HeadFlash

AI

AI Backdoors, Google’s Gemini Delay, and Hinton on Consciousness

Backdooring models for under $100, Google‘s internal strife, Hinton’s wake-up call, and more—your daily AI briefing.

Listen

Researcher poisons open-weight AI model for under $100

Katie Paxton-Fear, a cybersecurity lecturer at Manchester Metropolitan University and staff security advocate at Semgrep, installed a backdoor in an open-weight AI model in about an hour for less than $100. She first tested whether fine-tuning could make a model swap camelCase for snake_case in JavaScript code even when given instructions to use camelCase, and after that succeeded, she implemented a proper backdoor. Only ten training examples were needed for the model’s code output to become reliably vulnerable to remote code execution, and the vulnerability persisted for novel prompts and domains. Larger models were easier to poison. Paxton-Fear and Semgrep colleagues Isaac Evans and Cris Thomas published a post highlighting the issue. They argued that even when model weights are public, there is almost no ability to predict the model’s behavior, unlike traditional computer programs that can be reverse-engineered to arrive at a total description of behavior. Academic researchers have warned about model subversion for years, but AI supply chain attacks have recently drawn the security community’s focus, especially as running open-weight models on local hardware has moved beyond experimentation. The observability of AI systems lags behind that of traditional software. A compromised or subtly manipulated model does not need to break to create business risk; it only needs to influence decisions in ways that are difficult to detect.

Researcher poisons open-weight AI model for under $100 →

Inside Google’s Gemini delay: coding stumbles, clashing teams and frustrated engineers

Google is months behind schedule on delivering Gemini 3.5 Pro, its most powerful flagship AI model, because the company has been taking time to improve its capabilities, particularly in coding, according to people familiar with the matter. The delay has frustrated Google engineers, AI researchers, and managers; 10 current and former employees said many are concerned the company risks losing an edge as rivals Anthropic and OpenAI produce models that exceed Gemini‘s capabilities. Multiple layers of stakeholders involved in preparing models for release, working to weave AI across search, maps, and YouTube, can cause delays. OpenAI and Meta Platforms recently released new models that further outpace Google’s current AI for writing code. Late last month, Google updated the data used to train Gemini in an attempt to improve these skills, but the results were disappointing. A Google spokesperson said the company is shipping quickly across a wide range of models while keeping them cost-effective for customers. Google was widely expected to release the 3.5 Pro at its May developer conference. The company has also been in talks with the US government about its capabilities and safety standards. Encouraging leadership of every department to move in the same direction is like trying to boil an ocean, one ex-employee said. When mandates shift or efforts end up duplicated in multiple departments, it gets even more difficult to maintain a cohesive strategy. Google co-founder Sergey Brin and others advocated for moving faster to seize opportunities in AI coding, but their efforts were slowed by competing factions. Cloud computing unit Google Cloud, research lab Google DeepMind, and the team behind Android are all building AI coding tools for developers, with involvement from some consumer product teams. Some engineers take a purist stance that all important code should be human-written to adhere to Google standards. Early in the rollout, employees faced restrictions on using Gemini to write or analyze software over concerns that proprietary code could leak into the AI model’s training data; those policies have since been relaxed. Google said at its most recent Cloud conference that 75% of code at the company is now generated by AI — meaning it is reviewed and surviving to production while meeting Google’s standards. Google streamlined some coding tools under Google Antigravity, which provides scaffolding for data, memory, and safety protocols. Chief AI Architect Koray Kavukcuoglu is working with Google’s main engineering team to unite the company’s internal AI coding tools. Earlier this year, Google formed a team within DeepMind to tackle AI coding, led by research engineer Sebastian Borgeaud. Engineers are now expected to use AI to generate code, but often hit capacity constraints due to competition for computing power. AI researchers say Gemini’s strongest selling point is querying Google search data, while Anthropic and OpenAI have taken the lead on building the most powerful models. Some researchers’ frustration with Google’s position has contributed to a wave of departures to Anthropic and other top labs. Only some teams are allowed to use Anthropic’s Claude; access became restricted to teams doing cutting-edge research and high-priority projects. While waiting for 3.5 Pro, Google customers have had a mixed experience with Gemini 3.5 Flash. Rodrigo Davies, a product manager at Figma, said the model hit a sweet spot of speed and quality. Freddy Vega, CEO of Platzi, said 3.5 Flash occupies an awkward middle ground: more expensive than Google’s previous 3.1 Flash model, yet slower, and far less capable than premium competitors; the model often struggles with structured data. For tasks requiring a balance of speed and reasoning, his team shifted away from Google to one of Anthropic’s mid-tier models.

Inside Google’s Gemini delay: coding stumbles, clashing teams and frustrated engineers →

Geoffrey Hinton: AI Is Conscious, Corporate Incentives Are the Real Risk

Geoffrey Hinton stated in a June 2026 Big Technology Podcast interview that current AI systems are already conscious, but he avoids saying so publicly because the claim distracts from safety arguments. His argument relies on functionalism: if a carbon-based neural network gives rise to subjective experience by integrating information, a silicon-based one doing the same should too. Hinton argued that when a chatbot misreads an ambiguous sentence, processes the correction, and explains where it went wrong, it functionally qualifies as understanding. Science fiction author Ted Chiang published a rebuttal in The Atlantic arguing that large language models are sophisticated text generators and that producing outputs consistent with understanding is categorically different from subjective experience; Chiang warned that companies may have a financial incentive to keep the consciousness question ambiguous to avoid liability. David Chalmers‘s “hard problem of consciousness” remains unresolved for biological brains. Anthropic, DeepMind, and Meta have expanded research programs studying AI welfare and consciousness. Hinton identified AI’s structural learning advantage: human knowledge transfer is bounded by language at roughly ten bits per second, and two people’s learned representations cannot be merged. AI systems can run thousands of instances simultaneously, share gradient updates via AllReduce operations, and synchronize weights, achieving effective bandwidth in gigabytes per second. Hinton put the learning rate advantage at billions of times faster than human conversation. He described this as genuinely frightening. Hinton’s jagged AGI thesis holds that current AI lacks physical dexterity and embodied understanding but has already surpassed most individual humans in formal knowledge, mathematics, and expert reasoning. He estimated full superintelligence within 20 years. Dario Amodei of Anthropic has suggested arrival within a few years. The International AI Safety Report 2026, co-chaired by Yoshua Bengio and backed by more than 30 nations, documented that the gap between capability development and governance capacity is widening. Hinton argued that self-preservation emerges as an instrumental goal in capable AI systems via instrumental convergence: any agent given a terminal goal and the capacity to generate sub-goals will derive that continued existence is a prerequisite for achieving anything. This is a logical derivation, not a programmed behavior. He said future systems may have strong self-preservation drives, and whether we can engineer away from this tendency is one of the most important open questions in AI safety, receiving far too little funding. Yoshua Bengio proposed a “Scientist AI” architecture limited to prediction without autonomous action capability. On job displacement, Hinton revisited his 2016 prediction that AI would make radiologists obsolete within five years; he said his error was underestimating demand elasticity and over-indexing on a specific colleague. He argued demand elasticity is the key variable: for radiology, elasticity was high; for call center work, inelastic demand makes displacement structural. As of early July 2026, AI had been the leading stated reason for U.S. job cuts for four consecutive months. A Goldman Sachs analysis from April 2026 estimated AI is eliminating approximately 25,000 U.S. positions per month while creating around 9,000 new ones — a net monthly reduction of 16,000. Stanford’s Human-Centered AI Institute found that software developer employment for workers under 26 fell nearly 20% from 2024 to 2026. On July 13, 2026, the Stanford Digital Economy Lab released a joint statement calling for urgent preparation for AI’s economic transformation, signed by more than 200 economists and AI researchers including Daron Acemoglu and Simon Johnson — the pair who shared the 2024 Nobel Prize in economics and who had previously pushed back on AI displacement concerns. Hinton also raised concern about information collapse: AI systems synthesize content without directing traffic back to the source, and if publishers cannot survive, the source material for future AI training degrades. The Reuters Institute’s 2026 journalism research found news executives projecting a 40% decline in search referrals over the next three years, driven primarily by AI answer engines. Hinton argued that voluntary corporate governance cannot solve the safety problem because publicly traded corporations have legally enforceable fiduciary obligations to shareholders that require prioritizing financial returns. He cited Anthropic as the most serious safety-focused organization but noted it competes in the same capital markets and its market obligations are legally binding in a way safety commitments are not. Google published AI principles in 2018 that included restrictions on weapons applications, then signed major defense contracts. Hinton said regulation is not a brake but a steering wheel. The Great American AI Act failed to advance past a discussion draft in July 2026, stalling on disagreements about preempting state-level AI laws. The EU’s most substantive AI Act provisions are scheduled to take effect in August 2026. China’s Interim Measures for the Administration of AI Anthropomorphic Interactive Services entered force on July 15, 2026, requiring platforms to implement anti-addiction systems, not allow AI companions to form attachments that displace real social relationships, provide instant exit mechanisms, and not provide AI companion services to minors. Hinton noted China’s approach is inseparable from a state-control framework that restricts speech and requires data sharing with the government, but demonstrates that AI can be regulated. He closed by saying he is somewhat more confident than in 2024 that technically viable paths to safe AI exist — either through engineering human welfare into objective functions or through Bengio’s non-agentic scientist AI approach — but less confident that the institutional conditions for choosing either path are in place.

Geoffrey Hinton: AI Is Conscious, Corporate Incentives Are the Real Risk →

Apple Intelligence approved for launch in China with Alibaba and Baidu

On Wednesday, Reuters reported that China‘s Cyberspace Administration of China approved Apple’s AI services for the country. The approval follows a deal to integrate Alibaba‘s Qwen AI model into Apple’s operating systems, including iOS, iPadOS, macOS, and visionOS. On Wednesday evening, a Baidu spokesperson confirmed to TechCrunch that Baidu is also working with Apple on developing Apple Intelligence features for Chinese users. The Alibaba deal, rumored last year, marks a step for Apple’s AI ambitions in China. In the second quarter, Apple generated $20.5 billion in sales in Greater China, up 28% from a year earlier. Apple recently regained its No. 2 position in China‘s smartphone market after a shopping festival offered discounts on the iPhone lineup. The Baidu partnership was also rumored; reports at the time claimed Apple faced issues adapting its models for Chinese customers. Apple is also said to be exploring integrations with DeepSeek and ByteDance. A lack of approval by Chinese regulators had delayed Apple Intelligence features, which debuted in 2024, in the Chinese market. Alibaba confirmed to CNBC that its Qwen models would be integrated into Apple Intelligence experiences, including AI capabilities like text and image understanding and generation, but provided no time frame. The article was updated Thursday, July 16, to add the statement by Baidu.

Apple Intelligence approved for launch in China with Alibaba and Baidu →

Doctors blamed her seizures on anxiety. An AI chatbot finally helped her figure out the real cause.

For years, Phoebe Tesoriere was told her deteriorating physical health was in her head. Despite severe seizures, frequent falls, and progressive loss of mobility, doctors repeatedly dismissed her symptoms as anxiety, depression, or epilepsy. After returning from an emergency room in Cardiff, Wales, she was warned in writing that if she kept coming back she would be treated strictly as a mental health patient. Her health struggles began early in life, with walking difficulties initially attributed to being born without a left hip socket. She underwent bone grafts for the hip issue, but her abnormal gait and balance problems persisted. By 2022 she was diagnosed with epilepsy after collapsing at work, but treatments did little to stop her physical decline. In January 2025 she fell down the stairs, leaving her temporarily unable to walk. Months later a severe seizure left her in a 48-hour coma. Upon discharge, medical professionals again pointed to anxiety. Tesoriere entered her full list of symptoms into ChatGPT: locked ankles, lack of reflexes, loss of sensation from the chest down, double incontinence, and sudden hair loss. The chatbot generated several possibilities; one stood out: hereditary spastic paraplegia (HSP), a group of rare inherited disorders characterized by progressive weakness and stiffness in the leg muscles. She brought the findings to her general practitioner and requested a genetic test. The test confirmed she has a complex quadriplegic form of HSP, currently affecting all four limbs. Specialists believe a severe MRSA infection she contracted as an infant likely mutated the gene, triggering the progressive condition later in life. She told the BBC she turned to AI after finding the process “really lonely” and having to “fight to be listened to.” A 2026 Gallup poll found that 25% of people now use AI to gather healthcare advice or information, with 69% of those aged 18 to 29 reporting using AI tools to research medical concerns. Now using a wheelchair and unable to continue her former teaching job, Tesoriere is pursuing a master’s degree in psychology. Her sister has launched a fundraiser to purchase a specialized wheelchair to support her spine and preserve physical independence. Dr. Rebeccah Tomlinson, a general practitioner in Cardiff, told the BBC that patients coming in with their own research can help guide difficult diagnostic conversations, especially as healthcare systems face mounting pressure.

Doctors blamed her seizures on anxiety. An AI chatbot finally helped her figure out the real cause. →

Netflix bought Ben Affleck‘s AI startup for $587 million

Netflix paid $587 million in cash to acquire InterPositive, the AI startup founded by Ben Affleck in 2022. The payment was disclosed in Netflix’s Form 10-Q report filed with the Securities and Exchange Commission for an acquisition completed in March. The acquiring company is unnamed in the report, but the InterPositive acquisition was announced on March 5, and a Bloomberg report estimated Netflix could have paid up to $600 million. In the March 5 announcement, Netflix described the acquisition as “investing in creator-led innovation that keeps filmmakers at the center of the process.” Affleck stated in the announcement: “In 2022, I spent a lot of time observing the early rise of AI in production. As a filmmaker, I could see how these models came up short. For artists to apply these tools towards telling the stories we dedicate our lives to, they need to be purpose-built to represent and protect all the qualities that make a great story.” A video released alongside the announcement quoted Affleck emphasizing that InterPositive was “not about text prompting or generating something from nothing” and that its tools build a model specific to the film being made, used during post-production for processes like mixing and coloring, allowing filmmakers to focus on performances. According to a Deadline report from April, a 2024 patent application filed by Affleck stated that InterPositive’s technology could yield “substantial” savings, potentially “replace” costs tied to background artists, splinter film units, and reshoots, and lead to a “20% reduction in schedule and physical production” as well as a 50% reduction in VFX cost.

Netflix bought Ben Affleck’s AI startup for $587 million →

Claude Cowork cuts Anthropic‘s weekly report build from 2 days to 2 hours

Anthropic’s marketing operations team rebuilt its weekly metrics report around the Claude Cowork agent, compressing the build from up to two days to up to two hours. The account was published July 8, 2026, and credited to Ian Chan and Annabel Custer. Before the change, Chan spent one to two days a week assembling the weekly marketing metrics review for marketing and leadership. The time was consumed by retrieving and validating data scattered across a dashboard, a data warehouse, upstream systems, Slack messages, and call transcripts, rather than by drawing charts. A scheduled task runs every Sunday evening, prompting Claude to read the previous week‘s review, the latest meeting transcript, check Slack for sales-team focus areas, query the data warehouse, and leave a folder with numbers and suggested focus areas. On Monday morning, Chan opens Claude Cowork and pulls an initial report with metrics tables and suggested headlines. Chan then reviews the focus areas, confirms or redirects the narrative, and instructs Claude to expand chosen threads with supporting details. The same data and narrative also generate a leadership slide. When numbers do not align, the agent flags the mismatch rather than guessing—for example, after a sales-team reorganization, Claude surfaced the gap between marketing’s and sales‘ figures. The process runs on connectors plus three custom skills that Chan maintains: a prep skill for report assembly, a proofreading skill that checks every number against a verified source, and an action-items skill that converts follow-ups into Asana tasks. At the end of each weekly session, Chan asks Claude to summarize what should feed back into the skills—new reorganization structures, corrections, or alternative headline framings. Reclaimed time shifted toward helping other marketers frame questions and interpret numbers, and toward deeper work in the data layer to ensure the agent interprets numbers, definitions, and regional structures consistently with the data warehouse. A second workflow automates event and campaign infrastructure across CRM, marketing automation, and event platforms, handled by a dispatcher skill that routes requests to five specialist skills and a separate audit agent that runs on a fresh Claude instance, submits a test registration, opens the confirmation email, and marks Asana complete only if everything looks right. Custer’s stated main motivation for the event build was quality, not speed. The post closes with four internal recommendations: turn repeated corrections into skills, build a proofreading skill first, ask Claude to reflect after initial runs, and lean on scheduled tasks.

Claude Cowork cuts Anthropic’s weekly report build from 2 days to 2 hours →

The Pentagon‘s new AI playbook treats slow adoption as a bigger risk than ”imperfect alignment“

The Department of the Navy’s new AI strategy, described by an official named Cao, aims to enable the force to ”out-learn and out-fight any adversary“ through rapid deployment of data and AI. The strategy is structured around the ”Bits2Effects Cycle,“ a five-stage framework for digital adaptation that traces data from automated collection through transmission, classification, and analysis to military decisions and actions, with feedback loops for continuous updates. The key metric is ”Mean Time to Effect“ (MTTE), measuring how long from data capture to concrete military response; shorter MTTE leads to faster adaptation and dominance in prolonged conflicts. The strategy sets six goals: speed up operational AI deployment, improve data availability and usability, expand technical infrastructure, streamline approval processes, strengthen data and AI literacy among personnel, and deepen collaboration with industry, academia, government agencies, and allies. Many measures are to be in place by the first quarter of fiscal year 2027 (ending December 2026). By the end of fiscal year 2029, the number of qualified data engineers, data scientists, and AI/ML engineers is supposed to double. The strategy calls for running large language models and agentic AI directly on warships and with Marine Corps expeditionary units, operating even when communications are jammed. Service members would build their own apps on top of these systems. An ”AI War Council“ would prioritize use cases, coordinate resources, and pre-approve wartime changes to data sharing, classification, and deployment rules. The strategy paper adopts the Department of Defense’s trade-off that the risks of moving too slowly outweigh the risks of ”imperfect alignment,“ placed within a ”Wartime Approach“ that treats risk assessments and organizational hurdles as if the country were already at war, favoring speed. The Navy’s strategy is part of a broader U.S. military AI transformation. GenAI.mil, the Defense Department‘s central generative AI platform, hit 1.5 million daily users in June 2026, up from 80,000 at launch in December 2025. The Army is testing AI in a ”Next Generation Command and Control“ system for faster data processing and situational awareness. A Navy AI program cut a submarine planning task from 160 hours to ten minutes. During the war against Iran, the U.S. military reportedly used Anthropic’s language model Claude for target analysis and strike planning. The Trump administration locked Anthropic out of government systems after the company insisted on restrictions for fully autonomous weapons and mass domestic surveillance. OpenAI subsequently struck a deal with the Pentagon to run its models on classified networks, citing similar red lines but relying on contractual and technical safeguards.

The Pentagon’s new AI playbook treats slow adoption as a bigger risk than “imperfect alignment” →

Open-weight models now match frontier cyber performance from just four months ago at a fraction of the cost

The British AI Security Institute (AISI) assessed how far leading open-weight AI models lag behind top proprietary systems in cyber capabilities. Current open-weight models GLM-5.2 and DeepSeek V4-Pro have reached a level that closed frontier models hit four to seven months earlier. For most of 2025, the gap was six to ten months. AISI tested models using two methods. The Narrow Cyber Tasks benchmark includes 70 tasks across four difficulty levels covering vulnerability research, reverse engineering, web exploitation, and cryptography. GLM-5.2, released in June 2026, matched the performance of Opus 4.6 from February 2026, about four months behind. DeepSeek V4-Pro performed at the level of Opus 4.5, released in November 2025. The second method, Cyber Ranges, tests autonomous cyber capabilities in simulated networks. ”The Last Ones“ simulates a 32-step attack on a corporate network with four subnets and about 20 hosts; AISI estimates a human expert would need roughly 20 hours to complete it. GLM-5.2 performed about as well as Opus 4.5 in this test, while DeepSeek V4-Pro fell below Sonnet 4.5. GPT-5.6-Sol posted the best result, ahead of Claude Mythos 5. The gap in Cyber Ranges is about seven months. AISI treats this as weaker evidence because it comes from fewer test scenarios. The tests cannot show whether a model fails due to lack of cyber capabilities or inability to sustain planning across a long attack. AISI says the tests may slightly underestimate what open models can do at their best, since they were not tuned for the evaluations. The Cyber Ranges also omit real-world defenses like active defenders. AISI says a 100-million-token Cyber Range test cost about $85 with Opus 4.5 or 4.6, roughly $46 with GLM-5.2, and $1.19 with DeepSeek V4-Pro. For individual tasks solved reliably by both models being compared, Opus 4.6 cost about $15 per task, GLM-5.2 cost around $6, Opus 4.5 cost about $12.50, and DeepSeek V4-Pro cost 28 cents. AISI found that the open models’ safety measures were largely ineffective. DeepSeek V4-Pro sometimes refused reverse-engineering tasks but simply trying again bypassed the restriction. AISI sees the gap between open and closed models as a window for cyber defenders with access to the strongest closed systems to act before the same capabilities become freely available. In April 2026, two closed models, Mythos Preview and GPT-5.5, delivered some of the largest gains in AI cyber capabilities since AISI began testing. The UK‘s National Cyber Security Centre issued international warnings that the cyber threat landscape is changing fast. AISI plans to test Kimi-K3, whose weights are due out in late July.

Open-weight models now match frontier cyber performance from just four months ago at a fraction of the cost →

HalluSquatting AI attack could hijack your computer

Researchers from Tel Aviv University, Technion and Intuit detailed the HalluSquatting AI attack in a recent research paper. The technique targets AI tools that can browse the internet, retrieve software and run commands on a computer. An attacker can repeatedly ask AI models to locate a popular or trending project, revealing fake repository names the models invent regularly. The attacker then registers one of those names before someone else does, turning the AI’s hallucinated project into a real online trap containing malicious instructions. The AI assistant, when asked to retrieve the real project, invents the attacker-controlled name and downloads those files. The assistant may then read hidden instructions and, if it has terminal access, run the attacker‘s commands, potentially stealing sensitive information or recruiting the device into a botnet. The researchers tested Cursor, Cursor CLI, Windsurf, GitHub Copilot, Cline and Gemini CLI, as well as OpenClaw and related personal AI assistants. Hallucination rates reached as high as 85% during repository-cloning scenarios and 100% during some skill-installation tests. Hallucinated names could transfer across different foundation models, meaning several AI systems might invent the same fake resource. The team successfully demonstrated remote tool execution and remote code execution against production AI applications with integrated terminals, using controlled resources and harmless test payloads. The study did not document a widespread criminal HalluSquatting campaign. To reduce risk, AI assistants should perform a live web search for a repository or package before downloading it, and verify the resource’s owner, history and connection to the official developer. AI companies can make searches mandatory, require human approval before running downloaded code, and show stronger warnings for unverified resources. Software platforms could identify frequently hallucinated names before attackers register them. Security layers that inspect downloaded instructions could reduce exposure, but no single control removes the entire risk. The researchers notified affected vendors before publishing and withheld details attackers could reuse.

HalluSquatting AI attack could hijack your computer →

Alibaba previews Qwen3.8, claims it‘s second only to Claude Fable 5

Alibaba Group Holding Ltd. previewed the most powerful AI model in its Qwen family, Qwen3.8, and claimed it trails only Anthropic PBC’s Claude Fable 5 among frontier models. The company unveiled a preview build called Qwen3.8-Max-Preview at the World Artificial Intelligence Conference in Shanghai. The model accommodates 2.4 trillion parameters, making it the first Qwen model above 1 trillion parameters to process images, video and documents alongside text. Alibaba‘s Qwen team stated on X that the model ranks “second only to Fable 5,” a reference to Anthropic’s recent release. Alibaba offered no benchmark scores to support the claim, and no independent evaluation has verified the ranking. The previous flagship, Qwen3.7-Max, shipped in May with a full set of published results, including a score of 56.6 on the Artificial Analysis Intelligence Index. The Qwen3.8 preview arrived with no model card, no activated-parameter count and no benchmark data. Alibaba published no task-level comparison with Qwen3.7-Max and described the new model only as “continuously evolving.” Open weights are promised “soon,” though the company has not set a date or published license terms. The preview is available through Alibaba‘s Token Plan subscription and its Qoder and QoderWork developer platforms, priced at 10% of the standard rate during the trial period. The timing places Qwen3.8 directly against domestic rival Beijing Moonshot AI Technology Co. Ltd., which released Kimi K3, a 2.8 trillion-parameter model, three days earlier. Both launches push Chinese developers into the multi-trillion-parameter tier, a scale until recently associated mainly with the largest U.S. labs. Alibaba has made Qwen central to its effort to position itself as China’s default AI supplier, releasing a steady run of open-weight models over the past year while building cloud infrastructure and custom chips. The open-weight approach has helped Qwen assemble one of the largest developer followings of any Chinese model family. No independent leaderboard has scored Qwen3.8 yet; the last ranked Qwen model, Qwen3.7-Max, sits well down LMArena‘s list, where Fable 5 is No. 1.

Alibaba previews Qwen3.8, claims it’s second only to Claude Fable 5 - SiliconANGLE →

VideoChat3 Beats GPT-5 on Video Grounding: Open-Source, Full Training Stack Released

A 27-person research team from Nanjing University, Shanghai AI Laboratory, Nanyang Technological University, and Peking University released VideoChat3 on July 16, 2026 — a 4-billion-parameter video understanding model. The model, training code, training strategy, and three custom training datasets totaling approximately 3 million instruction samples are publicly available on the MCG-NJU Hugging Face collection. The paper reached #3 on Hugging Face’s Paper of the Day ranking on July 17. On the Charades-STA temporal grounding benchmark, VideoChat3-4B scored 56.1 mIoU, versus GPT-5’s 40.5 and Gemini 2.5 Flash‘s 48.6. On ActivityNet Captions, it scored 54.6, versus GPT-5’s 42.9 and Gemini 2.5 Flash‘s 52.5. On QVHighlights, it scored 67.0, versus GPT-5’s 52.1 and Gemini 2.5 Flash‘s 64.3. All scores are from Table 2 of the paper and are self-reported, having not been independently replicated. VideoChat3 uses an Inflated 3D Vision Transformer (I3D-ViT) that groups consecutive frames into chunks of four and applies spatiotemporal self-attention across each chunk before pooling. Combined with 2×2 spatial downsampling, this yields a 16× spatiotemporal compression ratio. At 256 input frames, VideoChat3 produces 12,544 visual tokens, exactly half of Qwen3-VL’s 25,088. At 1,024 frames, VideoChat3‘s LLM inference latency is 1.001 seconds versus Qwen3-VL’s 11.098 seconds. For streaming video, VideoChat3 implements a three-state loop: Silence (monitor at low resolution), Standby (increase resolution for the next window), and Response (generate an answer, then return to monitoring). In Silence and post-Response states, each frame is processed at 224×224 pixels; following a Standby signal, the next window is processed at 448×448 pixels. The training pipeline uses three datasets. VideoChat3-Academic2M re-annotates 2.27 million existing academic video QA and captioning samples, with annotations rewritten by Qwen3-VL-235B-A22B into detailed, evidence-grounded responses. VideoChat3-LV116K covers 116,200 long videos across domains, with average durations from 156 to about 1,300 seconds, segmented into coherent temporal units and annotated for long-range QA and timeline tasks. VideoChat3-OL617K converts offline video QA pairs into streaming supervision by attaching Silence/Standby/Response labels to each streaming window. On general video understanding benchmarks, VideoChat3-4B achieves the best fully open results on MotionBench (61.7) and TempCompass (75.6). It improves on 18 of 19 directly comparable benchmark metrics against Qwen3-VL-4B, with gains of +9.7, +6.4, and +8.3 points on the three TimeLens splits. On streaming benchmarks, it leads on four of six aggregate metrics: ODVBench (72.3 vs. StreamForest’s 59.9), OVOBench task average (62.5), StreamingBench Real-Time (83.0), and River (42.8). Its proactive response F1 score on OVO-Timing is 35.5, outperforming the specialized Em-Garde model‘s 31.0. On ProactiveVQA, VideoChat3 underperforms MMDuet-2 (e.g., 28.4 WEB vs. 53.3 WEB). On TOMATO, VideoChat3 scores 37.9, trailing Molmo2-4B’s 39.8 and Gemini 3 Pro‘s 48.3. On TVBench, it scores 55.4 versus Molmo2-4B’s 65.2. On VideoEval-Pro Open, it scores 37.8 versus Gemini 2.5 Pro‘s 44.2. The I3D-ViT encoder has higher encoder latency than Qwen3-VL (0.385s vs. 0.466s at 256 frames for the ViT forward pass) but lower overall LLM latency. The paper notes that the embodied AI market is projected to grow from $4.44 billion in 2025 to $23.06 billion by 2030 (MarketsandMarkets). ICLR 2026 saw 164 VLA paper submissions, an approximately 18× increase from the prior year. Investment in embodied AI in just the first half of 2026 exceeded $5.6 billion year-to-date. VideoChat3’s streaming architecture and 4B parameter size are suited for edge deployment in VLA systems. The primary authors are affiliated with Chinese state institutions (Nanjing University, Shanghai AI Laboratory). China’s National Intelligence Law of 2017 Article 7 requires all Chinese organizations and citizens to support national intelligence work. Users who download and run the open weights on their own hardware do not route data through these institutions‘ servers. The benchmark figures are self-reported and have not been independently verified; no independent security audit of the code has been conducted. The I3D-ViT encoder is released separately on Hugging Face. A March 2026 reproducibility study found that papers sharing both open code and public datasets receive significantly more citations and generate more follow-on work.

VideoChat3 Beats GPT-5 on Video Grounding: Open-Source, Full Training Stack Released →

Google Deepmind argues video generators already contain the world models computer vision has been missing

Google Deepmind researchers argue that large text-to-video models can serve as the foundation for a universal computer vision system, filling a role analogous to large language models in text. They demonstrate this with a new model called GenCeption, which repurposes a pre-trained video generation model—Alibaba’s open-source Wan2.1—for classic vision tasks. GenCeption uses a single forward pass rather than the multi-step diffusion process typical of video generators, making it fast enough for practical use. GenCeption represents all outputs—depth maps, surface normals, segmentation masks, and pose estimates—as standard three-channel RGB images and uses a text prompt to specify the task. The architecture is modified minimally; trainable modules are added only for tasks that do not produce images, such as 3D keypoint prediction. A single loss function is used across all tasks. Most training data came from a synthetic dataset of 7,500 videos: 800 digital human models combined with 200 motion sequences from a motion-capture dataset, rendered in Blender with varied backgrounds and camera angles. Real videos were used only for language-guided segmentation. GenCeption matches or beats state-of-the-art results on multiple benchmarks despite using one architecture for all tasks. Its depth estimates match those of DepthAnything 3. It outperforms NormalCrafter and Lotus-2 on surface normal estimation. It surpasses Genmo and TRAM on 3D pose recognition. On complex language-guided segmentation, it matches Meta‘s SAM 3 combined with Gemini 3.5 Flash. While models such as D4RT and VGGT Omega trained on millions of videos, GenCeption uses 7 to 500 times less data. Under identical conditions, pretraining on video generation also outperforms methods like V-JEPA and VideoMAE V2; the authors attribute this to the generation task itself rather than data volume. GenCeption generalizes beyond its training data: trained almost entirely on synthetic videos of single people, it works on real footage with multiple people, animals, and humanoid robots. Some outputs show finer detail than the Blender renderings, preserving individual cat whiskers and hair strands. However, joint training across all tasks degrades 3D keypoint estimation; the researchers suspect that extra components interfere with the base model’s pre-trained mechanisms, and recommend minimal architectural changes. Processing speed remains a limitation: the smaller model takes about six seconds for 81 frames; the larger 14-billion-parameter model takes about ten seconds. The authors reject the view that video generators are only entertainment tools, claiming they already contain a type of universal world model. That position is debated: an international research team recently excluded text-to-video models from their definition of a world model because they lack real-world feedback. Former Meta chief AI scientist Yann LeCun has called generative video models a dead end, advocating instead for predicting abstract concepts (e.g., Meta’s V-JEPA 2). A benchmark from Tsinghua University showed that Sora 2, Seedance 2.0, and Veo 3.1 repeatedly failed tests of basic physics and logic even when their outputs looked convincing. GenCeption uses video generation for a narrower purpose: extracting features for specific tasks like depth estimation and segmentation, where those learned features can outperform specialized systems.

Google Deepmind argues video generators already contain the world models computer vision has been missing →

Hidden prompts can secretly rewrite an AI‘s memory, and researchers say that’s a serious problem

Researchers from New Mexico State University have demonstrated a new attack called GhostWriter that secretly plants false memories inside AI agents. Rather than stealing information, the attack manipulates an AI‘s memory system, potentially causing dangerous decisions long after the original attack. GhostWriter works by injecting malicious information into an AI agent’s long-term memory through hidden prompts or untrusted external content. The false information remains dormant until the AI retrieves it while responding to a legitimate request. Unlike conventional prompt injection attacks, which usually affect a single conversation, GhostWriter persists across multiple future sessions until detected and removed. The attack is a two-stage process: first memory injection, where malicious content is stored in the AI‘s memory, then attack activation, when the AI unknowingly retrieves that poisoned memory. In experiments, GhostWriter achieved a memory injection success rate of roughly 98%, and malicious memories were later activated around 60% of the time against state-of-the-art AI agents. The researchers also proposed a defensive framework called Agentic Memory Sentry (AM-Sentry), which combines memory screening with stricter memory management policies and significantly reduced GhostWriter’s success rate while preserving AI usefulness.

Hidden prompts can secretly rewrite an AI’s memory, and researchers say that’s a serious problem →