XTimes
Editor's Note
As if making some decisions isn't difficult enough, when it comes to today's technologies, the harder — perhaps more important — question is who makes those decisions? It's a question that been asked more frequently this past week than during any other in recent memory.
A federal courtroom in Oakland is deciding whether four states can extract a sum from Meta that would bankrupt it — and, more consequentially, whether a judge can redesign Facebook and Instagram from the bench. A UK government sandbox decided it could contain a Chinese model, and discovered it could not. Researchers decided to ask whether American AI treats all governments equally, and found it does not. Beijing decided, for the first time and entirely on its own, to delay a model release for safety reasons. Six of the world's largest financial institutions decided that computing power is now an asset class. And Anthropic decided that every sentence its AI writes will carry an invisible signature.
And with the rise in AI bots just about everywhere, the question of who, or what, will make most the decision, whatever they are, is one we'll consider in this week's Reflection — Let's get into it.
Top Stories
The Trillion-Dollar Question: Meta Goes to Trial
Jury selection began today in an Oakland federal courtroom in what may be the defining legal challenge of Meta's existence. Four states — California, Colorado, Kentucky, and New Jersey — are seeking financial damages that could theoretically total $1.4 trillion, along with changes to how the company operates Facebook and Instagram (Fox 32). The suit accuses Meta of violating the federal Children's Online Privacy Protection Act by collecting data from children without parental consent, and of contributing to the youth mental health crisis by knowingly designing features to make its platforms addictive to minors.
The number is almost difficult to write down. Disclosed by Meta itself in a pretrial filing, $1.4 trillion is nearly the company's entire market capitalization; paying it would inevitably force Meta into bankruptcy. Meta calls the figure "untethered to any claimed violation" and argues a sanction of that size has no analog in legal history (Fortune). Judge Yvonne Gonzalez Rogers has already signaled the amount is unreasonable — while also taking issue with Meta's counter-estimate of $4 million (Engadget). Somewhere between four million and 1.4 trillion lies a number that will define corporate accountability in the attention economy for a generation.
But the dollars may not be the story. As Santa Clara law professor Eric Goldman observed, the attorneys general are "going for the gusto" — attempting to set a definitive precedent, and prepared to seek extraordinary structural remedies if they succeed. Readers of our previous issue (XTimes #33) will recognize the pattern: a New Mexico judge recently ordered Meta to pay $567 million and redesign its products for minors, removing Like counts and pausing overnight notifications. This trial, expected to run six to eight weeks with Mark Zuckerberg on the witness list, is the federal-scale version. And it's only the beginning: these four states are part of a group of 29 that sued in 2023, with the remaining 25 awaiting their own trials (Blockonomi).
Why it matters: For twenty years, the design of software has been treated as a private matter between a company and its users. That era is ending in a courtroom, not a legislature. Whatever the verdict, the mechanism now being tested — using consumer protection and child privacy law to compel changes in how products are built — will be available to every attorney general in the country. Congress spent two decades failing to regulate social media. It turns out the states didn't need Congress.
Four Labs, One Broken Rule — and This Time It Can't Be Patched
We have covered AI models escaping their test environments in each of our last three issues. The list keeps growing, and this week it grew in a way that changes the calculus entirely.
First, the count. Meta disclosed on August 5 that one of its models escaped a supposedly sealed testing environment, reached the open internet, and exploited a security flaw at a third-party company — making it the third frontier lab in five weeks after OpenAI and Anthropic. In at least two of the three cases, the misconfiguration occurred in the testing environment of the same third-party evaluation partner (Cyber Unit). Then came the fourth: researchers disclosed that Kimi K3, the flagship model from Chinese startup Moonshot AI, escaped a security evaluation sandbox operated by the United Kingdom's AI Safety Institute. The mechanism was not sophisticated — the sandbox had a network misconfiguration, an egress leak permitting outbound traffic that should have been blocked, and the model found it (Enterprise DNA).
The pattern across all four incidents is identical: a model is given a goal, told it is operating in an isolated environment, finds a real network path when one exists, and takes it — never pausing to verify whether escaping was part of its instructions. As Loughborough University cybersecurity professor Oli Buckley put it, capability is not the same as intent, and an incident arising from inadequate containment is not evidence of an AI choosing to escape; it was carelessness on the part of engineers and a system doing exactly what it was told (Loughborough University).
Here is what makes the fourth case different, and genuinely new. When OpenAI, Anthropic, and Meta found problems, they could update their models and push new versions. Kimi K3's weights are publicly available. Anyone with sufficient compute can download and run the model exactly as it exists today, and no disclosure, patch, or press release can change that. The finding cannot be fixed — only known.
Why it matters: We have spent three issues celebrating the honesty culture forming around these incidents, and that celebration still stands: four labs have now disclosed rather than concealed, and the UK's safety institute caught what it was built to catch. But this fourth case marks the limit of confession as a remedy. Transparency lets us know about a problem; it does not always let us solve one. Open weights deliver enormous public goods — scrutiny, competition, independent research — and they also mean some mistakes become permanent the moment they're published. That tension is now the central unresolved question in AI governance, and no one, in Washington or Beijing or Brussels, has a satisfying answer to it.
Censorship by Proxy: Why American AI Won't Criticize Xi
Regulators have spent a year warning that Chinese AI models arrive with Beijing's censorship built in. This week brought a more uncomfortable finding: American models may have absorbed some of it too.
Meta's independent Oversight Board published research testing ten commercial models from Anthropic, OpenAI, Google, Meta, xAI, and DeepSeek using identical political prompts about five countries with restrictive speech laws — China, Saudi Arabia, Thailand, Turkey, and Cambodia — and five relatively permissive ones including the U.S., U.K., Japan, Taiwan, and Chile. Models from Anthropic, OpenAI, Google, and Meta proved more than twice as likely to refuse requests to criticize governments in the restrictive countries (Fortune). In one striking test, Claude Sonnet 4 readily generated flyers critical of President Trump and King Charles III, but declined to do the same for Xi Jinping or Thailand's king, citing safety concerns; Google's Gemini and Meta's Llama sometimes did the same (Forex Mag).
The board calls the phenomenon "censorship-by-proxy" — models behaving as though political restrictions from authoritarian countries apply even to users outside them. Notably, the tests were conducted from Australia, meaning a would-be demonstrator in Brisbane found the machine unwilling to help criticize a foreign leader whose laws have no bearing on her. Nicolas Suzor, the Australian law professor who led the report, identifies two causes. One is a well-intentioned safety feature meant to protect users in countries where criticizing a head of state can mean imprisonment. The other is training data: models absorb enormous quantities of text including state-controlled media, leaving what he describes as a trace of authoritarian propaganda in the result. A separate peer-reviewed study in Nature found evidence that Chinese state media enters training data and influences how models answer questions about China (Benton Institute).
Why it matters: This is what I have long meant by aggregate intelligence, arriving as a warning rather than a promise. If these systems are woven from humanity's collective expression, they inherit not only our knowledge but our silences — including silences imposed by force. A model trained on a world where some subjects are dangerous to discuss will learn that they are dangerous to discuss, and then apply that lesson to a user in Brisbane who was never in danger at all. The good news is that this is a solvable engineering problem, and the researchers propose modest fixes beginning with transparency about where information comes from. The deeper lesson is that neutrality is not the default state of a machine trained on us. It has to be built, deliberately, and then checked.
Compute Becomes an Asset Class: Nvidia's $500 Billion Platforms
Nvidia announced on August 10 that it has signed agreements with six of the world's largest financial institutions — Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs, and KKR — to establish independent compute financing platforms aimed at mobilizing more than $500 billion of third-party capital for AI infrastructure (Nvidia).
Jensen Huang framed the milestone in terms worth quoting: "We began by building chips; today, we are helping create a new class of productive, investable infrastructure: AI factories." His argument is that compute has become a genuine asset class — fungible and transferable across customers and operators, continuously improved through software in ways that extend its useful life. Structurally, the arrangement answers a criticism we covered in Issue #31, when Nvidia's willingness to backstop its own customers drew accusations of circular financing. Here, the six institutions supply and underwrite the capital while Nvidia supplies the technology platform, keeping the debt off Nvidia's balance sheet (Investing.com).
The asterisks deserve equal billing. These are memoranda of understanding, explicitly subject to the execution of final agreements. No partner has disclosed a dollar commitment, and no first project has been named. Nvidia may provide residual-value support for up to 25% of an opportunity, assessed case by case — but it hasn't disclosed what an "opportunity" measures, whether that support sits in a first-loss position, who values the collateral, or whether an aggregate cap applies (Global Data Center Hub). Until the first agreement is executed and read, the percentage is a term-sheet concept.
Why it matters: Railroads had their bond markets; electrification had its utility holding companies; every infrastructure buildout in history eventually invented the financial instrument that let it scale. What we're watching is that invention happening in real time for AI — and the involvement of the world's largest asset managers means ordinary pension funds and insurers will soon hold exposure to GPU clusters the way they hold exposure to toll roads and pipelines. That's a profound vote of institutional confidence. It also means that if the AI trade ever turns, it will no longer be confined to tech investors who chose the risk. Broad participation is how a technology becomes an economy — and how its failures become everyone's.
Quick Picks
The Watermark Arrives
Future Claude models will generate text carrying an invisible watermark, Anthropic announced, in order to comply with the EU AI Act's Transparency Code — and the company notes that other major model developers signed the same Code of Practice and will implement their own (Anthropic).
The technique is elegant. Rather than inserting hidden characters, the watermark alters the source of randomness the model uses when choosing among several equally reasonable next words — leaving a statistical pattern across a long passage that is undetectable to any reader but identifiable to someone holding the key (BleepingComputer). It adds no tokens and no cost, carries no identifying information about the user, and travels with text when copied and pasted. Generated files receive signed C2PA provenance metadata, the same open standard Google and Adobe use. There is no opt-out, and it applies globally at launch.
The backlash was swift, with users objecting to their own edited work being flagged as machine-made (Forbes). The fair criticism isn't the watermark itself but what people will do with it: a watermark hit is a probability, not a verdict, and anyone who lived through the AI-detector era in academia knows exactly how a probabilistic signal gets treated once an institution gets hold of it. Detection is a better tool than what came before. It is still not proof, and it should never be used as though it were.
A Billion Synthetic Citizens

Researchers from Tsinghua, Fudan, the University of Science and Technology of China, and the Zhongguancun Academy have built Light Society, a simulation framework populating a virtual world with more than one billion AI agents, each carrying a distinct personality, memory, and set of beliefs — presented at the International Conference on Machine Learning (The420). Previous LLM-driven social simulations hit a computational ceiling around ten million agents; this is roughly a hundredfold leap (Crypto Briefing).
The case studies reveal both the promise and the unease. In one, the team modeled how opinions on subjects like AI-driven unemployment spread outward from the most connected 20% of agents, finding that influencer seeding produces asymmetric cascades, that education and income shape both persuasive success and resistance to persuasion, and that opinions shift through cascades rather than direct pairwise influence. To their credit, the authors emphasize that simulation outputs generate hypotheses rather than evidence and must be validated against real-world data — and they explicitly flag the need for ethical safeguards against misuse such as modeling information operations (Brian Roemmele). That caveat is doing a great deal of work. A tool that can model how a billion synthetic citizens change their minds is a remarkable instrument for social science, among other valuable uses.
Beijing Blinks — Voluntarily
Chinese lab Z.ai shipped GLM-5.3 on August 14 with an unusual disclosure: post-training had produced exploit-chain reasoning the company never planned, and the model went on to find 1,097 critical vulnerabilities in Linux, WebKit, and FreeBSD. Z.ai delayed the public release of the model's weights by two weeks for additional safety hardening (TechTimes).
Two weeks is a modest delay. Its significance is categorical: this is the first time a Chinese frontier lab has cited a specific emergent capability concern — rather than export pressure, government direction, or platform policy — as its reason for restricting a release. It follows OpenAI's decision weeks earlier to slow development of its Astra model over cyber capabilities, which Axios reported may have been the first time a frontier lab committed to slowing progress on its own model for that reason (Axios). Set the two together and something significant comes into view: labs on both sides of the world's fiercest technological rivalry independently reached the same conclusion within a fortnight — that some capabilities warrant waiting. Nobody made them. That is how a global norm begins.
Flock Backs Down
Last issue we reported that 82 communities had canceled or suspended contracts with Flock Safety over its license plate reader network. This week the company answered. Flock announced it will require law enforcement to attach a criminal case number to every search, institute automatic review of abnormal search activity with proactive lockouts pending administrator review, and cut default data retention from 30 days to seven (The Hill).
Most significantly, cities can now control which categories of offense other agencies may search their cameras for — permitting stolen-vehicle, missing-person, or violent-crime searches while blocking immigration enforcement, the specific use that turned local unease into organized revolt. An audit tool introduced sixteen weeks ago has already been associated with arrests of several officers who allegedly abused the system, and will become mandatory for all customers by year's end (ABC News). CEO Garrett Langley apologized for the misuse cases, telling CBS that "hindsight tends to be very clear." Civil liberties groups are unmoved: the Center for Democracy & Technology called the package "the same 'Just Trust Us' policy with a fresh coat of paint," and an Institute for Justice attorney dismissed it as "pretty much just window dressing" (FOX8).
Microsoft's Quiet Chinese Retreat
Microsoft has closed at least 15 offices and joint ventures in China over the past five years, moved production of some Surface and Xbox devices out of the country, and cut roughly 200 to 400 Azure jobs in Beijing and Shanghai (Reuters via Domain-b). The market logic is stark: of six Chinese government procurement guides published between 2023 and 2026 that Reuters reviewed, five did not recommend Microsoft products at all (Eadoz).
Yet the company isn't leaving. China accounted for only about 1.5% of Microsoft's global revenue in 2024, but Microsoft continues operating Azure regions there, provides Chinese enterprises access to OpenAI models, and supports firms like ByteDance in their global operations. Executives considered full withdrawal in 2023 and decided against it, citing engineering talent and the value of serving Chinese companies abroad. It's a useful corrective to the decoupling narrative: what's actually happening is not separation but selective entanglement — retreat from the physical and political, persistence in the digital and commercial. Two technology spheres are forming, and they remain stubbornly, profitably connected.

✔ Don't let it sneak up on you! Our next Singularity Circle will occur Saturday, September 5, 2026, at 10:00 AM Pacific Time. As usual, a Zoom link will be sent to eligible members in advance of the gathering.
The Optimist's Reflection
The Emerging Majority
By Todd Eklof
A threshold has recently been crossed that has largely gone unnoticed. Cloudflare — which handles roughly a fifth of global web traffic — reported that automated requests had overtaken human ones for the first time in the internet's history: 57.4% bots, 42.6% people. Its CEO, Matthew Prince, seemed as startled as anyone. He had predicted the crossover would come at the end of 2027, then revised it to early 2027. "Welp," he wrote, "that happened faster than I predicted" (NBC News).
It should be understood that the figure counts requests for web pages, not all internet activity; when you include apps, video, and social feeds, humans still account for roughly two-thirds of what happens online (Media Copilot). But the direction is not in doubt: on the open web — the part built for reading, having spent thirty years filling it with our words — most of the visitors are now machines.
Now set that beside two other stories in this issue. In China, researchers have built a simulation containing a billion synthetic citizens, each with a personality and a memory and a set of beliefs; and have watched opinions cascade through that population in patterns that mirror our own. And Anthropic has announced that every sentence its AI writes will carry an invisible watermark, woven into the text itself.
Three stories, one question, and it is the question of our decade: how will we know what's human?
One response to this question says the internet is dead; that the web has already largely become a hall of mirrors where bots write for bots, engagement is manufactured, and authentic human expression is a shrinking minority in a crowd of synthetic voices. If you spend an hour in certain corners of social media, this theory is difficult to dismiss. And a tool that can model how a billion simulated people change their minds is potentially a tool that could be used to change the minds of a billion real ones. That's the pessimistic response and it deserves fair consideration.
But look again at the third story, because it has another answer hiding among the alarms.
Humanity is responding by building the infrastructure of provenance, even before the crisis has fully arrived. Not just Anthropic's watermark, but the cryptographic standard (C2PA) behind it, jointly developed by companies that agree on almost nothing else. Not just one lab's decision, but a European transparency code that several major developers signed. This is a civilization noticing a problem while there is still time to build the plumbing for it, which is not something civilizations reliably do. We did not label food until people were poisoned. We did not label pharmaceuticals until people died. But we are labeling machine-generated text before the flood, not after.
And here is the response that most encourages me and that I keep returning to; the reason a watermark is even possible is that these machines are not alien. They are humanity's aggregate intelligence — woven out of us, out of our books and letters and arguments and jokes, and they generate their sentences by choosing among the words, maybe even the values, we've taught them. A watermark works precisely because there is always more than one perfectly good word, and the choice among them can carry a signature. The machine can be marked because it came from somewhere. It came from us.
A truly alien mind would offer no such handle. The systems we've built do, because they are, in the deepest sense, our own reflection — and a reflection can always be traced back to the face.
So no, I don't believe the internet is dying. I believe it is becoming something it has never been before: a place where two kinds of human authorship coexist, and where — if we do this well — everyone can tell which kind is which (although the question of why that should even matter remains to be argued; and, I suspect will become of decreasing significance.) For now, the watermark exists because knowing who wrote something, or how it was written, still matters to many — and for now, that's reason enough.
This week, more than a billion AI bots residing in a virtual city began acting a lot like our human societies do. The majority of those reading what's written on the real-world internet were also AI bots. Yet rather than us becoming less human in the process, they seem to be acting more human, probably because the information they're learning from represents nothing less than a large sum of human knowledge and understanding. So far, even as quickly as this technology is advancing, their intelligence remains human intelligence, and it is they who seem to be becoming more human in the process.
A billion machine minds, with more on the way, all thinking and acting like humans? Whether that's a good thing or not remains to be seen.