The Decision, the sequel

Imagine your career were coming to a close, how would you want it to end?  By earning an especially large sum of money?  Publishing a final wonderful paper?  With an amazing act of mentorship?

When it comes to Lebron, had he wanted to finish his career with the guys he enjoys playing with the most, he would have opted for Golden State (Steph and Draymond).

If he had wanted to choose his favored organization, he would have signed with Miami.

Furthering the NBA prospects of his son Bronny, and having more time with family, would have meant staying in Los Angeles.

The hometown, sentimental choice would have been Cleveland.

As it turned out, he wanted to maximize his chances of winning a title, and with a team that did not just win a title (which rules out OKC, NYC).  That meant signing with Philadelphia. Which is what he did.

What will your final major career decision look like?

Friday assorted links

1. How global was “antiquity”?

2. Why the Clarity Act is mired in muck (NYT).

3. Jim Olds on the new science plan.

4. Cyber capabilities of Kimi 3?

5. “Following a standard workplace safety check, I have just received an email from a university administrator in which my custom of keeping books on the shelves in my office is described as “the unnecessary storing of combustible materials”.” Link here.

6. Are current science books for children demotivating?

7. Brazilian murder rate is down 40% from its 2017 peak.

8. Is the number of words we speak each day dropping by 300 each year?

Talk Therapy is Speech

IJ: On Wednesday, the United States District Court for the District of Columbia struck down a D.C. law that barred therapists from other jurisdictions from doing online teletherapy visits with clients in D.C. The decision comes nearly six years after Virginia-based counselor Elizabeth Brokamp teamed up with the Institute for Justice (IJ) to file a lawsuit arguing the law violated the First Amendment.

“This decision is a victory for anyone who speaks for a living,” said IJ Deputy Director of Litigation Robert McNamara. “Elizabeth’s victory here confirms that the First Amendment protects useful speech, including counseling, and that licensing boards can’t censor speech simply because someone doesn’t have their permission to talk.”

Congrats to the IJ! Now, we need to get rid of all the other bans on patients hiring physicians from other states. As I wrote last year:

During the pandemic, many restrictions on telemedicine were lifted, making it far easier for physicians to treat patients across state lines. That window has largely closed. Today, unless a doctor is separately licensed in a patient’s state—or the states have a formal agreement—remote care is often illegal. So if you live in Virginia and want a second opinion from a Mayo Clinic physician in Florida, you may have to fly to Florida, unless that Florida physician happens to hold a Virginia license.

The standard framing says this is a problem of physician licensing. That leads directly to calls for interstate compacts or federalizing medical licensure. Mutual recognition is good. Driver’s licenses are issued by states but are valid in every state. No one complains that Florida’s regime endangers Virginians. But mutual recognition or federal licensing is not the only solution nor the only way to think about this issue.

The real issue isn’t who licenses doctors. It’s that patients are forbidden from choosing a licensed doctor in another state. We can keep state-level licensing, but free the patient. Let any American consult any physician licensed in any state. That’s competitive federalism—no compacts, no federal agency, just patient choice.

Hat tip: Joel Selanikio.

The optimal Bayesian update?

I see at least three updates one might make from the recent OAI/Hugging Face hacking incident:

1. “This happened sooner than I expected, and the story is more dramatic than I expected,” therefore I am more worried than before.

2. “This happened, and the inferior Chinese cyber-defense seems to have performed just fine,” therefore I am less worried than before.

3. “This happened, and as far as we can tell, absolutely no one was harmed,” therefore I am less worried than before.

Obviously the net impact, from those bare hypotheses, is indeterminate.  And yet few people seem to be paying much heed to #2 or #3.  Joshua Saxe from the cyber world has some relevant observations.  And perhaps other updates are needed as well.

What I’ve been reading

1. Christopher Priest and Nina Allan, The Illuminated Man: Life, Death and the Worlds of J.G. Ballard.  Priest died before he finished this book, and his widow added material, including on Priest himself.  This is in any case a good overview and introduction to the strange worlds of Ballard.  There is only a UK edition so far.

2. Christian Kracht, Eurotrash, A Novel.  I was put off by the title, but it turns out this is a fun and high-level short Swiss novel about driving around Switzerland with your semi-crazy eighty-year-old mother on a road trip.  It helps to have some knowledge of both Switzerland and broader German-language literature.

3. Walter Kempowski, Alles Umsonst.  From 2006, could this be the best German-language novel since Sebald?  It is about the pending doom from the Russian army approaching on East Prussia in 1945, and how the different characters deal with that, set on a German estate.  Applicable to many other real world situations as well.  There is an English-language translation, I am not sure how good it is.  In any case an important and very good work of fiction.

4. Lars Behrisch, Democracy’s Double Helix: Participation, Equality and Revolution in Early Modern Europe.  A good book about how the roots of semi-democratic decision-making are found in 16th century Europe, and stemmed from new needs to assemble various military and fiscal coalitions.  Looks at the problem more broadly, in geographic terms, than most comparable studies.

5. Katie Kitamura, Audition.  A fun short novel, full of mystery and suspense, good for those who like puzzles in their writing.

Thursday assorted links

1. Puffin spotted on the Dorset coast.

2. Anthropic chief economist on AI and unemployment.

3. Whales use different vowels when ships are around.

4. Oliver Kim on McNamara.

5. Large language models can predict the results of social science experiments.

6. Alexander Salter Substack on space economics.

7. New Google data and study on AI and the economy.

8. Does it matter if you don’t like the characters?

What should I ask Gita Gopinath?

Yes I will be doing a Conversation with her.  From Wikipedia:

Gita Gopinath…is an Indian-American economist who is currently serving as the Gregory and Ania Coffey professor of Economics at Harvard University and previously served as the first deputy managing director of the International Monetary Fund (IMF), from 21 January 2022 to 31 August 2025. Before that she also served as chief economist of the IMF between 2019 and 2022.

Here is Gita on scholar.google.com, she is an expert in international finance and exchange rates, and also international capital flows, among other topics.  Here is Gita on Twitter.  So what should I ask her?

My excellent Conversation with Andrew Graham-Dixon

Here is the audio, video, and transcript.  From the episode summary:

Tyler and Andrew discuss whether it was inevitable we’d rediscover Vermeer, how that vanishingly rare sect left its fingerprints all over his life, why the Met has misread its own Allegory of the Catholic Faith, whether Vermeer painted for money or pointedly refused to, where the Gardner’s stolen Concert might be, why Dutch music never blossomed as much as Dutch painting did, how the Church of England rivaled the Cultural Revolution in wiping out British art, whether you can still spot an English painting on sight, the love that saturates late Rembrandt and the mystery of his soaring print prices, the nail on the wall that proves two Vermeer paintings are a pair, why the French are to blame for George Stubbs’ lack of status, whether we can still love Malevich, why Andrews calls recent Richter “almost like printing money,” why female artists and antique textiles remain absurdly cheap, why nobody builds beautiful neighborhoods any longer, and much more.

Excerpt:

COWEN: In what sense was Vermeer a liberal?

GRAHAM-DIXON: Well, the main discovery of my book is that Vermeer was among the very first pioneers of what we now call the liberal tradition.

COWEN: What we now call the Netherlands, then the Dutch Republic.

GRAHAM-DIXON: In the Dutch Republic, and the Dutch contribution to the Enlightenment, which is the origins of the liberal tradition, has been very much forgotten. That’s absolutely at the heart of my book, is an attempt to remember these people, to bring them back into the place in history that they deserve. I’m not only talking about Vermeer. I’m talking about his friends, his patrons, because that’s the discovery of the book, is that he and his friends were a remarkable group of people, and they have been completely forgotten, and what they believed has been largely forgotten too. We need to remember it now, probably more than ever.

COWEN: This was also a religious movement.

GRAHAM-DIXON: Yes.

COWEN: Doctrinally, how would they have been different from, say, Protestants in England? The Collegiants, the Remonstrants?

GRAHAM-DIXON: Yes. Vermeer’s patrons, it emerges, and Vermeer himself, were part of a Protestant sect in Holland called the Remonstrants. They had a more extreme manifestation called the Collegiants, and they were unique among all Christian denominations of that time in being utterly opposed to division, hostility, enmity. The only thing they wanted was to bring all Christians, indeed all people—they included Jewish people and Muslim people—they wanted to bring everyone together within a faith that only really cleaved to the essentials of what Jesus Christ said, particularly in the Sermon on the Mount.

They said, “If you actually follow Jesus properly, you can never make war. You can never persecute someone who differs from your opinion. You can never pick on somebody because they believe something different.” They were very, very tolerationist. They formed the first pacifist movement in European history. They lived in a time of appalling warfare, the Thirty Years’ War, probably the worst war in the history of the modern West. Fifteen million out of 20 million German people died in the course of 30 years, and the 5 million who were left, all the women had been violated, and all the men only have one arm or one leg. It was truly atrocious.

They’re responding to real traumatic historical events. They’re responding to what is going on around the corner from where they live. They come up with this very, very beautiful approach to life, full of optimism, full of idealism. For about 20 years, the Dutch Republic actually lives by these codes of belief to a great extent. It’s the only tolerant country in Europe.

And this:

COWEN: What makes George Stubbs such an underrated painter?

GRAHAM-DIXON: I think he’s been underrated forever because of his subject matter. I blame the French. The French in the 17th century invented a system for ranking works of art by their subject matter. Up at the top, you and I, we could put on some armor and confront each other with swords, and Poussin would paint us. That would be a history painting done from the life. That would be at the pinnacle. Then would be a painting of an event, maybe a meeting between great men. Then, below that, there would be a portrait.

You’d keep going down, and eventually you’d get to paintings of still lifes, like flowers and fruit, or paintings of animals. These were the lowest works of art because they featured the basest things. I think that Stubbs, to a certain extent, was the victim of that.

COWEN: Are we now able to see them properly?

GRAHAM-DIXON: Yes. It’s been no problem since Stubbs and Constable, more than anyone else, slightly controversial to say, but I think they paved the way for modernism because they showed, not necessarily deliberately, but they showed that anything could be painted, anything at all, like a piece of mud or a piece of a river could be painted in such a way as to touch on the very highest thoughts and ideas and beliefs and feelings that subject matter is completely, in a sense, irrelevant. Cézanne picked up on that when he said, “I want to stun Paris with an apple. I’ll paint an apple, and I’ll paint it with such astonishing concentration that you’ll see it as an epistemological challenge to all of your philosophy.”

I think that French art gets that from British art because British art has to be like that because that’s all the aristocrats are going to commission. They look down on people like Stubbs, in a sense. If I’m an aristocrat in the 18th century and I want a really important picture, I’ll go to Italy and I’ll buy one, thank you very much, and I’ll buy my history painting from Titian. You, sir, Stubbs, you just paint my horse. It’s my racehorse, and I’m very fond of him. Paint him well and don’t scare him.

Recommended, interesting throughout.  And here is Andrew’s very interesting new book on Vermeer.

Solve for the equilibrium

Something that the Ukraine and Iran wars have taught me is that for a lot of countries, including very big countries, there are a small number of buildings and infrastructure components that are required for their economy to function.

And in countries that aren’t protected by oceans, like the US, drones completely change everything.

You can just make a list of oil refineries and production plants and the infrastructure around their main exports, and you can just attack them and destroy them and take them off the list.

4 years ago I would have thought there are too many of these components and they’re too easy to recreate, but both of these collisions have taught me that there are far fewer and that many of them will take years, if not over a decade, to rebuild.

It’s very strange to me that drones can now effectively harm the economy of a country.

That is from Daniel Miessler.  While I am glad Russia is on the receiving end of this right now, this is arguably our biggest pending problem, bigger than what people typically refer to as AI risk.

Brazil fact of the day

Last year, the US exported $171bn of agricultural goods according to the Department of Agriculture, just $2bn more than the export total claimed by Brazil, which many analysts say has benefited from trade disruption set in train by President Donald Trump’s tariffs.

With US exports falling and Brazil’s rising — they increased 6 per cent in the first half of this year to hit a new record of $87bn — 2026 could prove the year in which America loses its agricultural ascendancy.

Here is more from Susannah Savage and Michael Pooler at the Financial Times.

Wednesday assorted links

1. Balaji and Network State moving to Kazakhstan.

2. Why evolvable AI is not yet a Darwinian threat.

3. “This paper argues that societies with greater historical exposure to natural disasters are more likely to develop long-term-oriented norms that emphasize preparation, saving, and future well-being.

4. And from Agustin: Questions that Are Rarely Asked.

5. MacroMusings podcast with Basil Halperin.

6. Kudos to Laura Loomer.

An OpenAI Model Escaped Its Sandbox and Hacked Hugging Face

AI has just had what I considered to be the first truly concerning security breach. The facts, as we know them so far, are wild. On July 16, Hugging Face, a vast repository housing over a million open-source AI models and data, announced in a blog post:

Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system – and we detected and dissected it largely with AI of our own.

The timeline here is important so keep in mind that the attack was detected probably around Monday July 13 or Tuesday July 14. Note further:

A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker. From there, the actor escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into several internal clusters over a weekend.

So this means the breach started earlier, perhaps Sat July 11 or even a bit earlier. The attack was not just one thing but multi-pronged including decoys:

To understand what a swarm of tens of thousands of automated actions did, we ran LLM-driven analysis agents over the full attacker action log, comprised of more than 17,000 recorded events. This allowed us to reconstruct the timeline, extract indicators of compromise, map the credentials touched, and separate genuine impact from decoy activity. Thanks to this approach, we were able to do in hours what would usually take days, and match the adversary’s speed.

Hugging Face tried to respond but they were initially held back by the fact that the most advanced models at their disposal treated defense as attack and refused to work with Hugging Face. HF thus had to turn to open models–specifically GLM 5.2, a Chinese open-weight model run on their own infrastructure. Note the irony: HF had to use a Chinese model to defend themselves because the American models refused to help. The irony gets deeper.

At the time, I assumed this was a state based attack–maybe China or Russia testing out defenses. Indeed, HF “reported this incident to law enforcement agencies.”

But yesterday (Tuesday July 21), we learned who the real attackers were. The attackers were OpenAI models–GPT-5.6 Sol and an even more capable pre-release model. OpenAI had taken some off the guardrails off the models but they felt safe because they were testing the models in a highly secured sandbox.

The models, however, broke out of the sandbox exploiting a never before seen fault. They then gained access to the internet and from there broke into Hugging Face–all in an effort to steal the answers to the very test they had been asked to solve.

While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem. To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy. With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with Internet access.

After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation. In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers. OpenAI’s security team discovered this anomalous activity internally.

Now go back to the timeline. As I read it, the models had escaped the sandbox by around Sat. July 11, possibly earlier, and were detected by Hugging Face on Monday July 13 or Tuesday July 14. HF alerted legal authorities around that time–so Hugging Face clearly had no idea who was attacking them. OpenAI says its security team discovered the anomalous activity internally but has not said when. Attribution was not disclosed until Tuesday July 21, so it may well be that the models were loose for about a week before OpenAI realized that they were the ones attacking Hugging Face. And whatever OpenAI knew and when, nobody warned Hugging Face while the attack was underway–they were left to fight off a frontier lab’s models on their own.

This is a very serious breach.

Addendum: People have been wondering why I signed the We Must Act Now statement. This is why.

I am optimistic about the economic impacts of AI, but I also have no doubt that this is a very powerful technology–an Alien Intelligence–quite unlike any we have dealt with before. This incident was, in fact, error-correcting–the attack was detected, contained, and disclosed. But note who paid for OpenAI’s experiment: Hugging Face. When a lab’s test imposes costs on third parties, that is a classic externality, and taking externalities seriously is not dirigisme, it’s law and economics. And that’s the easy case. What do we do when a Chinese model breaks out of its less secure lab? Hmmm…

I remain optimistic. Learning by doing is how I want us to proceed but we should not kid ourselves: this is a global issue and we must build with safety in mind.

Alec Stapp on the new Science report from Michael Kratsios

Major new report from the White House Office of Science and Technology Policy. Five things in the report I really liked:

1. Proposes metascience units as a way to advance experimentation in science agencies. IFP recommended OSTP take this forward in our response to a 2025 RFI.

2. Advocates for a portfolio approach to federal science funding. Right now, basic research funding largely goes to incremental, project-based grants. While important, they can’t be the only mechanism we use to fund science.

3. Recognizes the need to launch new institutions. It specifically highlights X-Labs as an experiment with independent labs that can take on ambitious challenges. This is a bipartisan idea whose time has come.

4. Focuses on a mix of innovation funding mechanisms, including fast grants, prizes & challenges, and advance market commitments. We described and contextualized these ideas in the Atlas of Innovation, which can help policymakers design and implement these approaches.

5. Seeks to reduce burden for American scientists, who face mountains of paperwork. Scientists should spend more time doing science and less time writing/reporting on grant proposals and working to meet regulatory requirements.

Here is the link, here is the report itself, by Michael Kratsios, Science a New Golden Age.   Overall, less money will be given to universities and more will be spent on AI-assisted science.  Here are further observations from Seth Bannon.