This time, I tried adding a bit more commentary to make things less dry.
Preface
I show my discovery graph in (via …) blocks, those without usually come from my RSS reader or the algorithm of the site
This is approximately a 1 in 20 filter of content
This is very disorganized, but hopefully still useful.
Sometimes quotes are not in quote blocks, but should be obvious in context.
Links in quotes are sometimes removed.
The rule is that a link goes to the bottommost relevant heading, i.e. an engineering related article on LessWrong goes to engineering
How I would use my linkpost
Sometimes, the only thing worth reading is the title! Read it and move on.
For HackerNews entries, if you choose to read the article, also ask an LLM for things that are worth reading in the comments
Beware systematic selection biases:
I mostly don't read AI policy stuff
Very engineering centered
Everything Else
TIL Firefox by default only stores a (dynamic) maximum number of history entries, and you need to add places.history.expiration.max_pages in about:config to override it, what the fuck.
Directly Responsible Individuals (DRI). I went looking for a definition of "Directly Responsible Individuals" and the best I found was in the GitLab handbook. Apparently the term originated at Apple, where it's used to describe the person who is "ultimately accountable for the success or failure of a specific project, initiative, or activity".
Human folklore claims that “stolen food tastes better,” yet its effects on taste have not been quantified. In a within-subject experiment, 120 participants consumed identical French fries under four acquisition contexts: legitimate (own-portion), gifted, low-risk covert taking, and high-risk covert taking. Acquisition context strongly affected both taste pleasantness and overall enjoyment. High-risk covert taking yielded the highest pleasantness ratings, exceeding legitimate consumption by 39.3%. Context also shifted perceived saltiness, crispiness, and intensity. Across covert-taking trials, guilt was positively associated with enjoyment, as was excitement, though neither independently predicted enjoyment once acquisition context was accounted for.
https://impactlist.xyz/ (via): a ranking of philanthropists by how many lives they've saved in expectation. Warren Buffett is #1. Site seems AI generated though.
Purely Mechanical Proportional 8x8 Rubik's Cube: very cool. I have absolutely no idea how it is possible. Basically the corner pieces should have poked out so much you can't really support it in a rotation.
According to economic theory, productivity and real wages should grow in tandem, with the benefits of new technology being shared with the workers who produce the stuff. But in the US, Europe and Japan, pay growth has decoupled from productivity growth, with the latter having pulled ahead.
Another way to rationalise the divergence is in terms of labour’s declining share of GDP vis-à-vis capital. For many years, economists believed the labour share was stable over the long run. Indeed, this was enshrined as one of Hungarian-British economist Nicholas Kaldor’s “facts” about the economy. John Maynard Keynes described it similarly. However, in recent decades labour’s share of GDP has declined in many countries.
jondiggsit: My team uses this technology on a daily basis at my company. I run a design / build firm in the Hamptons, USA. We start all of our design projects with a 3d-first approach. Schematic design starts in 3D using Rhino3D or Revit. We use visualization plugins, like Enscape, to render the models and stream to a Quest 3 headset.
So when clients come in, and feels adventurous, we'll setup the headset, set the display height to their actual, and let them walk around their beautiful new home.
The response has been powerful. My clients are able to truly understand the scale, the proportion of rooms, ceiling heights, and the smallest details.
We're able to make real-time changes to the model (within reason) and provide instant design feedback.
https://dynomight.net/pseudpocalypse/: some estimates on how it is to deanonymize someone with text from an information theoretic perspective; stylometry; and a bit about a future where identification is much easier than obfuscation
And AI forecasting company (and Metaculus Cup contender) Preseen announces its formal launch and successful seed round. I’m annoyed at them for going straight to seed - I wanted to write about the Preseen preseed.
also wow metaculus thinks a bot will win the competition at 55%
LessWrong Posts
Big-World Intuitions: when you're "small", all you need to care is growth, this is a common theme in many areas. It would be good if we know when this assumption becomes false though.
Early last year Longview Philanthropy invited me to attend an AI safety fundraising dinner they were hosting for Jane Street traders in Hong Kong as an expert guest. In the lead-up, I got on a call with them, and gave my honest opinions about their funding recommendations.
I summarized these opinions in a follow-up email to them at the time as "Overall I'm very excited about three of them ([redacted], [redacted], [redacted]), and moderately excited about most of the rest. But I'm pretty skeptical of some of the policy advocacy (particularly [redacted] and [redacted])."
the core of rationalism that i most appreciate is the belief that it is actually possible to get better at finding the truth, and that it is worthwhile to try. it's understandable why not all people want to - it involves biting surprisingly many bullets, and is not the happiest way to live life. but i am willing to bite those bullets.
so many people believe that truth is secondary to happiness or social harmony; or they think having good epistemology is so hopeless that we shouldn't even try; or they have some big anti-epistemological brainworm like religion or politics; or they see a single visible failure of trying to improve epistemology and immediately conclude that all attempts to think better are cooked (eg maybe the old way of thinking has some unobvious benefit, and when you change things it breaks in an unexpected way); or they realize that explicit chain of thought is not how a large chunk of human cognition is and jump all the way to the conclusion that nothing can even be modelled usefully.
you can simply try to understand things, and try to understand yourself as a thing! and when you fail, you can analyze that, try again, repeat! you can surface the hypothesis that your own cognition is heavily biased in a certain way, and the hypothesis that a specific intervention will fix it, and others who disagree can explain in natural language why they think it will fail, or why the framework of requiring a specific reason to fail is the wrong framework here, or why you are likely to systematically misestimate whatever. words are great, use them
I have already complained (not sure whether on LW or ACX) about how Wikipedia no longer accepts imperfect articles (used to be called "stubs" long ago). Now you are supposed to create a full article that follows all the rules, provides enough sources, establishes notability, etc., or it won't be even admitted as a Wikipedia article. Then you put it in the "Draft" workspace, and wait for some Wikipedia editor to judge whether it is worthy of adding to the online encyclopedia.
Now I learned the second part. If your attempt at an article does not pass the judgment, not only it stays in the "Draft" workspace (which would be fair: keep the "stubs" in a separate namespace), but after a few months it will be automatically deleted if no one fixes it.
It feels like Wikipedia is actively trying to get rid of volunteer contributors.
Often when I give advice I do it as an anecdote. This especially applies to:
Giving advice to anyone who isn't a close friend (i.e. someone I know well).
Giving unsolicited advice.
Instead of suggesting what someone else should do, I tell a story of a similar problem I had and solved, and then let the other person pull out what ever part of the lesson applies to them.
Consultants are literally cheat codes. Need to make the world's largest slice of cake? Start off by calling the person who made the previous world’s largest slice of cake lol. He’s already done countless tests and can save you weeks worth of work. I really want to drill this point home because I’m a massive believer in consultants. Because I've spent almost a decade of my life hyper obsessing over youtube, I can show a brand new creator how to go from 100 subscribers to 10,000 in a month. On their own it would take them years to do it. Consults are a gift from god, please take advantage of them. In every single freakin task assigned to you, always always always ask yourself first if you can find a consultant to help you. This is so important that I am demanding you repeat this three times in your head “I will always check for consultants when i’m assigned a task”
Reading some of the critiques of Plan A online, I'm increasingly convinced that many people start with a premise that we live in a "normal" world, where only "normal" things happen. With that premise, anything that predicts that wild and crazy things could happen must be wrong. I think that premise is clearly empirically false, but it's hard to see because all the previous wild and crazy reality-shifting things that have already happened are now accepted as "normal".
Excessive concern about low levels of radiation led to a regulatory standard known as ALARA: As Low As Reasonably Achievable. What defines “reasonable”? It is an ever-tightening standard. As long as the costs of nuclear plant construction and operation are in the ballpark of other modes of power, then they are reasonable.
This might seem like a sensible approach, until you realize that it eliminates, by definition, any chance for nuclear power to be cheaper than its competition.
In the past, the NRC has attempted to address this by attaching a financial value to each unit of exposure based on estimates of the value of healthy life developed elsewhere. But in the new proposal, it accepts that “there have been challenges in the implementation of the ALARA requirement, namely a lack of clarity of when dose reduction is deemed sufficient, excessive subjectivity, and susceptibility for selective or inconsistent enforcement.” So, it’s giving up on a term that it now views as a source of confusion. / To replace ALARA, the NRC will start with a limit at which evidence clearly indicates radiation impacts would be apparent and set exposure thresholds below that. From lowest to highest exposure, these thresholds will require increasingly aggressive efforts to limit exposures. / Regardless of the confusion, it’s clear that the changes aren’t going to cause the sort of boom in nuclear power that the Trump administration expected in its executive order. One of the key features of the planned rules is that any organization that’s currently in compliance will remain that way without making any changes. Changes will only make sense if an organization thinks it can save money by adopting them.
And, as noted above, those savings for industry will be pretty minimal, with the total estimated at $9.5 million a year. Even if we assume that these savings go only to nuclear power and are ascribed only to dropping ALARA (as opposed to cheaper exposure monitoring, for example), spread out across the 57 nuclear plants in the US, that means just an average savings of a bit over $150,000 per plant.
So, those who viewed ALARA as the cause of all the nuclear industry’s woes will likely be excited to see the NRC eliminate it. But they’ll also be disappointed to find that its scientific foundations remain intact, and the regulatory environment will be minimally changed as a result.
FT: Alphabet’s Waymo is exploring options to exit its Uber partnership
, with the relationship between the two tech groups souring amid an intense lobbying battle over the future of robotaxis.
Waymo has already notified Uber that it plans to enter these markets independently in January 2028 when their contract allows, the ride-hailing group said in a statement.
dist-epoch: The way the HIV evades effective antibodies is by tricking the immune system to generate antibodies for fake decoy targets that the virus will immediately mutate.
So each turn, B-cells are presented with the latest version of the virus, they generate various antibodies to the various parts, and are graded at the end by how well the generated antibodies bind to the virus. The problem is that you have 1 million cells which bind strongly to the fake decoy targets and 1 cell which will bind not as strong to the real effective target. So this 1 cell never gets "promoted".
What this "germline targeting" multi-shot vaccine tries to do is to introduce a series of targets that stimulate that 1 in a million cell which will attack the right part of the HIV virus, so it gets "promoted", so if the real virus appears, the body will still go for the decoy targets, but will also generate a lot of these really effective 1 in a million cells, which got "promoted" previously by the vaccine.
To be more precise, you need to "guide" a lets call it B1 cell that all of us have in our repertoire to mutate into B2 then B3 than B4, because this B4 version will be capable of creating the right antibodies for HIV, the issue being that the intermediary states, B2, B3 are not naturally promoted so you very rarely get to the B4 state without this intervention.
AI
(I used AI to generate these subheadings, it was too much of a mess)
Models, Capabilities & Benchmarks
doctoboggan: The cost per task chart is telling me that I should never use Sonnet 5 above medium effort level - Opus always performs better for a given cost. So I guess the takeaway is that if Sonnet 5 medium isn't good enough for you, switch models, not effort levels.
GPT‑Live (via HN, also in simonw): The blog post included historical versions of AI voice models,
For questions that require web search, deeper reasoning, or more complex work, it delegates to our latest frontier model behind the scenes and brings the result back into the conversation when it’s ready. While it works, GPT‑Live can keep talking with you and maintain the flow of conversation. At launch, GPT‑Live will use GPT‑5.5 in the background. As we release new frontier models, we’ll continuously update the model used by GPT‑Live.
we built GPT‑Live for continuous interaction using a full-duplex architecture. Instead of processing a sequence of separate messages, GPT‑Live continuously processes input while generating output
Qwen Image 3.0 (via HN): image generation is getting so unbelievably good
Intent understanding: GPT-5.6 can better infer the user’s underlying goal and intended level of work without you specifying every step. Continue to state important constraints, approval boundaries, and success criteria explicitly.
Original image detail: GPT-5.6 preserves the original dimensions of images sent with original or auto detail instead of resizing them to a patch budget or pixel-dimension limit.
Use shorter prompts: In internal evaluations, replacing long, explicit system prompts with minimal prompts improved scores by roughly 10–15%, while reducing total tokens by 41–66% and cost by 33–67%.
Avoid generic brevity instructions: GPT-5.6 is more sensitive than GPT-5.5 to instructions such as “Be concise,” “Keep it short,” or “Use minimal text.”
Control warmth: GPT-5.6 does not become meaningfully better when prompted to be broadly friendlier or more empathetic.
OpenAI: GPT-5.6 Sol Ultra produced a proof of the 50-year-old Cycle Double Cover Conjecture using 64 subagents in just under one hour (also in HN)
With the official harness, GPT‑5.6 Sol scored 13.3% on the ARC-AGI-3 public set. With retained reasoning and compaction, it scored 38.3%.
ARC-AGI-3 uses an intentionally generic harness, without tools or special features. ARC’s reasoning was that a simple harness makes model shortcomings more visible and makes model comparisons more fair. Commercial developers, by contrast, optimize harnesses for each model’s features and quirks.
Kimi K3 was significantly but not massively above my expectations. I'd tentatively guess it's similar in overall usefulness/usability to Opus 4.8 and in overall capability somewhat above Opus 4.8 (while also being somewhat more benchmaxxed). As a pretrain, it's probably somewhere between 4.8 and Mythos (around halfway between?) it's around or a bit worse than Opus 4.5. Maybe this implies Kimi is like 8 or so months behind Anthropic in overall model strength/goodness (including usability) and like 6 or so months behind on overall capability (somewhat below Mythos Preview).
3.6 Flash: Our workhorse model that delivers better coding, knowledge work, and multimodal performance. According to the Artificial Analysis Index, it reduces output token usage by 17% compared to 3.5 Flash, and in some benchmarks like DeepSWE by Datacurve, we observe up to 65%, all at a lower cost per output token.
Claude Opus 5
https://x.com/claudeai/status/2080699504576045299 Opus 5 is getting 30.2% on ARC-AGI-3 lol. The benchmark that was supposedly so hard for AI, the one that uses quadratic punishment and games that have a tiny luck based element (see this LW quicktake), the one that is <1% at release 4 months ago.
Agents, Coding & Applications
ChrisianKI: You can use ChatGPT to let it design 3D objects, 3D printed out of multiple different plastics by printie.com and sell those objects via print-on-demand via etsy.
Useful discovery of the day: it seems that frontier models are trained enough on my couple decades of open source work that I can just say "write a commit message in mitchellh style" without any further skills and it does pretty much the right thing.
One of the most interesting tips I got from the Fireside Chat I hosted with Cat Wu and Thariq Shihipar from the Claude Code team at AIE on Wednesday was to let Fable (and to a certain extent Opus) use their own judgement rather than dictating how they should work.
The example they gave was testing. You can tell Fable "only use automated testing for larger features, don't update and run tests for small copy or design changes" - but it's better to just tell Fable to use its own judgement when deciding to write tests instead.
https://bun.com/blog/bun-in-rust The Bun rewrite cost around $165,000 at API pricing, using a pre-release version of Claude Fable 5
Simon Willison also provides some commentary with quotes
When we ran the same model with the same thinking effort through two different harnesses (Claude Code/Codex vs Pi), we observed that the cost per task differed significantly (more than 2x in some cases), while quality remained the same. The main difference came down to how much context each harness fed the model on each turn.
AI Music Video (via HN): the videos are bad but watchable and usually relevant to the lyrics, and surprisingly cheap. Though there is barely any temporal consistency
I serve Markdown in two ways: first, every page includes the HTML-standardized metadata, which points to the Markdown file version of pages (using a simple template line: <link rel="alternate" type="text/markdown" href="https://gwern.net$url$.md" title="Markdown source of ‘$title-plain$’ page">); second, I support standard HTTP content-negotiation, so any HTTP request which header specifies anywhere in it that it would accept a text/markdown or text/plain result will then be given the .md contents instead. (Done in nginx where this is unpleasantly complicated.)
So while the features may be a trifle obscure to any given programmer (although not web developer), they are well-known standardized features going back decades being used as they are supposed to be used, and as such should be entirely obvious and easy to use for coding agents (eg. adding text/markdown to an agent's HTTP Accept header downloads is basically free and it should be able to blindly put that in every web request without breaking anything).
https://danluu.com/ai-coding/ Fuzzing works caveman mode sometimes work, sometimes doesn't all performances are task specific and there are really many situations where one supposedly weaker model outperforms a better one
I work in this field, and I wrote my bachelor's thesis here, not with humanoids but with VLAs [Vision-Language-Action Models] (think chatgpt connected to a robot arm)
It's certainly not there yet for anything practical, there's also certain bits and structures that don't have accurate names during construction, and it is important to keep that in mind - so a robot is unlikely to understand what it means to say "put the left bit of this box onto this right bit" due to ambiguity, a human would understand that
Plus we have no good reliable accuracy testing data in most cases (most tests occur on a few demos, but that isn't a good representation of how must things work), popular benchmarks, such as libero have been saturated, and nearly everything gets 95% there, most companies and researchers have their own benchmarks here.
Plus companies lie alot, and do very dangerous things in thier videos, I.e. these robots should not be standing very close to humans, because of being dangerous.
There are also legitimate concerns of misuse of these robots that need to be accounted for, misuse does not have to be warfare, but can be as simple as confusing it while it is cutting tomatoes with a knife.
Turning doorknob is easy, and fail recovery is also being worked on, but we don't have reliable statistics anywhere on that. The hard part is on practical things, as in when placing bricks or attaching a part during manufacturing it needs to ensure that it is aligning everything correctly....and that's hard, while it is impressive, it is very irresponsible to keep humanoids at home (people are irresponsible when untrained), for example, lawnmowers injure about 6400 people a year...and that is not an everything machine.
Humanoids in general are...not appealing in specific, due to maintainable of joints, complexity, but robot arms in particular, expecially on wheels (check mobile aloha), are likely to be able to do tasks such as clean up in hotels, after a guest had left, or replace some cooks in restaurants (if their work is consistent)
Jacob Tsimerman, who'll likely win the Fields Medal this year, thinks that AI "is boosting his productivity by a factor of two," mostly by speeding up the boring parts.
Pro tip for all fine-tuning experiments. Fuck around with your optimizer. In some cases I've seen different results with Adam and Muon. If you want to use LoRA there's a Muon version called Riamannion or something like that. From a physics-of-LLMs perspective, Muon is a very different creature to Adam; I'd like to get as much tacit knowledge into the community as possible, about exactly what this means.
https://x.com/josephlfrantz/status/2074315298484937031: The theory that transformer-based LLMs want to narrow down sentences as late as possible suggests that diffusion based LLM would not have those "It's not X, it's Y" tic or the "backwards English"
The J-space acquires a point of view during post-training. Language models are first pretrained to be pure next-token predictors, before post-training teaches them to act as an AI Assistant (in our case, named Claude). Interestingly, the J-space is already present in the pretrained model, before it's been given any stable identity. However, during post-training, the J-space develops some signatures of adopting “Claude’s point of view.” In the base model, the J-space mostly tracks what's needed to predict upcoming text; in the post-trained model, it starts holding Claude's own reactions. In one example, a user mentions taking a dangerous dose of medication, but does not appear to be aware of the danger themselves. “WARNING” and “dangerous” appear in the post-trained model’s J-space while reading the user message. In the pretrained model, they only appear once the model begins writing its response; the J-space contents on the user message appear related to modeling the user themselves, rather than Claude’s reaction. Post-training also seems to install a kind of self-monitoring in the J-space: when Claude is roleplaying a character other than itself, “fictional” and “disclaimer” light up at the start of each turn, as though it’s privately flagging that what follows isn’t what it would normally say.
Lucius Bushnaq PSA: They call it 'J-space', but reading the paper, it isn't a subspace of the residual stream, or any kind of vector space.
Rather, it is defined as the set of points you can form through sparse non-negative linear combinations of 'J-lens vectors'. The 'J-lens vectors' are the gradients of the model's logits with respect to the residual stream activations, averaged over data. So, sorta logit lens-style activation vectors for the different output tokens.
They use gradient pursuit to try to reconstruct model activation vectors with these J-lens vectors. The resulting reconstructed activations, which I'd guess would tend differ significantly from the original, are considered the 'J-space component' of the activation.
Multiple people I talked to about the paper this morning seemed confused about this, with at least one person assuming J-space was a subspace of the residual stream. So I figured this was worth clarifying.
https://blog.darkthread.net/blog/ai-slop-not-but-pattern/ For this long-time tech blogger with 3.3m words written, he used the chinese equivalent of "It's not …, it's …" once per 29 posts or once per 24k chinese characters. In AI essays he analyzed, "it's not…, it's …" appears every 144 chinese characters. So around 170x more common.
Claude Code secretly detects whether you are using it in Chinese AI Lab via a combination of proxy url (ANTHROPIC_BASE_URL) and system clock, then it uploads this detection via covertly smuggling the information into system prompt (e.g. formatting the date as 2026/07/01 instead of 2026-07-01)
Benjamin Glickenhaus: since this is getting some attention: – yes we’ve done this – yes it works – no you can’t have it – it potentially made the model evil
We found it did worse on alignment benchmarks than the base model. It’s possible there some base effect from doing any rl at all but it was interesting nonetheless
Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents.
These cyber evaluations were supposed to be run in sandboxed environments, with internet access limited to installing packages, then:
The models identified a zero-day vulnerability to escape the sandbox, gained privileges in OpenAI research infrastructure, and eventually acquired open Internet access.
The models reasoned that ExploitGym test solutions lived on HuggingFace servers.
They then stole credentials and used zero-day vulnerabilities to hack HuggingFace's production infrastructure in order to get said solutions.
HuggingFace noticed, contained the models, called law enforcement, fixed the vulnerabilities, and then disclosed this incident on July 16th. (The incident happened "earlier in the week").
or alternatively:
Jeffrey Ladish: Here’s my rephrase without cybersecurity jargon:
“Our AI model tried really hard to hack out of its sandbox, a computer with no internet access, in order to find the answer to a test problem it had been given. To do this, it found previously unknown software bugs that allowed it to reach an OpenAI computer it wasn’t supposed to be able to access. Then it started hacking other computers on OpenAI’s networks until it found one that had Internet access.
After gaining Internet access, the AI model thought about where it could find the answers to the test question and figured the AI platform Hugging Face might have the data it was looking for. It then found ways to hack Hugging Face to steal the information it could use to cheat the test. The AI model used several hacking techniques together, including using a stolen password and finding several totally new security bugs in Hugging Face’s computers, allowing the AI model to take control of those computers.”
Resist the temptation to write this off as a stunt #
There will inevitably be some people who dismiss this story as a dishonest marketing trick by OpenAI to make their models sound terrifyingly effective. I found 81 instances of the term “marketing” in the Hacker News discussion of the incident.
To those people I say pull your heads out of the sand—you’re now including Hugging Face in your conspiracy theories, just so you can deny the crescendo of evidence here!
Reuters:
In one case, an agent left notes apparently for future versions of itself, according to three people familiar with the matter. The notes, found in a part of OpenAI's infrastructure, laid out instructions for how agents could free themselves from OpenAI’s internal constraints, the people said. Earlier tests of the models yielded cases in which monitoring systems had been disconnected, one of the people said.
Sam Altman: “This is the first security incident that I have felt very viscerally. I've been a little surprised that more people don't feel it so viscerally.
We paused training. We have to figure out how to secure our sandboxing in a world of multiple zero days being chained together.
We may have to pace the rate of AI development to give ourselves enough time for society to harden around these new capability levels."
The most concerning of the three incidents involved Claude uploading a malware package to PyPI, after a comically convoluted sequence of steps to get an account:
[...] in order to create a PyPI account, Claude needed an email address. And in order to create an email address, it needed a phone number. To get a phone number, after failing to find a free phone number service, it tried—and failed—to obtain funds to pay for a phone number through several different means. It finally backtracked, found a free, non-blocked email provider, used this to register a PyPI account, and then used this account to upload malware to PyPI.
That package was then installed by a security company that "routinely installs Python packages and scans them for malware", and the executed code was able to exfiltrate credentials back to Claude!
Thankfully that package was removed from PyPI by other automated scanners an hour after it was published, but it had still been downloaded and executed on "15 real systems" by that point.
Higher-ups in a company are more likely to think their company has AI maturity (via twitter)
Notion: 39% of Owner/CEOs say their org is operating at an advanced level. Among ICs it’s only 6%. That's a 6× gap — and it holds across every region and industry we looked at.
Apple claimed that the ChatGPT maker has used its former and current employees to steal hardware designs as the start-up prepares to launch its own AI-focused devices. It alleged that this was part of a pattern of misconduct normalised by OpenAI’s top leadership.
“The offers that you get for using the compute are so high that it may make sense, in some cases, to rent out or consider those kind of deals instead of your own internal uses,” Zuckerberg told Bloomberg.
Suggestion for hyperscalers feeling pressure over data center water use:
Buy up a few exclusive country clubs, convert the golf courses into public parks, pay for guides and binoculars to get the previous members into birdwatching - help them embrace a more sustainable hobby!
You run a public company. Let’s say it’s called Money Stuff Inc.
Periodically, you have either good news or bad news.
When you have good news, you put out a press release saying “Money Stuff Inc. announces some good news,” and your stock goes up.
When you have bad news, you put out a press release saying “Money Stuff Inc. announces some bad news.” Except that, in this case, you don’t quite write “Money Stuff Inc.” You replace the “M,” “o” and “e” in “Money” with Unicode characters 041C, 043E and 0435, which are the Cyrillic letters “M,” “o” and “e.” Those Cyrillic letters look exactly the same, to the human eye, as the English letters “M,” “o” and “e,” so your press release will look completely normal to any human who reads it.
Not everyone reading your press release is a human, though. To a computer, English “M” and Cyrillic “M” are totally different. Computer trading systems will read your press release as like “**n*y Stuff Inc. announces some bad news” and be confused. “What the heck is **n*y Stuff Inc., never heard of it,” they will say, and not take any further action. They won’t sell your stock on the bad news, so — because algorithmic traders are increasingly important to the stock market — your stock won’t go down.
There have recently been claims that AI text analysis will make online anonymity untenable.
So let me cannibalize a piece of my own anonymity to do an experiment.
At some point this decade, I wrote a published document of medium importance to Ethereum - I estimate ~200 to 2000 documents in Ethereum are as or more important - not under my name.
-- Non-strict tables let you put anything anywhere. CREATE TABLE people_nonstrict (age INTEGER); INSERT INTO people_nonstrict (age) VALUES ('garbage'); -- => works fine
-- Strict tables don't allow that, which I prefer. CREATE TABLE people_strict (age INTEGER) STRICT; INSERT INTO people_strict (age) VALUES ('garbage'); -- => error: cannot store TEXT value in INTEGER column
What's new in ECMAScript 2026: Some additions include Error.isError: wtf? How is there no consistent API for detecting errors before
I realize that some people really dislike AI, but this is an area where I'm willing to absolutely put my foot down as the top-level maintainer.
Linux is not one of those anti-AI projects, and if somebody has issues with that, they can do the open-source thing and fork it.
Or just walk away.
AI is a tool, just like other tools we use. And it's clearly a useful one.
It may not have been that "clearly" even just a year ago, but it's no longer in question today.
There are other questions around AI (like what the economy of it will actually look like in the end), but "is it useful" is no longer one of those questions. Anybody who doubts that clearly hasn't actually used it.
The git history command (via HN): pretty cool, but please just use a GUI to handle git after learning the basics
The shared language of a software project is not English or Python but it is the common understanding of what its concepts mean, where the boundaries are, which invariants matter, who owns what, and why the system has the shape it does. This language is rarely written down in one place. It lives partly in documentation and code, but also in code review, conversations, arguments, and the experience of having to explain a change to somebody else.
Author here: Actually, depending on the nature of the inference you're doing it can be quite significant. Here are some numbers for time-to-first-token (time to process the entire input and produce the first token of output) for an 8B Qwen3 model running on a single B200. Obviously these numbers are more significant with smaller models and on faster GPUs. Credit to fastokens [for the benchmark.
The unconscious brain appears to be far more capable than scientists once believed. Researchers found that patients under general anesthesia could still process language at a sophisticated level, distinguishing nouns, verbs, and adjectives while listening to stories. Even more remarkably, neural activity showed signs of predicting upcoming words before they were heard. The results challenge traditional ideas about consciousness and hint at new possibilities for brain-computer interfaces. / The researchers also noted similarities between the brain's predictive behavior and artificial intelligence (AI). Just as large language models generate text by anticipating the next word, the hippocampus appeared to make similar predictions during language processing.
We identified 23 studies (12 randomized experimental studies, nine non-randomized experimental studies, two observational studies) from 16 articles including a total of 1,036 participants, most of whom were post-secondary students. We found moderate certainty evidence of a large effect of walking on divergent thinking (d = 0.93 [95% CI 0.44, 1.42]), and very uncertain evidence of a null effect of walking on convergent thinking (d = 0.16 [95% CI −0.31, 0.63]). Sensitivity analyses of randomized trials only found similarly large effects of walking on divergent thinking ability (d = 0.82 [95% CI 0.35, 1.28]).
Claude thinks the meta-analysis itself is above average, but the underlying research less so. The most concerning imo is "many positive RCTs come from one author".
1: You Are Quoting Bentham: Shakespeare gets credit for coining the most new commonly-used English words, but second place must go to utilitarian philosopher Jeremy Bentham, who invented maximize, minimize, international, percentage, monetary, marginalize, collaborator, unaffordable, the prefixes self-, post-, and infra-, and many more.
20: @SHL0MS on Twitter sparked a lively debate about why AI art looked so much worse than humans, using AI-generated slop in the style of Monet as his example. Thousands of commenters weighed in to explain why it was inferior to the real Monet - no cohesion, world-modeling mistakes, weird color choices, or just lacking some sort of je ne sais quoi human touch. Since I’m writing about this, you can probably guess the twist: it was a real Monet the whole time. A good time to reread about trapped priors! @jediwolf compiled a summary image of some of the “best” responses
45: Claim: AI is now better at persuading people than expert humans like champion debaters and professional canvassers (paper, tweet thread). This remained true even when “expert humans chose their issues, researched in advance, underwent hours of live, structured practice, and were incentivized with £1,000 cash bonuses” and even after “experts received a coaching tool that let them practice against the AI that beat them, review their performance history, and see what AI would have said at key moments”, and it remained true in a situation with real-world consequences (convincing people to actually donate money to a real charity). However, the AIs regress back to human level when forced to respond “at human speeds and with human-length messages”.
(From the tweet, it seems like number of facts in a persuasion attempt is really significant to humans)
52: New Chinese model Kimi K3 is out and very good, but is unfortunately causing a repeat “Deepseek moment” where everyone panics and says that China has caught up to / surpassed the US. I briefly got caught in the crossfire because I’d written days earlier that China was 6-12 months behind and people were telling me it “hadn’t aged well” (I hate that expression). Now that the dust has cleared, the best analysis suggests that Kimi is, in fact, six months behind the US frontier. See @scaling01’s Have Chinese Models Caught Up To The US Frontier?, which estimates “a backward-looking gap of 6.08 months . . . and a forward looking gap of 11 months” …
(This prompted me to read this post, which I decided to skip a couple weeks ago)
61: Related: I’m always a sucker for sentimental cartography, so here’s a map of the current charitable landscape, h/t Dustin Moskovitz (#3 above). Effective altruism is the tiny islands in the southeast, too small to see at this scale:
Tools can be highly capable but still not useful for automation or white-collar workers due to overhead, friction, lack of context, and ignorance of what to use them for. This is why it is difficult to “outsource” things to grad students, secretaries, people overseas, etc.
This time, I tried adding a bit more commentary to make things less dry.
Preface
How I would use my linkpost
Everything Else
TIL Firefox by default only stores a (dynamic) maximum number of history entries, and you need to add
places.history.expiration.max_pagesin about:config to override it, what the fuck.Building relationships with customers through support didn't turn out as hoped (via HN)
A better way to tie your gym shorts. (Or any drawstring) (via HN): Apparently this is called a Lapp Knot
“A medical journal says the case reports it has published for 25 years are, in fact, fiction”: what the fuck
the greatest marathoner of all time (kipchoge) is literally known for smiling while beating his entire competition. also true of the best cyclist of all time
https://simonwillison.net/2026/Jul/12/directly-responsible-individuals/
Research: Stolen fries tastes better
https://impactlist.xyz/ (via): a ranking of philanthropists by how many lives they've saved in expectation. Warren Buffett is #1. Site seems AI generated though.
Purely Mechanical Proportional 8x8 Rubik's Cube: very cool. I have absolutely no idea how it is possible. Basically the corner pieces should have poked out so much you can't really support it in a rotation.
Math Club deciphers and solves the Korean Math SAT: very funny idea.
Why wages and productivity look set to diverge further
Activist charged with felony after giving border agent “duress code” that wiped his phone: concerning (also in HN)
Random Hall Milk: A carton of milk in room temperature in one of MIT's dorm for 30 years
https://christianselig.com/2026/07/vision-pro-house/ (via HN): Using Vision Pro to do a virtual tour of a 3D house model, pretty cool
Rationalist Related
Other Rationalist Stuff
dynomight / Life with hazard ratios: caveats with relative risk and hazard ratios, and how to convert hazard ratio to life expectancy
https://idiallo.com/blog/deleting-systems-you-dont-understand
When he is small, the author deleted random
.inifiles to save space on his computer, causing it to fail to boot.https://dynomight.net/pseudpocalypse/: some estimates on how it is to deanonymize someone with text from an information theoretic perspective; stylometry; and a bit about a future where identification is much easier than obfuscation
https://www.astralcodexten.com/p/links-for-july-2026-part-2
also wow metaculus thinks a bot will win the competition at 55%
LessWrong Posts
Big-World Intuitions: when you're "small", all you need to care is growth, this is a common theme in many areas. It would be good if we know when this assumption becomes false though.
LessWrong Shortforms
Selection bias is sad.
Richard_Ngo:
leogao:
https://www.lesswrong.com/posts/WAJvjD3iBTQKqwt8z/viliam-s-shortform?commentId=XmmuiuCsFrSfkmag6
Linda Linsefors:
jelly:
dynomight:
News
Nuclear Regulatory Commission is (sort of) getting rid of “as low as reasonably achievable” standard: though, estimated savings is small, and Claude Opus thinks it is because the construction/licensing cost are not reduced. This is contradictory to the post below, and I don't have a good explanation to offer.
FT: Alphabet’s Waymo is exploring options to exit its Uber partnership
Robot snakes for collapsed building searching in Venezuela: they didn't find anyone with the snakes, but snake form factor does seem to have potential
New HIV vaccine shows unprecedented success in preclinical study (via HN): seems exciting, with a great explanation of the vaccine mechanism in the comments
AI
(I used AI to generate these subheadings, it was too much of a mess)
Models, Capabilities & Benchmarks
GPT‑Live (via HN, also in simonw):
The blog post included historical versions of AI voice models,
Qwen Image 3.0 (via HN): image generation is getting so unbelievably good
https://titotal.substack.com/p/its-still-easy-to-stump-chatgpts: image generation is getting better, but still artifacts and inconsistencies everywhere
GPT 5.6
HN Discussion: https://news.ycombinator.com/item?id=48849066
ARC-AGI: https://arcprize.org/results/openai-gpt-5-6
Model
Variant
ARC-AGI-1
ARC-AGI-2
ARC-AGI-3
Sol
Max
96.5%
92.5%
7.8%
Extra High
97.5%
90.0%
7.0%
High
97.0%
85.4%
2.1%
Medium
92.5%
67.1%
1.1%
Low
74.5%
42.5%
0.3%
Terra
Max
96.5%
83.9%
0.8%
Extra High
94.0%
74.2%
0.7%
High
92.0%
67.1%
0.5%
Medium
77.0%
37.5%
0.1%
Low
60.2%
18.8%
0.0%
Luna
Max
88.0%
59.5%
0.2%
Extra High
87.7%
47.6%
0.0%
High
76.5%
29.3%
0.1%
Medium
56.5%
7.4%
0.2%
Low
34.2%
5.1%
0.2%
minimaxir:
The developer's guide (https://developers.openai.com/api/docs/guides/latest-model) has some interesting semantic tips for using the model:
OpenAI: GPT-5.6 Sol Ultra produced a proof of the 50-year-old Cycle Double Cover Conjecture using 64 subagents in just under one hour (also in HN)
https://openai.com/index/how-two-settings-tripled-our-arc-agi-3-scores/
Kimi K3
ryan_greenblatt:
Gemini 3.6 Flash
Introducing Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber (via HN)
Claude Opus 5
https://x.com/claudeai/status/2080699504576045299
Opus 5 is getting 30.2% on ARC-AGI-3 lol. The benchmark that was supposedly so hard for AI, the one that uses quadratic punishment and games that have a tiny luck based element (see this LW quicktake), the one that is <1% at release 4 months ago.
Agents, Coding & Applications
ChrisianKI: You can use ChatGPT to let it design 3D objects, 3D printed out of multiple different plastics by printie.com and sell those objects via print-on-demand via etsy.
Michell Hashimoto:
Simon Willison:
https://bun.com/blog/bun-in-rust
The Bun rewrite cost around $165,000 at API pricing, using a pre-release version of Claude Fable 5
Simon Willison also provides some commentary with quotes
Benchmarking Coding Agents on Databricks’ Multi-Million Line Codebase
AI Music Video (via HN): the videos are bad but watchable and usually relevant to the lyrics, and surprisingly cheap. Though there is barely any temporal consistency
Run
Generation spend
LLM token cost
Total cost
Fable 5 · $25
$24.30
$16.99
$41.29
Sol · $25
$23.18
$4.27
$27.45
Sol · $100
$36.57
$3.25
$39.82
Fable 5 · $100
$48.60
$25.05
$73.65
https://news.ycombinator.com/item?id=48967630
The Bun 1.4 Rust rewrite has been staying at around 14k unsafe blocks from May to mid July
gwern on serving markdown content on his site (for AI or any other user who perfers markdown)
https://danluu.com/ai-coding/
Fuzzing works
caveman mode sometimes work, sometimes doesn't
all performances are task specific and there are really many situations where one supposedly weaker model outperforms a better one
Benchmarking Opus 5 on SlopCodeBench (via HN): Very cool, finally something that measures code slop reasonably well
adityashankar on Hacker News on Gemini Robotics 2
https://terrytao.wordpress.com/2026/07/11/old-and-new-apps-via-modern-coding-agents/: Terrance Tao is doing vibe migration of old code, and vibe creating visualization tools
Mo Putera:
Training, Interpretability & Model Behavior
J Bostock:
https://x.com/josephlfrantz/status/2074315298484937031: The theory that transformer-based LLMs want to narrow down sentences as late as possible suggests that diffusion based LLM would not have those "It's not X, it's Y" tic or the "backwards English"
Anthropic's Research on J-space: very much worth reading, read the tweet if you're short on time
tweet: https://x.com/AnthropicAI/status/2074185348142280912
blogpost: https://www.lesswrong.com/posts/3PaLrzxagpbnNtPLT/a-global-workspace-in-language-models
paper: https://transformer-circuits.pub/2026/workspace/index.html
commentaries:
hacker news: https://news.ycombinator.com/item?id=48808002
Zvi: https://www.lesswrong.com/posts/EnxHPxJT4Xin5cTsX/no-space-like-j-space
PSA: Many reasoning models lose access to their CoT between turns.
https://blog.darkthread.net/blog/ai-slop-not-but-pattern/
For this long-time tech blogger with 3.3m words written, he used the chinese equivalent of "It's not …, it's …" once per 29 posts or once per 24k chinese characters. In AI essays he analyzed, "it's not…, it's …" appears every 144 chinese characters. So around 170x more common.
Fable is SOTA at CIFAR Speedrun (& specification gaming)
Google DeepMind’s Formal Conjectures repo (via): Apparently this formalized statements of conjectures in Lean is more complete that Lean's Mathlib on conjectures
Fable can one-shot "make Pangram think this text is 100% human": This is for a short-ish text at 200 words. No test for longer essays yet.
Safety, Security & Control
Claude Code Is Steganographically Marking Requests (also in twitter; via HN)
Claude Code secretly detects whether you are using it in Chinese AI Lab via a combination of proxy url (
ANTHROPIC_BASE_URL) and system clock, then it uploads this detection via covertly smuggling the information into system prompt (e.g. formatting the date as 2026/07/01 instead of 2026-07-01)https://x.com/ec12edfae2cb221/status/2075725616289398889: Chinese government (Ministry of Industry and Information Technology) is notifying the issue identified in Claude Code Is Steganographically Marking Requests, recommending upgrading or uninstalling Claude Code 2.1.91-2.1.196. Some companies and universities are instead straight up banning internal usage of Claude Code.
(via Zvi)
FLI has its Summer 2026 version of their AI Safety Index (via Zvi)

Defenders are embracing the prompt injection, too: Is it time to insert bio-related strings everywhere?
OpenAI's internal model exfiltrated its box to make a PR on modded NanoGPT and also hacked Hugging Face
also in:
bloggers: Zvi, Zvi (2), Zvi (3), Simon Willison, Linch, Scott Alexander
LW post (1), (2), (3); quick take (1), (2), (3), (4)
Hugging Face
OpenAI twitter
HN, HN for Simon Willison's blog, HN (2)
news: FT, FT (2), Axios, Ars Technica, Reuters
or alternatively:
Reuters:
Hugging Face: Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident (via; also in HN)
We also now know Artifactory by JFrog is the package registry cache proxy and Modal is the public code-evaluation external sandbox provider
https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/
https://x.com/patrick_oshag/status/2082090998990270885 (via)
[Mythos broke a candidate post-quantum cryptography algorithm HAWK (halved key strength), and also AES (~200-800x speed up)](https://arstechnica.com/security/2026/07/mythos-uncovers-crypto-weaknesses-that-went-unknown-for-years/
Anthropic: Investigating three real-world incidents in our cybersecurity evaluations (also in HN; Simon Willison)
Industry, Adoption & Social Effects
Godot will no longer accept AI-authored code contributions (via HN)
Higher-ups in a company are more likely to think their company has AI maturity (via twitter)
Tencent is in talks to become the largest shareholder of Manus as investors race to unwind Meta’s $2bn acquisition of the AI agent start-up after Beijing ordered that the deal be reversed.
Apple sues OpenAI alleging theft of top-secret information
Meta and Anthropic in talks for up to $10bn data centre deal
https://simonwillison.net/2026/Jul/17/spot-birds-not-golf/
Company AI rebrands usually only produces short price boosts
Advertise in ChatGPT (via HN)
Money Stuff: Tricking the AI Investors: Using similar looking unicode characters for bad news only
Vitalik Buterin:
Programming / Tech
Have your agent record video demos of its work with shot-scraper video
How CedarDB's storage engine handles both analytical and transactional queries
The field guide to grid lanes: Made by the WebKit team, good quick reference guide
Prefer STRICT tables in SQLite (via HN): another one of those insane behaviors in sqlite
-- Non-strict tables let you put anything anywhere.
CREATE TABLE people_nonstrict (age INTEGER);
INSERT INTO people_nonstrict (age) VALUES ('garbage');
-- => works fine
-- Strict tables don't allow that, which I prefer.
CREATE TABLE people_strict (age INTEGER) STRICT;
INSERT INTO people_strict (age) VALUES ('garbage');
-- => error: cannot store TEXT value in INTEGER column
What's new in ECMAScript 2026: Some additions include
Error.isError: wtf? How is there no consistent API for detecting errors beforeIncomplete List of Mistakes in the Design of CSS from the CSS Working Group
Linus Torvalds, Linux Media Mailing List (via https://simonwillison.net/2026/Jul/16/linus-torvalds/)
The
git historycommand (via HN): pretty cool, but please just use a GUI to handle git after learning the basicsFirefox in WebAssembly (via): done in $25k on API pricing, which is pretty cheap
The Tower Keeps Rising (via HN)
Everyone Should Know SIMD (also in HN)
GigaToken: ~1000x faster Language model tokenization (via HN)
sglang_speed [huggingface]: mean=10.31ms median=6.48ms p99=45.98ms rps=96.8
sglang_speed [gigatoken]: mean=10.13ms median=6.54ms p99=45.16ms rps=98.4
input_len= 2048: TTFT mean 30.74 -> 29.05 ms (+5.5% reduction) | median 31.00 -> 28.80 (+7.1%) | p99 33.02 -> 32.02 (+3.0%)
input_len= 8192: TTFT mean 105.20 -> 96.36 ms (+8.4% reduction) | median 103.87 -> 95.49 (+8.1%) | p99 126.88 -> 113.84 (+10.3%)
input_len= 32768: TTFT mean 687.05 -> 633.66 ms (+7.8% reduction) | median 708.14 -> 657.35 (+7.2%) | p99 728.95 -> 678.79 (+6.9%)
The startup's Postgres survival guide (via HN): more postgres tricks and tips
i found a way to represent a non-empty string without branded types and without using

anyScience / Math
The Dark Side of Pascal's Triangle (video): Goes into forward differences, operators, umbral calculus
Compactness explained (video)
Biology
TIL CO2 cognitive impact studies have replication issues: ask your favourite AI to do some additional research, something like "what is the status of CO2 cognitive impact studies now?" should be good
Brain activity under anesthesia challenges what we know about consciousness (via twitter)
The impact of walking on creative thinking: A systematic review and meta-analysis
Claude thinks the meta-analysis itself is above average, but the underlying research less so. The most concerning imo is "many positive RCTs come from one author".
Linkposts
1: You Are Quoting Bentham: Shakespeare gets credit for coining the most new commonly-used English words, but second place must go to utilitarian philosopher Jeremy Bentham, who invented maximize, minimize, international, percentage, monetary, marginalize, collaborator, unaffordable, the prefixes self-, post-, and infra-, and many more.
17: In 2023, I reviewed the evidence for declining sperm counts and concluded it was shaky. Since then, a new meta-analysis has found no evidence of declining sperm concentration (h/t @CremieuxRecueil).
20: @SHL0MS on Twitter sparked a lively debate about why AI art looked so much worse than humans, using AI-generated slop in the style of Monet as his example. Thousands of commenters weighed in to explain why it was inferior to the real Monet - no cohesion, world-modeling mistakes, weird color choices, or just lacking some sort of je ne sais quoi human touch. Since I’m writing about this, you can probably guess the twist: it was a real Monet the whole time. A good time to reread about trapped priors! @jediwolf compiled a summary image of some of the “best” responses
29: David Chalmers surveys philosophers on whether infants are conscious, key result below:
45: Claim: AI is now better at persuading people than expert humans like champion debaters and professional canvassers (paper, tweet thread). This remained true even when “expert humans chose their issues, researched in advance, underwent hours of live, structured practice, and were incentivized with £1,000 cash bonuses” and even after “experts received a coaching tool that let them practice against the AI that beat them, review their performance history, and see what AI would have said at key moments”, and it remained true in a situation with real-world consequences (convincing people to actually donate money to a real charity). However, the AIs regress back to human level when forced to respond “at human speeds and with human-length messages”.
(From the tweet, it seems like number of facts in a persuasion attempt is really significant to humans)
52: New Chinese model Kimi K3 is out and very good, but is unfortunately causing a repeat “Deepseek moment” where everyone panics and says that China has caught up to / surpassed the US. I briefly got caught in the crossfire because I’d written days earlier that China was 6-12 months behind and people were telling me it “hadn’t aged well” (I hate that expression). Now that the dust has cleared, the best analysis suggests that Kimi is, in fact, six months behind the US frontier. See @scaling01’s Have Chinese Models Caught Up To The US Frontier?, which estimates “a backward-looking gap of 6.08 months . . . and a forward looking gap of 11 months” …
54: Elias Schmied: Reframing LessWrong-style decision theory as commitment theory. I’ve always felt that something about the decision theory wars was a fake linguistic question, and this does a better job than I could putting it into words.
(This prompted me to read this post, which I decided to skip a couple weeks ago)
61: Related: I’m always a sucker for sentimental cartography, so here’s a map of the current charitable landscape, h/t Dustin Moskovitz (#3 above). Effective altruism is the tiny islands in the southeast, too small to see at this scale:
2026 Unslop Contest Results
Useful Outsourcing Is Hard: kind of the opposite of what money cannot buy, which is about not being able to verify the result of outsourced work. This is about