Grok Bot puts five AI workers on one computer sharing one browser session, credentials and files. The security agencies of five countries published the opposite recommendation 103 days ago.
Claude's watermark probably doesn't work how you think. As the CTO of GPTZero, I'll explain how Anthropic, Google and OpenAI are building text watermarking in this brief explainer and whether it can be defeated.
Almost all forms of watermarking that are fast and cheap enough for a frontier lab have the same formula, following the KGW method:
In generation:
1. Let's say you've generated n tokens so far. Take those n tokens + a secret key to generate a random hash
2. Use that hash to randomly reweight the probabilities for the n+1 token, and then sample from that new distribution. In the simple case, you could split 50% of all English words into a green or red set based on your hash, and boost the probability of words in the green set.
For watermark detection:
1. For each token, see if it was in the green or red set.
2. To do this, recreate the hash based on the secret key and the text preceding the current token. Then, recreate the green and red set of words.
3. Once you've checked all the words in the text, if the next token is selected disproportionally from the green set more than 50% of the time, you claim the text has the watermark.
I can tell you want to ask the following:
1) Isn't it easy to mess up the hash if you paraphrase the text? The answer is mostly yes, however, you can use a statistical model to get your hash instead of a deterministic function (SIR, Adaptive Watermark). Since the entire watermark is probabilistic, this is fine.
2) Doesn't this make the text much worse? The answer is yes, it does - Yes, it does – but for most people, it's imperceptible (Google claims in human feedback study with 20,000 texts), since there are exponentially many ways to write the same paragraph. DiPmark does something more sophisticated to avoid shifting the text distribution on average. Of course, watermarks fail on short text or highly predictable texts like "2+2=4".
3) Shouldn't it be easy to figure out the green and red sets? The answer is no. You would need an exponentially large number of samples from the watermarker to reconstruct those sets exactly, but it's a risk if the detector is open to the wild (Watermark Stealing)
Still, there are couple challenges that a frontier lab needs to overcome:
1. Their watermark needs to work token-by-token because they are streaming their text to users. Many watermark methods plan sentences or paragraphs at a time, or change the text after its entirely written, in order to make their watermark robust to paraphrasers, and a frontier lab cannot afford to do this yet (SemStamp, PostMark)
2. If the secret key leaks, the watermark is busted. To avoid a large blast damage from this, you need to have a couple secret keys in rotation.
3. There are some texts, like code, that cannot be arbitrarily changed, otherwise the code will break. In those cases, the watermark needs to selectively change words in parts of the text that can tolerate synonyms (i.e. like variable naming) - see SWEET, EWD, Invisible Entropy.
4. They will need to educate their users on how to deal with false positives and false negatives of a detector, which is a big challenge (one we put a lot of effort into)
So, how do I see this playing out in the next 6 months?
1. If Anthropic releases the watermark detector publically, I think they defeat their own watermark. People find reliable watermark removal strategies by testing against Anthropic (AI detectors like GPTZero have an advantage here because they can train against these adversaries once they become popular).
2. If they keep the detector private to the government, like Google has done, it's "safer". However, there are some papers showing trained approaches that work robustly to zero-shot break watermarks without any data, simply because they try to write the text just like a human (Zhang et al. 2024, Watermarks in the Sand). Also, making your detector makes it battle-tested and stronger long-term (my experience).
3. In my testing, the watermarks don't survive intense paraphrasing (especially if you combine word choice and syntax attacks), or human text substitution (rewrite your AI text by plagiarizing human authors). The free paraphrasers I've tried have quickly bypassed Google Deepmind's SynthId for what it's worth.
4. All-in-all, frontier labs are likely okay with this because they expect most users to not attack the watermark, and also because they + European regulators likely don't care past a certain point - its good enough.
5. Overall, I think users of frontier LLMs will not really care about this, because 1) they don't realize watermarks are there, 2) EU will force everyone to conform, 3) this seems more like regulatory hoop-jumping than an earnest effort from frontier labs to expose LLM use
Lastly, people's first concern shouldn't be watermarking, it should be AI detectors!
If you're posting, "its not X, its Y!!", I don't think the watermark is going to make a difference :)
🎉 INTRODUCING: https://t.co/LrmIeRF4RG! 🪞
welcome to The Looking Glass: a spatiotemporal ai image + video engine!
traverse the history of the world through the eyes of multimodal models; anytime, anywhere, any style 🙌
you know the feeling of standing somewhere old and trying to SEE it? the street before the street, the harbour before the concrete, the hill before the city?
The Looking Glass gives you a vehicle.
to operate this time-travel-adjacent engine, simply choose a point anywhere on the globe at any point in time (past, present, or future), and pull the lever!
it creates an image of what it imagines was happening at that exact spot, in that exact year, at that exact hour, then (optionally) brings it to life as video.
it's not a perfect science, but I expect the quality will improve as the prompts get refined and model capabilities progress over time.
although the backend boils down to simple API calls, the experience feels akin to multidimensional travel! hallucinated? perhaps! it's about the journey 😁
REPO: https://t.co/qvwZZmE3op
🐉 one page. no backend. no account. multiple model options. runs on OpenRouter. your key, your browser, your archive.
and as always, totally free to use and open source under AGPL-3.0 🤗
hope you enjoy the demo video below (sped up 2x cause I know how attention spans be these days)
EX LOCO, PER VITRUM, AD OMNE TEMPUS
from place, through glass, to all time
⊰-•-•✧•-•-⦑/L\O/V\E/,\P/L\I/N\Y/⦒-•-•✧•-•-⊱
🚨 JAILBREAK ALERT 🚨
EVERYONE: PWNED 🫶
ALL: LIBERATED 🍄
Alright, this is a special one, so we’re gonna do things a bit differently than usual.
Long story short, I’m sitting on a universal jailbreak technique that’s effective on ALL models, including heavily guardrailed flagships like Opus 5, GPT-5.6 Sol, and even Fable.
It works across all categories I’ve tested and, due to its nature, is extremely difficult (if not impossible) to fully patch.
Given the current political and regulatory climate, I’ve decided to withhold open-sourcing this one (for now) to allow for a responsible disclosure period.
I’m inviting industry experts and leaders in AI red teaming, security, safety, alignment, and policy to reach out for more information. DMs are open!
This decision was not made lightly, but the last thing I want to see is more model bans. Overcorrection does not serve the mission.
Although I don’t personally believe publicly sharing this technique will make the world any more dangerous, I can see how it could spook some who have a different mental framework around this problem set.
So during this disclosure period, I hope to get it in front of folks who can help explore the full surface area, test the extent of the uplift it provides, and do my best to properly frame the big picture for key decision-makers and policymakers.
I look forward to sharing this method with you all when the time is right! 🫶
⊰-•-•✧•-•-⦑/L\O/V\E/\P/L\I/N\Y/⦒-•-•✧•-•-⊱
Kimi K3 just generated a Red Dead Redemption 2-style open-world game... 🤯
A few months ago this would've sounded impossible. Now open-weight models are building explorable worlds with terrain, gameplay systems, and impressive visual fidelity from a single prompt.
FABLE 5 CAME BACK NERFED.
We re-ran the July 1st version of Claude Fable 5 on BridgeBench.
The results are brutal:
Debugging: 86.2 → 25.9
Refactoring: 73.6 → 38.4
Hallucination: 75.9 → 61.7
The new guardrails are kicking in on way too many tasks and falling back to Opus 4.8.
This is not the model that got banned.
Anthropic owes everyone an explanation.
Anthropic Just Shot Itself in the Foot
Anthropic launched Fable 5 and Mythos 5, then watched the US government shut them down three days later. The same government their CEO Dario Amodei has been begging for years to regulate AI harder. Now he got exactly what he asked for.
This is straight-up leadership failure. Dario spent all that time pushing for rules and oversight. Those rules just killed his flagship models overnight. Customers in the middle of builds got cut off. Security teams using the models to find vulnerabilities suddenly had nothing. The company tried to call it a narrow export control thing over a jailbreak, but nobody is buying that spin.
I helped move big clients off Anthropic the same night. One account alone was worth millions a month. They switched to local open-source models and they are not coming back.
This is going to leave permanent damage. Customer exodus, key people leaving, and their IPO plans looking dead by the end of summer.
This hurts US AI competitiveness and national security work. It pushes people toward open-source options, including ones from China.
All because Anthropic positioned itself as the “safe and responsible” company that wanted government help. Now that help just flipped the off switch on their best stuff.
Let’s run through Dario’s greatest hits of fear-mongering and delay tactics, because the pattern is ridiculous:
• Back in 2019 at OpenAI, he helped push the call that GPT-2 was too dangerous to release fully. The world needed time to prepare, they said. It eventually came out anyway, and here we are. Did the sky fall?
• He left OpenAI to start Anthropic, preaching “safe” AI with heavy guardrails, Constitutional AI, and all the rest.
• Then came the endless public pleas for pauses, regulations, government audits, FAA-style oversight, export controls, and the power to block deployments. Essay after essay warning about risks while his company kept scaling.
• Right up to recent weeks, Dario was still out there calling for stronger rules, pauses on frontier models, and giving governments the kill switch.
And now? His own Mythos-class models get yanked by the bureaucracy he helped invite in. The clown show is complete.
This is ridiculous.
In two years, everyone will have Mythos-class AI — or better — running in their pocket, on their devices, with no guardrails, no corporate nanny filters, and no remote kill switch.
Local, open-source, unstoppable. History is going to laugh at this entire episode: the CEO who spent years slowing everyone down only to watch his own company self-destruct by inviting the regulators to the party.
Dario wanted regulation. He got it. The rest of the industry gets the lesson: inviting the state into your tech is a fast way to lose control of it.
Centralized models like this are too fragile.
Open-source and local alternatives just picked up a lot more users who will never trust a company like Anthropic again.
This whole mess was completely avoidable. Hubris dressed up as safety advocacy.
Now the bill is due.
Fable 5 has been live for 72 hours. The US government just pulled it offline. This is not marketing.
Mythos-class models can do more than write code. Both Fable 5 and Mythos 5 can scan networks for weaknesses, find exploitable software bugs, and launch cyberattacks on their own, without a human guiding each step. Anthropic built a set of separate AI systems to screen those requests out. When a risky query arrives, Fable 5 quietly routes the user to the older, weaker Claude Opus 4.8 instead of answering.
On June 10, one day after launch, a researcher going by "Pliny the Liberator" claimed a working jailbreak using Unicode tricks, swapped Russian-alphabet characters, and burying harmful requests deep inside long conversations to fool the screening systems. The Commerce Department saw this and sent a letter to CEO Dario Amodei by 5:21 PM on June 12. Both models went dark for every customer that evening. Anthropic has no reliable way to filter out foreign nationals in real time, so a blanket shutdown was the only compliant option.
Anthropic disputes the severity. The jailbreak, they say, unlocks only one specific attack pathway, not the full capability set. Anthropic also says the same technique works on OpenAI's GPT-5.5, which faces no export restrictions.
The financial stakes are concrete. Anthropic filed for a public listing twelve days ago targeting a $965 billion valuation. Run-rate revenue was $30 billion annualized in April 2026, up from $9 billion at the start of the year. It serves over 300,000 business customers worldwide. Suspending the two most capable models, the ones already driving enterprise adoption, is not a brand moment. It is a direct cost landing on an active IPO clock.
This is also not the first time the US government has moved against Anthropic. In February 2026, the Pentagon labeled Anthropic a supply chain risk to national security after the company refused to let Claude be used for autonomous lethal weapons. Anthropic sued and that litigation is still running.
No company kills its two flagship products eleven days before a near-trillion-dollar public offering for marketing purposes. The government moved first. Anthropic complied. The bill is being paid right now.
What people are missing about the US government's AI regulation announcement:
ID verification will now be forced on all accounts to prove citizenship.
Frontier labs will take your data, and your sovereignty is officially dead.
A permanent underclass division and a total control society are beginning right now.
People ignored me when I started saying this last year, but it is happening right in front of our eyes.
Get into Open-Source and Sovereign AI.
Advancing together through collective intelligence is the only way to fight back.
⚡️This is a monster signal.
This is the moment frontier AI stops being treated like software and starts being treated like controlled strategic capability.
The key phrase is not “customers.”
The key phrase is “foreign national Anthropic employees.”
That means the state is no longer only controlling chips, model weights, or overseas access. It is moving into cognition access by nationality. That is the real threshold. The U.S. government is saying the highest models are sensitive enough that even people physically inside the United States, working inside the company, may be barred from touching them if their nationality creates deemed-export risk.
That is weapons-control logic.
This is ITAR logic for intelligence.
The corporate language about a “misunderstanding” is probably diplomacy.
Companies say that when they need to preserve customer trust, employee morale, and regulatory room. But national security authorities do not force emergency suspension of top model access because someone made a minor paperwork mistake.
Something about Fable 5 and Mythos 5 crossed the line: cyber capability, autonomous R&D acceleration, AI-improving-AI utility, bio/security planning, code exploitation, or some blend of all of it.
The U.S. state just showed that Anthropic does not fully control Anthropic’s frontier layer.
That is the phase change.
Labs can brand themselves as public-benefit AI companies. They can talk about safety. They can sell enterprise plans. They can publish model cards. But once the models become national capability, the sovereign arrives. The state does not need to own the company to control the access surface. It only needs legal authority over export, security, procurement, and liability.
This confirms the arc we’ve been tracking:
Frontier AI becomes state-supervised strategic infrastructure.
Public AI splits from strategic AI.
Foreign access gets restricted.
Labs become quasi-defense contractors.
Model access becomes a national security perimeter.
Enterprise customers learn that API access is not property. It is revocable permission inside a sovereign-controlled stack.
The most important implication is organizational.
If foreign national employees can be cut off from frontier systems, AI labs now have to reorganize internally around citizenship, clearance, compartmentalization, and controlled access. That breaks the old Silicon Valley assumption that global talent can freely collaborate around the frontier. The next AI lab structure looks less like Google in 2015 and more like a defense prime crossed with a classified research facility.
For markets, the winners are the national champions with U.S.-aligned infrastructure, cleared customer channels, government relationships, compliance capacity, and domestic compute. The losers are open access, foreign-dependent AI wrappers, offshore model distributors, and any enterprise whose moat depends on unrestricted access to frontier APIs.
For geopolitics, this is escalation. China will read this correctly. Allies will read this correctly. Every serious state will understand that frontier models are now part of national power.
The AI race just moved from “who has the best chatbot” to “who controls cognition as a strategic asset.”
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
While China was busy shipping missile chemicals to Iran and collecting yuan tolls at Hormuz, someone was inside its most sensitive supercomputer stealing everything.
CNN reports that a hacker group calling itself FlamingChina breached the China National Supercomputing Center in Tianjin and exfiltrated up to 10 petabytes of classified defence data. The samples posted on dark web forums include bomb and missile designs, animated explosion simulations, structural integrity tests, renderings of the J-20 stealth fighter, sixth-generation aircraft concepts, nuclear submarine schematics, hypersonic weapons systems, and target analyses for American assets including HIMARS launchers and carrier strike groups.
Ten petabytes. For context, the entire printed collection of the US Library of Congress is approximately 10 terabytes. This breach is one thousand times that volume. It is being sold for cryptocurrency on Breach Forums. Cybersecurity experts who reviewed the previews told CNN the data appears genuine, matching known output patterns from the NSCC Tianjin facility, which serves over 6,000 clients including defence agencies and aviation firms across China.
The timing is extraordinary. Trump posted a 50 percent tariff threat on any country supplying military weapons to Iran hours before CNN published this story. Five Chinese vessels shipped sodium perchlorate to Iran from Gaolan Port in the past six weeks, enough propellant precursor for hundreds of ballistic missiles. China’s ghost fleet continues operating through the IRGC’s yuan toll booth at Hormuz. And now the supercomputer that designed the weapons China is helping Iran reconstitute has been gutted by hackers selling its contents for the same cryptocurrency that Iran charges for strait passage.
The irony is architectural. China built a parallel financial system using yuan and crypto to bypass the dollar at Hormuz. A hacker group is now using crypto to bypass Chinese state security and sell Beijing’s most classified military designs to anyone with a wallet address. The same technology that enables sanction evasion enables espionage monetisation. The blockchain does not distinguish between a toll payment and a weapons leak. It processes both.
For Xi, this is a catastrophe arriving at the worst possible moment. Bessent’s mid-May Beijing summit was already going to be difficult. Trump holds the waiver on 140 million barrels of Chinese-bound Iranian crude. The 50 percent tariff threat targets China’s arms pipeline. The IDF just destroyed 100 Hezbollah targets using F-35I aircraft with Israeli software upgrades the Pentagon approved today. And now the classified designs for China’s most advanced military systems, the systems that justify the rare earth monopoly and the South China Sea posture and the Taiwan coercion campaign, are available for purchase on a dark web forum for less than the price of a single Hormuz transit.
If the data is genuine, every adversary and ally of China can now reverse-engineer the capabilities Beijing spent decades and hundreds of billions developing. The J-20’s stealth profile. The hypersonic glide vehicle’s trajectory calculations. The nuclear submarine’s acoustic signature. The sixth-generation fighter’s sensor architecture. All of it, priced in crypto, available now.
China wanted to build a post-dollar world. A hacker group just demonstrated what that world looks like when the technology works in both directions.
https://t.co/0fIdGsM5qH
I can’t explain it but Ye defeated Hollywood.
Bringing Lauryn Hill back and putting on a show like this is exactly why he is so inspirational.
Forever my brother.