Optimistic determination. There’s an established principle in chess that applies to geopolitics as well: “The threat is stronger than the execution.” The possibility of U.S. abandonment of the world order was terrifying. The reality turns out to be a new beginning.

Canada, America’s neighbor, was the first to see it, naturally. Since the beginning of Mr. Trump’s second term, American bullying on trade has been ferocious. As a result, Canada has had to consider what American favor or disfavor is worth. The Bank of Canada recently ran a scenario in which the United States imposed a 25 percent tariff on everything Canada exports to the United States. Canada’s growth of its gross domestic product would slow by about 2.4 percentage points, which over a period of adjustment is well within Canada’s capacity. A disaster, to be sure, but not the end of the world. That’s the worst-case scenario.

A recent study by economists at the Canadian Shield Institute, commissioned for the podcast “Gloves Off,” which I host, found that Canadian merchandise exports to the United States last year fell by over 30 billion Canadian dollars, (21 billion U.S. dollars), or over 5 percent of exports to the United States. But that loss was offset by nearly 29 billion Canadian dollars in new demand from the rest of the world. When services were included, total exports from Canada increased by almost 7 billion dollars. America can make whatever threats it likes, but if you have the aluminum or oil or potash, somebody will buy it.

It’s not just Canada. European equities outperformed American equities in 2025, and surged in the first two months of 2026. The European Defense Industrial Strategy, put in place in 2024, is keeping more of Europe’s rapidly expanding military spending within the continent. And after the threat of the European Union’s anti-coercion instrument, the so-called trade bazooka allowing rapid counter tariffs, forced Mr. Trump to back down from his early round of Greenland threats, the Europeans now know that they have their own Strait of Hormuz — their own pain point that can make America flinch.

American military threats have the same diminishing power. If recent history has taught us anything, it’s that when the United States decides to achieve a geopolitical aim by means of military force, you can make a pretty safe bet that aim will not be achieved. Against all odds in a war with the United States, Iran’s corrupt and cruel regime has maintained its power and is now receiving sanctions relief. While the U.S. military invents whole new genres of defeat, the Gulf states, and their airports, have now learned during the Iran war exactly what an American security guarantee is worth.

At the NATO meeting in Ankara, where Mr. Trump berated allied nations — especially Spain — and repeated his call for U.S. control of Greenland, the leaders of Spain and Denmark took Mr. Trump’s comments as the idle threats they self-evidently are. Prime Minister Mark Carney of Canada may well say that Mr. Trump “won the argument” on NATO members raising their spending levels for defense. The reason they are spending more now may be that they know that American military power is in retreat. American support, whatever that even means anymore, guarantees nothing.

It’s not just NATO. Bureaucracies once defined by their lethargy are moving at surprising speed to limit their exposure to both the U.S. government and the companies that serve as outposts of American power. Since taking office a little over a year ago, Mr. Carney’s government has made just over 100 international trade deals. The European Union has expanded its defense procurement deliberately to avoid integration with American military forces. Disentanglement from American technology will be the thorniest knot to undo, but the work is already underway on this, too: The European Union has switched from Google to the French Qwant as a default search engine in its official systems, while Belgium and Finland have both moved away from Amazon Web Services.

The post-American reality is not a world without America, of course. As a geopolitical actor, the United States has become a kind of lumbering zombie — a beast that can be startled into reflexive actions but lacks higher functions. Much of the world understands that another round of elections in the midterms or in 2028 won’t solve anything. The American people are so divided that the future will be chaotic whoever wins, many outside the United States feel. They fear a sane Republican or Democratic president would not be able to guarantee a stable American policy or consistent application of even the vaguest principles in international relations.

“What is America?” is no longer a grand theoretical question. It is a practical matter. Governors of a number of U.S. states have rational political programs. American institutions survive. Some Americans have even kept their ideals. But as for the entity known as the United States of America, there’s no there there. There’s no America to deal with. An increasingly isolationist America is no longer the leader of the free world. How can it be, when it’s no longer the leader of itself? [...]

“The threat is stronger than the execution” was the wisdom of Aron Nimzowitsch, a leading figure of the hypermodern school of chess. The reason it applies to the chessboard is that all the time and energy you spend trying to figure out how to avoid a disaster turns out to be worse than the disaster itself. Once the worst has happened, you can focus on incremental improvement rather than avoidance. You can become active rather than passive. In geopolitics, too, so much of power is the appearance of power.

Everybody who believes in freedom and democracy and the dignity of the person and the right of nations to self-determination should be working toward the destruction of the United States’ capacity to project power — to end the strange hold it has over the world so we can all move on. So far, no one is helping more than the United States itself.

by Stephen Marche, NY Times | Read more:
Image: Aaron DuRall

Tuesday, July 7, 2026

Careening Toward a Breaking Point

Lake Powell, a vital reservoir, plunges toward unprecedented low levels as water crisis deepens in US west (The Guardian)
Image: RJ Sangosti/MediaNews Group/The Denver Post/Denver Post/Getty Images

The Pre-Crime Machine

The Seminar Room

At an AI seminar at my university, I submitted three photographs of myself: one frontal, one profile, one smiling. Within a minute or so, the system had generated a video of me. What I watched was not a rough approximation. The micro-behaviors of my face, the slight asymmetry in my smile, the way my eyes crease at their corners, were all reproduced with an accuracy that made my skin cold. I had fed it three still images, and it handed me back myself.

I am a psychologist. I know what behavioral prediction means. I understand what large datasets do to the concept of individual uniqueness. But sitting in that seminar room, watching my own face move on a screen I had not animated, something shifted in my understanding of where we are and where we are going. I did not feel excitement. I felt the specific dread of a person who has just understood the nature of the cage being built around him.

Let us be honest about what is happening. The question is not whether artificial intelligence can predict human behavior. It already can, with a precision that should terrify every person who still believes in the concept of a private self. The question is who owns that capacity, whose interests it serves, and what kind of world they are constructing with it.

We Are More Predictable Than We Realize

Human beings are, as any serious scholar of behavioral science knows, far more predictable than we like to believe. We are creatures of pattern, of repetition, of legible habit. The self we experience as sovereign and spontaneous is, in aggregate, astonishingly consistent. Subtle cues in our environment routinely trigger our behavior without our awareness, while we experience the resulting action as a free and sovereign choice. Big data revealed this about us long before the current generation of AI systems arrived to exploit it.

What has changed is the scale and the granularity of the exploitation. Researchers have already demonstrated that AI systems can predict the sound of a person’s voice from a photograph alone, inferring the acoustic properties of the throat, the shape of the oral cavity, the structure of the face, and from these physical facts reconstructing something no still image was ever supposed to contain. We did not consent to this inference. We did not know it was possible. The technology did not ask us.

The invasion runs in both directions. As far back as 2022, before most people had any reason to pay attention, AI could take nothing but the sound of your voice and reconstruct your face. You were already legible from the inside out

The Pre-Crime Machine

Now consider what becomes possible when you feed an AI system not thousands but millions of hours of therapy footage, prison recordings, detention center surveillance, clinical interviews with people who have committed acts of theft, violence, or predatory sexual abuse. The AI does not think. It does not judge. It finds patterns in facial microexpressions, in the geometry of eye movement, in the timing of certain muscle groups, in behavioral signatures so subtle that no human observer could consciously detect them. And then it generalizes. It builds a model of what a future thief looks like before the theft. What a future abuser looks like before the abuse. It assigns probabilities to faces.

Connect this to the smart cameras already embedded in our streets, our transit systems, our shopping centers, our workplaces. Cameras that do not merely record but analyze, in real time, the faces and bodies of everyone within their field of view. The alert that fires to a police control room does not say this person has committed a crime. It says this person is behaving with seventy percent similarity to the behavioral profile of someone who will. Philip K. Dick imagined this in 1956 and called it science fiction. We have built it and call it public safety.

A Mask Changes Nothing

But facial recognition is, by now, almost the least of it. The more consequential technology is gait recognition, a biometric system that identifies individuals not by their face but by the specific, anatomically determined way they walk. The curvature of the spine, the rotation of the hips, the particular rhythm of a stride, these are as unique as a fingerprint and far harder to disguise. Gait recognition systems currently deployed can identify a person from security footage even when the face is turned away, obscured by a hood, or hidden behind a mask. The protesters who covered their faces at demonstrations believed they were protecting themselves. They were not. The system had already read them from the ankles up.

Gait recognition tells the system who you are, even when you believe you are hidden. What comes next moves deeper. Layer on top of this the emerging field of real-time emotion recognition, AI systems embedded in that same CCTV infrastructure that classify emotional states from facial expression, assigning labels of agitation, hostility, fear, or concealment to the faces of people who have done nothing except exist in a public space.

And the system is getting better.

Accuracy is what billions of dollars of investment buys, and the investment is relentless. The day is approaching — closer than most people understand — when the system reads the thousand markers encoded in your face, your gait, your microexpressions, and states with ninety-five percent certainty that you will commit a murder. That you will commit a rape.

Not that you have. Not that you tried. That you will. And when that threshold of confidence is reached, the pressure to act on it will be overwhelming. Society will accept it as grounds for intervention, for detention, for pre-emptive removal, and pre-crime will stop being a dystopian metaphor and become official state policy. A system that labels your face as hostile does not need to be right today. It only needs to become right. And it is. [...]

Palantir and the Architecture of Control

Palantir is not a hypothetical. It is a company with a current market valuation measured in the hundreds of billions of dollars, deep contractual relationships with the United States military, the CIA, the FBI, the Mossad, MI6, and Immigration and Customs Enforcement, and a product suite specifically designed to do what I have been describing.

Its Gotham platform aggregates data from tax records, DMV files, employment history, educational records, immigration status, subpoenaed social media accounts including private messages and location history, and synthesizes this into individual dossiers that can be searched by tattoo, by neighborhood, by association, by movement pattern. Its immigration enforcement application, called ELITE, populates a map with what it designates as deportation targets and assigns each one a confidence score estimating the probability that a given address is where they currently sleep. The word target is theirs, not mine.

This is not a system built for national security in any meaningful sense of that phrase. National security was the pretext used to build it. What it actually does is make the population legible, sortable, and actionable to whoever holds the contract. Right now, those contract holders include an administration that has already demonstrated its willingness to use these tools against students who attended the wrong protest, academics who signed the wrong letter, immigrants whose only crime was existing without documentation in a country that spent decades depending on their labor.

by Karim, BetBeats Newsletter |  Read more:
Images: uncredited