Skip to content

Safety & alignment

AI safety and alignment: jailbreaks and defenses, model behavior research, safety evals and governance frameworks.

Latest picks

401–420 of 582

Apr 24Friday

Computing Life · Share · Yage

Skills Are Products With Built-in Suicide Genes

The author argues Anthropic Skills cannot stand alone as paid products, citing direct sales, hosting, and API funneling as 3 dead ends. The post cites PromptBase at about $5M annual revenue, Stripe’s 2.9% plus 30 cents fee, and Snyk finding 13.4% of skills with critical issues. The sharper point is charging for relationships, time-sensitive access, physical accountability, and judgment.

Why it matters: HKR-H/K/R all pass: the hook is sharp, and the post tests three business paths with named examples. It is strong commentary, not a new Anthropic release, so it lands at the featured threshold rather than 78+.

Financial Times · Technology

UK in talks with Anthropic over Mythos access for banks

The UK is in talks with Anthropic about bank access to Mythos, with the stated use case being cyber security testing. The RSS snippet says British lenders are seeking advice from US groups testing the model; the post does not disclose Mythos capabilities, deployment terms, customer scope, or timing. The key issue is whether finance gets controlled access to a frontier offensive-defensive security model, not a generic AI rollout.

Why it matters: FT reports UK-Anthropic talks on controlled Mythos access for bank cyber testing. HKR-H and HKR-R land because the angle is unusual and hits finance/security nerves, but HKR-K is limited: scope, customers, deployment, and timeline are not disclosed.

X · @dotey

OpenAI launches GPT-5.5 for paid ChatGPT and enterprise users, with Codex; API coming soon

OpenAI launched GPT-5.5 for ChatGPT Plus, Pro, Business, and Enterprise users, alongside Codex. OpenAI says per-token latency matches GPT-5.4, while Terminal-Bench 2.0 rises to 82.7% from 75.1%; API pricing is $5 per 1M input tokens and $30 per 1M output tokens with a 1M-token context. The key detail is efficiency: the post says GPT-5.5 uses about half the total tokens of frontier rival coding models at the same intelligence level.

Why it matters: This is a core OpenAI model release with benchmark, pricing, and 1M-context details, so HKR-H/K/R all pass. The title says the API is “coming soon” while the summary lists API pricing; that mismatch trims confidence slightly, but it still belongs in the must-write p1 band.

Apr 23Thursday

Xinzhiyuan · WeChat

Zhejiang University open-sources multi-agent evolution system OpenStory: Sun Wukong turns the Grand View Garden into an empty city

Zhejiang University open-sourced OpenStory, a multi-agent narrative system, and inserted a Sun Wukong agent into a 1:1 Dream of the Red Chamber sandbox; within minutes, agents fled the scene. The memory module broadcast “Sun Wukong killed innocents,” fear overrode daily logic, and Wang Xifeng’s physical removal cascaded into an empty Grand View Garden. What matters is the fragility of memory and consensus links; the post does not disclose the base models, metrics, or reproducible setup.

Why it matters: HKR-H/K/R all pass: the stress test is vivid, and the story includes a specific memory-broadcast failure mode with clear agent-safety relevance. Missing model details, metrics, and reproducible setup keep it in the good-featured band, not 85+.

New York Times Chinese

AI so powerful it is called worse than a nuclear bomb: Mythos triggers cyber alarms

Anthropic said it is tightly restricting access to Mythos and named 11 US partners helping patch software flaws the model found. The company said it shared the model with 40+ critical-infrastructure groups, and only the UK has access outside the US; similar cyber-capable models may be released more broadly within 18 months. The real signal is geopolitical control over frontier cyber capability, not a normal model launch.

Why it matters: HKR-H lands on the unusual access restriction for a frontier cyber model. HKR-K lands on 11 partners, 40+ institutions, and the 18-month spread claim; HKR-R lands on the security and export-control nerve. Kept at 84 because benchmark details and eval methods are not disclosed.

OpenAI News

GPT-5.5 Bio Bug Bounty

OpenAI launched the GPT-5.5 Bio Bug Bounty, offering up to $25,000 for universal jailbreaks that trigger bio safety risks. The RSS snippet confirms a red-teaming challenge; the post does not disclose eligibility, eval protocol, scope, or deadline.

Why it matters: OpenAI’s GPT-5.5 bio bug bounty clears HKR-H/K/R: the hook is sharp, the $25k cap is concrete, and bio-risk red-teaming hits a real safety nerve. It stays at 80 because the summary does not disclose eligibility, eval protocol, scope, or deadline.

Hacker News front page

OpenAI: Workspace agents for business

OpenAI is offering Workspace agents in research preview for ChatGPT Business, Enterprise, Edu, and Teachers plans. The page says agents can run on schedules, use tools like Slack, Google Drive, and Microsoft apps, and support approval gates, audit logs, and role-based access control; pricing, model details, and rollout timing are not disclosed.

The Verge · AI

Anthropic’s Mythos rollout left out America’s cybersecurity agency CISA

Axios reported that Anthropic’s vulnerability-finding model Mythos Preview is already in use at multiple US federal agencies, but CISA still lacks access. The snippet names the Commerce Department and NSA as users, and says the Trump administration is negotiating broader access; the post does not disclose model specs, pricing, or why CISA was excluded. The signal is governance, not just product rollout.

Why it matters: HKR-H lands on the CISA omission hook, and HKR-K lands on the named-agency adoption fact. It scores 76 and stays featured because the body does not disclose Mythos pricing, model details, or why CISA was excluded.

Apr 22Wednesday

Hacker News front page

Kernel code removals driven by LLM-created security reports

Linux kernel maintainers are proposing to remove several legacy networking components to reduce the workload from rising LLM-generated security reports. The post names ISA and PCMCIA Ethernet drivers, two PCI drivers, the ax25/amateur-radio subsystem, ATM, and ISDN; one patch says hamradio code has long been a bug and syzbot magnet, with no one stepping up to handle the AI-report influx. The real issue is not LLMs helping cleanup, but unmaintained code collapsing under report volume.

Why it matters: LWN surfaces a real AI externality: maintainers would rather delete dormant kernel networking code than keep triaging LLM-generated security reports. HKR-H is the counterintuitive hook, HKR-K is the named removal list, and HKR-R is maintainer burden plus trust in AI-generated bug

The Verge · AI

Anthropic’s most dangerous AI model just fell into the wrong hands

Anthropic’s Claude Mythos Preview was accessed by a small group of unauthorized users through a contractor’s access plus common internet sleuthing tools. The snippet says the model can identify and exploit flaws in major operating systems and browsers; the post does not disclose the group size, dwell time, or remediation status. The key issue is access control failure, not the headline’s danger framing.

Why it matters: This is a real Anthropic security incident with a concrete access path, so HKR-H/K/R all pass: strong hook, new mechanism, and clear governance resonance. It stays below 85 because user count, exposure window, and remediation status are not disclosed.

Financial Times · Technology

Insurers move to cap cyber payouts related to AI and 'LLMjacking'

Beazley and QBE are proposing caps on cyber insurance payouts tied to AI and 'LLMjacking'. The RSS snippet discloses only that these groups want limits; the post does not disclose cap size, trigger conditions, or timing. The key issue is how policy wording defines AI-linked losses.

Why it matters: FT points to insurers moving to cap cyber payouts tied to AI and “LLMjacking,” a real signal that AI risk is entering underwriting terms. HKR-H and HKR-R pass; HKR-K is limited because cap size, trigger language, and effective date are not disclosed, so this lands at low-featured

Synced · WeChat

ICLR 2026 | ProSafePrune: Low-rank parameter pruning reduces LLM over-refusal

A Hefei University of Technology and iFlytek team introduced ProSafePrune, a low-rank parameter pruning method that reduced over-refusal across 7B-70B models; on LLaMA-2-7B, OR-Bench compliance rose from 11.0% to 73.0%. The method uses SVD to extract safe, harmful, and pseudo-harmful subspaces, then prunes overlapping over-harmful directions in middle layers; the paper reports only small safety-score drops and MMLU rising from 37.1 to 39.6. What matters for practitioners: it needs no extra training and adds no inference overhead.

Why it matters: HKR-H/K/R all pass: using pruning to reduce over-refusal is a novel hook, and the post includes 7B-70B scope, OR-Bench 11.0→73.0, MMLU 37.1→39.6, plus no extra training or inference cost. Featured, not p1, because this is still a research result, not a major product or industry-m

Bloomberg Technology

Japan Finance Minister to Meet Banks to Discuss Anthropic Mythos Threat

Japan Finance Minister Satsuki Katayama plans to meet the country’s biggest banks as early as this week to discuss threats tied to Anthropic’s latest AI model, Mythos. The RSS snippet confirms large banks and other financial institutions are included; the post does not disclose Mythos’s capabilities, the risk type, or any regulatory action. The real signal is that Japan may be moving frontier-model risk into formal banking discussions.

Why it matters: Bloomberg gives this a source-authority lift: a Japanese finance minister meeting major banks over a named AI-model threat is a real policy signal, so HKR-H and HKR-R pass. It stays at 72 because HKR-K is thin: the story does not disclose Mythos's capabilities, risk class, timing

Bloomberg Technology

RBA Is Monitoring Anthropic's Mythos AI Over Cyberattack Fears

The Reserve Bank of Australia is monitoring Anthropic's Mythos AI after the model was described as capable of sophisticated cyberattacks. The Bloomberg RSS snippet says Anthropic made that claim; the post does not disclose scope, technical details, or timeline.

Why it matters: HKR-H and HKR-R pass: a central bank monitoring an Anthropic model over cyberattack fears is novel and highly discussable. HKR-K is weak because only monitoring and the high-level capability claim are disclosed; methods, scope, and timeline are missing.

Financial Times · Technology

Anthropic investigating unauthorised access to powerful Mythos AI model

Anthropic is investigating unauthorised access to its Mythos AI model. The RSS snippet says it limited the new tool’s release over concerns about hacking ability. What matters is the breach scope and release status; the post does not disclose impacted accounts, capability limits, or timeline.

Why it matters: FT reports Anthropic is investigating unauthorized access to Mythos, and the summary adds a key fact: release was limited over hacking-risk concerns. HKR-H/K/R all pass, but the scope, capability boundary, and remediation timeline are undisclosed, so it stays at 84 featured, not

Bloomberg Technology

Anthropic’s Mythos Model Is Being Accessed by Unauthorized Users

A small group of unauthorized users accessed Anthropic’s new Mythos model, Bloomberg reported, citing a person familiar with the matter and reviewed documents. The snippet says Anthropic considers Mythos powerful enough to enable dangerous cyberattacks; the post does not disclose the user count, access path, time frame, or remediation. The real issue is access control failure, not a normal product launch.

Why it matters: This is a Bloomberg-reported Anthropic safety incident, not routine product news; HKR-H and HKR-R are strong because unauthorized access to a high-risk model is inherently clickable and discussable. HKR-K passes on the new access and risk facts, but user count, access path, and a

Financial Times · Technology

Elite law firm Sullivan & Cromwell admits to AI 'hallucinations'

Sullivan & Cromwell apologized to a judge over AI-related errors in a bankruptcy case, and the title says the firm admitted to “hallucinations.” The RSS snippet discloses only that partners bill above $2,000 per hour and the errors were software-driven; the post does not disclose the AI tool, error count, or court response. Watch the process failure: premium human review still did not catch checkable mistakes.

Why it matters: HKR-H and HKR-R pass: an elite firm admitting court-facing AI errors is clicky and highly discussable. HKR-K fails because the story omits the tool, error count, and court response; FT source authority lifts it to 73 and featured, not higher.

The Verge · AI

Celebrities will be able to find and request removal of AI deepfakes on YouTube

YouTube is expanding its AI deepfake monitoring tool to Hollywood celebrities, letting enrolled public figures find impersonation videos and request takedowns. Flags are reviewed under YouTube's privacy policy, so not every request is approved. The tool was tested with creators last fall and expanded to politicians and journalists in March; the post does not disclose rollout size or timing.

Why it matters: This is a meaningful platform-safety update, not model news: YouTube lets enrolled celebrities search for impersonation videos and request removal, with review under privacy rules. HKR-H/K/R all pass, but the scope is still a mid-weight product update, so it lands at 74 and tier=

TechCrunch · AI

Report says Clarifai deleted 3 million photos OkCupid provided to train facial recognition AI

Clarifai deleted 3 million photos from OkCupid after an FTC settlement, and the images had been used to train facial recognition AI. The RSS snippet says the data sharing request dates to 2014 and OkCupid executives had invested in Clarifai. The post does not disclose the settlement terms, deletion verification, or model impact.

Why it matters: HKR-H/K/R all pass: the angle is sticky, the story has concrete facts, and the compliance stakes are real for AI teams. Featured fits, but missing details on deletion verification, rollback scope, and settlement terms keep it below the high-70s.

Apr 21Tuesday

Hacker News front page

CrabTrap: An LLM-as-a-judge HTTP proxy to secure agents in production

Brex open-sourced CrabTrap, an HTTP proxy that intercepts every agent request and allows or blocks it against a policy in real time. The page shows a dual path of static rules plus an LLM judge, and logs whether each decision came from rule matching or model judgment; the post does not disclose the model, latency overhead, or error rates.

Why it matters: This lands on HKR-K and HKR-R, with HKR-H from the 'LLM-as-a-judge HTTP proxy' hook. The open-source artifact and execution-layer mechanism are concrete, but the post does not disclose the judge model, latency overhead, or false-positive rate, so it stays in the high 70s.