I was just in Mumbai, and I have to give them credit for the progress they’re making on infrastructure. The new Aqua Line metro is phenomenal. But the amount of work India still has to do on basic cleanliness and sanitation and it is hard to understand until you see it yourself. Would love for more westerners to go just to understand how wealthy they are, but that's a different point.
Mumbai is completely surrounded by water, yet there are almost no places where people can actually enjoy the water. The beaches are filled with trash, the water is badly contaminated, and almost nobody swims, even when it’s brutally hot outside. Walking on the beach is just mud and trash meeting filthy water on the horizon.
There are much poorer places around the world where people can still use the beaches. This is not just about money. India has gone decades without adequate trash collection, sewage treatment, or enforcement for a population of more than a billion people. At this point, the scale of the problem feels almost impossible, and the oceans around the world are paying the price for Indias garbage output as well.
I like the direction Modi is taking the country, but India needs to treat cleanup like a national emergency. Stop with the small campaigns and organize a full scale blitz.
Offer unemployed people paid work picking up trash, clearing drains and waterways, cleaning beaches, and maintaining public spaces. Give them proper equipment and supervision. Then build the collection and waste processing systems needed to stop everything from becoming filthy again a week later.
India has shown that it can build metros, airports, highways, and digital infrastructure. Clean streets and usable water should be treated as infrastructure too.
Mumbai should have one of the greatest waterfronts in the world. Instead, it's has basically an irrelevant feature of the city and feels surrendered to sewage and garbage.
Sometimes when I'm on a call I wanna explain stuff using diagrams. Its too much of a pain to pull up excalidraw and share screen.
So, I'm making this browser plugin for myself.
Draw, Edit, Move, Scale objects on screen while you talk.
A short history of how we got here, because the chronology is the whole story.
January: the Pentagon demands unrestricted use of Claude for autonomous weapons and domestic surveillance. Anthropic says no.
February: the President orders every federal agency to drop Anthropic. The Defense Secretary bans Pentagon contractors from doing business with them. A rival announces its classified-network deal within hours.
March: the Pentagon designates an American company a "supply chain risk" under a statute written for foreign adversaries. A federal judge blocks it.
May: the Pentagon signs AI deals with seven companies. Anthropic is not one of them.
June 9: Anthropic releases Fable 5.
June 12: Commerce issues an export control directive over a jailbreak that, by the government's own account, was demonstrated verbally, came with no written explanation, and involves a capability you can get from other publicly available models today.
Two things are true at once.
First: Anthropic spent months marketing Mythos as too dangerous to release. Sam Altman said it was "incredible marketing to say we have built a bomb." The Commerce Department has now formally agreed it is a bomb. If you describe your product as a munition in every press release, eventually a government takes you at your word. They wrote the legal predicate themselves and called it a brand.
Second: we have run this experiment before. In the 90s the government classified encryption as a munition under ITAR. Activists defeated it by printing PGP's source code as a book, because books are protected speech and floppy disks were arms exports. A t-shirt with three lines of RSA Perl was legally a munition. The controls collapsed because math does not stop at customs.
The new wrinkle is the "deemed export" rule: showing controlled technology to a foreign national inside the US counts as exporting it abroad. Which is why Anthropic's own foreign-national employees are now locked out of the model they built. The munition is in the building and the people who made it are not allowed to look at it.
The jailbreak is the paperwork. The refusal was in January.
🦔Microsoft canceled its internal Claude Code licenses this week after token-based billing made the cost untenable, even for a company with effectively infinite cloud resources. Uber's CTO sent an internal memo warning the company burned through its entire 2026 AI budget in just four months. American AI software prices have jumped 20% to 37%, and GitHub (owned by Microsoft) is dropping flat-rate plans for usage-based billing across its products.
My Take
The AI subsidy era is ending in real time. The same company that put $13 billion into OpenAI and built the Azure infrastructure powering most of Anthropic's compute just looked at the bill from a competitor's coding tool and decided it was not worth paying. That is not a productivity failure on Anthropic's end. Token-based pricing is forcing every enterprise customer to confront the actual cost of running these models at scale, and the number turns out to be far higher than the flat-rate experiments suggested.
This ties directly to my Gemini Flash post yesterday. Anthropic, OpenAI, and Google all raised effective prices in the last six months. Enterprises that built workflows assuming AI costs would keep falling are now watching annual budgets evaporate in months. Two outcomes look likely from here. Either enterprises scale back AI usage to fit budgets, which slows the revenue ramp the labs need to justify their valuations ahead of IPOs, or the labs cut prices and absorb the losses, which makes the unit economics worse at exactly the wrong moment. Both paths land in the same place, the numbers stop working, and somebody has to take the writedown.
Hedgie🤗
I have three monitors on my desk. The left one shows the order book. The middle one shows Truth Social. The right one shows the investigation queue.
On April 21st, the left screen moved first.
I am a Senior Surveillance Analyst at a commodities exchange. I have held this position for nineteen years. My job is to monitor trading activity for suspicious patterns and generate compliance reports. I am employee of the quarter. I have a mug.
At 19:54 GMT on April 21st, someone placed 4,260 sell orders on Brent crude futures. They did this during post-settlement. The window after the market closes when daily volume is typically in the dozens. Sometimes single digits. Sometimes I watch the screen and nothing happens for forty minutes and I think about whether my daughter is happy.
On April 21st, someone placed $430 million in directional bets in 120 seconds during that window. One hundred and twenty seconds. I timed it on my watch because the system clock rounds to the nearest minute and I have found, in nineteen years, that precision matters to no one but me.
At 20:10 GMT, the President posted on Truth Social that he was extending the Iran ceasefire.
Brent dropped from $100.91 to $96.83.
I flagged the trade. I flag a lot of trades. I want to tell you what happens to my flags.
My flags go into a system called TRACE. Trade Review and Compliance Evaluation. I did not name it. The system generates a report. The report goes to a committee. The committee has a name I am not allowed to share but I can tell you it meets quarterly and the conference room has a credenza with bottled water that is sparkling because someone once put still water in the room and a managing director sent an email about it that was longer than most of my surveillance reports.
The committee reviews my flags. The committee has reviewed all of my flags. Here is the complete record of actions taken on my flags in 2026:
Reviewed.
That's it. "Reviewed" is a status. In compliance, a status is the absence of an action that has been given a name so it looks like one.
Let me show you my flags.
March 9th. Someone bet millions on oil falling at 18:29 GMT. Forty-seven minutes later, a CBS reporter posted that the President said the Iran war was "very complete, pretty much." Oil dropped 25%. Forty-seven minutes. I flagged it.
March 23rd. Someone sold 5,100 lots of Brent and WTI crude futures between 10:49 and 10:50 GMT. Fourteen minutes later, the President posted on Truth Social about a "COMPLETE AND TOTAL RESOLUTION" to hostilities. Oil dropped 11%. Over 13,000 contracts traded in sixty seconds after the post. Fourteen minutes. I flagged it.
April 7th. Someone established a $950 million short position in oil futures at 19:45 GMT. Three hours later, the President declared a two-week ceasefire. Nine hundred and fifty million dollars. I flagged it.
April 17th. Someone placed $760 million in bearish bets twenty minutes before Iran's foreign minister confirmed the Strait of Hormuz would reopen. Seven hundred and sixty million. I flagged it.
April 21st. The $430 million. Fifteen minutes. I flagged it.
That is $2.1 billion in directional oil bets in April alone. Every one of them landed on the correct side of a presidential announcement. Every one of them was placed in a window so narrow you could measure it in bathroom breaks. I flagged every single one.
The CFTC chair told a Congressional committee that his organization has "zero tolerance" for fraud and insider trading. I wrote that quote on a Post-it note and stuck it to my right monitor. The one that shows the investigation queue. The investigation queue has not moved since March.
Zero tolerance. Zero staff. Zero budget. Zero prosecutions under the STOCK Act since it was signed in 2012.
Fourteen years. The law has existed for fourteen years and has been enforced zero times. In compliance, we call that a compliance rate of one hundred percent. No cases filed means no cases lost. You cannot fail an audit you never conduct. We call that excellence.
Last month the White House sent an internal email to staff. I was not on the distribution list but I have read reporting on it and I need you to sit with what I am about to say. The email instructed White House staff not to use insider information to place bets on prediction markets.
The White House had to send a memo telling its own employees not to insider-trade.
I want you to read that sentence again. Not because the instruction was unclear. Because the instruction was necessary. Because someone in the building looked at the same pattern I have been flagging for months on my three monitors and decided the appropriate response was an email.
The President's son sits on the advisory board of Kalshi. He is an investor in Polymarket. Both are prediction markets. Both saw accounts created days before U.S. military action.
One account. I cannot stop thinking about this account. It was called "Burdensome-Mix." It was created in December. On January 2nd, it placed $32,500 on Venezuela's president being removed from power. On January 3rd, Maduro was seized by U.S. special forces. Burdensome-Mix collected $436,000. Then it changed its username. Then it disappeared.
One account is a coincidence. But there were six.
Six accounts were created on Polymarket in February. All bet on U.S. strikes on Iran by the 28th. When the President confirmed the strikes, the six accounts collected $1.2 million between them. Five of the six never placed another bet. The sixth went on to correctly predict the ceasefire date and made another $163,000.
My surveillance system logged all of this. My system logs everything. My system does not have opinions and neither do I. I generate reports. The reports go to committees. The committees meet quarterly. Between meetings, the windows get shorter and the bets get larger.
March 9th: 47 minutes. March 23rd: 14 minutes. April 17th: 20 minutes. April 21st: 15 minutes.
The window is compressing. In March, you had time to make coffee between the trade and the announcement. By April, you had time to send a text. By summer, at this rate, the trade and the announcement will be the same event.
The spokesman said any implication that administration officials are engaged in insider trading is "baseless and irresponsible reporting."
Then the White House sent the email again.
I have been in compliance for nineteen years. I have seen insider trading run out of strip mall offices by men who could not spell "derivative." I have seen pump-and-dump schemes coordinated over WhatsApp by people who used their real names. I have seen a man try to manipulate soybean futures from a Panera Bread.
I have never seen $2.1 billion in perfectly timed trades across five presidential announcements in a single month go uninvestigated.
But I have also never seen a compliance system work this beautifully. Every trade flagged. Every report filed. Every committee briefed. Every quarterly meeting attended. Bottled water: sparkling. Minutes: distributed.
Zero prosecutions.
As long as the flags go up and the cases don't, my performance review says I am meeting expectations.
I am meeting expectations. The system is meeting expectations. The $2.1 billion is meeting expectations. The fourteen-year-old law with zero prosecutions is meeting expectations.
The left screen moves. The middle screen moves. The right screen stays perfectly, immaculately still.
In my field, we call this price discovery.
Incident Response Plans assume attackers move at human speed.
The Vercel security breach just made that assumption dangerous.
Here's the attack chain.
A Context employee got compromised.
Context compromise exposed Google Workspace OAuth connection linked to a Vercel employee's account.
From there, the attacker moved through Vercel's internal systems before most teams would have finished writing the incident ticket.
Vercel's CEO said it directly:
The attacker was "significantly accelerated by AI" with "surprising velocity and in-depth understanding" of their systems.
That's not standard breach language.
That's a CEO telling you the attacker knew his internal environment better than most insiders and got there faster than any traditional red team would.
That's the new baseline for what a sophisticated attack looks like.
Two exposures worth auditing in your own environment this week.
- The "non-sensitive" classification blind spot.
The attacker enumerated variables that weren't flagged sensitive.
That label didn't reduce risk, it reduced visibility of incorrectly marked sensitive variables.
Most teams treat it as a safety signal when it's actually a monitoring gap.
- The OAuth trust chain.
One compromised third-party AI tool -> One OAuth connection -> Internal access.
Most organisations can't tell you how many OAuth grants exist across their teams, which AI tools hold them, or what those tools can actually reach inside their environment.
Shadow AI have never just been about data leaving your organisation. It's about access entering through tools your team connected months ago and nobody reviewed since.
AI-accelerated attackers don't give you the dwell time your IR playbook was written for. The reconnaissance that used to take weeks now happens in the time it takes your SOC to triage the first alert.
Vercel responded well, he was transparent that Mandiant has been engaged, law enforcement notified, customer guidance published fast. The attack was sophisticated. The response was professional.
The advice from them for customers is to reset all your API Keys for Vercel.
The question for the rest of us is what we do with this before it shows up in our environment.
- How many third-party AI tools in your stack have OAuth access to internal systems and when did you last review them?
#vercel #aisecure #shadowai
STAY WITH ME.
A few years ago, a patient was referred to me because he was diagnosed with complicated cirrhosis. He had an infection which led to a condition called hepatic encephalopathy (brain failure due to high ammonia levels). The treatment largely involved ammonia reducing therapies. One drug was central to this - Rifaximin - a non-absorbable antibiotic that reduced ammonia in the body. I prescribed him Rifaximin for 6 weeks and advised him follow-up.
He came back to me, not after six weeks, but in 4 weeks, this time, in liver coma (worst stage of brain failure - due to very high ammonia). He spent two days in the ICU and six days in total in the hospital. His hospital bill was close to INR 80,000. He had no insurance and his wife borrowed the money from neighbors and friends to clear hospital dues.
Upon questioning, I found that he was not taking the Rifaximin drug I had prescribed. He was only on the other two drugs (one, a syrup called lactulose for improving ammonia clearance in gut). I was furious, because the patient spent a whole week unecessarily in the ICU and wasted so much money that he never had - just because he was "not compliant" to my orders. I decided it was time for me to school him a bit.
But I was wrong. He was compliant. He had purchased Rifaximin and was on it. For 15 days. Thereafter, he could not afford it. He was an autorickshaw driver who shuttled school children every morning and evening. He could hardly make ends meet. He had two children of his own. The Rifaximin brand I prescribed him was 42 rupees per tablet. He had to consume two a day - which would mean 2520 rupees a month. He just did not have that money - so he skipped it - to not compromise on other important matters - childrens education and food.
He was confused and scared about opting for a cheaper version of Rifaximin because one, he was unsure about the quality of Rifaximin that was not prescribed by me and two, he was "scared" that I would scold him for buying a cheaper Rifaximin and if that got him into trouble.
I was confused and scared about prescribing a cheaper version of Rifaximin because one, I was unsure about the quality of Rifaximin that was not "a good promoted brand" and two, I was "scared" that his family would scold me for prescribing a cheaper Rifaximin and if that got him into trouble.
It is heartbreaking that many doctors still simply don’t trust generic medicines. Too often, they worry that these cheaper options are lower quality or might cause more problems than the big, famous brands. This fear leads them to prescribe expensive drugs instead, and the real tragedy is that it pushes vital healthcare out of reach for the ordinary people who need it most - like my patient.
This narrative, that generic drugs 'are never good' and that only big pharmaceutical marketed drugs are what works has been deeply ingrained into doctors and patients alike - I do not know by whom and since when. Looking back, these strong emotions were based on either opinions, testimonials or second- and third-hand information. Not evidence.
Like I said. Stay with me. This is life changing and will disrupt the drug market in India. Here are the results of The Citizens Generic vs. Brand Drugs Quality Project.
1/11
The Subtle Art of Overeating Politely
A hotel’s complimentary buffet breakfast is the closest thing to a polite catastrophe . At 6:30 a.m., grown adults who normally need three alarms to wake up are already hovering outside the restaurant door like it’s a flash sale. The moment it opens, civilisation leaves the room . People surge forward with the desperation of a species that fears the poori might run away.
The continental section sits there, lonely, untouched. Croissants looking depressed, bread slices drying in the AC because the true desi minimalists walk past them like past bad memories. Bread and eggs? Why again? They station themselves at the dosa counter with the same intensity that they used for land disputes.
Meanwhile the Full-Hog Overachievers begin their day’s construction work: plate upon plate stacked with paratha touching pasta touching pineapple touching ideological confusion. They aren’t here to eat; they are here to economically punish the hotel for daring to include breakfast in the tariff. A subset of them say “ nothing is good” before they go for a second helping. Another guest drinks nine cups of masala chai and wonders aloud why his BP is rising. The rest of us know.
Then come the Protein Bros, those majestic creatures whose arms enter the buffet three seconds before the rest of their body. They demand fourteen egg whites and bargain like they’re at Chickpet. One bro even pours whey powder into sambar, declaring it a fusion dish. The chef’s soul quietly exits his body.
Nearby, a diabetic guest requests a strict egg-white omelette while simultaneously dual-wielding mango and pineapple juice like nutritional nunchucks. Their glucose meter files for voluntary retirement. And just when the buffet thinks it has seen enough, the rich sleepers float in at 11:20 a.m.Breakfast long gone, even the toaster unplugged. But time, to them, is a rumour. They demand pancakes from the void, and hotel staff obey with the resignation of civil servants during budget season. The order a la carte..
The business traveller meanwhile is on Day four and has a serving of toast–fried egg–coffee déjà vu. He pockets bananas like he’s smuggling state secrets, sips coffee with dead eyes, and silently wonders when he last felt joy. Children, on the other hand, are pure chaos wrapped in sugar.They are charging at waffles, drowning them in chocolate syrup, and rejecting anything that looks remotely like nutrition. The hotel staff steps aside as they sprint past, muffins in both hands like victorious gladiators. Their moms are trying to feed them something they detest. The dads overlook this event…
Uncles are the true apex predators: poori, dosa soaked in ghee, pongal the size of a meteor, five cups of chai, and then the inevitable announcement “I eat very light these days.”
Fitness Moms interrogate the buffet like they’re cracking a terror cell: “Which oil? Which farm? What breed of almond?” And after all this detective work, they consume three papaya cubes and radiate smug wellness.
Foreign tourists wander around in innocent confusion, eating idli with jam, mixing chutney with muesli, sipping sambar like broth until suddenly their tongue goes numb and they realise India has entered their bloodstream.
The lonely cereal guy sits surrounded by 800 calories of joy and chooses cornflakes anyway, crunching like he’s punishing himself for existing.
Somewhere, an influencer couple rearranges that poori for 40 minutes, taking photos from all angles. By the time they finish, the poori has the emotional stability of a punctured balloon. Nearby, professional buffet looters stuff muffins into handbags, slip bread rolls into jacket pockets, and walk out rustling like walking vegetable markets.
And through all of this, someone always makes an impossible request from masala cornflakes, gluten-free poha to a sugar-free gulab jamun while the staff stares into the horizon questioning every life choice.
A complimentary buffet breakfast is not nourishment. It is revenge, it is childhood trauma, it is class struggle, it is comedy, it is tragedy, it is a deeply personal confrontation with carbs.
It is the Olympics of Paisa Vasool. And after the dust settles, after the plates are cleared, after the last banana is smuggled away, everyone makes the same bold declaration:
“Tomorrow, I’ll eat light.”
And of course, as we leave, all of us are already telling the same lie to ourselves, the oldest lie in the history of complimentary breakfasts:
Tomorrow, we’ll behave better.
Tomorrow arrives.
We won’t.
But it’s sweet that we believe it.
To be clear: the problem isn't Copilot. It's the "add AI to everything" playbook. It's led to inferior and overpriced AI products.
$30/seat/month for a wrapper most teams could build in a weekend with MCP or Claude agents - customized to their actual workflows.
Microsoft is already scaling back because adoption is a ghost town.
https://t.co/qLkKBkn0pu
. @zomatocare I receive wet and damaged pizzas for my order and there is no way to reach out to customer support? Is this why you charge platform fees or all that jazz??
Just had a fascinating lunch with a 22-year-old Stanford grad. Smart kid. Perfect resume. Something felt off though.
He kept pausing mid-sentence, searching for words. Not complex words - basic ones. Like his brain was buffering.
Finally asked if he was okay. His response floored me.
"Sometimes I forget words now. I'm so used to having ChatGPT complete my thoughts that when it's not there, my brain feels... slower."
He'd been using AI for everything. Writing, thinking, communication. It had become his external brain. And now his internal one was getting weaker.
Made me think about calculators. Remember how teachers said we needed to learn math because "you won't always have a calculator"? They were wrong about that.
But maybe they were right about something deeper.
We're running the first large-scale experiment on human cognition. What happens when an entire generation outsources their thinking?
Don’t get me wrong, I’m beyond excited about what AI and AI agents will do for people in the same way that I was excited in 2009 when the App Store was launched.
But thinking out loud you got to think this guy I met with isn't the onnnnnly one that's going to be completely dependent on AI.