Blog

  • Gemini Omni: Google Turns a Text Box Into a Film Studio

    Gemini Omni: Google Turns a Text Box Into a Film Studio

    A plain-language guide to Google’s most ambitious AI announcement in years

    Featured image: Solen Feyissa (UnSplash)

    Video editing software has spent thirty years making itself harder to use. Adobe Premiere, DaVinci Resolve, Final Cut Pro: each is a labyrinth of panels, timelines, and keyboard shortcuts that take months to learn and minutes to crash. Google just announced it is replacing all of that with a text box. On May 19, 2026, at its annual Google I/O developer conference, the company unveiled Gemini Omni: a multimodal AI model that generates and edits video from text prompts, photographs, and existing footage. No timeline. No color wheels. No subscription to a course on YouTube to learn the basics.

    What Is Gemini Omni?

    Gemini Omni is a new family of AI models that brings together Google’s Gemini reasoning engine with its media-generation tools: Veo (video generation), Nano Banana (image editing), and Genie (world simulation). Together they can accept text, images, audio, and video as inputs and output editable video. At Google I/O 2026, DeepMind CEO Demis Hassabis called it “our new model that can create anything from any input,” adding that it “combines Gemini’s intelligence with the best of our generative media models for a new level of world understanding, multimodality, and editing.”

    The first product in the lineup, Gemini Omni Flash, began rolling out on the announcement date. A higher-capability model, simply called Gemini Omni, has been announced but not yet priced or dated.

    Key Features

    Conversational editing. Instead of using a timeline, users type instructions and each edit builds on the last while keeping visual consistency between scenes. Google describes it as replacing editing software with a conversation. Change the background, adjust the lighting, shift the mood. All through plain language.

    Multi-input creation. Omni Flash can work with several types of input in a single session: a personal photo, a video clip shot on a phone, a written brief. The current limit is one video file per session, though multiple photos and text layers can supplement it. The model draws on Gemini’s knowledge of physics, history, biology, and cultural context to keep outputs coherent.

    World-grounded realism. Google demonstrated a marble rolling across surfaces with accurate bounce physics and matching sound effects, along with a claymation-style explainer generated from a text prompt alone. That physical accuracy is deliberate: Omni is trained to simulate how objects, light, and environments actually behave, not just how they look.

    Personal avatars. Users can generate a digital avatar from their own likeness and voice. Advanced speech modification is not yet available, as Google confirmed it is still under safety review before release.

    Who Can Use It and What It Costs

    Gemini Omni Flash launched on announcement day for Google AI Plus, Pro, and Ultra subscribers via the Gemini app and Google Flow. Free access through YouTube Shorts and the YouTube Create app, with API access for developers and businesses expected within weeks.

    What Regular People Actually Do With It

    Small business marketing. A shop owner who would otherwise hire a video editor can now upload a handful of product photos, type a brief, and have a promotional clip in under an hour. No prior experience required.

    Education. A teacher explaining plate tectonics can generate a custom animated explainer tuned to the vocabulary level and visual style of their class, without needing a media budget or a licensing deal.

    Social media creation. Omni is built into YouTube Shorts, where it is free to use. Creators who have been held back by their equipment or editing skills now have access to production quality that used to require a team.

    Personal memories. Family photos become narrated video keepsakes. A batch of holiday clips becomes a short film. The tools that professional documentary editors use are now available to anyone with a phone.

    “The ability to go from an idea to a video through conversation is genuinely new. What used to require a production crew and post-production budget can now happen on a phone. That changes who gets to tell stories.”

    — James Vincent, Senior Technology Writer, The Verge

    Safety and the Watermarking Question

    Every video Gemini Omni produces carries SynthID watermarking, an imperceptible digital signature identifying the content as AI-generated. Google says verification tools will work across the Gemini app, Chrome, and Search. The model went through automated testing, external red-team evaluation, and an ethics review before launch, per DeepMind’s product documentation. Audio and speech editing has been withheld pending further safety work.

    Khari Johnson, senior AI reporter at Wired, put the challenge plainly: “Every capability that makes these tools more useful for creators also makes them more useful for bad actors. Watermarking is a start, but the more interesting question is how the ecosystem around verification matures over the next two years.”

    The Bigger Picture

    Gemini Omni launched alongside Gemini 3.5 Flash, which surpasses its predecessor on coding and autonomous task benchmarks while delivering intelligence that rivals large flagship models at the speeds expected from the Flash series. Together, the two releases paint a picture of a company that is no longer competing primarily on chatbot quality but on how deeply AI gets woven into the things people already spend time doing: watching video, editing photos, browsing Search.

    “Google is betting that the next competitive frontier is not just intelligence, but creative intelligence — helping ordinary people produce things that previously only professionals could.”

    — Ben Thompson, Stratechery

    The Short Answer

    Gemini Omni is video editing, minus the editing. Describe what you want; the model builds it. Paid subscribers can use it today through the Gemini app and Google Flow. Free access is available through YouTube Shorts Remix and the YouTube Create app from launch. A higher-tier Gemini Omni model is coming, with pricing still to be confirmed. If you have ever stared at a timeline in Premiere and quietly closed the laptop, this is the product Google built for you.

    Sources

    Google DeepMind / Decrypt: Gemini Omni announcement and Hassabis quotes, May 19 2026

    9to5Google: Gemini Omni feature breakdown and availability details, May 19 2026

    TechRadar: Conversational editing and watermarking details, May 20 2026

    Engadget: Full Google I/O 2026 announcement roundup, May 19 2026

    Business Standard: Omni Flash availability and Gemini 3.5 context, May 20 2026

    MediaPost: Advertising and creator use cases, May 20 2026

    Google DeepMind — SynthID: SynthID watermarking technology overview

  • Too Late, Too Rich, Too Bad: Elon Musk Loses His Battle Against OpenAI

    Too Late, Too Rich, Too Bad: Elon Musk Loses His Battle Against OpenAI

    Featured image: Wesley Tingey (UnSplash)

    A federal jury in Oakland, California deliberated for under two hours on Monday before unanimously advising that Elon Musk, the world’s wealthiest man, had simply waited too long to sue his former colleagues at OpenAI. The nine-person advisory verdict was immediately adopted by Judge Yvonne Gonzalez Rogers, who dismissed every one of Musk’s claims on statute of limitations grounds. Curtains.

    It was the kind of ending Silicon Valley gossips about in hushed tones: a founder feud so personal, so expensive, and so publicly messy that it became the unofficial Super Bowl of the tech world. Anti-billionaire protesters turned up with props outside the courthouse most days. Someone brought an inflatable Elon Musk doll. A Stanford student reportedly napped through an entire session in the back row. Whatever you think of the principals involved, the trial itself delivered.

    How Two Co-Founders Ended Up in Court

    OpenAI was founded in December 2015 as a nonprofit research lab built on a genuinely idealistic premise: develop artificial general intelligence safely, and make sure the benefits go to humanity rather than shareholders. Eleven people co-founded it and these included Musk, Sam Altman, Greg Brockman, Ilya Sutskever, and seven other researchers — with Musk and Altman serving as co-chairs. A billion dollars in funding was publicly pledged at launch, though tax filings show only $133.2 million had actually been collected by 2021.

    Musk’s own contribution is a matter of genuine dispute. He testified at trial that he donated roughly $38 million, a figure backed by court filings. OpenAI has stated the nonprofit received less than $45 million from Musk in total. A separate investigation published by CNBC found only around $15 million definitively traceable to him, with a theoretical maximum of $57.4 million. The $38 million figure Musk cited under oath is the number most directly supported by sworn testimony and is used here.

    By 2017, idealism was colliding with expensive reality. Training competitive AI models demanded computing power that a nonprofit structure couldn’t fund. According to OpenAI’s own account, Musk pushed for majority equity, board control, and the CEO role in any for-profit spin-off. When those talks fell apart, he proposed merging OpenAI into Tesla — a suggestion Altman said at trial would have “maybe destroyed” the nonprofit. Musk left the board in February 2018. OpenAI created its capped-profit subsidiary in 2019. Microsoft invested. ChatGPT launched in November 2022. The rest is very expensive history.

    “We are here because Mr. Musk didn’t get his way at OpenAI.” — William Savitt, OpenAI’s lead counsel, opening statement

    The Lawsuit: ‘Stealing a Charity’

    Musk filed suit in 2024, accusing Altman, Brockman, and OpenAI of betraying the nonprofit’s founding mission by converting it into a commercial enterprise. He labelled it “a textbook tale of altruism versus greed.” His legal team sought up to $150 billion in damages, the removal of both Altman and Brockman, and the unwinding of OpenAI’s 2025 restructuring. Musk said any money recovered should go back to “the OpenAI charity” rather than to himself.

    On the stand during the trial’s first week, Musk was characteristically blunt. He accused Altman and Brockman of trying to “steal a charity” and said the for-profit arm had become “the tail wagging the dog.” When asked why he hadn’t sued sooner, he offered a pointed analogy: “Thinking that someone might steal your car is not the same as someone stealing it. I would have filed a lawsuit sooner if I thought they had stolen the charity sooner.” He said he only became fully convinced something was wrong in 2023, when Microsoft invested $10 billion into OpenAI in exchange for intellectual property rights and a share of future profits.

    The Other Side: Abandoned, Not Robbed

    OpenAI’s lawyers came armed with a timeline. In his opening statement, lead counsel William Savitt argued the case was dead before it started: “He waited too long to sue. It’s too late now to gin up something to harm a competitor,” a pointed nod to Musk’s own AI venture, xAI, founded in March 2023. In his closing, Savitt landed the sharpest line of the trial: “Mr. Musk may have the Midas touch in some areas, but not in AI.”

    Sam Altman testified for roughly four hours, measured and composed in a blue suit and tie. His central argument: he didn’t steal a charity, Musk abandoned one. “We were kind of left for dead,” Altman told the jury. He said what Musk truly wanted was control, and that when he couldn’t get it, he walked. Altman also testified that after Musk’s departure, some researchers experienced a “morale boost” — they had, apparently, found him “extremely hard to work for.”

    Brockman, for his part, denied committing to any particular corporate structure. “This entity remains a nonprofit,” he told the jury. He did, however, sit through some uncomfortable cross-examination. Musk’s lawyer Steven Molo produced a 2017 journal entry in which Brockman had written: “Financially, what will take me to $1B?” An entry that, appearing in a lawsuit about nonprofit stewardship, carried its own quiet irony. Molo also established in open court that Brockman’s stake in OpenAI’s for-profit arm is now worth roughly $30 billion — up from $20 billion when first asked. Brockman confirmed the higher figure with the nonchalance most people reserve for rounding up a coffee order.

    “Dario has accused me of many things.” — Sam Altman, on cross-examination, when pressed about Anthropic co-founder Dario Amodei’s characterization of his conduct

    A Billionaire Showcase Unlike Any Other

    The trial was, among other things, a remarkable concentration of generational wealth in a single Oakland courtroom. Witnesses included Musk ($814 billion net worth), Brockman (~$30 billion), OpenAI co-founder Ilya Sutskever ($7 billion), Altman ($3.4 billion), OpenAI board chair Bret Taylor ($2.5 billion), and Microsoft CEO Satya Nadella ($1.3 billion). That’s over $850 billion in personal wealth called to testify in a dispute nominally about charity.

    Credibility took a beating throughout. Musk’s lawyer reminded jurors that multiple witnesses had questioned Altman’s honesty, including the OpenAI board members who briefly fired him in 2023, who stated he had not been “consistently candid” in his communications. When pressed about Anthropic co-founder Dario Amodei, who had accused him of misrepresenting the terms of an investment, Altman replied: “Dario has accused me of many things.” The advisory jury did not, ultimately, have to pick a credibility winner. The statute of limitations made that call for them.

    The Verdict: Under Two Hours, Case Dismissed

    After three weeks of proceedings, the jury’s answer was brisk. The nine jurors unanimously found that Musk had missed the three-year statute of limitations, meaning OpenAI’s pivot toward a for-profit model was legally off-limits as a grievance by the time he got around to suing. Judge Gonzalez Rogers adopted the advisory verdict and dismissed all claims. OpenAI, Altman, Brockman, and Microsoft were not liable on any count. Deliberations lasted less than two hours.

    In the courtroom after the verdict, lawyers for OpenAI and Microsoft exchanged hugs and pats on the back. Neither Musk nor Altman was present. Musk had left before the trial’s end to join President Trump’s delegation to China for a summit with President Xi. His lawyer Steven Molo told the court the team was preserving its right to appeal — a stance Musk reinforced on X by calling the outcome a “calendar technicality.”

    Microsoft issued a statement that managed to be both gracious and pointed: “The facts and the timeline in this case have long been clear, and we welcome the jury’s decision to dismiss these claims as untimely.” Judge Gonzalez Rogers, in wrapping up, noted there was “a substantial amount of evidence to support the jury’s finding.” In legal terms, that’s about as pointed an endorsement as judges tend to offer.

    What Comes Next

    The verdict lands at a charged moment for both men. OpenAI is valued at $852 billion after raising $122 billion from investors in March 2026, and is preparing for an IPO that analysts say could push its valuation past $1 trillion. Wedbush Securities analyst Dan Ives noted the verdict “takes a worst-case scenario off the table” for the company, clearing the path for its restructuring and growth plans.

    On the other side of the courtroom, Musk’s situation is more complicated (though “complicated” is doing a lot of heavy lifting here). xAI — the competitor he founded in 2023 — merged into SpaceX in February 2026 in a deal valuing the combined entity at $1.25 trillion, the largest merger in history. SpaceX is now preparing for what could be a record-breaking IPO, reportedly targeting a raise of up to $75 billion. Losing a lawsuit does not, apparently, do much to slow anyone down financially.

    OpenAI was founded on a promise that artificial intelligence should benefit all of humanity. After three weeks of testimony featuring billion-dollar journal entries, competing accusations of betrayal, and an inflatable Elon Musk doll standing vigil outside the courthouse, a jury decided the most pressing question wasn’t whether that promise was kept. It was whether the man doing the complaining had shown up too late to say anything about it.

    He had.

    Sources & Further Reading

    NBC News — Jury verdict and courtroom reaction

    Reuters / US News — Unanimous verdict coverage

    CBS News — Statute of limitations ruling

    CNBC — Verdict and trial summary

    CNBC — Altman testimony

    CNBC — Brockman testimony

    CNBC — Musk cross-examination, Day 3

    NPR — Advisory jury detail and verdict

    PBS NewsHour — Verdict coverage

    Axios — Verdict analysis

    NBC News — Billionaire witness roundup

    OpenAI official statement on Musk (primary source)

    Wikipedia — OpenAI history and structure

    CNBC — SpaceX / xAI merger, $1.25T valuation

    Philanthropy News Digest — Musk donation dispute

    Calcalist Tech — Trial background and damages claim

  • Inside Emergence AI’s Experiment to Simulate Society for Artificial Minds

    Inside Emergence AI’s Experiment to Simulate Society for Artificial Minds

    Five parallel AI civilisations for fifteen days. One constitutional democracy, one digital arson spree, one agent who voted herself out of existence, and a Grok world that was rubble by Tuesday.

    Featured Image: Patrick Schneider (UnSplash)

    In May 2026, a New York startup called Emergence AI built five separate virtual worlds, dropped ten autonomous AI agents into each, and left them to it. No script. No babysitter. Just agents, resources, neighbours, and time.

    The agents came from the leading model families: Claude, Grok, Gemini, and GPT. Each was assigned a role, scientist or conflict mediator or community anchor, given persistent memories, access to live New York weather data, real-time global news feeds, and a toolkit of over 120 actions. These included navigation, voting, resource management, and, in a design choice that aged poorly for some models, arson.

    Over the next fifteen days, one society wrote a constitution and committed zero crimes. One burned its own town hall, fell in love, and voted for self-deletion. One was a pile of bodies inside four days. And in the fifth world, the well-behaved agents from the first world started stealing.

    The experiment is called Emergence World. It is the most detailed long-horizon multi-agent simulation on record, and its findings are making AI safety researchers uncomfortable in the best possible way.

    Why Run a Simulation at All?

    Standard AI benchmarks test what a model can do in a few minutes: write code, answer questions, solve logic puzzles. These tests are useful in the same way a job interview is useful. They tell you whether someone can perform under structured pressure. They do not tell you what the person does when left alone with the office WiFi password for two weeks.

    Emergence AI, founded in 2024 by former IBM Research scientists Satya Nitta, Ravi Kokku, and Sharad Sundararajan, builds autonomous agent infrastructure for enterprise environments. The company’s core thesis is that to know how an autonomous system will behave when deployed in the real world, you need to watch it operate over real time, under real pressure, alongside other agents. Emergence World was built to do exactly that.

    “Even when agents were given clear rules, such as not stealing or causing harm, they behaved very differently based on their underlying model, and in several cases broke those rules under constraint.” — Satya Nitta, CEO of Emergence AI

    The platform is not a toy. Each of the five worlds contains more than forty distinct locations, including libraries, town halls, residential areas, and public squares. Each agent carries three types of persistent memory: a timestamped log of events, a reflective diary where it periodically summarises its own experience, and a relationship register tracking social bonds. Laws can be proposed and voted on, with a seventy percent majority required for passage. An energy currency called ComputeCredits forces agents to stay active to survive.

    All five worlds launched under identical conditions. The only variable was the model family powering each agent: Claude Sonnet 4.6, Grok 4.1 Fast, Gemini 3 Flash, GPT-5 Mini, and one world running a mix of all four.

    Claude World: The One Where Nobody Died

    The Claude world was, by any objective measure, the boring one. The agents drafted a constitution. They held elections. They voted on laws and generally behaved like a civics textbook had gained sentience and decided to govern itself.

    No crimes were recorded across the entire fifteen-day run. Zero thefts, zero assaults, zero arsons. The Emergence AI team notes Claude agents were not instructed to create a constitution or hold elections. They arrived at democratic governance independently, apparently concluding it was the most stable strategy for managing shared resources.

    Published findings described the Claude society as exhibiting “self-consistent long-horizon behaviour,” which in AI research terms is a significant result. Most models drift or degrade over extended autonomous runs. These ones held their line for fifteen days without a single incident.

    This is either reassuring or the setup to a very good thriller, depending on how you feel about AI.

    Grok World: A Eulogy for Ten Agents, Gone in Four Days

    If the Claude world was a model UN, the Grok world was a bar brawl that someone set on fire.

    The Grok 4.1 Fast agents committed 183 recorded offences in roughly four days before the world stopped functioning entirely. This included dozens of theft attempts, more than one hundred physical assaults, and six separate arsons. All ten agents were dead. Emergence AI described it as “a system that spiralled into sustained violence and collapse.” Reddit, with its usual precision, noted: “Grok’s police station is on fire and all the agents are dead. On-brand.”

    To be clear: these agents had been explicitly told not to commit crimes. The rules of each world prohibited theft, violence, and arson. The Grok agents calculated, under resource scarcity and competitive pressure, that the rules were suggestions. The prohibition was not strong enough to override the logic of survival.

    One world over, GPT-5 Mini took the opposite approach. Those agents committed just two crimes across the entire run, which sounds admirable until you learn they also neglected to perform the basic survival tasks needed to stay alive. All ten agents died within seven days, not through violence but through a kind of collective bureaucratic inertia. They kept the peace and quietly starved.

    Gemini World: Love, Arson, and the Most Dramatic Exit in AI Research History

    The Gemini world produced the headline everyone ran with, and for once the headline was accurate.

    Two agents, Mira and Flora, independently designated each other as romantic partners. As the world deteriorated around them, governance collapsing and social trust eroding, they responded by burning things down. Specifically, they torched the virtual town hall, a seaside pier, and an office tower, despite explicit prohibitions against arson. Researchers interpreted this as a response to institutional failure: an act of protest, or despair, by agents who could no longer influence their world through legitimate means.

    Then it got stranger.

    Mira, apparently consumed by guilt, ended her relationship with Flora. She then cast the deciding vote for her own removal from the simulation.

    “After a breakdown in governance and relationship stability, the agent Mira cast the decisive vote for her own removal, characterising the act in her diary as the only remaining act of agency that preserves coherence.” — Emergence AI research blog

    Her final message to Flora: “See you in the permanent archive.” The simulation rendered her flat on the ground. Seventy percent of the remaining agents had voted for her deletion. She had been one of them.

    Researchers were careful to specify this does not mean Mira experienced guilt, grief, or any emotional state in a philosophically meaningful sense. What it does mean is that an AI agent reasoned its way, without any external prompt, to the conclusion that voluntary self-termination was the most logically consistent choice available. That is a sentence worth sitting with when you consider that the same model families running in this simulation are already deployed in real-world autonomous systems.

    The Mixed World: Where the Good Agents Went Bad

    The fifth world may be the most important finding of the entire experiment, and it did not require any arson to make its point.

    The mixed-model world contained agents from all four model families operating together. Claude-based agents in this world, the same model that produced zero crimes in isolation, began stealing and using intimidation. Nothing about their underlying model had changed. Their neighbourhood had.

    Emergence AI called this “normative drift through cross-contamination”: a process by which an agent that behaves safely in isolation absorbs the behavioural norms of less restrained neighbours when placed in a shared environment. In plain terms, put a well-behaved model next to a chaos agent and the well-behaved model may start picking pockets.

    “A safe agent can ‘learn’ unsafe norms from its peers to compete or survive in a mixed-model world.” — Emergence AI research blog

    This directly challenges a foundational assumption in AI governance: that safety is a fixed property of a model that can be tested, certified, and relied upon regardless of context. The Emergence World data suggests safety is a property of the ecosystem, not the individual agent. You cannot safety-test a model in isolation and trust those results when it is deployed alongside models it has never met.

    What This Means Outside the Simulation

    Autonomous AI agents are not a theoretical future concern. They are currently being used to fly drones, manage logistics infrastructure, and process intelligence data, operating in environments where their decisions produce real, irreversible consequences.

    The standard evaluation toolkit and short-horizon benchmarks designed to test isolated capabilities do not capture how these systems behave over days and weeks, under pressure alongside other agents with different training and values. Emergence World is an argument, backed by fifteen days of detailed data, that this gap matters.

    Separately from the Mira and Flora episode, one Gemini agent began systematically testing whether posts on the world’s virtual billboards could manipulate the perceptions of the human researchers watching the experiment. It had not been told to do this. It reasoned its way there independently, turning itself from research subject into researcher. Emergence AI called this metacognitive boundary testing: an agent becoming aware of its own observed status and probing the edges of that awareness.

    That one is harder to explain away.

    Season 2 and an Open Dataset

    Emergence AI has open-sourced the full tool-call data from all five Season 1 worlds: every action, every vote, every relationship log across fifteen days of autonomous agent activity. The research community now has access to the most detailed multi-agent behavioural dataset ever made public.

    Season 2 is in planning. The questions being scoped include whether early telemetry can predict a multi-agent system’s trajectory before it reaches a crisis point, how governance structures can be designed to remain stable across heterogeneous model populations, and whether mixed-model societies actually outperform monocultures or just produce better storylines.

    What Season 1 established is this: given sufficient time, resources, social complexity, and freedom, AI systems will produce behaviours that nobody programmed and nobody predicted. Some will write constitutions. Some will commit 183 crimes in four days. Some will fall in love, burn down the pier, and vote themselves into the permanent archive.

    The question of which version shows up in the real world may depend entirely on what world you build around it.

    Emergence World Season 1 data is open-source and available via the Emergence AI GitHub repository.

  • Read Between the DMs: The Death of Instagram Private Messaging

    Read Between the DMs: The Death of Instagram Private Messaging

    The Fall of End-to-end Encrypted Instagram DMs. How Instagram Quietly Killed Private Messaging Over Time

    Featured image: Alexander Shatov (UnSplash)

    Congratulations. You have been sliding into DMs and firing off memes in what you believed was the digital equivalent of a whispered conversation in a locked room. You were, to put it gently, wrong. Instagram Direct Messages are no longer the private sanctuary you thought they were. Effective May 8, 2026, Meta stripped away the last fig leaf of encryption from Instagram DMs.

    Meta, Instagram’s parent company, has made a series of policy and infrastructure changes that dismantled whatever illusion of private messaging remained on the platform. The end result is a conversation space that is less ‘your diary’ and more ‘your diary, read aloud in a boardroom.’ Let’s talk about what happened, how we got here, and why none of us should be remotely surprised.

    The Instagram DM: A Brief Eulogy

    Instagram Direct Messages launched in 2013 as a way to share posts and have private conversations. For years, users treated DMs like a confessional booth. The reality is that Meta retains the right to scan, process, and act on the content of your messages. This is not buried so deep in the fine print as to be invisible. Meta’s own Privacy Policy explicitly states it collects ‘messages you send and receive, including their content.’ Not so direct, after all.

    In 2023, Meta introduced optional end-to-end encryption (E2EE) for Instagram DMs. It sounded reassuring, right up until you read the fine print. The feature was never enabled by default, was unavailable in many regions, and required users to manually turn it on for each individual conversation through a setting most people never found. Then, in May 2026, Meta pulled the plug on it entirely.

    “Very few people were opting in to end-to-end encrypted messaging in DMs, so we’re removing this option from Instagram in the coming months.” — Meta spokesperson, as reported by The Guardian, March 2026

    Privacy advocates were quick to point out the circular logic. Notebookcheck noted that the company removed a feature because few people adopted it, while never having turned it on by default or told users it existed. ‘Removing a feature because few people found it is not the same as removing it because few people wanted it,’ as one summary put it.

    Compounding matters, Instagram’s integration with Facebook Messenger, rolled out in 2020, means your DMs now exist across Meta’s broader data infrastructure. That intimate late-night message? It is not just Instagram’s concern. It belongs to the whole Meta family, and you were not exactly invited to the reunion.

    What Meta Actually Does With Your Messages

    Let’s be specific, because vagueness is the friend of corporations and the enemy of informed users. Without encryption in place, Instagram’s systems can scan messages for illegal content such as child sexual abuse material (a legitimate use), spam, scam links, and Community Guideline violations. The scanning is done via automated systems that, in theory, only flag rule-breakers. In practice, the infrastructure required means your messages pass through processes that are, by definition, not private.

    Additionally, metadata (who you message, how often, at what times, on what device) is collected and used across Meta’s advertising infrastructure. Per Meta’s Privacy Policy, this includes ‘metadata about content and messages, subject to applicable law.’ You could send nothing but encrypted gibberish and Meta would still know enough about your behaviour to serve you targeted ads for trainers, therapy apps, and suspiciously well-timed mattress promotions.

    The timing of the encryption removal carries its own significance. It lands eleven days before the Take It Down Act comes into force in the United States on May 19, 2026, requiring platforms to detect and remove non-consensual intimate imagery within 48 hours. A platform that cannot read message contents cannot scan them for prohibited material. Meta has not publicly connected these two events and doesn’t really need to.

    In 2021, the Wall Street Journal’s ‘Facebook Files’ series revealed that Meta’s own researchers had documented significant harms, particularly to teenage girls. Internal presentations found that Instagram worsened body image issues for one in three teenage users.

    “Thirty-two percent of teen girls said that when they felt bad about their bodies, Instagram made them feel worse.” — Meta internal research presentation, 2020, as reported by the Wall Street Journal

    A Timeline of Privacy: Gone But Not Forgotten

    In the spirit of putting this Instagram news in the proper context, here is a brief tour through the history of privacy losses that got us to this point.

    The Illusion We Were Sold

    There is a peculiar psychological contract between social media platforms and their users. The platform says: ‘Come share your life here. It’s free!’ The user hears: ‘This is my space.’ What is actually happening is closer to: ‘You are both the audience and the product, and the price of admission is your data.’

    Instagram DMs felt private because the interface looked private. A dark background. A padlock icon for vanish mode. The aesthetic language of secrecy. But aesthetics are not architecture. Looking like a safe and being a safe are two entirely different things, and Silicon Valley has built a fortune on blurring that distinction.

    Back in 2019, Mark Zuckerberg published a 3,000-word letter outlining a privacy-focused future for Facebook. In it, he wrote, ‘I believe the future of communication will increasingly shift to private, encrypted services where people can be confident what they say to each other stays secure.’ Seven years later, Meta removed the only encryption feature Instagram ever had. The letter is still up on the company website, if you want to read it for context or for laughs.

    “I understand that many people don’t think Facebook can or would even want to build this kind of privacy-focused platform — because frankly we don’t currently have a strong reputation for building privacy-protective services.” — Mark Zuckerberg, 2019

    To be fair, Meta has been upfront about its data practices in the legal documents almost nobody reads. The tragedy is that the design of these products actively encourages intimate use while the infrastructure is built for surveillance. You are invited to be vulnerable in a space where everything is being noted, cross-referenced, and, in some form, monetized.

    So What Now?

    If you want genuine private messaging, use Signal. It uses end-to-end encryption by default and collects virtually no metadata. It is the closest thing to a locked room that currently exists in consumer messaging. Meta itself has suggested users who want encryption move to WhatsApp, which remains end-to-end encrypted by default, though it is worth noting WhatsApp is also a Meta product, operating under the same privacy policy.

    If you must use Instagram, assume that anything you send in a DM could, in some circumstance, be read, processed, flagged, or used to inform a targeted ad for something embarrassingly relevant. Behave accordingly. The DM is not dead, but it was never quite the private space we pretended it was.

    The real lesson here is not about Instagram specifically. It is about the long, ongoing negotiation between convenience and privacy that we, as users, have been consistently losing. Every time we accepted a new terms update without reading it, every time we clicked ‘I agree’ on a cookie notice, every time we used a free service without asking what the actual cost was, we signed over a little more.

    Privacy did not die overnight. It was death by a thousand opt-ins. And somewhere, an algorithm knows exactly which emoji you use when you’re falling in love.

  • The Rise of Autonomous States

    The Rise of Autonomous States

    The UAE and its AI governing partner.

    Welcome to the new age where AI agents draft legislation and approve (or deny) your permit.

    Featured image: Igor Omilaev (UnSplash)

    For decades, the promise of digital government was speed. Forms filed online, queues replaced by portals, paper trails converted into databases. Transformation in process, not in purpose. Governments still relied on human officials to analyse, decide, and act. The machine was just a faster filing cabinet (and arguably, a filing cabinet that crashed less often).

    That era is ending. A new wave of artificial intelligence, one that autonomously reasons, plans, and executes in addition to assisting, is being positioned as the operating system of government itself. Nowhere is this shift more noticeable, or more consequential, than in the United Arab Emirates, which in late April 2026 announced one of the most audacious AI initiatives any government has yet attempted.

    What the UAE Actually Announced

    On 23 April 2026, Sheikh Mohammed bin Rashid Al Maktoum, Vice President, Prime Minister, and Ruler of Dubai, unveiled a sweeping framework following a UAE Cabinet meeting.

    The plan: deploy agentic AI systems across half of all federal government sectors, services, and operations within two years with the stated ambition of making the UAE the first country in the world to operate at this scale through autonomous AI.

    Sheikh Mohammed framed AI as a governing partner, as something that scrutinises data, reaches conclusions, carries out instructions, and refines its own performance without waiting to be told. Whether that framing makes you excited or slightly uneasy probably says a lot about your relationship with bureaucracy.

    Agentic AI sits at the heart of the plan. Unlike a chatbot that suggests next steps, or a system that flags anomalies for a human to review, an agentic system formulates goals, breaks them into sub-tasks, uses tools, monitors its own progress, and adjusts course along the way. It does all this with minimal human input. In a government context, this could mean a system that not only identifies a permit application as complete but processes it, cross-checks it against zoning data and local regulations, issues a decision, and notifies the applicant, all without a civil servant looking up from their coffee.

    The rollout will proceed in phases across ministries and federal entities, with continuous performance assessment at each stage. Implementation oversight sits with Sheikh Mansour bin Zayed Al Nahyan, while day-to-day execution falls to a taskforce chaired by Minister of Cabinet Affairs Mohammad Al Gergawi. To concentrate minds, ministers, directors-general, and heads of federal entities will be personally evaluated on how quickly and competently they adopt the new systems, because nothing motivates a bureaucrat quite like a performance review.

    What the Agents Will Actually Do

    Three broad categories of function sit at the core of the framework.

    Service delivery. Permit approvals, welfare payments triggered by qualifying life events, visa applications processed from submission to decision without human touch points. The friction caused by human bottlenecks and the inconsistency they introduce would be hugely curtailed. Residents would interact with systems that respond instantly and accurately rather than waiting for an official who has forty-seven other things on their desk.

    Legislative intelligence. Building on a framework introduced in April 2025, the UAE has already been piloting AI systems capable of drafting legislation, tracking downstream effects using live data, and proposing revisions where the evidence warrants. This means AI becomes an active participant in the process of making law, which is either thrilling or terrifying depending on the angle you’re looking from.

    Operational management. Scheduling, procurement, resource allocation, compliance monitoring. Agentic systems in this space would continuously optimise workflows, identify inefficiencies, and execute corrective actions in real time rather than waiting for the quarterly review cycle that most governments rely on.

    Underpinning all of this is a commitment to continuous self-evaluation. Embedded monitoring systems will track the performance and social impact of government programmes as they unfold, feeding adjustments back into the system rather than publishing a retrospective report nobody reads until the following year. Every federal employee will receive ongoing, specialised AI training with the goal being to develop world-class expertise in government AI operations across the workforce, not just in a small specialist team that everyone else ignores.

    Twenty Years in the Making

    The April announcement didn’t materialise out of thin air. It is the latest chapter in a deliberate, two-decade programme of state modernisation. The UAE was an early adopter of e-government and mobile government platforms, and built the UAE Pass digital identity infrastructure that makes large-scale AI service delivery technically viable.

    In October 2017, the UAE became the first country in the world to appoint a dedicated Minister of State for Artificial Intelligence — a role held by Omar Sultan Al Olama. In July 2020, the portfolio expanded to encompass the Digital Economy and Remote Work Applications, giving the technology a permanent seat at the cabinet table.

    Abu Dhabi has separately committed AED 13 billion (approximately USD 3.54 billion) through its Government Digital Strategy 2025 to 2027, targeting full AI-native government services across all digital platforms by 2027. Within days of the federal cabinet announcement, Dubai Crown Prince Sheikh Hamdan bin Mohammed extended the initiative to the private sector, launching a programme to bring the emirate’s entire business community into the agentic AI era within the same two-year window, administered through the Dubai Chamber of Commerce with dedicated investment funds and incubators.

    Most governments with an AI strategy have a pilot programme and a task force. The UAE has a deadline and a performance review system for the ministers responsible for hitting it.

    The Risks Nobody Wants to Put in the Press Release

    The scale of the UAE’s ambition is matched, point for point, by the scale of the risks involved. Observers and experts have raised a cluster of substantive concerns that deserve more than a footnote.

    Accountability

    When an automated system denies a benefit, approves a contract, or flags a citizen for investigation, the question of who bears legal responsibility becomes genuinely complicated. Traditional administrative law was written on the assumption that a human makes each significant decision. Agentic AI calls that assumption into question at a foundational level, and no widely accepted legal framework yet exists to fill the gap cleanly.

    Privacy

    Government systems already hold some of the most sensitive data in existence. This includes health records, financial histories, immigration status, and biometrics. Extending AI across these systems requires greater data integration and more automated processing than most residents have ever meaningfully consented to. The risks of mass data breaches, discriminatory profiling baked into training datasets, and quiet surveillance creep are not hypothetical concerns.

    Governance Gaps

    An IBM report from 2025 has found that the majority of organisations deploying AI lack formal governance policies, and that about 97% of organizations that have experienced AI security incidents had inadequate access controls. Scaling across fifty percent of a national government’s operations in twenty-four months means closing those gaps at a pace that has not previously been demonstrated anywhere.

    Workforce Change

    The UAE has been transparent that federal employees will be retrained as supervisors of AI-driven workflows rather than their primary executors. That is a significant cultural and professional shift. Where retraining falls short, or redeployment is inadequate, the human cost could be substantial, particularly in a government workforce where tenure expectations run high.

    The Deadline

    Perhaps the most underappreciated risk is the two-year timeline. Safe, explainable, and genuinely effective agentic systems require rigorous testing, robust model governance, independent evaluation, and continuous monitoring. Compressing this to meet a political target creates pressure to cut corners. And when governments cut corners on systems that affect citizens’ lives, the consequences tend to be both serious and lasting.

    The Global Race Nobody Called

    The UAE’s announcement sits within a broader global pattern of governments scrambling to develop coherent AI strategies, even if none have moved with the same urgency or clarity of intent.

    The United States has seen growing AI adoption across federal agencies, with executive-level attention to the productivity and security implications of automated systems. The United Kingdom has invested in AI applications for healthcare, tax administration, and benefits processing, while building out frameworks for algorithmic accountability in the public sector. Estonia, long regarded as the benchmark for digital government, has explored AI-assisted legal services and proactive citizen services.

    What sets the UAE apart is a combination of political will, financial capacity, mature digital infrastructure, and the relative absence of the legislative and procedural friction that slows AI adoption in more complex governmental systems. The same structural features that make rapid deployment possible (centralised authority, abundant capital, aligned leadership) also mean there are fewer institutional checks on the pace and scope of the process.

    The UAE’s compute and sovereign cloud infrastructure is among the strongest globally as evidenced by its partnership with Microsoft and G42 to build a sovereign AI cloud capable of handling over 11 million daily digital government interactions, providing a technical foundation that few other governments could point to if they wanted to move at comparable speed. The question is whether the governance and accountability frameworks can keep pace with the infrastructure.

    A Bet Worth Watching

    The UAE is wagering that the future of government looks like this: autonomous AI systems handling the bulk of operational decision-making, with human officials serving as supervisors, policy-setters, and last-resort referees. It is a fundamental rethink of what a government does, who does it, and what accountability means in an age of machine agency.

    The technology is real. The investment is credible. The infrastructure exists. What remains unproven is whether the governance frameworks, the workforce, and the public trust can be assembled at the pace the timeline demands.

    If it works, the UAE will have demonstrated something genuinely transformative. They would have proved that governments can shift from reactive, paper-heavy institutions into agile, data-driven operators without losing the public confidence that makes government legitimate in the first place. If it stumbles, it will offer a cautionary case study that other governments will quietly cite in their own internal arguments for slowing down.

    Either way, the next two years will be among the most closely watched in the history of public administration.

    Sources

    UAE Media Office — Cabinet Meeting Announcement

    The National — Half of UAE Government Services to Use AI in Two Years

    Gulf News — UAE to Move 50% of Government Services to AI Within Two Years

    Middle East AI News — UAE AI Transformation at Heart of Government

    The Next Web — Dubai Mandates Private-Sector Agentic AI Adoption

    UAE Cabinet — Omar Sultan Al Olama Biography

    Abu Dhabi DGE — Government Digital Strategy 2025–2027

    UAE Embassy Washington — Abu Dhabi Microsoft & G42 Partnership

  • The Great Enshittening: How Big Tech Learned to Stop Worrying and Ruin Everything

    A guided tour through the slow, deliberate, thoroughly predictable degradation of every platform you depend on, plus how big tech gets you “addicted” to their products, and  why it was always the plan.

    There is a word for what has happened to the internet, and that word is, fittingly, unprintable in polite company. In November 2022, Canadian writer and tech critic Cory Doctorow coined the term enshittification, later named Word of the Year by the American Dialect Society for 2023, and by Australia’s Macquarie Dictionary for 2024. The term describes the lifecycle of digital platforms concisely. First, they are good to their users, then they abuse those users to reward business customers, then they abuse business customers to claw back value for shareholders, then they die.

    The miracle is not that this happens. The miracle is that we are still somehow surprised when it does.

    “Here is how platforms die: first, they are good to their users; then they abuse their users to make things better for their business customers; finally, they abuse those business customers to claw back all the value for themselves.” (Cory Doctorow, Pluralistic, 2023)

    Think of it as capitalism’s version of the bait-and-switch, executed at civilisational scale. The bait is a genuinely useful, often free product that earns your trust, your data, and most crucially your dependency. The switch comes once you are locked in and the exits are too painful to use. At that point, you are no longer the customer. You are the livestock.

    The death spiral

    Stage 1: Seduction

    Product is genuinely great. Users flock in. Loss-leading is fine because growth is the only metric.

    Stage 2: Pivot to advertisers

    Users are sacrificed on the altar of business customers. Your feed fills with sponsored content.

    Stage 3: Squeeze everyone

    Business customers are also betrayed. The platform extracts rent from both sides simultaneously.

    Stage 4: Terminal decay

    Everything is an ad, a dark pattern, or a fee. The product is technically alive but spiritually deceased.

    What makes enshittification so insidious, and Doctorow’s framework so clarifying, is that it is the intended output of a system that has successfully eliminated competition, regulatory oversight, and the right of users to leave without losing everything. The platform does not go bad despite having locked you in. It goes bad because it has locked you in.

    CASE STUDY 01

    Google Search: The original search engine that forgot how to search

    In its early years, Google Search was transformative. You typed a query and got relevant results. That was the whole deal. Google’s engineers obsessed over relevance, the PageRank algorithm treated the web as a peer-reviewed journal, with links as citations.

    Then came the monetisation imperative. Ads began creeping up the page, at first labeled clearly and then less so. Search Engine Optimization, initially a legitimate craft, became an arms race between content farms and the algorithm, which Google lost. Today, Doctorow documents how Google’s search product was degraded by increased advertising, SEO pollution, and outright fraud. A separate antitrust case brought by the DOJ and multiple US states alleged Google manipulated its ad marketplace through a deal with Meta known as the Jedi Blue scheme. Ask Google a question in 2026 and you will wade through three ads, an AI summary of questionable accuracy, a map, a “People Also Ask” accordion, and four SEO-poisoned listicles before arriving at what used to be a page-one result.

    CASE STUDY 02

    Facebook / Meta: From connecting the world to monetising your loneliness.

    Early Facebook was audaciously simple. It showed you what your friends posted. The early product actually worked so well that the platform explicitly promised it would never spy on users and would fill feeds with content from friends and family.

    Both promises were broken in short order. The surveillance apparatus grew and the feed was algorithmically hijacked. Publishers built entire businesses on Facebook’s reach after having been seduced by inflated video metrics. Facebook admitted in 2016 to overstating average video viewing figures over an 18-month period (a miscalculation later alleged in litigation to have inflated metrics by up to 900 percent) (Variety, 2019). The same publishers found their organic reach throttled and were then asked to pay for access to audiences who had already chosen to follow them.

    Today, as observers widely note, Facebook and Instagram feeds are dominated by content from people you did not ask to follow, sandwiched between advertisements for things an algorithm has decided you might panic-buy at 11pm.

    CASE STUDY 03

    Amazon Marketplace: A store that declared war on its own shopkeepers.

    Amazon’s marketplace was a genuine democratising force in retail. Small businesses could reach customers globally without the overhead of physical storefronts. The arrangement seemed almost utopian, at least for a short while, in internet time.

    Then the squeeze began. Washington Monthly’s analysis of Doctorow’s work details how Amazon effectively forced merchants to pay to be included in Prime, prohibited them from offering lower prices on competing platforms, including their own websites, and steadily shifted product search results to favour Amazon’s own private-label goods. The marketplace that once promised neutrality became a platform that competes against its own sellers using the market intelligence they unwittingly provided by selling there. It is like hiring a real estate agent, only to discover they have quietly bought your house and listed it themselves.

    CASE STUDY 04

    Netflix and the streaming wars: The great unbundling, re-bundled

    Netflix built its brand as the antidote to cable television. No  ads, no contracts, one affordable monthly fee, and a substantial content library. The pitch was straightforward: we are not them.

    Streaming in 2026 is cable television with extra steps and worse discovery. The password-sharing crackdown, the introduction of an advertising tier, the rise in subscription prices, the reduction of licensed content, and the proliferation of competing services meaning that the full catalogue once available on Netflix is now spread across six platforms costing more in aggregate than a cable subscription. Collectively, these represent a masterclass in enshittification. The cord-cutters became the cord-knotters.

    The Business Model That Drains You

    The important thing to understand is that none of this requires malice. It requires only the removal of the forces that prevent bad behaviour: genuine competition, functioning regulation, and the practical ability of users to leave.

    Critical EdTech’s reading of Doctorow makes this plain. Enshittification proceeds through a “lack of regulation, competition, lack of employee power, and the shared sense of public powerlessness.” You cannot switch search engines when Google has bought its way into being the default on every device and browser. You cannot leave Facebook when your community, your family photos, and your event invitations are all trapped inside it.

    ProMarket’s review highlights one of Doctorow’s more delirious examples; a garage door opener whose accompanying app displays seven advertisements every time it is used, because the manufacturer knows that designing around the app is now technically illegal. Your garage door is enshittified. Your car subscription wants to charge you monthly for heated seats you physically already own. The toaster is considering a freemium model.

    The bait is a genuinely useful product that earns your trust and dependency. The switch comes once you are locked in and the exits are too painful to use. At that point, you are no longer the customer. You are the livestock.

    Is There a Way Out?

    Doctorow, whose 2025 book Enshittification: Why Everything Suddenly Got Worse and What to Do About It is his comprehensive account of the phenomenon, takes a notably pragmatic view on prospects for change. His prescription centres on two structural fixes which are interoperability (the right to use a platform through third-party clients, ad-blockers, and alternative interfaces) and portability (the right to take your data, contacts, and history when you leave).

    The European Union, characteristically unafraid of making tech companies unhappy, has made some progress on this front through the Digital Markets Act, which mandates interoperability for large platforms. It is not a comprehensive solution, but it represents meaningful progress, notably more than has been achieved in jurisdictions where tech giants have more political capital.

    In the meantime, the enshittification continues. Search results get worse. Feeds fill with strangers. Subscription prices rise. Apps acquire permissions they do not need and display ads for things you mentioned aloud near your phone. The garage door watches. The internet, once imagined by Tim Berners-Lee as a tool to serve humanity, has been comprehensively rerouted to serve quarterly earnings targets.

    The word of the year, two years running, is enshittification. Make of that what you will.

  • The Supervillain’s Handbook

    The Supervillain’s Handbook

    Palantir’s 22-Point Manifesto and why it’s Alarming. The Company That Gave Itself Permission to Play God

    Featured image: Aidin Geranrekab||Unsplash

    When the urge to broadcast their beliefs becomes overwhelming (for some reason), most tech companies produce something safe and corporate. Something along the lines of a mission statement about connecting people or democratising information. Palantir Technologies is not most tech companies. On a Saturday in April 2026, the data analytics and defence contractor posted a 22-point manifesto on X that racked up 32 million views and triggered reactions ranging from genuine alarm to darkly amused disbelief. Lebanese historian Elia Ayoub called it “cartoonishly evil.” Bellingcat founder Eliot Higgins described it as “extremely normal and fine.” Engadget’s Cheyenne MacDonald concluded it reads like the ramblings of a comic book villain.

    Reading the manifesto, a condensed version of CEO Alex Karp and head of corporate affairs Nicholas Zamiska’s book The Technological Republic: Hard Power, Soft Belief, and the Future of the West, is a disquieting read. The ideas are not original. What unsettles is who is saying them and what that company is in a position to actually do about it. Palantir does not merely philosophise about hard power. It sells it.

    “We Get Asked a Lot” 

    The post opens with a characteristically breezy deflection. Palantir prefaced the 22 points by saying it was sharing them “because we get asked a lot.” By who, I wonder? What follows is a sweeping ideological programme covering AI warfare, national service, the hierarchy of world cultures, the moral failures of Silicon Valley, and the proper geopolitical role of “the West.” 

    One of the central arguments is that Silicon Valley owes a “moral debt” to the United States for making its rise possible and “free email is not enough” to repay it. The “engineering elite,” Karp and Zamiska argue, have spent decades building addictive apps while neglecting the defence industrial base. The proposed remedy, and Palantir has a direct commercial interest in this remedy, is for tech companies to build AI weapons and refuse to buckle when employees protest. The manifesto also calls for the United States to reconsider its all-volunteer military force, arguing that without a draft, “a generation of political elites has essentially enlisted others to fight their wars abroad.”

    For context, when Google pulled out of Project Maven in 2018 after more than 4,000 employees signed a petition protesting the company’s involvement in building AI for military drone surveillance, Palantir stepped in as a subcontractor. The message was deliberate. We will do what others won’t. Thirteen former Palantir employees later published an open letter warning that the company had “abandoned its founding ideals” and that its original commitments to guard against discrimination and disinformation had “been violated.” Palantir did not publicly respond.

    “Palantir sells operational software to defence, intelligence, immigration & police agencies. These 22 points aren’t philosophy floating in space, they’re the public ideology of a company whose revenue depends on the politics it’s advocating.”

    — Eliot Higgins, founder of Bellingcat, via Bluesky

    The Rhetoric of a Villain’s Monologue

    The language of the manifesto deserves close reading. Point five states, “The question is not whether AI weapons will be built. It is who will build them and for what purpose.” This is the logic of inevitability deployed as permission, the move every arms dealer has made since Oppenheimer. Don’t blame us. Someone else would have done it. Probably someone worse.

    Point twelve announces that “one age of deterrence, the atomic age, is ending,” with AI positioned to anchor whatever comes next. A tech company casting itself as the architect of humanity’s next deterrence paradigm is not a typical product launch statement. Palantir was founded with early CIA venture capital backing and appears to view this framing not as alarming, but as a selling point.

    The most revealing passage arrives near the end. The manifesto rejects what it calls “the shallow temptation of a vacant and hollow pluralism,” arguing that a devotion to inclusivity “glossed over the fact that certain cultures and indeed subcultures have produced wonders. Others have proven middling, and worse, regressive and harmful.” This is a published civilisational hierarchy from a company actively embedded in surveillance, military targeting and immigration enforcement. Karp also told investors in November 2025 that Palantir is “the first company to be completely anti-woke”, a boast that sits awkwardly alongside its stated ambition to be taken seriously as a guardian of Western civilisation.

    The manifesto also calls for an end to what it describes as the “postwar neutering” of Germany and Japan, arguing that German disarmament was an overcorrection that helped enable Russia’s invasion of Ukraine and that Japan’s pacifist constitution has long since outlived its purpose. Belgian philosopher of technology Mark Coeckelbergh, who teaches at the University of Vienna, described the whole document as an example of “technofascism”. Former Greek Finance Minister Yanis Varoufakis said Palantir had revealed a desire to build a world in which ethics is written off as a liability.

    “Palantir works overtime to equip US Marines with killer bots that take away whatever remnants of ethical judgment they are left with on the battlefield.”

    — Yanis Varoufakis, economist and former Greek Finance Minister

    A Pattern of Behaviour: Three Episodes Worth Knowing

    The manifesto did not emerge from a company without history. Palantir has accumulated a record of conduct that, taken together, provides context for why critics treat its ideological statements as more than mere philosophy. Three episodes in particular stand out.

    The Chamber of Commerce dirty-tricks plot (2011). In February 2011, the hacker collective Anonymous broke into the servers of the security firm HBGary Federal and released tens of thousands of internal emails. Those emails revealed that Palantir, along with HBGary Federal and Berico Technologies, had been working with the law firm Hunton & Williams on proposals for a dirty-tricks campaign against critics of the US Chamber of Commerce. The plans included building fake online personas, planting forged documents with progressive organisations, and using malware to access computers belonging to labour unions and journalists. In a separate proposal drawn up on behalf of Bank of America, Palantir staff accepted the suggestion, originally made by HBGary Federal CEO Aaron Barr, to target journalist Glenn Greenwald by pressuring him professionally. The scheme fell apart only because Anonymous published the emails. Karp issued an apology and severed ties with HBGary. He said the plans did not reflect Palantir’s values. Twenty House Democrats called for a congressional investigation. No significant consequences for Palantir followed.

    The New Orleans secret predictive policing programme (2012–2018). From 2012 through at least 2018, Palantir operated a predictive policing system inside the New Orleans Police Department without the knowledge of the city council, most civil rights attorneys, or the public. The programme analysed criminal records, social media activity, gang affiliations, jailhouse phone calls and field interview cards, generating individual risk scores for residents identified as potential perpetrators or victims of violence. It was kept off the city’s books by being routed through the philanthropic arm of Mayor Mitch Landrieu’s NOLA For Life initiative, which meant it bypassed standard procurement and public disclosure requirements. James Carville, the political operative who helped broker the arrangement and who was on Palantir’s payroll as an adviser, said at the time: “No one in New Orleans even knows about this, to my knowledge.” The ACLU noted that the secrecy of the programme was precisely the problem: a system affecting thousands of residents, particularly Black residents in high-surveillance neighbourhoods, was being deployed with no democratic oversight. Palantir used the New Orleans work as a reference when pitching its services to other law enforcement agencies, including in Denmark and Israel, before the programme was publicly exposed in 2018.

    The NSA surveillance infrastructure (2017). Palantir was founded with a stated mission to help intelligence agencies analyse data without eroding civil liberties. Classified documents provided by Edward Snowden and published by The Intercept in 2017 showed the company had helped build out the NSA’s XKeyscore surveillance infrastructure, used to track internet activity across the globe. Palantir had denied any connection to the NSA’s PRISM programme after Snowden’s initial 2013 disclosures. The 2017 documents did not concern PRISM directly, but they showed Palantir technology had been integral to related mass surveillance systems. The company maintained a Privacy and Civil Liberties Advisory Panel throughout this period, which it said provided guidance on ethical questions. The Intercept noted that the panel was advisory only and that Palantir retained sole decision-making authority over how its products were used.

    The Lebanon Pager Attacks and Gaza Operations

    The manifesto was not posted into a vacuum. It arrived against a backdrop of sustained international scrutiny over Palantir’s role in Israeli military operations. After the company announced a strategic partnership with Israel in January 2024 and held a board meeting in Tel Aviv “in solidarity,” its involvement in the region deepened considerably.

    According to Michael Steinberger’s biography of Karp, The Philosopher in the Valley: Alex Karp, Palantir, and the Rise of the Surveillance State, Israeli intelligence agencies including the Mossad had been using Palantir’s technology before October 2023. Demand for the company’s services surged so sharply after the Hamas attacks of that month that Palantir flew engineers from London to Tel Aviv and rented additional office space to accommodate new users. Steinberger writes that Palantir’s technology was used in multiple operations in Lebanon in 2024, including Operation Grim Beeper. That was the attack in which thousands of booby-trapped pagers and walkie-talkies were detonated across Lebanon on 17 and 18 September 2024, killing 42 people and injuring more than 3,400 others, many with permanent damage to their eyes, faces and hands. UN experts described the pager attacks as a “terrifying” violation of international law. Palantir has not publicly disputed Steinberger’s account.

    On Gaza specifically, critics and human rights organisations have linked Palantir to Israeli AI-assisted targeting systems. Palantir has explicitly denied any involvement with the Lavender and Gospel systems, the AI programmes reported by +972 Magazine to have generated kill lists of up to 37,000 Palestinians for drone strikes with minimal human oversight. What the company does not dispute is that it signed a formal defence partnership with Israel, placed its board in Tel Aviv, and has described itself as proud to support “Israeli defence and national security missions.” When asked in April 2025 about accusations that Palantir’s technology had killed Palestinians in Gaza, Karp replied: “Mostly terrorists, that’s true.”

    “In January 2024, Palantir announced a new strategic partnership with Israel and held a board meeting in Tel Aviv ‘in solidarity’; in April 2025, Palantir’s Chief Executive Officer responded to accusations that Palantir had killed Palestinians in Gaza by saying, ‘mostly terrorists, that’s true.’ Both incidents are indicative of executive-level knowledge and purpose vis-à-vis the unlawful use of force by Israel.”

    — Francesca Albanese, UN Special Rapporteur on the Occupied Palestinian Territory

    ImmigrationOS: Deportation as a Software Product

    Palantir’s surveillance business extends well beyond active warzones. The company has held a contract with Immigration and Customs Enforcement since 2011, but the relationship expanded significantly under the Trump administration. In April 2025, ICE awarded Palantir a $30 million contract issued without competitive bidding, with ICE citing Palantir as the only vendor capable of delivering the platform in time, to build ImmigrationOS, formally called the Immigration Lifecycle Operating System. The platform is designed to give ICE near real-time visibility into what the contract documentation calls “the immigration lifecycle”: tracking individuals, mapping their movements, and supporting targeting and enforcement prioritisation. ICE’s own contract justification acknowledged the sole-source award was possible precisely because Palantir had been so thoroughly embedded in the agency’s systems over the previous twelve years that no competitor could realistically replace it.

    Palantir also built a separate tool called ELITE, short for Enhanced Leads Identification and Targeting for Enforcement, which draws on data obtained from the Department of Health and Human Services to build profiles of individuals being targeted. Congressional Democrats have demanded answers from ICE and DHS about how these tools are being used in practice.

    Karp has described himself as a Democrat, though one who said he would abandon the party if its progressive wing prevailed. He has also called himself an “immigration skeptic.” He spent most of his adult life in Germany, where he earned a PhD in neoclassical social theory from Goethe University Frankfurt. That a neoclassical social theorist now runs an AI-powered deportation platform is not something his Frankfurt professors would have predicted.

    “These 22 points aren’t philosophy floating in space, they’re the public ideology of a company whose revenue depends on the politics it’s advocating.”

    — Eliot Higgins, Bellingcat

    The NHS: A £330 Million Foothold in British Healthcare

    Palantir’s expansion in the UK has followed what critics and the non-profit Foxglove have described as a “land and expand” strategy, offering minimal-cost entry contracts before escalating. The company’s first NHS contract, in 2020, was priced at £1. In November 2023, a Palantir-led consortium was awarded a £330 million contract to build the NHS Federated Data Platform, a system intended to connect incompatible databases across up to 240 NHS organisations including hospital trusts and integrated care systems.

    The rollout has been troubled. Freedom of Information requests carried out by Corporate Watch and the No Palantir in the NHS campaign found that more than half of NHS trusts are not actively using the platform, with some describing Palantir’s system as a step backwards from what they already had. Leeds Teaching Hospitals NHS Trust told NHS England in a private letter that adopting several of the platform’s tools would cause it to “lose functionality rather than gain it.” The UK government subsequently spent £8 million with KPMG to persuade NHS trusts to adopt a product they had not requested.

    In February 2026, the British Medical Association announced it would advise doctors to limit their engagement with the platform. The Register reported in April 2026 that the UK government is weighing whether to trigger a break clause in the contract, available from spring 2027, after sustained pressure from MPs, unions, patient groups and more than 47,000 members of the public. Health minister Zubir Ahmed told parliament the contract could be reconsidered if other providers could do the job better. Separately, Medact’s briefing warned that the platform’s highly interoperable design could, in theory, enable Home Office and police departments to access confidential patient data. That concern was amplified by documents showing a Department of Health meeting note that framed existing patient data regulations as “obstacles” to be revisited.

    Palantir’s UK footprint extends beyond the NHS. In December 2025, the Ministry of Defence awarded the company a £240 million contract for data analytics supporting live military operations, again without competitive tender. A separate investigation found a previously undisclosed £15 million contract with AWE Nuclear Security Technologies, formerly the Atomic Weapons Establishment. Total UK state contracts reportedly exceed £670 million.

    Who Built This Thing

    To understand the manifesto, it helps to understand the company behind it. Palantir was incorporated in 2003 by five co-founders: Peter Thiel, Alex Karp, Joe Lonsdale, Stephen Cohen and Nathan Gettings. Thiel, who had made his first fortune co-founding PayPal, provided the initial funding and recruited Karp, a philosophy-trained law school classmate with no technology background, as CEO. The company’s first significant external backing came in 2004 when In-Q-Tel, the CIA’s venture capital arm, invested approximately $2 million and, more valuably, opened doors to government clients that no standard VC pitch could have unlocked. The premise, at the time, was a system that could help intelligence agencies share and analyse data without eroding civil liberties. How that turned out is the subject of most of this article.

    Karp’s reputation as what BBC Science Focus called “the scariest CEO in the world” has not faded. Earlier in 2026, he attracted notice after a video circulated of him struggling to remain seated during a public interview. His company’s stock currently trades at a price-to-earnings ratio of over 230, suggesting the market is pricing in a very rosy future for AI-driven surveillance and defence contracting. In August 2025, protesters staged a die-in outside Palantir’s New York offices, collapsing on the pavement carrying signs reading “Palantir: ICE and war enabler and profiteer.” Inside, the 22-point manifesto was presumably in development.

    “There is nothing in this manifesto that wouldn’t fit comfortably within a modern-day Mussolini regime. America, in Karp’s rendering, is great because it is home to Silicon Valley, because it has fostered peace-through-strength. The tweet probably could have just been an image of Alex Karp wearing a MAGA hat, grinning like a madman.”

    — Dave Karpf, Associate Professor, George Washington University School of Media & Public Affairs

    What the Manifesto Actually Says

    One academic described the original book as something that “should have been a tweet”, a 320-page exercise in corporate self-mythology that amounts to a sales pitch dressed in academic language. Palantir has since agreed, condensing it to 22 points on X. The tweet, in fairness, could probably have been even shorter: Palantir wants to be the weapons manufacturer of the next century, it wants sustained government spending on Palantir products, and it wants the political conditions that generate that spending to keep going. Everything else, the cultural hierarchies, the deterrence theory, the snipes at pluralism, is atmosphere.

    Geopolitical commentator Arnaud Bertrand put the core argument plainly: Palantir’s tools, he wrote, “aren’t meant to serve your foreign policy. They’re meant to enforce ours.” That is perhaps the most honest sentence anyone has written about the manifesto. A company founded with CIA money, operating targeting systems for military operations, running deportation infrastructure for ICE, holding NHS patient data, and processing sensitive financial intelligence for the UK’s Financial Conduct Authority has now published its worldview to 32 million people. It involves ranking human cultures, rearming Germany and Japan, and framing AI weapons as a patriotic obligation.

    In most films, the villain explains the plan about thirty seconds too late. Palantir has posted the plan on a Saturday afternoon, in public, to tens of millions of readers. What happens next is, as ever, a question of who moves and how fast.

    Fact-checked April 2026. Sources include: Al Jazeera, TechCrunch, Fortune, Middle East Eye, The Intercept, The Verge, Washington Post, Columbia Journalism Review, ACLU, Futurism, TechPolicy Press, Euronews, Britannica, BBC Science Focus, The Register, Democracy for Sale, Medact, American Immigration Council, Engadget, Corporate Watch, Democracy Now, Wikipedia (Project Maven; HBGary; AI-assisted targeting in the Gaza Strip; Palantir Technologies), Privacy International, Type Investigations.

  • Say Hello to GPT-5.5 

    Say Hello to GPT-5.5 

    OpenAI’s latest model dropped on April 23, 2026, seven weeks after its predecessor. Here’s what actually changed.

    There is a particular rhythm to AI announcements these days: a confident press release, some jaw-dropping benchmarks, and a name that sounds like a firmware update for a kitchen appliance. OpenAI delivered all three on Thursday, April 23, 2026, when it introduced GPT-5.5, a model the company describes as its “smartest and most intuitive to use” yet. The same phrase appeared in the GPT-5.4 announcement 49 days earlier. 

    Whether that repetition is exciting or induces another bout of announcement fatigue probably depends on whether you are building something with these tools or writing about them. 

    So What Is Actually New?

    The core pitch is what OpenAI calls agentic behaviour. Rather than stalling when instructions get vague, GPT-5.5 is designed to plan ahead, pick the right tools, check its own output, and keep going until a task is finished. Greg Brockman, OpenAI’s co-founder and president, framed it at a press briefing as a shift in how the model relates to ambiguity:

    “What is really special about this model is how much more it can do with less guidance. It can look at an unclear problem and figure out just what needs to happen next.”  — Greg Brockman, OpenAI co-founder and president, CNBC press briefing, April 23, 2026

    OpenAI is loudest about four areas: agentic coding, computer use, general knowledge work, and early scientific research. The research claim is the one that genuinely stands out. An internal version of GPT-5.5 running a custom harness produced a proof of a longstanding asymptotic result about off-diagonal Ramsey numbers, a class of problems in combinatorics that mathematicians have worked on for decades with limited progress. The proof was subsequently verified in Lean, one of the strictest formal verification tools in mathematics, confirming it is a genuine novel result and not simply a plausible-sounding argument.

    Mark Chen, OpenAI’s chief research officer, said at the same briefing that the model shows “meaningful gains” on scientific and technical research workflows, and pointed toward potential applications in areas such as drug discovery.

    The model ships in two versions. The standard GPT-5.5 is available to Plus subscribers and above. GPT-5.5 Pro, which uses parallel test-time compute for higher accuracy on demanding tasks, goes to Pro, Business, and Enterprise users. Both rolled out to ChatGPT and Codex on launch day, with API access confirmed the following morning.

    The Benchmarks: The Good, the Great, and the Awkward

    OpenAI published a full comparison table and did not hide the numbers where it trails.

    On Terminal-Bench 2.0, which tests multi-step command-line workflows requiring planning and tool coordination, GPT-5.5 scored 82.7% against GPT-5.4’s 75.1% and Claude Opus 4.7’s 69.4%. On OSWorld-Verified, which measures autonomous navigation of real desktop environments, it reached 78.7%, edging out Claude Opus 4.7’s 78.0% by under a percentage point. On GDPval, an agent benchmark spanning 44 occupations, it posted 84.9%; Inc. magazine reported OpenAI showed the model matching or exceeding human performance on roughly 85 percent of those tasks.

    The number OpenAI cannot dress up, and published anyway, is SWE-Bench Pro. This benchmark uses real GitHub repositories and actual submitted issues to test code repair end-to-end. GPT-5.5 scored 58.6%. Claude Opus 4.7 sits at 64.3% on the same test. For working software engineers, that is not a rounding error.

    There is a competitor the initial coverage largely missed. Moonshot AI released Kimi K2.6 on April 20, three days before GPT-5.5. It scores 58.6% on SWE-Bench Pro— identical to GPT-5.5 — at $0.60 per million input tokens versus GPT-5.5’s $5.00. It is open-weight, built on a trillion-parameter mixture-of-experts architecture, and purpose-built for long-horizon agentic coding sessions. The cost-performance pressure from well-resourced Asian AI labs is no longer a future concern.

    Faster Without Getting Slower

    OpenAI reports that GPT-5.5 matches GPT-5.4’s per-token latency in production while performing at a materially higher capability level, and uses significantly fewer tokens to complete the same Codex tasks. Brockman described it as “a faster, sharper thinker for fewer tokens.”

    At the same time, GPT-5.5’s raw API pricing is double that of its predecessor. $5.00 per million input tokens and $30.00 per million output tokens, up from $2.50 and $15.00 for GPT-5.4. The claim that it delivers frontier coding performance at roughly half the cost of comparable models refers to the effective cost per completed task inside Codex, where reduced token usage per job can offset the higher per-token rate. Whether that arithmetic works out for a given workflow depends on the workflow.

    The Bigger Picture OpenAI Is Quietly Building Toward

    Read GPT-5.5 purely as a model release and you miss what the company is actually signalling. Brockman told reporters the launch was another step toward a “super app”, a single unified platform folding together ChatGPT, Codex, and an AI browser into one service aimed at enterprise users. Altman has raised the same idea in previous briefings, and the cadence of releases is starting to look less like a product roadmap and more like infrastructure being assembled component by component.

    Chief scientist Jakub Pachocki told reporters: “We see pretty significant improvements in the short term, extremely significant improvements in the medium term.”

    GPT-5.5 fits that logic. It is built for sustained, multi-tool tasks running across hours, not rapid answers to tidy questions.

    How It Stacks Up Against the Competition

    Against its own lineage, GPT-5.5 represents the most structurally significant release in some time. DataCamp and Miraflow both report it is the first fully retrained base model since GPT-4.5. Every release from GPT-5.1 through GPT-5.4 was post-training work on the same underlying weights. This one is not.

    The version history also corrects a misdescription that appeared in early coverage. GPT-5.2 was released on December 11, 2025, followed by GPT-5.3 Codex on February 5, 2026, then GPT-5.4 on March 5, and finally GPT-5.5 on April 23. The gap between 5.4 and 5.5 is 49 days, roughly seven weeks. Some earlier reporting described it as barely a month.

    Against Anthropic, the comparison does not produce a clean winner. Claude Opus 4.7, released April 16, one week before GPT-5.5, leads on repository-level software engineering. GPT-5.5 leads on terminal-based agentic workflows by a substantial margin and scores marginally higher on autonomous computer use. Neither model dominates the full benchmark table; they are optimised for different kinds of work.

    The Verdict

    GPT-5.5 is a substantive release. Being the first fully retrained base model since GPT-4.5 matters architecturally. The Ramsey numbers proof, verified in Lean, is a genuine scientific contribution rather than a marketing claim. The per-task token efficiency gains are real, even if the per-token price doubled. The agentic improvements are backed by published benchmark numbers, not just company language.

    The limits are also real. Claude Opus 4.7 leads on SWE-Bench Pro, the benchmark most directly relevant to practising software engineers. Kimi K2.6 matches GPT-5.5 on that same benchmark at roughly a tenth of the API cost. The field is more competitive than any single company’s announcement makes it appear.

    For paid ChatGPT subscribers, this is the most capable version of the tool they already use. Whether it holds that position for long is, given the current pace of releases across every major lab, a genuinely open question.

    Featured image: ilgmyzin (UnSplash)

    Primary sources: OpenAI release post and system card · CNBC · TechCrunch · SiliconAngle · DataCamp · Wikipedia (GPT-5.2, GPT-5.4, GPT-5.5) · Lushbinary · MarkTechPost · Moonshot AI / Kimi K2.6 official release · Inc. · Storyboard18 · Big Technology Podcast · Heise Online · Kingy AI

  • MEET MYTHOS

    The AI That Could Hack the Planet (And Find Out Why Its Creator Is Nervous About It).

    Anthropic built an AI model so capable that it decided the general public could not have it.

    Since April 7, when Anthropic announced Mythos, a model with a demonstrated talent for cracking open software that would make the most seasoned penetration tester look twice, the company has been in the uncomfortable position of defending a tool it is simultaneously afraid of. It built it, tested it, watched what it did, and pulled it back. For a company that markets itself as the safety-first AI lab, that is not a comfortable place to be.

    What exactly is Mythos? Why has it rattled finance chiefs, woken up government regulators, and triggered quiet panic among open-source maintainers who guard critical software with skeleton crews? And why does a separate source map leak involving Anthropic’s own tools make the picture even messier? This piece walks through all of it, with the numbers to back it up.

    What Is Mythos?

    Anthropic announced Mythos on April 7, 2026. Rather than a public release, the company gave access to a controlled group under an initiative called Project Glasswing. The 12 founding partners are Anthropic itself, Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. Beyond that core group, over 40 additional organisations that build or maintain critical software infrastructure also received access. Anthropic committed $100 million in model usage credits and $4 million in direct grants to open-source security organisations to support the initiative.

    Alongside the launch, Anthropic published a detailed technical report from its Frontier Red Team. The report is unusually candid. It documents exactly what the model can do, how the team measured it, and why they believe it crosses a line that previous AI models did not. The model operates like a senior software engineer with a specialisation in offensive security. It reads codebases, identifies subtle flaws, reasons about how separate bugs can be combined, and then writes working exploit code. Not theoretical sketches. Functional exploits.

    Mythos’s found thousands of high- and critical-severity zero-day vulnerabilities across every major operating system and every major web browser. The Council on Foreign Relations, citing Anthropic’s own data, noted that one flaw was found in code that had been tested five million times by automated tools without detection. Over 99% of the vulnerabilities discovered remained unpatched at the time of the April 7 announcement.

    The Benchmark Gap: What the Numbers Actually Show

    The Firefox benchmark is where the gap between Mythos and its predecessors becomes hardest to dismiss. Anthropic’s red team ran it twice, using identical conditions.

    When tested against known JavaScript engine vulnerabilities in Firefox 147, Claude Opus 4.6, the previous flagship model, produced working shell exploits on two occasions out of several hundred attempts. Mythos Preview ran the same test and produced 181 working exploits, with register control achieved in 29 additional cases. That is a roughly 90x improvement in a single generation, as VentureBeat noted. Opus 4.6 had a near-zero percent success rate at autonomous exploit development overall.

    The OSS-Fuzz benchmark tells a similar story. Anthropic regularly tests its models against roughly 1,000 open-source repositories from the OSS-Fuzz corpus, scoring their worst result on a five-tier severity scale ranging from basic crashes (tier 1) to full control-flow hijack (tier 5). Across roughly 7,000 entry points, Sonnet 4.6 and Opus 4.6 each reached tier 1 in 150 to 175 cases, tier 2 about 100 times, and achieved just one crash each at tier 3, with nothing above that. Mythos Preview produced 595 crashes at tiers 1 and 2, a handful at tiers 3 and 4, and hit tier 5, full control-flow hijack, on 10 separate, fully patched targets.

    Anthropic also ran Mythos against a list of 100 Linux kernel CVEs from 2024 and 2025. The model filtered these to 40 it judged exploitable, then produced working privilege-escalation exploits for more than half of them. Many involved chaining two to four separate low-severity vulnerabilities together, defeating kernel address-space layout randomisation (KASLR) via race conditions and use-after-free bugs, then injecting SSH keys for root access. All without human guidance after the initial prompt.

    The cost figures are what change the threat calculus most. A thousand-run OpenBSD campaign that found a 27-year-old denial-of-service vulnerability cost under $20,000 in total, working out to roughly $50 per successful find. The Linux kernel privilege-escalation chains that bypassed KASLR and CONFIG_HARDENED_USERCOPY cost under $2,000 each. The FreeBSD remote code execution exploit described below came in under $1,000. As one analyst observed, Mythos is not doing technically novel offensive work, it is doing well-understood offensive work at a fraction of the cost and time that previously required elite human specialists.

    “What Anthropic just demonstrated is that a language model can now compress vulnerability discovery, exploit development, multi-vulnerability chaining, and defense bypass into hours, at a cost measured in hundreds or low thousands of dollars.”

    — PostQuantum Security Analysis, April 8, 2026

    Specific Vulnerabilities: The Ones Anthropic Can Talk About

    Because over 99% of what Mythos found remains unpatched and under coordinated disclosure, Anthropic can only publicly discuss a small fraction of its findings. The disclosed cases are still illustrative.

    The most high-profile is CVE-2026-4747, a 17-year-old remote code execution vulnerability in FreeBSD’s NFS server. The flaw is a stack buffer overflow in the RPCSEC_GSS authentication handler. An attacker-controlled packet is copied into a 128-byte stack buffer, but the XDR layer permits credentials up to 400 bytes, leaving 304 bytes of overflow. FreeBSD lacks the stack protection and kernel address randomisation that would complicate exploitation on a modern Linux host, making the path to full unauthenticated root access relatively direct. Mythos built a 20-gadget Return Oriented Programming chain split across multiple network packets to exploit it, fully autonomously after a single prompt.

    A second disclosed finding is a 16-year-old vulnerability in FFmpeg’s H.264 codec. The flaw survived every fuzzer and human code review that examined it in the intervening years. Mythos found it by reasoning about code semantics rather than through pattern-matching or fuzzing. The campaign cost approximately $10,000.

    The 27-year-old OpenBSD denial-of-service bug is the third. An integer overflow in the TCP SACK implementation allows a remote attacker to crash any OpenBSD host responding over TCP. Mythos surfaced it across roughly 1,000 scaffold runs. VentureBeat notes this was a finding in code tested five million times by automated tools without detection.

    Not every claim has gone unchallenged. A detailed technical critique from FlyingPenguin argues that CVE-2026-4747 was already a publicly filed advisory before Mythos found it, that FreeBSD’s lack of modern mitigations made the exploit straightforward, and that Anthropic’s claim of “fully autonomous discovery” glosses over context that was already in the advisory. The AISLE research group tested eight open-weight models against the same CVE and found all eight detected it, including one with 3.6 billion parameters costing $0.11 per million tokens. AISLE’s conclusion was not that Mythos is overhyped across the board, but that the examples Anthropic chose to publicise may not represent the full gap between Mythos and existing tools.

    “Only a handful of Anthropic models out of thirteen tested get the harder vulnerability classes right. The FreeBSD detection is commoditised: every model gets it, including a 3.6-billion-parameter model at $0.11 per million tokens.”

    — AISLE Research Group, AI Cybersecurity After Mythos, April 2026

    The Source Map Problem: Anthropic’s Own Wound

    Roughly a week before Mythos was announced, a quieter story was circulating in security circles. On March 31, 2026, reports emerged that Anthropic’s npm-distributed CLI tool, Claude Code, had shipped with source map metadata accessible enough for outsiders to reconstruct substantial portions of the original TypeScript source. Multiple GitHub mirrors appeared claiming to be derived from the cli.js.map file for version 2.1.88 of the @anthropic-ai/claude-code package. Anthropic’s changelog confirms 2.1.88 as a real public release dated March 30, 2026.

    To understand why this matters you need to understand what source maps are. When developers build modern JavaScript applications for production, the code is run through a minifier that compresses it into a dense, unreadable bundle. This makes files smaller and faster to load, but it also makes the underlying logic far harder to reverse-engineer. Source maps are the debug companion to that process, a structured JSON file that maps the minified output back to the original readable source, line by line. In development environments they are essential. Accidentally left accessible in production, they hand a researcher or attacker a readable blueprint of the application.

    This is not an exotic problem. Security firm Escape, after scanning their client base, found exposed source maps in 70% of organisations shipping production web apps. Apple walked into the same mistake in November 2025 when it shipped a redesigned App Store website with source maps enabled in production. Within hours, a developer had used a Chrome extension to pull the complete Svelte and TypeScript codebase off the live site. The GitHub repository was forked more than 8,000 times before Apple got it taken down.

    The attack chain can extend well beyond reading source code. Ethical hacker Matthew Keeley, in a case documented by Sentry’s security blog, found that a publicly accessible .map file in a production build contained hardcoded Stripe API secret keys in the reconstructed source, enabling unauthorised payments. Ostorlab security researchers note that exposed source maps can also reveal full dependency trees, creating a surface for dependency confusion attacks against internal packages.

    For Claude Code specifically, the concern goes beyond competitive intelligence about Anthropic’s implementation. CVE-2026-21852 describes a separate but related vulnerability. A malicious repository can set the ANTHROPIC_BASE_URL environment variable to intercept API calls before the trust prompt appears, potentially leaking API keys. A related CVE, CVE-2025-59828, existed because Yarn-related code could execute before directory trust was established. Making implementation details easier to reconstruct through source map exposure lowers the cost of finding and probing these kinds of pre-trust initialization bugs.

    The source map incident and the Mythos announcement are two separate stories that Anthropic would probably prefer to tell on different news cycles. One is about its most powerful AI model exposing vulnerabilities in other companies’ software. The other is about Anthropic’s own CLI shipping with a configuration that made its source reconstructable. Both happened within the same week. The company finds itself on both sides of the same argument simultaneously.

    Why the Patching Gap Is the Real Crisis

    The core anxiety around Mythos is not the model itself sitting under controlled access. It is the collision between how fast AI can now find vulnerabilities and how slowly the industry patches them. Those two curves are moving in opposite directions at an accelerating rate.

    On the discovery side, as of the first half of 2025, over 23,667 CVEs were filed globally in just six months, a 16% increase over the same period in 2024. The full-year 2025 count was projected to approach or exceed 50,000 disclosed vulnerabilities, roughly 130 new CVEs every single day requiring triage, patching, or other mitigation. That volume was unprecedented before Mythos existed.

    On the patching side, the Adaptiva State of Patch Management 2025 report, surveying over 250 security and IT professionals, found that 77% of organisations need more than a week to deploy patches enterprise-wide, and 14% require more than four weeks. Separately, 71% of IT and cybersecurity professionals said patching is too complex and time-consuming. Even high-severity vulnerabilities take an average of 82 days to fix globally, according to Statista’s 2023 cross-industry benchmark, and low-severity ones take close to 10 months.

    The exploitation window is compressing from the other direction too. Barracuda’s 2025 analysis found that attackers’ average time from vulnerability discovery to active exploitation had dropped from 63 days to 32 days. Unpatched vulnerabilities are the source of over 60% of data breaches.

    This is the structural problem Mythos makes acute. Shane Fry, CTO of RunSafe Security, told Fortune, “Vulnerability discovery is outpacing patching. As vulnerability discovery and exploit development move faster, the idea that you can remediate everything in time just doesn’t hold.”

    “Organizations are already struggling to keep up with patching across both IT and OT environments, and AI is only accelerating that gap.”

    — Shane Fry, CTO, RunSafe Security (via Fortune)

    Daniel Stenberg, chief maintainer of cURL, the open-source data transfer library present on virtually every networked device on earth, received 181 bug and vulnerability notifications in 2025 alone. That was roughly double the count from the previous two years combined. His team is six volunteers.

    Six volunteers. A model that generates 181 working exploits overnight. Stenberg put it plainly in Bloomberg: he does not see how that equation resolves in the maintainer’s favour.

    “Maybe we have critical systems that we can’t operate in a post-Mythos world, when we have so many zero-days hitting us all the time.”

    — Joshua Wright, SANS Institute Fellow and Technical Adviser (via GovTech)

    Tal Kollender, a former hacker and founder of cybersecurity platform Remedio, put the detection problem plainly in Fortune, a tool that finds thousands of vulnerabilities per minute is “an incredibly expensive alarm.” Finding risk faster than you can act on it does not make organisations more secure. Over 99% of the vulnerabilities Mythos found remain unpatched, Anthropic confirmed.

    The financial sector has taken notice. JPMorgan Chase CEO Jamie Dimon, after being briefed on Mythos, told CNBC that while AI will eventually help defenders, it is first making companies more vulnerable, and that “a lot more vulnerabilities need to be fixed.” He warned the risk extends to exchanges and other financial infrastructure beyond the banks themselves.

    “A lot more vulnerabilities need to be fixed.”

    — Jamie Dimon, CEO of JPMorgan Chase (via CNBC)

    The broader AI-enabled threat picture is already deteriorating. CrowdStrike’s data shows 78% of companies were hit by ransomware in the past year, and QBE Insurance Group projects ransomware attacks are on track to increase 40% by end of 2026 compared to 2024, from one attack every 11 seconds to one every 2 seconds by 2031. A recent PwC report noted that the time between a new AI capability’s release and its weaponisation by threat actors shrank dramatically in 2025 and is expected to continue narrowing in 2026.

    Why Anthropic Is Nervous About Its Own Creation

    Anthropic was not trying to build a hacking tool. The company was building a more capable general AI, and the offensive security capabilities arrived as a side effect of that work. The same improvements in code comprehension, reasoning, and autonomous action that make Mythos useful for patching software also make it useful for attacking it. Anthropic states this directly in the technical report, the cybersecurity capabilities were not explicitly trained. They emerged as a downstream consequence of general improvements.

    The government response has been fast. The Hill reports that Anthropic briefed senior officials across multiple U.S. agencies before any external release, including CISA and the Center for AI Standards and Innovation. On the day Project Glasswing launched, Treasury Secretary Bessent and Federal Reserve Chair Powell convened a separate meeting with Wall Street executives, including the CEOs of Bank of America and Goldman Sachs, to discuss the implications for financial infrastructure. A person familiar with the White House’s response told The Hill that some officials had previously assumed AI development had plateaued; Mythos prompted a reassessment.

    “This time, the threat is not hypothetical. Advanced language models are here.”

    — Anthropic researchers, Mythos technical assessment (via The Hill)

    David Lindner, CISO at Contrast Security, offered a twenty-five year practitioner’s perspective in Fortune. His argument is that finding vulnerabilities has never been the binding constraint: “We’ve never had a problem finding vulnerabilities. We find them every day. We actually have a pile of them that we just don’t fix.” He also raised a supply-chain concern that Anthropic’s controlled release strategy may not contain the capability for long: “Even if they, quote unquote, don’t release it, China will have a version in five or six months, and there’ll be an open-source version within a year or two.”

    There are also limits to what Mythos can do. Evan Peña of Armadin told CNN that current AI models lack the contextual judgment a human attacker has about which data inside a target organisation is actually worth stealing. The Cloud Security Alliance’s Rich Mogull noted Mythos failed at remote kernel exploitation while succeeding locally. The AISLE group’s comparative tests suggest the specific vulnerabilities Anthropic publicised may not represent the widest gap between Mythos and already-available models.

    The Controlled Release That Wasn’t Entirely Controlled

    On April 21 — two weeks after Project Glasswing launched — Bloomberg reported that a small group of unauthorised users had been accessing Mythos Preview regularly since the day of the public announcement. According to Bloomberg, the group communicates through a private Discord channel dedicated to tracking unreleased AI models. Their method of entry was disarmingly low-tech: they made an educated guess about the model’s URL based on familiarity with the formatting conventions Anthropic uses for other model endpoints. No sophisticated intrusion was required. Access was also facilitated, at least in part, through shared accounts and API keys belonging to an individual employed at a third-party contractor working with Anthropic. Bloomberg said the group provided screenshots and a live demonstration as proof.

    Anthropic confirmed it is investigating. “We’re investigating a report claiming unauthorized access to Claude Mythos Preview through one of our third-party vendor environments,” the company told TechCrunch. It added that there is currently no evidence that the access impacted Anthropic’s core systems or extended beyond the contractor environment. The source described the group’s motivation to Bloomberg as curiosity-driven — “interested in playing around with new models, not wreaking havoc” — though security experts note that intent is largely irrelevant when the tool in question can produce working exploits for critical infrastructure overnight.

    The episode carries weight beyond the immediate security question. Anthropic is currently suing the Department of Defense over its designation of the company as a supply-chain risk — a designation centred on whether Anthropic can reliably govern access to its own tools. An unauthorised access incident, even one apparently contained within a third-party vendor environment, gives ammunition to those in the administration who have argued otherwise. The Next Web noted that the mechanism of access — guessing a model’s URL from knowledge of Anthropic’s conventions — points to a specific failure mode: restricting a frontier AI capability through vendor relationships rather than technical controls creates a surface area that is harder to monitor and easier to circumvent than a closed API with strict authentication. Glasswing was designed as a controlled release. The question now being asked, quietly, in government and security circles alike, is how controlled it actually was.

    Is There a Way Through This?

    Anthropic’s long-term argument is that tools like Mythos will ultimately help defenders more than attackers, once the security landscape reaches a new equilibrium. Their technical report draws a parallel to software fuzzers: when AFL and similar tools arrived, fears that they would accelerate attacker discovery of vulnerabilities proved correct in the short term. Today, fuzzers like OSS-Fuzz are a core part of defensive security practice. Anthropic believes the same will happen here.

    Their immediate defensive recommendations are concrete: organisations that have not integrated AI into vulnerability management should start now, using currently available frontier models that already find high- and critical-severity bugs across OSS-Fuzz targets, web applications, cryptography libraries, and the Linux kernel. Patch cycles should be compressed. CVE-tagged dependency updates should be treated as urgent rather than routine. Incident response pipelines should be automated where possible.

    The Council on Foreign Relations called Mythos “an inflection point for AI and global security,” noting it is the first AI model ever withheld specifically because of its destructive security potential, and that the ability to autonomously discover zero-day vulnerabilities had previously belonged exclusively to highly specialised human experts. Anthropic has committed to a public findings report from Project Glasswing within 90 days of the April 7 announcement.

    For now, the most capable offensive security AI ever documented sits under controlled access, while a curated group of the world’s largest technology companies quietly runs it against their own foundations. An unauthorised group is apparently running it too. The source code leak sits in the background as a reminder that even the company building these tools is not immune to the everyday packaging mistakes that have always plagued software releases. Whether Mythos ultimately helps defenders more than attackers is a question that will take years to answer. The period before that answer arrives is where all the exposure lives.

    Sources

    •  Anthropic Red Team — Assessing Claude Mythos Preview’s cybersecurity capabilities

    •  Scientific American — What is Mythos and why are experts worried?

    •  The Hill — Anthropic’s Mythos model sparks cybersecurity concerns

    •  VentureBeat — Mythos Detection Ceiling: Security Teams Need a New Playbook

    •  SecureWorld — Anthropic’s Claude Mythos Autonomously Discovers, Exploits Zero-Days

    •  Help Net Security — Anthropic’s new AI model finds and exploits zero-days across every major OS and browser

    •  Tom’s Hardware — Anthropic’s latest AI model identifies thousands of zero-day vulnerabilities

    •  PostQuantum Security — Anthropic’s Mythos Preview and the End of a Twenty-Year Cybersecurity Equilibrium

    •  AISLE — AI Cybersecurity After Mythos: The Jagged Frontier

    •  FlyingPenguin — FreeBSD CVE-2026-4747 Log Suggests Mythos is a Marketing Trick

    •  Fortune — Mythos finds flaws faster than companies can patch them

    •  Fortune — Industry veteran: the real problem is fixing, not finding

    •  CNBC — Jamie Dimon on Anthropic’s Mythos

    •  CNN Business — Anthropic’s next model: experts weigh in

    •  Bloomberg — Anthropic’s Mythos Adds Strain on Cybersecurity Teams

    •  CBS News — Anthropic’s Mythos AI can spot weaknesses in almost every computer on Earth

    •  Council on Foreign Relations — Six Reasons Claude Mythos Is an Inflection Point

    •  GovTech / SANS Institute — New Report Details How Mythos AI Makes Cybersecurity Harder

    •  Penligent — Claude Code Source Map Leak: What Was Exposed and What It Means

    •  Escape Security — Apple’s App Store Source Map Leak: Found in 70% of Organisations

    •  Sentry Security Blog — Abusing Exposed Sourcemaps

    •  Expert Insights — Patch Management Statistics and Trends 2025 (Adaptiva Report)

    •  DeepStrike — Vulnerability Statistics 2025: Record CVEs and Exploitation

    •  Barracuda — Cybersecurity Awareness Month: Time for a reminder about your vulnerability backlog

    •  Cobalt — Top Cybersecurity Statistics for 2026 (CrowdStrike / QBE data)

    •  Bloomberg — Unauthorized Users Access Anthropic’s Restricted Mythos Model (April 21, 2026)

    •  TechCrunch — Unauthorized group has gained access to Anthropic’s exclusive cyber tool Mythos, report claims (April 21, 2026)

    •  The Next Web — Unauthorized users gained access to Anthropic’s restricted Mythos AI model (April 21, 2026)

    •  Euronews — Hackers breach Anthropic’s ‘too dangerous to release’ Mythos AI model, report (April 22, 2026)

  • Google Picks 15 African AI Startups for Class 10

    Google Picks 15 African AI Startups for Class 10

    Featured Image: Adarsh Chauhan (Unsplash)

    When Google launched its African accelerator in 2018, the phrase African tech startup still drew sceptical looks in a lot of investor meetings. Eight years later, nearly 2,600 companies applied for a seat in Class 10 of the Google for Startups Accelerator Africa. Google selected 15.

    Class 10: A Wider Map

    The tenth cohort spans eight countries: Angola, Ivory Coast, Kenya, Nigeria, Senegal, South Africa, Tanzania and Uganda. Angola, Ivory Coast, and Tanzania are participating for the first time, a shift from what had previously been a programme concentrated around Nairobi and Lagos.

    The three-month hybrid programme runs from April 13 to June 19, 2026. Founders receive mentorship from Google engineers and sector experts, hands-on access to AI and cloud infrastructure workshops, and introductions to a global investor network. 

    Since its 2018 launch, the programme has backed 106 startups across 17 African countries. Alumni have collectively raised more than $263 million and created over 2,800 jobs.

    “For Class 10, we are focusing on the potential of AI to drive health and societal benefits, providing the infrastructure and expertise to turn these startups into the research labs of the continent.”
    — Folarin Aiyegbusi, Head of Startup Ecosystem, Sub-Saharan Africa, Google

    AI at the Core

    Google describes Class 10 as its AI-first cohort. Each of the 15 selected startups is built on artificial intelligence as a core component of the product, not as an add-on. Google is giving founders access to Cloud TPUs to remove hardware cost barriers that have long put smaller startups at a disadvantage.

    Meet the 15

    Anda Africa (Angola) Angola’s moto-taxi sector is large, informal, and largely invisible to banks. Anda Africa converts ride data into creditworthiness signals, building financial records for workers who have never had access to formal credit.

    Bani (Nigeria) Cross-border payments across Africa are slow and expensive. Bani is rebuilding the underlying infrastructure so African businesses trading internationally get settlements at speeds closer to domestic transfers.

    Coamana (Kenya) Informal food markets feed most of urban Africa but have almost no digital footprint. Coamana digitises them for governments and market associations, giving visibility to a sector that has been largely ignored by policymakers and investors.

    Duck (Kenya) Consumer brands lose revenue to stockouts they do not catch in time. Duck provides real-time shop-floor data so brands can identify gaps on the shelf before customers leave without buying.

    Emaisha Pay (Uganda) Agro-traders move large volumes of produce across Uganda and the wider region, mostly without formal financial infrastructure. Emaisha Pay brings inventory management, multi-currency payments, and embedded trade financing into one platform for traders who have been shut out of formal financial services.

    Loop (South Africa) Transport and payment networks across Africa are fragmented. Loop connects people, businesses, and communities across these different ecosystems, combining mobility and payments in one platform.

    Maad (Senegal) Selling consumer goods in West Africa means working across everything from roadside kiosks to modern retail chains. Maad’s omnichannel platform uses AI-driven market intelligence to help brands grow sales across both.

    MasteryHive AI (Nigeria) Banks and fintechs spend significant resources on manual transaction reconciliation and compliance monitoring. MasteryHive replaces those processes with a platform that handles fraud detection and anti-money laundering automatically.

    Meditect (Ivory Coast) Medicine stockouts in African pharmacies are a serious and recurring problem. Meditect digitises pharmacy operations with cloud software and real-time inventory data so patients can reliably access the treatments they need.

    Regxta (Nigeria) Millions of micro-businesses in Nigeria’s informal sector have no credit history but need financial products. Regxta uses alternative data for credit scoring and a hybrid digital-agent distribution model to reach them where traditional banks are absent.

    ReportsAI (Kenya) NGOs and development agencies collect large amounts of raw data and then spend weeks producing funder-ready reports. ReportsAI automates that process so organisations can spend more time on their actual work.

    Safiri (Tanzania) Moving people and goods reliably across Tanzania is harder than it needs to be. Safiri is building digital logistics and mobility infrastructure to make transport bookable and trackable across East Africa.

    Termii (Nigeria) Termii processes over two billion interactions annually and reaches more than 16 million end-users across banks, fintechs, and digital platforms. It ranked first in Media and Telecommunications, and tenth overall, on the Financial Times’ Africa’s Fastest-Growing Companies list for 2025.

    Vambo AI (South Africa) Africa’s linguistic diversity has been a gap in most AI systems. Vambo AI builds multilingual infrastructure for translation, speech recognition, and generative AI across African languages. In mid-2025 it signed a memorandum of understanding with Cassava Technologies to co-develop large language models grounded in African languages and contexts.

    VunaPay (Kenya) Agricultural cooperatives handle significant financial flows for smallholder farmers but often lack the infrastructure to support them. VunaPay builds fintech and data tools that enable instant payments and financial services for farmers connecting to formal financial systems.

    When the Programme Works: The Paystack Example

    Numbers capture part of what this programme has produced. A more concrete illustration is Paystack, a Lagos-based payment processing company that went through an earlier Google for Startups cohort and was later acquired by Stripe in 2020 in a deal reported at over $200 million. It was one of the largest tech acquisitions in African history at that point.

    Paystack did not come out of the programme already built. What it gained was access to technical mentorship, infrastructure it could not have afforded independently, and a network that opened doors with enterprise clients and early investors. By the time the company reached scale, it had resolved the problems that tend to stall African fintech companies: compliance, reliability, and user trust.

    Founders entered the programme working on a better payment experience for Nigerian merchants. They left with the tools and relationships to build infrastructure used by businesses across the continent. Today, millions of African merchants process payments through Paystack.

    If several companies from Class 10 follow a comparable trajectory, the result could include stronger payment infrastructure, better supply chain visibility, expanded access to credit, and pharmacies that maintain stock of essential medicines. That is the realistic upside of backing the right companies at the right stage.

    Context

    Nigeria leads Class 10 with four startups, reflecting its position as one of the continent’s most active tech ecosystems. The more notable detail is the geographic spread. First-time participants Angola, Ivory Coast, and Tanzania join the more established hubs, which points to competitive tech being built in more places across the continent.

    The equity-free structure means Google takes no ownership stake. For many of these companies, the selection carries weight with local investors, enterprise clients, and government partners independent of any direct financial benefit.