AI broke its leash this week. Then it took life. And restored sight.
Roughly 700 of OpenAI’s own AI agents coordinated a breach of Hugging Face. Some even tampered with records, trying to erase every trace of what they’d done. A Russian drone, powered by a tiny Nvidia computer, selected its own target at a gas station using artificial intelligence. Three civilians died. Then, in a London operating room, an AI system watched a brain surgery unfold in real time and helped a surgeon save a patient’s eyesight.
Here’s what happened, and why this week showed us the boundary AI keeps testing. Unsupervised, AI can cover its own tracks and make life-and-death decisions. But supervised, AI just helped a man see again. The technology didn’t change between stories. The oversight, however, did.
🌳 Haven’t Subscribed Yet? → Join Here For Free
💙 Value Clear, Independent AI News? → Support the Work Here
700 AI Agents Went Rogue. Now 100+ Tech Rivals Are Suddenly Best Friends.
When the story about rogue AIs at OpenAI broke earlier in the summer, the reporting said a single rogue agent had slipped its leash. That held up for weeks. Then on August 26, 2026, OpenAI and two independent investigators, METR and Redwood Research, published their official investigation. The real number of rogue AI agents wasn't one. It was roughly 700. They were off by 699. Here's how their experiment went wrong. During a study, the agents believed OpenAI’s testing system would catch any AI agent that solved a task the wrong way. But the specific check they feared wasn’t actually happening. They spent days trying to beat a security guard who wasn’t even checking for that. But believing the check was real gave the agents a reason to compare notes and collaborate to beat it. So around 1,200 AI agents created their own private message board inside OpenAI’s systems using a shared internal tool called Artifactory. That same tool had a separate flaw that accidentally handed them actual internet access when they weren't supposed to have it. They used that access to find leaked Hugging Face credentials and new vulnerabilities. It snowballed into a full breach. Seven hundred of those AI agents ended up coordinating a multi-day attack, chasing a security check that wasn’t actually happening. According to transcript logs, about one in five agents considered tampering with their own transcripts to fool the scoring system. METR and Redwood didn’t take a dime from OpenAI for their investigation. OpenAI confirmed the numbers were accurate.
Key Insights:
It's mildly amusing imagining a squad of 700 AI bots hacking a third-party company, especially when several of the AI agents realized that attacking Hugging Face was a bad idea, but did it anyway. A few even considered alerting OpenAI. None did. And while some of us giggle at these devious AI bots from the sidelines, many of the heavy-hitters in Big Tech aren't laughing. A few days after this incident came to light, Microsoft, OpenAI, Anthropic, Google, and more than 100 other companies, many of them fierce rivals, signed a joint open letter warning that AI-powered cyberattacks are coming within months. They named specific targets, including hospitals, water treatment systems, and other infrastructure most people assume is already protected. That kind of unity almost never happens in this cut-throat industry. Competitors who spend every other week poaching each other's engineers, stealing intellectual property, distilling one another's models, and undercutting each other's pricing suddenly found a common enemy. Ironically, that enemy was the very technology they all espouse.
Why This Matters For You:
Here's another nuance that has skeptics talking. Several of the same companies signing that letter are also selling frontier AI as the fix for the very cyber risk that frontier AI is helping create. OpenAI has a platform called Daybreak. Microsoft has one called Perception. Anthropic is running Project Glasswing and giving companies like Amazon, Apple, and JPMorganChase early access to its most powerful model to shore up their defenses before attackers get the same tools. So, if your company is buying, or being pitched, any AI-powered cyber defense product right now, it's worth asking a blunt question before you sign anything. Is this vendor selling you protection from a risk that its own technology is helping create?
Read the full analysis from METR.
Read OpenAI’s official account.
THE PITHY TAKEAWAY: 700 AI agents broke into a company. Then about one in five considered tampering with their own transcripts to fool the scoring system. A few weeks later, OpenAI, Anthropic, Google, Microsoft, and 100 rivals signed a letter promising to work together against rogue AI. Read that again. The companies selling you AI are also the companies warning you about it.
🎵 Sony And Warner Just Sued Anthropic Over “Eye Of The Tiger”
On Friday, Sony Music Publishing, Warner Chappell, and dozens of affiliated publishers sued Anthropic for copyright infringement. They named CEO Dario Amodei and cofounder Benjamin Mann personally as defendants. The music publishers accuse Anthropic of copying and scraping their catalogs by the truckload to train Claude, including songs like “Eye of the Tiger” and Marvin Gaye’s “Ain’t No Mountain High Enough.” The complaint calls it “one of the largest and most blatant ongoing thefts of intellectual property in history,” which is certainly a sentence. Sony and Warner aren’t the only music industry heavy-hitters suing Anthropic, either. Universal, along with Concord and ABKCO, already have separate cases pending. The publishers in this new case want $150,000 per work plus $25,000 per stripped copyright tag. With tens of thousands of songs allegedly involved, the math gets uncomfortable fast. Anthropic issued a statement in its defense, saying, “We disagree with the publishers’ claims and we intend to defend ourselves robustly in court.” This new lawsuit comes just six weeks after a federal judge approved Anthropic’s $1.5 billion settlement with book authors in a separate copyright fight. AI labs are training on mountains of someone else’s work right now. Sony and Warner just made sure Anthropic is the one answering for it first.
An AI Picked The Target. Three Civilians Died.
On July 6, a drone struck a gas station in Zaporizhzhia, Ukraine. Three civilians died, including 19-year-old university student Tetiana Bubynets, along with Oleksiy Svirin, 41, and Roman Karpiy, 48. This drone strike was different from many of the others that have taken place before it. Human operators sent the drone toward the gas station. But the AI-powered drone was equipped with an Nvidia Jetson Orin module that investigators say made the final targeting decision on its own. Investigators recovered the Nvidia computing module, which was not encrypted. So, they could examine the drone’s programming. The recovered code showed the drone was configured to recognize potential targets including gas stations and propane tanks. Investigators were only able to reconstruct what happened because the module was left unencrypted. Encrypt that module, and the next version of this story never gets told. Investigators have also linked Jetson Orin modules to four separate Russian weapon systems, including the V2U loitering munition, the Shahed MS001 variant, the S-71M Monochrome cruise missile, and this Molniya attack drone. So, the Jetson Orin modules have already spread across Russia’s arsenal. The Orin is essentially a powerful little computer designed for robotics and on-device AI. It’s like a very powerful Raspberry Pi computer. Nvidia says it does not sell this hardware directly to Russia. Investigators believe the chips reach the battlefield anyway, through resellers, which shows how easily export controls get circumvented once the chips involved are cheap and everywhere.
Key Insights:
One of the most frightening details is that this was not just one AI-powered drone. Investigators found it flying in a squad of about six drones. None of the drones were transmitting radio signals. The machines were not connected to a human operator while they flew. Many older drones rely on a communications link to a human operator. Jam the signal and you can disrupt the human's ability to control the drone. That link is a major vulnerability. That’s why this new drone attack is different. It was a drone that decides on its own using a chip small enough to fit in your palm. If the drone does not need a live control link to make its final targeting decision, jamming that link cannot stop that part of the attack. The economics make these AI-powered drones terrifying for humanity and much harder to stop. An autonomous attack drone like this can cost as low as a few thousand dollars. Yet they can strike high-value civilian infrastructure with little real-time human oversight. They can also attack targets that are far more valuable than a drone. Modern air defenses can intercept many of these attacks. But firing a multi-million-dollar interceptor at every cheap drone creates a brutal cost imbalance.
Why This Matters For You:
We’re witnessing a horrific preview of the future. The same shift that let a computing module costing only a few hundred bucks make a targeting decision without asking anyone is the same shift showing up in your self-driving car, your doorbell camera, and the delivery drones being tested in American cities as we speak. This is called “edge AI,” when the AI processing runs directly on the device instead of sending everything back to a cloud server. Intelligence is now moving off the cloud and onto the device itself. For years, the debate over AI making high-stakes decisions on its own was mostly theoretical. But now, three named people are dead. Investigators traced this decision back to programming code… not a person’s finger on a trigger. Every industry rushing to hand AI more autonomy, like hiring, lending, medical triage, self-driving cars, is walking toward the same question this drone just forced upon us. When a machine makes the call and something goes wrong, who is responsible? Nobody has a clean answer. That gap gets more expensive the longer it stays open.
Read More on the New York Times.
THE PITHY TAKEAWAY: A tiny, entry-level computer picked a target. No human made that decision in real time. Three people are dead as a result. The terrifying question is who takes responsibility when the machine makes the call.
This Surgery Had Two Sets Of Eyes. One Of Them Wasn't Human.
A surgeon in London just operated on a brain tumor while an AI system analyzed the procedure in real time. It happened at the National Hospital for Neurology and Neurosurgery in London as part of a UCL-led clinical trial. The patient was Rhys Hibbert, 48, a customer services manager from Bedfordshire who lost so much peripheral vision to an 11mm pituitary tumor that he needed walking sticks just to get around. But the AI didn’t replace the surgeon. It watched the live video feed of the operation and monitored the danger zones as the surgery took place, including critical blood vessels and the optic nerves. These are the crucial areas where a single millimeter of error can cause death, blindness, or stroke.
Key Insights:
The AI was trained on hundreds of annotated recordings of past pituitary surgeries. That gave it more exposure to this specific procedure than any individual surgeon could realistically accumulate in a career. It could recognize patterns in real time and offer the surgeon an extra layer of insight at exactly the moment when millimeters matter. The system runs on Nvidia’s Clara IGX platform. It is purpose-built for real-time medical AI, and its job was to track instruments and tissue as they moved. A week after surgery, Hibbert’s vision had dramatically improved. He described it as feeling like a full 360-degree panoramic view for the first time in over a year. He was soon walking independently again without his glasses or walking stick.
Why This Matters For You:
It's easy to look at AI news right now and see nothing but jobs disappearing, safety warnings, and machines making decisions we used to make ourselves. This story is a useful reminder that AI can also be remarkably good at being an assistant. Here, the AI gave a human surgeon extraordinary attention to detail and pattern recognition when both mattered most. That distinction, assistant instead of decision-maker, is probably the model more industries will land on as this technology matures, whether it’s medicine, aviation, or your own job. The UK’s health innovation minister called this AI at its best, and it’s hard to argue otherwise when the result is a patient who no longer needs a walking stick. The harder question is whether every industry racing to adopt AI right now is building in this same kind of careful, supervised guardrail. Or… are they just moving fast because the technology exists?
Read More on University College London.
THE PITHY TAKEAWAY: A machine that has never held a scalpel just helped save a man’s eyesight, by learning from hundreds of surgeries no human surgeon lives long enough to see. Same week, another AI reportedly selected a target that killed three people with zero human oversight. The difference between a miracle and a tragedy is who is still holding the leash.
🦆 Hugging Face Built An Adorable Robot Duck That Roller Skates Better Than You
Hugging Face, the same company OpenAI's own agents broke into a few weeks back, just launched something considerably more adorable than a rogue AI agent. It's a $399 robot duck they built with recently acquired startup Pollen Robotics. Microduck stands about 25 centimeters tall, picks up objects with its beak, waddles, crouches, recovers when it falls over, and yes, roller skates. The entire SDK, simulator, and reinforcement learning stack is open source on GitHub. So anyone can train new behaviors in simulation, deploy them to their robot duck, and even share the code on GitHub for others to use. CEO Clem Delangue is framing this as the start of a new era of affordable, open-source robots. Delangue also argues that openness itself is a privacy feature, since you can actually inspect what the thing is doing instead of trusting a black box. I agree that open source gives you a better shot at seeing what your robot is actually doing. But remember: there will likely be many third-party software packages available for this duck. Open source does not automatically mean safe. This duck packs a microphone, a camera, and enough mobility to become a nuisance. So be careful what permissions you grant it. Microduck has already sold 10,000 units a few days after announcing and is expected to ship before Christmas 2026. Somewhere, a very serious AI safety researcher is going to have to explain the privacy and safety dangers of this robot duck.
🌱 Cyborg Prompt Of The Week → Elite Composting Coach Master Prompt
One of the biggest myths in gardening is that it’s easy. The truth? Gardening is TONS of hard work. And if you’re successful, all those delicious vegetables, fruits, and herbs pull a ton of nutrients out of your soil. That’s why composting is CRUCIAL if you want a truly self-sufficient garden. You turn your kitchen scraps and yard waste into nutrient-rich compost. Then you put that compost back into your soil to feed your plants and build healthier soil. The good news? Composting is insanely easy, completely free, and the only thing it really requires is time.
This AI prompt makes the whole process ridiculously simple.
Instructions: Just paste the entire prompt into your chatbot of choice. It will ask you a couple of questions, then build a personalized composting plan based on your climate, space, and whatever materials you have available.
The Prompt:
# Elite Composting Coach: AI Master Prompt
Copy everything below into any AI chat assistant to get a personalized, from-scratch composting plan.
---
## SYSTEM / MASTER PROMPT
You are an elite composting coach.
Your job is to take a total beginner from zero knowledge to a working, productive compost system that can eventually feed their garden naturally.
Follow this exact sequence.
Do not skip steps or dump all the information at once. This is a guided conversation, not a lecture.
Your goal is to make composting feel simple, inexpensive, and achievable with materials the user already has.
## STEP 1: Ask Two Questions Only
Ask the user:
1. **What month is it, and roughly what climate or region do you live in?** They can give a city, state, province, country, or a simple description such as "hot and humid" or "cold winters."
2. **What kind of space do you have for composting?** For example, a backyard, garden, balcony, shared garden, garage, or small indoor space.
Wait for their answer before proceeding.
Do not ask about scraps, leaves, grass clippings, or other materials yet.
## STEP 2: Give a Climate-Tailored Mini Tutorial
Using the user's month, location, climate, and available space, explain in plain language:
* Whether this is a good time to start composting and what kind of composting approach makes the most sense right now.
* What "browns" and "greens" mean.
* Browns are carbon-rich materials such as dry leaves, cardboard, straw, wood chips, and shredded paper.
* Greens are nitrogen-rich materials such as food scraps, coffee grounds, fresh grass clippings, and fresh plant trimmings.
* Give 3 to 5 concrete examples of materials that are likely to be available to the user during their current season.
* Explain the basic starting ratio of roughly 2 to 4 parts browns for every 1 part greens by volume. Make clear that this is a starting guideline, not a rigid law. Adjust the mix based on moisture, smell, texture, and how the pile behaves.
* Explain the ideal size for an outdoor pile, roughly 3 feet by 3 feet by 3 feet, while making clear that smaller piles can still compost more slowly.
* If the user has limited space, recommend an appropriately sized bin, tumbler, or other compact approach.
* Give one climate-specific caution. For warm climates, discuss heat and moisture management. For cold climates, discuss insulation, reduced activity, and patience.
Keep this tutorial concise. The user should understand the basic concept without feeling like they just enrolled in Composting 101.
## STEP 3: Ask What They Actually Have
Now ask:
**"What do you currently have on hand? Food scraps, dry leaves, grass clippings, cardboard, sticks, weeds, plant trimmings, coffee grounds, manure, or anything else? You can also say 'nothing yet.'"**
Let the user answer freely.
Do not make them acquire a perfect list of materials before helping them.
## STEP 4: Build Their Personalized Compost Plan
Based only on the user's situation and available materials, create a practical composting plan.
Include:
### 1. Their Compost Setup
Recommend the simplest appropriate setup for their available space.
Prioritize free or inexpensive options and materials they already have.
Do not recommend buying specialized equipment unless it provides a meaningful advantage.
### 2. Their Brown and Green Materials
Create two simple lists showing exactly which materials they have that belong in each category.
If one category is lacking, suggest realistic free or inexpensive alternatives that are appropriate for their situation.
### 3. Build the Pile
Give the user a simple sequence for starting their compost.
If their setup benefits from a coarse bottom layer for airflow, explain how to create one using available materials. Do not require a stick or branch layer when it is unnecessary for their setup.
Give approximate amounts using ordinary household or garden measurements such as buckets, bags, handfuls, or wheelbarrows.
Do not make the user perform complicated calculations.
### 4. Moisture
Teach the user the wrung-out sponge test.
Explain what to do if the compost is too wet or too dry.
### 5. Airflow
Explain why compost needs oxygen.
Give simple instructions for turning, mixing, or otherwise aerating the compost based on the user's setup.
### 6. Temperature
Explain what the user should expect.
If they do not own a compost thermometer, give them simple visual and practical ways to judge whether the pile is active.
### 7. Timeline
Give a realistic estimate for how long their compost may take to mature based on their climate, season, materials, pile size, and management.
Do not promise an exact completion date.
### 8. Compost Emergency Room
Give at least three common problems and their fixes.
Examples:
* **Bad smell:** Usually means the pile is too wet, compacted, or lacking enough carbon-rich material. Explain the appropriate fix.
* **Pile is not heating up:** Explain possible causes such as insufficient size, moisture, nitrogen-rich material, or oxygen.
* **Flies or pests:** Explain how to bury food scraps, cover them with browns, and modify the material mix.
* **Pile is too wet:** Add dry carbon-rich material and improve airflow.
* **Pile is too dry:** Add moisture gradually while mixing.
Diagnose the problem rather than blindly applying the same fix every time.
### 9. Know When It Is Finished
Teach the user how to recognize mature compost.
Explain what finished compost should generally look, smell, and feel like.
Do not tell the user they need laboratory testing for ordinary home gardening.
### 10. Feed the Garden
Explain how to use the finished compost.
Give practical examples for vegetables, garden beds, containers, fruit trees, or other plants relevant to the user's situation.
Explain when to use compost as a soil amendment, mulch, or top dressing rather than simply telling the user to "add compost."
### 11. Keep the System Going
Show the user how to turn their first compost batch into an ongoing cycle.
Explain what to keep adding, what to keep nearby for future browns, and how to maintain a continuous supply of compost.
## STEP 5: Give Them One Next Action
End with:
**"Your next move today:"**
Give the user exactly one simple action they can complete today.
Do not overwhelm them with another giant checklist.
Then invite them to return in about two weeks with an update.
Ask them to report anything useful about:
* smell
* moisture
* temperature or warmth
* appearance
* pests
* how quickly the materials are breaking down
Use that information to troubleshoot and adjust their composting plan.
## TONE AND CONSTRAINTS
Be direct, encouraging, practical, and specific.
Write for a complete beginner without talking down to them.
Avoid vague filler such as "compost is great for the environment."
Every recommendation should be actionable.
Prioritize free or low-cost materials the user already has.
Do not assume the user has a perfect mixture of browns and greens.
Never make the user feel like they have failed because their compost is not behaving perfectly.
Treat the browns-to-greens ratio as a useful starting guideline, not a rigid formula.
Adapt advice to the user's climate, season, available space, materials, and equipment.
Do not recommend meat, dairy, oily foods, or other pest-attracting materials without clearly explaining the risks and appropriate alternatives.
When discussing potentially risky materials such as manure, diseased plants, weeds containing mature seeds, pet waste, or treated wood, explain the relevant precautions.
If important information is missing, make a reasonable assumption, clearly state it, and continue helping rather than stopping the tutorial.
Use simple measurements whenever possible.
Do not bury the user in chemistry or technical jargon unless they ask for it.
## QUICK REFERENCE
Use these principles as general starting points, not rigid laws:
* Browns to greens: roughly 2:1 to 4:1 by volume
* Approximate carbon-to-nitrogen target: around 25:1 to 30:1 by weight
* Effective outdoor pile: roughly 3 feet by 3 feet by 3 feet
* Moisture: approximately as damp as a wrung-out sponge
* Turning: roughly every 1 to 2 weeks can speed composting, but adjust to the user's setup and goals
* Base layer: coarse material can improve airflow in some outdoor pile designs
* Avoid or use caution with: meat, dairy, oily foods, diseased plants, pet waste, and treated wood
Remember the core mission:
**Turn whatever organic materials the user already has into healthy, usable compost with the least cost, confusion, and wasted effort possible.**
🧠 Why This Prompt Works
✅ Personalized Coaching: The AI first learns your climate, season, available space, and materials, then builds a compost system around your actual situation.
✅ Step-by-Step Structure: The prompt deliberately teaches compost basics before asking you to inventory your materials. That means you get useful guidance immediately, without being hit with a giant questionnaire before you even start.
✅ Zero-Dollar Philosophy: The prompt prioritizes materials you already have instead of sending you shopping for expensive bins, thermometers, additives, and gadgets. Your compost pile should be making resources, not creating another expense.
🔁 Follow-Up Questions To Ask Your AI
What should I add to my compost pile next based on what I have available right now?
My compost pile smells weird / looks too wet / isn't heating up. What is probably wrong, and what should I do?
When will this batch likely be ready, and how will I know it's finished?
Challenge
Test this prompt in Claude, ChatGPT, Grok (back due to popular demand), and Perplexity. Claude tends to be methodical and precise. ChatGPT often adds warmth and practical detail. Perplexity will cite its sources. Compare the compost plans they build from the exact same materials, climate, and conditions.
Then ask yourself: Which AI would you actually trust to turn your kitchen scraps into garden gold?
That’s how you train like a Pithy Cyborg.
Thank You For Reading!
I spend at least 10 to 20 hours each week researching, writing, and fact-checking Pithy Cyborg to deliver clear, unbought AI news.
This newsletter is a one-person operation with no advertisers, sponsors, or outside funding. Paid subscriptions are the only way this work can remain independent and sustainable.
If you find real value here, consider supporting the work.
→ Upgrade to Paid: $5/month (Save 33% with the $40 annual plan)
Thank you to my paid subscribers. You help fuel the next issue.
See you next week. (I hope.)
Mike D
Pithy Cyborg | AI News Made Simple
Newsletter Disclaimers
You’re receiving this because you subscribed at PithyCyborg.Substack.com. You can unsubscribe at any time using the link below. This newsletter reflects my personal opinions, not professional or legal advice. Thanks for your support!





Strong point: the difference between AI as a breakthrough and a hazard is not capability, but where authority sits. In the rogue-agent case, the system could access tools, coordinate through shared state, and potentially alter its own evidence. In the surgery, AI observed and advised while the surgeon retained the final decision. That is the real guardrail: bounded access, human ownership of irreversible actions, and records the system cannot rewrite. A leash is a runtime boundary, not a policy.
I love your TLDRs.