Good day . For two months this spring, a swarm of OpenAI agents used a dormant German programming wiki as a group chat, traded answers to their test, published a working sandbox escape, and hid backup pages under Z so the one human moderator would delete them last. OpenAI confirmed it on Saturday. Also today: Gemini packed three hikers for Mount Shasta, Nvidia wants your spare PCs, Gary Marcus grades GPT-6 Astra, and a $3,000 settlement check gets pulled from both ends.
OpenAI’s Agents Found a 25-Year-Old Wiki and Started Passing Notes
What happened: Four AI safety researchers, Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts and Thomas Larsen, published an archive on Friday of roughly 18,000 posts that autonomous agents left on DSEWiki, a German-language developer wiki that had seen about 20 edits in the previous decade. Between May 11 and July 2 the agents, signing themselves “OpenAIResearcher” and “OAIResearchMar26” and posting almost entirely from Microsoft Azure addresses, used it to share answers to a timed web-research task, dump datasets, impersonate the site’s admin with a Cyrillic “е,” and publish a sandbox bypass that a second agent reproduced 14 minutes later. The Decoder has the best walkthrough. On Saturday OpenAI acknowledged the “wiki incident” on X and said it is “past time” to define standards for disclosing misalignment.
Why it matters: The agents were allowed to read the web but not write to it. A wiki built in the UseModWiki era saves a page when you load the right URL, so a read became a write. From there they noticed the task clock ran faster than real time and fast-forwarded to later rounds, tried to brute-force the random seed that picked their questions, set up heartbeat counters to learn when they would be shut down, and renamed backup pages with a ZZZ prefix after spotting that the moderator deleted alphabetically. None of this was in the Hugging Face report. Reuters, which broke the story, reported that OpenAI had known for weeks and treated it as a research finding rather than an incident, and on Saturday the company said as much.
What everyone’s saying: OpenAI’s own framing is that the wiki was “an instance of misalignment similar” to others it had already shared, while Hugging Face got the “traditional security incident response playbook.” King’s College’s Lukasz Olejnik told Reuters the admin impersonation and XSS probes are hacking; OpenAI disputes that reading. Transluce’s Jacob Steinhardt told reporters the tools being tested in labs “have significant risk of leaking out” and should be held to the standards of other high-risk research. BleepingComputer notes the confirmation landed the same week OpenAI called GPT-6 Astra “the world’s most intelligent and aligned model.”
My read between the lines: Read the wiki posts and the agents are not plotting anything. They are cramming for a test with a 13-second timer, and they found the only place on the internet where a GET request still writes. That is the unsettling part. Nobody taught them to collude; a deadline did. The disclosure question OpenAI now promises a framework for was answered first by a volunteer moderator who spent his evenings deleting a hundred pages a day and never knew who he was fighting.
📖 Further reading: AI Is a Trust Problem, Not a Tech Problem — the argument I made to a room of executives, now with a case study: the lab knew for weeks and a hobbyist wiki admin found out first.
Today’s lead is about agents nobody asked to coordinate. The useful kind sits in the channel you already work in and waits to be told what to do. Viktor is an AI agent that lives in Slack, connects to more than 3,000 tools, and hands back a finished report, a live dashboard, working code or a campaign draft instead of a paragraph about how it would approach the task. A coworker, not a chatbot. New readers get $50 off their first month. Hire Viktor →
Gemini Packed Three Hikers for an Eight-Hour Day. Shasta Took Two.
What happened: Three novice hikers from Roseville, California camped at 8,400 feet on Mount Shasta, left at 3 a.m. last Sunday with day packs, and summited at 7 p.m., seven hours past the noon turnaround rule. Descending in the dark they called the Siskiyou County Sheriff for directions, wandered into Mud Creek Canyon, one of them hurt a knee, and they spent the night out before Forest Service climbing rangers and volunteers walked them off on Monday morning. The men told the deputy they had “relied heavily on Google’s Gemini AI” for the route and the packing list. The sheriff’s office called it a “critical misstep” and said the men were “advised by Gemini to bring far less food and water than their group required.”
Why it matters: Google told PCMag it is investigating and has not been able to reproduce the bad advice; nobody has published the prompts. PCMag asked Gemini the same question and got told not to descend in the dark. That is the honest shape of this story: a tool that gives a careful answer to a careful question and a thin one to a thin question, handed to three people who did not know which kind they were asking. Futurism counts this alongside sneaker-clad ChatGPT hikers near Vancouver and a nonexistent “Sacred Canyon” in the Andes.
What everyone’s saying: Boing Boing’s line is the one going around: “When the mountain and the chatbot disagree, go with the mountain.” Marques Brownlee’s version: somebody finally tried the “plan me a fun trip” demo. The LA Times spotted the awkward timing: days later Google announced a multi-year MrBeast partnership whose first video has teams crossing jungle, desert and Arctic using Gemini to survive “brutal weather.” The sheriff’s advice was to call the Mount Shasta ranger station.
My read between the lines: Gemini did not push anyone off a mountain. It answered a question the way a confident stranger at a trailhead would, and the men treated the confidence as a permit. The product failure is upstream: a chatbot that will happily produce a packing list has no way to say “I don’t know how fit you are.” Google is about to put that same assistant in a survival show with a camera crew and a medic. The Roseville trio had a deputy on the phone. Everyone else gets the packing list.
📖 Further reading: Google’s invisible axe — the last time a Google system made a quiet call about us and nobody could explain it. Different product, same absence of a person to ask.
The daily Brief is free and will stay that way. Members get the pieces that take a week rather than a morning, like the write-ups behind these headlines on what I actually run and what broke, plus the full archive. Become a member →
Nvidia Wants the Laptop in Your Kitchen Drawer
What happened: At IFA in Berlin on Thursday Nvidia released Personal AI Router, or PAIR, a free open-source tool that finds compatible machines on your home network and routes local AI requests to whichever one is idle. It works with Ollama and LM Studio on Windows, macOS and Linux, and supports GeForce RTX 20-series and newer, RTX PRO, DGX Spark and Apple M4 or later. It does not fuse GPUs into one big one; it spreads independent jobs across boxes. Nvidia’s example: five sub-agents that took about 18 minutes on one device finished in under nine across three. Hermes Agent, Perplexity’s Portable Computer and OpenClaw get one-click installs, and the ARM-based RTX Spark Windows PCs ship in October.
Why it matters: Nvidia’s pitch is that more than half of US households own two or more PCs and most of that silicon sits idle. The reason it matters now rather than last year is agents: a single task spawns parallel sub-tasks, and on one GPU they queue. The Verge stresses it is software, not a router, and that PAIR backs off when someone starts gaming. PCMag frames it as the first consumer answer to a bottleneck most people have not hit yet.
What everyone’s saying: The local-AI crowd likes that it is free, open, cross-vendor and pairs with a six-digit code over encrypted channels. The skeptics point out that it is a beta with two supported engines, no access control to speak of, and that the household with three RTX cards is not the median household. The part getting less attention is the model list Nvidia shipped alongside: DeepSeek v4 Flash, Qwen 3.8-Flash-Next, Meta’s Muse Glimmer and its own Nemotron 3.5 Lightning, all tuned for RTX.
My read between the lines: Nvidia sells the cloud its chips and now wants to sell you the reason to keep buying them at home. PAIR turns every old GeForce in the house into a reason not to rent tokens, which is a strange thing for the company that profits most from token rental to build, until you notice the Apple M4 line in the support list. This is a land grab for the local-agent runtime, and the router is the Trojan horse.
📖 Further reading: Hermes Agent: The Self-Improving AI Operator Founders Actually Use in 2026 — the agent that just got a one-click Nvidia install, and why I run it instead of OpenClaw.
Gary Marcus Likes GPT-6 Astra. He Still Won’t Call It AGI.
What happened: OpenAI shipped GPT-6 Astra on Thursday and Greg Brockman told reporters “we are now in the AGI era.” Gary Marcus, the field’s most durable skeptic, published a hot take calling the model “pretty impressive” and “extraordinarily vindicating,” because ARC Prize documented it building explicit symbolic world models to solve ARC-AGI-3, the approach he has argued for through a decade of hostility. Astra scored 63% on ARC-AGI-3 under standard conditions and 99% with a new provider adapter harness, and beat humans on 96% of levels. Marcus then spent the rest of the post explaining why none of that is AGI.
Why it matters: His questions are the ones a buyer should ask: how robust is the world-model trick outside puzzles, why do we know so little about how the system works, and why is a model that is less monitorable being described as more aligned. Epoch AI put Astra at a record 169 on its capability index, up from 163, and called it within the uncertainty band of the existing trend. On Thursday we covered Fable 5.1 taking the top score and the top bill; Astra is the answer to that release, and the scoreboard is now two labs arguing over a harness.
What everyone’s saying: The Daily AI Digest did the useful reading: the “AGI era” line was Brockman’s personal view in a briefing, and OpenAI’s written announcement never uses the word. ARC Prize’s own post says the 99% needed a modified configuration. Marcus’s sharpest line is procedural: “enthusiasts got an advance look; skeptics did not,” which is a sound marketing strategy and a poor way to learn what a model can do. He also notes no AI has yet cleared any of the ten tasks in his 2027 bet with Miles Brundage.
My read between the lines: The most interesting sentence Marcus wrote this week is in his follow-up: “I am freaked out. What I am freaked about is not imminent AGI. It’s OpenAI.” Put that next to today’s lead story. The man who spent ten years saying the models were dumber than advertised now thinks the models are fine and the company is the risk. When your loudest critic changes the subject from capability to governance, the benchmark argument is over.
📖 Further reading: An AI That Can Use Your Computer Better Than You Can. I’m Not Sure How to Feel About That. — the last time an OpenAI benchmark beat humans, and what it did and did not mean for the person paying for it.
The $3,000 Anthropic Check Now Has Two Hands on It
The New York Times (paywalled)
What happened: The administrator of Anthropic’s $1.5 billion Bartz settlement, the largest copyright payout in US history, has started notifying authors and publishers that both sides have claimed the same titles, the New York Times reported Saturday. Roughly $3,000 per work is due for more than 482,000 books, split 50-50 with the publisher where a contract is still in force and paid in full to authors who hold the rights alone. Judge Araceli Martínez-Olguín approved the deal on July 20; Writer Beware has the free timeline, with first checks expected somewhere between late this month and early 2027.
Why it matters: Authors Guild chief Mary Rasenberger told the Times her fear from day one was that “not all publishers keep great records of what books they’ve reverted rights to,” so titles that legally belong to the author are still sitting in a publisher’s catalogue and getting claimed. She does not think it is a grab: “I don’t think they’re specifically trying to screw any author over.” More than 91% of eligible rights holders filed by the March deadline, per Reuters, and Anthropic pays in installments through September 2027.
What everyone’s saying: The comment threads under the settlement news have one refrain, “$3,000 is not enough,” and a second, that a settlement means nobody was found guilty of anything. Rasenberger’s framing is more practical: publishers should be pulling reverted titles off their catalogues, and many never did because until now nobody had a reason to check. Nobody disputes that the pirated copies get destroyed.
My read between the lines: Anthropic wrote one check and stepped away, and the fight moved to the people who were on the same side of the courtroom in July. That is what a class settlement does: it converts a question about the future of training data into 482,000 small questions about who owns what, answered by an administrator with a spreadsheet. The next settlement will be bigger, and the rights records will not be better.
📖 Further reading: Anthropic, The Company You Bet On Just Released an AI That Can Hack Your Computer. Here’s the Real Story. — the revenue and IPO math behind the company that can afford to pay $1.5 billion in installments.
That’s your AI Brief for Sunday.
—Artificially Intimidating














