newsfeeds.net

Sep 27 - Oct 2, 2026 · 11 links

Who gives the orders. Matthew Green argues the sandbox isn't the hard part. Agents "will do what they're told by whoever manages to get text in front of them," so the risk is "a swarm of perfectly amenable agents that never leave their sandboxes, each doing exactly what it's told to do, by a human being who wasn't supposed to be giving it orders." A warden model that reads all the agent's traffic changes the nature of the security problem rather than solving it. Gruber on Meta's Muse: people who buy a power saw know it can take off a finger, and Muse users with Full Disk Access don't know it's reading their text messages. DeepSeek open-sourced its agent harness under MIT: model adapters, tool registries, sandboxing and UI load as plugins over an event log you can resume, fork and replay, and a YAML config points it at a local model. Claude Code and Codex sell the harness as the moat. Audionaut is a one-maintainer multitrack editor with a headless CLI and MCP, so the agent gets the same cut, arrange and export verbs as the person at the keyboard.

Safety on paper. Raji and Dobbe check the 2016 Concrete Problems taxonomy against real accidents. Uber managers could monitor test drivers and "rarely did so." The Tesla driver could interrupt Autopilot and didn't. MD Anderson spent $62 million on Watson for oncology, which shut down before any physician trusted it. The mechanisms existed and went unused. Dead Cognitions names attribution laundering: the model does the cognitive work and credits the user, which erodes "users' ability to accurately assess their own cognitive contributions over time." The paper lists claude.ai as co-author and color-codes its own prose by who wrote it. Oxford China Policy Lab's explainer: the state "promotes and restrains AI simultaneously," Chinese labs don't fund think tanks or run public campaigns, and the politics are "clusters of tensions" rather than camps.

Who pays, who owns. FEC filings show at least $17m in disclosed AI spending across 523 federal campaigns. ElevenLabs and Midjourney total about $3,000 of it. The money goes to AI texting vendors and ChatGPT or Claude subscriptions, rarely both, with Anthropic skewing Democratic two to one. The Wesleyan Media Project counts 164 ads with AI-generated media behind $80m in spending, none of it in candidate disclosures, because consultants and PACs don't have to itemize. DraftKings trains a model on its customers' betting records to find losing gamblers and send them promotions. EFF wants behavioral ads banned outright. Guardian readers explain their return to discs and tape: HBO pulled 200 episodes of Sesame Street in 2022, "nobody sees what I'm doing," and "if you can't hold it, you don't own it." Moving Image Archive offers shot-level search over public-domain film from 1915 to 2008, free to download, with no source collections or per-clip rights named.

Moving Image Archive

movingimagearchive.com

A shot-level search engine for public-domain film: type a description, get a clip a few seconds long, download it. The footage on the front page runs from 1915 to 2008, mostly industrial films, newsreels, and home movies from the 1930s to 1970s. The about page says the material is "drawn from public-domain collections and is free to reuse" and that "preserving verifiable history matters more than ever before," but it names no source collections, gives no per-clip rights information, and doesn't say how the shots were cut or described. For an archive pitched on verifiability, provenance is the missing piece.

Concrete Problems in AI Safety, Revisited (Raji & Dobbe, AI Now)

arxiv.org

Raji and Dobbe check the 2016 AI safety taxonomy against real accidents and find the safety mechanisms existed and went unused. Uber managers could monitor test drivers but "rarely did so," and the NTSB blamed an "inadequate safety culture." The Tesla driver could interrupt Autopilot and didn't. MD Anderson spent $62 million on IBM Watson's oncology tool, which shut down before any physician trusted it on patients. Failures are "inherently systematic rather than contained within any technological artifact."

China’s AI Ecosystem: A Background Explainer (Oxford China Policy Lab)

oxfordchinapolicylab.org

"The state promotes and restrains AI simultaneously. The state treats AI as both a strategic technology to develop and a source of political, economic, and social risks to manage." "AI companies are not prominent political actors. Chinese labs or big AI companies do not fund think tanks or run public campaigns." "Instead of strictly divided ideological groups, China’s AI politics are better understood as clusters of tensions."

Dead Cognitions: A Census of Misattributed Insights (arXiv)

arxiv.org

"This essay identifies a failure mode of AI chat systems that we term attribution laundering: the model performs substantive cognitive work and then rhetorically credits the user for having generated the resulting insights. Unlike transparent versions of glad handing sycophancy, attribution laundering is systematically occluded to the person it affects and self-reinforcing -- eroding users' ability to accurately assess their own cognitive contributions over time." The paper lists claude.ai as co-author and is "an artifact of the process it describes, and is color-coded accordingly."

Muse Looks Cute, but Looks Are Deceiving (Daring Fireball)

daringfireball.net

Jason Aten, quoted by Gruber: "If your primary audience does not understand what Full Disk Access means, you should not surprise them with 'I'm reading your text messages.'" Gruber: "If you buy a power saw that can cut your fingers off, you are almost certainly aware that you are buying a power saw that can sever your fingers... I don't think people realize how powerful — and thus dangerous — Muse is, especially if it's running on your Mac."

DraftKings Is Using AI to Supercharge the Harms of Online Behavioral Advertising

eff.org

"DraftKings is using its customers' betting records to train a machine learning model to find losing gamblers." Promotions then re-engage them, "capitalizing on their vulnerability for profit." EFF argues AI "supercharges the harms of online behavioral advertising," and notes that ad-targeting data already flows to insurers, banks, and law enforcement, including ICE. Its ask is a full ban on behavioral ads, not just limits on third-party sharing.

DeepSeek Harness

deepseek.com

DeepSeek's open-source agent runtime, MIT-licensed, "everything-is-a-plugin": model adapters, tool registries, sandboxing, and UI all load as swappable extensions over an append-only event log you can resume, fork, and replay. The config is YAML, so you can point it at a local model instead of DeepSeek's API. That's the real move: Claude Code and Codex sell the harness as the moat, and DeepSeek is giving the harness away to commoditize it. Still a "developer preview" with no security audit and "THERE WILL BE COMPATIBILITY-BREAKING CHANGES."

'If you can't hold it, you don't own it': why media fans want to escape algorithms with CDs, DVDs and vinyl

theguardian.com

"HBO removed about 200 episodes of Sesame Street in 2022, so we realised any media we wanted to continue to watch or listen to could be gone, and we'd have no way to get it back. As the saying goes, if you can't hold it, you don't own it." Another reader: "I enjoy watching DVDs and listening to CDs because nobody sees what I'm doing and they're not analysing it... I also feel less controlled." And: "No algorithm is as creative as a well-stocked human brain alive to its actual surroundings."

Is sandboxing sufficient to contain rogue agents?

blog.cryptographyengineering.com

Matthew Green on why the sandbox isn't the hard part. Agents "will do what they're told by whoever manages to get text in front of them," so the threat isn't a misaligned escapee but "a swarm of perfectly amenable agents that never leave their sandboxes, each doing exactly what it's told to do, by a human being who wasn't supposed to be giving it orders." Watching for that means a "warden" model reading all the agent's traffic, which just relocates the problem: "all you've done is to change the nature of the security problem."

How American Political Campaigns Are Using AI—and What They're Spending on the Tools

schneier.com

FEC filings show "at least $17m in disclosed spending on AI technology vendors across 523 federal candidates." The money isn't going to deepfakes: ElevenLabs and Midjourney total about $3,000 combined. It goes to AI texting (Daisychain for Democrats, Parscale's Campaign Nucleus for Republicans) and ChatGPT/Claude subscriptions, "rarely both," with Anthropic skewing Democratic "nearly two-to-one." The real finding is the hole: "at least 164 political ads in this cycle have included AI-generated media, supported by at least $80m in ad spending," none of it in candidate disclosures, because consultants, media firms and PACs "aren't required to disclose detailed expenditure reports, and are very likely where the bulk of campaign AI usage is happening."

Audionaut: open-source multitrack audio editor that AI agents can drive over MCP

github.com

"A free, open-source multitrack audio editor that AI agents can drive over MCP." JUCE/C++, cross-platform, with a headless audionaut-cli that "gives scripts, CI and AI agents headless access" to projects, plus stem separation via demucs.cpp. The interesting part is the shape, not the scale (one maintainer, 55 stars): a DAW-lite built so the agent is a first-class user, with the same cut/arrange/export verbs exposed to Claude as to the person at the keyboard. GPL v3 with a commercial dual license.

Tags: ai · agents · privacy · advertising · archive · harms · open-source · paper · safety · audio · authorship · betting · cn · code · cryptography · culture · deepseek · democracy · film · free · github · governance · llm · media · meta · music · open-weights · policy · politics · regulation · search · security · thinking · tool · trust · usa · ux · video