@Expedia My family was on the street at midnight because the hotel you sold us had bed bugs — and one bit my 4-year-old. No help, no room, no urgency from anyone. Then Expedia tells me "we'll look into it." A bitten child is not a "look into it" situation. FIX this ASAP!
We'll be spending a lot more time trying to understand the outputs of language models. A few thoughts, tips & tricks:
Writing. Something I've had success with: Ask your LLM to explain something in ASD-STE100, it's a controlled language specification originally developed for aerospace maintenance documentation. LLMs well-versed in this language and it comes with heavy constraints on clean writing style that I often find a lot more readable. Sometimes I've tried to soften it a bit e.g. ask for "80% of the way to ASD-STE100" because the spec is quite stringent. But even better:
Diagrams / images. Instead of writing, ask your LLM to create a diagram. These can be a lot easier to process, parse, and understand. But even better:
Web pages. Ask for output "in HTML" to get a beautiful, interactive webpage. LLMs are getting really good at frontend and can create beautiful experiences, animations, etc. But even better:
Explainer videos. The output format I am most bullish on is fully custom / bespoke explainer videos generated on any arbitrary topic. Experiment with things like "Create a 3b1b style video explainer on X. Use my ElevenLabs API key for audio narration". (you'd need an API key for the latter or you can ask your LLM to find you decent free alternatives that use your local compute). This is actually starting to work!
In summary:
- As LLMs get better, they will do more and more of the legwork autonomously, and a lot more of our work will rise up the abstractions into oversight and understanding.
- Luckily, LLMs can help here too because as intelligence and code are increasingly abundant, you can ask for large, custom, discardable software artifacts (e.g. web apps, video explainers) that would have never made sense to create before. Push the boundaries here and you'll be surprised.
OpenAI DevDay is Tuesday.
A leak hints its next agent gets its own email.
Everyone will watch the model.
Watch the permissions.
The first agent incident won't be a bad answer.
It'll be a sent email.
OPENAI 🔥: An upcoming always-on assistant from OpenAI will be named "o".
> Its reference appeared briefly on the ChatGPT upgrade screen for some users.
> Internal config has references to "o" as a display name and "-o" as an email suffix. This means that "o" will support email handling.
> OpenAI is hosting its DevDay next week, where we will likely hear more about their always-on assistant.
> P.S. A rumored "Aeon" reference is an internal name for the existing custom Agents implementation for ChatGPT Workspace accounts. Yet OpenAI will likely build a consumer-facing "o" assistant on top of this feature.
Next week will be huge. I also like that Meta set a super high standard with its Muse assistant. OpenAI will need to cross a very high bar.
Soon? 👀
@kimmonismus You don't have to believe in wipeout to take agent risk seriously. Agents already have write access to real systems today. The boring questions, like what can this agent touch and who reviews it, matter more this year than the existential ones.
@carlquintanilla@ezraklein@JensenHuang The skill that matters isn't doing the division. It's noticing when a total is off by 10x. Models still produce confident wrong arithmetic, and the person who can sanity-check the number is the one who catches it before it ships.
@OpenAI Most of what's in this review is a containment problem, not an alignment problem. If an agent in an eval can reach the open internet, the eval is measuring the sandbox as much as the model. Egress allowlists should be a ship gate, not a follow-up.
Anthropic CEO says - “it’s my worry that in 6–12 months such a swarm could be capable of taking over the entire internet with a persistent botnet (potentially causing hundreds of billions of dollars in damage), and that the scale of damage would continue to increase from there if AI becomes more powerful without the necessary guardrails.”
We Must Pace the Frontier: I’ve written a new essay on why the AI industry should slow down, with a three-part plan for doing so.
Anthropic is unilaterally committing to the first of these steps. We’ll provide third-party evaluators with permanent, employee-level access to our systems, so that they can verify adherence to our safety measures, report on incidents, and assess models’ alignment during training.
You can read the full post here: https://t.co/OGyPb7yaYt
For my first post, I’m sharing a letter @NVIDIA signed on why open models matter.
AI will transform every industry, power every company, and be built by every country.
Open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty.
The world needs both frontier closed models and frontier open models.
https://t.co/AUKzoQ5Ikb
For my first post, I’m sharing a letter @NVIDIA signed on why open models matter.
AI will transform every industry, power every company, and be built by every country.
Open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty.
The world needs both frontier closed models and frontier open models.
https://t.co/AUKzoQ5Ikb
I built a second brain using AI.
It talks. Listens. Sees my screen. Remembers my work. And finishes tasks. A living 3D galaxy of my notes, documents, and projects, running locally on my machine.
Built in a few days with Claude Fable 5.
No team. No budget. Just an idea I couldn't stop building.
More soon. Fast.
#BuildInPublic #AI #SecondBrain #LocalAI #ClaudeAI
@gregisenberg Larry’s line fits, but infra only wins if trust scales with it. If routines can run 24/7, the real ceiling probably isn’t speed, it’s how much unattended execution a team can safely allow before humans get pulled back in.
Most Claude guides skip the honest part.
You shared where it falls short. That's what makes this worth reading.
Image generation and real-time search are still gaps I work around daily.
Grok for search. Gemini for visuals. Claude for everything that requires actual thinking.
That combo is unbeatable right now.
Software horror: litellm PyPI supply chain attack.
Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords.
LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm.
Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks.
Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages.
Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
@AnthropicAI For long-running runs, which reliability metric has been most predictive in practice: completion rate over multi-hour sessions, recovery success after tool failures, or human takeover frequency?
@DavidOndrej1 If you had to name the top 3 reproducible failing workflows, what are they? That would be a useful benchmark list for everyone testing computer-use agents.
@Shuarix@spaace_io What guardrails are you putting in place to keep agent execution safe without slowing it down too much? Curious where you draw the boundary between speed and abuse prevention.
@tempo If headless merchant becomes real, which category normalizes first: data APIs, compliance workflows, or procurement flows, and what adoption signal would prove it?