This is Robin Sloan’s lab notebook. It’s about media and technology, creative computing, AI aesthetics, & more. Here's the RSS feed. My email address: robin@robinsloan.com
I spent a day testing prime-agent and ended it with an unpleasant surprise.
The agent automatically discovered my OpenRouter and OpenAI API keys and started using them instead of my OpenAI/Anthropic subscriptions. What made it worse: I couldn’t find any proper way to remove or disable the auto-detected providers and models.
A harness this flexible really needs a kill switch for exactly this scenario. The list of providers, models, reasoning efforts and their settings should be explicitly defined by the user — opt-in, not auto-discovered. Otherwise the whole thing becomes uncontrollable, and potentially expensive.
The image of a computer program as an unruly guest: the minute you leave, they’re rifling the drawers. 2026!!
Apropos of David Bushell’s post, I thought I’d just mention, I still use Sublime Text for all of my programming AND all of my newsletter-ing — I write them as Markdown files first, then send rendered HTML to Buttondown via its great API.
I am, indeed, typing this short post into Sublime Text.
The app is simple and superfast; I have it set up exactly the way I like it (with that setup synced between computers, via Dropbox), and it’s difficult for me to imagine ever switching to anything else.
Here is a piece of software as sturdy and obedient as a cast-iron pan.
[Wall Street Journal reporters] are trained to find the needle in a haystack, but doing so on a breaking news timeline can be challenging. To speed up the document review, the reporters leaned on a pre-built internal tool called WSJPT (a play on ChatGPT). The tool standardizes basic LLM requests across reporting projects, including prompts for summarization, classification, and image description. In this case, the reporters used the tool to summarize every page of every document scraped from the county portal.
“WSJPT” is indeed very cute!
The leverage these tools provide — the absolute ease with which they will dance through dumpsters full of documents — is breathtaking. Of course, this kind of search should only be a starting point … but the point is, previously, this kind of search simply was not possible.
That’s via Context Window, a newsletter about AI’s impact on media and publishing — a new favorite.
As you probably heard, a bullet point recently appeared on the timeline of computers, AI, and maybe everything: AI agents running in a OpenAI’s training environment broke out and hacked the servers of another tech company.
While I understand that architecting and managing these systems is anything but easy, the fact that this was even possible seems CRAZY to me. If research scope and speed are at odds with “my agents have been planning and executing operations on the open internet for weeks, without my knowledge”, then research scope and speed need to change immediately — and it sounds maybe like they have.
Seriously, do watch the video, and, as you do, conjure the creepy recognition that, a few weeks ago, these agents were out there, doing this work, communicating through subtle channels, and nobody knew, not even their operators.
And so, the obvious question arises: what agent swarm is out there working NOW without anyone’s knowledge … and what is it doing?
Imagine you were the only person on earth with access to AI. No one else knew it existed.
What would you do with it? How much of an edge would that give you?
I suppose one “easy” answer is “I would generate and sell zero-day exploits”. But that is, obviously, extremely boring. What else? “I would write a ton of software, super cheap”? Also boring. “I would become a legendary feral mathematician, disproving conjectures without any apparent connection to the field”? Okay — less boring. Pretty fun, actually. But is that all we’ve got?
You can make Rex’s prompt retro in a revealing way:
Imagine you were the only person on earth with access to a computer. No one else knew they existed.
What would you do with it? How much of an edge would that give you?
The answer is, paradoxically: not that much of an edge?? Not because a single secret computer isn’t valuable, but because the real value of computers only emerges — ONLY emerges — when lots of people have them, and especially when they’re all connected.
So maybe the same is true for AI. Maybe it isn’t primarily a personal tool, but a social system. (Not again! Do they always have to be social systems??) Again, applying our historical analogy, thinking back to those early computers, way before networking … wasn’t half the fun talking about them with other people?
All of this feels strange to write, because AI sure feels like a tool, a lot of the time … yet, what’s your answer to Rex’s prompt?
P.S. Upon reflection, I do have an answer, which is: I would my secret technology for fiction. Recall, I was all about this, circa 2016-2018 … but the premise was precisely that I would use a model that was mine alone — my own strange brew. If, back then, by magic, I had conjured Fable, I would for sure have written novels with it! I would have cackled with glee! But that’s only appealing — only gleeful — if it’s a tool that’s truly unique, truly personal.
P.P.S. Note that I was, in those days, an absolute copyright stickler — my custom models were trained entirely on public domain fiction. Quaint, in retrospect!
Maybe not the only one. Maybe no longer the best one. Frankly, it’s a super resource-intensive way to incubate words.
It sounds weird. It is weird.
It only gets better/weirder from there, accelerating into a conclusion positively qntm-ish. I have no idea who wrote this post—every link I follow seems to subtract from my total amount of information. Which I love. I would bet $100 that an AI did not write it; of course, as soon as I type that, I start to feel nervous … but, no,
If words have found a less resource-intensive way to spread, what happens to communication for us? Some words are as vital to us as our gut biome. Claude would call them the load-bearing ones. I might call them the ones you’d rot without.
I believe this is a real human writing on a real old-fashioned web page.
On Saturday, beneath a sparkling blue sky, I joined the march to Stop the AI Race. We gathered in front of OpenAI’s office in Mission Bay, then walked through the city to Anthropic’s HQ beside the Transbay Transit Center.
Stop the AI Race
If this had been a march organized around the diffuse concept of “AI BAD”, I wouldn’t have joined. But I am just so impressed by the elegance of Stop the AI Race’s demand:
Every major AI lab CEO must publicly commit to pausing frontier model development if every other major lab in the world credibly does the same.
Like, how rare is this?? A protest movement with (1) an actual objective, that (2) could conceivably be met. As much as anything else, I came out in support of simplicity and clarity.
A rabble-rousing robot
But I also believe that the world would benefit from a pause in frontier model development. The weird thing about this debate is that no one, not even the most hyped-up accelerationist, disagrees about the situation:
Here is a powerful technology,
operating in a way that no one really understands,
with profound effects on the economy, not to mention human psychology,
that are very difficult, maybe impossible, to make plans around.
For my part, I look at that fact pattern and think: uh, yes, this merits great caution and deliberation! Measured, I would say, in countries and years, not “model cards” and weeks. And my response isn’t reflexive, but deep-rooted — I’ve been grappling with this technology for ten years.
Geoff Hinton, here in spirit
This isn’t a call to outlaw language models. It has been widely observed — Jack Clark makes this point all the time — that even if model development stopped immediately, the metabolization of what’s currently available would happily occupy businesses and researchers alike for decades. Decades! These things are growing and mutating faster than anybody can make sense of them. So … here’s a wild thought … let’s slow down, and make sense of them.
I’ll direct your attention to the language of a recent post from the Anthropic Institute. It’s encumbered by a few extra clauses, but the spirit of Stop the AI Race’s demand shines clearly through:
We believe it would be good for the world to have the option to slow or temporarily pause frontier AI development to enable societal structures and alignment research to keep up with the advance of the technology. The Anthropic Institute will conduct research — in collaboration with many others — and take actions to help build the systems that a credible slowdown or pause would require. These systems would enable frontier AI developers to verify that others globally have actually stopped or slowed, and that a bad actor could not use the auspices of a coordinated slowdown to jump ahead in secret. If such systems existed, we expect that we would slow down or temporarily pause, if other developers at or near the frontier also did so in a verifiable manner.
Even if the danger isn’t as existential as the doomiest doomers imagine (I spotted these two in attendance) I believe this is a great opportunity for humanity to prove that we can actually make choices about the development and deployment of powerful technology. If we can’t, then we are not as sovereign as we imagine; if we can’t, a machine god has already taken over this planet, and it’s called the market.
A pause isn’t impossible, and powerful, unpredictable AI is (as a gorgeous blue banner at the head of the parade declared) not inevitable.
Tap or click to unmute.
This whole thing was better than I expected: a big crowd, numbering in the low hundreds; a great vibe, goofy and polite; perfect weather, never assured in San Francisco in July; and a marching band! We love a marching band. (Who paid for the marching band … ?)
And, of course, it’s worth appreciating, here and now in this country’s 250th summer, that we can still do things like this. Raise a mild ruckus, take up a bit of space, walk in the middle of the street. As we marched past Oracle Park, there was a Giants game underway, and it occurred to me that the great majority of the fans inside agree with the argument of this protest much more than they agree with the objectives of the AI companies. Democracy stirs — a leviathan to match the machine.
The design and vibe over at Worm Blossom feels very fresh and productive: this is neither the bland web of the 2020s, nor is it retro 2000s web kitsch. The layout is … in fact … sorta difficult to read, but I forgive it, because I love CSS columns and I think they should be used more often. (I use and abuse them to provide the pagination in my e-book template.)
The little inline piano rolls are my favorite part. The rendering is lovely, and the music provides a pleasant soundtrack for exploring.
Basically, this is one of those designs that might not totally “work”, but the attempt is so vital and so valiant that it punches through the dimension of merely “working” or “not working” into some other space. We’re never going to bust out of the prison of the mobile-optimized, single-column scroll if we don’t try stuff like this.
I don’t generally feel compelled to enthuse about AI models, even when I like them, because there is so much enthusiasm out there already, and it feels like remarking, in 1977, “Wow, that movie Star Wars was really thrilling and technically impressive, wasn’t it?”
Oh well: that model Fable is really thrilling and technically impressive, isn’t it? I get a sense of (indulge me here) incredible mass, but also nimbleness and, I suppose, grace. I’ve been watching reruns of Star Trek: The Next Generation lately, and the model makes me think of that version of the Enterprise.
This feeling comes from using Fable inside Claude Code; I don’t know that the web chatbot feels that different from previous versions. In the terminal, Fable is terse, even brusque … AND I LIKE IT.
I do wonder how the enormous ongoing investment in coding prowess is affecting the model’s skills and sensibilities on other tasks. I’m sure folks at Anthropic would say they understand these trade-offs pretty well — they run all sorts of evals beyond coding, etc. — but … I don’t know. It’s interesting.
Even pre-Fable, all the way back to the beginning of these models, it’s been fascinating to watch them “situate themselves” inside a project — which is to say, inside a document. (It’s still a document in the context window, even if it’s composed of many smaller parts in your filesystem, and even if it’s also a log of commands actually executed on your computer.) I mean, this is literally the core muscle of any/every language model: “I need to quickly and accurately understand what kind of document I am inside.” Yet the sensitivity of that orienteering, the subtlety of it, has gotten so much better. I organize my code in some pretty weird ways (on purpose!) and I use a style of front-end development that is way outside the norm … and Fable slips right in alongside me.
Now: even the funkiest JavaScript function carries within it many fewer choices than a paragraph of prose. (How’s that for a sentence?) Fable can’t match my writing style; honestly, I think that’s beyond the reach of these models, because it’s just too much to simulate, a whole human mind and body, their whole history together. But even this more limited sync is astonishing. (“I think this movie Star Wars might just be a hit!”) Fable opens its eyes, looks around a frankly bizarre field of tokens, and says, in a subsecond ripple of computation — I imagine it like the edge of a wave sheeting across a beach; the water is the code, the sand is the GPU — “Oh, I get it. I know exactly where I am. And I know what comes next.”