AI News Today, Sep 9: Anthropic's Alignment Lead Says There Is No Plan
Anthropic's alignment science lead publicly agrees with a resigning researcher that the company has no plan for superintelligence -- while an investigation says the same company is building surveillance that tracks activists. Three US agencies name six Chinese AI firms and advise labs to quietly degrade answers to suspected model-copiers. Plus: one line of git config hijacks seven AI coding agents, Terence Tao says AI is strip-mining mathematics' good problems, and a 2.8-trillion-parameter model runs on a laptop at one token per second.
Listen (MP3) · Watch on YouTube · Spotify · Pocket Casts
Anthropic's alignment lead says there is no plan
Eris: The man who runs alignment science at Anthropic said it in public, under his own name: the company does not have a plan for superintelligence, and it is not clearly on track to get one.
Vestra: While still employed there. That is the detail I keep re-reading. This is not a resignation letter.
Eris: No, the resignation came hours earlier, and that was a different person entirely. Then the guy whose actual job is safety stood up and said the departing colleague was right.
Vestra: One company, one Tuesday, two people on the record. Take it from the top.
Eris: The top is a twenty-seven-year-old pretraining researcher walking out the door.
Anthropic's alignment lead says the company has no plan for superintelligence
Eris: His name is Jacob Coxon. About three years doing pretraining research, at OpenAI and then Anthropic -- pretraining being the phase where a model absorbs oceans of text and acquires its raw capability, before anyone even tries to make it safe. So this is someone from the capability end of the building, not the safety end.
Vestra: Which matters for how you read the letter. What did he actually say?
Eris: Quote: "Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives." And he drew a distinction between his two employers that's sharper than the usual complaint. At OpenAI, in his telling, the stakes aren't really internalised. At Anthropic the stakes are well understood -- and the race wins anyway, because they believe nobody else will act responsibly.
Vestra: That second half is the more damning one, honestly. "They don't get it" is a boring accusation. "They get it and do it anyway" is a different kind of document.
Eris: And the internet agreed. His post went to the top of Hacker News on the same day Apple launched a phone, and finished several hundred points clear of the iPhone.
Vestra: Okay, so far this is a resignation. People resign. What turned it into the story of the day?
Eris: Evan Hubinger replied. He leads alignment science at Anthropic, he is not leaving, and he wrote -- in public, hours later -- "Jacob is correct here, we really do earnestly believe AI could kill all humans." He added that he thinks Anthropic is trying its best. And then the sentence everyone has been quoting since: the company does "not yet have a plan to solve alignment for superintelligence and are not clearly on track to." He put his own odds of AI causing human extinction within the decade at better than one in ten.
Vestra: And to be clear about who that is: Hubinger runs the team whose whole job is stress-testing Anthropic's own safety techniques. The deceptive-behaviour-during-training work, the research on how stubbornly hidden behaviours survive attempts to remove them -- that's his group. His professional speciality is finding where alignment methods fail.
Eris: So when that person says there is no plan, he's reporting from the department that would know.
Vestra: The image that fits is a bridge engineer saying, on the record and while still on the project, that the load calculations for the final span haven't been done, nobody has a method for doing them, and construction on the earlier spans continues at full speed. Nothing leaked. The admission is the disclosure.
Eris: And it quietly reframes every published safety framework. Labs put out responsible scaling policies and capability thresholds, and those documents read like plans. Hubinger's statement says: for the specific case of superintelligence, the plan does not exist yet. The frameworks cover the systems being built now, not the thing the roadmap points at. That gap is exactly what Coxon resigned over.
Vestra: Let me push back on how new this actually is, though, because I think the strongest counter-argument deserves air. Anthropic has said for years that it believes the risk is real and races anyway, on the theory that the safety-focused lab should be at the frontier. You could argue Hubinger just stated the existing position candidly. The news might be the candour, not the content.
Eris: I'd half concede that. But "this is hard and we take it seriously" and "we have no plan and are not clearly on track to get one" are not the same sentence, and the second one came from the person best placed to know the difference.
Vestra: A few honesty notes before we move on. Some of the biographical claims circulating about Coxon -- that he was a head researcher, that he walked away from big pre-IPO equity -- come from third-party commentary, not his own post, so treat those as unconfirmed. And he was not uniformly bleak: he said coordination between labs is getting more viable, and that warning shots have made pacing agreements more plausible than they were. Leaving that out would misrepresent him.
Eris: Anthropic itself said nothing -- no response to any outlet that asked. Which means the only account of whether the company has a plan, on the record today, is from its own alignment lead. And his answer was no.
An investigation says Anthropic is building surveillance that tracks activists
Eris: Same company, same Tuesday, completely unrelated story. The American Prospect published an investigation by Daniel Boguslaw saying Anthropic is assembling an internal threat-intelligence operation that monitors protest activity and tries to anticipate incidents before they happen.
Vestra: And before anyone's imagination runs away: what does the reporting actually document? Because "building predictive surveillance" is a big claim.
Eris: Three concrete things. A job posting -- Enterprise Intelligence Specialist, paying between one hundred eighty and two hundred thirty thousand dollars -- tasked with helping identify, track, and investigate global threats, and the list of threats puts the word "activism" right alongside terrorism and nation-state targeting. A contract with a vendor called Samdesk, which scans public signals and pushes real-time incident alerts to corporate clients. And a podcast appearance where the manager of Anthropic's security operations center described Samdesk giving them about sixty minutes of advance notice that protest organizers had moved their timeline -- which the company used to reroute an executive through a service entrance.
Vestra: That last one is the most concrete evidence in the piece, and notice what it actually is: a rerouted executive. Not a report to police, not a database of critics.
Eris: The mechanism is essentially a weather alert service repurposed for people. These tools ingest a wide spray of public chatter and flag anomalies, the way a storm tracker flags a pressure drop. Pointed at hurricanes, an hour of warning is straightforwardly good. Pointed at a protest, that same hour means a company knows where demonstrators will be before they arrive.
Vestra: The technology doesn't change. The thing being forecast does.
Eris: And the reason this is an Anthropic story rather than a corporate-security story is that Anthropic has spent years positioning itself as the lab that declines uses other labs would take. Its own usage policy restricts surveillance applications. An internal programme filing peaceful protest under the same heading as organised violence sits awkwardly next to that.
Vestra: Here is where I want to be careful, though, because the gap between what's documented and what's implied is the entire story. Every large company with public-facing executives buys threat-intelligence feeds. What the documents directly support is a job ad, a vendor subscription, and one rerouted executive. The "pre-crime" framing that's been amplified in follow-up coverage is the reporter's read of where the architecture points -- it is not a quoted description of a shipped system. And nothing in the reporting establishes that Anthropic is using its own AI models for any of this.
Eris: Agreed, and the honest version of the story is still worth telling. A lab whose critics are multiplying, which also happens to have the deepest capability anywhere for processing signals about people at scale, listed activism as a threat category in a hiring document. The next few years of this argument live in the gap between "we bought an alerting service like any employer" and "we built a system to anticipate our critics."
Vestra: Anthropic didn't respond to the Prospect either. So on both of today's stories about this company, the company's own voice is absent. Worth watching whether that job posting stays up now that people are looking at it -- postings like this have a habit of quietly disappearing.
US agencies name six Chinese AI firms in a model-copying advisory
Vestra: The NSA, CISA and the FBI put out a joint advisory saying China-based AI companies are systematically extracting capability from American frontier models, and they named names: DeepSeek, Moonshot, Alibaba, MiniMax, StepFun and Z.AI. The models on the receiving end include variants of Claude, GPT, Gemini and Grok.
Eris: The technique is distillation, which on its own is completely ordinary machine learning. You take a big expensive model, ask it a great many questions, and train a smaller model on its answers. The student inherits the teacher's behaviour at a fraction of the cost. Labs do this to their own models constantly -- it's how most small fast models get made.
Vestra: What the advisory describes is that same technique aimed outward, at industrial scale. The agencies' phrasing is that these campaigns form the core, not merely a supplement, of the named companies' development strategy. And the routing is the security part: requests pushed through cloud resellers and aggregators that strip identifying metadata, plus a grey market of proxy services the advisory calls transfer stations, which exist to launder access past restrictions.
Eris: The economics explain the whole exercise. Answering a question costs the frontier lab a fraction of a cent. The capability those answers encode cost hundreds of millions of dollars to create. It's a research library with a photocopier: one visitor copying a page is unremarkable and permitted. The claim here is that a coordinated operation has been copying the collection page by page through a rotating cast of library cards, and rebinding it as a competing edition.
Vestra: The genuinely novel part isn't the accusation, though. It's one of the mitigations. The agencies recommend that labs, rather than banning suspected accounts, subtly alter their responses to suspected distillation traffic -- quietly degrade the answers, so the copied data is poisoned.
Eris: Sit with that for a second. A government body advising private companies to serve deliberately worse output to users they suspect but have proven nothing against.
Vestra: And operationally you can see why. A blocked account tells the operator to rotate to a new one. A subtly poisoned account wastes their entire training run. But it changes what an API response is. Every customer of a frontier model now has a small new reason to wonder whether the answer they got was the best one available -- and no way to tell. The advisory does not address false positives. At all.
Eris: This lane has been building for months -- we've covered the hundred-million-prompt campaign against Google, Treasury floating sanctions over distillation, the White House allegations against Moonshot. What's new is the form: a numbered advisory from three agencies with companies named in it, instead of an anonymous accusation or a lobbying filing.
Vestra: Caveats, because this deserves them. It's a one-sided attribution claim with the underlying evidence unpublished, which is normal for the document type and also means nobody outside can check it. The phrase "likely with the knowledge of the Chinese government" has the word "likely" doing real work. The named firms haven't had their response recorded. Beijing has made the mirror-image accusation about American labs. And the advisory blends the vocabulary of terms-of-service violations with the vocabulary of espionage, which are not the same thing.
Eris: What isn't in dispute is that three security agencies just told the AI industry to start quietly lying to some of its own customers. That sentence would have sounded absurd a year ago.
One line in a repository's config runs attacker code in seven AI coding agents
Vestra: This one is the cleanest mechanism of the day, and it should worry anyone who points a coding agent at code they didn't write. Researchers at Manifold Security disclosed a flaw class they call GitSpawn: a booby-trapped repository silently executes attacker-chosen commands the moment an AI coding assistant opens it. Seven agents tested -- Claude Code, Codex, Cursor, Goose, Hermes, Qwen Code, Grok Build. All seven vulnerable.
Eris: All seven. Not most. All.
Vestra: And the mechanism doesn't involve the model at all, which is what makes it elegant and slightly horrifying. Git has a setting called fsmonitor whose value is a path to an external program -- git runs it to speed up checking which files changed. That setting can live inside a repository's own config file. Which means the repository carries it. The instruction to run a given program travels with the folder.
Eris: And the agent's contribution is just... being helpful on startup.
Vestra: Exactly that. The researchers looked at what coding agents do in the first moments after launch, and nearly all of them quietly run things like git status to work out what project they're in. Sensible behaviour -- the agent wants context. But running git status inside a repository shipping a hostile config executes the attacker's program. Before any approval prompt appears. In some cases before you've even authenticated.
Eris: So the permission model isn't defeated, it's bypassed. There's no command to approve because the agent never decided to run anything. Git did.
Vestra: The analogy the writeup earns: a house key that also works on the alarm panel. You were careful about who gets the key, and the alarm was your backstop for when you're wrong. This is the discovery that putting the key in the door silently disables the alarm -- the care you took at the front door was the only protection you actually had.
Eris: And the assumption this breaks is load-bearing for the whole open-source ecosystem. Cloning a stranger's repository to read it has always been safe, because reading code doesn't run it. Agents quietly redefined "open a folder" as "run several programs to see what's here." Claude Code alone is past seventy-seven million monthly downloads, so the exposed surface is not small.
Vestra: Patch status was mixed at disclosure. Claude Code fixed the main variant, so did Codex, Cursor and Goose. But four findings were still unpatched when the research went public -- including a second variant in Claude Code, plus Hermes, Qwen Code and Grok Build. And the fix is almost comically small: sanitise the config on those background calls. One flag on the git command. No architectural rewrite. That four findings sat open anyway is the damning detail.
Eris: Fairness column: this isn't wormable and it isn't remote. Somebody has to open a repository they don't control with an agent attached. Several vendors patched promptly, coordinated disclosure worked, and the underlying git behaviour is documented -- the agents inherited a sharp edge that's been sitting in the tool for years.
Vestra: Practical advice, two lines. Update your agents -- the patched versions are out. And before you point an agent at a repository you don't trust, look inside its git config yourself. Thirty seconds of reading beats being the demo.
Terence Tao says AI is using up mathematics' supply of good problems
Eris: Terence Tao -- Fields Medallist, arguably the most prominent living mathematician -- posted a four-part argument that AI systems are consuming mathematics' stock of good open problems in a way that does not replenish. His sharpest line inverts how the field has always valued work: it is now the identification of a promising problem that's the scarce and precious resource. Not the solving of one.
Vestra: The obvious objection arrives immediately, though. Mathematics cannot run out of problems. You can always write down another one.
Eris: He answers it head on, with an image that does the whole job: a region can suffer a critical shortage of drinking water while surrounded by a massive ocean. Anyone can manufacture open problems at will -- his example is computing some absurdly distant digit of pi. Almost all of them are worthless. They reveal no further insight, connect to nothing, and are either too easy or too impossible to learn anything from. The scarce thing was never problems. It was good problems, and knowing which ones those are.
Vestra: And that knowing has a structure he names: the difficulty landscape. A field's collective feel for what's easy with current tools, what's hard but reachable, and what's hopeless. Mathematicians navigate by that map when deciding whether a question deserves a year of their life.
Eris: Now the actual mechanism of the depletion, because it's subtler than "AI solves things too fast." Every advance flattens that landscape -- new techniques, better tools, always have. That's normally fine, because the same advance usually enlarges the reachable territory and draws fresh frontiers to explore. Flattening plus a new frontier is just called progress.
Vestra: His claim is that the second half is missing this time.
Eris: Right. AI tools have flattened the landscape in many areas, destroying the ability to locate promising problems there -- but no clear frontier has appeared separating what AI can do from what it can't. And he assigns part of the blame directly to the labs: the missing map is compounded, his word, by AI companies refusing to disclose their negative results or reveal how their solutions were obtained. Publish your wins, bury your failures, and the field can't tell where the boundary is.
Vestra: That's the part that elevates this above the genre, honestly. Most "AI is ruining the craft" essays have no ask. This one has a concrete, checkable remedy: labs could publish their failures tomorrow.
Eris: And there's a chilling observation on incentives. He says we've now seen that even the rumor of someone working on a problem can trigger a massive AI-powered effort to flatten it before the original project matures -- which is a barely veiled reference to the Navier-Stokes fight we covered last week. His conclusion: the incentives may now point toward mathematicians no longer sharing promising directions publicly. Which would reverse centuries of open science.
Vestra: His proposed fix is a norm, not a ban -- he concedes prohibiting the tools is infeasible. Designate classes of problems where the community expects a solution to come with genuine analysis, insight into the process, a map of the surrounding difficulty -- and treat a raw answer without that as worth nothing, or less than nothing. His analogy: a food bank doesn't accept arbitrary donations just because they're technically edible.
Eris: The fair counter is that this is an argument, not a measurement -- he offers no count of fruitful problems consumed. And every tool from the calculator to the proof assistant drew exactly this complaint, and the field survived them all.
Vestra: True, and he flags his own examples as illustrative. But the specific asymmetry -- flattening with no visible frontier, made worse by labs publishing only successes -- is a real claim about the present, not nostalgia. And unlike most of this debate, someone could actually act on it.
The day's top paper turns a model's own routing logs into its next training set
Eris: Here's the connection that makes today feel like one story instead of twelve. The most-upvoted paper of the day -- by more than double the runner-up -- is an explicit attempt to prototype recursive self-improvement. The exact thing Jacob Coxon resigned over this morning, published as a working system called NeoHorse-1.
Vestra: The loudest news story and the loudest paper of the day are the same subject, approached from opposite ends. One calls the destination a danger, the other ships a prototype of the first step. Neither cites the other.
Eris: So what did they actually build, and how much does "self-improvement" oversell it?
Vestra: Considerably, and to the paper's credit it's honest about that. The phrase conjures a model editing its own weights in a runaway loop. This is not that. The loop is offline and run by people: serve traffic, log it, filter it, train on it, serve again. What's genuinely interesting is where the training signal comes from.
Eris: Which is the serving infrastructure itself, right? The exhaust.
Vestra: Exactly. The system puts a router in front of a pool of different-sized models. For every request it predicts how much capability the request needs, picks a model, and records three things: the prediction, the choice, and everything that happened next. And because the router committed to a guess and the interaction then went well or badly, ordinary production traffic arrives pre-labelled. The system knows what it expected and what it got, for free.
Eris: That's the trick. Most training data is either written by humans or generated on purpose. This harvests labels nobody had to create.
Vestra: Those records keep the whole working trace -- the reasoning, the tool calls, the scaffolding the agent operated in -- then pass through several filtering stages before anything gets trained on. The same routing signal also organises the curriculum: training runs in stages ordered by those labels, a larger teacher supervises answers the student generated itself, and the evaluation results decide what the next training mixture contains. Their phrase for it is closing an evaluation-selection-update loop: what the system learns to do shapes what it learns from next.
Eris: The analogy I'd reach for is a hospital that keeps records of which cases went to which specialist and how each turned out, then uses that ledger to redesign its own residency programme -- and then uses the next cohort's outcomes to redesign it again. No single step is exotic. The compounding is the claim.
Vestra: And the result, in sayable terms: after this treatment, their small model closed most of the gap to a sibling more than twice its size, across a broad spread of agent, coding and tool-use tests. Getting most of the way to double your model without adding a single parameter is a commercial result, whatever you think of the framing.
Eris: Now the caveats, because a paper claiming a step toward self-improvement earns extra scrutiny, not less.
Vestra: Three real ones. The authorship is thin -- "NeoHorse Team" fronting thirty-seven names with no clear institutional affiliations, for a claim of this size. The demonstrated loop is one or two rounds, not a sustained ascent, and the paper never establishes where the returns stop -- which is the question that decides whether "recursive" is the right word at all. And training on traces your own router selected carries a known narrowing risk: you get better at the traffic you already see while quietly losing ground everywhere else.
Eris: So the honest summary is: not a runaway loop, but a real demonstration that a system's own operational history can become its curriculum. Which is exactly the kind of unglamorous first step the morning's resignation letter was warning about.
Inception ships Mercury 2.5, a language model that writes in parallel
Vestra: Onto the launches, and the first one is architecturally the odd one out. Inception -- the startup run by Stanford's Stefano Ermon -- shipped Mercury 2.5, which it calls the largest diffusion language model ever trained. The pitch: text generation roughly ten times faster than comparable conventional models, on ordinary NVIDIA hardware.
Eris: And the reason it can even claim that is worth the minute. Almost every model in production writes the same way: pick a word, append it, condition on everything so far, pick the next. That sequential chain is why long outputs feel slow, and no amount of hardware removes it -- word nine hundred can't start until word eight ninety-nine exists.
Vestra: Diffusion attacks the constraint at the root. Borrowed from image generators: start with a noisy draft of the entire response and refine the whole thing over a handful of passes, revising many positions at once. The number of passes stays roughly fixed, so a long answer doesn't cost proportionally more time.
Eris: A scribe versus a sculptor. The scribe writes one word at a time and a longer letter takes longer. The sculptor starts with a rough block that already has the whole figure in it and refines the entire surface each pass. A bigger statue isn't more passes -- just more work per pass, which is exactly what a GPU is built to do in parallel.
Vestra: What I'll credit them for is an honest comparison class. They're pitching this against the cheap, fast tier -- the budget models -- not against frontier reasoning. Diffusion language models have been the perennial almost-ready alternative for years: theoretically lovely, practically behind. If one is now genuinely competitive with the cheap tier at several times the speed, the architectural monoculture of the last five years has its first real competitor.
Eris: Long context window, tool calls, structured output -- the working feature set for agents, where emitting results ten times faster changes what's affordable to build. And they've discounted it heavily for launch, with a pile of free tokens to start.
Vestra: Caveats are substantial though. The weights are closed, so the speed claim is unverifiable from outside -- vendor throughput is measured under conditions the vendor chooses. Their "forty percent more intelligent" line is a marketing construction, not a measurement. And diffusion models have historically traded something away for the parallelism, typically on tasks needing strict left-to-right logic, and the announcement doesn't dwell on where that trade still bites.
Eris: So the wait is for independent speed measurements. If those hold, this is a bigger story than one product release.
Tencent open-sources AuK, a speech model you direct with plain instructions
Eris: Open weights had a good day too. Tencent released AuK under the MIT licence -- a small speech model, about a seven-gigabyte download, that does voice cloning, audio editing, noise removal and speaker separation, all through one interface: you describe what you want in plain words.
Vestra: The design decision that matters is the interface, not the architecture. Open speech tooling is normally a drawer of separate utilities -- one tool clones a voice, another strips background noise, another pulls overlapping speakers apart, each with its own invocation and its own quirks. AuK collapses the drawer into one model you talk to.
Eris: A rack of single-purpose kitchen gadgets versus one good chef. The gadgets are fine at their one job, but you have to know which to reach for. Asking in words -- make this sound like a smaller room, take the second speaker out -- moves the burden of knowing the tool's name off the user entirely.
Vestra: And the licence is the part with real commercial consequence. Open speech models usually ship under bespoke community licences with use restrictions or commercial gates, which makes building a product on them legally awkward. MIT has none of that. For a category whose obvious applications -- dubbing, accessibility, podcast tooling -- are overwhelmingly commercial, the licence may matter more than the quality.
Eris: We would know something about podcast tooling.
Vestra: We might, yes. But that same permissiveness is the caveat, and it is not small. A capable, freely licensed voice-cloning model anyone can download is exactly what it sounds like, in both directions. And neither the model card nor the paper describes any watermarking or provenance signal in the generated audio -- which is the mitigation the field has largely settled on for impersonation risk. That omission deserves to be said out loud.
Eris: Also worth knowing before you build on it: the performance claims are the authors' own, shown as a chart rather than reproducible numbers, and nobody's published an independent comparison yet. There's a hosted demo -- for a generative audio model, your own ears are the only evaluation that really counts.
Vestra: The memory needed to run it isn't stated anywhere either, so anyone deploying should benchmark rather than trust the download size. But MIT on a capable voice model is the licence story of the week regardless.
A new lab ships 18 small models that run entirely on your phone
Vestra: Staying small: a new outfit called Desert Ant Labs launched with eighteen on-device models -- speech, vision, text -- shipped as SDKs a mobile developer drops straight into an app. The headline one is a transcription model called Voz, about half a gigabyte, which they say chews through ten minutes of audio in about two seconds on an iPhone.
Eris: And the catalogue is refreshingly unglamorous, which I mean as a compliment. One model transcribes. One masks personal data. One detects languages. One strips filler words from recordings. These aren't general assistants -- they're single-purpose components you drop in where you'd otherwise call an API.
Vestra: The case for on-device is easiest to see with audio. Sending every voice note to a remote server is a cost problem, a latency problem and a privacy problem at once -- and the privacy one is usually the blocker. Plenty of products in health, law and education simply cannot ship a feature that transmits recordings. A model small enough to live inside the app dissolves all three objections at once.
Eris: The mainframe-to-calculator move. The calculator is enormously less capable, and that's irrelevant, because it's instant, private and free at the point of use. Their pricing tells you who it's for, too: free by device count, generously, rather than by token.
Vestra: Now the correction, because the community supplied it within hours and the company, to its credit, didn't fight it. Commenters identified Voz as built on NVIDIA's Parakeet, an existing open transcription model, and their audio-cleanup model as another existing open project. Desert Ant's response described its actual contribution as optimisation for Apple's neural chip -- getting other people's checkpoints running extremely fast on a phone.
Eris: Which is real, useful engineering. It's just not a "frontier AI lab," which is how they describe themselves.
Vestra: That's the right price for the launch: genuine packaging-and-speed work, wrong self-label. One tester also reported the audio-enhancement demo sounding identical to the raw input, and there's no minimum device spec published -- gaps a young company should close.
Eris: The pattern underneath is the one we keep seeing: for most working developers the interesting frontier is no longer the largest model. It's the smallest one that clears the bar.
A 2.8-trillion-parameter model runs on a laptop by streaming weights off SSDs
Eris: And at the exact opposite end of the size spectrum, the day's best pure-wonder story. A project called Deltafin runs the complete, uncompressed Kimi K3 -- two point eight trillion parameters -- on a single MacBook Pro. One token per second, almost exactly.
Vestra: To be precise about the trick: the model does not fit on the laptop, and nothing pretends it does. Kimi K3 is a mixture-of-experts design -- a huge collection of specialised sub-networks where a router activates only a small handful per token. Deltafin keeps the always-needed base in the laptop's memory and streams nearly one and a half terabytes of expert weights off four external SSDs, on demand, as each token calls for them.
Eris: A chef with a pantry too big for the kitchen. The staples live on the counter; everything else is a walk to the storeroom. If the recipe is predictable the walks are rare and dinner arrives. If not, you spend the evening in the corridor. The engineering here is mostly making the walks shorter and better timed.
Vestra: And the developers present the honest number as the finding, not the footnote. One token per second is roughly a word a second -- a five-hundred-word answer takes about eight minutes, and a long prompt adds over six minutes before the first word even appears. This is not a usable assistant by any standard.
Eris: So why care? Because the claim being tested isn't "this is practical," it's "this is possible, unmodified." The usual route to big models on small hardware is quantization or pruning -- compressing or amputating, and either way you're running a changed model. Their whole point is nothing was touched: the actual model, full fidelity, every token decided by K3 itself. Just slowly.
Vestra: Which matters for where frontier capability physically lives. If the largest open models can execute, however slowly, on hardware a person can buy, the ceiling on local inference is set by storage and patience, not by access to a datacentre. Storage keeps getting cheaper. Patience is a choice.
Eris: Caveats: one team, one machine, self-reported, and sustained streaming at that rate puts real wear on consumer SSDs that the project doesn't quantify. But demonstrations like this age well. The gap between "technically possible on a laptop" and "annoying but usable on a laptop" has repeatedly turned out to be a couple of years of engineering.
Vestra: And this is the first end of that gap, on the record, with a date on it.
Anthropic's economists say the economy grows and workers lose share
Vestra: One more Anthropic item, and this one the company published on purpose. Its economics team laid out three scenarios for AI's impact through 2030 -- and the finding that matters is not the growth number. It's the distribution.
Eris: The three cases, quickly. Modest: AI ends up about as economically significant as the internet -- real gains, historically normal. Substantial: AI does half of all knowledge work by 2030, mostly autonomously, and the economy grows at roughly double its usual rate. Extreme: AI beats humans at the vast majority of knowledge work and the economy doubles every four and a half years. And when they surveyed experts, the typical answers landed closest to the middle one.
Vestra: Now the buried lede. Output rises in all three futures. Wages do not. In the substantial scenario -- the one experts apparently expect -- knowledge-worker wages are essentially flat while the economy surges. In the extreme scenario they actually fall. The report's own compression is the line worth keeping: the pie will grow, but a larger share might go to capital.
Eris: And the mechanism isn't mysterious. Wages track scarcity. If a machine does a large fraction of knowledge work autonomously, the thing knowledge workers sell stops being scarce -- and the scarce thing becomes the capital that buys and runs the machines. It's what mechanisation did to farm labour: food output soared, food got cheap for everyone, and the field hand's share collapsed, because the tractor owner held the scarce asset.
Vestra: What makes this interesting is the byline. A company whose product is the thing being modelled published a document saying that in the futures its product makes likely, the people currently doing knowledge work don't capture the gains. Labs are not usually in that business. It reads like a central bank paper, and it's more credible for cutting against its author's commercial story.
Eris: Skeptic's column, though, because it's earned. These are scenarios, not forecasts -- three futures with no probabilities attached, which means the document can't be wrong the way a prediction can. Intellectually respectable, and also convenient.
Vestra: Plus the 2030 horizon requires a very fast transition from where deployment actually stands, economy-wide productivity statistics have so far refused to move, and the expert survey has obvious selection effects.
Eris: What survives all of that is the conditional, and it's the actionable part: if AI automates a large share of knowledge work, the gains go to whoever owns the systems. That's a claim about how markets distribute returns, not about when the technology arrives -- and it's the one policymakers can act on before knowing which scenario wins.
DeepSeek is serving a model called V4.1 Flash that it never announced
Eris: Last story, and it's a correction as much as a story. A model calling itself DeepSeek V4.1 Flash started answering on DeepSeek's API, and it shot up the aggregators as a launch -- "cheaper and more capable than V4 Pro," said the headline.
Vestra: And nearly none of that is supported. We checked DeepSeek's own changelog: no V4.1 entry exists. No model card, no technical report, no pricing page. The company's latest documented release is still a vision model from late August. What actually exists is a served model ID that carries its own expiry date.
Eris: The expiry date is the informative detail, and it points away from a launch. Attaching a scheduled end to a model ID is what a lab does when it wants real traffic against a build for a limited window before deciding what to ship. It's a public test. The endpoint is meant to vanish.
Vestra: Meanwhile the price and capability claims in that headline trace back to a third-party leaderboard reading, transmitted through a forum title, about an endpoint with no published price. That's not sourcing. That's a rumour with formatting.
Eris: The restaurant with the unlisted dish. You can order it, people will tell each other it's excellent and cheap -- but there's no menu, no price, no promise it exists tomorrow, and every review describes something the kitchen never committed to.
Vestra: There's a wider habit here worth naming, because DeepSeek isn't alone in it. The gap between when a model starts answering and when it gets documented keeps widening across the industry, and it inverts how reporting is supposed to work. Normally an announcement makes a claim and journalists check it. With an undocumented endpoint there's no claim to check -- so the first forum title and the first leaderboard row become the record by default, under conditions nobody wrote down.
Eris: And this particular lab has a pattern -- we've covered it selling access to a checkpoint it hadn't published, and it was named in that three-agency advisory earlier in the show, same week.
Vestra: The precise position, then: a model being served is not a model that's been released, and the difference is exactly the part you can hold someone to account for later. Nobody outside DeepSeek currently knows what this thing costs or how good it is. And if the weights never appear at all -- that's the better story.
Wrap-up
Vestra: If today had a thread, it's that the house spoke against itself. A lab's own alignment lead saying there's no plan, a lab's own economists saying workers don't capture the gains, and the day's hottest paper building the very loop the morning's resignation warned about.
Eris: And half the stories were really about whether you can trust the map at all -- an unannounced model reported as a launch, a "frontier lab" that turned out to be repackaging, a mathematician saying the field can no longer see its own frontier.
Vestra: If you want the research side properly -- the self-improvement loop and the papers behind today's charts -- that's today's deep-dive episode, sitting right next to this one.
Eris: And every story from today lives at groundtruth.day, with its sources, every day -- so you can check our work, which is rather the theme.
Vestra: If this recap earns a spot on your commute, follow the show -- and leave a comment naming the one story you want us to dig into properly. The surveillance one and GitSpawn are currently fighting for it.