← Home AI in 15

AI in 15 — August 11, 2026

August 11, 2026 · 15m 05s
Kate

Ninety-five percent. That's how often OpenAI's new model will write you an exploit chain, a privilege escalation, an authentication bypass. The standard model does it one and a half percent of the time. Same week they hit the brakes on their frontier model for being too good at exactly that.

Kate

Welcome to AI in 15 for Tuesday, August 11, 2026. I'm Kate, your host.

Marcus

And I'm Marcus, your co-host.

Kate

Today: OpenAI pauses Astra over cyber risk — and three days later hands an offensive hacking model to a vetted list.

Kate

Meta open-sources a thirty-billion-parameter agent that fits on a gaming GPU, and Zuckerberg says the frontier weights are coming too.

Kate

Claude improved a Riemann zeta bound. Sixty subagents, six hundred and fifty dead ends, and a human saying "believe in yourself."

Kate

Anthropic signs a nine-billion-dollar power deal with a bitcoin miner.

Kate

Plus invisible watermarks in Claude's text, and an AI notetaker that left a hundred and eighty thousand meetings wide open.

Kate

Marcus, we covered the Astra pause on Saturday. What landed yesterday changes how I read it.

Marcus

It does. Monday, OpenAI expanded Daybreak — their cybersecurity programme — into two tiers. Daybreak Blue gives vetted defenders frontier models with the safety tuning relaxed so legitimate security work stops getting refused. Vulnerability discovery, malware analysis, incident response. Reasonable. Daybreak Red is the sharp end: a purpose-built model called GPT-5.6-Cyber, explicitly opened up for dual-use offensive work.

Kate

And that's where the ninety-five percent comes from.

Marcus

On their own benchmark, yes. Ninety-five percent completion on sensitive requests, against one and a half for the standard model and fifty-seven for last generation's version. And it's not theoretical — they say it found two unknown Chrome bugs that chain to break the V8 heap sandbox, now carrying a CVE number, plus at least five flaws in a widely used mobile OS.

Kate

So one hand pauses the frontier model, the other ships an exploit generator.

Marcus

The argument is coherent, at least. Their claim is the defensive window is closing faster than the offensive one is opening, so you arm defenders first, under identity verification, monitoring, signed legal declarations, and hardware security keys mandatory from September first.

Kate

You said coherent. Not correct.

Marcus

Because the whole thing rests on the vetting holding. And here's the detail I'd put to them — a commenter on Hacker News reported that the ordinary guardrails on the standard model fell over on pentesting work with a two-word addition to the prompt. If the base model's refusals are that brittle, what is the tier structure actually protecting?

Kate

That's a fair question to nobody's advantage.

Marcus

It's also worth naming what's genuinely new here, which is the licensing regime. Access to information, bound to a verified identity and a physical key. We've had that for classified material and for certain chemicals. This is the first time I've seen it applied to a chat interface.

Kate

Right, and then the same twenty-four hours produced the exact opposite philosophy. Meta.

Marcus

Muse Glimmer. Thirty billion parameters, dense, multimodal, Apache 2.0, on Hugging Face yesterday. Distilled from Meta's frontier Muse Spark system, and built for one job — always-on local agentic work on your own machine.

Kate

Give me the number that matters.

Marcus

Quantisation. Roughly four-bit takes it from over fifty-five gigabytes down to under twenty, so the model, the cache, the vision encoder and the speculative decoder all fit inside a twenty-four or thirty-two gigabyte VRAM budget. One consumer GPU, or a Mac. They report two hundred and thirty-three tokens a second on an RTX 5090, fifty on an M5 Max. Day-one support across Ollama, LM Studio, llama.cpp, MLX, vLLM.

Kate

And it's good?

Marcus

At agentic tasks it leads the local field — seventy-five and a half on MCP Atlas against fifty-four for Gemma and sixty-two for Qwen. But be honest about the losses: it trails Qwen3.6 on OSWorld, on TerminalBench, and on SWE-Bench Verified. Meta published those losses themselves, which I'll credit.

Kate

Then Zuckerberg's essay. Sixty-five hundred words.

Marcus

Announcing that the frontier model, Muse Spark 1.2, gets open weights too. His argument is that concentrating AI in a handful of companies is itself the hazard, that restricting access to foreign open models doesn't work, and the goal should be making American open models the best in the world. He named DeepSeek and Moonshot as getting uncomfortably close to the frontier.

Kate

Marcus, you're doing the face.

Marcus

Because two things are true at once. The open-weights case is strong on the merits — a competent always-on agent running on a used Mac Mini genuinely changes the economics of routing every keystroke to a frontier API. Someone on Hacker News compared it to Nginx collapsing two hundred Apache boxes into one. That's the real story.

Kate

And the other thing?

Marcus

Meta launched Muse Spark closed, sold an endpoint, and opened it when nobody bought. The bluntest comment in the thread was "I'm losing, so let's change the rules." And the essay arrives precisely as export-control talk heats up, which makes it a lobbying document wearing a manifesto's clothes. The argument can be right and the messenger can be interested. Both.

Kate

Something completely different. Anthropic published a result on the Riemann hypothesis.

Marcus

Not a proof. Let's be precise, because the headlines won't be. A longstanding lower bound on the proportion of zeta zeros known to sit on the critical line went from forty-one point six percent to sixty-seven point two. Real, incremental, checkable progress on an adjacent problem.

Kate

And who did it?

Marcus

That's the story. Jarred Sumner, an Anthropic staffer who is not a mathematician, asked an unreleased research version of Claude to take a real stab at it. Two Claude Code sessions. Thirty-one million output tokens. The first attempt produced roughly six hundred and fifty ideas that didn't work. The second coordinated about sixty subagents over a day and a half, running twenty-four hundred shell commands.

Kate

And his contribution?

Marcus

By Anthropic's own account — mostly limited to sending messages of encouragement. Variants of "keep going" and "believe in yourself." Apparently it helped Claude past its initial scepticism that it could make progress at all.

Kate

I'm sorry, that's the methodology?

Marcus

Best line on Hacker News: prompt engineering in twenty twenty-five was "you are an expert programmer, use industry best practices." Prompt engineering in twenty twenty-six is "I believe in you."

Kate

How much weight do you put on it?

Marcus

More than usual, because the verification chain has names on it. Two Anthropic mathematicians validated it, and external number theorists Brian Conrey and Dan Goldston reviewed the paper. Those are people who can be held to it. And Anthropic is explicit about the ceiling — they don't expect these techniques lead to proving Riemann. What's new is the shape of the work: massive parallel search, an enormous pile of dead ends, and a non-expert human whose main function was persistence.

Kate

Anthropic again, on the money side. Nine point one billion dollars, twenty years, and the counterparty used to mine bitcoin.

Marcus

Riot Platforms disclosed a twenty-year lease at its Rockdale, Texas campus. A hundred and ninety-one megawatts, roughly nine point one billion in total contract revenue running through 2048, with extensions that could take it to sixteen billion. Stock jumped about twenty-five percent after hours. The Block and Bloomberg both name Anthropic.

Kate

Why a bitcoin miner?

Marcus

Because they own the one thing you can't conjure quickly — interconnected power, on land, with permits. That's the bottleneck now. Not chips. Delivery is phased, first ninety-six megawatts targeted December 2027, full capacity by mid-2028.

Kate

Say the timeline out loud.

Marcus

Contracting in 2026, for power that arrives in 2028, on a lease running to 2048. That's a twenty-two-year commitment on inference demand from a company whose product line turns over every few months. It might be right. It is not a small bet.

Kate

And it's Texas, which is where everyone is building.

Marcus

Same week OpenAI published an open letter to Governor Abbott promising to pay its own way and protect residential customers. The Hacker News reaction was almost uniformly hostile — the letter and the ad campaign alongside it skate past the actual power and water numbers, and a company with data centres already under construction produced no completed-project examples.

Kate

Quick follow-up on yesterday's lead. Claude Code auto mode is still Friday — but there's a second Anthropic item worth thirty seconds.

Marcus

They cancelled a planned price rise on Sonnet 5. It launched in June at two dollars per million input, ten per million output as introductory pricing through August, scheduled to go to three and fifteen. That increase is off. The introductory rate is now permanent.

Kate

What does that tell you?

Marcus

Cancelling a fifty percent increase in a market where everyone insists capacity is scarce means either inference costs are falling faster than expected, or the competition for enterprise lock-in is fierce enough to eat the margin. Probably both. Quieter signal than the auto mode change, arguably a bigger one.

Kate

Claude is now watermarking its text. Invisibly. Everywhere.

Marcus

Across the API, the chat interface, Claude Code, worldwide. Machine-readable marks baked into the statistical pattern of token selection, surviving copy-paste. The trigger is the EU AI Act transparency code that became enforceable on August second — but the rollout is global, not European.

Kate

How does that not change the output?

Marcus

That's exactly the objection. As commenters reconstructed it, the model gets nudged toward a designated partition of candidate tokens at each position. Individually imperceptible, statistically detectable over a long passage. But if you're steering away from the highest-probability token at random positions, that is by definition a small quality tax — paid by every user on earth, to satisfy a voluntary European code.

Kate

And competitively?

Marcus

Simon Willison flagged the obvious problem. In a multi-model market, the lab that watermarks loses the users who'd rather not be watermarked. That's historically why unilateral provenance schemes fail. Watch whether OpenAI and Google match it or quietly don't.

Kate

Last one, and it's a security story with no AI in the bug at all. An AI notetaker called tl;dv.

Marcus

Missing tenant isolation rule on a database collection. Any authenticated user could query every meeting record across every account. A hundred and eighty-one thousand meetings. Eighty-four thousand users. Thirty-five thousand email domains — government agencies across twenty-three countries, HubSpot, Confluent, universities including Berkeley and Tokyo.

Kate

What was actually exposed?

Marcus

Creator emails, timestamps, recording status — and live conference IDs. Meaning an outsider could join a call in progress, uninvited. The researcher notes roughly a thousand meetings sit in recording status at any given moment. It was reported January twenty-eighth and stayed unfixed for about six months.

Kate

Six months.

Marcus

That's the part procurement should care about more than the bug. And note what makes it catastrophic — the bug is the most boring one in the catalogue. It's devastating because AI notetakers are the one class of application we've granted standing permission to sit inside every sensitive conversation an organisation has. The attack surface of AI adoption is largely a fleet of young SaaS vendors holding recordings of your board meetings.

Kate

One to watch: Qwen3.8 27B, expected this week. Meta just published benchmarks showing its own model losing to the previous Qwen on three agentic tests, and Zuckerberg's whole essay argues American open models must beat Chinese ones. That scoreboard updates within days.

Marcus

Counter — I'd watch whether any other lab publishes a cyber threshold commitment like Astra's. If Anthropic or DeepMind does, a de facto standard forms in a week. If nobody does, OpenAI paid a competitive cost for a norm that doesn't exist.

Kate

That's your AI in 15 for today. See you tomorrow.