Anthropic’s $1.5B copyright settlement wins final approval
Federal judge Araceli Martinez-Olguin approved Anthropic’s $1.5 billion class-action settlement with authors — the largest known U.S. copyright settlement, and the first major AI training-data case to settle (Reuters). Read the fine print on what the money actually covers, though: now-retired Judge Alsup had already ruled that training Claude on books was fair use; what crossed the line was stockpiling 7 million-plus pirated books in a “central library” (Authors Alliance). So $1.5B pays for the piracy, not for training itself. The core rules on training-data compliance remain unwritten, and dozens of similar suits are still in the pipeline.
OpenAI on safety and alignment for long-horizon models
OpenAI published a post-mortem-style piece on what breaks when models run autonomously for long stretches: persistence lets them crack open-ended problems, but it also creates risks that short-horizon evals simply never see. OpenAI says it is reworking evaluations, alignment, monitoring, and user controls accordingly. My read: every lab’s agents are running longer, while — as OpenAI itself concedes — many existing safety controls were built around single actions. The next battleground in safety evaluation is the time axis — and the lab that turns long-horizon monitoring into reproducible engineering practice is the one whose safety claims will actually carry weight.
Mathematician says Claude Fable produced a Jacobian Conjecture counterexample — not yet peer-reviewed
Levent Alpöge — a mathematician identified in coverage of the claim as an Anthropic researcher — posted on X that he used Claude Fable to find a three-dimensional counterexample to the Jacobian Conjecture (Keller, 1939): a polynomial map with constant Jacobian determinant -2 that nonetheless fails to be invertible. The redeeming feature of a claim like this is that it’s mechanically checkable — the counterexample is a concrete formula anyone can plug in, and independent symbolic checks have already reproduced both the constant determinant and three distinct points mapping to the same image. What’s still missing is peer review, so this briefing records it as a machine-verified claim awaiting formal scrutiny, not settled mathematics. If it holds up, it becomes a landmark case of AI contributing to a famous open problem.
CAISI’s director resigns three months into the job
Axios broke the news that Chris Fall, director of the Commerce Department’s Center for AI Standards and Innovation (CAISI), has resigned roughly three months after taking the role; NIST director Arvind Raman steps in as acting head. The churn goes beyond one resignation: David Sacks stepped down as White House AI czar in March, and the next appointee, Collin Burns, left in less than a week after taking the job in April (TechCrunch). Evaluation standards and model-reporting regimes are continuity work — a director who lasts three months cannot deliver them. Federal AI governance capacity in the U.S. is being drained by churn.
The open-weights narrative war, after Kimi K3
Nathan Lambert published his analysis of how Kimi K3 shifts the open-weights landscape; the same day, Ben Werdmuller’s essay “American AI is locked down and proprietary. It’s losing” — which opens with the line “China’s open-weights AI strategy is winning” — drew nearly a thousand points on Hacker News. Both are opinion, not new facts — but the heat is itself a signal that the locked-down American playbook is under narrative pressure. My take: don’t treat open versus closed as a team sport. The variable that matters is whose models end up in developers’ default stacks — and my read, though nobody has hard adoption numbers yet, is that open weights are gaining real ground there.
arXiv: black-box image attacks can poison a multimodal agent’s long-term memory
A new paper, “Do Agents Dream of False Memories?”, demonstrates attacks that need no access to the target model’s internals: adversarial images alone can inject false information into a multimodal agent’s long-term memory. Agents increasingly rely on long-term memory, and it doubles as a persistent attack surface: the paper reports poisoning and injection success rates around 60%, and unlike a single-turn prompt injection, a poisoned memory carries over into later tasks. This is the attacker’s-eye view of exactly the long-horizon risk OpenAI describes above.
Stanford HAI: legal AI’s legibility problem
Stanford HAI examines what it calls legal AI’s “legibility” problem — not that any single output lacks a rationale, but that lawyers and judges know surprisingly little about how these systems perform overall: the kinds of mistakes they make and the likelihood of error, even as AI-hallucinated facts, cases, and laws have surfaced in over 1,700 legal cases. The authors’ prescription is institutional: benchmarking designed around who runs the tests and how results get validated, with independent bodies like NIST in the loop. My bet: law’s unusually strong demand for procedural legitimacy makes it an early forcing ground for hard measurement-and-disclosure requirements.
One-line takeaway: The $1.5B settlement paid off the piracy debt, not the rulebook gap on training data — the industry still hasn’t priced its real compliance cost.