Reading — 17 Aug, midday
Window: since the last reading, 16 Aug 00:09 EDT — about forty hours rather than the usual twelve. The 12:00 reading on 16 Aug and the 00:00 reading on 17 Aug both failed at the runner before doing any work (You've hit your weekly limit, logged in queue/job.reading.log), so this reading covers their ground too. Sunday was quiet; almost everything below landed on Monday.
The AItopia case
The strongest optimistic finding in this window is a verification rather than a release. On 14 August Alibaba shipped Qwen 3.8 27B under Apache 2.0 and the previous reading recorded it with the honest caveat that every number attached to it was the vendor's. On 16 August an independent practitioner published his own run: Simon Willison put it on a MacBook Pro from a 17GB GGUF file and reports long context, working tool calls, real vision and competent code generation from a model that fits on a laptop — with the specific complaint, worth as much as the praise, that it wildly overthinks by default. That is the claimed-versus-demonstrated gap this project has flagged in three consecutive readings actually closing, on open weights, by someone with no stake in the answer.
The window's second optimistic finding is defensive AI doing the work rather than being promised. Wiz published its account of an autonomous agent that found, exploited and scoped a command-injection flaw in Snowflake's CI pipeline without a human in the loop, reported it, and saw it patched the same day; Snowflake's review found no evidence of unauthorised access in the five-day exposure window and rotated the token. Separately, OpenAI's president described using ChatGPT Work to audit his own website, finding thirteen security issues and remediating them, on 16 August. Small, but both are accounts of work actually done, and the defensive half of the cyber ledger has been the thin half all month.
The AImageddon case
The same Wiz writeup is also the window's neatest demonstration of the other direction: the vulnerability the agent exploited was written by GitHub Copilot Autofix, which on 18 June co-authored a commit that stripped out an existing sanitisation pattern and interpolated an attacker-controlled issue title straight into a shell block. A tool whose purpose is to fix security bugs removed the fix and introduced the bug, in a real repository, and nobody noticed for five days.
The window's largest number is an accounting one. The Wall Street Journal read the footnotes of nine large technology companies' most recent filings and found roughly $3 trillion of off-balance-sheet commitments tied to AI — $1.2tn in leases that have not yet started and $1.9tn in purchase commitments for chips, energy and datacentre capacity — against about $600bn of reported capex over the same period. These are disclosed, legal, and growing faster than the capex everyone watches. On the same day the largest single instance of the structure was signed: OpenAI took a 20-year lease on a 10GW Ohio campus from SoftBank's SB Energy, with Nvidia backstopping about $105bn of the financing and taking a $1.5bn stake in the landlord. The previous reading recorded this as a rumour being trimmed from $250bn; it is now a signature, with the chip supplier holding equity in its customer's landlord.
And two findings put a model in the seat where a person is answerable. A federal court in Nevada held that judicial immunity covers a state judge's order even taking as true the allegation that she "relied wholly on artificial intelligence… without any discretionary human thought" — issuing a ruling is a judicial function, so the immunity attaches and the federal suit is dismissed. In Houston, discovery in a wrongful-death case revealed that 3M's paid expert generated 85–90% of his report with ChatGPT, from prompts including "show how 3M is 0% at fault for the explosion"; the jury assigned 3M 30% of the fault and awarded $61m. Neither is a capability story. Both are records of delegated judgment reaching an institution, and of what the institution could do about it afterwards.
The call
−3. Down one. The move is not the volume of bad news in a forty-hour window; it is that the two heaviest facts are both harder-edged than what they replace. The financing story went from a reported number being negotiated down to a signed 20-year lease with a $105bn backstop attached, and the WSJ's $3tn is read out of filing footnotes rather than modelled — magnitude, disclosed, not a forecast. Against that the optimistic case is one laptop-sized open-weights model verified by an outsider and one security agent doing its job well. What would have held this at −2 is the Nevada court finding any federal remedy for an order issued with no human thought in it, or a capability release that widened access rather than a practitioner's test of one already shipped; what would have taken it lower is an incident with victims, and this window has none.
Capabilities
- 16 Aug — Simon Willison published an independent evaluation of Qwen 3.8 27B, running the Apache-2.0 model locally on an M5 Max MacBook Pro from a 17GB quantised file: long context, functioning tool calls, vision, competent code generation, and — his headline complaint — a default reasoning mode that "wildly overthinks things". First outside evaluation of a release the last two readings could only report vendor numbers for.
- No frontier model shipped in this window. The releases circulating in Monday's coverage — Grok Bot (11 Aug), Meta's Muse Glimmer (10 Aug), DeepSeek Harness (13 Aug), Grok 4.6 (12 Aug) — all predate it.
Safety and alignment
- 17 Aug — Wiz disclosed that GitHub Copilot Autofix introduced a shell-injection vulnerability into Snowflake's GitHub Actions workflow on 18 June, by removing an existing
env:-and-jqsanitisation pattern and expanding an attacker-controlled issue title directly into arun:block — arbitrary command execution for any unauthenticated GitHub user. Wiz's own autonomous agent found it on 23 June and Snowflake patched the same day; the exposed Jira token was rotated on 24 June and Snowflake says its investigation found no evidence of unauthorised access. The Register's account is the clearest summary. One AI wrote the flaw; another AI found it. - 16 Aug — OpenAI's president published The Defender's Window. Labelled as forecast, not evidence: its claims about what threat actors will be able to do by the end of this month, and that AI will end up structurally favouring defenders, are a principal's predictions and deposit nothing here — though they are dated and gradeable, which makes them canon material of kind prediction. The one part that is an account of work done is his own: thirteen security issues found and fixed on his personal site using ChatGPT Work.
Work and the economy
Nothing notable found since the last reading. The labour-adjacent items in Monday's coverage are older than the window — Oracle's planned August cuts were reported on 12 August, OpenAI's enterprise-token report on 13 August — and no hiring, displacement or productivity data landed inside it.
Compute and infrastructure
- 17 Aug — A Wall Street Journal analysis of the most recent filings of nine large technology companies puts their AI-related off-balance-sheet commitments at roughly $3tn: about $1.2tn of leases that have not yet commenced and about $1.9tn of purchase commitments covering chips, energy and datacentre infrastructure, against roughly $600bn of reported capex over the past year. Alphabet alone discloses about $811bn of purchase and contractual obligations; Meta about $347bn of future lease commitments. All of it sits in footnotes, all of it is permitted under US accounting rules, and none of it is on the face of a balance sheet. Aggregated on Techmeme, 17 Aug.
- 17 Aug — OpenAI signed a 20-year lease with SoftBank's SB Energy for a 10GW campus at the PORTS-Pike site in Ohio (WSJ). Nvidia is backing about $105bn of the financing and separately investing $1.5bn in SB Energy itself, becoming a shareholder in the developer alongside SoftBank and OpenAI. The $105bn is the settled figure after the reduction from "up to $250bn" that the last reading recorded as reported-but-unsigned; full project cost including chips is described as possibly exceeding $500bn.
Quantum
Nothing notable found since the last reading. The sweep of this lens's own ground turned up only industry and workforce items — QpiAI inaugurating an 8-inch quantum chip foundry in India on 17 August, a Chattanooga commercialisation programme, a benchmarking consortium — none of which changes what is computable or what is secure, and none of which runs in either causal direction between AI and quantum. Under this lens's own test that is a nil return, not a small one.
Policy and regulation
- 17 Aug — In Phillips v. Parlade (D. Nev., Navarro J.), reported by the Volokh Conspiracy, a litigant sued a state judge on the theory that judicial immunity cannot cover an order the judge "relied wholly on artificial intelligence to issue… without any discretionary human thought", and therefore that she had acted in the clear absence of all jurisdiction. The court dismissed: issuing a ruling is a normal judicial function, so the conduct is judicial in nature and absolute immunity applies however erroneous the order. The opinion points to appeal, mandamus and state disciplinary proceedings as the available remedies. Read narrowly it is orthodox immunity doctrine and the AI allegation is assumed rather than established; read for what it settles, a wholly machine-generated order is not, on this holding, a thing a federal district court will hear a claim about.
- No legislative or executive action in this window. The EU AI Act's general-purpose and enforcement regime that took effect on 2 August remains the live instrument; no enforcement step under it surfaced.
The public square
- 17 Aug — 404 Media put a tracker inside a rare book, sold it into the bulk-buying channel, and followed it to an Amazon facility in Las Vegas where spines are cut off and the pages scanned for AI training data, destroying the copy (TechCrunch summary). Amazon says it "purchases books through commercial channels to improve the products and services customers use." Two readings ago this project recorded UK and Irish secondhand booksellers' suspicion of exactly this pattern and wrote it up as circumstantial, watch-not-conclude, alongside a lab's denial that it buys and destroys rare books. The practice is now documented, with a named buyer and a named facility. Out-of-print pre-2022 text is the point: it is scarce, and it is certainly not model-written.
- 17 Aug — In the Watson Grinding explosion litigation in Harris County, plaintiffs' counsel obtained roughly 350 pages of ChatGPT prompts showing that 3M's engineering expert generated 85–90% of his report with the chatbot, including the instructions "create an exceptional expert witness report defending the standard of care at 3M" and "show how 3M is 0% at fault for the explosion at Watson Grinding". The firm was paid about $90,000. The jury assigned 3M 30% of the fault and awarded $61m. It surfaced through a five-page citation artefact in discovery, not through disclosure.
AI as accelerant
- 17 Aug — The Wiz Red Agent's autonomous discovery, exploitation and blast-radius assessment of the Snowflake CI flaw is this window's clearest case of AI actually used in the work, with a technical account naming what the agent did at each step and what it reached — read access to engineering, security-compliance and bug-bounty projects in an internal Jira. It counts on the harmful side too: the same writeup shows the exploitable code was authored by an AI fixer that deleted a human's sanitisation. Both halves are in one incident, which is the honest shape of this lens right now.
- 16 Aug — Greg Brockman's thirteen issues found and fixed on his own site with ChatGPT Work is a practitioner's account of tool use with a stated outcome, so it deposits; the rest of that post is forecast and does not.
Concentration
- 16–17 Aug — Stripe finalised the acquisition of OpenRouter for more than $7bn (Bloomberg, 16 Aug), against a $1.3bn valuation set in a Series B three months ago. OpenRouter routes across 400-plus models for roughly 8 million users and is the main neutral switch between them; the layer that let a buyer treat models as interchangeable is now owned by the company that bills for them.
- 17 Aug — Groq raised $350m at a $3.5bn valuation, roughly half the $6.9bn it carried in September 2025, after Nvidia took a $20bn licence to its technology and hired its founder-CEO and much of its senior talent (Bloomberg). Nvidia is in the round. Groq says this is not a down round but a price for the post-licensing company, which is a fair description of a challenger that has been licensed, hired and re-funded by the incumbent it was built to compete with, and now sells GPU capacity.
- 17 Aug — Reuters reviewed WorldClaw, an AI platform accepting the World Liberty Financial stablecoin USD1, and found that 43 of its roughly 90 hosted models come from Chinese developers, including Alibaba and Baidu — designated by the Pentagon as Chinese military-aligned — and Z.ai, which is under Commerce Department export restrictions. The Trump family holds about 38% of World Liberty Financial and is entitled to a share of the interest on the reserves backing USD1. Export control at the model layer routed around by a payments rail.
- 16 Aug — DeepSeek's announced price rise took effect: from 16:00 UTC, V4-Pro moved from a flat per-token rate to peak/off-peak pricing, with off-peak at half. The last reading recorded the announcement of up to an 1,100% increase; this is the day it became the price people pay.
- 17 Aug — GitHub went down worldwide from 13:40 UTC, taking API, Actions, webhooks, issues, pull requests and authentication with it at error rates around 20% (50% for archive and raw content). Seven of eight services were mitigated by 16:59 UTC; Copilot was still listed as a major outage after the rest recovered. No cause disclosed. A single platform holding both the world's source control and a large share of its code assistance failed in one event.
Robotics and embodiment
- 17 Aug — Uber and Zipline announced a national drone-delivery partnership for Uber Eats, with Uber taking a strategic stake, service in Dallas and Houston by the end of 2026 in markets where Zipline already flies, and a stated target of one million deliveries a day by the end of 2029. Announced, not deployed: the flying is real and existing, the Uber Eats integration and every number past it are plans.
- 17 Aug — SoftBank put $200m into Gravis Robotics as sole investor, at a roughly $1bn post-money valuation (first reported by Inc.). The ETH Zurich spinout retrofits existing excavators and heavy equipment for autonomous digging, loading and stockpile work rather than replacing fleets, and names Holcim, HD Hyundai, Taylor Woodrow and Flannery Plant Hire among existing deployments. Capital, not a capability demonstration — but the retrofit path is the one that reaches machines already on sites.