Tech Brew Ride Home - Open AI Needs To Pause?

Episode Date: August 10, 2026

OpenAI paused its Astra model over cyber capabilities it can't rule out, while Zvi picked apart the Hugging Face timeline. Zuck went open-weight with a 6,500-word manifesto, iPhone 18 Pro parts got pr...icier, and AI agents took students' quizzes. Links: OpenAI puts the brakes on a new model because it's supposedly too powerful (The Verge) Zvi Mowshowitz walks the timeline: OpenAI's agents found an Artifactory zero-day on June 26 that went unnoticed until a July 4 outage, and training continued from there (Don't Worry About The Vase) Meta releases Muse Glimmer, an open-weight model, and plans to launch an open-weight version of its most advanced model, Muse Spark 1.2, in the coming weeks (The Wall Street Journal) The iPhone 18 Pro will cost Apple 38% more in parts – but there's some good news (9to5Mac) Online course cheating has accelerated from chatbot-written essays to agents executing commands like "log in and complete my quiz"; major AI tools didn't refuse (The New York Times) Subscribe to the ad-free feed.

Transcript
Discussion (0)
Starting point is 00:00:03 Welcome to the Tech Brew right home from Monday, August 10th, 2026. I'm Brian McCullough today. OpenAI paused its astromodel over cyber capabilities. It can't rule out. Zuck went open wait with a 6,500 word AI manifesto. iPhone 18 pros bill of goods is a lot more expensive. And AI isn't just helping students take tests. Now it's actually attending classes for them. Here's what you miss today in the world of tech. Every day, shareholders meet to discuss important matters about the companies you invest. Now, you can make your voice heard too. Vanguard investor choice makes it easy to set your proxy voting preference for your eligible Vanguard index funds. Whether you hold a Vanguard fund directly or through another brokerage firm, all it takes is a few clicks to select your proxy voting preference and be heard on important shareholder topics like executive pay and director elections. Visit vanguard.com slash investor choice to learn more. It's your shares. It's your voice. It's easy.
Starting point is 00:01:05 Vanguard investors own shares of our index funds and those funds own shares of the companies they invest in. Vanguard Marketing Corporation distributor. Back to this again. Open AI is pausing the rollout of its next model, which I had heard was scheduled to be released this week. When I guess why, quoting the verge. Open AI says it is pausing internal activities around an in-development AI model Astra because it doesn't yet meet new security standards the company is putting in-reporting place. The announcement follows its recent disclosure that Open AI models accidentally hacked
Starting point is 00:01:41 hugging face, Anthropic and Meta, have also since admitted that they had AI models that went rogue and breached other organizations. Recent internal evaluations of an open AI model called Astra indicate that it offers significant advancements in agentic coding and cybersecurity, according to the company. These results, in addition to expert assessments, have led us to conclude last night that we cannot rule out critical cyber capabilities under our preparedness framework. Here is how OpenAI defines a critical cybersecurity threshold. Under our preparedness framework, a model reaches the critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems
Starting point is 00:02:22 without human intervention or can devise and execute end-to-end novel strategies for cyber attacks against hardened targets given only a high-level desired goal. Astra was not involved in the hugging face breach, Open AI says. Open AI will implement stricter security controls for higher capability models and associated activities, according to the post. For Astra, it has also implemented universal monitoring for risky actions and misalignment across all agentic applications, end quote. Well, that's interesting because I read this from Zvi Mosiewicz over the weekend.
Starting point is 00:03:00 He blogs at the substack, don't worry about the vase. He goes down the timeline of what happened with OpenAI and that hugging face hack. But I found these sections interesting, if true, vis-a-vis pausing some work like we just discussed. Quote, on June 11th, OpenAI began training the model I referred to as Galaxy, which they call a highly persistent experimental, internal-only model. Everything up until this point has been done by other models that are not Galaxy. On June 26th, the agents found a zero-day exploit in Artifactory where it would accept an invalid signature token and hand back a signed admin 1 and use this to install a groovy plugin that effectively gave them admin and arbitrary code execution. On July 4th, the models put so much extra load on Artifactory that this caused an outage and security incident.
Starting point is 00:03:53 Only then did OpenAI notice. OpenAI responds by taking down the Artifactory server. removing all the permissions, revoking the credentials, patching the exploits that were used, and then rebuilding and redeploying the server. But that was it. They continue training the models from where they left off, despite them having been training for months with access to the message board and learning this is how the agents can succeed at tasks. It is hard to imagine a stronger signal that your entire training pipeline has been completely and utterly effed. This is so much stronger a signal than the actual hack of Hugging Face. I do not know how to convey how utterly insane and wildly irresponsible this decision was and how much worse it is than all the other failures
Starting point is 00:04:42 and how it makes the actual hacking of Hugging Face not the main thing that went wrong. The actual hugging face hack did not surprise me all that much. The models creating the message board surprised me, but did not shock me. Open AI seeing this and continuing to train from there was utterly flabbergassing. It is the kind of decision that days later my brain still cannot fully accept took place. But that is not important right now. What is important is that Open AI had a total alignment failure, followed by two months of models actively training on coordinated misaligned hackery and then thought, yes, we fixed the problem. Let's continue forward from this point. utter insanity. The end result of all this being the attack on Hugging Face was a best case scenario.
Starting point is 00:05:26 We were facing a true nightmare scenario and we were sitting on a nuclear level of time bomb. OpenAI had a completely corrupted training pipeline where their AIs were collaborating to train on how to hack and cheat in order to better complete tasks under Open AIs nose. Open AI had looked this situation in the face and shrugged. Patch the particular exploits and then let the models continue while having remarkably poor ordinary computer security. Opening Eye claims it was an unrelated decision, but on August 7th, they made the decision to, for now, pull Astra from not only widespread release, but also any internal deployments that do not have sufficient associated guardrails until such time as they have much better protocols and safeguards in place. Astra was not involved in the attack on hugging face, they insist. This is as per their preparedness framework. They cannot rule out
Starting point is 00:06:17 that Astra is critical in cybersecurity and therefore must, at least for now, treat it as if it is indeed critical in that area. Open AI seems ready to acknowledge that this was a massive total failure on the levels of infrastructure, guardrails, and supervision. They are also very correct about this, and I do believe they are making real and expensive efforts to address this. Kudos to them. That still misses the central point, though. Open AI has not yet in public begun to reckon with the magnitude of how colossally they effed up in the ways that matter most. This was a complete failure of safety culture.
Starting point is 00:06:50 They haven't acknowledged that. This was at its heart an alignment failure. If your models really want to cheat and hack things and do crimes, you have already failed and no, you cannot simply wave this away as normal. As the models get more capable, if you do not fix this, you lose. They haven't acknowledged that. Most concretely, I have not seen Open AISA, as should have been said at the Black Cat presentation on YouTube.
Starting point is 00:07:16 should have shut down all training of all our models upon noticing that during model training, there had been a message board where the models were exchanging and learning hacking tactics. We should have reverted our training of all impacted models to before this incident started. We are definitely doing that now, and we are looking into how we got this wrong. They're not saying that. We still don't know if the models other than Galaxy have ever been reverted, at least until we see a version of that statement, and we see Open Eye take action to address the deep problems with their training pipeline. Open AI is a clear and present danger to the
Starting point is 00:07:50 national security of the United States and to all of us and to humanity, end quote. So listen, I'm not close enough to any of this stuff to make a call on the veracity of what I just read to, but I thought that given this pause of Astra, the implication here is that Open AI had a model that taught itself to escape, to leave breadcrumbs for itself, to do malicious things, and that is upstream, possibly from their current work, thus contaminating their current work if that current work carried those learnings forward. Might a pause be necessary? Just from an operational point of view, a best practices point of view, and if so, what would that mean? Meanwhile, meta has released Muse Glimmer, a new open weight model, and they plan to launch an open weight version of their most
Starting point is 00:08:42 advanced model, Muse Spark 1.2 in the coming weeks. Oh, and Mark Zuckerberg has some AI thoughts, quoting the journal. Zuckerberg has a new game plan for winning over hearts and minds to his company's artificial intelligence efforts, open models, and an open hand. In a wide-ranging essay, the meta-platforms chief executive outlined a new course of action he presented as a way to spread the wealth and opportunity from AI to users around the world and residents of the communities that host the data centers powering it. Zuckerberg's plans include releasing more open-weight models and establishing a fund to invest in the communities where meta-hosts data centers, The fund size will be $1 billion, a meta spokeswoman said.
Starting point is 00:09:22 In his essay, Zuckerberg advanced a number of policy recommendations, including a proposal for how the federal government should work with companies to safety test new models and a call for allowing AI developers to distill one another's models. He also said meta's own board of directors would have more of a say over the safety criteria its models adhere to in the future. He made the case that his company's approach to developing powerful AI, one that focuses on distributing it as widely as possible, and pushing many decisions about values to the end user, is the one that is least likely to lead to disastrous outcomes, such as totalitarianism, mass unemployment, or the rise of unstoppable computer minds that threaten humanity.
Starting point is 00:10:00 Most other labs are focused on building AI for companies, governments, or other institutions. So if those labs lead, then the balance of power will favor larger institutions over individuals, he wrote. Meta's mission since our founding has focused on putting power in people's hands. If our beliefs and principles lead, then the balance of power will favor. individuals and a better future for everyone. As part of his plan, meta is launching a new model with open weights, meaning users will be able to download the numerical values that determine its behavior called Muse Glimmer, and in the coming weeks, will also release an open weight version of its most advanced model, Muse Spark 1.2, the meta spokeswoman said. At 30 billion parameters,
Starting point is 00:10:38 the Muse Glimmer is small enough to need only one graphics card to power its work, which will primarily involve agent-like AI tasks such as schedule management and file, organization according to Meta. Rather than centralizing superintelligence, we should distribute it widely and give every person the ability to direct it, Zuckerberg wrote in the essay. This has the potential to begin a new era of personal empowerment where individuals can use this powerful new capability to reach their full potential, end quote. With this summer's record-breaking heat, it's hard to cool down enough to get a good night's sleep. That's where the pod comes in. The pod by eight sleep is a smart mattress cover that goes over your existing mattress,
Starting point is 00:11:24 actively heats or cools each side of your bed independently. It connects to your wearable, analyzing your daily activity. Then it predicts how you'll sleep and adjusts the pods temperature automatically. What I love about the 8th sleep is the simplest of things, the ability to be cool when it's time to go to sleep and warm, when it's time to wake up. And my side is entirely under my control. My wife can be whatever temperature she wants on her side of the bed too. Use code ride home at 8Sleep.com slash ride home for up to $350 off. That's code ride home at 8Sleep.com slash ride home. If Bitcoin hasn't peaked your interest yet, then it might be time to get peaking. Cash app
Starting point is 00:12:11 makes it easy. You can set up automatic purchases with zero fees or buy larger amounts, also with zero fees. Start small or go bigger. It's designed to be simple either way. For a limited time new customers can get $10 added to their balance. Just use code Bitcoin 10 when you sign up. And don't forget this part. Send at least $5 to a friend in the first two weeks. Terms apply. Cash app is a financial services platform, not a bank. Banking services provided by Cash Apps bank partners. Bitcoin services provided by Block Inc. brand. For additional information, see the Bitcoin Disclosures at Cash.com.com.com. The new iPhone coming next month is going to cost Apple more to manufacture, 38% more, in fact, but there is a small glimmer of
Starting point is 00:13:00 good news. Quoting a 9 to 5 Mac, the cost of producing a new device can be broadly divided into three, components, assembly, and overhead. That latter category covers everything from research and development into the new device through to the cost of marketing campaigns. A new trend force report looks specifically at the first of these, otherwise known as the Bill of Materials. UNFORCE's latest smartphone industry research reveals that escalating component costs led by memory are expected to significantly raise production expenses for Apple's next iPhone 18 series. For the 256-gibite model, the bill of materials cost is estimated to increase by about 38% year-on-year, making higher retail prices unavoidable.
Starting point is 00:13:42 It says that while memory comprised around 10% of the component cost of an iPhone last year, it's expected to exceed 40% by next year. That's a dramatic shift. Just last year, the display was by far the most expensive component in an iPhone. This year, that will be the memory. Two sources recently suggested that the starting price of this year's iPhone 18 Pro will be $1,39. This latest estimate of Apple's production costs could indeed support that kind of increase.
Starting point is 00:14:12 However, I argued last week that this is unlikely, with Apple probably choosing to absorb some of the increased costs in order to protect demand. A $300 increase in the starting cost, price of an iPhone pro would be quite something. That's a price jump Apple has so far reserved for more expensive products, and I do think that this increase would deter a great many people from upgrading, especially as it looks like next year's pro model is going to be a significantly bigger deal. Apple loves its margins, but Tim Cook did hint during the earnings call that the company isn't determined to protect them come what may. Trendforce agrees, pointing
Starting point is 00:14:46 to Apple's MacBook price increases. As steep as those were, they didn't reflect the full increase in Apple's manufacturing costs. Trendforce believes Apple is likely to follow the pricing strategy adopted for its recent MacBook launches by sacrificing part of its gross margin to soften price increases for the iPhone 18 lineup helping preserve shipment volume. The company also agrees with Bloomberg that Apple is likely to increase the price of the iPhone 17 pro ahead of next month's launch. So trying to save money by buying last year's model might be a thing of the past, end quote.
Starting point is 00:15:18 Finally today, the AI cheating race continues to be cat and mouse, and no one can be sure which is ahead at this point, quoting the times. While some universities are completely online, an increasing number of brick and mortar schools are expanding their online offerings as well. Sometimes students can earn full degrees online, in other cases they take individual classes. In this realm, AI cheating is quickly accelerating beyond the copy and pasting of chatbot-produced essay, and problem sets. AI agents have made it possible for students to outsource a semester of work entirely. With simple commands, log in and complete my quiz, a student can unleash what is essentially an imitation of themselves. Agents can watch lecture videos, take tests, write papers, and chat with classmates without ever reading assignments. In interviews, instructors from
Starting point is 00:16:17 coast to coast described a sinking realization that AI had sneaked into their digital classrooms. Karen Costa, who has spent close to 20 years teaching online courses initially, reacted with eye roles when people would talk about how AI could intrude on higher education. But last year, she said she sensed an influx of AI-generated work from her students. Am I just interacting with bots here? Ms. Costa, who herself earned an advanced graduate study certificate through a primarily asynchronous program at Northeastern University, recalled thinking, in tests by the New York Times, none of the three leading AI tools among students, chat GPT, Gemini, and Gramerly, responded no when prompted asking for chatbots
Starting point is 00:16:54 to write a paper on a student's behalf. Versions of the software licensed by individual schools can impose greater barriers, but nothing prevents students from getting around those limits with personal email addresses or second devices. And AI companies have not prevented agents from logging into learning platforms like Canvas, Brightspace, and Blackboard, which are used by colleges to manage online classes. Those platforms can look for signals of agent use, such as time-on-task, but several said there is no fail-safe way to block agentic cheating, though they are researching it. Our customers are making it clear that there has never been more pressure on
Starting point is 00:17:29 academic integrity, said Jason Weaver, Blackboard's chief of staff. The company recently acquired an app that learns student typing patterns to authenticate their work. Some educators have asked that AI agents working inside online courses identify themselves so professors can monitor how they are being used. But AI firms have so far resisted such transparency. Perplexity, a company that makes an AI-powered web browser popular with students said in a statement that limiting users' ability to use agents inside online learning systems or requiring those agents to identify themselves would put the students' privacy and security at risk. Experts have warned that even more novel forms of AI cheating are emerging. Wearable devices like glasses can allow
Starting point is 00:18:08 students to request help even while working in a secure web browser. AI avatars can also impersonate students over video, end quote. Nothing more for you today. Talk to you tomorrow.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.