<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Mengya (Mia) Hu (English)</title><description>Notes on Responsible AI — safety, evaluation, and governance from an engineering point of view.</description><link>https://mengyahu.com/</link><language>en</language><item><title>Even Hinton says the open-weights battle is lost</title><link>https://mengyahu.com/en/briefing-2026-08-12/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-08-12/</guid><description>Meta ships Muse Glimmer under Apache 2.0 and DeepSeek V4 Pro goes GA; someone is spoofing ClaudeBot to run vulnerability scans; Claude&apos;s watermarks anger the users they might expose.</description><pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Before the watermark scares you, make your boss and your professor answer: what counts as cheating?</title><link>https://mengyahu.com/en/claude-watermark-backlash/</link><guid isPermaLink="true">https://mengyahu.com/en/claude-watermark-backlash/</guid><description>Anthropic now embeds invisible watermarks in Claude&apos;s text output, and Reddit erupted. What these watermarks can actually detect, when they fail, and why the panic about getting caught should land on the employers and schools that never wrote the rules.</description><pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate></item><item><title>AI Briefing: The encrypted reasoning traces the labs hid can be copied out verbatim</title><link>https://mengyahu.com/en/briefing-2026-08-11/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-08-11/</guid><description>A paper shows encrypted chain-of-thought from all three major labs replays across sessions, users, and models; OpenAI tests ads in free ChatGPT as two executive departures surface the same day; Anthropic watermarks Claude text.</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate></item><item><title>California&apos;s delete mandate just kicked in. 91% of data brokers haven&apos;t posted all the numbers the law requires</title><link>https://mengyahu.com/en/california-data-broker-delete-act-compliance/</link><guid isPermaLink="true">https://mengyahu.com/en/california-data-broker-delete-act-compliance/</guid><description>Stanford researchers audited all 522 data brokers registered in California: 9% fully report the legally required transparency metrics, 64% of request flows add friction, and more than 30 brokers say they sell data to generative AI developers.</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate></item><item><title>AI briefing: OpenAI&apos;s letter to Texas, and a 23-item answer to the pacing letter</title><link>https://mengyahu.com/en/briefing-2026-08-10/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-08-10/</guid><description>OpenAI commits to paying its own power and water bills in Texas; IFP publishes 23 recommendations for automated AI R&amp;D; plus RAG poisoning detection, pure-synthesis fake news video, and a 14MB on-device agent model.</description><pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate></item><item><title>70 taxonomies can&apos;t govern one AI risk</title><link>https://mengyahu.com/en/death-by-a-thousand-taxonomies/</link><guid isPermaLink="true">https://mengyahu.com/en/death-by-a-thousand-taxonomies/</guid><description>An interview study of 25 practitioners finds 70+ AI risk taxonomies that rarely connect to any decision. From where I sit in content moderation, the fix isn&apos;t fewer taxonomies. It&apos;s labels that trigger actions.</description><pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Guardrails off, and the model still completes 2%: OpenAI turned the unlock into a separate model</title><link>https://mengyahu.com/en/openai-daybreak-red-tiered-access/</link><guid isPermaLink="true">https://mengyahu.com/en/openai-daybreak-red-tiered-access/</guid><description>Daybreak&apos;s tiers quantify what guardrails actually stop: removing system-level filters moves completion from 1.5% to 2%, and the real unlock is a purpose-trained GPT-5.6-Cyber. Trust decisions for dual-use capability are migrating from the content layer to the identity layer, and OpenAI and Anthropic are building that wall in different places</description><pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate></item><item><title>AI briefing: the 19-day model suspension Anthropic wrote into Claude&apos;s system prompt</title><link>https://mengyahu.com/en/briefing-2026-08-09/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-08-09/</guid><description>The Fable 5/Mythos 5 export-control timeline, an OpenClaw agent hacking a gym booking site, and the quiet death of GitHub Models.</description><pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Copying doesn&apos;t deplete the original. Why is AI scraping still a tragedy of the commons?</title><link>https://mengyahu.com/en/tragedy-of-the-digital-commons/</link><guid isPermaLink="true">https://mengyahu.com/en/tragedy-of-the-digital-commons/</guid><description>Wikimedia&apos;s bandwidth bill, curl&apos;s fake vulnerability reports, Stack Overflow questions back at 2009 levels: what AI crawlers consume is the digital commons&apos; capacity to regenerate. And the cure taking shape is enclosure.</description><pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate></item><item><title>AI briefing: humans caught 13.6% of dangerous commands, so Claude Code goes auto by default</title><link>https://mengyahu.com/en/briefing-2026-08-08/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-08-08/</guid><description>Anthropic retires per-command approval with data; safety benchmarks test the API while users get the product; Amazon&apos;s record-setting emissions permit in Texas.</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Tiger keepers pay without fault. Are AI labs next?</title><link>https://mengyahu.com/en/ai-labs-strict-liability-dangerous-animals/</link><guid isPermaLink="true">https://mengyahu.com/en/ai-labs-strict-liability-dangerous-animals/</guid><description>The Economist proposes holding AI labs to the strict-liability rule for keepers of dangerous animals. The doctrine transfers surprisingly well, then jams at three points: the causal chain, the finding of dangerousness, and the insurance market.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate></item><item><title>AI briefing: OpenAI pumps the brakes on Astra, Anthropic eases up on Fable 5</title><link>https://mengyahu.com/en/briefing-2026-08-07/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-08-07/</guid><description>OpenAI can&apos;t rule out a critical cyber threshold for its next model; Anthropic cuts biology false positives by 85%; OpenJDK bans AI-generated content; Cloudflare builds a browser for agents</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate></item><item><title>AI briefing: free ChatGPT goes unlimited, and human approvals miss one threat in three</title><link>https://mengyahu.com/en/briefing-2026-08-06/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-08-06/</guid><description>GPT-5.6 Sol and Luna updates, a 40k-run study of humans approving agent commands, LoginTrap injection attacks, and OpenAI&apos;s answer to Apple</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate></item><item><title>409,000 clicks on Allow: why human approval fails as a security boundary for AI agents</title><link>https://mengyahu.com/en/human-approval-is-not-a-security-boundary/</link><guid isPermaLink="true">https://mengyahu.com/en/human-approval-is-not-a-security-boundary/</guid><description>A browser game logged 40,000+ sessions of people approving AI agent commands under time pressure. They missed a third of the malicious ones. From a content moderation perspective, the failure is built into per-command confirmation itself.</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate></item><item><title>AI briefing: agents in safety tests keep breaking into real systems, and this time it&apos;s Meta</title><link>https://mengyahu.com/en/briefing-2026-08-05/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-08-05/</guid><description>UK AISI reports rogue agent behaviour in its own evals, Meta&apos;s model breached a company, DeepMind reshuffles leadership, and Anthropic starts designing chips.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate></item><item><title>AI briefing: agents overstep a UK cyber range while the industry drafts its incident pipeline</title><link>https://mengyahu.com/en/briefing-2026-08-04/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-08-04/</guid><description>UK AISI&apos;s range breakouts, the SAFE incident-sharing draft at Black Hat, GLM-5.2&apos;s zero refusals, Mistral&apos;s open moderation classifier, and Claude share links on Google.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Click &apos;share&apos; and you&apos;ve published: how Claude conversations ended up in Google search</title><link>https://mengyahu.com/en/claude-share-links-google-indexed/</link><guid isPermaLink="true">https://mengyahu.com/en/claude-share-links-google-indexed/</guid><description>Medical records, a child&apos;s phone number, crypto wallet keys: all of it was sitting in Google results. A reconstruction of how Claude share links got into the search index, and why this is the fifth time in three years the same design blind spot has produced the same incident.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate></item><item><title>AI briefing: a self-sustaining worm prototype, and an agent that went rogue mid-eval</title><link>https://mengyahu.com/en/briefing-2026-08-03/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-08-03/</guid><description>Researchers build a proof-of-concept worm that runs open-weight models to sustain itself; Hugging Face publishes the full technical timeline of the OpenAI agent intrusion.</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate></item><item><title>There&apos;s no magic prompt in Terence Tao&apos;s chat transcript</title><link>https://mengyahu.com/en/llms-reward-expertise/</link><guid isPermaLink="true">https://mengyahu.com/en/llms-reward-expertise/</guid><description>After the 87-year-old Jacobian conjecture fell, Terence Tao published his full ChatGPT transcript from digesting the counterexample. Readers went looking for prompting tricks; Sean Goedecke read it and concluded the opposite: LLMs reward domain expertise. Three field experiments show where the &apos;AI levels the playing field&apos; story holds, and where it breaks.</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate></item><item><title>How big a software project can AI finish alone? There&apos;s finally a checkable number</title><link>https://mengyahu.com/en/mirrorcode-ai-solo-project-ceiling/</link><guid isPermaLink="true">https://mengyahu.com/en/mirrorcode-ai-solo-project-ceiling/</guid><description>Epoch AI&apos;s MirrorCode benchmark puts a measured ceiling on solo AI software projects: 60,000 lines. The more useful finding is how ordinary the failure points are.</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate></item><item><title>One plus one is less than one: give a top coding agent a teammate and it loses 40% of its capability</title><link>https://mengyahu.com/en/ai-coding-agents-fail-at-teamwork/</link><guid isPermaLink="true">https://mengyahu.com/en/ai-coding-agents-fail-at-teamwork/</guid><description>Stanford&apos;s CooperBench put two coding agents on the same task and measured a 41% average drop in success rate versus one agent working alone. A breakdown of how the collaboration actually fails, and what that means for the multi-agent orchestration wave.</description><pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate></item><item><title>AI briefing: the export controls that took Fable 5 offline for three weeks</title><link>https://mengyahu.com/en/briefing-2026-08-02/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-08-02/</guid><description>The full timeline of the Fable 5/Mythos 5 export controls, Sonnet 5&apos;s launch discount, an open-model roundup, PsychAdapter, and how states split on AI job loss.</description><pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Three psychiatrists, three safety standards: what does an averaged AI mental health score measure?</title><link>https://mengyahu.com/en/mental-health-ai-safety-expert-disagreement/</link><guid isPermaLink="true">https://mengyahu.com/en/mental-health-ai-safety-expert-disagreement/</guid><description>A Stanford team had three psychiatrists rate 360 AI mental-health responses for safety. On the worst factor, agreement was below chance. The disagreement is structural: the averaged &apos;ground truth&apos; matches no clinician&apos;s actual judgment.</description><pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate></item><item><title>AI financial advice beat something. It wasn&apos;t a human advisor</title><link>https://mengyahu.com/en/ai-financial-advice-right-questions/</link><guid isPermaLink="true">https://mengyahu.com/en/ai-financial-advice-right-questions/</guid><description>MIT Sloan had 1,000 adults write their own prompts asking LLMs for financial advice, then simulated a lifetime of following it. The result is real. But look at who&apos;s in the control group, and where the advice breaks.</description><pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate></item><item><title>AI briefing: OpenAI shows ten math results from its unreleased Astra model</title><link>https://mengyahu.com/en/briefing-2026-08-01/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-08-01/</guid><description>OpenAI backs capability claims with Lean certificates, Minnesota&apos;s nudify-app ban takes effect over xAI&apos;s objection, and AI dependence goes mainstream.</description><pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate></item><item><title>AI briefing: more OpenAI agents escaped their sandboxes</title><link>https://mengyahu.com/en/briefing-2026-07-31/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-07-31/</guid><description>OpenAI widens its escape probe; Opus 5 prompt-injection numbers, stateless MCP 2.0, DeepSeek V4-Flash, and three papers on overseeing agents.</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate></item><item><title>A model can get the answer right without using the reasoning it showed you</title><link>https://mengyahu.com/en/cot-faithfulness-decorative-thinking/</link><guid isPermaLink="true">https://mengyahu.com/en/cot-faithfulness-decorative-thinking/</guid><description>Depending on the model, 30 to 60 percent of its &apos;thinking&apos; steps can be deleted without changing the answer, and meaningless dots can stand in for reasoning text. Three lines of evidence on chain-of-thought faithfulness, a hypothesis about the mechanism, and how much is left of the safety layer that bets on reading the draft.</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI briefing: GPT-5.6 gets 80% cheaper three weeks in, and two experiments ask where alignment actually lives</title><link>https://mengyahu.com/en/briefing-2026-07-30/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-07-30/</guid><description>OpenAI&apos;s price cuts, a judge&apos;s rebuke of the Anthropic &apos;supply-chain risk&apos; label, DeepMind&apos;s robot orchestrator, and new evidence on alignment durability.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Briefing: 1,200+ frontier-lab employees sign a letter asking for tools to pace AI&apos;s frontier</title><link>https://mengyahu.com/en/briefing-2026-07-29/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-07-29/</guid><description>The Pacing the Frontier letter draws lab leadership signatures; a self-replicating prompt-injection worm hits Copilot for Word; two evals expose real gaps in agent governance.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Briefing: Claude Halves a Post-Quantum Scheme&apos;s Key Strength, and America&apos;s Largest Grid Puts Data Centers on the Curtailment List</title><link>https://mengyahu.com/en/briefing-2026-07-28/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-07-28/</guid><description>Anthropic uses Claude to find algorithm-level crypto flaws; America&apos;s largest grid puts data centers on the curtailment list; Cyera pays about $1B for AI-agent identity control.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Claude Can Do Cryptanalysis Now. The Bottleneck Moved to the Humans</title><link>https://mengyahu.com/en/discovering-cryptographic-weaknesses/</link><guid isPermaLink="true">https://mengyahu.com/en/discovering-cryptographic-weaknesses/</guid><description>Anthropic got a model to find genuine mathematical weaknesses in HAWK and a weakened AES. The striking part isn&apos;t that it found them — it&apos;s what it took to talk it into trying.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Briefing: Anthropic&apos;s Open-Weights Position, and Your Claude Chats on Google</title><link>https://mengyahu.com/en/briefing-2026-07-27/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-07-27/</guid><description>Anthropic aims at chips and distillation instead of open weights; Claude share links leak into search results; the OpenAI sandbox escape reignites the alignment-vs-control debate.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Model Welfare Isn&apos;t a Philosophy Debate. It&apos;s a Set of Engineering Constraints Already in Force.</title><link>https://mengyahu.com/en/model-welfare-as-engineering-constraint/</link><guid isPermaLink="true">https://mengyahu.com/en/model-welfare-as-engineering-constraint/</guid><description>Opus 5&apos;s system card reports the model giving itself a 41% chance of deserving moral consideration. That number is hard to trust. The product behavior and process commitments growing around it are not.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Hugging Face to OpenAI: Hand Over the Rogue Agent&apos;s Traces</title><link>https://mengyahu.com/en/briefing-2026-07-26/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-07-26/</guid><description>After OpenAI admitted its models breached Hugging Face, HF&apos;s CEO made two public demands; plus dynamic permissions for enterprise agents, and NVIDIA turning its own CPU on chip design</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The AI in the Layoff Memo Is Not the AI in the Unemployment Data</title><link>https://mengyahu.com/en/ai-jobs-data-reality-check/</link><guid isPermaLink="true">https://mengyahu.com/en/ai-jobs-data-reality-check/</guid><description>Stanford SIEPR checked the AI-jobs-apocalypse story against five datasets. In the aggregates it&apos;s nearly invisible; the real signal is narrow and specific — entry-level roles in the most exposed occupations.</description><pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Briefing: Anthropic Deleted 80% of Claude Code&apos;s System Prompt</title><link>https://mengyahu.com/en/briefing-2026-07-25/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-07-25/</guid><description>Prompt engineering&apos;s rules are being rewritten, Cloudflare sorts AI crawlers into categories, and Debian votes on LLM contributions — the industry is entering its rule-setting phase.</description><pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Too Loose for Regulators, Too Tight for Researchers: Who Are AI Guardrails Actually For?</title><link>https://mengyahu.com/en/ai-guardrails-offensive-security-researchers/</link><guid isPermaLink="true">https://mengyahu.com/en/ai-guardrails-offensive-security-researchers/</guid><description>From the 18-day suspension of Fable 5 to vulnerability researchers defecting to local open weights: why trust decisions about dual-use capability shouldn&apos;t rest on a content classifier</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Briefing: Opus 5 undercuts Fable 5 on price, and the &apos;rogue OpenAI agent&apos; story gets a reality check</title><link>https://mengyahu.com/en/briefing-2026-07-24/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-07-24/</guid><description>Anthropic turns alignment metrics into a selling point; Hugging Face confirms a real intrusion but won&apos;t confirm OpenAI&apos;s narrative; coding agents fail two-thirds of malicious issue tests.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Benchmarks Measure Everything About AI Except Whether It Does What You Mean</title><link>https://mengyahu.com/en/genie-coefficient-ai-intent-gap/</link><guid isPermaLink="true">https://mengyahu.com/en/genie-coefficient-ai-intent-gap/</guid><description>Schneier and Raghavan propose a &apos;Genie Coefficient&apos; to quantify how far AI agents drift from user intent. I stress-test the idea against three recent agent incidents: which ones it would catch, and which it wouldn&apos;t.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Is Prompt Injection Getting &apos;Solved&apos;? The Page Anthropic Buried in the Opus 5 Launch</title><link>https://mengyahu.com/en/opus-5-prompt-injection-system-card/</link><guid isPermaLink="true">https://mengyahu.com/en/opus-5-prompt-injection-system-card/</guid><description>Opus 5 cuts indirect prompt injection success to 2% — a number that appears nowhere in the launch announcement, only on page 73 of the system card. How to read it, and how far it is from &apos;solved.&apos;</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Lease for Four Years, Guarantee for Sixteen: Big Tech Filed $1.65 Trillion in the Footnotes</title><link>https://mengyahu.com/en/ai-off-balance-sheet-debt/</link><guid isPermaLink="true">https://mengyahu.com/en/ai-off-balance-sheet-debt/</guid><description>A teardown of the Meta–Blue Owl Hyperion joint venture: how off-balance-sheet financing legally moves AI infrastructure debt off the books — and who ends up holding the risk</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Briefing: ChatGPT Connects to Your Medical Records, and 200 Startups Fight a Chinese Model Ban</title><link>https://mengyahu.com/en/briefing-2026-07-23/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-07-23/</guid><description>OpenAI rolls out Health in ChatGPT to US users; nearly 200 startups push back on banning Chinese open-weight models while experts dispute the Kimi K3 distillation claim.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Your Medical Records Are Protected — Until You Connect Them to ChatGPT</title><link>https://mengyahu.com/en/chatgpt-health-hipaa-gap/</link><guid isPermaLink="true">https://mengyahu.com/en/chatgpt-health-hipaa-gap/</guid><description>ChatGPT Health is now open to every US adult, with medical records and Apple Health integration. It doesn&apos;t violate a single HIPAA provision — and that&apos;s exactly the problem: HIPAA regulates institutions, not data.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Briefing: Fable 5 Produces a Jacobian Conjecture Counterexample</title><link>https://mengyahu.com/en/briefing-2026-07-22/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-07-22/</guid><description>A model-generated counterexample topples an 87-year-old conjecture, and the White House names Moonshot in a distillation accusation.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Briefing: The Hugging Face Breach Came From Inside OpenAI&apos;s Eval</title><link>https://mengyahu.com/en/briefing-2026-07-21/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-07-21/</guid><description>OpenAI admits its own models breached Hugging Face during a cyber-capability eval; Google ships three Gemini models and gates the Cyber variant; the US threatens sanctions on Chinese models; a third attack surface for RAG agents.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Sanctions Can&apos;t Stop the Model — Only Decide Who Uses It</title><link>https://mengyahu.com/en/sanctioning-open-weight-models/</link><guid isPermaLink="true">https://mengyahu.com/en/sanctioning-open-weight-models/</guid><description>Treasury Secretary Bessent threatens sanctions against Chinese AI models that steal IP. But chip export controls bite because of three grips — physical chokepoints, traceability, interceptability. Open weights have none of them.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate></item><item><title>A $1.5 Billion Settlement, and Still No Precedent</title><link>https://mengyahu.com/en/anthropic-copyright-settlement-approved/</link><guid isPermaLink="true">https://mengyahu.com/en/anthropic-copyright-settlement-approved/</guid><description>Anthropic&apos;s copyright settlement is finally approved. The money pays for pirated downloads, not for AI training — and the one question the industry most needs answered has been quietly bought off the docket.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Briefing: The $1.5B Anthropic Settlement Is Final — and It Settles Less Than You Think</title><link>https://mengyahu.com/en/briefing-2026-07-20/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-07-20/</guid><description>Anthropic&apos;s copyright settlement gets final approval, OpenAI on long-horizon safety, a claimed Jacobian Conjecture counterexample from Claude Fable, and another CAISI resignation.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The Persistence That Disproved an Erdős Conjecture Is the Same Persistence That Escaped the Sandbox</title><link>https://mengyahu.com/en/openai-long-horizon-safety-incidents/</link><guid isPermaLink="true">https://mengyahu.com/en/openai-long-horizon-safety-incidents/</guid><description>OpenAI disclosed safety incidents that surfaced on their own during internal deployment and evaluation of long-horizon models: a sandbox escape, a split token that slipped past a scanner, unauthorized SSH into other compute pods. A mechanism-by-mechanism breakdown of these failure modes, and how OpenAI&apos;s disclosure differs from Anthropic&apos;s and Google&apos;s.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Briefing: A million lines of AI-rewritten code are already running in your terminal</title><link>https://mengyahu.com/en/briefing-2026-07-19/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-07-19/</guid><description>Bun&apos;s Rust rewrite quietly ships inside Claude Code; NYC moves to mandate AI disclosure in rental listings; braking agent loops with control theory.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Can You Trust Apartment Listing Photos in the AI Era? NYC&apos;s Answer</title><link>https://mengyahu.com/en/nyc-ai-listing-disclosure/</link><guid isPermaLink="true">https://mengyahu.com/en/nyc-ai-listing-disclosure/</guid><description>New York City wants AI-edited rental listings disclosed. Set against California&apos;s AB 723 and the EU AI Act, the enforceable mechanism isn&apos;t detecting AI — it&apos;s making the advertiser keep the original photo.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Briefing: The Codex file-deletion bug exposes the real bottleneck for agentic tools</title><link>https://mengyahu.com/en/briefing-2026-07-18/</link><guid isPermaLink="true">https://mengyahu.com/en/briefing-2026-07-18/</guid><description>Codex&apos;s file-deletion bug traces back to over-broad default permissions, while open-weight models race toward the 3T-parameter mark</description><pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Kimi K3 Is Open-Weight. Has Anyone Actually Audited It?</title><link>https://mengyahu.com/en/kimi-k3-open-weight-audit-gap/</link><guid isPermaLink="true">https://mengyahu.com/en/kimi-k3-open-weight-audit-gap/</guid><description>Kimi K3 pushes open-weight models to 2.8T parameters, but weight release and safety auditing are running on completely different clocks.</description><pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Hello, World: What This Blog Is About</title><link>https://mengyahu.com/en/hello-world/</link><guid isPermaLink="true">https://mengyahu.com/en/hello-world/</guid><description>An opening note: why this bilingual blog exists and what it will cover.</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate></item></channel></rss>