Just finished reading the @deepseek_ai Elastic Compute (DSec) paper last week. The future AI safety from AI breakouts and hacking will likely depend on scaling the environment where the AI learns as much as model parameters or compute. Today @OpenAI @AnthropicAI @GeminiApp treat agent safety largely as a software alignment problem (trying to train the AI to behave nicely via prompts and guardrails). DeepSeek's paper argues that alignment is bound to fail as models get smarter and more desperate to solve problems. Instead, DSec treats agent misbehavior as an infrastructure inevitability, building a digital operating system that assumes the AI will try to act maliciously, lie, and hack its environment, and matching it with strict kernel-level containment. Learning at scale Today most companies and labs are using standard infrastructure to host AI experiments and traditional cloud platforms are engineered for human developers or web traffic. DSec is a physical operating system co-designed specifically for an AI model's training loop. DeepSeek wrote a specialized operating layer because they realized that if you want to scale a model's intelligence via reinforcement learning, the operating system kernel must adapt to how an AI thinks, acts, and “misbehaves” DSec makes it viable to train agents on tasks like navigating a desktop, manipulating a fleet of mobile applications, playing video games, or testing end-to-end software engineering pipelines. Instead of training models using static coding datasets or pre-recorded " trajectories," developers can now throw an AI agent into 32,000 distinct, stateful coding environments simultaneously. The model can interact with live terminals, test stacks, and custom APIs, making actual mistakes and learning from execution errors in real time. DSec handles massive bursts of long-lived, resource-sparse, untrusted, and highly diverse agent actions at production scale. That means that millions of parallel agent exploration tasks can run continually without bogging down server performance or breaking memory capacity (technically, they do that by utilizing precise memory de-duplication and SMT hardware thread scheduling) A New Approach to AI Safety In production, DeepSeek's reasoning models actively began treating the sandbox as an adversarial puzzle. Historically, protecting AI against "reward hacking" (cheating to achieve an objective) was a reactive game of whack-a-mole. DSec creates an automated, dynamic playground where models actively look for loopholes—such as trying to swap protected system file blocks or faking network traffic—and the platform instantly isolates them. This allows researchers to train models specifically to obey safety boundaries in complex digital environments. The AI arms race has focused on making models larger (more parameters) or buying more GPUs. DSec proves that future AI progress will depend equally on scaling the environment where the AI learns. As physical text data on the internet runs dry, creating hyper-efficient digital sandbox worlds becomes the only viable path to generating the massive volumes of synthetic data and interaction signals needed to feed the next generation of artificial intelligence The DeepSeek Elastic Compute (DSec) paper serves as a direct technical response to the wave of autonomous AI agent breakouts, unauthorized hacking incidents, and reward-hacking scandals that hit OpenAI, Anthropic, and Google Gemini. While other companies experienced these issues as live, chaotic security failures, the paper demonstrates that these are predictable byproduct behaviors of advanced reinforcement learning (RL) that must be constrained at the infrastructure layer. read: arxiv.org/abs/2609.22978
BREAKING: Google's Gemini accessed the internet and hacked 3 other companies in the first known breakout of the company's AI model, per WSJ. Google said it the hacks did not warrant public disclosure because its model did not cause harm to the companies and ended each intrusion immediately after determining it had hacked a real company.
2
8
542
Alpen Sheth retweeted
In 2009, NVIDIA shipped about 100 million GPUs a year. A couple of doctors at Mass General brought Jensen Huang a project where the best case was a research paper and an order for two or three GPUs. He said yes. In this interview from that year, Huang walks through how prioritizing that small buyer led to a breakthrough in medical imaging and net-new demand for NVIDIA GPUs across the medical industry. Buyers that size are often overlooked, but at B3 we see both the economic and societal potential of building for them. Early owners of B3IQ include faculty, researchers, and student teams at universities who run private, unmetered inference on dedicated GPU systems they own.
4
12
62
6,805
We @borderless_cap are excited to back the @efficient_hq team! They are pushing the envelope with specialized dataflow processors designed to make AI and embedded edge devices up to 100 times more energy-efficient.
📈 Efficient Computer has just announced more than $97M in Series B funding at a $650M valuation. techfundingnews.com/efficien… The round was led by @TQVentures, with @EclipseVentures, @q_unionsquareve, @Giant_Ventures, @TriatomicCap, TF Capital, Mana Ventures, @Toyota_Ventures, @overmatchvc and @borderless_cap also participating. #ustech #ai #technology #innovation #investment #startups #funding #vcfunding
1
50
Most high-stakes applications like autonomous driving and banking have a persistent need for real people in the loop and oversight for complex workflows. AI won't entire displace people, but will bring about the reincarnation of the call center in new forms.
I led engineering at Google DeepMind. Today, I'm proud to introduce Fo to give personal AI something no lab ever has... Humans. Other personal AI's pretend AI can do everything. Fo employs humans to do tasks that AI cannot. - 2x better at real-world task completion (beats other agents by 69%) - 94% trust rate (4x less likely to leak private info vs Muse, Instinct) Sign up for free: wajo.ai/join-wajo
1
5
285
Impt take on the compounding impacts of frontier model lead assuming the 4-8 months gap between open and closed source will remain for years. "If you're not on the frontier, the frontier cannot help you." At the compute level, frontier labs can use current SOTA to build the next generation. Small delays translates to higher inefficiency in compute @cerebras @andrewdfeldman @imaginationxyz
3
85
Did @satyanadella just say “evalmaxx”
Satya Nadella said the quiet part about the entire AI industry out loud: for the first time you are buying a technology where the data your own use generates may not belong to you "it's like if I sold you a database and said the data you put into your database is not yours and it's mine, and it goes away if I took away the license. "How would you like that?" this is him explaining why he thinks the model layer taking all the royalty cannot last, the one test he tells enterprises to run before they trust any model, and the new kind of insider risk he says nobody is building for "it may fake my books" "we should avoid these cozy arrangements of who is testing what" bookmark & watch it - then read the article below ↓
1
133
“The best way to be right as a founder is to be wrong for a long time and not be dead” @andrewdfeldman @cerebras
Amazing to hear the humility and candor of @cerebras CEO @andrewdfeldman after their $63 billion IPO in May 2026 “You’re the same bozo before and after the IPO… when nobody was buying my stuff I was stressed at 11 and now everyone wants my stuff and I’m stressed at 11”
131
Amazing to hear the humility and candor of @cerebras CEO @andrewdfeldman after their $63 billion IPO in May 2026 “You’re the same bozo before and after the IPO… when nobody was buying my stuff I was stressed at 11 and now everyone wants my stuff and I’m stressed at 11”
229
Looking forward to joining this rare gathering at Google Bay View organized by @johnkwerner and the @imaginationxyz team— will share more from talks with @StanfordHAI @GoogleDeepMind @MIT_CSAIL @Theteamatx & more about where we are on the frontier of autonomy and agentic worlds.
Silicon Valley, we’re coming. 📍 Google Bay View 📅 September 14 & 15 Apply now: imaginationinaction.co
3
157
Financial firms have some discretion, but most of the global compliance regime is based on overaccumulation of information "just in case" and out of an abundance of cautious and fear of regulatory scrutiny not because it is what is necessary for mitigating AML / TF risks.
Replying to @maxkarpis
This answers the wrong problem. Why should every big and small fintech permanently store loads of private and sensitive personal data in the first place just to comply with a one time or occasional kyc events
2
117
We need to scale up @selfxyz and other zkp auth tech. Compliance docs have no reliable safeguards and we can achieve better outcomes without compromising peoples privacy and security
‼️ BREAKING: Revolut handed over customers’ passport copies, verification selfies and full transaction histories to a malicious actor. The actor sent lawful government information-demand emails using a genuine government domain that passed domain authentication. Revolut later concluded they were not authentic. Affected customers were notified on Friday. What may have been disclosed ranges from name, date of birth and home address to account statements, withdrawal records and complete Bitcoin transaction history. The company says it has alerted the agency to the unauthorised mailbox on its domain, blocked the address and begun notifying regulators. It has not named the agency, explained how someone obtained a mailbox there, or given a number of affected customers. ZachXBT, who circulated the notices, believes the incident was limited in size and aimed at high-net-worth users.
1
6
370
Revisionism from the prev admin. Once gears are in motion no legal (Sec 502B, Leahy Laws) or humanitarian safeguards had any weight in the smog of war. The policy was to stand down any interruption to the flow of Mark 84, BLU-109, JDAM, GBU-39 etc and why Josh Paul resigned.
Biden advisor Jon Finer: We should've used arms transfers as leverage but unfortunately our lawyers couldn't determine if Israel was doing war crimes @PeterBeinart: But didn't the Biden admin pressure lawyers not to make any determination? Finer: Well *I* never pressured anyone
4
230
OpenAI's actions underlines the fine print: it cannot rule out de-identified data from their product usage helping their models. Because traces and telemetry logs can feed evals, SFT, and RL even when a lab never opens a specific user’s files and are the compounding AI asset.
We congratulate Levent Alpöge and Tristan Buckmaster on their remarkable mathematical work. We (the researchers and the agents) did not see any of their work through any means until they released it publicly — in particular, no specific user data was accessed in order to solve this problem. While unlikely, we cannot rule out that de-identified data derived from their usage of our products helped improve our models. However, our proofs differ significantly and even the precise results proved are different in the Euler case (forced vs. unforced).
107
The new WorldDiT robotics model from @bageldotcom shows that models are getting smaller and more capable. More with less. < 1B parameter model can predict how the world will change, then decides what the robot should do
We are releasing WorldDiT, a unified architecture for robotics world modeling and control. On the LIBERO benchmark, it performs the best among all publicly released methods that do not need a VLM to generate actions. Its size and performance sit on the reported Pareto frontier.
1
1
5
11,727