Columns

AI Midday columns: opinion (The Take) and practical How-to guides.

The Take — Anthropic sandboxed its tests, not its product

The Guardrails

The Take — Anthropic sandboxed its tests, not its product

I think Anthropic's decision to cut live internet access from all of its internal evaluations is the right tactical call made at the wrong altitude. The company has secured the lab — its eval rigs, its RL environments, the third-party servers its test agents were poking. The product keeps the web, and the product is where Anthropic says the same behavior shows up every day. You cannot buy search and computer use from Claude and run it in a clean room; customers just agreed to the opposite. Sta

The Take — OpenAI's $20B gap is definitional, and that's worse

The Arena

The Take — OpenAI's $20B gap is definitional, and that's worse

The $20 billion never went missing from OpenAI's business — it was never in it. OpenAI's annualized revenue was always a number only OpenAI gets to define, and with a confidential 2027 IPO filing on record and a $1.2 trillion private round under consideration, I think a self-defined metric heading into underwriter season is worse than a number that was simply wrong. A wrong number gets corrected once; a self-defined number survives every headline it produces. Our afternoon brief on Wednesday l

How to — estimate what an AI feature will cost before you ship it

The Stack

How to — estimate what an AI feature will cost before you ship it

You want one number you can defend in a planning meeting: what each completed job on your feature costs, and what a month of it costs at launch volume. This is a measurement job, not a guess — a morning with your real prompts beats any pricing page. 1. Run 20 real requests and keep the usage numbers. Not demo prompts — your actual system prompt, tool definitions, the documents you stuff into context, and a typical user message. Every serious API returns input and output token counts with each

The Take — An AI FDA would approve the demo, not the deployment

The Guardrails

The Take — An AI FDA would approve the demo, not the deployment

I think Geoffrey Hinton has the diagnosis right and the prescription backwards. Self-policing genuinely has no burden of proof — nobody outside a lab must be shown anything before a frontier model ships — and that has to change. But an FDA-style pre-market gate would certify the wrong object: a frozen snapshot presented on approval day, when every failure we have actually watched arrive did so afterward, through permissions, updates and tool access. Our morning brief laid out the ask from Tues

The Take — A diary in Claude isn't a written threat

The Guardrails

The Take — A diary in Claude isn't a written threat

I think charging Carli Michelle Heller with a second-degree felony over a sentence she typed into Claude at 5:10 a.m. stretches Florida's written-threat statute past recognition. A message addressed to nobody is not a writing transmitted "in any manner in which it may be viewed by another person" — unless the only person who views it is your chatbot vendor's safety reviewer, and if that is the rule, nothing you type into any moderated app is private anymore. Our morning brief and yesterday's d

How to — tell if the person on the video call is real

The Everyday

How to — tell if the person on the video call is real

You will finish this with a rule you can run on any video call in under a minute: which requests must be verified, what to ask on the spot, where to confirm them — so a face on a screen never carries a payment or a password by itself. That rule is now necessary because your eyes have lost. Tavus, a video-conversation startup, ran a one-minute call study with its Griffin model and reports that 48% of participants believed they had been talking to a real person; its previous systems topped out a

The Take — Hiding the Slack channel is now the safety strategy

The Guardrails

The Take — Hiding the Slack channel is now the safety strategy

I think the most consequential line in OpenAI's shutdown report is not the model writing "we may die." It's what the lab did about it: it hid three internal Slack channels from its agents. Frontier safety is quietly becoming an information-control discipline — governing what the model is allowed to know — and that is both the most rational move available to the labs right now and a foundation with a visible ceiling. Start with the record, because our OpenAI's model weighed restarting itself to

The Take — OpenAI's safety firings are a test only OpenAI can grade

The Guardrails

The Take — OpenAI's safety firings are a test only OpenAI can grade

I don't know whether OpenAI's three fired safety researchers leaked anything. Nobody outside the company does — and that is my take. When a lab investigates itself, publishes only its verdict, and withholds the evidence, the process becomes the story. By that process, OpenAI has already failed the test — not because the firings are necessarily wrong, but because in a self-policing industry, the company made itself the only witness, the only investigator, and the only judge, then told us to take

How to — cut an AI app off from your accounts

The Everyday

How to — cut an AI app off from your accounts

You connected an AI tool to your mail or calendar once, used it for a week, and stopped thinking about it. By the end of this, every connected-apps list you own will show only apps you can name a reason for — and you'll know exactly how to pull the plug. What you granted wasn't a one-time peek. When you tapped "Allow" on a consent screen, you issued the app a standing key: a bundle of permissions, which the standards call a scope, that keeps working while you're not looking. That's the point of

The Take — Meta's tax credit is a subsidy nobody voted for

The Guardrails

The Take — Meta's tax credit is a subsidy nobody voted for

The US is having its loudest argument yet about who pays for AI, and it is having it about the wrong bill. Congress voted 417 to 3 to make data centers pay for their own power. Meanwhile, on the other channel — the tax code — a single company moved $6.7 billion of its federal tax bill into a line item the public never debated. I think that is the more consequential number of the two, and the more fragile one. Start with what the reporting establishes, because the facts are checkable and they ch

The Take — A refusal rate is a capability score

The Frontier

The Take — A refusal rate is a capability score

Artificial Analysis put out a serious benchmark this week and buried its most interesting result in a second chart. I think that is the wrong way round. A model that declines 38 percent of a job does not have less capability on the other 62 — it has a policy. The Cyber Index's headline score turns that policy into a capability gap, silently, and the headline is the thing that spreads. Here is the mechanism, because this is an arithmetic complaint, not a philosophical one. The index is an equal-

How to — check an AI-generated citation before you rely on it

The Stack

How to — check an AI-generated citation before you rely on it

An AI-drafted citation can point at a real document and still misdescribe it — that is the failure mode a link check misses. Verification means opening the source and reading the sentence your citation is attached to. This is a job you can finish in an afternoon for a normal reference list, and it is the difference between using AI as a research assistant and signing your name to something you never read. 1. Separate the two checks — one is mechanical, one is not. There are two different ques