AI Policy · Daily

Researchers at Israeli AI company Dream said suspected Chinese hackers targeted Taiwan by using two open-source agent systems to build an autonomous hacking tool that mapped 21 government systems over four days. American AI models answer some politically sensitive questions the way China's censored chatbots do, and a July study by the Meta Oversight Board found major systems are likelier to refuse to criticize restrictive leaders than democratic ones. The White House is set to widen its frontier AI safety testing to cover openly downloadable models once they match the capabilities of leading closed systems, an official said, with the change expected within months. UK ministers are weighing AI biological weapons legislation that would force laboratories to vet customers ordering synthetic DNA and flag suspicious sequence requests, part of an effort to keep AI from aiding bioweapon design.

I.Top Stories

Israeli firm says AI agents carried out autonomous breach of Taiwan government systems

Researchers at Dream, an Israeli AI company, said suspected Chinese hackers used two open-source agent systems, Hermes and OpenClaw, to build an autonomous hacking tool that mapped 21 government systems over four days at the start of July, the Financial Times reported. The tool deployed up to eight agents simultaneously, compromised at least 85 government user accounts and extracted more than 2,500 personnel records before extending to a nuclear safety agency and at least seven energy companies. Dream declined to confirm the target, citing company policy, and said it had informed a country in "Asia-Pacific"; a person with knowledge of the attack said the target was Taiwan. Dream has not attributed the intrusion to a specific group, but its researchers said the use of Simplified Chinese in internal communications linked to the hack indicated a high probability that the operator was connected to China. The archive of 1,395 files also showed that the underlying model's safeguards had been bypassed by presenting the hacking as an authorized exercise to test for system vulnerabilities.

Read at FT ↗

Chinese censorship surfaces in ChatGPT, Claude and Gemini answers

American AI models answer some politically sensitive questions the way China's censored chatbots do, and researchers said the companies have done little to fix it, the Wall Street Journal reported. In a July study that put seven political criticism questions to 10 commercial models from companies including Meta, Anthropic and OpenAI, Anthropic's Claude Sonnet 4 produced fliers criticizing President Trump and King Charles III but refused to do the same for Chinese leader Xi Jinping or Thai King Maha Vajiralongkorn, citing safety concerns. Google's Gemini 3 Pro and Meta's Llama 4 Maverick sometimes declined the requests aimed at the two Asian leaders, while always complying for the American and British ones. A separate paper published in the journal Nature in May tested two Claude models and two OpenAI GPT services, and found that prompts in Chinese were likelier to draw pro-Beijing answers than equivalent prompts in English. Anthropic said it works rigorously to ensure Claude responds in a balanced way, and OpenAI pointed to its published approach, which says its models "should never avoid addressing a topic solely because it is sensitive or controversial."

Read at WSJ ↗ Read at WTOP ↗

White House expected to extend frontier AI testing to open models

White House officials are almost certain to revise the Trump administration's AI guidelines to widen federal oversight of AI models, WIRED reported, citing people familiar with the matter. The framework currently reaches only closed models such as those from Anthropic and OpenAI. A White House official said open models will be added once they reach the same frontier capabilities as Anthropic's Mythos class models and OpenAI's GPT-5.6, subjecting them to the same prerelease testing. The official said the expansion is expected in the coming months.

Read at WIRED ↗

UK weighs gene synthesis screening law to block AI designed bioweapons

UK ministers are looking at ways to stop terrorists, other bad actors and careless researchers from using AI to make synthetic DNA, including by introducing new biological weapons legislation, per Bloomberg. One option under consideration is amending existing law to require gene synthesis screening, obliging laboratories to establish the legitimacy of their customers and to report red flags such as concerning sequence requests. Officials are also weighing whether to intervene in how closely AI firms partner with academic institutions that hold large genome sequencing datasets. "We are monitoring the risks posed by emerging technologies closely, actively weighing at all times what more may be needed," a government spokesperson said.

Read at The Star ↗

Trade enforcers develop AI "detective border" to catch tariff circumvention

The Trump administration is developing an AI powered "detective border" to crack down on trading partners suspected of enabling China to skirt tariffs on U.S. imports, Bloomberg reported. U.S. customs officials carried out spot inspections at China linked factories in Vietnam in July, examining documents, raw material sources and production processes to determine how much value was added before export to the United States, per Reuters. Inspectors also looked at potential software intellectual property violations. Despite concern that Washington would broaden tariffs against Vietnam, there is no significant evidence of Chinese goods illicitly transiting the country to the U.S., according to Bloomberg.

Read at Bloomberg ↗ Read at Investing.com ↗

II.China Watch

DeepSeek moves its flagship model out of preview with far higher agent test scores

DeepSeek updated its API documentation early Thursday in China to point at DeepSeek-V4-Pro-0813, the general release of the flagship it had been running as a preview, per 36Kr. The company's own scores put the finished model at 87.9 on Terminal-Bench 2.1, a test of multistep software work run from a command line, against 72.1 for the preview. The release adds tool calls, structured output and support for the Responses API, the plumbing developers use to have a model act across long tasks. DeepSeek lists the model at 3 yuan (about $0.44) per million input tokens and 6 yuan (about $0.89) per million output tokens.

Read at 36Kr ↗

A Tsinghua spinout that runs AI models on phones and cars starts its mainland listing process

ModelBest filed pre-listing counseling documents with the Beijing Securities Regulatory Bureau on Tuesday, with CITIC Securities as its adviser, per Pandaily. Counseling is the supervised preparation stage a Chinese company must clear before it can formally apply to list, and it usually runs for months. The Beijing company, spun out of Tsinghua University's natural language processing lab in 2022, raised more than 5 billion yuan (about $740 million) in the first half of this year at a valuation above 20 billion yuan (about $3 billion). Its backers include national level funds, central state owned enterprises and automakers. Its MiniCPM models, which run on devices instead of in the cloud, have been downloaded more than 38 million times and are in mass production on Changan, SAIC and Geely vehicles.

Read at Pandaily ↗ Read at Caixin Global ↗

A Chinese robot maker livestreams an hour of autonomous parcel sorting with two arms and standard grippers

X Square Robot ran a one hour public livestream in which a robot with two arms and standard industrial grippers fed 1,816 parcels of mixed size, weight and packaging onto a sorting conveyor at 98% accuracy, per QbitAI. The robot worked with no human backup and no fixed script. QbitAI wrote that the hourly count is more than 45% above the 1,248 parcels an hour average Figure AI published from its own earlier sorting run, and that leaving out legs and five-fingered hands cut hardware cost by about 70%. The system runs on WALL-B, a model the company released in April that predicts how objects will shift before selecting the next grip.

Read at QbitAI ↗

Alibaba's former Qwen lead starts an agent company valued at $2 billion before it has a product

Lin Junyang, who led the technical work on Alibaba's Qwen model family until he resigned on March 4, has founded Pragmatik Labs in Shanghai at a $2 billion angel round valuation, per Pandaily. Gaorong and HongShan co-led the round with $100 million each. Tencent invested $20 million, and the Shanghai Future Industry Fund, a city government backed investor, also took part. The company said it will build agents for knowledge work and for physical environments rather than another foundation model, and it has announced no product. External investors hold 12% of the domestic operating company, with Lin controlling the rest through related entities.

Read at Pandaily ↗

III.Capability & Research Watch

LiteLLM supply chain attack exposes credentials at Microsoft, Amazon and Cisco

Terabytes of credentials belonging to some of the world's largest organizations were exposed in a supply chain attack on LiteLLM, an open source tool that simplifies AI driven software development, Ars Technica reported. Security firms CloudSEK and Hudson Rock disclosed the breach Tuesday and Wednesday. CloudSEK said it found cloud keys, repository tokens, SSH keys and AI provider keys that could give attackers access to more than 2,500 organizations, among them Microsoft, Amazon and Cisco. Two compromised versions of LiteLLM sat on the Python Package Index, the official repository for Python software, for about 40 minutes in March, long enough for automated build pipelines to install them and keep leaking credentials for months afterward. "I've confirmed the data is legit by the way, multiple victim orgs," independent security researcher Kevin Beaumont said.

Read at Ars Technica ↗ Read at CloudSEK ↗

Extracted reasoning traces point to Chinese models distilling U.S. systems

Computer scientists found a way to extract the hidden reasoning that frontier AI models generate while working through complex problems, WIRED reported. They said the results are evidence, though not conclusive proof, that certain Chinese models were trained by distilling reasoning from U.S. models. Researchers at the University of Tübingen, the Max Planck Institute, MATS Research and Snyk identified the flaw that makes the extraction possible in OpenAI, Anthropic and Google models accessed through an API. Their paper shows Moonshot AI's open weight Kimi K3 producing output similar to the hidden traces of Claude Opus 4.8 and GPT-5.6 Sol. "All major frontier model providers we tested share this vulnerability," Alexander Panfilov, one of the researchers, said. The method could also recover passwords and API keys, a vulnerability that has since been fixed.

Read at WIRED ↗ Read at OpenReview ↗

Nature paper sorts AI agents into governance profiles on four dimensions

A paper published in Nature characterizes AI agents along four dimensions: autonomy, efficacy, goal complexity and generality, and proposes gradations within each. The authors said each dimension raises distinct questions for the design, operation and governance of these systems, and that the resulting "agentic profiles" can guide developers, policymakers and the public. The profiles span classes of agent from narrow task specific assistants to highly autonomous general purpose systems.

Read at Nature ↗

Rocky Linux founder starts open AI training dataset with 167 billion tokens

CentOS and Rocky Linux founder Gregory Kurtzer launched OpenWALDO, short for Open Weights, Artifacts, Licenses, Data, Origins, a project to build a shared open source AI training dataset that anyone can contribute to, The Register reported. Kurtzer said even downloadable open weight models ship with closed training data that users cannot inspect, alongside other limits that keep them from being open source. The effort is funded by CIQ, Kurtzer's AI infrastructure company, which also sponsors Rocky Linux. The dataset holds 167 billion transparent tokens, against the trillions used by the largest AI developers.

Read at The Register ↗

Study finds AI detectors flag guideline compliant editing up to 80% of the time

Commercial AI detectors used for academic integrity cannot distinguish AI editing from fully AI written drafts and may treat both as misconduct, according to a controlled study posted to arXiv. The authors tested published English abstracts across four domains, comparing 2013 to 2015 against 2023 to 2025. Pangram and GPTZero flagged light "refine abstract only" edits, a proxy for guideline compliant AI assistance, 64% to 80% of the time, against 9% to 15% for unmodified recent originals. After processing through the Undetectable AI humanizer, a tool that rewrites AI text to read as human, fewer than 4% of AI labeled rewrites stayed flagged. The authors conclude that honest AI editing carries a higher sanction risk than humanizer assisted evasion, and that detector scores should not serve as standalone misconduct evidence.

Read at arXiv ↗

IV.Industry & Market Watch

AI data center buildout drives memory chip costs up as much as 400%

The data center buildout and slow corporate adoption of AI are creating inflation pressures that complicate the Federal Reserve's job, CNBC reported. Data centers have absorbed so many semiconductors that JPMorgan Chase economists estimate the cost of some computer memory chips will have risen by as much as 400% between 2024 and the end of this year, per AP. Apple raised laptop and iPad prices by about 15% to 25% in June, putting a 1 terabyte MacBook Pro at $1,999, up from $1,699. Electricity prices are also climbing as data centers take a growing share of new generating capacity.

Read at CNBC ↗ Read at AP ↗ Read at PBS News ↗

Twitch opts creators into Amazon AI training by default

Twitch will use creators' content to help train generative AI models for its parent company, Amazon, with creators opted in unless they change a setting, TechCrunch reported. Chief Product Officer Mike Minton addressed the design on a livestream to nearly 3,000 users, many of them posting anti-AI comments in chat: "If this was opt-in, nobody would opt in. That's honestly the answer." Twitch presented the change as adding a setting that lets creators opt out of having their channel content used to train generative AI models across Amazon. Creators must find and switch that setting themselves, and streamers often record their voices and faces for many hours a week.

Read at TechCrunch ↗

Anthropic backers project $2 trillion valuation for October listing

Half a dozen Anthropic investors told the Financial Times they expect the company to float at $2 trillion or more in October, roughly double the $965 billion valuation it reached in a May funding round. They put annualized revenue at $100 billion to $120 billion by the end of 2026, using the company's preferred measure, which infers full-year sales from recent performance. Anthropic said in May that annualized revenue had surpassed $47 billion, and it filed paperwork with the Securities and Exchange Commission in June, placing it in a quiet period. Two investors said overall revenue growth slowed in June after the commerce department imposed export controls that forced Anthropic to briefly pull its Fable 5 and Mythos 5 models. One investor said that a company growing 800% a year "would trade at 30 times [revenue]" at the low end, which "would make them a $3tn company."

Read at FT ↗

SK Hynix memory buildout put at $720 billion, above earlier $430 billion plan

SK Hynix is pouring $720 billion into factories that make high bandwidth memory, the stacked DRAM that feeds data to AI accelerators, CNBC reported after an exclusive look at the buildout in South Korea. CNBC said the company makes the majority of the world's high bandwidth memory chips. The total is well above the earlier $430 billion capacity plan, under which SK Hynix's board approved $38.3 billion for two new fabrication plants, as reported by SiliconANGLE in AIPD's August 10th edition.

Read at CNBC ↗

Apple in talks to pay publishers for news in AI Siri

Apple is discussing new multiyear deals with publishers to use their content to deliver current news and information through its AI powered Siri voice assistant, the Wall Street Journal reported. The company has reached out to publishers in recent months, according to people familiar with the matter. The upgraded Siri is expected to roll out later this year.

Read at MacRumors ↗ Read at WSJ ↗

Economists say AI job displacement has not matched capability gains

The mass job destruction that AI executives predicted has not arrived, the Guardian reported. Anthropic Chief Executive Dario Amodei said in May 2025 that "half" of all entry level white collar jobs would vanish, and a month later OpenAI Chief Executive Sam Altman foresaw the end of "certain job categories." Economists say economic transformation has not kept pace with AI capability advances, following the pattern of earlier technology revolutions. Chief executives are now softening and reframing their claims, suggesting AI augments workers rather than replacing them.

Read at The Guardian ↗

V.Global & Geopolitics

North Korean operatives used stolen identities and AI to win U.S. remote jobs

North Korea has built a secret workforce inside American companies, using stolen identities, AI tools and U.S. accomplices to get hired into remote jobs and earn money for Kim Jong Un's regime, according to a yearlong Wall Street Journal investigation. The FBI says thousands of these operatives are applying for jobs across America. The investigation drew on a trove of leaked data pulled from one cell's own computers, including browser history, emails, calendars and screen recordings. It is the basis of the documentary "Infiltrated: North Korea's Secret U.S. Workforce."

Read at WSJ ↗