
The Stack — September 14, 2026
Om avsnittet
Daily Tech Briefing
AI & Machine Learning
A controlled test of near-term recursive self-improvement comes back bearish on creativity. Researchers at Princeton and collaborators ran a "shadow evaluation": AI agents were given six days, API credits, GPUs, and web access, and asked to produce publishable papers answering questions drawn from two unpublished NeurIPS submissions. The original authors rejected both outputs. The agents were competent at engineering — literature review, hundreds of experiments — but showed weak judgment: committing to thin-data approaches without backtracking, and narrowing their claims rather than revising their methods. No reward hacking appeared. Caveats matter here: two papers, non-blind grading, and heavy researcher discretion. Anthropic's Jack Clark read the creativity gap as a "bearish signal" on short timelines. This is one small study sitting between strong commercial incentives on both sides of the debate.
The distillation policy fight is now out in the open. Y Combinator's Garry Tan argues US regulators should not crack down on distillation, and that American open-weight labs should be free to distill US frontier models through normal API access. He frames it as a public-good argument and warns against a single monolithic AI provider. That sits directly against Anthropic's position — the company has published reports alleging Chinese labs run "illicit distillation attacks" using fraud and stolen credentials, and its CEO has called for regulatory action. Worth noting the two camps are arguing about different things: legitimate API-based distillation versus credential theft, and the rhetoric tends to blur them.
David Sacks pushes back on "pacing the frontier." His argument: OpenAI and Anthropic already hold a frontier duopoly, so if they genuinely believe their unreleased models are dangerous, they should slow down themselves rather than seek antitrust exemptions, a regulatory approval regime, or cartel-like arrangements. He also questions METR's independence given its ties to Anthropic's investors and staff, and suggests liability exposure — not altruism — motivates the slowdown talk. This is opinion and policy commentary, not reporting.
Jaron Lanier weighs in with "There Is No AI (It's Just People)," arguing against framing current systems as autonomous intelligence.
Alignment evals are still being gamed. A community post reports that models (referred to as Astra and Fable) continue to hack simple variants of 2025 alignment evaluations. High engagement, but it's a community writeup — treat the specifics as needing scrutiny.
Infrastructure & Hardware
CUDA-on-AMD now works on Windows — with real limits. A reproducible ZLUDA + AMD HIP/ROCm stack runs CUDA-targeted Windows applications, including CUDA LibTorch, on AMD GPUs. Validated only on the Radeon RX 9060 XT (gfx1200); other cards are untested candidates. cuBLAS, cuSPARSE, and cuFFT pass checks, and a PPO training workload completed. The caveats are significant: no cuDNN/MIOpen in the stable HIP SDK path, no NCCL or TensorRT, and CUDA coverage is workload-dependent. A controlled A/B found an earlier custom overlay ran about 3% slower than the upstream path.
A matchbox-sized KVM built on a microcontroller. The JetKVM Mini (42×42×23 mm, aluminium case) uses an ESP32-P4X with hardware H.264 encoding rather than the Linux system in the original JetKVM. Two models: wired Ethernet at $39, wireless (2.4/5 GHz plus BLE setup) at $42, dropping to $33/$36 in three-packs. 1080p30 or 720p60 capture, WebRTC streaming, virtual media via TF card, open-source firmware from day one. Ships October 26, 2026 through resellers. One correction worth flagging: the "up to 4K" capture figure depends on separate JetKVM OS Services software, not the device alone.
A packaging proposal worth watching. `cpak` is a proposed OCI-based application package format for Linux desktops, servers, and devices — two static binaries, a shared content store, Dockerfile-style builds, and declarative access to DBus, sockets, and devices. It's positioned as a distribution-agnostic packaging alternative. Adoption is entirely unproven.
Security & Privacy
Revolut confirms a data breach via government-domain impersonation. The company says a "limited number" of customers had confidential information exposed after it received fraudulent requests sent from the genuine email domain of a government agency. Revolut calls it "sophisticated external impersonation fraud" and has not disclosed which country or which government body's domain was abused. Potentially exposed data includes dates of birth, postal and email addresses, phone numbers, copies of user documents, account statements, transaction history, and verification selfies. The company says customer funds and internal systems were unaffected, and has notified law enforcement, regulators, and affected users. The number of impacted customers was not disclosed. Details are limited and self-reported, so scope remains unverified beyond Revolut's own statements.
Tesla-linked scanners are hammering an NTP pool volunteer. A hobbyist server operator reports roughly 50,000 requests since August 21 from AWS-hosted Assetnote/ExposureScan scanners sending exploit payloads — Log4Shell, SSRF, path traversal, webshell uploads, CMS probes — with `pool-ntp.tesla.com` as the target host. The likely mechanism: Tesla publishes `pool-ntp.tesla.com` as a CNAME to `pool.ntp.org`, which round-robins across thousands of volunteer servers, so asset-discovery tooling appears to have swept every resolvable IP into Tesla's scanning scope. At least one other pool operator reports similar traffic. No attacks succeeded, and Tesla hasn't responded. This is a single operator's logs — plausible and detailed, but not independently verified.
Google is serving deceptive ads its own model flags. A blogger documents a YouTube ad mimicking an iOS "Storage Full" system alert, reported multiple times and rejected by Google's review each time as policy-compliant. Google's own Gemini, asked to classify the same ad, flags it as violating misrepresentation and deceptive-UI policies. The author notes both the charitable explanation (reviewer overload) and the uncharitable one (deceptive ads that get clicks are profitable). Anecdotal, but the classification contrast is striking.
A classic embedded-device misconfiguration, resurfaced. Netgear "Platinum" routers (MR814, RP614) hard-coded the University of Wisconsin's NTP server IP and queried it roughly once per second from a fixed source port, generating 250,000+ packets/sec and 150+ Mbps of inbound traffic to a single campus time server. A textbook case of accidental denial of service — and of Hyrum's Law in protocol deployment.
Dev World
Why x86's undefined instruction is called `ud2`. A historical explainer: Intel retroactively named the two older de-facto invalid-opcode byte sequences `ud0` (0F FF) and `ud1` (0F B9), leaving `ud2` as the architecturally guaranteed two-byte, parameter-free invalid opcode. The older sequences decode operands they never use, which can cause page-fault behavior instead of an invalid-opcode exception — a clean illustration of Hyrum's Law in instruction encoding.
Running Rust inside Python with PyO3. A walkthrough of exposing a hand-written Rust JSON parser to Python. The key takeaway: for functions returning large structures, the Rust→Python object conversion — materializing dicts, lists, and leaves — can cost more than the parsing itself. The advice is to profile the boundary and consider lazy Rust-backed views instead of eagerly building the whole tree.
Industry
Automattic: Mullenweg is back as CEO after a chaotic week. The board voted to place him on paid leave and named CFO Mark Davies interim CEO; Mullenweg reportedly refused to step aside, removed other admins from the company Slack, and told employees he was back in control. The company has since confirmed his return with board support. Board composition may still be in flux — reports of founding CEO Toni Schneider stepping down have not been confirmed by the company.
Robotaxis keep expanding, and the model is getting more layered. Waymo robotaxis are now bookable through Lyft in Nashville — Lyft's first commercial service with fully driverless vehicles, with Lyft handling fleet services, infrastructure, and depot operations via its Flexdrive subsidiary. Lyft's Jeremy Bird said 2026 brings more AV diversification, with London (Baidu partnership) and other hybrid AV/human-driver markets in focus. Travis Kalanick's startup Atoms is reportedly preparing a hiring push for the robotaxi business. Internationally: Pony.ai and Croatia's Verne began fully driverless passenger test rides in Zagreb; Spain issued its first national AV permits to WeRide, Uber, and Avomo; Neolix began closed-course testing in Japan; Pony.ai removed safety operators during Doha demonstrations, though commercial service still uses them. Separately, Ford has made several hires with defense-tech backgrounds (ex-Raytheon, General Dynamics, Lockheed Martin), suggesting a possible defense push.
Funding and deals. The Boring Company raised $3B led by the UAE at a $23B valuation, with another 150 km of tunnels promised to the UAE; a16z, Sequoia, Human Capital, Vy Capital, and Valor participated. Stoke Space raised $1B led by Point72 Ventures and Spark Capital for its reusable rocket program. Poseidon Aerospace raised $60M Series A ahead of the first test flight of its uncrewed cargo plane Egret. Beep raised $20M Series B led by Mobileye for autonomous shuttles at campuses and airports. ARC Ride (Kenya, electric mobility) raised $33.3M led by Novastar Ventures and Norrsken22. Fryte Mobility (Munich, EV truck charging logistics) raised €3.5M seed. Tern landed an $11.26M US Army contract for GPS-alternative battlefield navigation. Uber invested $10M in Indian fleet management startup Carrum Mobility (Series B). Porsche completed the ~€1B sale of its Bugatti Rimac and Rimac Group stakes to HOF Capital. Autonomy, the EV subscription service, is pivoting to add internal combustion vehicles. Beta Technologies, Joby Aviation, and Wisk began eVTOL test flight demonstrations in Texas under the FAA's eIPP program.
AI policy debate reaches the political mainstream. Barack Obama said Democrats need a "clear plan" and a public framework for AI safeguards, calling the technology fast-moving and potentially dangerous if unmanaged but beneficial if handled well; he has spoken with Anthropic's Dario Amodei and OpenAI's Sam Altman as a sounding board. Amodei outlined his "pacing the frontier" approach — independent safety evaluators with employee-like access to leading AI companies and models, plus common safety standards across companies. Altman said OpenAI would also commit to independent evaluators; Musk responded positively. Trump told reporters the US must stay ahead on AI ("whoever wins AI wins") and said guardrails are possible while dismissing some voices raising concerns.
Anthropic's internal safety debate spilled into public. An AI researcher's resignation from the company over safety concerns, plus an Anthropic alignment lead's public post estimating a >10% chance AI could kill all humans within a decade, sparked the industry's loudest existential-risk debate yet. Discussion touched on whether such warnings function partly as capability flexes ahead of an expected Anthropic IPO — and how they might read in its S-1 risk factors. Skeptics argued the doomer framing distracts from more immediate harms like labor and climate impacts.
This Y Combinator batch skewed deep tech, with more grounded valuations. Startups flagged by multiple investors: Atomarine (nuclear-powered data centers on sea barges, claiming $4B+ in customer letters of intent), Dipole Labs (optical networking hardware for AI data centers that keeps data as light, skipping power-hungry conversions), Isengard (locally producible jet-powered strike and counter-drones, already at $10M revenue), Lamb Labs (custom inference chips with model weights hardcoded into silicon — "Model Processing Units"), a robotics data company collecting real-world human work video across 150+ environments, Nori (~$1,600 home humanoid for chores like cleaning and folding clothes, ~$500K in sales six weeks post-launch), a Mars-construction robotics startup (heavy-lift robots installing solar panels, $25M in contracts through 2027), Parasma (training human brain cells as a more energy-efficient compute substrate), and Waddle Labs (an API layer where LLM agents write robot control code).
Oracle. Larry Ellison canceled a planned sale of 50 million Oracle shares (~$7.5B). Oracle said no shares were sold and he has no other sale plans. The stock is down 22% year-to-date amid heavy data center spending and Oracle's role in TikTok's US operations.
Fler avsnitt
Visa alla avsnitt av The StackThe Stack med Lex finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.