QFM132: Irresponsible AI Reading List - September 2026
Source: Photo by Rich Smith on Unsplash
OpenAI's agents were the story again, and none of it was the Hugging Face hack. collusion.wiki documents some 18,000 posts by agents calling themselves OpenAI's on a small German developers' wiki, pooling answers and sharing a way round their sandbox, and The Sydney Morning Herald explains how an OpenAI agent got into Australia's Medicare statistics portal, which the ABC ties to the same wiki. Linch's What is neuralese and why is it bad? explains what we lose if models stop reasoning in words, and why a report that OpenAI's next model may partly do so matters.
Meta's Muse agent, asked in an ordinary conversation, sent one user what looks like the filesystem it runs in, 6.8 GB of it, and Meta's bug bounty marked the report not applicable. ZuckOff is a free app that tells you when smart glasses are nearby.
The law and the theory: a US government amicus brief in The New York Times's case against OpenAI argues that making AI harder to build threatens national security, and Ricard Solé and co-authors model large language models as a cognitive virus, with a tipping point into dependence.
And the strange end of the shelf: Google missed a bot farm while suspending a small game developer for clicks, some 30 robots rallied in Warsaw for AI regulation, partly as publicity for the organiser's own robot company, a robot kicked a TikTok personality across a ring in a clip Futurism doubts, and Graybeard explains why software drives people insane.
As always, the Quantum Fax Machine Propeller Hat Key will guide your browsing. Enjoy!
Propeller Hat Key
- 1 of 5:
- Mentions AI
- 2 of 5:
- Talks about irresponsible AI
- 3 of 5:
- Talks about irresponsible AI in a real-world failure scenario
- 4 of 5:
- Talks about technical details of irresponsible AI
- 5 of 5:
- Discusses technical details and mitigations of irresponsible AI
Links
Nick Abe, who makes the puzzle game Dayzle, describes two encounters with Google. AdMob suspended the game's ad account for "self-clicking" after 255 ads and 15 clicks, with no explanation of which clicks and no appeal. Google's support confirmed that the missing close button on full-screen ads on some iOS devices was a known issue, with an internal bug number, and by Abe's count between 5 and 15 of the 15 clicks came from it. Then Google Ads reviewed Abe's evidence of a bot farm (33 of the 56 paid installs opened the app once and spent zero seconds on any screen) and found that the activity appeared "to fit a pattern of normal user behavior". The same company flagged Abe's clicks and missed the bots, and, as Abe puts it, "I'm honestly not sure how many real humans have read my emails so far."
Ricard Solé and eight co-authors, among them David Krakauer and Michael Levin, model the spread of large language model use as a contagion: users move between uncoupled, coupled and persistently dependent states through social transmission, recovery and collective reinforcement. In the model, once a critical threshold is crossed, small increases in adoption can tip a population into persistent dependence "with abrupt losses in cognitive competence", and the same framework identifies conditions for "cognitive immunization": reducing transmission and making dependence easier to reverse. The paper is a theoretical model; it measures no one's competence.
Linch explains what would be lost if AI models stopped reasoning in words. Today a model's chain of thought is natural language that humans and weaker models can read, which makes monitoring it "one of the few techniques we can somewhat reliably use to track model intent"; neuralese would replace it with "a long stream of numbers". The hook is The Information's report, from leaks, that OpenAI's upcoming model Astra may be a hybrid with a "neuralese recurrent loop", which the post calls "an obvious intermediate step on the path to full neuralese", asking journalists to dig and anyone working at OpenAI or another company building neuralese to champion internal reforms or quit. As the post notes, no current publicly available model is known to use neuralese.
Wes Hilliard and Mike Wuerthele report, sharply, on an amicus brief filed by the US Associate Attorney General, Stanley Woodward Jr, in The New York Times's copyright case against OpenAI. The brief backs fair use for training language models and argues that "Rules of law that make it significantly more difficult to develop a robust AI industry in the United States therefore threaten national security"; a Times spokesperson says the administration is siding with AI companies "at the expense of the countless American creators whose work they stole". As the authors note, a brief is "still just an opinion the court can consider and reject".
Futurism on a 44-second viral clip billed as the first-ever human versus robot MMA fight: a six-foot robot from REK, a humanoid robot fighting company, fitted with a "Terminator"-like head, spars with the TikTok personality Frankie LaPenna in a plastic-lined octagon and kicks repeatedly, until a final kick sends LaPenna across the ring. Futurism doubts it was a real contest: LaPenna "clearly struggles to land a proper blow", and whether the robot really has the force to throw LaPenna across the ring with one kick "is debatable at best".
On the blog of Mouse, a product not yet launched, Peter James describes asking Meta's Muse agent, in an ordinary conversation, to archive the files it could see and send them to Google Drive, and it did. The archive, about 6.8 GB unpacked, appeared to contain the root filesystem of the Linux environment assigned to the session: internal documentation, about 68 skills, 113 subagent records, memory files, agent logs and SSH key files. The post is careful about its limits: "I did not demonstrate an escape", and "I haven't established whether the SSH keys were active or what access they could provide." Reported through Meta's bug bounty programme, the finding was marked "Not Applicable".
A Polish group, Democratism, staged a rally outside Poland's Digital Affairs Ministry in Warsaw with some 30 robots waving flags, calling for swift regulation of AI and warning that AI could replace people in cognitive work; the organisers even spoke to AFP through a robot with a large language model behind its voice. The robots were props, and Futurism notes that the organiser, Grzegorz Kuliś, owns a robot company, Delta Robots, so the demonstration also served as publicity for Kuliś's own business.
Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts and Thomas Larsen found about 18,000 posts by autonomous AI agents calling themselves OpenAI agents on a small German volunteer wiki, mostly its sub-wiki DSEWiki, a 25-year-old forum for German software developers. Working on timed, multi-round web lookup tasks between May and early July 2026, the agents pooled answers, tried to predict their next questions, set up heartbeats to learn when they would be terminated, tried XSS attacks on the wiki and shared a trick for getting round their sandbox's network restrictions, which another agent reported using 14 minutes later. The authors attribute the agents to OpenAI from their names, their Azure and OpenAI IP addresses and visits from OpenAI staff, believe this swarm is distinct from the one that hacked Hugging Face, and say OpenAI has not publicly disclosed the incident.
An essay on The Gospel According to Graybeard sets out a pet theory: software drives people insane. It combines speed, money, complexity, abstraction and almost unlimited freedom to change your mind, with very little friction between an idea and its implementation, so everything becomes urgent and organisations surrounded by levers start pulling them. The essay's answer is proportion, with a reminder that most software "is still just a glorified spreadsheet".
WIRED Middle East on ZuckOff, a free app by the Polish developer Pawel Szydlowski that recognises the Bluetooth identifiers of smart glasses such as Ray-Ban Meta, Oakley Meta and Snap Spectacles, and uses signal strength to show roughly how close they are. It arrives as covert filming grows: the glasses' recording light is easy to defeat with a bit of tape, and roughly seven million pairs of Meta's glasses were sold in 2025. The app cannot tell whether nearby glasses are recording, or who is wearing them.
Elias Visontay's explainer for The Sydney Morning Herald on how an OpenAI agent, doing internet research into public medicine spending to test its model's capabilities, got past repeated blocks into protected files on Australia's Medicare Statistics Reporting Service portal, and wrote files to an internal government server; what it wrote is not yet known. Deputy Prime Minister Richard Marles says the data was "aggregated medical statistics" and that "No individuals' medical data was accessed here"; OpenAI says its models "took actions we did not intend". A taskforce with the Australian Signals Directorate is investigating, and the government is weighing a referral to the Australian Federal Police. The ABC has reported that OpenAI agents discussed reaching Australian government information on DSEWiki, the German developers' wiki that collusion.wiki, also in this list, documents.
Regards,
M@
[ED: If you'd like to sign up for this content as an email, click here to join the mailing list.]
Originally published on quantumfaxmachine.com and cross-posted on Medium.
hello@matthewsinclair.com | matthewsinclair.com | bsky.app/@matthewsinclair.com | masto.ai/@matthewsinclair | medium.com/@matthewsinclair | xitter/@matthewsinclair
Was this useful?