A researcher finds ChatGPT’s ad cookie linking your browsing back to your account
Security researcher Buchodi published a network-traffic analysis of OpenAI’s ad collection script: it sets a cookie called __obi with SameSite=None, so browsers attach it to cross-site requests bound for OpenAI’s endpoints, meaning any page that loads OpenAI’s ad resources sends it along. Across 936 advertiser pixels and over a thousand hostnames, he observed the same __obi value flowing back to OpenAI from a dozen commercial sites, including Chewy, Wayfair and Coursera, with the script also picking up on-page data such as email, phone number and form fields (email, phone and names are SHA-256 hashed before transmission). He reproduced the full chain on his own phone with two independent capture methods. OpenAI publicly documents its measurement pixel for advertisers, and the pixel’s other cookie, __obref, is set on each advertiser’s own domain and stays per-site; when he asked OpenAI support about __obi on September 14, he got no direct answers. Two limits he states himself: testing covered Chrome on Android only, and he did not directly observe the server side resolving the data back to individual accounts. My read: the mechanism is standard adtech, the same playbook as Meta’s and Google’s pixels. What changed is the host product, a chat assistant people confide in. Once ads enter the business model, “we don’t sell your data” deserves the same line-by-line scrutiny you’d give any ad network.
Google open-sources AX, an agent orchestrator built for billions of concurrent sessions
AX is a declarative orchestrator, meaning a control layer that schedules and manages large fleets of agent tasks: Tasks run in sandboxes with resource limits, Workspaces pre-provision repos and MCP servers, a Gateway allowlists outbound traffic, and a Model primitive centralizes model config and credentials, with sub-second suspend and resume for idle agents. This is Kubernetes thinking applied to agents. The hard problem in agent deployment is shifting from “is the model smart enough” to “how do you safely run ten thousand of these at once”, and Google is betting the answer is an infrastructure layer. (Also at agentexecutor.io.)
Pirate Face keeps a torrent copy of open models in case they get taken down
The project mirrors permissively licensed models (Apache-2.0, MIT) from Hugging Face as checksum-verified torrents, with Hugging Face itself as the web-seed, that is, the HTTP source the torrent pulls from: while a model is still up, downloads come straight from HF; the day it disappears, the peer swarm keeps serving it. “Open weights” has always carried a quiet assumption that the hosting platform never pulls the files. This turns model persistence from a platform promise into a distributed fact, a step worth remembering in open-model governance; by restricting itself to permissive licenses (with one approved exception, Kimi-K3), it largely keeps clear of copyright disputes.
A first-person account: the whole company ships Claude Code output nobody reads
X user voxium describes their new employer: specs, docs, tests and tickets all come out of Claude Code, engineers work 12-to-13-hour days mostly executing generated output, almost nobody at any level actually reads the material, morale is low, and management is pressing on. This is one person’s account on X, one side of the story. It still matches a pattern that keeps surfacing: once code generation stops being the bottleneck, human review capacity becomes the bottleneck. An organization that keeps the generation while dropping the review is accruing risk without gaining speed.
TechCrunch: world model labs won’t even brief their own data suppliers
Yann LeCun’s AMI Labs and Fei-Fei Li’s World Labs both keep product plans quiet: AMI co-founder Michael Rabbat says “we’ll talk about it when we’re ready to talk about it”, while Alex de Vigan, CEO of data supplier Physicl, complains that his team could build more useful data if they knew what the labs were working on. The game theory holds: don’t reveal your target market, and competitors enter later. The cost is that outsiders can’t evaluate these systems, and even the supply chain is working blind.
BBC: plenty of AI insiders don’t buy the extinction story
The BBC talked to people who have worked at OpenAI, Meta and DeepMind about last week’s viral doom warnings from former Anthropic employee Jacob Coxon; many reacted with jokes rather than alarm. Rishub Jain, who spent seven years at DeepMind before founding the safety research firm Sampura Research, told the BBC these ideas have been debated for years and the current tone is “definitely been a little jokey”. Views on existential risk inside the industry form a continuous spectrum. Reporting it as doomers versus accelerationists flattens what is actually there.
Vocci’s $249 ring is a voice recorder that looks like jewelry
A ring under 6 grams with titanium surfaces (likely a coating, per TechCrunch): double-tap to record, 8 hours per charge, transcripts and summaries in the app. TechCrunch’s review lands on the real issue: the recording indicator faces the wearer, so the person across the table has no way to tell they are being recorded. The smoother AI note-taking gets, the more consent depends on the wearer volunteering it, and the hardware is evolving toward forms the other party cannot detect.
Research radar
JEPA-Anything: Learning Predictive Models across Different Worlds
JEPA (joint-embedding predictive architecture, the world-model approach championed by LeCun that predicts in latent space instead of generating pixels) has mostly been domain-specific so far. This paper proposes Orthogonal Predictive Factorization: split the latent prediction target into complementary factors, learn each through its own pathway, then recombine them in a shared predictor. One framework runs across seven domains (vision, biology, clinical trajectories, control, molecular dynamics, physical fields, weather), beats baseline JEPAs on all 10 matched dynamics tasks, and one predicted biological intervention received experimental support in wet-lab work (cell co-cultures, patient-derived organoids, tumor fragments and mice). If you work on world models or scientific ML, the thing to check is whether the cross-domain experimental setup holds up; if it does, this is rare positive evidence that world models can become general infrastructure rather than per-domain tools.
Today in one line: the moment an AI assistant plugs into an ad business, its privacy promises need line-by-line rereading against adtech industry standards; __obi is just the first one that got caught.