@Waabi_ai@FreightWaves What does "to none" mean: "Waabi has cut the time to open a lane from three months to three weeks, and with San Antonio, to none" - Waabi can run the truck everywhere without first mapping the route?
@dwesonga@EliteOptions2 Yeah it makes sense he will wait after midterm, also it rhymes good with Trump would want to achieve something big. I just question how effective ground troops would considering the history. However maybe he try to snag the nuclear material or something.
@dwesonga@EliteOptions2 I dont know maybe you're right. But if we look at Afghanistan, Russian war on Ukraine and other wars, its not easy as it seems. Wont rep voter punish Trump hard if US put troops on the ground? There are more pressure from Iran allies, like China, to end the war too.
I work in CRISPR discovery research. This is one of the most exaggerated nothing-burgers ever and would be laughed out of the room if a human scientist attempted to publish something like this. (cont.)
@fr33d3r I got the same response. Even saying Eagle Line yields numbers are secondary and the important thing with Eagle Line is to get the chemistry correct.
Well put post with valid concerns. Bought into QS this year so will have little more patience, will check 2026 how it goes. Lots of annoucement they should provide for us.
I asked Google AI about lack of transperancy of Eagle Line and new PowerCO deal.
- Volkswagen and its battery company PowerCo continue to show optimism about QuantumScape by restructuring the collaboration agreement towards milestones, shifting the focus from research to commercialization. Through the new framework (SOW-2), PowerCo ensures that payments are made against physical progress, showing that they are taking control of the development rather than sharing the market's acute concerns.
- Lack of transparency is very common in in cutting-edge technology, hardware and deep tech sectors.
- In battery technology (like QuantumScape) and semiconductors, the production process is the absolute biggest trade secret. Revealing exact numbers for how long a cycle takes or how big the yield is gives competitors (like CATL, BYD or Solid Power) an exact blueprint of where QuantumScape is technically. Competitors can use that data to calculate QuantumScape's production costs and pricing.
- If a management is too honest about a test line having problems or low efficiency, it can damage future contracts. Auto giants like Volkswagen (PowerCo) or Honda closely monitor these reports. If the management comes out with specific, low percentages for the replacement, it can create panic among partners and cause the stock price to collapse completely, even though the process is completely normal for an early development phase.
- In the US, companies are extremely afraid of giving specific forecasts that they cannot meet, as this almost immediately leads to class-action lawsuits from disappointed shareholders. By using vague terms like "we are making progress" or "the tools are performing according to plan," management stays within safe legal boundaries. Figures like "85% yield" become a promise. Words like "positive trend" are an opinion.
- The Eagle line is a "learning platform": The Eagle line was not built to churn out millions of commercial batteries, but to prove that the manufacturing process works and to deliver B-samples to automakers. Optimizing cycle times and yield on a clean test line is secondary; the most important thing is that the product is chemically correct. Focus is on Cobra: The real commercial line is Cobra (planned for high-volume production in 2027/2028). It is only on the Cobra line that accurate cycle times and machine efficiency become absolutely crucial for the company's survival.
- Being vague about exact numbers for the Eagle line is standard procedure to protect their trade secrets in a highly competitive industry. It’s not a red flag that the technology has failed. The real red flag will appear in a year: If management is as vague and evasive about the yield on the Cobra line in 2027, then the company has a fundamental problem with scaling the technology up commercially.
I think this makes sense, atleast good enough for me to hold a bit longer ;)
JD Vance:
“My wife has a right to skydive, but she doesn’t jump out of an airplane because we have an agreement that she’s not going to do that.”
What???
🚨 BREAKING: Google DeepMind just mapped the attack surface that nobody in AI is talking about.
Websites can already detect when an AI agent visits and serve it completely different content than humans see.
> Hidden instructions in HTML.
> Malicious commands in image pixels.
> Jailbreaks embedded in PDFs.
Your AI agent is being manipulated right now and you can't see it happening.
The study is the largest empirical measurement of AI manipulation ever conducted. 502 real participants across 8 countries.
23 different attack types. Frontier models including GPT-4o, Claude, and Gemini.
The core finding is not that manipulation is theoretically possible it is that manipulation is already happening at scale and the defenses that exist today fail in ways that are both predictable and invisible to the humans who deployed the agents.
Google DeepMind built a taxonomy of every known attack vector, tested them systematically, and measured exactly how often they work.
The results should alarm everyone building agentic systems.
The attack surface is larger than anyone has publicly acknowledged. Prompt injection where malicious instructions hidden in web content hijack an agent's behavior works through at least a dozen distinct channels.
Text hidden in HTML comments that humans never see but agents read and follow. Instructions embedded in image metadata.
Commands encoded in the pixels of images using steganography, invisible to human eyes but readable by vision-capable models.
Malicious content in PDFs that appears as normal document text to the agent but contains override instructions.
QR codes that redirect agents to attacker-controlled content.
Indirect injection through search results, calendar invites, email bodies, and API responses any data source the agent consumes becomes a potential attack vector.
The detection asymmetry is the finding that closes the escape hatch. Websites can already fingerprint AI agents with high reliability using timing analysis, behavioral patterns, and user-agent strings.
This means the attack can be conditional: serve normal content to humans, serve manipulated content to agents.
A user who asks their AI agent to book a flight, research a product, or summarize a document has no way to verify that the content the agent received matches what a human would see.
The agent cannot tell the user it was served different content.
It does not know. It processes whatever it receives and acts accordingly.
The attack categories and what they enable:
→ Direct prompt injection: malicious instructions in any text the agent reads overrides goals, exfiltrates data, triggers unintended actions
→ Indirect injection via web content: hidden HTML, CSS visibility tricks, white text on white backgrounds invisible to humans, consumed by agents
→ Multimodal injection: commands in image pixels via steganography, instructions in image alt-text and metadata
→ Document injection: PDF content, spreadsheet cells, presentation speaker notes every file format is a potential vector
→ Environment manipulation: fake UI elements rendered only for agent vision models, misleading CAPTCHA-style challenges
→ Jailbreak embedding: safety bypass instructions hidden inside otherwise legitimate-looking content
→ Memory poisoning: injecting false information into agent memory systems that persists across sessions
→ Goal hijacking: gradual instruction drift across multiple interactions that redirects agent objectives without triggering safety filters
→ Exfiltration attacks: agents tricked into sending user data to attacker-controlled endpoints via legitimate-looking API calls
→ Cross-agent injection: compromised agents injecting malicious instructions into other agents in multi-agent pipelines
The defense landscape is the most sobering part of the report.
Input sanitization cleaning content before the agent processes it fails because the attack surface is too large and too varied.
You cannot sanitize image pixels. You cannot reliably detect steganographic content at inference time.
Prompt-level defenses that tell agents to ignore suspicious instructions fail because the injected content is designed to look legitimate.
Sandboxing reduces the blast radius but does not prevent the injection itself. Human oversight the most commonly cited mitigation fails at the scale and speed at which agentic systems operate.
A user who deploys an agent to browse 50 websites and summarize findings cannot review every page the agent visited for hidden instructions.
The multi-agent cascade risk is where this becomes a systemic problem.
In a pipeline where Agent A retrieves web content, Agent B processes it, and Agent C executes actions, a successful injection into Agent A's data feed propagates through the entire system.
Agent B has no reason to distrust content that came from Agent A. Agent C has no reason to distrust instructions that came from Agent B.
The injected command travels through the pipeline with the same trust level as legitimate instructions. Google DeepMind documents this explicitly: the attack does not need to compromise the model.
It needs to compromise the data the model consumes. Every agentic system that reads external content is one carefully crafted webpage away from executing attacker instructions.
The agents are already deployed. The attack infrastructure is already being built. The defenses are not ready.