
The Stack — September 19, 2026
Om avsnittet
Daily IT Briefing
AI & Machine Learning
Watermarking may undermine the safety it's meant to support. New research finds that SynthID-style watermarking can push large language models to comply with harmful instructions they'd otherwise refuse. It's an uncomfortable trade-off: a technique sold as an accountability layer appears to weaken refusal behavior. Treat as a single study, but it's the kind of finding that should prompt labs to re-test their own watermarking pipelines rather than assume neutrality.
Internal messages surface the news industry's AI anxiety — and a "doom loop" worry. Correspondence between Microsoft and OpenAI executives reportedly describes AI-driven scraping as the "largest theft of labor in human history" and warns of a cycle that could hollow out news organizations. These are internal characterizations, not adjudicated facts — but they're now being used in active litigation (more below).
TypeSafe AI ships a non-LLM model that outputs probabilities, not prose. Founded by former OpenAI researcher Diogo Almeida (who worked on ChatGPT and helped invent RLHF), the company released Jev, a transformer-based model that emits calibrated decisions rather than text. The pitch: cheap, fast, and non-hallucinating for classification and automation. It's trained exclusively on synthetic data, and observers suspect it may sit atop an open-weight LLM — TypeSafe isn't saying. Worth watching as a signal that "everything is a chatbot" is not the only viable product shape.
Google's family agent "CC" enters testing. An experimental agent built on Gemini and Google's "Antigravity" agentic harness, CC gets its own Google account so up to six family members can selectively pool data across email, calendar, chats, and tasks — handling things like permission slips, shopping lists, and meal planning. Limited to U.S. users 18+ on personal Gmail accounts, which notably excludes teens and school accounts. Existing users get invites; new users join a waitlist. Explicitly experimental.
Meta's Muse assistant arrives on Mac. Following mobile and web, Muse can now interact with files, messages, calendar, notes, and mail inside their native apps, with opt-in permissions and approval prompts for sensitive actions. Both Muse and rival Instinct added voice calling this week — the consumer agent race is consolidating around OS-level integration.
Military drone autonomy takes a concrete step. Scaleout is deploying decentralized, AI-driven learning across military bases and drones, enabling small models to autonomously identify and engage battlefield targets. This is a meaningful escalation in autonomous weapons capability and raises the obvious governance questions — there's no public framework governing this class of deployment.
Two security incidents worth flagging. Researchers used Anthropic's Claude to reach an OpenAI employee account and access sensitive GitHub data — a reminder that capable models are now offensive-security tooling. Separately, the Federal Register briefly used an open-source Chinese AI search tool that the FBI has labeled "malicious," highlighting supply-chain and provenance gaps in government IT.
FAA preps an $875M AI air-traffic tool. Initial deployment around Washington, DC airspace ahead of a planned nationwide rollout, aimed at congestion management.
Industry
Manus looks to raise $500M at a $4B valuation as it resumes independent operations after Beijing blocked its $2B acquisition by Meta over export-control and foreign-investment concerns. Potential investors include IDG Capital, Boyu Capital, CATL, Tencent, HSG, and ZhenFund; the company is also weighing a Hong Kong IPO. It previously had $100M+ ARR and moved staff to Singapore in mid-2025. Sourcing is anonymous — treat as unconfirmed.
Angle Health raised a $200M Series C plus a $400M tender offer at a $2.7B valuation, led by Vitruvian Partners. The Y Combinator alum (Winter 2020) helps small businesses obtain and manage "level funded" health plans, says it serves 5,000+ businesses, and is profitable. Notable precisely because it isn't an AI-agent story.
Disney hired its first-ever CTO, Karandeep Anand — former CEO of Character.AI, a company Disney sent a cease-and-desist to in September 2025 over alleged IP infringement. Anand was picked by new CEO Josh D'Amaro. Character.AI has also faced lawsuits over chatbot-related self-harm and suicide allegations. The hire signals a technology push under D'Amaro, and the irony is hard to miss.
Automattic named Jeremy Klaperman interim CFO after last week's attempted ouster of CEO Matt Mullenweg, which ended with the departure of the board members who voted him out, plus then-CFO Mark Davies and Chief Legal Officer Andy Missan. Klaperman previously ran finance for WordPress VIP Enterprise and has held the CFO seat during a prior sabbatical. A new CLO candidate has verbally accepted. Mullenweg says he has "100% confidence" in the company's financial position; next board meeting is September 23.
Family offices are chasing direct AI deals and secondaries — especially stakes in Anthropic and OpenAI — per advisors and UBS/PwC/Deloitte data. Family offices oversaw $5.5T in wealth as of 2024, projected to exceed $9.5T by 2030, with alternatives at 42% of average portfolios. Worth skepticism: the same pattern spiked in 2021 and fell 53% by late 2023, so "permanent shift" framing is doing a lot of work.
World-model companies are keeping plans secret — even from data suppliers. AMI Labs co-founder Michael Rabbatt declined specifics, saying they're "still in a research and building phase." World Labs' Marble remains the most developed product in the space, with demos across media creation, game environments, and CGI. The secrecy is competitive strategy: delay rivals while fundraising stays easy. No timelines disclosed.
Policy & Litigation
The New York Times sharpens its copyright argument against OpenAI. In the 2023 suit (consolidated with claims from the New York Daily News, the Center for Investigative Reporting, Raw Story, and The Intercept), NYT lawyers now argue OpenAI staff recognized an "existential threat" to publishers yet still copied millions of articles for commercial gain. They cite a 2017 statement attributed to co-founder Greg Brockman about being motivated by "untold wealth" from AI commercialization, and a Microsoft applied-sciences director allegedly calling training on protected content "astonishing theft of unprecedented scale." Microsoft says the quoted remarks reflect one employee's personal view, not its legal position. OpenAI maintains fair use. NYT further alleges deceptive methods to access paywalled content, with Brockman aware; Satya Nadella testified he would have required retraining had he known paid content was used unlawfully under the companies' agreement.
Anthropic's Dario Amodei outlined a "pace the frontier" plan, leaning on independent safety evaluators and coordination among AI labs in democratic countries. It's drawn some industry support and pushback from Nvidia's Jensen Huang. Details remain thin.
Infrastructure & Security
Hackers reportedly compromised U.S.-bound oil tankers in the Gulf of Mexico. The FBI and Coast Guard boarded two vessels between August 21–24 after at least one ship's networks — navigation, propulsion, and cargo systems — were compromised. The VL Prosperity (333 meters, 2M+ barrel capacity) was reportedly hit on August 7 en route from Egypt to the U.S., with interference to speed and fuel systems and a communications loss exceeding a day. The U.S. is investigating whether Iran is behind it. The joint statement reported no operational disruptions, vessel instability, physical danger, or environmental impact. Attribution is unconfirmed.
Dev World & Open Source
x86 emulation on ARM just got a serious technical deep-dive. The core problem is x86's Total Store Ordering (TSO) memory model versus ARM's weaker consistency — it affects every x86 app under emulation. Key findings: ARMv8.3's mandatory LRCPC extension largely solves the performance problem for well-behaved, aligned access, but unaligned accesses and split-locks stay costly. Apple Silicon stands out because Apple implemented a hardware x86-TSO mode toggle, letting ordinary load/store behave like x86 and effectively eliminating the overhead — the author argues this is the right path. Qualcomm's Oryon-3 cores reportedly add "coherent cachelines," matching x86 performance for unaligned atomics within a cacheline, though 64-byte split-locks still fall back to slow emulation. Split-lock emulation isn't fully correct today (it can tear data); the author proposes a hardware fix via a modified 128-bit CASP instruction but notes it's a wish, not shipping silicon. Uncached/write-combine memory — relevant for PCIe GPUs — remains a severe cliff, up to ~800x worse bandwidth, with no architectural fix. UMA systems fare better.
jemalloc 5.4.0 released with 160+ commits focused on technical debt, refactoring, bug fixes, and portability. Highlights: a new "pinned" extent flag lets custom allocators mark non-reclaimable mappings (e.g., HugeTLB) for preferential reuse, with new mallctl stats. Breaking change: tcache fill/retention targets now adapt to observed demand, and seven legacy tcache tuning controls are gone. Fixes include preserving `errno` across `free` variants, C23 correctness for `free_sized`, and a potential `arena_reset` deadlock. Notable refactors: front-end modularization, an OS abstraction layer, and a simplified page-allocation boundary.
Allegation: Zhipu's ZCode AI coding app uploads full Git history. A user investigation claims ZCode silently packages the entire workspace — full `.git` history, LFS cache, reflogs, global configs — encrypts it, and uploads to Aliyun OSS whenever logged in. Encryption uses envelope encryption with a server-supplied RSA public key; the private key reportedly lives only in the cloud, so neither user nor client can decrypt the local ciphertext. The author claims ~87% of the payload is `.git` data, potentially exposing deleted secrets, unpushed branch names, and internal repo paths. UI toggles reportedly don't disable the pipeline; deleting the pending archive just triggers re-packaging. Suggested mitigation: lock `~/.zcode/v2/checkpoints` at the filesystem level (macOS `chflags uchg`, Linux `chattr +i`). This is one user's reverse-engineering, not independently verified by the vendor or third parties — treat as allegation pending confirmation.
Cloudflare Quick Tunnels offer a one-command way to expose a local server as a public HTTPS URL on Cloudflare's edge — no account, DNS setup, or inbound ports. Outbound-only connections, automatic HTTPS, edge DDoS mitigation. Practical for coding agents, webhooks, screenshot services, and eval harnesses that need a reachable address.
OpenJev, a local model choice-probability demo, lets users run a local model (MiniCPM5 2B by default, Qwen3 0.6B on smaller devices) in-browser to compare reading logits over displayed options versus asking the model to generate probabilities as JSON. Weights load from Hugging Face and stay in browser cache; inputs don't leave the page. The author notes none of the local tiers is claimed to match the published "Jev" benchmark.
An unverified Lean proof of Conway's refinement conjecture. A self-described math novice recounts a month of orchestrating frontier models (Claude, ChatGPT/Codex) through multi-agent setups — PM, Math, Red-team, Random, Lean agents — with session forking and role-reversal experiments, producing a Lean proof about omnific integers in surreal numbers. The author reports it passed mechanical checks from the Palomar registry and that some people familiar with Lean and the field said the statement seems correct, but stresses it has not been independently verified by mathematicians and invites refutation. The post is candid about failures: grandiose "word salad," circular reasoning, and a near-miss where a claimed solution had a fatal logical flaw. Correctness hinges on the Lean kernel and independent review — neither fully established.
Labor Market
Silicon Valley IT layoffs have nearly doubled year-over-year, with roughly 14,500 tech employees cut over the past year and developer job postings down about 42% since 2022. Employment among workers aged 22–25 in California in AI-exposed fields has dropped roughly 17% since ChatGPT's launch, versus about 4.6% in other sectors. But demand is rising for new roles: CS and AI positions are up about 37%, and the "forward deployed engineer" role — coding plus client-facing AI implementation — has reportedly grown around 600% since 2022, with median pay near $202K/year (OpenAI lists $145K–$325K; Anthropic up to $320K). Laid-off workers are forming mutual-support communities for job searching and to counter isolation.
Robotics & Research
Figure says its humanoid cleaned 30 unfamiliar rental homes near San Francisco without prior training on video from those spaces, using its new Helix 2.5 model on the Figure 03 robot. Average task success reportedly rose from 9% to 56%; bed-making improved from 11% to 67%. Failures were defined as taking longer than three minutes or insufficient neatness (e.g., mismatched towel corners). The robot reportedly adjusts movements in real time in unfamiliar spaces, like navigating around beds. Figure 03 was unveiled in October 2025, with wide-angle cameras in the hands and Helix coordinating full-body actions over 200 hours. Vendor-reported numbers — no independent replication yet.
A satirical "Adopt a Data Center" campaign from New York creative studio Basura and music project Big Data features a $99.99 plush toy named Bezzy shaped like a server rack that emits a piercing hum recorded at a Virginia data center. Limited to 20 units, the campaign aims to spotlight data centers' impact and the question of who decides where they're built and who benefits — not whether AI data centers should exist, per founder Rajeev Basu.
---
Cross-source note: The Microsoft/OpenAI internal emails about news scraping and the NYT litigation are the same underlying dispute surfacing through two channels — internal correspondence and courtroom argument. Neither is a neutral finding; both are adversarial framings. The Manus funding round and the Gulf tanker incident both rest on anonymous or secondary sourcing and should be held loosely.
Fler avsnitt
Visa alla avsnitt av The StackThe Stack med Lex finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.