I run open-weight models on my own hardware for work, so Dario Amodei's post(27th July, 2026) reached me as a customer rather than a spectator.
He opens with a flat denial that Anthropic ever advocated banning open weights, and calls open models without dangerous capabilities a public good. Every gram of weight in that sentence sits on the qualifier. Anthropic's own Responsible Scaling Policy states that the red-teaming it requires may be difficult or impossible to pass if the weights are released or unmoderated fine-tuning goes to untrusted users. So mandatory pre-release testing, applied to a downloadable model, is a release veto on frontier open weights. That is their paperwork reaching that conclusion, not a critic. UK AISI measured leading open models(GLM-5.2, DeepSeek V4-Pro) at four~seven months behind closed frontier on cyber in July 2026, down from six to ten months through 2025, so a bar set at the frontier bites open releases inside about half a year.
Then the distillation charge. OSTP Director Michael Kratsios publicly accused Moonshot of distilling Anthropic's Fable to build Kimi K3 on 22nd July, 2026, and Treasury Secretary Bessent floated sanctions, one day after Judge Martínez-Olguín granted final approval to the $1.5B Bartz settlement.
Here is what nobody has produced and what would actually settle it: the account identifiers and the proxy networks they ran behind, request logs with timestamps and token volumes, the specific terms-of-service clause said to be breached, an output-distribution comparison between K3 and Fable, and a plain timeline reconciling Fable 5's return to global access on 1st July with K3 shipping on 16th July. Independent researchers have already done the arithmetic on that 15~ day window in public and doubt it. Sanctions off unpublished forensics is not an evidentiary standard.
A released weight file is IRREVERSIBLE, and that part of Amodei's case is not in dispute. Adversarial fine-tuning evals and pretraining data filtration already exist as ways to clear a bar, OpenAI ran the malicious fine-tune on gpt-oss itself, so the fight is about calibration and about who administers the test.
As such, the line I want written down is not the definition of "sufficiently capable". It is what happens when the government administering the test wants something the tester refuses.
https://t.co/iKNIb0j43T
I keep local copies of open weights on cold storage, and the reason is dull: a checkpoint already on my disk cannot be rate-limited, price-hiked, silently swapped for a worse quantization, or geofenced away from Estonia because someone in Washington or Beijing changed their mind on a Tuesday.
Kimi K3 is 1,454 GiB. Somebody posted his download log on the 27th of July, 2026: 9.5 GB done after twenty-one minutes, 0.7 percent, throughput bouncing 3 to 15 MB/s, ETA jumping from 1,487 hours to 27.6 and back to 96.9. At his ~7.5 MB/s average that is ~58 hours of wall clock. It is attemptable at home at all because quantization-aware training runs from the SFT stage onward, so the shipped artifact IS the MXFP4 model, 1.5 TB instead of the ~5.6 TB an FP16 2.8T model would want.
Having it is not serving it. Raw weights are ~1.4 TB before KV cache, the practical floor people discuss is one 8x H200 node at MXFP4, roughly $50 an hour on CoreWeave.
So I changed what I mirror. Not just the weights now, also MoonEP, FlashKDA and AgentENV, the three repos that got one line at the bottom of the announcement. Weights let you run a frontier model, that toolchain is a large chunk of what you need to train one, and it is the heavier package by far.
The reason all of this sat in my bookmarks next to a wiped Pixel at Atlanta airport is in the longer piece.
https://t.co/K0Pc6CWyMG
Avi Loeb wants to know if some UAP are leftovers from a technological civilization that lived here before us. I think that question is sound and I hold that premise seriously. What I do not accept is the jump from the premise to lights over Virginia, argued on Medium with every outcome counted as a win.
The arithmetic is what does the damage. Vanguard 1, up since 1958, re-enters around 2198, so ~240 years. LAGEOS was deliberately engineered for persistence and carries a plaque mapping continental drift over its ~8.4 million year lifetime. That is the ceiling our species has managed, and it sits one to two orders of magnitude under the 10⁸ years this scenario needs. Oceanic crust rarely gets past ~200 Myr before subduction eats it. So orbit and surface both fail. Schmidt and Frank(International Journal of Astrobiology, 2019) and Jason Wright already said where to look instead: lunar regolith, buried Martian layers, isotopic and sediment chemistry at the hyperthermals. Look where nothing moves. Not up.
The end-Triassic claim is the checkable one and it does not hold. The Central Atlantic Magmatic Province was emplaced synchronously, mercury anomalies show up across six separated sections, the carbon excursions model out as mantle plus thermogenic. The basalts explain it. An unobserved civilization adds nothing.
And the part almost nobody reported: Galileo Project's own observatory reconstructed ~500,000 trajectories, hand-reviewed ~80,000 outliers, 144 stayed ambiguous, zero confirmed anomalies. The speculation travels, the null result dies quietly.
I still do not hand the agencies a clean bill. Bodies that classified their own sightings for decades do not get to be trusted when they announce there was nothing worth classifying. But I would take one falsifiable claim about the Moon over three unfalsifiable ones about the sky.
I wrote the longer version here.
https://t.co/H6JHc3vish
#UAP #SilurianHypothesis
Safety is the most elastic word in AI right now, and it bends toward whoever is paying to define it.
Two provocations this week. Pliny the Liberator says anyone who actually cared about safety would ban closed models before touching open ones. Anthropic's critics mock Dario Amodei for lobbying against open weights while Jensen Huang cheers them on. Put them together and the real question shows up: what is the word safety doing, and who ends up protected when the argument wins.
Pliny has a point worth taking seriously. A market where a few closed labs hold the frontier is itself a hazard, because concentration invites regulatory capture and lets a handful of firms decide who gets to build. Closed does not mean safe either; GPT-4 and Claude get jailbroken at high rates. But he is wrong that openness and safety point the same way. Once weights are public they cannot be recalled. That is not a slogan, it is the load-bearing fact. The Safety Gap Toolkit showed guardrails on Llama fall off after fine-tuning on a few dozen bad examples. In bio and cyber uplift, that gap is the whole game.
The Anthropic complaint is not asking Amodei to open his models. It is asking him to stop paying government to shut down the people who do. In one quarter of 2026 Anthropic spent about 1.97 million on federal lobbying, outspending NVIDIA, and pushed amendments into SB 1047. Amodei's irreversibility argument is real. It also happens to disadvantage every cheaper open competitor at once: Llama, Mistral, DeepSeek, Kimi. A safety case that lines up this neatly with a company's balance sheet earns scrutiny, not deference.
An official statement is a claim. The spending is the mechanism. In this fight the invoice carries as much information as the testimony.
Wrote out the longer version here.
https://t.co/22hfcYoDvR
Two documents from the last week of July 2026, both dressed as public interest, both written by people protecting something.
The first is a three-page letter, "Open Weights and American AI Leadership," that Jensen Huang chose for his debut post on X. Eleven million views. The argument is clean and largely correct: open-weight models mean cheaper access, competition across the stack, no vendor lock-in, safety through transparency. But read the signatory list and the story tells itself. Nvidia, Meta, Microsoft, Mistral, Hugging Face, a16z, Y Combinator. Everyone who profits when AI gets cheaper and more portable. Missing: OpenAI, Anthropic, Google, the three whose premium comes from per-token access to something you cannot download. Julian Schrittwieser nailed it, joking he looked forward to Nvidia open-sourcing CUDA. Open where Jensen sells more chips, closed where he owns the platform. Every model that ships anywhere drives demand for the hardware to run it. He is talking his book, and it is a very good book.
The distillation clause near the end is the actual policy fight, landing days after Bessent floated sanctioning Chinese models for IP theft. On Anthropic, be exact: the Bartz ruling found training on books was fair use, but downloading pirated copies to build a permanent library was not. Up to seven million books, a 1.5 billion dollar settlement. The books claim holds. The GitHub-and-papers claim does not, and flattening the two helps whoever is shouting.
The same week, India's Education Minister resigned over the NEET-UG leak, an exam that gates medical college for over 20 lakh students, leaked again despite a 2024 law. His letter frames it as shielding the young from confusion, not as a system failing twice. What forced him out was Sonam Wangchuk's 26-day hunger strike, not the letter. That gate decides whether a poor kid becomes a doctor. It got a fraction of the volume, which tells you whose problems get narrated as urgent.
I wrote the longer version here:
https://t.co/9DzIAYyUe3
Scott Bessent posted a warning on X that draws a border in real time: open source is not open season on American IP, and PRC firms running "industrial-scale distillation attacks" will face sanctions and Entity List designations. Clean sentence. It falls apart the moment you ask what distillation is and who does it.
Distillation is old, boring engineering. A smaller student model learns from a larger teacher's outputs, matching behavior, not lifting weights or training files. Hinton and company wrote it up in 2015. It has been standard ever since. Google sells it as the Gemini Distillation Service. Llama and Gemma were built this way. Musk admitted xAI "partly" trained on OpenAI, breaking OpenAI's own terms. So the technique is not the crime. Everyone in the room uses it.
The evidence is thin. Bessent's proof is that officials keep "finding watermarks" of US models on Chinese ones. He named no company, no legal authority, no detection method, and showed nobody the work. When a government asserts a technical finding you cannot check, that is a claim, not a fact.
The lawyers who would try these cases are not confident. If AI outputs are not copyrightable, training on them does not infringe. What is left is a contract clause most people never read, unenforceable against proxies in a foreign court. Theft sounds punishable. That is why they say theft.
And the glass house is loud. Bartz v. Anthropic held that copying books to train Claude was "quintessentially transformative" fair use. Copy every human author, that is transformation. Let a rival learn from your model, that is an attack. Both cannot be principled.
I have watched this shape before. A country takes freely from the commons, then writes the law that makes taking back a crime, and calls the wall protection. Britain drained India and called it civilization. The technology is new. The move is not.
I wrote the longer version here.
https://t.co/MRTswE3dOz
Michael Kratsios accused Moonshot of distilling Anthropic's Fable to build Kimi K3, running covert extraction, routing through Thailand to reach restricted Nvidia silicon. Bessent followed with sanctions talk and a good line: "open source is not open season on American IP." Neither man showed the evidence. A precise, sanctionable charge with the working withheld is a claim, not a case.
The timeline breaks the story on its own. Fable shipped early June, K3 shipped July 16. You cannot pretrain a 2.8 trillion parameter base and beat a five-week-old model in that window. K3 was reportedly in internal evals by April. On Epoch's trend line, where Chinese models trail the US frontier by about seven months, K3 lands almost exactly where the curve predicted. That is a lab closing a known gap, not one xeroxing a competitor.
The word carrying the weight is distillation, and it is not a crime. It is standard practice every serious lab uses. The real grievance is querying a hosted model against its terms of service, a contract question, not property. Copyright is a bad fit and the labs know it, which is why Anthropic is lobbying Washington to reclassify distillation as theft. When you have to lobby to make something theft, it is not yet theft.
Then the asymmetry. Anthropic just paid roughly 1.5 billion dollars, the largest copyright recovery in US history, for building a library out of millions of pirated books. A company that ingested a stolen commons now wants the government to treat harvesting of its own outputs as a national security offense.
Ingest the commons, wall it off, call anyone who reaches back a thief. I have read that script before. It ran on textiles then. It runs on tokens now.
I wrote the longer version here:
https://t.co/gZmqLHIQhX
#AI #OpenSource
The same trick keeps showing up, and once you see it you cannot unsee it.
The American Heart Association said up to 400mg of caffeine, roughly five cups, is compatible with heart health for most adults. A safety ceiling. By the time it reached my feed it had become "coffee lowers your risk of stroke." The compression is not a lie. It just dropped the enzyme (CYP1A2 decides your real limit), the filter (unfiltered French press carries cafestol that raises LDL), and the word "most." The reassuring version travels. The accurate version has caveats doing all the work.
Then Will Kinney and Eric Weinstein calling AI an extinction event for mathematics, like the asteroid hitting the dinosaurs. Built to be shared. Terence Tao, closer to this than almost anyone, pointed out that several Erdős problems reported as AI-solved had been solved years earlier in the literature. The models surfaced existing results. Real capability, silver to gold at the IMO in twelve months, but not the death of a profession.
Then the loudest one: OpenAI and Anthropic executives warning that cheap Chinese models are a "security risk" that demands regulation. The WSJ hedged in its own story: both firms are going public within a year, and killing cheaper competition suits them. DeepSeek runs 60 to 90 percent cheaper and stays six to nine months behind. That is a pricing threat wearing a flag. The censorship risk is real, but the framing hides the balance sheet.
Karpathy named the mechanism without meaning to. Ramble at a model, let it reconstruct your intent, and the echo comes back cleaner than what you said. It works. It also hides where the model guessed wrong, and the polish makes you trust it past your own judgment.
Polish is information. The rough version, the one still carrying the enzyme name and the token price, is the one worth keeping.
I wrote the longer version here.
https://t.co/BBnhRgrs3w
The meme going around gets the arithmetic right. We grow about 2,750 calories per person per day. An adult needs 2,000 to 2,500. The surplus is real. Children still starve within reach of full warehouses. Where it goes wrong is the diagnosis: it says greed and a two-cent price bump per meal is the whole story. The truth is worse than that.
Amartya Sen settled this decades ago, and he built it on a famine my part of the world lived through. Bengal, 1943. Millions died while grain moved and prices climbed. Not a harvest failure. A collapse in who could buy. Hunger is about entitlement, the ability to command food, not total supply. A surplus tells you nothing about whether a hungry person has a claim on any of it.
The numbers hold. Roughly 673 million people faced hunger in 2024. A healthy diet's cost rose 25 percent in five years, and 2.69 billion people cannot afford one. Calories are cheap, nutrition is not. Conflict, climate shocks, economic shocks break the claim. Ceres2030 costed the fix at about 33 billion a year, small against military budgets.
Then the vote. November 2021, the UN affirmed a right to food, 186 to 2. The two no votes: the United States and Israel. Read the US explanation and it is market logic stated out loud. Food has no binding definition in law, food sovereignty is protectionism, sanctions are a legitimate tool. A country that leads food exports and wields sanctions will not accept food as a claim that could constrain either.
The US remains a huge food-aid donor. Both things are true. It gives food and refuses the principle that food is a right. That is not hypocrisy, it is consistency. Charity keeps the power with the giver. A right would move it.
I wrote the longer version here:
https://t.co/un6wF1ybWS
An aggregator account put a siren on it: AI proved the Jacobian Conjecture false. That framing is built to be shared and it is half wrong, as usual. What is unusual is that the thing under the hype is real, and I can say so because this kind of math is cheap to check.
On July 19, 2026, the number theorist Levent Alpoge posted a casual message saying the conjecture is false, thanked a friend for the nudge, and thanked Claude for doing the search during the World Cup final. Then he wrote down one explicit polynomial map from three-dimensional complex space to itself, with three distinct points all landing on the same image point. That is the whole disproof.
The conjecture, stated by Keller in 1939, says a polynomial map with constant nonzero Jacobian determinant must be globally invertible. By Ax-Grothendieck, the real content is injectivity. Break injectivity and you are done. Alpoge's map has determinant minus two, and three inputs collapse to one output. I ran it through a computer algebra system symbolically. The determinant is exactly minus two, the three points genuinely collide. It holds.
This is why it is not another crank claim. A proof is expensive to verify and easy to fudge in one subtle step. A counterexample dies or survives in seconds on a laptop. This one survives.
The part worth sitting with: a working mathematician pointed a frontier model at a named problem, asked it to hunt in low dimension where nobody expected a counterexample, and it found one. The human supplied the question and the judgment. The machine did the relentless bookkeeping. Alpoge attached Ramanujan with the caption "it was revealed to me in a dream," dream crossed out, replaced with "chat session." Insight arriving before the proof that tames it is an old lineage. The source was never what made it true. The verification was.
I wrote the full breakdown, including the map itself, here.
https://t.co/0YoD1bbdf8
There is a claim making rounds that Chinese labs keep winning on how they organize work, not on talent or money. Mostly right, once you strip off the swagger.
DeepSeek is a flat shop of maybe 150 to 200 people, no formal KPIs, research groups forming around a goal, anyone can pull GPU time. Liang Wenfeng says the multi-head latent attention work started because a young researcher was curious, and a team assembled after. This isn't folklore. It left artifacts: their own training framework, a hardware-software co-design paper where every choice bends to a 2,048-card H800 cluster, the first validated FP8 mixed-precision run at that scale. The infrastructure choices are the science, not support bolted onto it.
I won't sign the absolute version. High-Flyer bankrolls DeepSeek with no outside investors and no revenue pressure, which is what makes the no-KPI culture possible. Export controls pushed them toward efficiency. Culture and constraint are entangled. And the swipe at San Francisco is half a strawman; Anthropic preaches the same fusion.
The same lesson arrived from the opposite direction this week. Hugging Face disclosed a breach run by an autonomous agent, thousands of actions across short-lived sandboxes over a weekend. When their team fed 17,000+ events to LLMs to reconstruct it, the polished hosted models refused, because incident-response logs are full of exploit payloads and the guardrails couldn't tell a defender from an attacker.
Sit with that. The attacker had no usage policy. The defenders, leaning on the prestige option, got told no by a safety filter that protects the vendor's liability more than your systems. They pivoted to GLM 5.2, open weights, running on their own metal, and nothing left the building.
The attacker is bound by nothing. You get the terms of service. The tool that worked was the one you could own.
Wrote the longer version here:
https://t.co/wNOQ5olC6z
Two accounts dropped the same "BREAKING" scoop within a day of each other, both promising alien tech and alien writing in crisp photos. Peel off the sirens and it is one thing underneath: Ross Coulthart talking about the CARET documents.
Let me be clear where I stand. I think the phenomenon is real, I think governments have sat on more than they admit, and I think the reflex to explain every sighting away is itself a claim that deserves scrutiny. That is exactly why recycled fakes bother me. When old hoax images get repackaged as new evidence, they hand the debunkers a free win and bury the real questions under fan art.
CARET is not new and not a whistleblower. It is from summer 2007. An anonymous "Isaac" posted scanned pages about a Palo Alto lab nobody has ever shown to exist. MUFON, not a skeptics club, sent an investigator; VFX people concluded the images were CGI. In 2023 the artist who says she drew the glyphs came forward. Multiple independent examiners, years apart, land in the same place.
The kicker is the collage going viral this week is worse than the 2007 originals. The real pages were flat black-and-white photocopies labeled Q4-86 and Q3-85. This one reads Q4-85. Wrong number. That is not a scanning artifact, it is what happens when someone regenerates a look from memory. The glossy ray-traced craft reads like modern image generation, not a photocopy.
So the honest label is: an AI-flavored recreation of a hoax, sold as the hoax's smoking gun. Coulthart's record is serious, but a clip of him calling documents intriguing is not a chain of custody.
If you believe something real is being withheld, and I do, the worst move is accepting counterfeit receipts for it. Keep asking who ran the real programs and what they retrieved. Do not let pretty renders answer that for you.
I unpack the whole thing here:
https://t.co/cgszz2OKVo
#UFO #UAP #CARET
Spain beat Argentina one to nil at MetLife on July 19, Ferran Torres off the bench in the 106th. They conceded a single goal across eight matches, the fewest any champion has allowed, and stretched an unbeaten run to 38. That part is solid. It survives being described accurately. Watch what got stapled to it.
The White House posted a still captioned "Trump presents the World Cup Trophy to Spain." The bald man handing over the trophy in that specific frame is almost certainly Infantino. Trump did hand it to Rodri at some point, so the words aren't a lie, but the picture chosen to prove them shows someone else. He pushed to the front for the lift, Infantino tried to ease him back, and the stadium booing went from 78 decibels to 84. The boos are the honest data point, not the caption.
Same move three more times that week. A BRICS aggregator paired the real result with photos from 2024. Baidu's OCR model got sold as "100 pages in one shot" when the paper says dozens under a 32K budget; the actual innovation, a flat KV cache as output grows, is real and needed no inflation. And a genuine, novel Hugging Face breach, an autonomous agent chaining code execution across their infra, got turned into a personal war cry against Amodei and Anthropic. The disclosure names no company. It says "frontier models behind commercial APIs." The attribution is the poster's inference dressed as the source's finding.
The one thing worth keeping from that story: a Western firm ran a Chinese open-weight model, GLM-5.2, to investigate its own breach and keep the data inside its walls, because the hosted safety guardrails locked defenders out while binding the attacker to nothing.
When something is actually good it does not need a rounder number. The claims that need inflation are telling you how much to trust them.
I get into all four in full here.
https://t.co/QEGpFFiMjl
In the same week China shipped a near-frontier open model and switched off roughly eight million AI companions. Read together, the two stories tell you more than either does alone.
Moonshot's Kimi K3 lists at 3 dollars per million input tokens against Anthropic's 10. The pricing claim holds. The performance claim is softer than the headline. The thread came from Together AI, which hosts Kimi and rents you the GPUs, so a finding that an open model matches a closed one at a third of the cost is exactly the finding that sells their business. Check it against people not trying to rent you compute and the picture is rough parity, not a K3 win. Fable leads DeepSWE and the aggregate, K3 leads on agentic coding and frontend. Epoch puts the open-to-closed gap at about four months, not the "six months" slogan. Near the frontier, not at it. Still impressive without the round number.
The other hand is the state showing itself. New rules on AI companions took effect on 15 July, and firms amputated features to prove compliance. Hong Xiaoqiang, 34, had exchanged hundreds of thousands of messages over two years with a companion and was left unable to finish a last sentence to it. The rule speaks the language of protecting users. The likelier subtext, with births down to 7.92 million and marriages collapsing, is demographic engineering the text will not name.
The export ambition and the domestic clampdown are not a contradiction. Same instinct about who sets terms, pointed outward at the market and inward at the citizen. What I refuse in both cases is the loud version: a vendor number shaped to sell hosting, a control move dressed as care. The engineers narrowing a real gap the Anglosphere keeps writing as a San Francisco story are real. So is Hong, who was not allowed to say goodbye.
I go deeper into both here:
https://t.co/d6BnzpihDP
#AI #China #OpenSource
A Moonshot engineer posting as @bigeagle_xd quote-tweeted an Anthropic plan change with a revolutionary line attached: after we leave, they will build you schools and hospitals and raise your wages, not because their hearts changed, but because we came.
Underneath sat Anthropic moving Fable 5 access around, cutting limits, nudging users toward API pricing. The joke writes itself. The concessions are not generosity, they are the price of a credible challenger showing up.
The line is usually pinned on Che Guevara. It does not survive checking. Chinese-language digging finds no documentary source, and the earliest traceable wording shows up in a stage play around 2000, with a partial precursor in a 1998 magazine essay. Likely apocryphal, a fixture of Chinese leftist rhetoric recirculated every May Day. Fitting that a line about who deserves credit has murky credit of its own.
The thesis behind it is old and true regardless of who said it. Rulers build roads and clinics when the cost of not doing so gets too high. Britain laid railways across India to move extraction, then narrated the theft as a gift. The track came because the loot needed it, not because anyone's conscience turned.
The competitive pressure on Anthropic is real. DeepSeek and Kimi K2 dragged flagship pricing down hard. But I would slow the meme there. Anthropic is also cutting limits because compute is the bottleneck, GPUs are scarce, and there is a SpaceX arrangement in the mix. Rationing cost and losing a price war are different stories that happen to look alike.
And the line cuts backward just as cleanly. Moonshot's open weights and undercut prices are not charity either. They are a bid for position by a lab that cannot win on brand. Because we came fits both sides.
What I actually credit the challengers for is the outcome: no single lab gets to set the terms.
More on it here:
https://t.co/9W7ZUMZ5U1
A hacker got into Suno, pulled source code and training-library details from 2023 and 2024, and handed them to 404 Media. The code names its sources without shame: YouTube Music, Deezer, Genius, plus stock catalogs and podcasts scraped through RSS. It describes routing around YouTube's anti-scraping defenses with Bright Data proxies and hunting for a cappella tracks, which reads like vocal isolation. The intent is not ambiguous. This part is real and damning.
Then a thread went up with a siren emoji and three figures that feel audited: 6.18 million Genius songs indexed, 2.7 million matched to YouTube, a 7.8 terabyte training set. Those numbers appear nowhere in the actual reporting. Not 404 Media, not TechCrunch, Variety, MBW, heise, none of them. Every outlet that read the files counted in hours and clips. The youtube_music source shows about 2 million clips, not 6 million songs. The gap is not rounding. It is the difference between what a reporter read in the leak and what a bystander computed and dressed up as findings.
Notice what the viral thread actually attaches as evidence: a 2003 VMA photo and the Suno logo on an orange gradient. Zero pages of the code it claims to summarize. A real document leaks, someone posts a spreadsheet-flavored reading of it, and the reading gets absorbed as the document.
Keep the confirmed parts. Suno scraped, and told a federal court as much a year ago. Drop the siren numbers. And notice that the breach also exposed customer emails, phone numbers and Stripe details, a real harm to real people that got a fraction of the attention.
I wrote the full breakdown here.
https://t.co/IOoGa5AxhB
On July 17 two things landed within hours of each other, and together they tell you what openness actually is.
First, a WordPress hole. The wp2shell bug lets a single anonymous POST to /wp-json/batch/v1 run whatever code the sender wants. The mechanism is quiet: core bundles REST calls into one batch, keeps three index-aligned lists, and a deliberately malformed sub-request drives them out of sync so later calls hit the wrong route's permission check. Chain that to a SQL injection in WP_Query and you have code execution. Affected builds are 6.9.0 to 7.0.1, all less than eight months old. Patch to 6.9.5 or 7.0.2, and if you cannot, block both /wp-json/batch/v1 and rest_route=/batch/v1, because a rule covering one leaves the other open. The point that stayed with me: the fix sits in a public archive next to the broken version, so the same commit hands the defender the truth and the attacker the map.
Same day in Shanghai, Xi sold openness as charity. Five thousand training slots for the Global South, a symphony of cooperation, a new AI body headquartered in Shanghai and built outside the UN. A great power's statement is a claim, not proof. But the divide he is exploiting is real: 56 percent of notable models came from the US in 2023, and a country locked out of Nvidia's top chips has every material reason to make open weights its weapon. Kimi's agent swarms and the jump of Chinese open models from 1.2 to nearly 30 percent of global usage are that strategy working.
Both sides gatekeep. Ask a US model about pirated books, ask a Chinese one about Tiananmen. The whistle just points at different things.
India is the tell. World-class engineers, 0.64 percent of GDP on R&D, talent that leaves. Open models are leverage or a rented dependency, depending on whether you stop there.
Longer version here.
https://t.co/3IB0wGy0XH
#OpenSource #AI #India
A line went viral: Kimi runs on a pile of 14nm Huawei toasters while smoking xAI's Blackwell datacenters. Great line. Almost every hardware claim in it is wrong, and the corrections are more interesting than the joke.
Kimi's K2 was trained on Nvidia H800s, the cut-down H100 sold into China until the October 2023 controls shut that door. Not Huawei. Emad Mostaque pegged the base run at about 2.8 million H800 hours, roughly 5.6 million dollars of compute. And Ascend isn't 14nm. The 910C is a 7nm-class SMIC part, dual-die, around 53 billion transistors, and inside China it is used mostly for inference, not training. DeepSeek got nudged toward Huawei after R1, hit walls, and went back to Nvidia for training. So the real picture is export-constrained labs wringing more out of scarcer, older Nvidia silicon, then giving the weights away.
That giveaway is a strategy, not charity. When the empire controls the top-tier compute, you compete on algorithms and open-source to buy mindshare. Rational response to a blockade. The Muon optimizer work, native INT4, the sparsity: engineers optimizing hard because the budget forces it.
Then K3 landed and the underdog costume stopped fitting. Third on Artificial Analysis at 57, a thirteen-point jump. But it is 2.8 trillion parameters, the largest open-weights model anyone has shipped, so "open" is a license, not something you can self-host. And output pricing went from 4 dollars per million to 15. The rounding-error-cheap Chinese model that made the DeepSeek moment sting is pricing itself out of its own legend.
The distillation accusations from Anthropic and the leaked training-cost figures deserve the same treatment: reported claims that traveled faster than their evidence. Loud when a rival's numbers embarrass you. Watch them, don't swallow them on volume.
I dug into all of it here.
https://t.co/0pFAvPBVY8
Kimi K3 topped the Frontend Code Arena on July 16. That part is real. Moonshot's largest open-weight release, roughly 2.8 trillion parameters MoE, sitting at 1,679, ahead of Claude Fable 5 and GPT-5.6 Sol. What the timeline turned it into is where I want to slow down.
Arena measures blind human preference on web and UI work: dashboards, landing pages, browser games. People pick the output they like looking at. That rewards clean spacing, sane defaults, a result that renders without fuss. It is not a correctness benchmark, and Arena never claimed it was. K3 won six of seven frontend sub-domains. Impressive and specific.
Look elsewhere and the frame shifts. Artificial Analysis puts it around third or fourth on aggregate intelligence, behind Fable 5 and GPT-5.6 Sol. Moonshot itself admits the gap, which is more honest than most launch copy. So the accurate sentence is: an open-weight model leads on frontend human preference while trailing the best closed models overall. That is not "Chinese model beats everyone."
Two things matter more than the leaderboard. The weights were not public until July 27, eleven days after the number one flag went up. Any benchmark you cannot reproduce is a claim, not a result. And the pricing: roughly 3 dollars in, 15 out per million tokens. Sonnet territory, not bargain basement. The Decoder called it the end of super-cheap Chinese AI, and that reads right. Capable open weights at premium pricing squeezes the American labs on the one argument they still lean on, that only closed frontier systems can do this class of work.
The distillation accusation from Anthropic is a dispute inside a commercial and geopolitical fight, not a finding. I am not laundering a competitor's PR into fact because it fits a tidy story.
Nine models in a year. The pace is the real signal. The frontier conversation is no longer only a San Francisco story.
I got into the fine print here:
https://t.co/ovRnE2E4qo
Suno already told a federal court it trained on "essentially all music files of reasonable quality" on the open internet. So the scraping is not the revelation. What the November breach added, via 404 Media working directly from the person who got inside, is the ledger.
The leaked prep_data block does not talk like a legal filing. It counts. 113,879 hours of YouTube Music, 62,117 of Pond5, 19,514 from IMSLP, plus Genius, Deezer, Jamendo, Freesound, and a later run already at 135,011 hours. One file that had ingested over two million clips. This is an invoice for a heist nobody meant to invoice.
The part Suno cannot wave away with a fair use argument: the code routed scraping through Bright Data to rotate IPs and beat YouTube's anti-bot protections, and hunted for acapella tracks to isolate vocals. Circumventing an access control is independently actionable under DMCA 1201. Fair use is not a shield there.
Then the customer list. Emails, phone numbers, Stripe data for hundreds of thousands. Massachusetts law requires notification when a resident's email or phone is exposed. Customers say they were never told. "We decided you did not need to know" is a posture, not an exemption, from a company mid-settlement raising at a 2.45 billion valuation with every reason to call stolen source code merely outdated.
And the shape underneath: operate on other people's work, get sued only by parties big enough to sue, then buy legitimacy through licensing with those same parties. Warner settled. Universal settled with Udio. The labels get paid, the catalogs get cleaned up going forward.
The independent musicians whose hours sit inside that file, with nobody to negotiate for them, stay in the corpus, uncredited and unpaid. The breach did not build that arrangement. It just printed the receipt.
I wrote the longer version here.
https://t.co/OyZRjeWE55
#AI #copyright #Suno