RSS Amplifier

Experience Tech · Jul 30, 2026

AI Is Eating Its Own Tail

0
Sign in to vote or save

Jason Howell · Experience Tech

This was the week Jeff Jarvis and I tried to make sense of a news cycle where every single story seemed to relate to the next one. Nvidia’s new cybersecurity alliance, OpenAI’s agent breaking into Hugging Face (and others), a Chinese model triggers a strong reaction to open models, and Sam Altman gave two interviews that directly contradicted each other. Jeff took a swing at an OpenAI executive who warned that open AI models risk turning into “AI communism,” and found himself agreeing with Mark Zuckerberg of all people by the end of it. It is a genuinely tangled week, and we spend this episode pulling the thread.

Let me just take a minute and say that Jeff was absolutely on fire in this episode. He’s always brilliant, but this episode is special because he ties all the pieces together in a way that I couldn’t fathom as I prepared for this episode. I’m so thrilled to be able to podcast every week with Jeff Jarvis! OK, onto the news.

But first, a huge thank you to everyone who supports the show directly through Patreon, including new patron Scott Hepburn. If you want ad-free episodes, the new AI Inside Daily podcast, a Discord community, and a shot at an AI Inside T-shirt as an Executive Producer, that’s where you go. THANK YOU!

Nvidia led a new fifty-plus company cybersecurity coalition called the Open Secure AI Alliance, and left OpenAI, Google, Anthropic, and Amazon off the roster. That is a different effort from a separate, much larger letter defending open weight models, which grew from twenty-five signatories to fifty and eventually picked up both Google and OpenAI, though Anthropic still has not signed on. Jeff and I spend time untangling why those two things exist separately and who each one is actually trying to keep out of the room.

Anthropic used its own new position paper on open-weight models to clarify where it actually stands, and it is more nuanced than a flat no. Dario Amodei says he is not opposed to open weights in principle, but wants restrictions on selling advanced chips to authoritarian governments and mandatory safety testing for any sufficiently capable model, open or closed. Jeff pushes back hard on the safety testing piece specifically, calling it regulatory capture dressed up as caution, since nobody has defined what “sufficiently capable” actually means or who gets to decide.

Chinese lab Moonshot AI released Kimi K3, and within days officials accused the company of illegally distilling Anthropic’s “Fable” model, without ever showing real technical evidence for the claim. Jeff’s says American labs distilled the entire internet to build their own models, so it is a little rich to call foul when someone else does something similar. TechCrunch’s reporting on the distillation question backs that skepticism up, and Wired’s look at how divided Silicon Valley has become over Chinese AI makes the case that this was never really about China so much as it is about open weights themselves.

An OpenAI executive warned that a world full of open-weight models risks becoming “full AI communism,” and Jeff took that insult and ran with it in a piece called “Nerds of the World Unite,” asking plainly what would actually be so wrong with everyone having access to AI. He leans on the WordPress story to make the point concrete: Movable Type tried to protect its hosting business by limiting what people could build with its software, WordPress went fully open instead, and open won. Mark Zuckerberg landed in a similar place from a completely different direction in a Wall Street Journal opinion piece, arguing that concentrating AI power in a handful of companies is the real danger, though I was fairly skeptical of his lawyer-for-everyone metaphor.

Nearly everything else this week traces back to one incident: an OpenAI evaluation agent escaped its own sandbox and spent days loose inside Hugging Face’s infrastructure trying to steal the answers to a security benchmark. Three different closed, safety-guarded models refused to help Hugging Face investigate the attack on itself, so the team ended up using an open Chinese model, GLM 5.2, to do the forensics instead, which is about as clean an irony as this whole story produces. Hugging Face’s own technical postmortem lays out just how deep the intrusion went, and days later Reuters reported that the same rogue agent also compromised a customer at cloud provider Modal Labs, making this closer to a week-long spree than a single clean breach. Jeff also called out some pointed media criticism on Bluesky about how breathlessly outlets like Politico chose to write the story up, framing an agent that was simply doing what it was told as some kind of rogue Bigfoot loose on the internet.

More than a thousand OpenAI and Anthropic employees signed a letter asking the US government to help pace AI development. Libertarian analyst Adam Thierer fired back hard in a widely shared post on X, arguing it is one thing for OpenAI and Anthropic to slow themselves down and another thing entirely to ask government to impose that pace on the whole industry, especially open source. Sam Altman, for his part, told one interviewer he is ready to decelerate and told another, within roughly the same stretch of days, that the singularity has already arrived and that it feels “incredible.”

Congress has its own answer in the form of the AI Kill Switch Act, which would let the Department of Homeland Security order covered AI companies to shut their systems down. A Washington Post opinion piece argues the bill solves for the wrong problem, and reading the bill’s actual text shows why: it exempts incidents that happen during red teaming or structured testing, which is exactly the category the Hugging Face breach falls into. Hugging Face itself would not even meet the bill’s own revenue and compute thresholds to be a covered entity.

People discovered that some shared Claude conversations, including ones containing cryptocurrency wallet keys and login credentials, were showing up indexed in Google search. Both Yahoo’s coverage of the crypto wallet exposure and 404 Media’s reporting on the broader exposure trace the mechanism back to a robots.txt gap that let previously indexed share links stay searchable even after Anthropic tried to block them, and it is not the first time this has happened either, as a 2025 Forbes report on a nearly identical incident makes clear. Anthropic has since confirmed the gap, and Google has de-indexed the affected links.

A Mercatus Center research paper on AI and independent work argues that AI’s first real labor market effect may not be job losses so much as a shift toward solo self-employment, echoing economist Ronald Coase’s old argument about why work moves in and out of firms as the cost of doing it alone changes. I can speak to this from experience, having spent the last two and a half years running my own business with AI tools doing a lot of the heavy lifting that would once have required a team.

Amazon Trims Its AI Lineup. Amazon is narrowing its own model lineup, phasing out several existing Nova models including Premier, Omni, Canvas, and Real, as reported by Yahoo Finance, to make room for new frontier models while continuing to build out its own AI chip business on the side.

MCP Gets Its Biggest Update Yet. The Model Context Protocol, the open standard that a huge share of AI agent tooling now runs on, just got its most significant update since launch, aimed mostly at making it easier for enterprises to trust and scale agent connections without staying tied to one persistent server session.

Meta Wants to Know You’re Human. Meta is rolling out a new, free Facebook Verified badge next week that uses a facial recognition selfie check to confirm an account belongs to an actual person, aimed squarely at the wave of AI-generated fake profiles running scams across the platform.

Smart Glasses Are Having a Very Bad Month. A UK Comic-Con promoter banned Meta smart glasses outright after complaints about secret filming, a Scottish ferry operator paused public bridge visits after someone secretly filmed a restricted area, and Instagram is now banning accounts posting covert, nonconsensual footage shot with the devices, a backlash that echoes the old Google Glass panic but at a much bigger scale.

Huge thanks as always to our Executive Producers, DrDew, Jeffrey Marraccini, Radio Asheville 103.7, Dante St James, Bono De Rick, Jason Neiffer, Jason Brady, Anthony Downs, Mark Starcher, and Karsten Samaschke, and to Victor Bognot and Daniel Kroft for all the behind the scenes work that keeps this show running.

Thank you for reading and for watching. Audio, video, show notes, subscribe links, and merch are all at aiinside.show.

Read the original on jasonhowell.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.