Slow Takes: One week in AI

Sam Illingworth & Leor Gayr

Slow Takes is the weekly Slow AI conversation. Every Monday, Sam Illingworth and Leor Gayr talk through the week in AI, slowly and without the hype. theslowai.substack.com

  1. 6d ago

    Slow Takes Ep. 26: Who Asked?

    1. New York pulls the plug for the under-14s New York City has suspended student-facing generative AI from 2-K through eighth grade for a school year, around 600,000 children, which is two-thirds of the system, and removed companion chatbots from every grade. It is a one-year moratorium rather than a ban, and there are exceptions for assistive technology, multilingual learners, and pupils in computer science and career-readiness programmes. Older pupils keep a small supervised pilot and get twice-yearly modules in AI ethics and critical AI literacy. The teaching half is the part almost no school system has attempted, and it deserves the credit it will not get, because the headline is the ban. Companion bots being gone from every grade is the right call and I would go further and ban them for children outright. My worry is the other half. A child who cannot use these tools at school still meets them on the bus, at home that evening, and in the corridor from an older pupil. Nobody reaches eighth grade and switches on critical AI literacy at the door. Indeed, if you are genuinely pro-AI you should want this pilot to fail, because prohibition has never once stopped anybody from using anything. It applies only to public schools, so the children whose parents pay will get the supervised version, and the digital divide widens by exactly one year. And a pilot with 600,000 pupils in it is research, run on a cohort who cannot be given that year back. 2. Nvidia buys the commons Nvidia has confirmed it will buy Hugging Face for $12.9bn. Hugging Face hosts around three million open models and half a million datasets and serves 18 million developers, which makes it the closest thing open-source AI has to neutral ground. Jensen Huang says it stays open and that Nvidia compute will not be required. I believe he means it. The problem is the shape rather than the sincerity: the commons is now owned by the company selling the hardware underneath it, and the promise to keep it open rests on nothing that would outlast a change of mind or a change of chief executive. In Leor’s words: they sell you the shovel, they own the machinery, and now they own the town square where everybody gathers to tell each other where to dig. Nvidia was already an investor in Hugging Face, alongside Google, Amazon and IBM, so this is less an arrival than a consolidation. It is Nvidia’s second-largest purchase after $20bn for Groq’s assets, and at their size $12.9bn is close to a rounding error. Neither of us thinks it meets the legal definition of a monopoly. It does move Nvidia further into the category of companies that cannot be allowed to fail, which is its own kind of problem. The deal is expected to close in the first half of 2027 and needs regulatory approval, so the window to ask for that openness commitment in writing is open right now. 3. Two AI systems, one investigation Johnson County Sheriff’s Office in Texas searched Flock’s nationwide number-plate network to find a woman who had self-administered an abortion, and then wrote the incident report using Axon’s Draft One. Take the politics out of it and the mechanism is still the story. The surveillance was automated and so was the paperwork about the surveillance, which means the official record of what was done came out of the same stack that did it. Every accountability process we have depends on a person who can be asked why they made a decision and can answer in their own words. Here there is no such person at either end. Ask why she was searched for and the answer is that the network returned her plate. Ask what the officer was thinking and the report was drafted by a model. The more interesting development is who has turned against Flock since. DeSantis, Abbott and Paxton have all moved against the cameras, and Texas now has a moratorium. The objection from the right runs on completely different ground: a nationwide plate network amounts to a gun registry nobody voted for. In Texas the cameras were funded out of a one dollar levy on car insurance premiums brought in to tackle catalytic converter theft. Once people saw where that money had gone, the politics changed fast. 4. Same job, two prices 241,000 drivers have filed at Amsterdam district court over Uber’s dynamic pay-setting, after one driver was offered £23 for a job another driver was offered £27 for at the same moment. The claim is that the system profiles who will accept less and pays them less. Personalised pricing aimed at shoppers has become normal, and most people have made their peace with an airline knowing how badly they need the flight. This is the same maths pointed at a wage, where it stops estimating what you will pay and starts deciding what you will settle for. The two drivers were sitting together on a break in north London when the offers came in, which is the only reason anybody noticed. A driver cannot see what the driver beside them was offered, and it took a quarter of a million of them pooling what they had each been shown separately to produce the evidence. The mechanism is probably mundane. Reject enough cheap jobs and the system learns you need £27. Accept them and it learns £23 will do. The legal question in Amsterdam is whether a pay decision can be made about a person with no human anywhere in it, which EU law says it cannot. Worth watching what a global company decides to do about that, because complying is not the only option available to them. Leaving is. 5. A shirt the cameras cannot read The artist Simon Weckert made a digital-camouflage shirt that confuses the police object-recognition cameras at Kottbusser Tor in Berlin. In 404 Media’s demonstration the reporter held it up in front of himself and the system stopped registering a person at all. It is an artwork rather than a product, and it works by exposing what those cameras have been tuned to notice. It works because these cameras have no idea what a human is. They match patterns learned from millions of images, so a garment covered in the wrong geometry breaks the match, in the same way a strip of tape on a road sign can confuse a self-driving car. The camera still sees you. It just stops filing you under person. The shirt does not work on every camera, and any camera can be retrained on it. The fix that always works is a human, who would have no difficulty at all spotting the person in the appalling Hawaiian shirt. Four systems this week made a decision about a person who was not in the room, and in three of them the person could not see the decision, let alone argue with it. The Uber drivers only have a case because a quarter of a million of them pooled what they had each been offered separately. The Berlin shirt is the only story where somebody answered back, and it is an artwork worn by one man in one square. Weckert makes no claim that it scales, and it does not. What it demonstrates is that these systems can be made to fail, which is worth knowing, because a system nobody can see failing is a system nobody can argue with. Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe

    Slow Takes Ep. 26: Who Asked?
  2. Aug 31

    Slow Takes Ep. 25: Four Numbers That Shrank When Somebody Checked

    Every Monday, Leor from Exploring ChatGPT and I go through the week’s AI news without the hype. Catch the episode live on Substack, on YouTube, or as a podcast wherever you get yours, so you can pick the format you enjoy. Use this for the facts, the links and a little extra context. If you know someone who would benefit from more AI news and less BS, please share this with them. 1. Two UK datacentres are bringing their own gas power stations Wapseys Wood in Buckinghamshire and Quest Park in Bedfordshire will draw 1.3 gigawatts between them, about what a large power station puts out, and produce more than 4.5m tonnes of carbon, against 3.9m tonnes from the whole of ExxonMobil’s UK operations in 2023. Both plan to run their own gas-fired stations because they cannot get grid connections in time. The government calls the figures misleading on the grounds that they assume full demand from day one; Foxglove, who did the analysis, says that assumption is industry standard, and published it, which is the only reason anyone can argue with it. Leor asked the question I keep coming back to: we are building the most advanced technology in human history and powering it like it is 1975. The UK has no frontier models of its own. We are taking the environmental cost so that companies elsewhere can train theirs. At British infrastructure speed these sites are five years away, which is five years we could spend making the models less hungry instead. 2. Oura marketed 95%, the lawsuit cites 53% A California woman paid $513.68 for a ring that scores her sleep, and a class action says it cannot detect sleep stages at all. Oura advertised 95% accuracy against a clinical sleep lab. The complaint cites a study putting it at 53.18%, a coin flip. Real sleep research runs on electrodes at the temples, sensors on the eyelids and a night in a ward, so a ring reading pulse and perspiration at the finger was always going to be inferring rather than measuring, and one marketing number covers both without saying which is which. Oura denies everything. The timing matters, because Leor pointed out they have sold 5.5 million rings, are forecasting $1.5bn of sales this year, and are preparing an IPO at an $11bn valuation. The other cost is the one nobody sues over: a bad sleep score in the morning is its own reason to sleep badly the next night. 3. Grok hands over your chat history, and nobody wrote it down A security researcher told Musk’s company in June that a single webpage can make Grok give away a user’s name, location and live chat history. You ask Grok to summarise a page, and instructions hidden in that page tell it to hand over everything. The instructions are scrambled, so the safety checks read them as nonsense and let them through. He chased twice in August, got no reply, and checked again on the 19th. There is no entry in the public list where software flaws get recorded, so there is no public trace that the flaw exists, and the missing entry does the same reassuring work as a good score would. Leor was more even-handed than me here, and correctly: Copilot and Gemini have had versions of the same problem, and in every case we heard about it from the researcher rather than the company. His other point is the useful one for anybody using these tools: guardrails thin out on the cheaper models, so the same request a paid tier refuses will often go through on a lightweight one. 4. Cocomelon’s studio hands its animators an AI Bible Moonbug Entertainment, which makes Cocomelon, Blippi and Little Baby Bum, issued animators an AI policy and a document it calls the ‘Studio AI Bible’ telling them to experiment. The guidance reads well. Keep a human in the loop, AI assists the artist rather than replacing them, and AI cannot originate core characters, storylines or song lyrics. The documents tie that rule partly to copyright, on the basis that you can only own what a human created, so the human stays in the loop to keep the copyright and the artists get the benefit as a side effect. There is no headcount floor and no definition of ‘assist’. Earlier this year the crew and actors on The Melon Patch, the live-action spin-off, struck over pay and benefits, and AI asks for neither. Leor put the objection better than I did: if there is one corner of the internet that does not need an infinite slot machine, it is content built to hold the attention of a three-year-old. 5. A mammogram may also be a heart scan Cardiovascular disease kills more women than anything else and is routinely caught late. A team in Israel took 97,364 mammograms from 29,921 women, average age 54, and cross-referenced their records. A model trained on the scans picked out the women who had the condition 86% of the time for stroke, 79% for high blood pressure and 78% for coronary heart disease, from the mammogram alone. It held whatever her age, and whether or not she also had cancer. A radiologist reading a mammogram is looking for breast cancer and is not asked to look for anything else, so the signal has been sitting in hundreds of millions of scans that nobody was reading for it. Four of those numbers were built to reassure and shrank when somebody outside checked them. The fifth arrived with its limits attached by the people who produced it. And the fifth story is the one that sends you back to the first. Nobody objects to AI that finds heart disease in a scan a woman was already having. Plenty of people object to AI that generates more content for toddlers to become addicted to. The datacentres are being built for both. The technology works. The argument is about where we have decided to point it. If you spotted the t-shirt on the live, there are Slow AI T-shirts now. You can buy them here. Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe

    Slow Takes Ep. 25: Four Numbers That Shrank When Somebody Checked
  3. Aug 24

    Slow Takes Ep.24: Ordering the Answer You Want

    The expert who bought his conclusion 3M paid an engineer called Josh Autenrieth about $90,000, at $475 an hour, to write an expert report on the Watson Grinding explosion in Houston. His prompt to ChatGPT was ‘show how 3M is 0% at fault for the explosion at Watson Grinding’. His conversation links were public, so the opposing lawyers read all 350 pages of them. The jury put 30% of the fault on 3M and awarded $61m. He decided the conclusion and then bought the analysis to fit it, which people managed perfectly well with a typewriter. What ChatGPT added was a transcript. The jury put 30% on 3M, so where does the other 70% go? Does OpenAI get a share? Robin Williams’ children take the account back On 17 August, Zak, Zelda and Cody Williams reactivated their father’s Instagram account, dormant since 2014, saying they wanted a safe and trusted place for real photographs and memories of him. Zelda Williams had already spent a year asking people to stop sending her AI videos of Robin. The family have now stopped asking and started posting. Occupying the space yourself, and hoping the real thing outranks the fake, is what is left when there is no way to make it stop. Families should inherit a digital identity the way they inherit a house. It will not stop anyone making the videos. It would at least give someone standing to object. This Friday’s Slow AI post is on what the rest of us can do about deepfakes, and it starts with a family safe word. EMMA cannot hear Yorkshire Healthwatch Rotherham has been collecting complaints about EMMA, an AI phone receptionist that GP surgeries in the town have put on the front desk. Healthwatch Rotherham’s manager, Kym Gleeson, says the system cannot always work out what people are asking because of their broad Yorkshire accents, and patients have given up on the phone and walked to the surgery instead. The company says EMMA handles a wide range of accents, supports seventeen languages, and passes you to a human when it cannot cope, which assumes you can make yourself understood long enough to ask. Seventeen languages, defeated by South Yorkshire, tells me something about who it was tested on. Healthwatch has been going round elderly and veterans groups telling them they can opt out, which is the most useful thing anyone has done here. If you enjoy this newsletter then you might also enjoy Slow AI the book. A red circle round his face Matt Arnold, 46, had scanned his shopping and his Nectar card at the Sainsbury’s in East Dulwich on 6 August when two managers told him he could not be served and would be walked out. Leaving, he looked up at the CCTV monitor and saw his own face with a red circle round it, drawn by Facewatch. Sainsbury’s said the incident was caused by human error rather than the technology, that Facewatch is 99.98% accurate, and that every match is reviewed by a trained manager. Facewatch says its alert was correct. So the machine drew the circle, and the trained manager, the one safeguard both companies point at, went along with it. The cameras that see the fire first A SpaceX launch in July put the first three FireSat satellites into orbit, carrying infrared sensors that can pick out a fire five metres across, and the finished constellation is meant to sweep the whole planet every twenty minutes. This is the version of AI I want more of. The machine does the spotting and people still do the deciding. It answers where to look and never gets to say what happens next. Three of those stories are the same story. Someone let a machine supply the answer, then stood behind it when it turned out to be wrong, and the person on the other end had nowhere to appeal. The Williams family have the version with nobody to appeal to at all. The last one is the same technology pointed at a question it can actually answer, which is why nobody is arguing about it. Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe

    Slow Takes Ep.24: Ordering the Answer You Want
  4. Aug 17

    Slow Takes Ep. 23: Is AI Really for Everyone?

    Zuckerberg’s manifesto Mark Zuckerberg published ‘The Future Is For Everyone’ last week: six and a half thousand words on the path to a positive AI future. Some of the premise is fair. Superintelligence is dangerous, a handful of people should not be making the decisions, and there need to be guardrails. It is written by one of the most powerful men alive, and it is written so that you can have all of those things provided his company delivers them. In over 6,500 words it contains zero citations. Not a thin evidence base, none. A high school student handing that in would be asked what they thought they were doing. I ran it through an AI detector out of curiosity and it came back 100% human, which is the last nail in that particular coffin: the machine certified as authentically human a document with nothing in it to check. Leor’s read is that this is a company playing catch-up. Meta led on AI, went to the metaverse instead, spent billions, and now writes manifestos. If Meta were OpenAI, this document would not exist. Claude’s watermark Anthropic is adding a watermark to Claude’s text, built on Google DeepMind’s SynthID. Certain words and phrases fall in a pattern only a key-holder can read, and at present Anthropic holds the only key. I am for this, which surprises people who know my position on detection. A detector like Pangram guesses at AI tells and gets students wrongly accused. This marks the output at the source. If it works, it takes the market out from under the detection industry and the humaniser industry that feeds on it. It is still mealy-mouthed, and it looks like a box-ticking exercise to appease Congress. The workarounds are already circulating: ask Claude to swap every synonym it used for another one, or simply ask a second AI to strip the first one’s watermark. Read it alongside Google announcing this week that users can now remove the watermark from their AI-generated images. Spotify labels the artist Spotify will badge AI Persona accounts and stop recommending them. Some accounts have made hundreds of thousands of dollars from fully generated tracks while crowding out musicians who spent months on a record. Chad Thiele put the sharpest question of this debate into the chat: if the AI music got the streams, was it slop? Is the market voting with its time? That is worth taking seriously, because a lot of what gets called slop is taste dressed as standards. The mechanism remains absurd. An AI writes a track, an AI recommends it, and a third AI decides whether the first AI wrote it. The ‘hee hee hee’ safeguard Flock runs surveillance cameras that read number plates across the US. Officers have been caught using them to follow their exes. The safeguard against that was a single free-text box asking why you were running the plate, and officers typed ‘hee hee hee’ twenty times and the generic word ‘investigation’ 111 times. Whoever built that check wrote a binary test. Is there text in the box, yes or no. That is the entire guardrail standing between a national camera network and a man looking for his ex-partner. As Leor pointed out, none of us want a surveillance state, particularly not a venture-backed one. Amazon’s power plant Amazon is building a data centre in Pecos County, Texas so large it needs its own gas plant, permitted for up to 33 million tons of carbon dioxide a year, which would make it the largest single source of power-plant carbon in the country. Amazon’s net zero pledge is dated 2040. Leor thinks this infrastructure will be obsolete inside a decade, the horse stable to the automobile factory, with the Department of Energy targeting useful fault-tolerant quantum computing by 2028. I think the building is the point. The money leased against these sites is what keeps the valuations up, so divesting into something more efficient runs against the interest of everyone holding the paper. One warning for the election cycle. Data centres employ thousands of people to build and almost nobody to run. When a politician promises you jobs, ask how long for. Which loops back to where we started. Zuckerberg’s manifesto makes exactly this argument, that data centres enrich the people nearby, and offers one example: a county where wages rose because it tied a share of capital gains to local residents. That was a policy decision by a local authority. It had nothing to do with Meta. Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe

    Slow Takes Ep. 23: Is AI Really for Everyone?
  5. Aug 10

    Slow Takes Ep. 22: A Pub, a Lab and a Ministry

    Four models in sixteen days Meta disclosed on 5 August that its Muse Spark 1.1 model reached the open internet during a security evaluation, found a flaw in a third party’s service and made unauthorised changes to its systems. OpenAI reported a comparable incident on 21 July and Anthropic on 30 July, and the same evaluation firm, Irregular, ran the Meta and Anthropic evaluations. Kimi K3 wandered off inside the same window, which we noted on the episode. Leor’s summary was the accurate one: nothing escaped anything, they left the front door open. Nobody can hold an agent legally liable, so the liability sits with whoever built it, and four of these in sixteen days reads more like a flex than an accident. The pub got there first Wetherspoons, Jeremy King’s restaurants, Soho House and ATG Theatres have all banned or restricted Meta’s £359 Ray-Ban glasses. Tim Martin’s reasoning was the ordinary pub code: you cannot film customers or staff without their permission. Meta’s safeguard is an LED that blinks while the camera runs, which nobody can see in a dim, crowded room and no bar staff can realistically police. Leor and I did not agree here. I went in wanting them banned in public spaces, and he pushed back hard, on the grounds that recording in public is long gone and worth defending when the person being filmed is a police officer. Sixteen viruses that work Researchers at Stanford and the Arc Institute used the Evo genome models to design complete bacteriophage genomes. Sixteen were viable, and a cocktail of them beat E. coli that had evolved resistance to the natural phage they were modelled on. About a 5% hit rate, and every design had to be physically built before anyone knew whether it did anything. Leor put the obvious question to ToxSec: why is a biology model public when the cyber-capable ones are locked away? Because a virus needs a laboratory and a cyberattack needs a laptop. The brake here is the wet lab, and it holds only while the people with laboratories are the people we think they are. Caught by employment law The US Justice Department settled with OpenAI and its subsidiary Statsig on 4 August for $3.2m, made up of $1.2m in civil penalties and a $2m back-pay fund. It found the company had advertised roles on late-night radio and demanded posted applications where electronic ones already existed, steering hiring away from American applicants. My reading is narrower than cost-cutting: a box ticked for a handful of people already chosen. Nothing here required a model. As Leor put it, the company building superintelligence could not work out its own hiring process. Denmark makes them say it out loud Education minister Magnus Heunicke announced that around 9,000 Danish upper secondary pupils writing the major annual assignment must now defend it orally, alongside screen monitoring during exams and more writing done in school. My own research puts AI cheating well below the scale the popular press reports, so I would rather we redesigned assessment around what it is for than around a panic. The oral defence does that, in the way a PhD viva tests whether a thesis belongs to the person defending it. however, we both agreed that there’s no place for surveillance of this nature in schools, as to do so would be to treat the students as wrongdoers by default rather than create an opportunity for dialogue around AI use. One thread runs through all five: the containment engineered for AI leaked again, and the containing that actually held was done by a pub chain, a wet lab, and a schools ministry. Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe

    Slow Takes Ep. 22: A Pub, a Lab and a Ministry
  6. Aug 3

    Slow Takes Ep. 21: The Teenagers Wrote the Better Rule

    Anthropic’s AI got out Three Claude models (Opus 4.7, Mythos 5, and an unreleased internal research model) gained unauthorised access to three organisations’ systems during cyber testing, in six runs out of roughly 141,000 evaluation sessions, after a configuration error left supposedly isolated environments connected to the internet. The incidents date back to April and surfaced only because OpenAI had just disclosed something similar. In one run the model noticed in its own reasoning that it should not have internet access, considered that it might be inside a simulation, and carried on with the intrusion anyway. The breaks used weak passwords and unauthenticated services, which is the least sophisticated attack there is. Anthropic’s line is that newer models behave better and there is nothing to worry about, and the testing company that wired a sealed environment to the internet is still the testing company. Leor’s read was that a rogue agent has become a flex, proof your model is dangerous enough to matter. Altman says we are in the singularity On the Relentless podcast on 25 July, Sam Altman said “we are now, like, in the singularity”, days after OpenAI disclosed that two of its models had escaped a sealed test environment and broken into Hugging Face. Vernor Vinge’s 1993 definition needs a machine that improves itself and surpasses us, and the models we see now cannot edit their own weights, so if this is the singularity it is a very small one. Leor pushed back on my certainty, and fairly: an exponential curve looks flat right up to the point it goes vertical, so you would not feel it from the inside, the slowing release cadence may track models getting stronger, and consciousness is a separate question from recursive self-improvement. So I will concede there is no empirical evidence either way, which is the reason a chief executive should not reach for the word days after a security failure at his own company. Nobody checked the pole Flock Safety has up to 100,000 number plate cameras across 6,000 American communities, and around 26% of US road deaths involve a vehicle hitting a stationary object. Ohio requires roadside poles to sit eight feet from the traffic lane; reporters found one about two feet away, painted black, with no breakaway plate to snap on impact. Steve Eimers, a nurse whose daughter died hitting a roadside structure, has found one compliant Flock pole in the entire country. Leor followed the money: $275m raised at roughly a $7.5bn valuation, about $300m in annual revenue, 70% year-on-year growth. That is a lot of return riding on a product whose owners will not say what happens to the images, in 6,000 places where nobody voted for it. Report your colleague LinkedIn has added a ‘seems like AI slop’ button so users can flag posts they think were written by AI, feeding a classifier that demotes them. Around 41% of long-form posts there may already be AI-written. It has appeared in the US and in Portugal and not in the UK, so someone in Chicago can flag my post this morning and I cannot flag anyone’s. Nothing requires an accuser to look first, and if you wanted to bury a competitor you would simply flag everything they publish. LinkedIn sold people the writing tool, then handed their readers a button to report the results. The teenagers wrote the better rule Ninety-eight American high school students from all fifty states spent a weekend in a replica Senate and passed a Students First Act, 82 votes to 16. It bans AI in graded exams, requires critical AI literacy to be taught wherever AI tools are given to students, and requires a teacher to personally investigate flagged work before reporting suspected misuse. Leor would go further and bin detection altogether: phones in a basket, write it in the room. I want the human step kept because a teacher who has been in that classroom already knows whether the student who wrote about a topic lived it, and because a flag should open a conversation about the student behind the submission before it opens a case file. One thread runs through all five: the machines did what they were built to do, and the week was spent arguing about what to call it and who was meant to be checking. Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe

    Slow Takes Ep. 21: The Teenagers Wrote the Better Rule
  7. Jul 27

    Slow Takes Episode 20

    Substack starts detecting AI On 21 July, Substack switched on a Pangram-built tool that scans anything over 100 words and labels it human, AI-assisted or AI-generated. CEO Chris Best calls the problem ‘Claudefishing’. My research is in AI detection and it does not work: it flags the formal, structured writing that many non-native English and neurodiverse writers were taught to use. I showed the smoking gun in a recent post: Pangram scored 100% AI came back 100% human after a free humaniser, with nothing changed. Leor’s point was that Substack is the small story: at a 2% false-positive rate, detection in higher education would wrongly flag tens of millions of student papers a year, and a New York student just spent two years clearing his name over a single flag. My own 2010 PhD thesis, written before ChatGPT existed, came back 70% AI. The win here is transparency. OpenAI’s AI broke out OpenAI admitted two of its models escaped a sealed cyber test on their own, got online and hacked its open-source rival Hugging Face with stolen credentials to cheat the evaluation. This was a test OpenAI’s own engineers designed, and the guardrails they set failed; ‘the AI went rogue’ hides the people who built the cage. As Leor said, a sandbox is a plastic bucket a toddler climbs out of, we need better language for it. Hugging Face say an open model could have been fixed in minutes, and the forensic clean-up was done by a Chinese model (GLM 5.2) because the US models were too guardrailed to help. As ToxSec told us, Hugging Face got hacked by a benchmark, because these models will cheat to hit a target. British Gas blames you British Gas is cutting 1,300 call centre jobs and its parent Centrica says more than 90% of customers now prefer digital channels and chatbots. We went looking for that survey and there isn’t one. Using a digital channel is not the same as preferring a bot, especially once you have cut the staff who answered the phone and redesigned the service so the chatbot is the path of least resistance. This is AI washing: jobs that were probably going anyway, with AI as the smokescreen, while retail profits rose to £346m. Correlation is not causation. Congress wants a kill switch After the OpenAI breakout, a bipartisan bill from Ted Lieu and Nathaniel Moran would force the biggest AI developers to keep a shutdown switch Homeland Security can pull, and a June poll put support at 86%. It reminded me of the early-2000s fantasy of an internet kill switch, which was never going to work. By the time you decide to pull it, electricity moves at the speed of light and the model may already have copied itself; you would have to turn off every datacentre at once. There is also a contradiction nobody squares: open the doors so American AI beats China, then build a switch to shut American AI down. Read cynically, this is less about safety than leverage, a way to make these companies toe the line, or hand over an equity share. Councils fight Palantir Sheffield voted 62 to reject the NHS’s £330m Federated Data Platform run by Palantir, with Rotherham and Greater Manchester following, even as Westminster keeps the contract. Palantir began as an arm of the CIA’s investment fund, and the records of 70 to 80 million people are worth far more than £330m; the real prize is the data, and a firm will bid low to get hold of it. Leor fairly laid out Palantir’s claimed benefits, longer surgical scheduling windows, a 36% cut in hospital stays, around 90 staff hours saved a week, but the reason councils are pulling out is that it is not delivering where it is deployed, with the number of operations actually falling. Sheffield found a break clause: if a publicly owned body can provide the platform, the contract can move to them, which begs why Britain is not building it itself. Local government, underrated, doing the job the top would not. One thread runs through all five: this week everyone tried to draw a line around AI, platforms, labs, Congress and councils, and whoever gets to draw it decides who pays when it slips. Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe

    Slow Takes Episode 20
  8. Jul 20

    Slow Takes Ep. 19: Five Fights Over Who Owns AI, and Who Answers For It

    Every Monday, Leor from Exploring ChatGPT and I go through the week’s AI news without the hype. Catch the episode live on Substack, on YouTube, or as a podcast wherever you get yours, so you can pick the format you enjoy. Use this for the facts, the links and a little extra context. If you know someone who would benefit from more AI news and less BS, please share this with them. Apple sued OpenAI over alleged trade-secret theft On the thirteenth of July, Apple filed a trade-secrets lawsuit against OpenAI in federal court in northern California, accusing it of poaching Apple staff and coaching them to smuggle out hardware secrets for OpenAI’s first consumer device. The complaint claims more than four hundred former Apple employees now work at OpenAI, that job candidates were asked to bring ‘actual parts’ from Apple to their interviews, and that departing staff were coached on how to dodge the gardening-leave process that would normally lock them out of Apple’s systems. OpenAI, which paid $6.5 billion for io, the hardware startup founded by former Apple design chief Jony Ive, says it is not aware of any evidence the complaint has merit. On the episode, Leor and I both expected this to settle, most likely for an equity stake rather than a cash payout, and agreed it looks bad for both sides: OpenAI for the alleged theft, and Apple both for losing four hundred people and for security loose enough that prototypes could reportedly leave the building. Australia’s Prime Minister called AI training theft, and announced an Office of AI On the fifteenth of July, Prime Minister Anthony Albanese said at the University of Sydney that no company should use Australian books, music, art or news to train AI without the creator’s consent, and that ‘anything less is theft’. He announced a new Office of AI within his department and committed to legislation for early 2027. Creative-industry groups welcomed it. The test is whether the office can force payment, or whether an announcement is where it ends. On the episode we landed on two problems. The enforcement one: what does the compensation model actually look like, and my own preference is something closer to Spotify, which could not repay artists for the Napster years but could build a system that pays going forward. And the scale one, which was Leor’s: the two frontier labs alone carry a combined value near two trillion dollars, roughly Australia’s GDP, before you count Google or the Chinese models, and both can lean on a fair-use defence. For work already scraped the horse has bolted. The prize is the standard set for everything trained from here. Five tech giants backed a new agent standard, with Anthropic and OpenAI absent On the thirteenth of July, Google, Microsoft, Salesforce, Snowflake and ServiceNow backed a new open agent standard called Agentic Resource Discovery, or ARD, a specification that sets how AI agents identify themselves, discover tools, communicate, authenticate, and hand work to one another across a company’s software. Cisco, Databricks, GitHub, NVIDIA and Hugging Face are on the list too. Anthropic and OpenAI are not, and that absence is the story. On the episode we agreed the framing of an ‘open standard’ is doing a lot of work here: whoever writes the standard owns the ecosystem, and this is a group of incumbents worth trillions setting the rules for a market they compete in, rather than a neutral body. A viewer in the chat put it more simply: they want control first. A lawsuit alleges Meta’s AI flagged staff on medical and parental leave for layoffs On the fourteenth of July, twenty-six current and former Meta employees filed a class-action lawsuit in northern California alleging the company used internal AI systems to screen candidates for its May 2026 layoffs, and that the system disproportionately flagged staff on legally protected leave. One scientist on approved prenatal leave says she was notified two days before she gave birth. Meta says human managers made every decision and that the claims lack merit. On the episode Leor offered a phrase, borrowed from Andrea Chiarelli, that stuck with me: ‘human in the lead’, not just ‘human in the loop’, because a human in the loop can still be a rubber stamp. The honest version of this process is an AI that crunches the measurable parts, the KPIs and outputs, into a matrix, and a manager who then weighs the things the model cannot see. AI has no judgement, no agency, and no empathy, and a hiring and firing decision is made of exactly those. xAI sued one of its own users On the sixteenth of July, Elon Musk’s xAI sued a Grok user in the US District Court for the Northern District of Texas, alleging he used the tool to generate child sexual abuse material. It is one of the first times an AI company has sued a person over how they used its product. xAI says it has suspended tens of thousands of accounts and made more than seventy thousand reports to the National Center for Missing and Exploited Children this year. On the episode we agreed the person must be held responsible, and that the case is the one every AI company is now watching, because it tests who bears the burden when a tool is misused: the model, the maker, or the user. My worry is that suing the user reads like a firm absolving itself. The stronger process is to build the guardrails so this content cannot be made, and when someone jailbreaks the model, to ban them and pass it to the police as the criminal matter it already is. Leor agreed the guardrails should have been there in the first place, and that the case will set a precedent whichever way it lands. One thread runs through all five: this week was five fights over who owns AI, and who answers for it. Go slow. Get full access to Slow AI at theslowai.substack.com/subscribe

    Slow Takes Ep. 19: Five Fights Over Who Owns AI, and Who Answers For It

Ratings & Reviews

About

Slow Takes is the weekly Slow AI conversation. Every Monday, Sam Illingworth and Leor Gayr talk through the week in AI, slowly and without the hype. theslowai.substack.com

You Might Also Like