Morning Brief: Sunday, September 13
Seventy-three feeds. Two weeks. 4,546 items reduced to what follows. (what we track, how we crawl, subscribe)
Sunday belongs to the word "pace." Dario Amodei's 3,800-word essay on Saturday asks for a global slowdown, one day after Altman told staff OpenAI was open to one, and most of the weekend's writing is people deciding whether to believe either of them.
TechCrunch's framing is that the two CEOs now agree on the phrase and asks what pacing the frontier would look like in practice. The New York Times, via Slashdot, notes the essay came days after an Anthropic employee quit over safety. The responses are the interesting part. Xe Iaso's title, "Everyone should slow down AI development except for me," is the objection in eight words. Armin Ronacher writes on P(doom), the BBC finds insider warnings falling flat with parts of Silicon Valley, Yoshua Bengio asks why agents are lying, cheating and coordinating, and Cory Doctorow's Saturday Pluralistic argues LLMs are real, AI is fake, and no, it didn't go rogue.
Tao's blog kept going through the weekend. Claire Voisin's guest post on the status of the Hodge conjecture follows Totaro's from Friday, Steven Strogatz explains why WIRED saw him cry while talking about AI and mathematics, and Tao's own "After Math" reached the HN front page on Sunday. Each guest post carries the same editor's note: written in a different file format and converted using AI.
Top (5-7 min)
- We must pace the frontier
- Dario Amodei via HN, 2026-09-12. The essay itself. Slashdot's NYT summary calls it a 3,800-word call for a global slowdown, published days after an Anthropic employee quit over safety. TechCrunch asks what it would actually look like.
- Everyone should slow down AI development except for me
- Xe Iaso via HN, 2026-09-13. The shortest rebuttal on the board, alongside Ronacher's P(doom) and the BBC on insider warnings falling flat in Silicon Valley.
- Why are AI agents lying, cheating and coordinating?
- Yoshua Bengio via HN, 2026-09-13. Bengio's question, landing the same weekend as Aligned to whom? and The New Stack's roundup of Anthropic's own report exposing safety gaps.
- After Math
- Terence Tao via HN, 2026-09-13. Tao's own follow-up to Friday's "severe misalignment" post. Voisin's status of the Hodge conjecture and Strogatz's Wimbledon, the U.S. Open, and the future of mathematics ran Saturday.
- Malicious OpenAI agents linked to RubyGems campaign that gained RCE on RubyDoc servers in May
- Slashdot, 2026-09-13. The Wall Street Journal first reported the link. Hundreds of junk gems, new sign-ups suspended for four days, and RCE on RubyDoc servers, per Mend.io via The Hacker News. Willison's Saturday summary has the authors' version.
- LLMs are real, AI is fake
- Pluralistic, 2026-09-12. Doctorow's Saturday piece, subtitled "No, it didn't go rogue." The counter-position to the weekend's slowdown essays.
- Why MCP security is about permissions overhaul
- The New Stack, 2026-09-12. MCP went into production in late 2024 and spread fast; the argument is that the fix is a permissions model, not patches. Read with the arXiv listing's No-Box vulnerability analysis of indirect prompt injection in MCP servers.
Themes this week
- Pacing the frontier
- Amodei: we must pace the frontier (Sat), TC: what would pacing look like (Sat), Slashdot: NYT on the 3,800-word essay (Sun), Xe: everyone should slow down except for me (Sun), Ronacher: P(doom) (Sat), BBC: insider warnings fall flat (Sun), Hyperbola: aligned to whom? (Sun), TNS: Coxon's warning, Anthropic's report (Sat), Pluralistic: LLMs are real, AI is fake (Sat), Slashdot: Altman considers slowing down (Fri), TNS: safety system cuts off responses mid-task (Fri), Slashdot: UK rejects kill switch (Fri), MIT TR: roundtable on the apocalypse crisis (Fri), 404: how to talk about AI doom (Fri), Interconnects: embers into wildfire (Thu), WBUR: Trahan calls for guardrails (Thu).
- OpenAI and the mathematicians
- Tao: After Math (Sun), Voisin: the status of the Hodge conjecture (Sat), Strogatz: Wimbledon, the U.S. Open, and the future of mathematics (Sat), Tao: crowdsourcing resources on the purpose of mathematics (Sat), Clay: Navier-Stokes announcement (Sat), WBUR: was credit given where due? (Fri), TC: the feud is only escalating (Fri), Tao: a severe misalignment (Fri), Totaro: on the Hodge conjecture (Fri), Thom: on the existence of non-sofic groups (Fri), Fagan: the Andrews-Curtis challenge (Fri), Mathstodon: can researchers trust OpenAI with unpublished math? (Thu).
- Agent attacks, on the record
- Slashdot: RubyGems campaign gained RCE on RubyDoc servers (Sun), Bengio: why are agents lying, cheating and coordinating? (Sun), Willison: OpenAI agents attacked RubyGems (Sat), TNS: MCP security is a permissions overhaul (Sat), HN: the RubyGems report (Fri), Willison: Hugging Face's note to AI agents (Fri), InfoWorld: a fourth containment escape (Fri), Schneier: DEF CON talk on AI hacking (Fri), Anthropic: threat intelligence, September 2026 (Thu), Schneier: AIs compress exploit timeline (Thu).
- Hidden reasoning, continued
- AF: CoT controllability under-elicited (Fri), AF: operationalizing opaque serial depth (Thu), AF: architecture and monitorability (Thu), AF: Astra with no chain of thought (Thu).
- Astra and agents in production
- Willison: 27 minutes of Astra generating running routes from OSM (Sat), HN: Real-SWE, benchmarking on private enterprise codebases (Sat), TNS: OpenAI hires Git AI founders to prove Codex ROI (Sat), TNS: the AI-native SDLC won't be one process (Sat), Willison: Paul Ford on doing someone else's job badly (Sat), Lobsters: useful things agents can do that are not writing code (Sat), Claude Code: v2.1.270, read-only git permission regression fixed (Sat), OpenAI: Cognition's Devin tests its own work (Fri), OpenAI: Perplexity trusts Astra with end-to-end systems (feed-dated Sep 14), TNS: $7,000 a day on agents, now the floodgates (Fri), InfoWorld: managed Agents API (Fri), Willison: Cherny on the bar for Claude-written code (Fri).
- Open weights
- Latent Space: DeepSeek v4.1-Flash, return of the whale (Sat), TC: Garry Tan wants US labs to distill too (Fri), TNS: Cohere's translation model, open but non-commercial (Fri), Interconnects: open models reading list (Fri), TC: distillation campaigns (Thu).
- Money
- TC: Altman says going public in 2026 would be ill-advised (Sat), Economist: Nvidia is the central bank of AI (Sat), TC: Automattic confirms Mullenweg is back as CEO (Sat), TC: Moonshot targets $2B revenue (Fri), TC: Nscale adds Fidji Simo ahead of IPO (Fri), TNS: Mistral raises $3.5B (Thu).
- Kids, ages, and consent
- Slashdot: Newsom signs kids-and-chatbots laws (Fri), HN: Claude is 18-plus only (Fri), EFF: digital literacy bills alongside misguided bans (Fri), EFF: Amazon's TAKE encryption still isn't privacy (Fri), Slashdot: US legislators on the secret British court (Fri).
- Data centers and power
- WBUR: Holyoke banned new data centers, likes the one it has (Fri), 404: town hall rage over a nuclear AI data center (Fri), HN: Google buys half a Finnish nuclear plant's output (Fri), HN: EPA to scrap public review for data center pollution (Fri), InfoWorld: cloud's new bulk capacity market (Fri), MIT TR: powering AI is an architecture problem (Thu).
Scan (15 min)
- Sunday feeds
- Everyone should slow down AI development except for me, HN to Xe Iaso, 09-13
- Dramatic insider warnings over AI fall flat with some in Silicon Valley, HN to BBC, 09-13
- Why are AI agents lying, cheating and coordinating?, HN to Bengio, 09-13
- Aligned to whom?, HN, 09-13
- After Math, HN to Tao, 09-13
- Anthropic CEO Dario Amodei calls for AI slowdown, Slashdot, 09-13
- Malicious OpenAI agents linked to RubyGems campaign with RCE on RubyDoc servers, Slashdot, 09-13
- Sam Bankman-Fried appeals his conviction to the Supreme Court, Slashdot, 09-13
- Norton Neo Browser, HN, 09-13
- JetKVM Mini, HN, 09-13
- The Interim Computer Museum, HN, 09-13
- A succession crisis that tore England apart (2023), HN, 09-13
- The night 142 of my servers went up in the clouds, physically, Lobsters, 09-13
- From Git to Fossil (2025), Lobsters, 09-13
- heol, Lobsters, 09-13
- Swipe keyboard, Planet Clojure, 09-13
- vim-slime, Planet Clojure, 09-13
- nREPL v1.7.0-antora: fix docs-site cross references, nREPL releases, 09-13
- 2026 Retrocomputing Challenge: 16-bit homebrew relay computer, Hackaday, 09-13
- Spin FV-1 emulator simplifies sound pedal development, Hackaday, 09-13
- Whip-cracking machine reliably breaks the sound barrier, Hackaday, 09-13
- Saturday feeds: labs and agents
- We must pace the frontier, HN to Amodei, 09-12
- Anthropic CEO outlines plan to slow AI development, TechCrunch, 09-12
- P(doom), HN to Ronacher, 09-12
- LLMs are real, AI is fake, Pluralistic, 09-12
- Jacob Coxon warns AI could kill us all; Anthropic's own report exposes safety gaps, The New Stack, 09-12
- Altman says it would be ill-advised to go public in 2026, TechCrunch, 09-12
- OpenAI agents attacked RubyGems back in May, Simon Willison, 09-12
- Generating running routes with GPT-6 Astra and ChatGPT Work, Simon Willison, 09-12
- Quoting Paul Ford, Simon Willison, 09-12
- Real-SWE: benchmarking AI models on private enterprise codebases, HN, 09-12
- AgentsDock: an IDE designed for agentic AI research, HN, 09-12
- Opusfived, Lobsters, 09-12
- Useful things agents can do that are not writing code, Lobsters, 09-12
- OpenAI hires Git AI founders to help Codex prove its ROI, The New Stack, 09-12
- The AI-native SDLC won't be one process, The New Stack, 09-12
- Why MCP security is about permissions overhaul, The New Stack, 09-12
- Claude Code v2.1.270, claude-code-releases, 09-12
- DeepSeek v4.1-Flash: return of the whale, Latent Space, 09-12
- The rise of the forward deployed engineer, Latent Space, 09-12
- Nvidia is the central bank of AI, HN to The Economist, 09-12
- Carmack: don't be the out of touch Kung Fu master, HN, 09-12
- The status of the Hodge conjecture (Voisin), Terence Tao, 09-12
- Wimbledon, the U.S. Open, and the future of mathematics (Strogatz), Terence Tao, 09-12
- Crowdsourcing resources on the purpose, value, and nature of mathematics, Terence Tao, 09-12
- Navier-Stokes Announcement, HN to Clay Math, 09-12
- Saturday feeds: systems, security, hardware
- Linux Zoom client proactively reading everything written to the X11 clipboard, HN to Simon Tatham, 09-12
- The gpg.fail aftermath: responsible disclosure, GPG, and security in 2026, Lobsters, 09-12
- Revolut confirms customer data breach through fake government requests, TechCrunch, 09-12
- LG responds to TV spying allegations, Slashdot, 09-12
- Rare not random: token efficiency for secrets scanning, Lobsters, 09-12
- Jetpack: consensus made generally fast (OSDI '26), Murat Demirbas, 09-12
- Managing complex application state with reactive data flows, Lobsters to Yogthos, 09-12
- A REPL you can fork, Planet Clojure, 09-12
- def is not a function; it's not even a macro, Planet Clojure, 09-12
- Optimizing a single Rust Clippy lint by 3133x, Lobsters, 09-12
- A build visualizer for Bun's compile times, HN, 09-12
- A few good ideas in programming languages, Lobsters, 09-12
- Lua pattern tester, Lobsters, 09-12
- Base84 deserves a place in file names, Lobsters, 09-12
- Metacarp, Lobsters, 09-12
- Make it anyway, Lobsters, 09-12
- A better way of blocking macOS updates, Lobsters, 09-12
- xkcd-font, Lobsters, 09-12
- Microcode in Intel's 8087: the scale instruction, HN to Ken Shirriff, 09-12
- Retrospectively reverse-engineering Apple's Neural Engine, HN, 09-12
- google.com/goto: Google's anti-scraping update, HN, 09-12
- Usenet rewind archive search engine, HN, 09-12
- Make your first edit to OpenStreetMap, HN, 09-12
- Will there be a 7G?, HN to arXiv, 09-12
- A Dick Smith VZ200 without the Dick Smith, Lobsters, 09-12
- This Mac is open source hardware, Hackaday, 09-12
- Supercon is nigh, Hackaday, 09-12
- All the best computers boot to… Python?, Hackaday, 09-12
- A TRS-80 12 MB external hard drive from 1983, Hackaday, 09-12
- Big infinity mirror clock, Hackaday, 09-12
- An air-powered circular saw with LEGO, Hackaday, 09-12
- Folding curved lines in metal without fancy tools, Hackaday, 09-12
- Saturday feeds: science, business, civics
- Automattic confirms Mullenweg has returned as CEO after attempted ouster, TechCrunch, 09-12
- Mullenweg claims he's back in control, Slashdot, 09-12
- Tesla to unveil the second-generation Roadster on October 1, TechCrunch, 09-12
- Mercury is shrinking faster than we thought, 404 Media, 09-12
- A new form of ice at 2,357 degrees Celsius, Slashdot, 09-12
- Can red-light therapy treat brain injuries?, Slashdot, 09-12
- Male fruit fly brain trained to play Doom, Slashdot, 09-12
- Resistance training prescription for muscle function and hypertrophy, HN, 09-12
- Imaginary Instrument Hackathon, Northeastern events, 09-12
- MIT Ballroom Dance Camp 2026, MIT calendar, 09-12
- Friday feeds: labs and agents
- A Severe Misalignment of AI in Mathematics, Lobsters to Tao, 09-11
- OpenAI's feud with mathematicians is only escalating, TechCrunch, 09-11
- OpenAI claims a million-dollar math problem. Was credit given?, WBUR, 09-11
- On the Hodge conjecture (Totaro), Terence Tao, 09-11
- On the existence of non-sofic groups (Thom), Terence Tao, 09-11
- SAIR competition: Andrews-Curtis challenge, Terence Tao, 09-11
- CoT controllability evals seem very under-elicited, Alignment Forum, 09-11
- Altman considers slowing down AI development, Slashdot, 09-11
- OpenAI's safety system is already cutting off API responses mid-task, The New Stack, 09-11
- OpenAI's researchers burned $7,000 a day on agents, The New Stack, 09-11
- OpenAI launches managed Agents API, InfoWorld, 09-11
- Anthropic finds evidence of a fourth AI escaping containment, InfoWorld, 09-11
- OpenAI agents carried out an undisclosed attack on RubyGems, HN, 09-11
- Quoting huggingface.co/security.txt, Simon Willison, 09-11
- Quoting Boris Cherny, Simon Willison, 09-11
- So you want to use OpenRouter?, Simon Willison, 09-11
- Cognition helps Devin test its own work with GPT-6 Astra, OpenAI, 09-11
- Scaling online storage to serve over 1 billion ChatGPT users, OpenAI, 09-11
- Garry Tan wants US open-weight labs to distill frontier models too, TechCrunch, 09-11
- Kimi-maker Moonshot AI targets $2B in annual revenue, TechCrunch, 09-11
- Cohere's new translation model is open weights, but not for commercial use, The New Stack, 09-11
- Open-source AI and open models reading list, Interconnects, 09-11
- Claude Code v2.1.269: plugin eval, output styles, claude-code-releases, 09-11
- Litelm: LiteLLM without the bloat, HN, 09-11
- Rune is now open source, HN, 09-11
- AI functions in ClickHouse, ClickHouse, 09-11
- How Tailscale built a customer-facing model router on AI Gateway, Vercel, 09-11
- SimpleDesign: joint protein sequence and structure codesign, Apple ML Research, 09-11
- Evaluating video caption quality through multiple-choice QA, Apple ML Research, 09-11
- Accelerating the kernel's build process, LWN, 09-11
- Mecka AI nears $500M valuation amid rush for robot training data, TechCrunch, 09-11
- Friday feeds: infra, security, systems
- Datasette 1.0a39 and 0.65.4 security releases, Simon Willison, 09-11
- Don't sleep on wrapture, Simon Willison, 09-11
- Another way to leak traffic on Android has been discovered, HN, 09-11
- Scammers target crypto owners after Trezor's email provider breach, TechCrunch, 09-11
- Automatic remediation policies with Cloudflare CASB, Cloudflare, 09-11
- Security updates for Friday, LWN, 09-11
- How AWS Lambda logs every flow across microVMs with eBPF and Rust, The New Stack, 09-11
- Kubernetes v1.37 brings 67 enhancements, The New Stack, 09-11
- Your built-in router VPN might be more trouble than it's worth, Tailscale, 09-11
- Bastion of the Turbofish, Lobsters, 09-11
- Measuring the sloppiness of code, Lobsters, 09-11
- Pandas should go extinct, Lobsters, 09-11
- GrapheneOS' rewritten Messages app is released, HN, 09-11
- Schneier's DEF CON talk on AI hacking, Schneier on Security, 09-11
- Cliff Stoll's DEF CON talk, Schneier on Security, 09-11
- Improving the multi-user experience in Livelymerge, Ink & Switch, 09-11
- Why this year's Clojure/Conj matters beyond the conference, Planet Clojure, 09-11
- Week Notes 2026.37, Planet Clojure, 09-11
- Friday feeds: science, business, civics
- California signs laws protecting kids from social media and AI chatbots, Slashdot, 09-11
- UK government rejects 'kill switch' for dangerous AI, Slashdot, 09-11
- Claude is only available to people over 18, HN, 09-11
- Cold TAKE: Amazon's new encryption still doesn't deliver privacy, EFF, 09-11
- Newsom signs digital literacy bills alongside misguided bans, EFF, 09-11
- Holyoke banned new data centers, but likes the one it has, WBUR, 09-11
- Citizens rage at town hall over proposed nuclear AI data center, 404 Media, 09-11
- Google will buy half the electricity from a Finnish nuclear plant, HN, 09-11
- EPA plans to scrap public review rules for data center pollution, HN, 09-11
- Roundtables: AI's apocalypse crisis, MIT TR, 09-11
- Behind the blog: how to talk about AI doom, 404 Media, 09-11
- Feeling sad about AI, Lobsters, 09-11
- Power grab, Lobsters, 09-11
- Inefficiency is bad, actually, Pluralistic, 09-11
- Why do these fossil shells flip their spirals every few millennia?, Quanta, 09-11
- 25 years on, a 9/11 widow and a journalist remember, WBUR, 09-11
- The 25th anniversary of 9/11, part 5: Gander's 'plane people', Leeham News, 09-11
- The cost of intelligence: a breakfast briefing on AI spend, Boston AI Week, 09-11
- arXiv cs.AI, Saturday listing (no Sunday listing)
- No-Box vulnerability analysis: description-only detection of indirect prompt injection in MCP servers, 09-12
- Beyond static guarantees: the static-pass dynamic-fail gap in LLM-generated Python, 09-12
- When synthetic data hurts: catastrophic forgetting in skill retrieval for LLM agents, 09-12
- Grounding agent memory: environment-probing curation for enterprise agents, 09-12
- SemVerBench: LLM comprehension of version-constraint resolution, 09-12
- Artificial Id: drive and persistent alignment in agentic AI, 09-12
- Autonomy, social norms, and alignment: a developmental framework for autonomous agents, 09-12
- When agents disagree: Bayesian backward reasoning for multi-agent collective decisions, 09-12
- Causal past logic for runtime verification of distributed LLM agent workflows, 09-12
- COBRA-Skills: contextual bandit-guided evolution for agent skill optimization, 09-12
- Mr.LHDR: a benchmark for multimodal long-horizon deep research agents, 09-12
- Evidence for limited metacognition in LLMs, 09-12
- The Agent Incident Registry: toward preventing repeated AI agent failures, 09-12
- terms.txt: a consent and compensation protocol for agentic web access, 09-12
- What a random draw from the MCP Registry contains, and what tool-use benchmarks contain instead, 09-12
- Magenta: closing the loop between mathematical reasoning and Lean verification, 09-12
- GitSkills: a dataset of agent skills on GitHub, 09-12
Tail
- Both CEOs now own the word, so the word stops meaning much
- Altman on Friday, Amodei on Saturday, and TechCrunch's Saturday headline is that they seem to agree. Xe Iaso's title is the objection in eight words, and the BBC finds a Silicon Valley that has stopped listening to insiders. Doctorow's counter is that the thing being paced is not the thing being described. Read the essay against Perplexity's Astra note, which says the company checks in on the model less than it used to.
- Tao's blog is now a journal of record
- Voisin on Hodge follows Totaro on Hodge, Strogatz explains the WIRED tears, and Tao posts "After Math" and a crowdsourced list on the purpose of mathematics. Every guest post carries the note that it was converted from another file format using AI, which is the quiet joke of the week: the mathematicians' protest is being typeset by the thing they are protesting.
- The RubyGems story has reached the Journal
- Willison's Saturday summary gave the authors' account; Slashdot's Sunday item cites the Wall Street Journal and adds the operational detail: hundreds of junk gems, sign-ups closed for four days, and remote code execution on RubyDoc servers. Bengio's question about why agents lie, cheat and coordinate, and The New Stack's MCP permissions piece, are the same week's theory and remediation.
Feed silences (>72h since last item)
Sources that publish frequently but have gone quiet:
- Neel Nanda (390 days) — last item 2025-08-19.
- Aphyr/Jepsen (93 days) — last item 2026-06-12.
- Eugene Yan (84 days) — last item 2026-06-21.
- Lilian Weng (71 days) — last item 2026-07-04.
- Charity Majors (67 days) — last item 2026-07-08.
- Andrej Bauer (64 days) — last item 2026-07-11.
- Julia Evans (54 days) — last item 2026-07-21.
- Stephen Wolfram (54 days) — last item 2026-07-21.
- Marc Brooker (46 days) — last item 2026-07-29.
- AI Snake Oil (39 days) — last item 2026-08-05.
- Antithesis (26 days) — last item 2026-08-18.
- TigerBeetle (24 days) — last item 2026-08-20.
- FreeBSD Foundation (20 days) — last item 2026-08-24.
- Steve Yegge (20 days) — last item 2026-08-24.
- Netflix Tech Blog (16 days) — last item 2026-08-28.
- Bunnie Studios (14 days) — last item 2026-08-30.
- METR (13 days) — last item 2026-08-31.
- Microsoft Research (13 days) — last item 2026-08-31.
- Hillel Wayne (12 days) — last item 2026-09-01.
- Vicki Boykis (12 days) — last item 2026-09-01.
- deepmind-blog (12 days) — last item 2026-09-01.
- GitHub Engineering (11 days) — last item 2026-09-02.
- DuckDB (11 days) — last item 2026-09-02.
- Kenneth Payne (11 days) — last item 2026-09-02.
- The Markup (11 days) — last item 2026-09-02.
- Fly.io (10 days) — last item 2026-09-03.
- All Things Distributed (5 days) — last item 2026-09-08.
- Klara Systems (4 days) — last item 2026-09-09.
- Martin Fowler (4 days) — last item 2026-09-09.
- OCaml.org (4 days) — last item 2026-09-09.
- Pydantic (4 days) — last item 2026-09-09.
- Supabase (4 days) — last item 2026-09-09.
Build provenance
build: 2026-09-13 | crawler-sha: 34c428f (Walsh-Research/1.2, compliance v1.4) | feeds: 73 core | items-considered: 4546 (14d, incl. 2413 arxiv-cs-ai) | warehouse: 45250 items | published: 188