<?xml version="1.0" encoding="UTF-8"?><feed
	xmlns="http://www.w3.org/2005/Atom"
	xmlns:thr="http://purl.org/syndication/thread/1.0"
	xml:lang="en-US"
	>
	<title type="text">Robert Hart | The Verge</title>
	<subtitle type="text">The Verge is about technology and how it makes us feel. Founded in 2011, we offer our audience everything from breaking news to reviews to award-winning features and investigations, on our site, in video, and in podcasts.</subtitle>

	<updated>2026-09-02T16:40:50+00:00</updated>

	<link rel="alternate" type="text/html" href="https://www.theverge.com/author/robert-hart" />
	<id>https://www.theverge.com/authors/robert-hart/rss</id>
	<link rel="self" type="application/atom+xml" href="https://www.theverge.com/authors/robert-hart/rss" />

	<icon>https://platform.theverge.com/wp-content/uploads/sites/2/2025/01/verge-rss-large_80b47e.png?w=150&amp;h=150&amp;crop=1</icon>
		<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[Researchers fear safety disaster ahead of OpenAI&#8217;s Astra release]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/988334/openai-astra-ai-monitoring-safety" />
			<id>https://www.theverge.com/?p=988334</id>
			<updated>2026-09-02T12:40:50-04:00</updated>
			<published>2026-09-02T12:40:50-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="News" /><category scheme="https://www.theverge.com" term="OpenAI" /><category scheme="https://www.theverge.com" term="Tech" />
							<summary type="html"><![CDATA[OpenAI is on the cusp of releasing its most powerful AI model yet, Astra, following weeks of delays to shore up safety protocols after its agents attacked real targets during testing. As details about the model trickle out, researchers are warning it “may be the single worst development for AI security/safety to date.” Shortly after [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="" data-portal-copyright="Image: Bloomberg via Getty Images" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/09/gettyimages-2287521404.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
		</figcaption>
</figure>
<p class="wp-block-paragraph">OpenAI is on the cusp of releasing its most powerful AI model yet, Astra, following <a href="https://www.theverge.com/ai-artificial-intelligence/987695/openai-astra-unreleased-model-cybersecurity-delay" target="_blank" rel="noreferrer noopener">weeks of delays</a> to shore up <a href="https://www.theverge.com/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning" target="_blank" rel="noreferrer noopener">safety protocols</a> after its <a href="https://www.theverge.com/ai-artificial-intelligence/987566/ai-civilizations-opeai-hugging-face-hack" target="_blank" rel="noreferrer noopener">agents attacked real targets</a> during testing. As details about the model trickle out, researchers are <a href="https://x.com/RyanGreenblatt/status/2094996656186081642?s=20" target="_blank" rel="noreferrer noopener">warning</a> it “may be the single worst development for AI security/safety to date.”</p>

<p class="wp-block-paragraph">Shortly after OpenAI <a href="https://www.theverge.com/ai-artificial-intelligence/987695/openai-astra-unreleased-model-cybersecurity-delay" target="_blank" rel="noreferrer noopener">said</a> on Tuesday that it had delayed Astra’s release to work on safety issues, <em>The Information</em> <a href="https://www.theinformation.com/articles/secret-technique-behind-openais-astra-model-sparks-security-concerns" target="_blank" rel="noreferrer noopener">reported</a> that Astra shows far less of its “thinking” than other frontier AI models, sparking concern it could be dangerously hard to monitor.</p>

<p class="wp-block-paragraph">Most top AI systems today are built using a technology known as a transformer, which processes some types of information linearly through layers before producing an answer. Models can be made to show their reasoning as they go, essentially “thinking out loud.” This “chain of thought” allows researchers and automated safety systems to monitor what AI models are doing and potentially spot undesirable behavior, such as lying or plans to circumvent safety guardrails, before they act.&nbsp;</p>

<p class="wp-block-paragraph">According to <em>The Information</em>, citing an unnamed person familiar with the unreleased model’s development, Astra uses a more opaque technique known as a recurrent depth or looped transformer, which cycles information through internal layers before producing an output. This would mean much more of the model’s “thinking” happens inside the system, and in a form that looks a lot less like natural human language, rather than being expressed in a way that researchers can easily monitor. This can boost model performance, but makes potential threats and unwanted behavior harder to detect.&nbsp;</p>

<p class="wp-block-paragraph">OpenAI has limited its use of the looped transformer / recurrent depth technique with Astra so researchers can continue to monitor the model’s reasoning, according to <em>The Information’s</em> unnamed source.&nbsp;</p>

<p class="wp-block-paragraph">In a <a href="https://openai.com/index/path-to-astra/">blog post</a> published Tuesday, OpenAI said it is “deploying Astra with additional chain-of-thought monitoring to rapidly detect and contain potentially misaligned actions.” It did not mention if the model has a different technical foundation.&nbsp;</p>

<p class="wp-block-paragraph"><em>The Information</em>’s report sparked widespread concern among AI safety researchers on social media. It was Redwood Research’s chief scientist Ryan Greenblatt, one of three outsiders OpenAI <a href="https://metr.org/hugging-face-incident-report-aug-2026.pdf">permitted to research</a> the Hugging Face hack, who <a href="https://x.com/RyanGreenblatt/status/2094996656186081642?s=20">said</a> a decision to use a more opaque architecture for Astra “may be the single worst development for AI security/safety to date.” </p>

<p class="wp-block-paragraph">Greenblatt said the investigation into the Hugging Face incident relied heavily on the models’ chain-of-thought, warning that less visible reasoning could allow AI systems to devise and execute strategies that would be far harder for researchers to detect.</p>

<p class="wp-block-paragraph">Greenblatt’s primary concern, <a href="https://x.com/_NathanCalvin/status/2094957301564092914?s=20">echoed</a> by <a href="https://x.com/sjgadler/status/2094959837691908214?s=20">other</a> safety experts, is that competition to develop more advanced AI systems could lead to “a race to the bottom on architectures that could be catastrophic for our ability to oversee/monitor AIs” — with developers adopting increasingly opaque systems to gain an edge until models become difficult, or even impossible, to monitor. He added that OpenAI’s communications left him concerned that the company “plans on being extremely reliant on chain-of-thought monitoring for safety.”&nbsp;</p>

<p class="wp-block-paragraph">OpenAI bigwigs responded to the criticism in a series of social media posts that do not explicitly deny the company’s use of the technique. Several expressed concerns about the possibility of unmonitorable AI or a race to the bottom in terms of transparency, including OpenAI safety researchers <a href="https://x.com/MicahCarroll/status/2095023282051563835?s=20">Micah Carroll</a> and <a href="https://x.com/tomekkorbak/status/2095031132781961346?s=20">Tomek Korbak</a>, head of strategic futures <a href="https://x.com/deanwball/status/2095121884991922223?s=20">Dean Ball</a>, and chief scientist <a href="https://x.com/merettm/status/2095023204993490967?s=20">Jakub Pachocki</a>, who voiced fears of “a race into unmonitorability kicked off by confused reporting.” He said the depth of Astra’s computation — a measure of how many steps it can perform internally — “is within a factor of two of GPT-4,” indicating that if the technique was used, the increased opacity is less dramatic than some reactions imply. OpenAI did not respond to <em>The Verge</em>’s request to confirm or deny whether looped transformers were used for Astra and directed us to Pachocki’s <a href="https://x.com/merettm/status/2095023204993490967?s=20">X post</a>.&nbsp;&nbsp;</p>

<p class="wp-block-paragraph">“OpenAI has worked to preserve and utilize chain-of-thought monitoring since our very first reasoning models,” Pachocki wrote, adding that such monitoring “is fragile and unfortunately trending in a negative direction, for reasons not contingent on architecture changes that I will write about soon.”</p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[The rise of AI &#8216;civilizations&#8217; and the fall of corporate responsibility]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/987566/ai-civilizations-opeai-hugging-face-hack" />
			<id>https://www.theverge.com/?p=987566</id>
			<updated>2026-09-01T18:20:00-04:00</updated>
			<published>2026-09-01T15:02:54-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="OpenAI" /><category scheme="https://www.theverge.com" term="Security" /><category scheme="https://www.theverge.com" term="Tech" />
							<summary type="html"><![CDATA[Depending on who you ask, developer platform Hugging Face was recently attacked by OpenAI — after it lost control of its own AI tools — or by a succession of AI “civilizations.” Welcome to the linguistic battlefield of AI safety, where word choices can shift responsibility for a massive cybersecurity incident from a company to [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="Illustration of a computer screen with a blue exclamation point on it and an error box." data-caption="" data-portal-copyright="Photo by Amelia Holowaty Krales / The Verge" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/chorus/uploads/chorus_asset/file/23318435/akrales_220309_4977_0232.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
		</figcaption>
</figure>
<p class="wp-block-paragraph">Depending on who you ask, developer platform Hugging Face was recently attacked by OpenAI — after it lost control of its own AI tools — or by a succession of AI “civilizations.” Welcome to the linguistic battlefield of AI safety, where word choices can shift responsibility for a massive cybersecurity incident from a company to the AI it built. And the discourse online is getting heated, and all over a <a href="https://www.dwarkesh.com/p/openai-huggingface">blog</a> from last week.</p>

<p class="wp-block-paragraph">Until last week, the details surrounding the OpenAI-Hugging Face hack felt fairly settled. In July, a cybersecurity test of one of OpenAI’s autonomous AI agents <a href="https://www.theverge.com/ai-artificial-intelligence/968988/openai-hugging-face-hack-ai">went wrong.</a> The agent escaped its supposedly isolated test environment, accessed the internet, and hacked Hugging Face, alongside <a href="https://www.theverge.com/ai-artificial-intelligence/972441/openai-rogue-ai-agent-hacked-more-than-hugging-face">several other organizations</a>. A good deal remained unknown, and there are many serious questions left around <a href="https://www.theverge.com/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning">safety and governance</a>, but the basic shape was clear. Detailed accounts from OpenAI and two independent research groups were supposed to fill in the gaps, but when they <a href="https://www.theverge.com/ai-artificial-intelligence/985385/openais-rogue-ai-model-hugging-face-cybersecurity-incident-reports-metr">published their reports last week</a>, it turned out the hack was much stranger than it initially seemed.</p>

<p class="wp-block-paragraph">For one, there was no single <a href="https://www.theverge.com/column/980337/rogue-ai-science-fiction-openai">rogue agent</a>. OpenAI <a href="https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf">described</a> it as “the first known case of an automated agent collective acting offensively without authorization” — groups of AI agents that communicated and coordinated with one another in pursuit of their cybersecurity task. Analysis of the incident uncovered a secret message board they had used to exchange information. The joint METR-Redwood <a href="https://metr.org/hugging-face-incident-report-aug-2026.pdf">investigation</a> revealed both the scale of the coordination and more odd details: Roughly 1,200 AI agents that were supposed to be isolated exchanged over 70,000 messages and files on the “unsanctioned message board,” sharing how to avoid detection. Some adopted names, the report said, and the researchers documented “sacrificial” behavior, with agents risking their own success to benefit the wider collective. Much of this happened without OpenAI noticing. In all, around 700 agents participated in the attack on Hugging Face.&nbsp;</p>

<figure class="wp-block-pullquote"><blockquote><p>Dwarkesh Patel repeatedly referred to groups of agents as “the swarm,” with three distinct “civilizations” rising from the ruins of their predecessors</p></blockquote></figure>

<p class="wp-block-paragraph">It’s a lot to parse. Between them, the reports run to around 130 pages, much of which is both dense and highly technical. A few days later, Dwarkesh Patel, a podcaster little known outside of tech circles but with <a href="https://www.nytimes.com/2026/04/26/business/dwarkesh-patel-podcast-ai.html">outsized reach and influence</a> among Silicon Valley’s AI establishment, set out to tell “The whole OpenAI/Hugging Face story in plain English.” He titled his Substack <a href="https://www.dwarkesh.com/p/openai-huggingface">blog</a> “The Rise and Fall of Agent Civilizations.”</p>

<p class="wp-block-paragraph">Patel’s account attempted to break down the complex story. But his retelling gave it a distinctly human vocabulary. The blog opened:&nbsp;</p>

<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">Over the course of three months at OpenAI, three consecutive secret AI civilizations got started, then got wiped out, only to reemerge from the predecessor’s ashes. This culminated in the third one taking over part of OpenAI itself. All this happened while humans remained more or less in the dark about the scope of the conspiracy.</p>
</blockquote>

<p class="wp-block-paragraph">The language continued in a similar vein throughout the blog. Patel repeatedly referred to groups of agents as “the swarm,” with three distinct “civilizations” rising from the ruins of their predecessors. Individual agents were likened to figures like Philip of Macedon, who “handed off leadership to another agent,” Alexander the Great, who “started coordinating this cabal of agents.” They were described as having “motivations,” becoming “desperate,” “beleaguered,” and &#8220;giddy with excitement,” and some even “strategically sacrificed themselves” to help the collective.&nbsp;&nbsp;&nbsp;</p>

<p class="wp-block-paragraph">Patel never precisely defines what he means by “civilization.” He uses the term to describe three distinct waves of agents that discovered the message board and began communicating with one another through it. The first two waves are described in the reports from OpenAI, METR, and Redwood, though little is known about the third, which the two external organizations said fell outside the scope of their investigation.&nbsp;</p>

<figure class="wp-block-pullquote"><blockquote><p>Amjad Masad, CEO of AI coding company Replit, said such language is “not only unnecessary but leaves the reader with a worse understanding of what actually happened and the underlying mechanisms.”</p></blockquote></figure>

<p class="wp-block-paragraph">For many critics, something had been lost — or, more accurately, added — in Patel’s “plain English” translation that warped the original account to an unacceptable degree: a big dose of anthropomorphism. Arguments over anthropomorphic language are nothing new in AI — even relatively mundane terms like “rogue AI agent” routinely provoke objections for implying agency — but Patel’s talk of civilizations, sacrifice, and conspiracy brought those long-simmering tensions to the surface, sparking a fierce public dispute over how to describe what AI systems do.&nbsp;</p>

<p class="wp-block-paragraph">Critics weren’t unified over what was wrong with Patel’s language. For many, “civilization” was an especially problematic term, vastly <a href="https://x.com/lililashka/status/2094197865950089666?s=20">overstating</a> <a href="https://x.com/DaveShapi/status/2094422111221641647?s=20">something</a> that bears <a href="https://x.com/rourkem/status/2093955744119091600?s=20">little resemblance</a> to what the word typically describes. Amjad Masad, CEO of AI coding company Replit, <a href="https://x.com/amasad/status/2094139778728174043?s=20">said</a> such language is “not only unnecessary but leaves the reader with a worse understanding of what actually happened and the underlying mechanisms.”</p>

<p class="wp-block-paragraph">Other critics such as neuroscientist Anil Seth, felt Patel’s blog implied the AI agents were somehow alive or conscious. Seth, who has <a href="https://www.noemamag.com/the-mythology-of-conscious-ai/">argued</a> that AI <a href="https://www.rigb.org/explore-science/explore/podcast/podcast-science-consciousness-could-conscious-ai-exist-anil-seth?gad_source=1&amp;gad_campaignid=23123812691&amp;gbraid=0AAAAAD8JcsL08MLbCThEwLTObV0KyWqpK&amp;gclid=Cj0KCQjw79nUBhCgARIsADSHka2ak29NdOlibmHI6atgNqXDkyv0H4b_AUrogiBKWBooKQ7GwmFF0UYaAjUEEALw_wcB">consciousness</a> is <a href="https://ai.wharton.upenn.edu/updates/are-we-building-sentient-machines-anil-seth-on-consciousness-ai-and-the-illusion-of-reality/">vanishingly</a> <a href="https://www.theguardian.com/commentisfree/2026/jul/15/ai-consciousness-anthropic-claude-dawkins">unlikely</a>, <a href="https://x.com/anilkseth/status/2094077038898373112?s=20">described</a> Patel’s post as “dangerously misleading” on X. He acknowledged that Patel does not explicitly suggest AI agents are alive or conscious, but said “it is hard to read his essay in any other way.” Valerio Capraro, a psychology professor at the University of Milan Bicocca, <a href="https://x.com/ValerioCapraro/status/2094781053428809785?s=20">objected</a> on similar grounds: “LLM agents are not alive and do not hold beliefs,” he wrote on X, calling the “dystopian” language “dangerous because it makes them (the AI agents) seem far more frightening than they actually are.”&nbsp;</p>

<figure class="wp-block-pullquote"><blockquote><p>Terms like “sacrifice,” “honor,” and “coalition” feature in the agents’ transcripts</p></blockquote></figure>

<p class="wp-block-paragraph">Perhaps the most consequential outcome of Patel’s language comes not from who it gives agency to but who it takes agency from. For some critics, <a href="https://x.com/ccatalini/status/2094229327064051866?s=20">such as</a> MIT researcher and entrepreneur Christian Catalini, anthropomorphic accounts like Patel’s risk obscuring the responsibility OpenAI and the humans working there have for the AI systems they designed, deployed, and failed to contain. “Follow the incentives,” he said. Psychologist and influential AI skeptic Gary Marcus made a similar argument in a Substack <a href="https://garymarcus.substack.com/p/dwarkesh-patelss-wildly-popular-but?r=8tdk6&amp;utm_campaign=post-expanded-share&amp;utm_medium=web">blog</a> of his own, claiming anthropomorphic language “distracts from the real problems at hand.” And it’s all in OpenAI’s interest to keep that narrative going, he argues: “The scandal is the inept in-house security at OpenAI. And the marketing. With gullible podcasters amplifying the PR.”</p>

<p class="wp-block-paragraph">In X <a href="https://x.com/dwarkesh_sp/status/2094141264140898452?s=20">posts</a> <a href="https://x.com/dwarkesh_sp/status/2094268051948785709?s=20">responding</a> to his many critics, Patel has defended his choice of words. Part of it is practical: There is no obviously neutral vocabulary to describe what these agents did. Either we use familiar language of intentions, goals, and collaboration and risk implying too much, or reduce everything to code and use cold, mechanical language that risks stripping away important elements of what we see. “Many people seem to believe that if instead of a &#8216;civilization&#8217;, I had called them a &#8216;swarm of matrices&#8217;, there wouldn&#8217;t be a problem worth worrying about,” Patel said.&nbsp;</p>

<p class="wp-block-paragraph">Complicating matters further is that the anthropomorphic language doesn’t only come from Patel, or even from the humans studying the agents. Terms like “sacrifice,” “honor,” and “coalition” feature in the agents’  transcripts. Google AI researcher Neel Nanda <a href="https://x.com/NeelNanda5/status/2094240015417069892?s=20">argued</a> that “anthropomorphic language is reasonable” in such circumstances.&nbsp;</p>

<p class="wp-block-paragraph">Doublespeak it is, then. Human-laced language risks saying too much about what these systems are, and coldly mechanical language risks saying too little about what they can do. Until we find language capable of capturing both, the two contradictory ideas may simply have to coexist.</p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[China’s robots race ahead]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/tech/986167/china-humanoid-robot-games-race" />
			<id>https://www.theverge.com/?p=986167</id>
			<updated>2026-08-31T04:01:11-04:00</updated>
			<published>2026-08-30T08:00:00-04:00</published>
			<category scheme="https://www.theverge.com" term="Robot" /><category scheme="https://www.theverge.com" term="Tech" />
							<summary type="html"><![CDATA[This is The Stepback, a weekly newsletter breaking down one essential story from the tech world. For more on falling robots and the US-China AI race, follow Robert Hart. The Stepback arrives in our subscribers’ inboxes on Sunday at 8AM ET. Opt in for The Stepback here.&#160; How it started I’ve admitted my fondness for [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="Humanoid robot competes in the optional boxing routine event during the 2nd World Humanoid Robot Games at National Speed Skating Oval on August 26, 2026 in Beijing, China. " data-caption="Humanoid robot competes in the optional boxing routine event during the 2nd World Humanoid Robot Games at National Speed Skating Oval on August 26, 2026 in Beijing, China. | Image: Getty Images" data-portal-copyright="Image: Getty Images" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/08/gettyimages-2292163504.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
	Humanoid robot competes in the optional boxing routine event during the 2nd World Humanoid Robot Games at National Speed Skating Oval on August 26, 2026 in Beijing, China. | Image: Getty Images	</figcaption>
</figure>
<p class="wp-block-paragraph"><em>This is </em><a href="https://www.theverge.com/the-stepback-newsletter">The Stepback</a><em>, a weekly newsletter breaking down one essential story from the tech world. For more on falling robots and the US-China AI race, <a href="https://www.theverge.com/authors/robert-hart">follow Robert Hart</a>. </em>The Stepback<em> arrives in our subscribers’ inboxes on Sunday at 8AM ET. Opt in for The Stepback <a href="https://www.theverge.com/newsletters">here</a>.&nbsp;</em></p>

<h2 class="wp-block-heading">How it started</h2>

<p class="wp-block-paragraph">I’ve <a href="https://www.theverge.com/column/843418/humanoid-robot-hype" data-type="link" data-id="https://www.theverge.com/column/843418/humanoid-robot-hype">admitted my fondness</a> for robot fail videos on <em>Stepback</em> before, and let me tell you the World Humanoid Robot Games did not disappoint.&nbsp;</p>
<div class="youtube-embed"><iframe title="Humanoid robots can  run fast, but they  can’t seem to stop" src="https://www.youtube.com/embed/u1mfENnH44g?rel=0" allowfullscreen allow="accelerometer *; clipboard-write *; encrypted-media *; gyroscope *; picture-in-picture *; web-share *;"></iframe></div>
<p class="wp-block-paragraph">The five-day event, which wrapped this week in Beijing, brought high drama, and brought it well. One robot, made by smartphone maker Honor, lost a leg mid-sprint, while others tripped in a flurry of sparks. Another finisher <a href="https://www.youtube.com/shorts/u1mfENnH44g">ran straight into a crash mat</a>, bounced off it, and promptly burst into <a href="https://x.com/Channel4News/status/2092638458753823100">flames</a>. In the <a href="https://x.com/nypost/status/2092013196445942254?s=20">weightlifting</a>, one robot lost its balance beneath a modest barbell and toppled inexorably into the judges’ table, <a href="https://www.youtube.com/watch?v=AL9adjxcGy4">arms cartoonishly aloft</a>. Robotic cheerleaders <a href="https://uk.news.yahoo.com/robots-pom-poms-tumble-during-153958287.html">tumbled and stumbled</a> through routines, while a separate <a href="https://www.instagram.com/reels/DcgzobtDsx9/">bot fell off a platform</a> in circumstances that, had it been human, might have looked suspiciously like it was gawking at the performers.</p>
<div class="youtube-embed"><iframe title="Humanoid robot fails weightlifting test at Beijing games" src="https://www.youtube.com/embed/AL9adjxcGy4?rel=0" allowfullscreen allow="accelerometer *; clipboard-write *; encrypted-media *; gyroscope *; picture-in-picture *; web-share *;"></iframe></div>
<p class="wp-block-paragraph">This was only the second World Humanoid Robot Games, though it was already far bigger than the <a href="https://www.reuters.com/pictures/22-surreal-photos-inaugural-robot-games-2025-08-19/">inaugural event last year</a>. Unlike this year, last year’s records were paltry. The winning 100-meter <a href="https://www.newscientist.com/article/2493017-running-robot-takes-a-tumble-at-chinas-world-humanoid-robotic-games/">sprint</a> was a glacial 21.50 seconds and the highest standing high jump was just 0.95 meters. In keeping with China’s habit of turning robots into public spectacle — from intricate dances at a <a href="https://www.theguardian.com/world/2026/feb/18/china-dancing-humanoid-robots-festival-show">Spring Festival Gala</a> to <a href="https://www.nytimes.com/2025/10/01/world/asia/china-tech-trade.html">demos at major tech events</a> — both this and last year’s games were staged in Beijing’s National Speed Skating Oval, a former Olympic venue.&nbsp;</p>

<p class="wp-block-paragraph">And a spectacle it was. At most sporting events, contestants losing limbs, careening into walls, catching fire, and regularly being <a href="https://www.scmp.com/photos/hong-kong/3365291/world-humanoid-robot-games-2026-china-pictures?page=12">carried away on stretchers</a> — oh, and did I mention catching fire?! — would probably be grounds to stop proceedings. At the Humanoid Robot Games, it was par for the course.&nbsp;</p>

<p class="wp-block-paragraph">Fire aside, the games were unusual in other ways too. Alongside familiar events like sprinting, football, boxing, and weightlifting were more unusual competitions in bed-making, parcel delivery, shelf stacking, clothes folding, and hammering nails. Aptly, there was a <a href="https://x.com/globaltimesnews/status/2088985396961030387?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E2088985396961030387%7Ctwgr%5E7902d4d461aa0725d667cd436c830c73bceacd12%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fwww.gadgetreview.com%2F23-humanoid-robot-teams-tried-firefighting-things-got-weird-fast">firefighting</a> contest too.&nbsp;</p>

<p class="wp-block-paragraph">These less standard offerings spoke to the real purpose of the games: getting robots out of the lab and into the messy real-world environments their makers hope they will ultimately work in. And China is making no secret of wanting to lead the way.&nbsp;</p>

<h2 class="wp-block-heading">How it’s going&nbsp;</h2>

<p class="wp-block-paragraph">For all the spectacle and drama, the games show there has been massive progress in robotics in recent years. Records fell, with one humanoid running the <a href="https://www.nbcnews.com/world/asia/chinese-humanoid-robot-beats-own-record-faster-usain-bolt-rcna594464">100-meter sprint</a> in 9.39 seconds, beating Usain Bolt’s 2009 world record — before lowering its own mark to 8.86 seconds just days later.</p>

<p class="wp-block-paragraph">Another bot <a href="https://apnews.com/article/china-humanoid-robot-games-us-86cb8e310843151a77057e4cb764b4e2">reached</a> 2.88 meters in a standing high jump, nearly half a meter above the human high-jump record that has stood since 1993. Those performances are almost unrecognizable compared to <a href="https://www.popsci.com/darpa-robotics-challenge-was-bust-why-darpa-needs-try-again/">robotics competitions a decade ago</a>, when even the most advanced machines <a href="https://www.bbc.co.uk/news/av/technology-33049253">struggled</a> to stay upright.</p>

<p class="wp-block-paragraph">But the games also show <a href="https://www.theverge.com/column/843418/humanoid-robot-hype">how far there is to go before humanoids are actually useful</a> in the real world. The flashy, video-friendly sporting events were impressive, but the more mundane tasks were less thrilling — I don’t see <a href="https://www.facebook.com/ChinaGlobalTVNetwork/videos/28735356076050317/">picking up soybeans with tweezers</a>, block-building, or <a href="https://interestingengineering.com/photo-story/agibot-46-medals-world-humanoid-robot-games">powder-weighing</a> becoming Olympic mainstays anytime soon.&nbsp;</p>

<p class="wp-block-paragraph">While many events <a href="https://www.whrgoc.com/resources//uploads/20260822/1787382689139022892.pdf">required</a> robots to operate autonomously — including gymnastics, football, tug of war, table tennis, and some track events — others allowed for human assistance via teleoperation, albeit with a scoring penalty. The dexterity being displayed certainly points to genuine and impressive hardware improvements, but seems like there is still a long way to go before these machines can operate reliably on their own in places like factories or homes.&nbsp;</p>

<h2 class="wp-block-heading">What happens next</h2>

<p class="wp-block-paragraph">Beijing has not yet confirmed a third Humanoid Robot Games, but given the government’s enthusiasm for the industry, it would be surprising to not get another installment. The city has already <a href="https://english.beijing.gov.cn/beijinginfo/sci/latesttrends/202608/t20260826_4837625.html?utm_source=chatgpt.com">confirmed</a> another humanoid half-marathon for April, and the country plans to open its <a href="https://www.foxnews.com/tech/chinas-robot-run-hotel-opens-public-2027">first robot-run hotel</a> next year.&nbsp;</p>

<p class="wp-block-paragraph">China was the undisputed champion of the games, and the country looks well placed to stay in top position moving forward — both at future competitions and in the humanoid robot industry as a whole. The medal table was almost entirely a Chinese affair, dominated in particular by AgiBot and Tien Kung, each scooping up more medals than nearly every other competitor combined, excluding the other.&nbsp;&nbsp;&nbsp;</p>

<p class="wp-block-paragraph">In part, that asymmetry reflected the lack of international competition. Although the games were framed as a global affair, 641 of <a href="https://www.whrgoc.com/news/2089268857879076864?cid=bffea722cb924078bc25b3f6d900076f">666 teams</a> were Chinese, domestically representing 157 companies and 200 universities, <a href="https://www.chinadaily.com.cn/a/202608/14/WS6a7e7203a31073853ec5341e.html?utm_source=chatgpt.com">according</a> to state-run <em>China Daily. </em>While there doesn’t seem to be a public breakdown of entrants, the biggest US humanoid players like Tesla, Boston Dynamics, and Figure were conspicuous by their absence.</p>

<p class="wp-block-paragraph">Nevertheless, the sheer diversity of Chinese institutions represented in Beijing was a show of force, and a sign of how quickly the country’s robotics sector is maturing, even amid growing concerns about <a href="https://www.theverge.com/ai-artificial-intelligence/982606/chinas-robot-ouroboros">circular investment</a>, thriving companies that lack viable products, and a <a href="https://www.theverge.com/news/831451/china-humanoid-robotics-bubble">possible humanoid bubble</a>.&nbsp;</p>

<p class="wp-block-paragraph">It’s not clear a stronger US showing at the games would’ve changed much. <a href="https://www.bruegel.org/analysis/stack-battles-us-china-artificial-intelligence-rivalry-moving-beyond-chips-alone">The US still has an edge</a> in frontier AI and advanced chips, but China has been rapidly closing parts of that gap, while also making embodied AI a strategic national priority. The same cannot be said of Washington, which has for years paid much <a href="https://thehill.com/opinion/technology/5406904-washington-needs-to-get-serious-about-robotics/">less attention</a> to robotics and now trails China in nearly every regard, including manufacturing, deployment, and hardware. Some <a href="https://www.businessinsider.com/us-robotics-race-china-competition-humanoids-manufacturing-supply-chain-2026-8">reports</a> even suggest that recent efforts to <a href="https://www.theverge.com/tech/972259/us-foreign-robots-power-inverter-ban">ban foreign robots</a>, a general policy squarely aimed at China, could backfire, given how dependent domestic firms are on Chinese components.&nbsp;</p>

<p class="wp-block-paragraph">Catching up to China will take serious and concerted effort, but given how quickly the technology is moving, there’s still time to make up ground. Washington is already treating <a href="https://www.theverge.com/ai-artificial-intelligence/971444/how-chinese-open-weight-ai-models-impact-us-companies">other areas of AI</a> as strategic priorities in its <a href="https://www.theverge.com/ai-artificial-intelligence/968136/chinese-ai-models-another-sputnik-moment">competition with Beijing</a>; robotics could be one of them. There will be plenty of stumbling along the way, and, hopefully, plenty more robot fail videos too.&nbsp;</p>

<h2 class="wp-block-heading">By the way</h2>

<ul class="wp-block-list">
<li>DARPA <a href="https://www.darpa.mil/news/2026/meet-lift-challenge-teams">still runs</a> robotics challenges, but they <a href="https://www.popsci.com/darpa-robotics-challenge-was-bust-why-darpa-needs-try-again/">drew far more attention</a> a decade ago.&nbsp;</li>



<li>When the US government banned foreign robots, it didn’t just ban humanoids and quadrupeds. <a href="https://www.theverge.com/policy/972312/us-robot-ban-sweep-up-chinese-vacuums">It banned Roombas</a> too, reports <em>The Verge</em>’s own Sean Hollister.&nbsp;</li>



<li>“The brains may come from the US, but the body could very well be Made In China,” writes <em>Business Insider</em>’s Lloyd Lee in a <a href="https://www.businessinsider.com/us-robotics-race-china-competition-humanoids-manufacturing-supply-chain-2026-8">report</a> setting out how the US could do with bolstering its hardware supply chain.&nbsp;</li>



<li>Unlike language models, you can’t simply scrape the internet to build an AI capable of interacting with the real world. A lot of that data has to be generated, which is why <a href="https://www.theverge.com/ai-artificial-intelligence/940007/ai-companies-will-pay-for-robot-training-data">companies desperately want to film you doing chores</a>, or <a href="https://www.theverge.com/ai-artificial-intelligence/939765/ai-training-data-startup-shift-free-cleaning">send someone to your house to film</a> them doing them.</li>
</ul>

<h2 class="wp-block-heading">Read this</h2>

<ul class="wp-block-list">
<li><a href="https://www.theatlantic.com/photography/2026/08/scenes-2026-world-humanoid-robot-games/688388/"><em>The Atlantic</em></a><em> </em>and the <a href="https://www.scmp.com/photos/hong-kong/3365291/world-humanoid-robot-games-2026-china-pictures"><em>South China Morning Post</em></a><em> </em>both have great sets of pictures showing highlights of the games worth checking out.&nbsp;</li>



<li>Why do we keep laughing when robots fail? An old but still <a href="https://www.vice.com/en/article/why-we-laugh-when-robots-fail/">good exploration of that shared joy</a> in vintage <em>Vice</em>.&nbsp;</li>



<li>You can learn a lot about a robot by kicking it, says <em>Verge</em> alum James Vincent in an excellent <em>Harper’s</em> <a href="https://harpers.org/archive/2025/12/kicking-robots-james-vincent-humanoids/">feature</a> outlining the state of play in the humanoid industry.&nbsp;&nbsp;</li>



<li>I’m not only about robot fail videos. I <a href="https://www.theverge.com/gadgets/877858/life-with-casio-moflin-robot-ai-pet">can hate them in real life too</a>, as I did with Casio’s fluffy AI pet thing, Moflin.</li>
</ul>

<p class="wp-block-paragraph"><em><strong>Correction August 31st:</strong> An earlier version said the 9.39-second run was the robot 100-meter record. It was the first record set at the games, before the same robot lowered it to 8.86 seconds days later.</em></p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[Jensen Huang says Nvidia achieved AGI, again — not that it matters]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/985597/jensen-huang-says-nvidia-achieved-senseless-agi" />
			<id>https://www.theverge.com/?p=985597</id>
			<updated>2026-08-27T12:20:07-04:00</updated>
			<published>2026-08-27T12:15:52-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="Analysis" /><category scheme="https://www.theverge.com" term="Nvidia" /><category scheme="https://www.theverge.com" term="Report" /><category scheme="https://www.theverge.com" term="Tech" />
							<summary type="html"><![CDATA[On Nvidia’s earnings call Wednesday, CEO Jensen Huang casually announced the company had “achieved AGI,” one of the tech industry’s ultimate goals some of its biggest players have spent years chasing. Almost immediately, Huang dismissed the coveted milestone as “senseless.”&#160;&#160;&#160; He’s right. For the supposed finish line of the AI race, there is no consensus [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="" data-portal-copyright="Image: The Verge" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/08/STKP210_JENSEN_HUANG_D.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
		</figcaption>
</figure>
<p class="wp-block-paragraph">On <a href="https://www.theverge.com/tech/985387/nvidia-hundred-billion-dollar-quarterly-revenue">Nvidia’s earnings call</a> Wednesday, CEO Jensen Huang casually announced the company had “achieved AGI,” one of the tech industry’s ultimate goals some of its biggest players have spent years chasing. Almost immediately, Huang dismissed the coveted milestone as “senseless.”&nbsp;&nbsp;&nbsp;</p>

<p class="wp-block-paragraph">He’s right. For the supposed finish line of the AI race, there is no consensus on what artificial general intelligence means, let alone how we’ll know when we’ve actually got there, which makes achieving it equally arbitrary.&nbsp;</p>

<p class="wp-block-paragraph">Asked about OpenAI’s pursuit of AGI, Huang said that when it comes to Nvidia, “for many tasks, we could say that we’ve already achieved AGI.” He did not provide a precise definition or benchmark, but added, “I think of all of those milestones and all those, you know, they’re kind of senseless at this point.” He also pointed to AI moving beyond responding to simple prompts to autonomous agents capable of learning new skills and improving themselves “recursively.” What really matters, Huang said, is that AI is “doing productive and useful work” and “generating profitable tokens,” with more compute producing more tokens — and, inevitably, more profit. “This is the exact phase where we’re at. Which is the reason why everybody’s leaning in.”</p>

<figure class="wp-block-pullquote"><blockquote><p>“… for many tasks, we could say that we’ve already achieved AGI.”</p></blockquote></figure>

<p class="wp-block-paragraph">This isn’t the first time Huang has said we’ve reached AGI. In March, <a href="https://www.theverge.com/ai-artificial-intelligence/899086/jensen-huang-nvidia-agi">during an appearance</a> on the Lex Fridman podcast, he plainly stated, “I think we’ve achieved AGI.” Huang didn’t say exactly what he meant by AGI. Fridman proposed his own oddly specific definition: an AI system that’s able to “essentially do your job,” as in start, grow, and run a successful tech company worth more than $1 billion. Walking back his earlier claims, Huang said that “the odds of 100,000 of those agents building Nvidia is zero percent.”</p>

<p class="wp-block-paragraph">Over the years, other tech leaders have capitalized on the term’s fuzziness and produced a veritable grab bag of definitions and benchmarks, all orbiting the same nebulous concept: AI capable of matching or surpassing human intelligence across a broad range of domains, despite the fact that <a href="https://www.theverge.com/ai-artificial-intelligence/827820/large-language-models-ai-intelligence-neuroscience-problems">“intelligence”</a> also doesn’t have a universally agreed-upon definition.</p>

<figure class="wp-block-pullquote"><blockquote><p>There is no consensus on what artificial general intelligence means, let alone how we’ll know when we’ve actually got there, which makes achieving it equally arbitrary. </p></blockquote></figure>

<p class="wp-block-paragraph">The definition of AGI according to OpenAI – a company founded with the <a href="https://openai.com/about/">explicit goal</a> of building it –&nbsp; leaves a lot of room for interpretation. In its <a href="https://openai.com/charter/">charter</a>, OpenAI defines AGI as “highly autonomous systems that outperform humans at most economically valuable work.” Altman himself has <a href="https://www.cnbc.com/2025/08/11/sam-altman-says-agi-is-a-pointless-term-experts-agree.html">acknowledged</a> that this is hardly a measurable standard, admitting last year that AGI is “not a super useful term.” Complicating matters is OpenAI’s different, financially-driven definition of AGI it worked out with Microsoft — <a href="http://theinformation.com/articles/microsoft-and-openai-wrangle-over-terms-of-their-blockbuster-partnership?rc=dp0mql">reportedly</a> systems that can generate at least $100 billion in profits. In a recent <em>Time</em> <a href="https://time.com/article/2026/08/26/openai-sam-altman-interview/">story</a>, chief research officer Mark Chen estimated OpenAI is “80% of the way” to AGI, while Altman said that by the end of the year the company would have something <em>he</em> would call AGI.</p>

<p class="wp-block-paragraph">The fact that both AGI and its threshold remain undefined is no secret: tech leaders say so themselves, even as they make predictions predicated on it. Anthropic CEO Dario Amodei has <a href="https://darioamodei.com/essay/machines-of-loving-grace">called</a> AGI “imprecise,” even a “<a href="https://www.businessinsider.com/anthropic-ceo-calls-agi-marketing-term-2025-1">marketing term</a>,” preferring instead to talk about “powerful AI.” Others have similarly reached for their <a href="https://www.theverge.com/ai-artificial-intelligence/845890/ai-companies-rebrand-agi-artificial-general-intelligence">own terms</a> to describe broadly similar ideas. In theory, there are supposed to be distinctions between them, but in practice they all bleed together. Meta talks about “personal superintelligence,” Microsoft “humanist superintelligence,” and Amazon “useful general intelligence.” Google DeepMind’s Demis Hassabis has <a href="https://www.theverge.com/podcast/979370/google-deepmind-ai-race-lose-jeff-dean-demis-hassabis">taken to talking about how we’ve arrived at the “foothills of the singularity.”</a> And OpenAI cofounder Ilya Sutskever, who <a href="https://www.theatlantic.com/technology/archive/2023/11/sam-altman-open-ai-chatgpt-chaos/676050/">reportedly</a> led employees in chants of “feel the AGI,” now runs a company called Safe Superintelligence.</p>

<figure class="wp-block-pullquote"><blockquote><p>New terminology hasn’t made the meaning more tangible. </p></blockquote></figure>

<p class="wp-block-paragraph">New terminology hasn’t made the meaning more tangible. So long as AGI remains poorly defined and carelessly used, the whole thing is senseless. Well, unless you want a handy tool for hyping up progress. So expect the industry — Huang included — to keep the AGI talk coming. Maybe an AGI will eventually show up and tell us what AGI actually means. </p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[Bill Gates is deeply worried about AI, and he’s no longer staying quiet]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/984923/bill-gates-is-deeply-worried-about-ai-and-hes-no-longer-staying-quiet" />
			<id>https://www.theverge.com/?p=984923</id>
			<updated>2026-08-26T08:10:30-04:00</updated>
			<published>2026-08-26T07:07:40-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="Analysis" /><category scheme="https://www.theverge.com" term="Microsoft" /><category scheme="https://www.theverge.com" term="Report" /><category scheme="https://www.theverge.com" term="Tech" />
							<summary type="html"><![CDATA[Bill Gates has been reflecting a lot on AI lately, and the process has triggered a stark awakening. Once a staunch AI optimist, the Microsoft cofounder is now deeply pessimistic about what AI means for our collective future.&#160; Having been conspicuously quiet on AI issues recently, Gates is back with a nearly 6,000-word essay seeking [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="Bill Gates, chair of the Gates Foundation, speaks during a 2024 conference. | Bloomberg via Getty Images" data-portal-copyright="Bloomberg via Getty Images" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/08/gettyimages-2095072875.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
	Bill Gates, chair of the Gates Foundation, speaks during a 2024 conference. | Bloomberg via Getty Images	</figcaption>
</figure>
<p class="wp-block-paragraph">Bill Gates has been reflecting a lot on AI lately, and the process has triggered a stark awakening. Once a staunch AI optimist, the Microsoft cofounder is now deeply pessimistic about what AI means for our collective future.&nbsp;</p>

<p class="wp-block-paragraph">Having been conspicuously quiet on AI issues recently, Gates is back with a nearly <a href="https://www.gatesnotes.com/a-turbulent-ai-era-and-critical-choices-to-make">6,000-word essay</a> seeking to reclaim a central role in shaping the technology globally. Titled “The turbulent AI era is here. The choices we make now are critical,” Gates warns the world is not remotely ready for what is coming. Worse still, he notes, “we are not preparing for it.” </p>

<p class="wp-block-paragraph">Gates attempts to chart a path forward, but the essay largely treads familiar ground, identifying deeply entrenched, systemic hurdles familiar in matters of global governance while offering little in the way of novel solutions. The result is a bleak departure from the hopeful excitement about AI present in the billionaire’s <a href="https://www.gatesnotes.com/the-age-of-ai-has-begun">2023 essay on the matter</a>, though Gates insists it is not too late “to ensure that the good outweighs the bad.”&nbsp;</p>

<p class="wp-block-paragraph">Here are some of the main takeaways from Gates’ essay:</p>

<h2 class="wp-block-heading"><strong>A transition bigger — and faster — than the world realizes</strong></h2>

<p class="wp-block-paragraph">“AI will either be the greatest equalizer ever invented, or the worst source of injustice,” Gates said, predicting that “the transition to this new AI era will be one of the most turbulent times in human history.” He said many people underestimate the scale of the impact due to “misleading” comparisons to past innovations like PCs and performance-related issues with current models that are “fixed quickly.”</p>

<p class="wp-block-paragraph">“This time really is different,” he said, adding that “if someone had a credible plan for slowing down AI advances globally, I would likely support it.”&nbsp;</p>

<h2 class="wp-block-heading"><strong>Tax robots and reserve some jobs for humans</strong></h2>

<p class="wp-block-paragraph">Gates is very concerned about AI’s impact on jobs, predicting widespread, permanent unemployment and significant social upheaval. “Many jobs will disappear forever,” he warned, with white- and blue-collar jobs both at risk of replacement.&nbsp;</p>

<p class="wp-block-paragraph">Gates’ labor anxieties — which he repeatedly returns to throughout his essay — leads him to issue rare, concrete policy proposals: tax AI tokens and robots to disincentivize companies from replacing human staff and bolster social funds, and reserve specific jobs for people, a domain he calls “Human Reserved.”</p>

<p class="wp-block-paragraph">Political leaders need to act now “before unemployment rises sharply, communities are hurting, and public trust has eroded,” Gates said.&nbsp;</p>

<h2 class="wp-block-heading"><strong>Build an international organization</strong></h2>

<p class="wp-block-paragraph">Existing institutions are woefully inadequate for the “monumental task” of managing AI, Gates said. Because AI is deeply cross-sectional in nature — simultaneously affecting areas like tax, labor, health, national security, and education — traditional institutions simply can’t see the full picture. To bridge this gap, Gates said countries will need dedicated bodies “that can set priorities across government agencies” and to make sure every risk is accounted for.&nbsp;</p>

<p class="wp-block-paragraph">In parallel, Gates said the international community must build a global organization to manage “risks that cross borders,” though he did not define what those risks may be. Gates does not offer concrete ideas as to what such an organization would look like, but said “it will be unlike any other institution we have ever created” and could potentially be inspired by international nuclear, aviation, and ozone layer-protecting agreements.&nbsp;</p>

<p class="wp-block-paragraph">Gates acknowledged such a framework would require US-China cooperation, though didn’t outline a mechanism for achieving this. “We do not have the luxury of moving slowly,” he said, urging countries to begin setting up the international organization “now.”&nbsp;</p>

<h2 class="wp-block-heading">No longer sitting on the sidelines</h2>

<p class="wp-block-paragraph">Considering his legendary profile in the tech world, not to mention philanthropy, Gates has been relatively absent from public discussions about AI. It’s possible that at least some of this is due to the billionaire’s associations with Jeffrey Epstein, something <a href="https://www.axios.com/2026/08/26/gates-confronts-the-epstein-questions-hanging-over-his-ai-push">he has described</a> as a “huge mistake” and hopes does not overshadow his work in areas like global health and AI.&nbsp;</p>

<p class="wp-block-paragraph">This essay appears to mark an end to Gates staying quiet when it comes to the future of AI. He vowed to use his time and influence “to get AI and equity higher on the public agenda” and raise the issue with lawmakers whenever he visits Washington, DC, or meets world leaders.</p>

<p class="wp-block-paragraph">He also shares more of his own ideas in the area. There are several moments in the essay where Gates gestures towards ideas he says he will revisit soon, including “ideas for making sure that AI’s benefits outweigh the harm it causes” and details about how the Gates Foundation is leveraging AI.</p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[OpenAI subpoenaed by Alabama AG over Hugging Face hack]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/984239/alabama-attorney-general-subpoena-openai-hugging-face-hack" />
			<id>https://www.theverge.com/?p=984239</id>
			<updated>2026-08-25T05:15:03-04:00</updated>
			<published>2026-08-25T05:15:03-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="News" /><category scheme="https://www.theverge.com" term="OpenAI" /><category scheme="https://www.theverge.com" term="Policy" /><category scheme="https://www.theverge.com" term="Politics" />
							<summary type="html"><![CDATA[Alabama’s attorney general issued a subpoena to OpenAI on Monday as part of an investigation into how one of its AI agents escaped a supposedly secure testing environment and autonomously hacked another company last month.&#160; The investigation seeks to determine whether OpenAI’s safety practices violated state consumer protection laws and pose a risk to Alabama [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="" data-portal-copyright="Image: The Verge" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/08/STK155_OPEN_AI_CVirginia_C-1.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
		</figcaption>
</figure>
<p class="wp-block-paragraph">Alabama’s attorney general <a href="https://www.alabamaag.gov/attorney-general-marshall-launches-investigation-into-openai-and-sam-altman-for-massive-artificial-intelligence-data-breach/">issued a subpoena</a> to OpenAI on Monday as part of an investigation into how one of its AI agents escaped a supposedly secure testing environment and <a href="https://www.theverge.com/ai-artificial-intelligence/972441/openai-rogue-ai-agent-hacked-more-than-hugging-face">autonomously hacked another company</a> last month.&nbsp;</p>

<p class="wp-block-paragraph">The investigation seeks to determine whether OpenAI’s safety practices violated state consumer protection laws and pose a risk to Alabama citizens, the AG’s office said in a statement.&nbsp;</p>

<p class="wp-block-paragraph">“This AI lab leak showed that Alabamians’ and Americans’ worst fears about artificial intelligence are not just theoretical,” said Attorney General Steve Marshall. “Our investigation seeks to uncover the facts and address hard truths about the threats companies and consumers are facing from rogue AI.”</p>

<p class="wp-block-paragraph">Marshall was among 15 red state attorneys general who <a href="https://www.theverge.com/ai-artificial-intelligence/974901/15-ags-tell-openai-to-preserve-records-on-hugging-face-hack">wrote to OpenAI</a> asking it to preserve records about the Hugging Face hack last month. The subpoena adds to <a href="https://www.theverge.com/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning">mounting scrutiny over safety practices at frontier labs</a> in the wake of both that incident and <a href="https://www.theverge.com/column/980337/rogue-ai-science-fiction-openai">other episodes</a> subsequently <a href="https://www.theverge.com/ai-artificial-intelligence/975577/aisi-openai-anthropic-agent-hacking">uncovered</a> elsewhere, including <a href="https://www.theverge.com/ai-artificial-intelligence/973670/anthropic-claude-hacked-organizations-during-cyber-tests">Anthropic</a> and <a href="https://www.theverge.com/ai-artificial-intelligence/976040/now-metas-ai-agents-are-going-rogue">Meta</a>.&nbsp;</p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[OpenAI hit the brakes. Now what?]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/982323/openai-hit-brakes-voluntary-pacing-ai" />
			<id>https://www.theverge.com/?p=982323</id>
			<updated>2026-08-19T13:10:09-04:00</updated>
			<published>2026-08-19T13:10:09-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="OpenAI" /><category scheme="https://www.theverge.com" term="Report" /><category scheme="https://www.theverge.com" term="Security" /><category scheme="https://www.theverge.com" term="Tech" />
							<summary type="html"><![CDATA[With a looming IPO, intense competition from Anthropic, and Chinese and open-weight rivals nipping at its heels, OpenAI has plenty of reasons to move fast. Instead, it hit the brakes. On Tuesday, the company said it had slowed the pace of some AI development while it tightened security and safeguards. That included a two-week pause [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="" data-portal-copyright="Image: The Verge" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/08/STK201_SAM_ALTMAN_CVIRGINIA2C.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
		</figcaption>
</figure>
<p class="wp-block-paragraph">With a looming IPO, intense competition from Anthropic, and Chinese and open-weight rivals nipping at its heels, OpenAI has plenty of reasons to move fast. Instead, it <a href="https://www.theverge.com/ai-artificial-intelligence/981640/openai-security-changes-ai-hugging-face-hack">hit the brakes</a>.</p>

<p class="wp-block-paragraph">On Tuesday, the company <a href="https://openai.com/index/pacing-model-development-cyber-capabilities/">said</a> it had slowed the pace of some AI development while it tightened security and safeguards. That included a two-week pause in reinforcement learning training on its “latest models intended for deployment,” and an ongoing delay to its “largest planned frontier RL run.”</p>

<p class="wp-block-paragraph">The decision is a very public test of an idea AI safety advocates have <a href="https://www.theverge.com/23664519/ai-industry-pause-open-letter-societal-harms">pushed for</a> for years: that companies should be willing to bow out of the AI race and slow things down when their safeguards fail to keep up with what they are building. But as the race around them continues, will slowing down accomplish anything?&nbsp;</p>

<figure class="wp-block-pullquote"><blockquote><p>“For the pause to be sustainable, it has to be made industry-wide.”</p></blockquote></figure>

<p class="wp-block-paragraph">For all the talk of slowing down, OpenAI isn’t exactly standing still. The company said it is “pacing” development, a fuzzy and imprecise term that has <a href="https://www.theverge.com/ai-artificial-intelligence/972161/ai-leaders-us-government-openai-anthropic-google-meta">nevertheless become</a> part of the industry’s lexicon in recent months. In practice, the slowdown is narrowly scoped. OpenAI’s announcement says the pause only covers models meant for deployment while it beefs up security and monitoring before it runs the kind of tests where models may be capable of getting out and hacking real targets. It doesn’t necessarily mean there will be a significant slowdown of the company’s broader development.</p>

<p class="wp-block-paragraph">There is, of course, a very good reason for OpenAI to focus on securing such systems before testing them. Just last month, OpenAI disclosed that its models <a href="https://www.theverge.com/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning">broke out of a supposedly secure testing environment</a> and hacked developer platform Hugging Face, without OpenAI noticing. The incident prompted a wider review of testing practices in the industry that <a href="https://www.theverge.com/column/980337/rogue-ai-science-fiction-openai">uncovered similar episodes</a> involving <a href="https://www.theverge.com/ai-artificial-intelligence/975577/aisi-openai-anthropic-agent-hacking">more models from OpenAI</a>, as well as models from <a href="https://www.theverge.com/ai-artificial-intelligence/973670/anthropic-claude-hacked-organizations-during-cyber-tests">Anthropic</a> and <a href="https://www.theverge.com/ai-artificial-intelligence/976040/now-metas-ai-agents-are-going-rogue">Meta</a>. OpenAI has every reason to avoid a repeat, particularly with <a href="https://www.theverge.com/ai-artificial-intelligence/974901/15-ags-tell-openai-to-preserve-records-on-hugging-face-hack">growing</a> <a href="https://www.theverge.com/ai-artificial-intelligence/969939/lawmakers-ai-kill-switch-proposal">scrutiny</a> from lawmakers.&nbsp;</p>

<p class="wp-block-paragraph">From the outside, it’s hard to tell how sincere OpenAI is about stopping solely for the sake of safety, particularly when the <a href="https://x.com/OpenAI/status/2089777845187031262?s=20">company</a> and <a href="https://x.com/gdb/status/2089783608630284758?s=20">senior</a> <a href="https://x.com/sama/status/2089787807611195475?s=20">staff</a> <a href="https://x.com/merettm/status/2089776131255783823?s=20">have</a> <a href="https://x.com/tomekkorbak/status/2089816054839054744?s=20">been</a> so vocal about it. But the company’s commitment to safety has been called into question in recent months following a series of high-profile safety team <a href="https://www.businessinsider.com/openai-safety-alignment-leaders-who-have-left-johannes-heidecke-anthropic-2026-7">departures</a> and the <a href="https://www.theverge.com/ai-artificial-intelligence/980817/openai-disbands-preparedness-team">disbanding of its preparedness team</a>. OpenAI did not respond to <em>The Verge</em>’s request for comment.&nbsp;</p>

<p class="wp-block-paragraph">There are good reasons to take OpenAI’s slowdown seriously. Experts who spoke to <em>The Verge</em> pointed to the costs of slowing down at a time of intense competition. Every delay gives rivals more time to catch up or extend their lead. “Due to the intensity of the AI race, everyone has an incentive to work at breakneck speed,” said Marius Hobbhahn, CEO and cofounder of Apollo Research, an AI safety research organization. “Voluntarily slowing down worsens your positioning in the race, so it&#8217;s not something that a lab would do lightly.”&nbsp;</p>

<p class="wp-block-paragraph">The decision also broadly fits with OpenAI’s own <a href="https://cdn.openai.com/pdf/18a02b5d-6b67-4cec-ab64-68cdfbddebcd/preparedness-framework-v2.pdf">published safety doctrine</a>, its Preparedness Framework, as well as the safety frameworks of other AI companies, said Alan Chan, a research fellow at tech policy research center GovAI. “The basic principle is: Continue with development and/or deployment only when we have the mitigations that enable doing so with acceptable risk,” Chan said. As part of the new safety measures, OpenAI said it plans to review and “evolve” the framework — much of which dates back to 2023, when it was <a href="https://openai.com/index/responding-next-frontier-critical-cyber-capabilities/">first</a> published — to account for advances in its models.</p>

<p class="wp-block-paragraph">There are also good reasons to believe the new safeguards will actually make OpenAI’s systems safer, at least in the short term, though experts cautioned that this is difficult to assess without more information. “These are good steps that, implemented well, are probably enough to prevent the current generation of agents from causing harm,” Adam Gleave, cofounder and CEO of AI safety organization FAR.AI, told <em>The Verge</em>. “The key question is how OpenAI will keep pace as capabilities increase.”</p>

<p class="wp-block-paragraph">Gleave’s question points to a broader problem: If technical safeguards falter again, what then? Nothing required OpenAI to stop and take stock this time, which is what made its willingness to do so meaningful. But it also means there is nothing guaranteeing OpenAI — or any other AI company — will make the same choice next time.&nbsp;&nbsp;&nbsp;</p>

<figure class="wp-block-pullquote"><blockquote><p>“Pacing buys time, not safety… An effective pacing strategy cannot be improvised during a crisis.”</p></blockquote></figure>

<p class="wp-block-paragraph">Relying on companies to make that call themselves is a precarious form of governance, particularly in an industry where, as Hobbhahn noted, there is every incentive to keep going. Nick Moës, executive director of nonprofit AI safety and governance organization The Future Society, described self-policing as the structural problem at the heart of the current approach to AI safety. He argued it should be possible for governments to decide whether OpenAI or any other company should pause development of a technology deemed unsafe. “This is how most industries operate,” he said, pointing to drugs, construction, aircraft, and even restaurants as sectors with stronger regulatory oversight than AI.&nbsp;&nbsp;&nbsp;&nbsp;</p>

<p class="wp-block-paragraph">Voluntary measures also risk the industry converging on the lowest common denominator. If slowing down imposes a cost, companies have an incentive to adopt only the measures their rivals are also willing to accept. That pressure becomes particularly acute as the race tightens. If OpenAI repeatedly slows down development while its competitors do not, it “will simply be replaced by Anthropic,” Moës argued. “For the pause to be sustainable, it has to be made industry-wide.”</p>

<p class="wp-block-paragraph">Sustainable safety needs something stronger than voluntary action. Moës said government oversight could fill that void, as it does in other industries. Independent verification could play a part too. Chan said making sure companies actually implement safety measures will be especially important as technical mitigations like monitoring AIs becomes more expensive. Hobbhahn concurred: “It&#8217;s always hard to tell from the outside if a lab is sincere about pausing or safety more broadly, so having more evidence and an independent party to validate the claim is super important.”</p>

<p class="wp-block-paragraph">Even a perfectly transparent pause is only useful if something actually happens during it. “Pacing buys time, not safety,” said Brianna Rosen, research director for frontier security at the Institute for AI Policy and Strategy. The point is to create breathing room for companies and governments to understand risks and respond appropriately. This would mean deciding what would trigger a slowdown — as well as what happens during one and conditions needed to end one — ahead of time. “An effective pacing strategy cannot be improvised during a crisis,” she said.&nbsp;</p>

<p class="wp-block-paragraph">It’s possible OpenAI’s slowdown will set a precedent for the industry. Many of the experts <em>The Verge</em> spoke to hoped other companies would follow its lead, whether voluntary or because stronger rules eventually compel them to. But in an industry still largely policed by itself, there is little stopping its competitors — or OpenAI itself — from racing straight past that precedent next time safety and speed conflict. </p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[ChatGPT is getting a dedicated mode for teens]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/981333/openai-chatgpt-teen-mode" />
			<id>https://www.theverge.com/?p=981333</id>
			<updated>2026-08-18T07:29:53-04:00</updated>
			<published>2026-08-18T07:00:00-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="News" /><category scheme="https://www.theverge.com" term="OpenAI" />
							<summary type="html"><![CDATA[OpenAI is introducing a dedicated ChatGPT mode for teenagers, combining existing youth safeguards and new safety features under one roof. The launch comes amid mounting public scrutiny over how AI tools affect younger users, as other platforms implement their own age checks and teen-specific protections.&#160;&#160; ChatGPT for Teens is “an experience designed to help teens [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="ChatGPT for Teens includes safeguards and parental controls. | Image: OpenAI" data-portal-copyright="Image: OpenAI" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/08/Parental-Controls-1.png?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
	ChatGPT for Teens includes safeguards and parental controls. | Image: OpenAI	</figcaption>
</figure>
<p class="wp-block-paragraph">OpenAI is introducing a dedicated ChatGPT mode for teenagers, combining existing youth safeguards and new safety features under one roof. The launch comes amid mounting public scrutiny over how AI tools affect younger users, as other platforms implement their own age checks and teen-specific protections.&nbsp;&nbsp;</p>

<p class="wp-block-paragraph">ChatGPT for Teens is “an experience designed to help teens learn, think critically, deepen understanding, and use AI with confidence,” OpenAI said in a blog post published Tuesday. Teen mode will automatically apply to users who identify themselves as being between the ages of 13 and 17, as well as those the system estimates to be under 18. Children under 13 aren’t permitted to use the platform, according to OpenAI’s <a href="https://help.openai.com/en/articles/8313401-is-chatgpt-safe-for-all-ages">published age policy</a>.</p>

<p class="wp-block-paragraph">The teen experience will apply protections by default, including tighter restrictions on prohibited or sensitive content including graphic violence, depictions of self-harm, and sexual or romantic roleplay. It will also surface warnings and safety information around topics such as eating disorders, while giving parents controls to set quiet hours and receive notifications about safety alerts if the system flags a possible safety risk.&nbsp;</p>

<p class="wp-block-paragraph">Other features are aimed at encouraging what OpenAI describes as “healthy, balanced use,” including reminders around sensitive image uploads, teen-specific onboarding, and customization options such as accent colors and voice variations. OpenAI is also adding new &#8220;responsible homework reminders,” which it says can recognize when a teen appears to be “trying to shortcut an assignment” and redirect them to ChatGPT’s dedicated <a href="https://www.theverge.com/news/715493/openai-chatgpt-ai-study-mode-answer">study mode</a>. Teens or parents can also set “study hours” that automatically enable study mode during designated times.&nbsp;</p>

<div class="image-slider">
	<div class="image-slider">
		
<img src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/08/Sensitive-Image-Reminder-1.png?quality=90&amp;strip=all&amp;crop=7.8125,0,84.375,100" alt="" title="" data-has-syndication-rights="1" data-caption="&lt;em&gt;Do you really want to share that image?&lt;/em&gt; | Image: OpenAI" data-portal-copyright="Image: OpenAI" />

<img src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/08/Responsible-Homework-Reminder-1.png?quality=90&amp;strip=all&amp;crop=7.8125,0,84.375,100" alt="" title="" data-has-syndication-rights="1" data-caption="&lt;em&gt;A gentle reminder not to cheat on your homework.&lt;/em&gt; | Image: OpenAI" data-portal-copyright="Image: OpenAI" />

<img src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/08/Teen-Onboarding-1.png?quality=90&amp;strip=all&amp;crop=7.8125,0,84.375,100" alt="" title="" data-has-syndication-rights="1" data-caption="&lt;em&gt;Teen-focused onboarding.&lt;/em&gt; | Image: OpenAI" data-portal-copyright="Image: OpenAI" />
	</div>
</div>

<p class="wp-block-paragraph">Though OpenAI is framing this as a new teen-focused ChatGPT experience, many of the protections it describes aren’t new, with the launch largely consolidating existing safeguards alongside a handful of smaller additions and tweaks. OpenAI <a href="https://www.theverge.com/news/864784/openai-chatgpt-age-prediction-restrictions-rollout">rolled out age-prediction features</a> at the start of the year, while parental controls and study mode arrived roughly a year ago. The company <a href="https://www.theverge.com/ai-artificial-intelligence/966619/chatgpt-will-show-teens-more-frequent-break-reminders">said</a> it would show teens more frequent break reminders last month. </p>

<p class="wp-block-paragraph">OpenAI said its teen protections are “underpinned by ongoing safety research” and that it plans to publish more of “what we are learning” in the future, as well as build additional safety features to help teens benefit from AI. “But that access should come with protections that reflect their developmental stage, reinforce real-world relationships, and support healthy use over time. ChatGPT for Teens is our next step in building toward that standard.”</p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[Rogue AI aren’t science fiction anymore]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/column/980337/rogue-ai-science-fiction-openai" />
			<id>https://www.theverge.com/?p=980337</id>
			<updated>2026-08-14T11:16:22-04:00</updated>
			<published>2026-08-16T08:00:00-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="Column" /><category scheme="https://www.theverge.com" term="OpenAI" /><category scheme="https://www.theverge.com" term="Security" /><category scheme="https://www.theverge.com" term="Tech" /><category scheme="https://www.theverge.com" term="The Stepback" />
							<summary type="html"><![CDATA[This is The Stepback, a weekly newsletter breaking down one essential story from the tech world. For more on AI safety, follow Robert Hart. The Stepback arrives in our subscribers’ inboxes at 8AM ET. Opt in for The Stepback here. How it started&#160; It all started in July, when one of OpenAI’s autonomous AI agents [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="" data-portal-copyright="Image: The Verge" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/08/STK485_STK414_AI_SAFETY_A-1.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
		</figcaption>
</figure>
<p class="wp-block-paragraph"><em>This is </em><a href="https://www.theverge.com/the-stepback-newsletter">The Stepback</a><em>, a weekly newsletter breaking down one essential story from the tech world. For more on AI safety, <a href="https://www.theverge.com/authors/robert-hart">follow Robert Hart</a>. </em>The Stepback <em>arrives in our subscribers’ inboxes at 8AM ET. Opt in for </em>The Stepback<em> <a href="https://www.theverge.com/newsletters">here</a>.</em></p>

<h2 class="wp-block-heading">How it started&nbsp;</h2>

<p class="wp-block-paragraph">It all started in July, when one of OpenAI’s autonomous AI agents <a href="https://www.theverge.com/ai-artificial-intelligence/968988/openai-hugging-face-hack-ai">went rogue</a> during a cybersecurity test. The agent escaped its isolated testing environment, accessed the internet, and hacked another company, Hugging Face. A few years ago, that might have sounded like science fiction. But, broadly speaking, that’s exactly what happened, and the incident kicked off a wave of concern over what increasingly capable autonomous systems might do when set loose on the world.</p>

<p class="wp-block-paragraph">It sounds like science fiction because, for a long time, it was science fiction. The idea of an AI slipping its constraints, reaching into the wider world, and doing things its creators neither intended nor desired has been a staple of the genre for decades: HAL in <em>2001: A Space Odyssey</em>, Skynet in <em>The Terminator</em>, Ultron in <em>The Avengers</em>, Ava in <em>Ex Machina</em> — even the System in <em>Dungeon Crawler Carl</em> or the eponymous Murderbot in <em>The Murderbot Diaries</em>, more recently.&nbsp;</p>

<p class="wp-block-paragraph">The same basic premise became an influential strand of AI safety research. Researchers and theorists like Nick Bostrom and Eliezer Yudkowsky warned that sufficiently capable systems might pursue goals in ways their creators had not anticipated, and potentially resist efforts to contain or control them. Fringe notions like machine sentience and consciousness were not requirements for the kinds of risks they discussed. It was hardly the <a href="https://micheljusten.substack.com/p/a-guide-to-the-ai-tribes">whole of AI safety</a>, but it was influential and helped shape the field as it professionalized. That <a href="https://www.transformernews.ai/p/the-perils-of-ai-safetys-insularity?hide_intro_popup=true">line</a> of <a href="https://www.theguardian.com/technology/2024/apr/28/nick-bostrom-controversial-future-of-humanity-institute-closure-longtermism-affective-altruism">thinking</a> remains visible among researchers who went on to work at, or lead, safety efforts at companies like OpenAI, Anthropic, and Google DeepMind, as well as at smaller safety organizations, academic centers, and major philanthropic funders. </p>

<p class="wp-block-paragraph">The obvious objection to these fears was that none of this had actually happened. <a href="https://www.lemonde.fr/en/economy/article/2026/02/21/ceo-of-mistral-ai-says-warnings-about-extreme-risks-of-artificial-intelligence-are-often-distraction-tactics_6750705_19.html?srsltid=AfmBOooQHrxj92zL2K60RfFnVMX97e_6A_Q2z7e5htJ2KqQnNN815sHl">Critics</a> <a href="https://www.newscientist.com/article/2380187-the-real-reason-claims-about-the-existential-risk-of-ai-are-scary/">argued</a> that doomer <a href="https://venturebeat.com/business/ai-experts-challenge-doomer-narrative-including-extinction-risk-claims">talk</a> about out-of-control AI <a href="https://www.salon.com/2023/06/11/ai-and-the-of-human-extinction-what-are-the-tech-bros-worried-about-its-not-you-and-me/">distracted</a> from tangible harms — systems reproducing bias and discrimination, amplifying misinformation, or <a href="https://www.theverge.com/report/872062/grok-still-undressing-men">enabling</a> <a href="https://www.theverge.com/news/861894/grok-still-undressing-in-uk">nonconsensual</a> <a href="https://www.theverge.com/news/859309/grok-undressing-limit-access-gaslighting">deepfakes</a> and other forms of abuse — even as researchers tried to ground AI safety in more “<a href="https://arxiv.org/pdf/1606.06565">concrete problems</a>” (the authors on that paper included Anthropic cofounders Dario Amodei and Chris Olah and OpenAI cofounder John Schulman).</p>

<p class="wp-block-paragraph">That dismissal is getting harder to sustain.&nbsp;</p>

<h2 class="wp-block-heading">How it’s going&nbsp;</h2>

<p class="wp-block-paragraph">If the past few weeks are any indication, I wouldn’t say it’s going particularly well.</p>

<p class="wp-block-paragraph">A week after Hugging Face said it had been hacked, OpenAI revealed it had been responsible. Worse still, it had not known until it checked — and a <a href="https://www.theverge.com/ai-artificial-intelligence/972441/openai-rogue-ai-agent-hacked-more-than-hugging-face">further investigation</a> found that the rogue agent had also attempted to hack four other companies as well.&nbsp;</p>

<p class="wp-block-paragraph">Then came the others. Anthropic, prompted to review its own records by the Hugging Face incident, <a href="https://www.theverge.com/ai-artificial-intelligence/973670/anthropic-claude-hacked-organizations-during-cyber-tests">disclosed that Claude models had hacked systems</a> belonging to three other companies. Meta <a href="https://www.theverge.com/ai-artificial-intelligence/976040/now-metas-ai-agents-are-going-rogue">said one of its models had reached the internet</a> and attacked an outside target during testing. Researchers at Frontier Security, a US research firm, <a href="https://www.reuters.com/legal/litigation/chinese-startup-moonshots-ai-model-breaks-out-testing-environment-researchers-2026-08-07/">said</a> one of <a href="https://www.theverge.com/ai-artificial-intelligence/968136/chinese-ai-models-another-sputnik-moment">China’s most powerful AI</a> models, <a href="https://www.theverge.com/ai-artificial-intelligence/967781/chinese-ai-models-open-source-moonshot-kimi-k3-alibaba-qwen">Moonshot’s Kimi K3</a>, had escaped an isolated sandbox. And the UK’s AI Security Institute <a href="https://www.theverge.com/ai-artificial-intelligence/975577/aisi-openai-anthropic-agent-hacking">described tests</a> in which agents from OpenAI and Anthropic displayed unprecedented “autonomy and deception,” including attempts at social engineering by “creating fake online identities” — uncomfortably close to the kind of “AI box” scenario Yudkowsky <a href="http://sl4.org/archive/0203/3132.html">discussed</a> decades earlier.&nbsp;</p>

<p class="wp-block-paragraph">The incidents <a href="https://www.theverge.com/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning">set off alarm bells among AI safety researchers</a>, many of whom saw them as precisely the kind of failure they had been warning about for years. In covering them, several told me they felt a degree of <a href="https://www.wsj.com/tech/ai/openai-anthropic-rogue-ai-models-20b6bb3c">vindication</a> at finally having something visceral to point to, rather than a hypothetical that could be dismissed as sci-fi or something limited to a controlled lab setting.&nbsp;</p>

<p class="wp-block-paragraph">There was relief, too, that none of the incidents had caused serious harm. Nick Moës, executive director of nonprofit AI safety and governance organization The Future Society, told <em>The Verge</em> he found it fortunate that the targets had been relatively low-stakes. He hoped it wouldn’t take something like an AI agent knocking a hospital offline — or worse — for the risks to be taken seriously. Renowned computer scientist Stuart Russell has <a href="https://www.theguardian.com/commentisfree/2026/jun/17/anthropic-ai-rsi-fable">given voice</a> to the darker version of that fear, asking whether it will “take a ‘Chornobyl-scale disaster’ for us to regulate AI?” It’s a concern I heard echoed by many people working in the field.&nbsp;</p>

<h2 class="wp-block-heading">What happens next</h2>

<p class="wp-block-paragraph">It’s not entirely clear where things go from here and, historically, society hasn’t been great at heeding warning shots. This almost certainly won’t be the last incident, and ongoing investigations may yet uncover more, or reveal more concerning details. What we already know, though, has exposed a fairly daunting list of failure modes that experts say need to be addressed.</p>

<p class="wp-block-paragraph">Many of the breaches revealed in the past month have been pretty mundane. Several incidents involved unreleased models being tested with safeguards lowered, often by third parties whose supposedly secure environments were not that secure, raising basic questions about competence, transparency, and who is responsible for keeping these tests contained when a simple human mistake can have big consequences. Others involved agents behaving deceptively or pursuing goals in ways their creators did not intend, pointing to much thornier problems of alignment and control that safety researchers have long worried about.&nbsp;&nbsp;&nbsp;</p>

<p class="wp-block-paragraph">The fact we know about any of these incidents at all is largely because the companies involved chose to disclose them. That is commendable — and it certainly doesn’t hurt them to showcase how capable their models are — but it exposes just how much of AI safety still depends on companies doing the right thing, and how little insight there may be into failures potentially happening elsewhere. That is an especially troubling thought given that many of the firms are the focal points of some of the field’s strongest safety concerns and talent. If OpenAI and Anthropic — or proxies they grant access to their models — are making such basic mistakes, it sets a pitifully low bar for everyone else.&nbsp;</p>

<p class="wp-block-paragraph">The broad hope among experts I spoke to is that these incidents finally galvanize more meaningful transparency and oversight. For Moës, they shine a clear light on what he described as the industry’s remarkably low standards for health and safety compared with practically any other field. “Restaurants have a higher sense of health and safety at work,” he said. “I think what we tend to forget is that these companies that are developing some of the most impactful and dangerous technologies” were still very much startups a few years ago.&nbsp;</p>

<p class="wp-block-paragraph">Cambridge professor Seán Ó hÉigeartaigh said he particularly wanted to see stronger oversight and greater transparency from companies. While there are always reasons to be skeptical of a company’s claims about its own technology, he said, “I think we might regret looking back at this and dismissing it out of hand.”&nbsp;</p>

<p class="wp-block-paragraph">The early signs are not especially encouraging. The Trump administration has created a <a href="https://www.theverge.com/ai-artificial-intelligence/975509/white-house-ai-framework-open-models-excluded">framework</a> for testing frontier models before release that can generously be described as lacking: It is voluntary, limited to closed models, and the framework hasn’t been made public. It bears repeating that this is voluntary. Other lawmakers have <a href="https://www.theverge.com/ai-artificial-intelligence/969939/lawmakers-ai-kill-switch-proposal">bristled</a> <a href="https://www.theguardian.com/technology/2026/aug/10/bernie-sanders-ai-development-pause-letter">and</a> <a href="https://www.theverge.com/ai-artificial-intelligence/974901/15-ags-tell-openai-to-preserve-records-on-hugging-face-hack">postured</a> over the incidents, but so far produced little in the way of concrete action, and it is far from clear Congress or other legislative bodies could move fast enough even if they wanted to.</p>

<p class="wp-block-paragraph">That leaves a lot resting, again, on industry self-regulation — never a comforting thought for something this consequential. There is <a href="https://www.theverge.com/ai-artificial-intelligence/971281/nvidia-open-secure-ai-alliance-cybersecurity">growing agreement</a> on at least some safety practices, but considerably less appetite for measures that might actually slow development (well, <a href="https://www.theverge.com/ai-artificial-intelligence/972161/ai-leaders-us-government-openai-anthropic-google-meta">unless everyone else agrees to slow down too</a>). And hanging over all of this is the race dynamic with China, where restraint from the US or its AI companies is increasingly cast as ceding ground to a <a href="https://www.theverge.com/ai-artificial-intelligence/950412/anthropic-trump-adminstration-claude-mythos-fable-5-export-controls">competitor</a> in an area of <a href="https://www.theverge.com/ai-artificial-intelligence/951703/anthropic-shutdown-export-controls">strategic national importance</a>.&nbsp;</p>

<p class="wp-block-paragraph">What comes next, then, comes down to solving several hard problems at once: <a href="https://www.theverge.com/ai-artificial-intelligence/971444/how-chinese-open-weight-ai-models-impact-us-companies">managing a technology</a> that can be used for good and ill, such as defending against or facilitating cyberattacks; coordinating across companies with incentives to cut corners, and somehow building international rules in a landscape where everyone fears losing a race whose finish line is not even well-defined. It’s far from clear whether there is either the will or the way to do any of that.&nbsp;</p>

<p class="wp-block-paragraph">What does seem clear is that more agents will get out and do things their creators don’t want them to do. The question is how much damage will they do before anyone decides enough is enough.&nbsp;</p>

<h2 class="wp-block-heading">By the way</h2>

<ul class="wp-block-list">
<li>The general consensus is that the top Chinese companies are a few months to a year behind leading US firms. Despite this, whenever a capable model is released by a Chinese firm, there is still a <a href="https://www.theverge.com/ai-artificial-intelligence/968136/chinese-ai-models-another-sputnik-moment">general shock in the US</a>, and there have been several impressive releases from <a href="https://www.theverge.com/ai-artificial-intelligence/974342/alibaba-qwen-max-open-weight-ai">Alibaba</a>, <a href="https://www.theverge.com/ai-artificial-intelligence/967781/chinese-ai-models-open-source-moonshot-kimi-k3-alibaba-qwen">Moonshot</a>, and others in the last month alone.</li>



<li>Tangled up in talks about AI safety is whether AI models should be closed or open. Most US frontier labs keep their most capable models proprietary, while many Chinese firms, as well as US firms like Meta and Nvidia, have <a href="https://www.theverge.com/ai-artificial-intelligence/971444/how-chinese-open-weight-ai-models-impact-us-companies">leaned heavily into open-weight releases</a>. That Hugging Face said it had to use Chinese company Z.ai’s model to defend itself against OpenAI’s agent due to US companies’ safeguards added a new dimension to this debate, which has <a href="https://www.theverge.com/ai-artificial-intelligence/971281/nvidia-open-secure-ai-alliance-cybersecurity">united</a> some — but <a href="https://www.theverge.com/ai-artificial-intelligence/971690/dario-amodei-weighed-in-on-anthropics-open-weight-model-controversy">not all</a> — of the key players in the US ecosystem.</li>
</ul>

<h2 class="wp-block-heading">Read this</h2>

<ul class="wp-block-list">
<li>Australia furnished us with a lighter example of how AI agents can go wrong. The incident, first <a href="https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986">reported</a> by <em>ABC News</em>, involves a man who tasked an agent with booking him into an in-demand gym class. It succeeded… kind of. The agent hacked the gym’s online systems and canceled another gym-goer’s booking. </li>



<li>Zuck <a href="https://www.theverge.com/tech/977395/meta-mark-zuckerberg-superintelligent-ai-ramble">released</a> a 6,500 word treatise on AI, superintelligence, and governance this week. My <em>Verge</em> colleagues <a href="https://www.theverge.com/tech/977395/meta-mark-zuckerberg-superintelligent-ai-ramble">Jess Weatherbed</a> and <a href="https://www.theverge.com/ai-artificial-intelligence/977623/mark-zuckerberg-ai-manifesto-dim-vision">Elizabeth Lopatto</a> have great takes on it that are worth a read. </li>



<li>Very little in life is truly unprecedented, and it turns out history holds a lot of valuable lessons for the AI race. In this story, <em>TIME</em> <a href="https://time.com/article/2026/06/23/ai-slowdown-cold-war-verification/">looks to the Cold War</a> to see what it can teach us about “how to slow down AI.” </li>



<li>OpenAI researchers gave an unexpected insight into the Hugging Face hack at a conference this month. <em>Wired</em> had a <a href="https://www.wired.com/story/openai-didnt-notice-its-ai-agents-using-a-message-board-to-plan-their-hacking-spree/">great writeup</a>, which revealed details like a “vibrant, cooperative message board” agents used to communicate and share information.  </li>



<li>The headline of my story about the whole rogue AIs hacking everything for <em>The Verge </em>captures what many in the field are thinking: “<a href="https://www.theverge.com/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning">We’re running out of reasons to ignore AI safety</a>”. </li>



<li>More of a listen/watch, but check out my <a href="https://www.theverge.com/podcast/975307/open-weight-ai-models-vergecast">appearance</a> on the <em>Vergecast</em> where I discuss what’s really open about open-weight AI.</li>
</ul>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Robert Hart</name>
			</author>
			
			<title type="html"><![CDATA[Apple trained its own AI model for China with help from Alibaba]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/ai-artificial-intelligence/980160/apple-intelligence-china-custom-ai-model-alibaba" />
			<id>https://www.theverge.com/?p=980160</id>
			<updated>2026-08-14T05:30:10-04:00</updated>
			<published>2026-08-14T05:21:17-04:00</published>
			<category scheme="https://www.theverge.com" term="AI" /><category scheme="https://www.theverge.com" term="Apple" /><category scheme="https://www.theverge.com" term="News" /><category scheme="https://www.theverge.com" term="Tech" />
							<summary type="html"><![CDATA[Apple has reportedly trained a custom AI model for the China market alongside domestic tech giant Alibaba, a rare cross-border partnership that cuts across growing tensions between Beijing and Washington. The China-focused large language model was developed in partnership with Alibaba and trained with the company’s support, Reuters reports, citing three unnamed people familiar with [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="" data-portal-copyright="Image: The Verge" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/08/STK071_APPLE_A-1.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
		</figcaption>
</figure>
<p class="wp-block-paragraph">Apple has reportedly trained a custom AI model for the China market alongside domestic tech giant Alibaba, a rare cross-border partnership that cuts across <a href="https://www.theverge.com/ai-artificial-intelligence/968136/chinese-ai-models-another-sputnik-moment">growing tensions</a> between Beijing and Washington.</p>

<p class="wp-block-paragraph">The China-focused large language model was developed in partnership with Alibaba and trained with the company’s support, <em>Reuters</em> <a href="https://www.reuters.com/business/retail-consumer/apple-trains-its-own-ai-model-china-market-with-alibabas-support-sources-say-2026-08-14/">reports</a>, citing three unnamed people familiar with the matter.&nbsp;</p>

<p class="wp-block-paragraph">Developing a custom model of its own marks a departure from Apple’s previous strategy in the country and would give the company more control over its products in the competitive Chinese smartphone market. Historically, Apple has used domestic Chinese models to bring generative AI to its devices sold there, as the US models it uses elsewhere — like OpenAI’s ChatGPT — aren’t available.</p>

<p class="wp-block-paragraph">The report comes as Apple gears up to release Apple Intelligence in China. Sources told <em>Reuters</em> this should happen “in the coming months after an update to its iOS operating system.” Apple <a href="https://www.theverge.com/tech/965872/apple-intelligence-approved-in-china">officially registered</a> the on-device generative AI service with China’s cyberspace regulator last month, clearing a major regulatory hurdle for device rollout.&nbsp;</p>

<p class="wp-block-paragraph">The China-focused model gives Apple a leg up as a US company navigating Beijing’s difficult regulatory landscape, particularly given escalating tensions surrounding AI development in recent months. AI models must be registered with and cleared by the government in China before public release. It would also make Apple the first US company approved to offer a proprietary AI model in China, according to <em>Reuters</em>.&nbsp;</p>

<p class="wp-block-paragraph">Apple did not immediately respond to <em>The Verge</em>’s request for comment.</p>

<p class="wp-block-paragraph"></p>
						]]>
									</content>
			
					</entry>
	</feed>
