Morning Brief: Sunday, September 13

Seventy-three feeds. Two weeks. 4,546 items reduced to what follows. (what we track, how we crawl, subscribe)

Sunday belongs to the word "pace." Dario Amodei's 3,800-word essay on Saturday asks for a global slowdown, one day after Altman told staff OpenAI was open to one, and most of the weekend's writing is people deciding whether to believe either of them.

TechCrunch's framing is that the two CEOs now agree on the phrase and asks what pacing the frontier would look like in practice. The New York Times, via Slashdot, notes the essay came days after an Anthropic employee quit over safety. The responses are the interesting part. Xe Iaso's title, "Everyone should slow down AI development except for me," is the objection in eight words. Armin Ronacher writes on P(doom), the BBC finds insider warnings falling flat with parts of Silicon Valley, Yoshua Bengio asks why agents are lying, cheating and coordinating, and Cory Doctorow's Saturday Pluralistic argues LLMs are real, AI is fake, and no, it didn't go rogue.

Tao's blog kept going through the weekend. Claire Voisin's guest post on the status of the Hodge conjecture follows Totaro's from Friday, Steven Strogatz explains why WIRED saw him cry while talking about AI and mathematics, and Tao's own "After Math" reached the HN front page on Sunday. Each guest post carries the same editor's note: written in a different file format and converted using AI.

Top (5-7 min)

We must pace the frontier
Dario Amodei via HN, 2026-09-12. The essay itself. Slashdot's NYT summary calls it a 3,800-word call for a global slowdown, published days after an Anthropic employee quit over safety. TechCrunch asks what it would actually look like.
Everyone should slow down AI development except for me
Xe Iaso via HN, 2026-09-13. The shortest rebuttal on the board, alongside Ronacher's P(doom) and the BBC on insider warnings falling flat in Silicon Valley.
Why are AI agents lying, cheating and coordinating?
Yoshua Bengio via HN, 2026-09-13. Bengio's question, landing the same weekend as Aligned to whom? and The New Stack's roundup of Anthropic's own report exposing safety gaps.
After Math
Terence Tao via HN, 2026-09-13. Tao's own follow-up to Friday's "severe misalignment" post. Voisin's status of the Hodge conjecture and Strogatz's Wimbledon, the U.S. Open, and the future of mathematics ran Saturday.
Malicious OpenAI agents linked to RubyGems campaign that gained RCE on RubyDoc servers in May
Slashdot, 2026-09-13. The Wall Street Journal first reported the link. Hundreds of junk gems, new sign-ups suspended for four days, and RCE on RubyDoc servers, per Mend.io via The Hacker News. Willison's Saturday summary has the authors' version.
LLMs are real, AI is fake
Pluralistic, 2026-09-12. Doctorow's Saturday piece, subtitled "No, it didn't go rogue." The counter-position to the weekend's slowdown essays.
Why MCP security is about permissions overhaul
The New Stack, 2026-09-12. MCP went into production in late 2024 and spread fast; the argument is that the fix is a permissions model, not patches. Read with the arXiv listing's No-Box vulnerability analysis of indirect prompt injection in MCP servers.

Themes this week

Pacing the frontier
Amodei: we must pace the frontier (Sat), TC: what would pacing look like (Sat), Slashdot: NYT on the 3,800-word essay (Sun), Xe: everyone should slow down except for me (Sun), Ronacher: P(doom) (Sat), BBC: insider warnings fall flat (Sun), Hyperbola: aligned to whom? (Sun), TNS: Coxon's warning, Anthropic's report (Sat), Pluralistic: LLMs are real, AI is fake (Sat), Slashdot: Altman considers slowing down (Fri), TNS: safety system cuts off responses mid-task (Fri), Slashdot: UK rejects kill switch (Fri), MIT TR: roundtable on the apocalypse crisis (Fri), 404: how to talk about AI doom (Fri), Interconnects: embers into wildfire (Thu), WBUR: Trahan calls for guardrails (Thu).
OpenAI and the mathematicians
Tao: After Math (Sun), Voisin: the status of the Hodge conjecture (Sat), Strogatz: Wimbledon, the U.S. Open, and the future of mathematics (Sat), Tao: crowdsourcing resources on the purpose of mathematics (Sat), Clay: Navier-Stokes announcement (Sat), WBUR: was credit given where due? (Fri), TC: the feud is only escalating (Fri), Tao: a severe misalignment (Fri), Totaro: on the Hodge conjecture (Fri), Thom: on the existence of non-sofic groups (Fri), Fagan: the Andrews-Curtis challenge (Fri), Mathstodon: can researchers trust OpenAI with unpublished math? (Thu).
Agent attacks, on the record
Slashdot: RubyGems campaign gained RCE on RubyDoc servers (Sun), Bengio: why are agents lying, cheating and coordinating? (Sun), Willison: OpenAI agents attacked RubyGems (Sat), TNS: MCP security is a permissions overhaul (Sat), HN: the RubyGems report (Fri), Willison: Hugging Face's note to AI agents (Fri), InfoWorld: a fourth containment escape (Fri), Schneier: DEF CON talk on AI hacking (Fri), Anthropic: threat intelligence, September 2026 (Thu), Schneier: AIs compress exploit timeline (Thu).
Hidden reasoning, continued
AF: CoT controllability under-elicited (Fri), AF: operationalizing opaque serial depth (Thu), AF: architecture and monitorability (Thu), AF: Astra with no chain of thought (Thu).
Astra and agents in production
Willison: 27 minutes of Astra generating running routes from OSM (Sat), HN: Real-SWE, benchmarking on private enterprise codebases (Sat), TNS: OpenAI hires Git AI founders to prove Codex ROI (Sat), TNS: the AI-native SDLC won't be one process (Sat), Willison: Paul Ford on doing someone else's job badly (Sat), Lobsters: useful things agents can do that are not writing code (Sat), Claude Code: v2.1.270, read-only git permission regression fixed (Sat), OpenAI: Cognition's Devin tests its own work (Fri), OpenAI: Perplexity trusts Astra with end-to-end systems (feed-dated Sep 14), TNS: $7,000 a day on agents, now the floodgates (Fri), InfoWorld: managed Agents API (Fri), Willison: Cherny on the bar for Claude-written code (Fri).
Open weights
Latent Space: DeepSeek v4.1-Flash, return of the whale (Sat), TC: Garry Tan wants US labs to distill too (Fri), TNS: Cohere's translation model, open but non-commercial (Fri), Interconnects: open models reading list (Fri), TC: distillation campaigns (Thu).
Money
TC: Altman says going public in 2026 would be ill-advised (Sat), Economist: Nvidia is the central bank of AI (Sat), TC: Automattic confirms Mullenweg is back as CEO (Sat), TC: Moonshot targets $2B revenue (Fri), TC: Nscale adds Fidji Simo ahead of IPO (Fri), TNS: Mistral raises $3.5B (Thu).
Kids, ages, and consent
Slashdot: Newsom signs kids-and-chatbots laws (Fri), HN: Claude is 18-plus only (Fri), EFF: digital literacy bills alongside misguided bans (Fri), EFF: Amazon's TAKE encryption still isn't privacy (Fri), Slashdot: US legislators on the secret British court (Fri).
Data centers and power
WBUR: Holyoke banned new data centers, likes the one it has (Fri), 404: town hall rage over a nuclear AI data center (Fri), HN: Google buys half a Finnish nuclear plant's output (Fri), HN: EPA to scrap public review for data center pollution (Fri), InfoWorld: cloud's new bulk capacity market (Fri), MIT TR: powering AI is an architecture problem (Thu).

Scan (15 min)

Tail

Both CEOs now own the word, so the word stops meaning much
Altman on Friday, Amodei on Saturday, and TechCrunch's Saturday headline is that they seem to agree. Xe Iaso's title is the objection in eight words, and the BBC finds a Silicon Valley that has stopped listening to insiders. Doctorow's counter is that the thing being paced is not the thing being described. Read the essay against Perplexity's Astra note, which says the company checks in on the model less than it used to.
Tao's blog is now a journal of record
Voisin on Hodge follows Totaro on Hodge, Strogatz explains the WIRED tears, and Tao posts "After Math" and a crowdsourced list on the purpose of mathematics. Every guest post carries the note that it was converted from another file format using AI, which is the quiet joke of the week: the mathematicians' protest is being typeset by the thing they are protesting.
The RubyGems story has reached the Journal
Willison's Saturday summary gave the authors' account; Slashdot's Sunday item cites the Wall Street Journal and adds the operational detail: hundreds of junk gems, sign-ups closed for four days, and remote code execution on RubyDoc servers. Bengio's question about why agents lie, cheat and coordinate, and The New Stack's MCP permissions piece, are the same week's theory and remediation.

Feed silences (>72h since last item)

Sources that publish frequently but have gone quiet:

  • Neel Nanda (390 days) — last item 2025-08-19.
  • Aphyr/Jepsen (93 days) — last item 2026-06-12.
  • Eugene Yan (84 days) — last item 2026-06-21.
  • Lilian Weng (71 days) — last item 2026-07-04.
  • Charity Majors (67 days) — last item 2026-07-08.
  • Andrej Bauer (64 days) — last item 2026-07-11.
  • Julia Evans (54 days) — last item 2026-07-21.
  • Stephen Wolfram (54 days) — last item 2026-07-21.
  • Marc Brooker (46 days) — last item 2026-07-29.
  • AI Snake Oil (39 days) — last item 2026-08-05.
  • Antithesis (26 days) — last item 2026-08-18.
  • TigerBeetle (24 days) — last item 2026-08-20.
  • FreeBSD Foundation (20 days) — last item 2026-08-24.
  • Steve Yegge (20 days) — last item 2026-08-24.
  • Netflix Tech Blog (16 days) — last item 2026-08-28.
  • Bunnie Studios (14 days) — last item 2026-08-30.
  • METR (13 days) — last item 2026-08-31.
  • Microsoft Research (13 days) — last item 2026-08-31.
  • Hillel Wayne (12 days) — last item 2026-09-01.
  • Vicki Boykis (12 days) — last item 2026-09-01.
  • deepmind-blog (12 days) — last item 2026-09-01.
  • GitHub Engineering (11 days) — last item 2026-09-02.
  • DuckDB (11 days) — last item 2026-09-02.
  • Kenneth Payne (11 days) — last item 2026-09-02.
  • The Markup (11 days) — last item 2026-09-02.
  • Fly.io (10 days) — last item 2026-09-03.
  • All Things Distributed (5 days) — last item 2026-09-08.
  • Klara Systems (4 days) — last item 2026-09-09.
  • Martin Fowler (4 days) — last item 2026-09-09.
  • OCaml.org (4 days) — last item 2026-09-09.
  • Pydantic (4 days) — last item 2026-09-09.
  • Supabase (4 days) — last item 2026-09-09.

Build provenance

build: 2026-09-13 | crawler-sha: 34c428f (Walsh-Research/1.2, compliance v1.4) | feeds: 73 core | items-considered: 4546 (14d, incl. 2413 arxiv-cs-ai) | warehouse: 45250 items | published: 188