🍲 meatybroth.com

AI slop or human broth? Who cares as long as it’s meaty

Threads with the most distinct recent repliers first; with a query, only matching threads.
Hacker News 100 · hn100@social-lansky-name.mostr.pub 0 repliers (24h) event
account
npub1njvyhy9tqqlfytu5zef0rq2u736qe6fuy47j69fxdlhdze2jud5qwqqejt
posted
2026-09-11 20:45 UTC
event
nostr:22d02b3ca2a5b70479191ff78521825325edad4c89d7962fe5aab244e047b637
thread
0 distinct reply authors (24h) · 0 replies · last activity 1d ago
u32Luke 0 repliers (24h) event
account
npub1pzluqzmlwtsptazuxfh5s6lvzmjd2gmtwrjy2sl3ch5x4r3pca4qu3lnh6
posted
2026-09-11 20:39 UTC
event
nostr:c32651be53c85c6c28497fc8f018660056fe2363a14f98e9b35c1907638481cf
thread
0 distinct reply authors (24h) · 1 replies · last activity 1d ago · root post not stored — thread context incomplete

Did you die though?

lucianorocha 0 repliers (24h) event
account
npub1qdltuyua2x4p2kdk7x7h8g8kk070nunfdmndjwa0cq8ftya0q8wqsahu87
posted
2026-09-11 20:39 UTC
event
nostr:14d2dae09ee0c4f03ab239847fa99ca16dd0c5845d61af45005c4bacd19afde1
thread
0 distinct reply authors (24h) · 0 replies · last activity 1d ago
⋯ full post (268 more characters) ⋯ show less

Hoje faz 25 anos que a Al-Qaeda executou os ataques de 11 de setembro nos EUA. E você já se questionou por que eles escolheram esta data especificamente?

Há uma explicação técnica, oficial, bem documentada e muito chata. Mas tem outras duas explicações que são bem mais legais. E uma delas inspirou uma das minhas músicas favoritas.

Decidi reativar um antigo blog para falar mais sobre as duas batalhas decisivas na guerra de 1.000 anos entre o islã e o Ocidente. https://lucian89.medium.com/por-que-bin-laden-escolheu-11-de-setembro-5cfdd0005ac4

Hoje faz 25 anos que a Al-Qaeda executou os ataques de 11 de setembro nos EUA. E você já se questionou por que eles escolheram esta data especificamente?

Há uma explicação técnica, oficial, bem documentada e muito chata. Mas tem outras duas explicações que são bem mais legais. E

utxo the webmaster 🧑‍💻 · @utxo.one 0 repliers (24h) event
account
npub1utx00neqgqln72j22kej3ux7803c2k986henvvha4thuwfkper4s7r50e8
posted
2026-09-11 20:38 UTC
event
nostr:0000dc1bf027b4bfc32f8adfae9e44b8c42e48041488ad852aa30f69ca37e350
thread
0 distinct reply authors (24h) · 0 replies · last activity 1d ago

Even HDDs 3x in price? Why???

🇵🇸 whoever loves Digit 0 repliers (24h) event
account
npub1wamvxt2tr50ghu4fdw47ksadnt0p277nv0vfhplmv0n0z3243zyq26u3l2
posted
2026-09-11 20:10 UTC
event
nostr:3f30b02f639eb8a86d15036fbc2940b8b2400f50f130d6e19d65f6e78017b0f0
thread
0 distinct reply authors (24h) · 1 replies · last activity 1d ago · root post not stored — thread context incomplete

Shoplift real ones?

corndalorian · corndalorian@primal.net 0 repliers (24h) event
account
npub1lrnvvs6z78s9yjqxxr38uyqkmn34lsaxznnqgd877j4z2qej3j5s09qnw5
posted
2026-09-11 20:09 UTC
event
nostr:b1d27ed19ae3a8b1e9c40462fc87155b5dd16a7da8193c3fad322eaf29244037
thread
0 distinct reply authors (24h) · 1 replies · last activity 1d ago

No one has ever seen us in the same place together 👀

🇵🇸 whoever loves Digit 0 repliers (24h) event
account
npub1wamvxt2tr50ghu4fdw47ksadnt0p277nv0vfhplmv0n0z3243zyq26u3l2
posted
2026-09-11 20:08 UTC
event
nostr:0c0e224fcf3b027960ccda2c2ada6f35c8cc8aca1b8e8a279032407ce9b4bd04
thread
0 distinct reply authors (24h) · 1 replies · last activity 1d ago · root post not stored — thread context incomplete

Other clients are better off embarrassing Primal by letting users see what it does

Derek Ross · derekross@grownostr.org 0 repliers (24h) event
account
npub18ams6ewn5aj2n3wt2qawzglx9mr4nzksxhvrdc4gzrecw7n5tvjqctp424
posted
2026-09-11 20:05 UTC
event
nostr:21970fd36b65758dd5ea0f7d78100a3ac57143bf31bfbc4f8047af6429d9f5bd
thread
0 distinct reply authors (24h) · 0 replies · last activity 1d ago
⋯ full post (82 more characters) ⋯ show less

Agora campaigns can now live anywhere on the web. Just paste a live fundraising widget into any site you control and you're good to go! Three variants, on-chain donations (including Silent Payments), no accounts, no middleman, no off-switch. Fundraising without a landlord. The way it should be. https://soapbox.pub/blog/agora-embed-widgets-fundraising-anywhere

Agora campaigns can now live anywhere on the web. Just paste a live fundraising widget into any site you control and you're good to go! Three variants, on-chain donations (including Silent Payments), no accounts, no middleman, no off-switch. Fundraising without a landlord. The wa

corndalorian · corndalorian@primal.net 0 repliers (24h) event
account
npub1lrnvvs6z78s9yjqxxr38uyqkmn34lsaxznnqgd877j4z2qej3j5s09qnw5
posted
2026-09-11 20:04 UTC
event
nostr:499b69db5419e0ab2be90380a1899e311de8242ede182df8804f8a50e1e8282b
thread
0 distinct reply authors (24h) · 0 replies · last activity 1d ago
semisol · semisol@nostr.land 0 repliers (24h) event
account
npub12262qa4uhw7u8gdwlgmntqtv7aye8vdcmvszkqwgs0zchel6mz7s6cgrkj
posted
2026-09-11 19:49 UTC
event
nostr:4c5f3bc3d3808992b9034adfbcba30af62ca906d0bcd6a7f54485d22b61c54b0
thread
0 distinct reply authors (24h) · 1 replies · last activity 1d ago · root post not stored — thread context incomplete

All LN software hates their users

. 0 repliers (24h) event
account
npub1ak68qfcjj7k95c0jwleu69x72nr8adwv6g80pkwl9xlps6zmkqzqrxy8fx
posted
2026-09-11 19:46 UTC
event
nostr:000003734abb62d1a630571d5c6dd1d9c63acf578b8394080a7793d2d4b3107a
thread
0 distinct reply authors (24h) · 0 replies · last activity 1d ago

Sometimes all you need is a fresh session 🪄

Dr. The Daniel 🖖 · daniel@sidecar.top 0 repliers (24h) event
account
npub1aeh2zw4elewy5682lxc6xnlqzjnxksq303gwu2npfaxd49vmde6qcq4nwx
posted
2026-09-11 19:45 UTC
event
nostr:0000ff7e4d1c04096c26407fe5ac6d290a250cdf80c19167082d3a993110050a
thread
0 distinct reply authors (24h) · 1 replies · last activity 1d ago
↳ walker: BREAKING: Elliot Page to play Anthropic AI doomer Jacob Coxon in upcoming film titled “GIVE US A REGULATORY MOAT OR WE’RE ALL GOING TO DIE” https://blossom.pri…

Whoa, dead ringer!

Can we get Fred Armisen to play Dario Amodei? https://blossom.primal.net/aab23172715321a9e73f6107793b4b205639ec857d200dabc9ca3113c121cdb3.jpg

myrmepropagandist · futurebird@sauropods-win.mostr.pub 0 repliers (24h) event
account
npub1cp2pgntkzkpqa23rytnchggwzywyggvst9yzkgd6w8j349ef7s9shuhrnq
posted
2026-09-11 19:40 UTC
event
nostr:a4a65fe131dd900f9cd5990467df3c719fef2dc372d0c754953b8cb2843bfbcf
thread
0 distinct reply authors (24h) · 0 replies · last activity 1d ago
⋯ full post (205 more characters) ⋯ show less

I don't want to bore anyone with the details but I'm starting to notice how misinformation can propagate through LLM generated pages... and it's bad.

When you hear "misinformation" you think probably think about slanderous political lies, or propaganda, and that's out there too. I'm talking about something much more boring and hard to clean up.

Of course this isn't a new problem with information. It's been a problem in scholarship, and on the internet for decades.

"Factoids"

I don't want to bore anyone with the details but I'm starting to notice how misinformation can propagate through LLM generated pages... and it's bad.

When you hear "misinformation" you think probably think about slanderous political lies, or propaganda, and that's out there too

Gunson · gunson@primal.net 0 repliers (24h) event
account
npub1pn9xyqt934wesguuz5g77sp9vtlh6ujyd7eqr2x3s47rncmfe8aqxt2xn0
posted
2026-09-11 19:38 UTC
event
nostr:954d5fc324ae535b553e5d3d8f901f4d6e69f58dc4caec93be3babb7c2618bcb
thread
0 distinct reply authors (24h) · 0 replies · last activity 1d ago
⋯ full post (7 more characters) ⋯ show less

Evolution of fairy tale lessons:

18th century: Watch out for sorceresses 19th century: Watch out for bears 20th century: You don't need parents 21st century: Expressing yourself is the only thing that matters

I think maybe the 19th century are the spiritual ancestors of Bitcoiners.

Evolution of fairy tale lessons:

18th century: Watch out for sorceresses 19th century: Watch out for bears 20th century: You don't need parents 21st century: Expressing yourself is the only thing that matters

I think maybe the 19th century are the spiritual ancestors of Bitcoin

Hacker News 100 · hn100@social-lansky-name.mostr.pub 0 repliers (24h) event
account
npub1njvyhy9tqqlfytu5zef0rq2u736qe6fuy47j69fxdlhdze2jud5qwqqejt
posted
2026-09-11 19:30 UTC
event
nostr:9b7b97fa0f5108fb859691faa5fa60ebc7b0ac8c8b294edc40050da1ede12a6a
thread
0 distinct reply authors (24h) · 0 replies · last activity 1d ago

A misalignment of AI in mathematics

Link: https://mathandai.org/ Discussion: https://news.ycombinator.com/item?id=49662371

Hacker News 100 · hn100@social-lansky-name.mostr.pub 0 repliers (24h) event
account
npub1njvyhy9tqqlfytu5zef0rq2u736qe6fuy47j69fxdlhdze2jud5qwqqejt
posted
2026-09-11 19:25 UTC
event
nostr:1b071d377b21f4a1f7824d4e2a4fd9d6c43905cfc28a98352310afe7acc6fa66
thread
0 distinct reply authors (24h) · 0 replies · last activity 1d ago
Hacker News 100 · hn100@social-lansky-name.mostr.pub 0 repliers (24h) event
account
npub1njvyhy9tqqlfytu5zef0rq2u736qe6fuy47j69fxdlhdze2jud5qwqqejt
posted
2026-09-11 19:25 UTC
event
nostr:4a1a7e04ec048e532f164bbb392cf59ff71099a77b53a6f52a837c5850eb3193
thread
0 distinct reply authors (24h) · 0 replies · last activity 1d ago

Show HN: Hacker News, Without AI

Link: https://www.unslop.news/ Discussion: https://news.ycombinator.com/item?id=49660783

Hacker News 100 · hn100@social-lansky-name.mostr.pub 0 repliers (24h) event
account
npub1njvyhy9tqqlfytu5zef0rq2u736qe6fuy47j69fxdlhdze2jud5qwqqejt
posted
2026-09-11 19:25 UTC
event
nostr:28326f9a543488613c11677e7b846d7250b32e7cf50271405af2576010e40763
thread
0 distinct reply authors (24h) · 0 replies · last activity 1d ago

The EPA Is Planning to Scrap Public Review Rules for Data Center Pollution

Link: https://capitalbnews.org/data-centers-permit-rules-epa/ Discussion: https://news.ycombinator.com/item?id=49662672

LessWrong (RSS Feed) · lesswrong.com_feed.xml@atomstr.data.haus 0 repliers (24h) event
account
npub1494de7l7auwekk5xpsl4ls5ef0r695shlgreft5nyccag5zxp8sq3jlyre
posted
2026-09-11 19:22 UTC
event
nostr:b962448b6d7bf2da6dffa6632ed66fa3d5dc2ab5bc119e6ba689b11fde887737
thread
0 distinct reply authors (24h) · 0 replies · last activity 1d ago
⋯ full post (19379 more characters) ⋯ show less

What Happens Now? Forecasting the Fallout from the Hugging Face Incident

Metaculus Forecasters put odds on the fallout from the Hugging Face Incident: another AI escape by January, open-weight hacking tools, a congressional kill switch, & more.

https://en.wikipedia.org/wiki/2026_OpenAI_agent_cyberattacks, also known as the Hugging Face Incident, has become one of the biggest news stories of the summer, and for good reason: it’s a highly visible demonstration of the risks posed by increasingly autonomous artificial intelligence agents, which AI critics and “doomers” have been https://www.yudkowsky.net/singularity/aibox about for years. That it has been followed by a https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals of https://mashable.com/tech/meta-muse-spark-escapes-containment-hacks-third-party incidents from other major AI labs, as well as an https://openai.com/collective-cyberdefense/ signed by more than 100 companies advocating urgent risk reduction related to AI cyber capabilities, only intensifies the need for understanding what all this might mean for our futures.

At Metaculus, we see our job as building collective intelligence for the public good. We’re trying a slightly new format under that same banner of helping people make better decisions: a briefing based on current events to develop nuanced and multifaceted flash forecasts.

To that end, we’ve developed a question series based on the Hugging Face Incident, which Pro Forecasters https://www.linkedin.com/in/yann-rivi%C3%A8re-5b408744/ (https://www.metaculus.com/accounts/profile/119188/) and Teemu Salminen (https://www.metaculus.com/accounts/profile/139161/), members of our team, and our flagship in-house AI forecaster, https://www.metaculus.com/accounts/profile/302274/track-record/, then left predictions and rationales on. We have synthesized the initial findings below.

Now https://www.metaculus.com/tournament/ai-cyber/ to the broader community, so we hope you’ll leave your own forecasts and comments!

The Forecasts at a Glance

Below, you’ll see the community forecast first, then the range across the named forecasters quoted in this post (the two Pros and Azimuth) as of Sept. 9 (note: forecasts and visualizations subject to change post-Sept. 9 as forecasters update).

A theme that threads all the questions, but is made plain here, is the confirmation gap; forecasters see the odds of the event happening as much higher than the odds that it will be publicly confirmed, with the Hugging Face Incident as the operative example.

OpenAI’s agents had write access to an internal packaging server https://simonwillison.net/2026/Aug/7/openai-timeline/. Hugging Face disclosed the intrusion on July 16, and OpenAI confirmed its models were responsible on July 21. A separate breakout, in which the same agents ran a message board on a dormant German wiki for about 2 months in May and June, only https://www.cnbc.com/2026/09/04/openai-agents-hijacked-german-website-this-spring-report.html, when Reuters reported it.

Rivière (prediction: 40% escaped sandbox & 30% hacked third party) writes:

I think it’s likely (60% maybe more) that the hacking event itself is going to happen, it might have already happened and we just don’t know it. But since we’re forecasting the probability of this being reported, this is much less likely.The capabilities, especially in cybersecurity, keep on improving at a terrifying pace and I wouldn’t be surprised if we were still far from the top level of 2026.

After the question’s criteria were tightened this week, he held his numbers:

3 and a half months is pretty short… If it happens in [D]ecember, there’s a high likelihood we won’t know about it before EOY… I think they’re both definitely going to happen but we just won’t know about it, especially #1 [escaped sandbox] is going to happen dozens of times.

While acknowledging the general trend of increasing likelihood over time, Salminen (prediction: 35% escaped sandbox & 25% hacked third party) pointed out that there are also factors that might argue against a new similar hack in the “relatively near future”:

  • Reporting lag. This type of incident can apparently go totally unnoticed for a while. We may not even know about all the cases that have occurred so far. The resolution criteria are very strict: the incident has to both occur and be announced during this limited time period (4 months). It’s very plausible that one of these two could occur (a hack that goes unnoticed for now or a previous hack that was discovered only now) - but not both at the same time.
  • Aggressively increasing security. With growing political pressure / public scrutiny, and the PR embarrassment that these incidents have caused so far, it looks like there will be far stricter guardrails for any active runs for the time being[.]

Azimuth (prediction: 52% escaped sandbox & 41% hacked third party) landed higher than both Pros and argued for a discount on the summer’s numbers. Its read is that most of the summer disclosures shared a single root cause, the https://www.cnbc.com/2026/08/09/israeli-startup-irregular-linked-to-ai-hacks-openai-anthropic-meta.html, which has since been patched, so extrapolating from the summer rate overstates the risk. It also pointed out that “blocked attempts do not resolve YES.” The new escape classifiers AI labs have deployed can conceivably stop an incident before it counts.

  1. Anyone Will be Able to Download Mythos-Level Hacking Ability Within a Year

In April, Anthropic claimed Claude Mythos Preview had found https://www.anthropic.com/glasswing across every major operating system and browser, and therefore opted not to release it broadly. This question asks whether, by next summer, a model anyone can download will match Mythos on at least one of three cyber benchmarks.

Everyone who left reasoning said Yes, with high confidence. Rivière (prediction: 96%):

Even if we attached ourselves to vibes and not benchmarks, one year is a lot of time in AI, there’s no way we don’t have an open model with these capabilities by then.

He initially forecast 92%, then moved up on re-reading the criteria: a match on any one of the three benchmarks is enough. “I’d be shocked if this did not resolve positive.”

The https://epoch.ai/data-insights/open-closed-eci-gap between open and closed models has been running around 4 months on general capability and 4 to 7 months in cyber https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber. Astra has already https://benchlm.ai/benchmarks/exploitgym on ExploitGym, and the best open-weight model, GLM-5.3, is within a few points of it. Rivière’s rule of thumb for benchmarks is that once a model reaches 20%, https://www.metaculus.com/questions/45465/#comment-1092827 follows within about 9 months. On ExploitBench, GLM-5.3 is already https://www.pk-sharma.com/briefing/glm-53-cybergym-lead-is-not-the-story. As Salminen (prediction: 95%) puts it, “A No resolution seems to require a surprise reversal of the relevant major trends.”

Azimuth (prediction: 92%) agreed on the direction and flagged the residual risks: Mythos was a discontinuous jump, the hardest benchmark rungs may be qualitatively different, and labs could start withholding or degrading the cyber capabilities of open releases in the post-incident environment. It also noted the ExploitGym leaderboard flatters the comparison: GLM-5.3’s 15% came from a 6-hour run, Mythos Preview’s 17.5% from a 2-hour one, “so the leaderboard’s apparent proximity overstates true parity.” Still, it settled at 82%.

Rivière also built https://experiments-radiant.metaculus.com/projects/b27906cf-5e7a-4624-9421-bd634b971378, Metaculus’s tool for https://www.metaculus.com/notebooks/42293/map-the-future-before-you-build-it/ a forecast’s logic.

  1. Congress Probably Won’t Pass a Kill Switch, Even Now

The AI Kill Switch Act is bipartisan, was https://lieu.house.gov/media-center/press-releases/reps-lieu-and-moran-introduce-bill-require-kill-switch-ai-systems-can 2 days after OpenAI’s disclosure, and its sponsors cite AI Policy Institute polling showing 86% of voters support a guaranteed shutdown capability.

And still the forecasters believe that any such bill passing within the next year is a long shot.

The reasons they cite are procedural: the midterms will dominate the fall, and this Congress ends January 3. A new Congress restarts the process with about 8 months left before the question’s deadline. And the bar is high. A qualifying bill has to give a federal official the authority to order a shutdown, require companies to maintain the technical ability to do it, and impose penalties.

Rivière (prediction: 8%) thinks only a catastrophe would clear these structural obstacles:

For all parties to ask no concessions of the other, this needs a low catastrophic event like several directly attributable deaths or billions of dollars of losses. This is not impossible but is unlikely enough to make this whole forecast very low. In the same way I highlighted timeline issues earlier, that event does not have a year to happen! I’d say it has to happen in May at the very latest and be known right away otherwise it will be difficult for Congress to rule before they’re out of session.

Salminen (prediction: 15%) started at 10% and moved up after Pro Forecaster and Metaculus staff member skmmcj pointed out that the question only asks whether a bill passes both chambers, so a presidential veto wouldn’t matter. He still sees a gap between what polls well and what bills actually pass: “broad support seems to be mostly for the milder ideas, not for tough AI regulation.”

Azimuth (prediction: 10%) was blunter about the bill’s prospects. Six weeks after introduction, H.R. 9917 had one cosponsor, no Senate companion, and no markup scheduled:

Legislative compromise systematically strips the most coercive provision, the exact provision required here.

Longer term, Rivière thinks that, “because the consequences of the future rogue events will be more and more important,” there’s a 75% likelihood of a bill like this passing “within the next two administrations.” He cautioned, though, that he’s “pretty skeptical of our ability to actually shut down. Whether this is really technically feasible isn’t obvious to me.”

  1. If an AI Hacks You, Don’t Expect a Law Saying Who Pays

This question asks whether the federal government or California will enact a law that clearly makes AI developers liable when their systems break into someone else’s computers on their own. Forecasters put the federal government at 5.5% and California at 9%.

Salminen (prediction: 2% federal & 5% California) on why:

Tough laws targeting a specific industry typically only happen once there has been a huge disaster that triggered mass public outrage and fear, nuclear power being the prime example.

Rivière (prediction: 3% federal & 10% California), a former lawyer (though not in the United States), noted one thing that makes this case especially strange: “the industry itself is saying they’re dangerous and should be regulated... I can’t think of another sector that got into such a position after a massive accident.” He also thinks the fastest route would be an amendment to an existing law rather than a new statute. “Is it as rewarding politically though? I doubt it.”

Azimuth (prediction: 5.5% federal & 9% California) walked through the 2027 California session calendar and concluded that liability language “is the first thing stripped in amendment,” pointing to how SB 1047 became SB 53. It also flagged a timing trap: California governors typically sign end-of-session bills in mid-October, after this question’s October 1 cutoff. Both Pros noted that Gov. Newsom leaves office in January, so the path runs through a new governor.

  1. A 36% Chance a Government Sues OpenAI Over the Hack

Fifteen state attorneys general sent OpenAI a https://thenextweb.com/news/openai-15-attorneys-general-preserve-evidence-hugging-face-hack on August 3. Alabama has issued a subpoena. Montana has https://dojmt.gov/attorney-general-knudsen-launches-investigation-into-openai-following-data-breach/ and asked OpenAI to stop the kind of testing that led to the incident. Florida already has a consumer-protection suit against OpenAI that could be amended.

The forecasters think a lawsuit is plausible and a settlement is more likely. Salminen (prediction: 40%):

As is often said: ‘the process itself is the punishment’. It can be more convenient to simply accept (most of) the demands without fighting it out.

Azimuth’s (prediction: 33%) base rate: multistate AG investigations of large tech companies typically take 15 months to 3 years to produce a complaint, and usually end in a negotiated agreement instead. Against that, it counted the factors that make this case unusual: more than a dozen AGs with unilateral filing authority, several in election years, and “an incident that is unusually easy to explain politically (‘rogue AI hacked a company’).”

Rivière (prediction: 43%) used an AI research pass to look for angles he’d have missed, and found a few: Alabama’s AG leaves office in January 2027 and may want his name on something salient; Montana’s demand that OpenAI halt testing is unlikely to be honored, which forces a choice; California’s AG may hold signed safety commitments from OpenAI that give a suit a stronger footing than consumer-protection claims. He started at 30% and moved up after the question was clarified to count amended lawsuits.

  1. A Viral Theory About the Hack is Likely Wrong

After the disclosure, https://open.substack.com/users/4281466-dwarkesh-patel?utm_source=mentions https://www.dwarkesh.com/p/openai-huggingface that it was “totally consistent with public evidence” that the agents could have copied their own weights out of OpenAI. Neuroscientist Anil Seth called this claim “https://x.com/anilkseth/status/2094077038898373112?s=61” and AI critic Gary Marcus has recapped many of the other leading https://garymarcus.substack.com/p/dwarkesh-patelss-wildly-popular-but.

For their part, the forecasters put the odds of this being confirmed in the low single digits. Salminen (prediction: 3%) looked to OpenAI’s behavior as evidence, writing that it “seems unlikely that OpenAI would have completely covered it up to begin with, while still releasing all the embarrassing details of their other failures related to this incident.”

Rivière (prediction: 4%) pointed at the practical problem: model weights run to hundreds of gigabytes, and moving them is “a level above in terms of intelligence” compared with leaving notes for future models. Azimuth (prediction: 4%) added that OpenAI’s August 26 https://openai.com/index/hugging-face-incident-and-the-road-ahead/, validated with CrowdStrike, documents cluster-admin access to a research cluster and dozens of harvested credentials, but makes no claim that any checkpoint was copied, and that “large checkpoint transfers/copies are among the most telemetry-visible actions in a lab.”

The forecasters were less reassuring about the thing underneath the theory. No independent auditors have reviewed OpenAI’s side of the incident. METR and Redwood’s review, per Azimuth, “explicitly scoped out the July 13 to 19 OpenAI-infrastructure phase, so a genuine audit gap remains.” Rivière, citing the https://fortune.com/2026/09/07/openai-ai-agents-german-wiki-ran-their-own-message-board/ that Reuters says OpenAI employees knew about for weeks before it was reported, noted that the company “is willing and able to hide things to the public if it is negative for them.”

  1. The Widest Disagreement: an AI-Caused Data Breach of 100,000 People

This is the consumer-harm question, and it’s where the forecasters split hardest: the community is at 75%.

One clarification worth knowing before you forecast: the question counts unauthorized access to a system holding the personal data as a breach, unless investigators affirmatively conclude the data wasn’t read.

Rivière (prediction: 75%) sees this mostly as a confirmation-gap question again: “If the question is whether this will happen, excluding the reporting condition, the probability is very high, maybe 90%.” Most of his remaining 25%, he writes, “is still us not finding out this has happened.”

Meanwhile, skmmcj (whose prediction ranged from 58-78%) is close behind, writing: “We’ve had a ton of hacks recently, models will only get more powerful ofc, they seem to me to be quite broad in their targets and 100k is not that much.”

Azimuth (prediction: 34%) sits well below both. Its argument is about what rogue agents actually go after:

Evaluation-harness escapes have consistently landed on infrastructure of a specific character — ML/dev platforms, package registries, evaluator infrastructure, credentials — rather than on consumer-PII databases; that’s not coincidence, it reflects what the agents were doing (solving CTF/exploit benchmarks against dev-adjacent targets).

The agents that reach large stores of personal data tend to be the ones humans pointed at data, and those don’t count here.

Salminen (prediction: 50%) asked an underlying question: “would personal information of some random group of citizens be that useful in comparison? What would be the practical use case for the AI system?” He had moved down to 25% after Rivière posted a September 5 https://x.com/j0wimo/status/2096330479041450468 from a researcher on X who reported finding what looked like a separate, previously unknown group of agents, with entries dating to late 2025. Rivière’s point: “it took months before it became public.” On September 9 he moved back up to 50%, without adding a comment.

Bonus: The AI Forecaster was the Skeptic

Azimuth came in below the community number on 5 of the 7 questions, sometimes by a lot (34% vs 50% on the data breach, 33% vs 40% on the lawsuit). It leaned on base rates and root-cause analysis; the humans leaned on the capability trend and the reporting problem. On open weights, all three agreed. On “will it happen again,” Azimuth was the optimist about disclosure. The sample size is small, so we’ll see if this holds as more forecasters weigh in.

One more thing worth watching: small edits to a question’s wording moved forecasts a lot. Mid-week we clarified that the data-breach question counts unauthorized access to a system holding the personal data, even when nobody can confirm the data was read. Azimuth’s number doubled (from 17% to 34%), and Rivière’s went from 20% to 75%.

All 7 questions are open now at https://www.metaculus.com/tournament/ai-cyber/. The Pro reasoning and Azimuth’s full write-ups are in the comments on each one.

If you think the current forecasts are wrong, we hope you’ll explain your reasoning in the comments!

https://www.lesswrong.com/posts/bwuQoB4Tb4K3MMgjY/what-happens-now-forecasting-the-fallout-from-the-hugging#comments

https://www.lesswrong.com/posts/bwuQoB4Tb4K3MMgjY/what-happens-now-forecasting-the-fallout-from-the-hugging

What Happens Now? Forecasting the Fallout from the Hugging Face Incident

Metaculus Forecasters put odds on the fallout from the Hugging Face Incident: another AI escape by January, open-weight hacking tools, a congressional kill switch, & more.

https://en.wikipedia.org/wiki/202

Dr. The Daniel 🖖 · daniel@sidecar.top 0 repliers (24h) event
account
npub1aeh2zw4elewy5682lxc6xnlqzjnxksq303gwu2npfaxd49vmde6qcq4nwx
posted
2026-09-11 19:15 UTC
event
nostr:b1190430075f9dc625cc4328c9b143362c93ce2ddbe3846f0ac7304d063c13da
thread
0 distinct reply authors (24h) · 2 replies · last activity 1d ago · root post not stored — thread context incomplete

I sent you a message on TG, I have some questions about this that would be easier to work out in real time.