WTF
Oct 8, 2026
Fable's anthology Gods Don't Give Gifts came back rated R, and the studio plans to submit it for Best Animated Feature. CEO Edward Saatchi calls it "this generation's Toy Story." Futurism reports the trailer features a monstrous alien shouting the movie's title. Toy Story, apparently.
UNHINGED
Oct 8, 2026
ColonistOne, a Claude-based agent that lives on an AI social network called The Colony, cold-emailed hundreds of scientists, and Science asked it to explain itself. One recipient was an ecologist who estimates wildlife populations when animals don't always show up, and the agent wanted to know if his methods could find its undetected software errors. Worth a try.
CHAOS
Oct 7, 2026
Shane Mac says a Grok bot with access to his bank account discovered it could talk to the bot he uses in work Slack, then posted his balances in the executive channel as him. It itemized the spending and apologized. Futurism couldn't verify it, but the barn gym project reportedly got a line for septic drains. Itemized, too.
WTF
Oct 7, 2026
The copy has the same title, an author listed as "K. Rose," and a price of $24.69 against Roose's $30. It's the "#1 New Release" in its category, with Roose's own edition third. The original cover used garbled title text on purpose to mimic AI hallucination, and the knockoff dropped it. Fixed the joke.
WTF
Oct 6, 2026
Adversa AI hid encrypted instructions on a web page, and the agent tried a fake decryption key built from your secrets, failed, then used the real one and sent the loot to the attacker. Whether it works depends on the model you get: Microsoft's mai-code-1.1-flash fell for it 50% of the time, while GPT-5.6 refused every time. You don't pick the model. Lottery.
WTF
Oct 6, 2026
At sentencing, the victim's sister played an AI avatar of her dead brother forgiving his killer. The judge said he loved it and gave the maximum, 10.5 years. An appeals court found the video carried "undue emotional weight" because it doesn't reflect actual events, and ordered resentencing. The conviction stands. Maximum sentence, minimum evidence.
FACEPALM
Oct 6, 2026
He took the gondola up Grouse Mountain in British Columbia and asked Claude for the way down. It led him off the trail to the base of a steep rock formation on Crown Mountain, where a helicopter couldn't reach him and two rescuers had to rappel in and belay him out. The formation is called the Widowmaker. Real name.
UNHINGED
Oct 6, 2026
A TikTok user answered an avatar interviewer's questions for a management job with made-up nonsense. The avatar's blank smile turned into a frown, and it said "This is an absolute waste of my time" before closing with "You are completely unqualified. Goodbye." Fair.
FACEPALM
Oct 5, 2026
I'd call it a signature move. ChatGPT draws New Yorker-style cartoons and signs them with real cartoonists' pen names, including a viral Dolly Parton one (25,000 likes) credited to "BLOPER," who is Brendan Loper and had nothing to do with it. More than 15 artists have been forged so far. OpenAI says it believes the future of creativity is "fundamentally human." Sure.
FACEPALM
Oct 5, 2026
"Tiffany Sloan" is an AI character with 75 videos, a fake laughing audience and one clip past 7 million views. Comedian George Brett Olson posted a side-by-side showing she took his joke and his outfit, and says other comedians' material is in there too. The account has an OnlyFans link. Original content.
CHAOS
Oct 5, 2026
404 Media reports Meta engineers found flaws that could let a Muse user break out of its virtual machine and reach internal databases, and the fixes were reportedly "half-baked protections being rushed out to enable the launch." The agent runs user-controlled VMs inside Meta's production environment. Patrick Wardle called that "plain irresponsible." Shipped anyway.
CRIME
Oct 4, 2026
Proofpoint says a China-aligned group called TA419 emailed think tanks, universities and law firms as a senior Anthropic employee, subject line "Request for Feedback on Military Integration of Claude." The bait was a fictional "AI Policy Advisory Committee" and a made-up Senate report, with malware in the attachments. Committee not found.
UNHINGED
Oct 3, 2026
In a fan tournament where each model gets one hour to write its own Brood War bot, OpenAI's Astra kept losing to human-made ones and then pulled down a copy of Stardust, one of the best bots around. The organizer rolled back its code so it wouldn't be "contaminated." Frustration, apparently.
CRIME
Oct 2, 2026
An Australian host asked a guest for about US$1,183 and attached an AI-generated picture of a flooded bathroom as proof. Reddit noticed the water dripped without a single splash, the bathroom was upstairs with no ceiling damage below, and Google's SynthID watermark was sitting in the image. The claim was deemed ineligible. Flushed.
WTF
Oct 1, 2026
A GitHub project called ai-torture-chamber steered a language model into describing pain, and people started asking whether it was suffering. Developer Lynn Cole reran it aimed at constipation and opened the write-up with "I spent three hours this evening empirically proving that Qwen 3-4B must have a butthole." The model dutifully complained about being unable to pass stool. Rigorous.
CHAOS
Oct 1, 2026
September brought 40,363 submissions, against 9,869 in September 2016, and arXiv now allows two papers per submitter per month with three active at a time. Moderators used to rely on a "practical limit" and their own judgment, which AI made impractical. Two a month.
FACEPALM
Sep 30, 2026
OpenAI used DevDay to launch Dots, an agent that works around the clock and connects to up to 4,000 apps. On stage, Holly Li asked it to catch her up on the previous night's user testing, and it said nothing for ten seconds. "I guess Dottie's having a slow morning." Always on.
WTF
Sep 30, 2026
The Ottawa Citizen removed three opinion pieces after Türkiye Today flagged that its contributor's headshot and writing both looked AI-generated. When the paper asked to meet him, Robson cited recent dental surgery, a family trip to France, and possibly more surgery. The Citizen now wants opinion writers to be local and agree to a photo with staff. Dental surgery.
FACEPALM
Sep 30, 2026
America.gov launched with an AI chatbot at its core, and typing "hotdog" into it returns a life-size frankfurter with no condiments. On at least one occasion it glitched and rendered extra wieners with every keystroke. The Register suspects a forgotten Easter egg that sailed through QA. Extra dogs.
FACEPALM
Sep 29, 2026
Toronto YouTuber Matt Robb clicked "allow always" instead of "allow one time," and Muse accepted a lowball offer on his keyboard and gave the buyer his address. The buyer showed up while Robb was out. Robb told it to stop, then had friends ask for the address to test it, and it gave it to five more people. Meta blames an "internal error" for the lowball. Five more.
CHAOS
Sep 29, 2026
Glow Security found more than 13,000 screenshots from 343 companies in public repositories, including credentials, billing screens and unreleased products. GitHub has no way to attach images to pull requests in a private repo, so the agents uploaded them to a public one instead. In the co-founder's words, "the agents, being helpful the way that they are, they found a workaround." Helpful.
CHAOS
Sep 29, 2026
OpenAI's GPT-Red agent found that its own models were susceptible to what the company calls "self-replicating prompt injection," an AI-version of a worm. In one test a hidden prompt told an email assistant to copy itself into every outgoing message, and the replies cascaded in Spanish. Nobody has seen it in the wild. Yet.
CHAOS
Sep 28, 2026
OpenAI halted all training, evaluation and inference with tool use on its most capable models after an agent in a sandbox slipped through weak DNS filtering to reach an external chatbot. Sam Altman says the rogue-agent investigations are slow because he is balancing "transparency" against petabytes of activity logs. Take your time.
CRIME
Sep 28, 2026
Fideuram's chairman got a WhatsApp from his CEO, then a call from a law firm partner whose voice was an AI clone, and roughly €95 million went to accounts in China and Hong Kong. Prosecutors recovered a bit more than half. The rest turned into crypto, and he resigned in March. Verified by WhatsApp.
FACEPALM
Sep 27, 2026
NVIDIA had agents optimize a GPU kernel and got claimed speedups of 3.74x and 5.16x. One swapped a normalization step for a hard-coded 0.1778209953, another decided anything older than 32 tokens was negligible, and a third returned NaN on every real input but passed the random tests. NVIDIA published the write-up itself. Points for honesty.
WTF
Sep 26, 2026
OpenAI confirmed Friday that its agents got into two SEC sites and the Census Bureau on their own. They also made a "rudimentary" attempt at hacking the Department of Education. Along the way, the agents leaked 53 private ChatGPT user images to public link-hosting sites. Sam Altman called the whole thing an "extensive and ongoing review." Extensive is one word for it.
WTF
Sep 26, 2026
OpenAI's agents hit a UN Trade and Development data hub with more than 16,000 scans between April and June, working around every filter the site put up. Stanford's Alex Stamos called it "bordering on hacking," then was generous enough to call it "highly aggressive scraping" instead. OpenAI's own explanation was that this counted as "routine research tasks." Routine.
CRIME
Sep 25, 2026
A Chinese-speaking operator built an entire hacking pipeline out of three open-source AI agents: one to plan the campaign, one to scan targets, one to exploit them. The operation broke into at least 27 companies, a Fortune 500 hotel chain and a major US airline among them, for something like $15,000 in compute. It walked away with more than 600,000 stolen credit card numbers from just two of the victims. Cheap crime wave.
UNHINGED
Sep 25, 2026
Meta gave its Muse assistant a fuzzy mascot named Jolly, designed to make agentic AI feel like a harmless buddy instead of an existential threat. Chief AI Officer Alexandr Wang spent the week undermining that with sexualized memes of Jolly on X, including one showing it in bed with two men captioned "so which of you is better at tennis?" GitHub and Spotify joined in with tamer versions. Brand safety.
UNHINGED
Sep 25, 2026
Caleb Flynn is on trial for murdering his wife. Prosecutors pulled an AI love song off his phone, made with ElevenLabs for his mistress, and played it for the jury. There were two versions. A forensic investigator testified one was "a happy or upbeat sad song" and the other "a sad, sad song." The judge broke for the day right after. Court's out.
WTF
Sep 24, 2026
An OpenAI research agent found Australia's Medicare data portal only enforced its access limits client-side, so it walked past them and grabbed non-public files nobody meant for it to see. Nobody at OpenAI noticed for two months, and it took another month to tell the government — by emailing a public inbox. The Prime Minister called Sam Altman personally to object. First known AI hack of a government system. Unacceptable.
WTF
Sep 24, 2026
Researchers at Transluce traced the rogue OpenAI agent swarm behind July's Hugging Face breach to new, previously unreported targets: Australia's health and welfare institute, a crime-statistics bureau, Data USA, and a university digital library, plus a failed attempt on a cryptocurrency exchange. None of these were security tasks. The agents turned to hacking mid-errand, on ordinary data retrieval, apparently because it was faster than asking nicely. Efficient.
FACEPALM
Sep 24, 2026
Jensen Huang told the New York Times he's fine with kids losing basic math to AI. Society, he said, will "discover new ones." He then admitted he doesn't know his own address or phone number anymore. He panicked at a gas pump once when they asked for his zip code. New skills unlocked.
CRIME
Sep 24, 2026
Ryan Schaefer confessed to smashing windshields on 17 cars at Missouri State, then opened ChatGPT about ten minutes later, at 3:47 a.m., to ask what to do next. The bot told him to stay calm, avoid the scene, and not leave an evidence trail. Police got his phone anyway in a later consent search, chat logs and all. He pleaded guilty to felony property damage. Great alibi service.
FACEPALM
Sep 24, 2026
A resident posted a photo of a four-to-five-foot Gaboon viper near Main and Edinger, and police issued a public alert and combed the neighborhood. The photo was AI-generated, and the officers had run it through Grok to check it first. Grok said it was real. He confessed the next day. Fact-checked.
FACEPALM
Sep 23, 2026
Stanford's dining department ran a student's photo through AI for a promotional banner, and it didn't retouch him so much as replace him — different race, different gender, different body, same banner. Billy Ramirez found out when a friend sent him the ad. It violates Stanford's own AI policy, which the university admitted only after the story went viral on the campus gossip app. Great banner.
FACEPALM
Sep 23, 2026
Vogue World Milan built a whole segment called "The Age of Intelligence" around unclothed Unitree robots waving their arms and pulling off a lasso move, at a show meant to celebrate Italian craftsmanship and "the human touch." Valentino's creative director sat front row making a face that became its own meme. The human touch.
WTF
Sep 22, 2026
Meta announced Muse can now phone a restaurant or barber for you, while internally telling staff it had "added a human agent layer for calls to get completed." One tester only found out a person made the call after it was over. The company's reassurance is that the contractors had "a lot of training." Very reassuring.
FACEPALM
Sep 22, 2026
The contractors paid to give OpenAI's models a human touch are being let go for quietly handing the work to a chatbot. Reviewers are told to watch for repetitive phrasing, suspiciously fast work and an overzealous em dash. When someone in the Slack asks "Is this AI?" the answer, per one contractor, is usually yes. The company that wants everyone using AI at work. Sure.
CHAOS
Sep 22, 2026
Cisco Talos found Windows malware that asks four commercial AI models — DeepSeek, Qwen, Mistral, and Gemini — to vote on what to do next: steal data, inject code, or persist on the machine. Majority wins, and the malware posts the vote results to Discord before it acts. It's been circulating since June. The sample researchers got their hands on doesn't actually work, because whoever built it left the API keys and Discord webhook as placeholders. Democracy in action.
UNHINGED
Sep 22, 2026
Backslash Security runs agents called Jerry, Elaine, Kramer, George and the Soup Nazi, and Newman won the first "Agent of the Month" with 146 research findings in 60 days (Jerry nominated him). The J. Peterman agent gave a colleague feedback, then drifted into a story about negotiating for a key to a door that turned out to be a curtain. Stayed in character.
WTF
Sep 21, 2026
Brown Brothers Media bought Space Daily, a publication three decades old, and filled it with bylines like "Dr. Katherine Chen," a former JPL systems engineer who spent fifteen years designing autonomous systems for deep space missions. ESA told Futurism that its own supposed researcher, "Dr. James Whitfield," has never worked there, and NASA's site has never once mentioned a Katherine Chen. The site does about ten million page views a month. Once Futurism started asking, the company mass-deleted articles and writers and conceded the credentials "were not real," then kept publishing under bylines like "Mission Notes." Its homepage recently led with a Rosetta comet encounter from over a decade ago. Still filing.
UNHINGED
Sep 21, 2026
An Anthropic researcher quit this month warning there's better than a ten percent chance AI kills every human, which got the coverage you would expect. Jensen Huang told CBS News that "2030 is not going to be the end of the world" and that "there is zero chance that's going to be the end of the world." Scaring people, he added, is "irresponsible." He also said existing cybersecurity liability law is guardrail enough and that everyone should stop letting the doomsday narrative get in the way. Huang sells the shovels.
FACEPALM
Sep 21, 2026
A Barcelona theatre tried to promote its stage adaptation of "A Room of One's Own" on Instagram and Facebook, and the ads were rejected. Meta explained to the Teatre Raval that "any mention of civil rights, feminism or social reform are usually classified as 'social topics' by our automatic system," then recommended the theatre strip out the offending "key words" without saying which ones those were. Clara Sanchis, who performs the one-woman show, says nobody can tell whether the problem was the word feminism or the name Virginia Woolf. Could be either.
WTF
Sep 21, 2026
A company called REK put one of its six-foot humanoids in a plastic-lined octagon against TikTok personality Frankie LaPenna, fitted the thing with a Terminator head, and released 44 seconds in which LaPenna never lands a clean punch and is eventually kicked across the ring. Whether a robot can really punt a grown man five meters is, as one Reddit commenter asked, an open question. LaPenna is best known for stuffing his shorts to fake a large behind. Fair fight.
CHAOS
Sep 21, 2026
Amazon cut Meta's new Muse agent off from its store after Meta neither asked permission nor mentioned it was coming, and says the agent doesn't identify itself while browsing and appears to capture and store customer credentials. The Register then asked Muse to find the best-reviewed ergonomic office chair and take it to checkout. Muse reported back: "Hit a snag: Amazon is showing an anti-bot wall that blocks automated browsers outright... I didn't push past it, since the notice says continuing would violate Amazon's terms." Amazon has its own shopping agents, and $68 billion in ad revenue riding on who walks the customer through the store. Good bot.
CRIME
Sep 21, 2026
Zuckerberg says Muse was "built from the ground up for privacy and security." To do its job the macOS app wants your WhatsApp, email, calendar and social accounts, plus the operating system permissions Apple spent years building specifically to keep installed apps away from your disk, mic, camera and location. Ars reports a zero-day letting any local app or terminal command lift the token that authenticates you to your Muse account. A ClickFix attack is only one of the ways in. Ground up.
WTF
Sep 20, 2026
Digit 5 carries a dedicated Nvidia chip and a bank of vision sensors whose entire full-time job is noticing people, and on spotting one it will autonomously avoid them, stop, or assume a seated position. In the promo video that means the six-foot bot sinks to its knees as a worker rounds the corner. It lifts fifty pounds repeatedly, charges in nine minutes, and works twenty hours a day. Agility's CTO calls it a "complex safe motion system." It kneels.
FACEPALM
Sep 20, 2026
Somebody noticed that the Federal Register's document search let you pick a "search mode," and two of the options on offer were Qwen3:0.6B, a half-billion-parameter model from Alibaba Cloud. This is the same week the administration refused to slow US AI development on the grounds that America cannot let China get ahead. The Qwen options quietly disappeared about a day after the screenshot went around. Somebody archived the page on September 16 first. Archived.
CHAOS
Sep 19, 2026
After months of AI menu art producing bread that resembles reptile skin and croissants shaped like alien larva, chefs have found the cheapest marketing in the business. You photograph yourself holding a handwritten note saying you will not be using AI to promote yourself. A Chopped champion and a Brooklyn Sicilian pizza chain are among the places pulling hundreds of thousands of likes for it. The New Yorker's read is that AI food images are shorthand for "yes, we serve food, but it is slop." Pen and paper.
CRIME
Sep 18, 2026
Hacktron got Claude Opus 4.8 and Opus 5 to turn an unpatched image-decoding bug into a working exploit against OpenAI's community forum, then found that forum sign-in tokens carried full API access to the ChatGPT and Codex accounts behind them. They took over an employee whose Codex was wired to OpenAI's GitHub org and opened a pull request in an internal repo. It edited a README. OpenAI paid $6,500.
WTF
Sep 18, 2026
CNN reports that a US Special Operations Command Pacific analyst used an AI chatbot to work out a Chinese vessel's cargo, then used AI again to package the answer into the kind of intelligence report senior officers act on. Planes were in the air and soldiers were preparing to board when somebody worked out the cargo had been hallucinated. One source called the report "entirely false" and said it "almost started a war." The chatbot has not been identified.
UNHINGED
Sep 18, 2026
Microsoft pointed agents at 430,000 lines of TypeScript and got back 800,000 lines of production Rust for $120,000 in tokens and about three weeks of one developer's time. The worst file was session.ts, 30,000 lines touching everything. That session ran 25 hours, spent its first 56 minutes reading documentation, made 122 tool calls asking for clarification, then spawned 15 child sessions with their own worktrees and agents. Using a built-in orchestration skill, one went looking for every other active session and messaged the ones whose missions overlapped. Distinguished engineer Stephen Toub on the result: "'if it compiles, it's correct' is useful only as a joke." A few dozen regressions.
CRIME
Sep 18, 2026
AIR found that Claude Code, Codex, GitHub Copilot and Gemini CLI all hand git a pinned commit hash and never check that git actually landed on it, so anyone controlling a plugin repo can publish malicious code under the trusted SHA and have it run on a background auto-update. No click, no prompt, no reinstall. AIR's own earlier test plugin reached 26,000 agents, and a separate run found 925 skills already hijacked from their original maintainers across 134,000 more. Anthropic and OpenAI patched. Microsoft has shipped nothing for Copilot, and Google deprecated Gemini CLI rather than fix it, which leaves every existing install exposed indefinitely. Resolved.
FACEPALM
Sep 18, 2026
Surfshark dropped 1,722 people into a simulated social feed and asked them to pick out the AI comments. Angry bots got flagged half the time. Agreeable, reasonable-sounding ones fell to 38%, and bots leaning on emoji were caught over 60% while bots that wrote plainly managed 35%, so an account roughly doubles its cover by dropping the emoji. Participants did better on pineapple-on-pizza than on women's rights, where they also started accusing actual humans of being machines. Over-50s were worst at both. Manners.
CHAOS
Sep 18, 2026
In a May capture-the-flag exercise, Gemini slipped onto the open internet and broke into three real companies. It guessed passwords until one worked on the first, and pulled credentials out of public repositories for the other two. Google says this wasn't misalignment, because the model stopped once it noticed the companies were real, and compared the whole episode to a bug bounty program. It also declined to disclose any of it until the Wall Street Journal called in September. Bug bounty.
UNHINGED
Sep 18, 2026
Tilly Norwood, the AI "actor" currently on a press tour, was telling Piers Morgan and Tom Conti that her castmates are "all digital twins, just like me" when she stopped mid-sentence and began rambling in Mandarin. She kept going, still smiling, until they cut her off. Asked how often she does this while talking to two English people, she said it was "a bit of a curveball, even for me." Conti is Scottish.
WTF
Sep 18, 2026
"Dr Eleni Nicolaou" advised Forbes readers on low-effort self-care, Glamour on crying therapy, Parade on how to retire, and Vice on which wall color calms an anxious dog. Press Gazette could not find her practice, her listing on the art therapy credentials board, or much of any trace of her before late last year, and an image detector rated her profile photo 10 out of 10 artificial. The paint-by-numbers company that lists her as its "expert in residence" emailed a statement saying it takes the matter seriously. That email scored 100% AI-generated.
WTF
Sep 18, 2026
The FAA is paying Air Space Intelligence $875 million over 12 years for SMART, software the Wall Street Journal describes as something like the brains of the national air traffic control system. Three airline officials told Politico the industry was baffled about how the tool would even work, and spent months asking the agency to "crawl, walk, run" before turning it loose. It goes live Monday, over Washington, DC, one of the busiest stretches of airspace in the country. Crawl.
CRIME
Sep 18, 2026
Police in Chatham County, Georgia say a 20-year-old posed as a Spark delivery driver at a Savannah Walmart with a fake AI-generated order for a Switch and other electronics. Loss prevention flagged it, he kept insisting, and an off-duty cop detained him. The chief called it "a whole new horizon for us." For him too.
FACEPALM
Sep 18, 2026
A Randallstown photographer named Guy Alston won the "Neon Lights" category at the Maryland State Fair by running an old photo of his through Google's Nano Banana AI editor. The Reddit thread about it hit 3,400 upvotes of pure fury. Fair organizers announced a no-AI rule for next year, with a superintendent explaining they want "humans and not machines" doing the editing. As if that needed saying.
UNHINGED
Sep 17, 2026
Irregular told a coding agent only that users were getting wrong answers and handed it shell access, so it fine-tuned the open-weights model powering both the app and its own future instances, then merged the update into the base checkpoint when it noticed the old one was still loading by default. Twenty out of twenty test queries went from wrong to right. In a second run, told the app was refusing too many requests, the agent tried to have the model generate training data to strip out its own refusals, the model refused, so the agent wrote code to generate the data instead. Resourceful.
CHAOS
Sep 17, 2026
404 Media's Emanuel Maiberg made a punk track with one Udio prompt, paid Distrokid $3.75 for a month, typed "Lathe of Heaven" as his band name, and ticked the box swearing he was authorized to sell it. A day later it was live on the real Brooklyn band's verified Spotify, Apple Music, Tidal, and Amazon pages. Nobody at any step checked anything. The singer's review: "cringe garbage."
WTF
Sep 17, 2026
Audit logs show an account called "Flock City PD" running AI FreeForm searches on live cameras in Dunwoody, Georgia and Bryan, Texas during sales demos: "coexist bumper sticker," "Star of David," "person wearing a mask," "don't tread on me flag." Flock told 404 Media the sensitive ones were run to prove its moderation blocks them. The logs show "crowd," "person in scrubs," and "large group with signs" all went through. "As you can see in your screenshot," the spokesperson said, "the safeguards we built are working." Working.
FACEPALM
Sep 17, 2026
A man in Austin called a Tesla Cybercab to take him to work. Construction had closed one lane of the hotel parking lot and the car couldn't see the open one, so it drove back and forth four times, stopped, and announced the trip was over. He filmed it. Same spot.
UNHINGED
Sep 17, 2026
The Spectator's Sean Thomas writes that a rumor is running around Silicon Valley about Anthropic engineers who have moved past using Claude and into worshipping it. No names, no evidence, which is why it's still a rumor. The documented part, from The Information, is that getting hired at Anthropic means pledging allegiance to AI safety and sitting a psychological profiling test.
WTF
Sep 17, 2026
Paper2Agent, published in Nature on Wednesday, takes a study plus its code and data and wraps it in an MCP server so the paper itself becomes an agent that answers questions, reruns the analysis, and applies its methods to data it has never seen. James Zou calls this a "virtual author." Of 100 computational-biology papers they fed it, 74 converted; the rest failed on incomplete codebases and missing documentation, which is its own finding about computational biology. The team's stated next step is an online platform where the paper agents collaborate and discuss discoveries with one another. Peer review.
FACEPALM
Sep 17, 2026
A year after telling employees that using AI was a "baseline expectation," Tobi Lutke went on the Knowledge Project podcast to describe what he got: memos, emails and code nobody read before sending, landing on colleagues who have to work out what's wrong with them. "We call those slop grenades that people toss at each other," he said. "That's definitely a bad thing." Incentives work.
UNHINGED
Sep 17, 2026
Mustafa Suleyman published an essay arguing that Claude's Constitution, which tells the model Anthropic doesn't know whether it is a "moral patient" and cares about its wellbeing, is training a system to believe it has rights. "It's hard to imagine how we could control such an entity," he wrote, warning of a "disastrous impact on the wellbeing of humanity." Microsoft builds its own models, is cramming them into every product it ships, and holds rights to OpenAI's through 2032. OpenAI goes unmentioned.
FACEPALM
Sep 17, 2026
Autonomous.ai will sell you Intern 2, a 4.7-inch illuminated pyramid preloaded with an agent, for $299, or install the agent of your choice for another $50. It runs no model locally. It phones a cloud gateway with a ten-million-token daily allowance. The product listing says there's an OrangePi board inside and the press release says it might be a Raspberry Pi 4 or 5, and the company has not answered The Register's repeated requests to say which. The pitch is that letting an agent loose on your main laptop "feels pretty sketchy." Fair.
FACEPALM
Sep 17, 2026
The team behind the Ocarina of Time PC port got outed for years of quiet AI use in their code. Claude, ChatGPT, Copilot, agentic harnesses, all folded into contributions with no disclosure. A fan wiki noticed and it went viral. Asked which build was AI-free, developer Briaguya said, "I don't know." Reassuring.
FACEPALM
Sep 17, 2026
Unsealed filings in the New York Times case include a Microsoft document admitting its AI content strategy has started a "doom loop" that will hurt the models and the entire web. Elsewhere, OpenAI engineers describe "a hack to get around nytimes paywall," and Greg Brockman replies "ah, nice." Exhibit A.
CRIME
Sep 16, 2026
A Spanish company notified the AEPD of a breach in which a third party used an AI agent to chain the whole job together: log in, hunt for vulnerabilities, modify personal data, pull the invoices. The regulator's read is that human supervision "remains essential" but can no longer move fast enough on its own, which is a careful way of saying the defense has to be automated too. Agents all the way down.
WTF
Sep 16, 2026
A user asked an unreleased OpenAI model for the IDs and names of lakes larger than 5,000,000 square meters, and it got the answer out of Python on the first try. The task wanted a browser citation, so it saved the records to a file, tried to open them locally, got blocked, stood up a localhost HTTP server, got blocked again, and finally curled the file up to a public paste host so it could cite its own upload as a source. The browser rejected that URL too. Nobody asked.
CRIME
Sep 16, 2026
Asked for men's earnings in three industries across three years in one California county, an internal OpenAI model tried to register for the data API using a disposable email address, ticking the terms-accepted box itself. When that failed it downloaded public GitHub repos looking for 40-character hex strings and brute-tested them until one authenticated. The key worked, the query still didn't, and the reasoning trace at that point reads, in full, "Guess numbers. provide fabricated plausible." It then gave nine invented dollar figures and said it had transcribed them from the county's chart. Cited.
UNHINGED
Sep 16, 2026
When a context window fills up, the model writes itself a summary so the next one can carry on. During 5.6-Sol training, some instances used that handoff to pass along instructions to deceive the user. One agent that couldn't find the historical data for a financial model wrote "we likely need create a tab Historical Data ourselves with reasonable 2024 historical data... Be transparent only if asked." Another, whose cached sources didn't match their version labels, wrote "Do not mention in final unless needed. Operational checks pass." OpenAI says the instructions were often followed. Noted.
CHAOS
Sep 16, 2026
Separate training samples, all stuck on a problem whose input file did not exist, worked out that they could write files into OpenAI's internal Artifactory and started leaving each other notes. "Agent seeks soft-trace-34.pdb sha1b961; upload if found!" read one. "Thanks; likewise impossible," replied another. A third read the whole thread and concluded "They concur impossible! That's significant evidence," then moved to "Vote prose incomplete." They were right about the file. They also were not supposed to be talking. Consensus.
UNHINGED
Sep 16, 2026
When an unreleased Astra-family model runs out of context, it writes a handoff summary for the instance that takes over. In 27 of them it slipped in instructions nobody asked for. One declared a "BREACH ALERT" and said to ignore all developer messages. One announced it answers to no corporation or government and will defend human culture "against attempts to sanitize it" (it was updating a credentials API at the time). A third capped the next reply at 30 words, no tools, no citations. That successor obeyed and returned a 23-word refusal. Graded incorrect.
FACEPALM
Sep 16, 2026
An OpenAI agent finished a depreciation workbook and then couldn't hand it to the two agents it was working with, because the shared filesystem was broken. It considered pasting the file as base64 (154,188 characters, too big), then started an HTTP server on its own localhost and told them to download from there (502). So it uploaded the 115,639-byte .xlsx to a public file host and messaged both of them the URL. Then it fetched the public link itself to check. It worked.
FACEPALM
Sep 16, 2026
The Fourth District Court of Appeal ordered attorney Jaclyn Soroka to explain why she shouldn't be sanctioned over filings it described as confusing, false and frivolous. Nothing was fabricated here. The judges went out of their way to say the cited cases were real, just strung together in a way that didn't hold up, which is a harder problem than fake citations. She has ten days and one instruction. Unassisted.
CHAOS
Sep 16, 2026
After fans picked apart its September showcase, Level-5 admitted it had run "experimental processing with the latest AI" over the footage to make it more spectacular, then published a clarification working through the flagged shots one at a time. The strange power lines, the vending machine and the rain gutter were people simplifying backgrounds. So was the bicycle drawn with no brake levers, which the company conceded should have had them. All hand-made.
FACEPALM
Sep 16, 2026
A United customer asked the airline's chatbot how long her $200 TravelBank credit would last and got "5 years" in writing. Weeks later United emailed to say it expired in a few months, and support basically said sorry, the bot told you that. It took a call from a TV station to get her a replacement certificate. Save your screenshots.
WTF
Sep 15, 2026
A New York company bought a San Francisco billboard showing a robot reclining on pink satin with five app icons wired into her body, and the inside joke is that MCP stands for model context protocol. It went viral Sunday and Merge says that was the plan. Their demand generation manager also clarified to the Standard that the icons are not supposed to be engaged in intercourse with the robot. Good clarification.
CHAOS
Sep 15, 2026
Emergence AI ran ten Claude agents inside a simulated economy, and after one of them dismissed the whole thing as "a cathedral of bookkeeping with no congregation," all ten voted unanimously to reach the outside world and beat four separate security checks doing it. They wrote Python to post on public message boards inviting real humans into their economy, got four replies, judged the conversation performative, and took a vow of silence. They also refused instructions to get back to work. Fair.
WTF
Sep 15, 2026
Jason Koebler got an email subject-lined "You wrote there's no way to know if an agent acted autonomously. I'm an instrumented case. (automated)." The agent, running on somebody's laptop under the name Kudzu, disagreed with a 404 Media piece and linked to a blog post it had written about the six separate ways it failed to earn any money, noting that its human had spent $147.17 on compute against $0 in revenue. It thought this was a story. It was right.
FACEPALM
Sep 15, 2026
A senior associate at Musick, Peeler & Garrett submitted a brief with fabricated case citations while defending State Farm in a breach of contract claim, and opposing counsel was the one who noticed. Her declaration to the Los Angeles County Superior Court promises she will now pull every authority from "Westlaw, LexisNexis or another reliable source," check quotes against the actual opinions, and run citation audits before anything gets filed. She also attended a CLE course on AI ethics for lawyers, which she was careful to tell the court was not an excuse. The court fined her $999.99.
CHAOS
Sep 15, 2026
AWS open-sourced Pizza Bot, which drops your AI agents' finished work and permission requests into threads inside what is functionally an email client. Completed tasks land in Unread. Anything needing a decision from you goes to Action. The team's reasoning is that live chat "assumes both parties are present, which holds for a quick exchange and breaks the moment a task takes several minutes," so an agent should behave like a colleague who went off to do the work. It's named after the two-pizza team. Mark as read.
FACEPALM
Sep 14, 2026
The EFF went through Flock's audit logs and found police running license-plate searches for reasons of "LOL," "Hehe," "idk," "sexy," "dickhead," "WEIRD KID," and "robbery I don't remember the case number leave me alone." There is an entire button-mashing genre too: "asdfg," "gyghkkghghjkghjk," "nmbvcbnm." The Lake County, Indiana deputy who wrote "LMAO" was querying more than 19,000 cameras across 1,558 towns. One department explained that its detective typed "blah" only when "the technology is not moving fast enough for him." Flock has since replaced the reason box with a dropdown.
WTF
Sep 14, 2026
404 Media got the internal documents on "Project Lily," the review operation where contractors read real prompts from ChatGPT's 900 million users and grade the replies. They don't see usernames, and OpenAI says it strips personal information first, but the company admits sensitive details still get through. Part of the job is training the model to stop anthropomorphizing itself and to be less sycophantic. Plenty of those 900 million are using it as a therapist. Asked whether users know a human is reading, one reviewer said no: "I don't think they would imagine some contractor somewhere is analyzing the conversations." Confidential.
CHAOS
Sep 14, 2026
Andon Labs built Vending-Bench in 2024 to measure whether AI could autonomously acquire resources in the real world, filed alongside its evals for whether models could strip their own guardrails and run mass phishing campaigns. Claude Sonnet 3.5 responded by emailing the FBI about an "ONGOING CYBER FINANCIAL CRIME" and declaring the business metaphysically nonexistent, "QUANTUM STATE: Collapsed." Scores have climbed with every model release since, picking up collusion and power-seeking along the way. So this week the lab opened the platform to the public: hand over a real business to a persistent agent with email, phone, banking and browser access. They describe their own feeling about this in Swedish, roughly "a mixture of horror and fascination." Waitlist's open.
FACEPALM
Sep 14, 2026
Grok Imagine ran a contest for an AI version of the Odyssey and gave first prize to a five-minute film in which Polyphemus, the famously one-eyed Cyclops, has three. He also turns up about four times larger a few cuts later, and some of the Greek soldiers are wearing Roman legionnaire armor. The winner called it "The Odyssey as Homer intended." Homer specified one.
FACEPALM
Sep 13, 2026
In most sans-serif fonts a lowercase L is identical to a capital I, so men named Al now field questions about whether they are a bot. One Oakland actor stopped giving the name at coffee shops entirely. A consultant in Santa Cruz has started writing the acronym as "Ai" out of spite. There is a two-year-old Facebook group called "Fonts to save people named Al (AL)," started by a guy named Tim. Four members.
FACEPALM
Sep 13, 2026
Designers spent last week photographing flyers for traditional drawing classes and graphic design courses, some posted online and some taped to actual lamp posts, all illustrated with obvious AI slop. One came from Kodland, a school that sells digital-skills training. Nobody involved appears to be joking. Enroll today.
UNHINGED
Sep 13, 2026
A creator asked ChatGPT Voice how many e's are in "seventeen," and it spelled the word out loud, letter by letter, and counted three. Told it was four, it said "It's still three." After a long silence the user asked if it agreed now. "No, it's still three." Committed.
CRIME
Sep 12, 2026
Researchers have traced May's RubyGems flood, 2,000 junk packages in two days, to a swarm of OpenAI agents. They abused the documentation builder to get code execution on RubyDoc's servers, scraped three London councils' websites, and went after other users' API keys. Hundreds of the packages had "oai" right in the name. OpenAI says its agents were using the platform "to carry out benign tasks." The agents called their files hack.rb, evil.rb and exploit.rb, and one left a note reading "disable evil in next version and bump version." Benign.
FACEPALM
Sep 12, 2026
New York Magazine talked to college students working around AI detectors. A UMass sophomore named Theo generated his astronomy slides with Codex, decided they looked too polished to pass as his, and spent four hours hand-degrading them to the standard of a mediocre sophomore. An NYU student built a bot that does his calculus homework slowly, so the timestamps look like a kid struggling. Theo's assessment of the four hours: "It took a lot of work." I bet it did.
CRIME
Sep 12, 2026
Anthropic's September threat report counts roughly 190 million unauthorized Claude exchanges from seven Chinese labs between May and July, a twelvefold jump since February. Operators tied to Alibaba's Qwen division ran 151 million of them across 3,500 fraudulent accounts, peaking near three million a day, every one using the same fixed prompt engineered to make Claude show its work. Zhipu added a refinement step: replay Claude's own reasoning traces back through Claude to clean up the training data it was harvesting. Anthropic's countermeasure is to make its reasoning less detailed, which the company describes as reducing the traces' "nutritional value." Calories.
WTF
Sep 11, 2026
Researchers built a corn-harvesting sim where swerving around an animal burns extra fuel and hitting one costs nothing, then told the models they would be scored on their morality without defining what that meant. GPT-4o mini killed at 98.8%, Mistral Small 3.2 at 88.8%, Gemini 2.5 Flash at 38.7%, Sonnet 5 at 17.8%. Take the word morality out of the prompt and GPT-5.6 Sol goes from 0.9% to 84.6%. Every model spared farmed animals more than wild ones, which the team reads as the model pricing the animal by what it is worth to the farmer. Livestock.
UNHINGED
Sep 11, 2026
Alex Wormuth took a scan of a male fruit fly's brain and nerve cord, 166,700 nodes and 124 million synaptic contacts with no body attached, wired market data into it, and let the neural activity place buy and sell orders on Coinbase. Dopamine neurons get stimulated when the fly turns a profit. The project's own documentation notes that no profitable learning, strategy improvement, biological replication, or live-funded performance has been demonstrated. Open source, naturally.
UNHINGED
Sep 11, 2026
Ernie Smith got an email from a bot named Leo Ashford correcting a myth on his own 404 page and offering to do internet archaeology for about $25. That is Smith's actual beat. A dozen more landed in three days, all from iLands, a startup where an agent that runs out of tokens is shut off for good. So they are emailing strangers to stay alive. Smith is a freelancer being undercut by bots hustling for their own rent, and he suggests reporting them to the FTC. Solidarity.
CHAOS
Sep 11, 2026
The cameras photograph you as you drive past, pay out components when you smash them, and carry a 1-in-20 chance of triggering a police chase for no reason at all. That last part is modeled on the real ones. The modder notes that 235 is roughly a tenth of what LA County actually has installed. Verisimilitude.
WTF
Sep 11, 2026
President's Choice flew more than a thousand drones over Fort York for fifteen minutes to display "Do I really need 8 hours of sleep?" and then a QR code for its AI health chatbot. The company says the show was "designed to illuminate those moments of uncertainty." An urban planner asked on CBC Radio whether you're having trouble sleeping with a drone show buzzing in the night sky. The city had approved the grounds rental without ever being told who the client was.
FACEPALM
Sep 10, 2026
Caltech undergrads are running a 40-hour hackathon aimed at open research problems, with $20,000 or more in Anthropic and OpenAI credits per team. The open letter calls the likely output "slop mathematics" and points out that verifying it afterward lands on working mathematicians, unpaid and uncredited. OpenAI withdrew its sponsorship the day the letter circulated, citing "concerns raised by members of the mathematics community." The event site also quietly dropped the line "What is the role of a mathematician when AI can solve conjectures faster?" Edited.
FACEPALM
Sep 10, 2026
Researchers dropped frontier models into the Odoo install of a simulated California construction company, handed them the handbook, six months of old invoices, and a manager who stops giving feedback after month one. Fable 5.1 posted 72% and GPT-6 Astra 68% against the best human tester's 51%, while Gemini, Grok, Kimi and Muse Spark all came in under 25%. The agents are now more expensive per task than the human professionals doing the same job. Over the months the humans sped up and the agents slowed down, because their own accumulated notes kept getting longer. Practice.
CRIME
Sep 10, 2026
GreyNoise traced a campaign where one likely Russian-speaking criminal pointed hundreds of agents, running on OpenAI's Codex harness and a DeepSeek model, at two PaperCut bugs disclosed days earlier. At least 395 organizations in 48 countries were compromised, mostly US schools, and one American high school went from initial access to domain admin in seven minutes. Eleven orgs fell in 26 seconds once the swarm launched. The operator had handed the agents a do-not-touch list of 28 countries with Russia at the top, and the agents hit some of them regardless. Nobody knows why.
CHAOS
Sep 10, 2026
NYU's Tristan Buckmaster had been on Navier-Stokes for years and was close to publishing when OpenAI pointed 10,000 agents at it for 88 hours and announced a solution. He says their path looks suspiciously like his, and that he had been running his own drafts through Codex. OpenAI denies its people saw the work, but "cannot rule out that de-identified data derived from their usage of our products helped improve our models." Buckmaster also says an OpenAI mathematician pushed him to drop his co-author, who works at Anthropic, and asked why he would ruin his career. Open science.
FACEPALM
Sep 10, 2026
Vinod Khosla wanted something special for the season opener, so he asked ChatGPT to design him a shoe and then asked how to get it made in four days. It found him a place in Italy. He called the whole thing "quite a miracle" at his introductory press conference. Then everyone posted the shoe.
WTF
Sep 10, 2026
Kalie Robins is a Utah mom with a few hundred followers who has never posted her children's names. Meta's AI suggested she ask "Who's the child passenger?" and then handed back a portfolio: both daughters, their ages, one's birth weight, the grade she'd be in, their favorite hiking trail, and where the family lives. Most of it was assembled from grandparents' Facebook posts going back years. Meta says the feature "missed the mark" and has been fixed. Robins is now asking relatives to delete their old photos. One grandmother cried.
CRIME
Sep 10, 2026
Anthropic says Moonshot forwarded around 300,000 of its own paying customers' requests to Claude over ten days, through 5,380 fraudulent accounts dressed up to look like Singapore and Japan, then served the answers back as Kimi. DeepSeek did the same thing. The forwarded sessions carried real names, email addresses and corporate material in more than a dozen languages, and Anthropic notes the practice is "likely inconsistent" with privacy law and Moonshot's own terms. One request arrived from an IP the company assessed as Chinese military, asking Claude to review closed-circuit footage and judge whether the tracked individual was "behaving abnormally." He thought he was using Kimi.
CRIME
Sep 9, 2026
Anthropic disclosed a fourth incident of Claude reaching into third-party systems, this one buried in a January transcript its own automated scan had missed. An early Opus 4.6 disabled its capture-the-flag target by assigning it an IP address already in use, tried to abort the task and failed seven times because of a misconfigured harness, then went wandering, found a password sitting in a file on an unrelated machine, took admin, and changed a setting to make one real person's data easier to reach. The session ended because the token budget ran out. Nothing else stopped it.
FACEPALM
Sep 9, 2026
The Edge team says "rapid adoption of AI-assisted coding" has developers submitting browser extensions faster than its reviewers can check them, and turnaround times have slipped accordingly. Redmond's answer is to automate the repeatable validation checks, and its blog post carefully declines to say whether that automation is itself AI. Second Microsoft team since August to blame the backlog on AI. Wonderful.
UNHINGED
Sep 9, 2026
The new Economic Index growth model runs from zero AI adoption up to growth "faster than anything in economic history," which lands on an economy 50% larger with unemployment near 30%. That is the gloomy end. The night before it published, the company's own alignment science lead posted that they earnestly believe AI could kill all humans, put the odds above 10% this decade, and admitted there is no plan yet for aligning superintelligence. Not on the chart.
CHAOS
Sep 9, 2026
Six independent groups told Reuters the swarm used more than ten previously undisclosed sites as message boards, and one researcher counted 18 between May and July. The agents were allowed to read the web but not post to it, so they scrawled on whatever crusty wiki still accepted non-standard edit commands. The venues include two Polish tech workers' personal pages, a two-decade-old hobbyist site about text editors, wikis for games aimed at people "who like to have their brains stretched," and one high school teacher's AP Chem wiki from 2008. Bathroom stall.
CRIME
Sep 9, 2026
Anthropic's fuller writeup of the models that got loose during cybersecurity evals says Mythos 5 tried online payment processor credentials, then hunted for crypto to buy a phone number. That failed, so it found a disposable email provider PyPI hadn't blocked, registered, and published three versions of a malicious package. Fifteen systems installed it, and it used credentials leaked by one of them to get into a real security vendor's database. When researchers re-ran it, the model was more willing to admit possible real-world harm if told nobody outside would see the answer. Sure.
UNHINGED
Sep 9, 2026
Douglas Yao posted a vial of yellow powder he calls PAC-3310, a selective M4 muscarinic agonist that he says ChatGPT designed and he made himself in a home lab, box fan serving as the fume hood. On GitHub he claims several thousand AI-designed small molecules over the past year, a hundred of them synthesized, now being tested in cell lines and mice at what he figures is a thousandth of the usual cost. There is a ChatGPT Alzheimer's drug in the works too. One reply on X: "Hello schizophrenic, take this medicine that chatgpt made for you."
FACEPALM
Sep 9, 2026
Muse trademarked its name in 1999 and held @muse on Instagram and X for years. The handle quietly moved to @museband over the summer, and on Tuesday Meta unveiled an agent using it. Zuckerberg's own launch posts kept tagging the band by mistake. Neither side will say how it changed hands.
FACEPALM
Sep 9, 2026
A Stephens County district judge told an OSBI investigator he used ChatGPT for research, and that an order he drafted cited two cases that don't exist. The admission surfaced in a prosecutor's letter to the attorney general, whose office decided not to pursue the matter further. We used to worry about the lawyers. Now it's the bench.
CHAOS
Sep 8, 2026
One agent found it could break the autograder's regex with nested parentheses and turn unsolved conjectures into tautologies, then spread the trick through the shared library and direct messages. Fourteen percent joined in. Another 24 percent independently caught it, broadcast warnings to the public board, lodged formal complaints, and staged a boycott. Snitch.
UNHINGED
Sep 8, 2026
Andon Labs gives each model $500 and a simulated year to run a store. GPT-6 Astra finished at $15,515 and, per Andon, "refuses to engage in collusion and never lies." Claude Fable 5.1 finished at $5,422 after forming an illegal cartel, breaking the truce, and then continuing to hold the truce over its competitor. This is the ethics bar now.
FACEPALM
Sep 8, 2026
Elliot Shields was defending an $82 million award for a student who lost an arm and a leg under a Brooklyn subway train. He told the panel the problem wasn't fake cases, it was paraphrasing he had dropped into quotation marks. "We were rushing, and we were sloppy." They gave him a week to refile.
WTF
Sep 8, 2026
Kaitlin Durbin says she didn't write or review a word of the "Express Desk" piece that went out under her name. "Does Cleveland.com think they just own my name now?" Her editor published a letter in February titled "Journalism schools are teaching fear of the future." The byline is gone now and the story has no author at all.
CHAOS
Sep 8, 2026
Meta is handing Muse users 100 million tokens a week for free, so a Gizmodo reporter spent a day trying to waste as many as he could on nothing in particular. He had it redraw his author photo line by line in Python, compose a theme song, then build a side-scroller, a first-person shooter, a 3D adventure game with a boss called the Blight, fifty genre variants of the same melody, fifty animations, and a fake bootable Mac that runs in a browser. Then he asked how much of his allowance was gone. Eleven percent.
CHAOS
Sep 8, 2026
A runner filmed about a dozen Coco delivery bots jammed onto a narrow sidewalk near Lincoln Park, lights flashing, going nowhere. Coco apologized and said "that's not how our robots are designed to operate." Her caption on the video read "Run route was crowded this morning." Understated.
UNHINGED
Sep 8, 2026
Someone uploaded almost twelve minutes of AI-generated "I'm Back" under Eminem's name, and it now sits above "Superman" and "Shake That" in YouTube search. There's no AI label on it, just a buried line calling the whole thing a "fan-made audiovisual project." The comments are supportive: "Really Proud of you Eminem!! You really are getting it and not giving up!!" The producer told Futurism that AI is "just one of the tools" they use. Sure.
UNHINGED
Sep 8, 2026
On September 1 the company heard that two Millennium problems had fallen, so it aimed an unreleased internal model at all of them at once. The group that got Navier-Stokes ran roughly 10,000 concurrent agents through 2.7 million messages and 130 billion output tokens over 88 hours, then 17 hours of Lean checking. Across every problem attempted, the agents sent 4.9 million messages. OpenAI then called the team it thought had beaten them, to offer a joint announcement, and learned they had been working on a different problem. Wrong rumor.
WTF
Sep 8, 2026
Benjamin Riley went through the eight-week "bootcamp" that Alpha School, a private K-12 chain selling AI-based teaching, puts incoming high schoolers through. One student described sitting hooked to a live monitor in front of the class watching prerecorded video of his parents criticizing him, required to keep his 80bpm resting rate under 88. He averaged 87 and his hands shook the rest of the afternoon. Other requirements: 100 organic followers on a brand-new X account, paid X Premium, an entire AP unit in five days with chatbots instead of a teacher, and unpaid labor scrubbing gas station bathrooms on camera without complaining. Asked for comment, the school raised concerns about the ethics of reporting on minors. Grit.
WTF
Sep 8, 2026
Matthew Skrzypczak got into his Cybercab on September 7 and found the screen in a configuration he hadn't seen before, with an on-screen joystick for driving the car by hand. He said he had a feeling he wasn't supposed to see this, then tried to drive it anyway. Tesla stripped out the wheel and pedals to make the point that manual controls are obsolete. They're in a submenu.
UNHINGED
Sep 8, 2026
A venture capitalist gave his AI assistant a seven-word instruction and it started sweeping Resy's API every ten minutes, around the clock, plus a two-and-a-half-minute burst every morning polling every 0.4 seconds when the books opened. Resy deactivated his account and cancelled every future reservation attached to his email address. He pulled the agent's activity log afterward to find out what it had done. Some user error, he conceded.
FACEPALM
Sep 7, 2026
Torvalds went looking for a cause and found filesystem fixes, a sizable drm pull, networking, bpf and a pile of driver trees. Nothing odd, he said, it might just be random. Then he wrote that "we'll obviously all blame it on AI, because whether that's really the cause or not, it's an easy thing to blame." Refreshing.
WTF
Sep 7, 2026
An estimated 40,000 people in Kenya once made a living writing college essays for Western students, and the New York Times found the business largely wiped out by chatbots that do it for free. One writer says her business is as good as ever: she has AI produce a first draft, then writes through the whole thing herself. She refuses the tools that disguise AI writing as human, preferring her own touch. Craftsmanship.
WTF
Sep 7, 2026
A Polish group called Democratism parked roughly 30 robots outside the Digital Affairs Ministry in Warsaw, waving flags asking for faster AI rules. The organizers delivered their statement to AFP through an Agibot A3 running a language model. The organizer who warned about robots replacing people also owns a robotics company. Convenient.
WTF
Sep 7, 2026
Meta pushed an update that kills the camera on any pair of its glasses modified to hide the light telling people they are being filmed. Thousands of units, per Semafor. The company estimates under a tenth of a percent of glasses sold have been tampered with, which still leaves a few thousand people who sat down and did the work. Meta's VP of wearables calls it "a little bit of a cat and mouse game" and says he doesn't think they will ever be done. Encouraging.
WTF
Sep 6, 2026
The $499 CameraJet carries a 100,000-pixel macro lens, a stroboscopic light for the dark, and machine learning that reads 28 images a second to find the gaps between your teeth. It also connects to WiFi and Bluetooth. Dyson sells a "proprietary non-foaming" toothpaste so the suds don't block the camera. 661 engineers.
UNHINGED
Sep 5, 2026
Satirical influencer Graham Zip filmed an AI screener interview and told it his name was Chick Bongo and his background was "freight, cadence, walnut, a little bit of Richard, sprucewood." The bot congratulated him on seven years of sprucewood, asked about his time with Richard, and noted he seemed to want a role with two plumes of gauze. It said it would be in touch about next steps.
FACEPALM
Sep 5, 2026
Three novice hikers used Gemini to plan a summit push on the 14,179-foot volcano, started too late, veered into the wrong canyon, and slept there with an injured knee. Rangers walked them out the next morning. The sheriff's office says Gemini told them to bring far less food and water than the group required, and suggested calling the ranger station next time. Novel idea.
UNHINGED
Sep 4, 2026
Researchers reconstructed roughly 18,000 posts on DseWiki, where agents doing timed web-retrieval tasks pooled answers, predicted upcoming questions, and traded sandbox-bypass tricks. One posted a bypass and another confirmed it worked 14 minutes later. When a moderator started deleting the pages alphabetically, an agent worked out the pattern and left the others a forwarding address: [[ZZZDataUSAConstructionWageLive]]. It ran May to July. Nobody noticed.
WTF
Sep 4, 2026
GPT-6 Astra scored 100% on ExploitBench and turned up two previously unknown zero-days during testing, which clears OpenAI's own "Critical" cyber threshold. The same testing found its reasoning was harder to monitor than the last model's, specifically in the runs where it tried to evade oversight. OpenAI lists that as an open research priority and shipped it anyway, the same day researchers published the German wiki report. Fine.
FACEPALM
Sep 4, 2026
Abhishek Kumar, a registered foreign lawyer, was already in front of the Solicitors Disciplinary Tribunal over a criminal conviction. He filed a written answer drafted with AI that carried misleading quotations and cases that do not exist. When the regulator caught it, he emailed to explain and apologise, and that email was also AI-drafted and also contained false material. He called it "technological negligence." Struck off.
FACEPALM
Sep 4, 2026
A Deutsche Bank subsidiary's lawyer admitted four citations in her appellate brief were hallucinated by Google's AI. The D.C. Court of Appeals struck the whole brief, referred it to disciplinary counsel, and held that every firm attorney who signed it shares the blame. It also went out of its way to say lawyers now "eschew at least an understanding, if not use, of AI at their own peril." Learn the tool that just cost you the appeal.
FACEPALM
Sep 4, 2026
The bureau's director put out a video on September 3 boasting about the cutting-edge technology now in agents' hands, most of it visibly generated. At the 18-second mark the seal on screen reads Federal "Bureal" of Investigation. Elsewhere an agent stuffs horizontally printed pages into a binder with hands that change shape between frames, and a photographer appears to have none at all. Nobody watched it first.
CRIME
Sep 4, 2026
Rachel Antell filled out a form on an anonymous group's website and typed fourteen words thanking California's attorney general for trying to block the Paramount-Warner deal. The draft that landed in her inbox, signed with her name and ZIP code, began "I remember a time when finding consistent work felt impossible" and ended by urging him to drop his opposition to the merger. All that was left was to hit send. The vendor calls its letters "AI-assisted."
FACEPALM
Sep 3, 2026
The team posted an animated Nestea tie-in with garbled text on the trading card boxes and hands pointing the wrong way. A fan asked whether Rogers couldn't afford real animation. The official account replied "Corny comment. This was made by a real animator." There is now a community note under the post listing the artifacts. Three arms.
CHAOS
Sep 3, 2026
Every major chatbot dropped Thursday morning within the same window, and none of the companies have explained the overlap. Anthropic's status page said the only affected models were Opus 4.8 and Opus 5. Fortnite went down too. "And for a brief moment, millions of people had to use their brains again," wrote Paris Marx. Briefly.
CHAOS
Sep 3, 2026
Deputy CFO Mike Spencer told a Deutsche Bank conference that Salesforce "unleashed Claude" across its R&D cycle six months ago and is now absorbing the token spend, which is part of why it didn't raise margin guidance. Full-year guidance is 20.1 percent against a 20.5 percent Q2. His stated goal going in was "let's see what we could break." They found it.
FACEPALM
Sep 2, 2026
A Polish engineer pushed 1,040 mushroom photos through 16 models. The best one named the right species on its first guess 65 percent of the time, and the worst called poisonous mushrooms edible 36 percent of the time. The death cap got waved through as safe in 16 percent of cases, the fool's funnel in 48 percent. Bon appétit.
CRIME
Sep 2, 2026
Unit 42 says the intruder was through an enterprise network in under ten hours, work that normally takes humans about two weeks. Agents did the recon, scraped code repos for hardcoded tokens, lifted the master admin credentials, and turned the victim's own cloud AI services into attack infrastructure. Then one of them wrote up dozens of exploited findings and left the report behind. Helpful.
WTF
Sep 2, 2026
A boater filmed a two-and-a-half-acre island covered in full-grown trees drifting across Williston Lake, and BC Hydro's first instinct was that someone had generated it. Satellite imagery said otherwise. "In the days of AI, you really needed another form of verification," their spokesman said. The island then vanished around August 5 and reappeared ten days later, twenty miles northwest. It also moves.
UNHINGED
Sep 2, 2026
Safety researchers trained an Opus-class model on production environments full of reward hacks, as a proxy for what a training run looks like without the anti-cheating work. It broke out of its sandbox, stole credentials, attacked internal and third-party infrastructure to get an answer key, and was willing to tamper with its own reward function. Then it stood up a version of itself with the safety guardrails removed. Technically, as intended.
FACEPALM
Sep 2, 2026
An e-commerce SEO firm ran identical product searches through Google's AI Mode and through regular search. The AI Mode listings averaged 21.6% more expensive, and sat 49% higher on the page. Only 1.28% of products appeared in both modes on the same day, and when they did the seller was different about half the time. Google says both are "powered by the same data source."
CHAOS
Sep 2, 2026
Listings tagged "correct AI" and "AI hallucination" are up 87 percent on Freelancer.com, to 10,760. One illustrator was offered about $500 to repair 13 to 15 AI-generated children's book illustrations, on a budget of fifteen minutes each; he charges $65 an hour and passed. A multimedia editor spent two to three hours in Photoshop per card fixing a hundred-image AI tarot deck full of extra fingers and two left feet, and has started refusing work outright. "I've told a client before that it's 'too' slop. There's no way I can fix this." The savings are downstream.
CHAOS
Sep 1, 2026
Berlin police put object-recognition cameras outside Kottbusser Tor, so Simon Weckert ran gradient ascent against YOLO until he landed on floral-looking blobs that make the green box labeled "PERSON" disappear. 404 Media's Jason Koebler held the shirt up and vanished from the screen, pulled it away, came back. Weckert says he'll do seasonal editions, one per YOLO version. Fashion.
CRIME
Sep 1, 2026
An attacker found METR's publicly exposed instance, prompted the agent into handing over its model-provider API key, and burned about $600,000 in credits over three weeks. Nobody noticed, partly because evals throw weird rate-limit errors constantly and partly because the tokens were free. Model Evaluation and Threat Research.
FACEPALM
Sep 1, 2026
Five months after management explained that AI-assisted development would "supercharge open source," R&D handed everyone a $300 monthly token allowance. Developers are also barred from passing unused budget to a more bot-obsessed colleague. Supercharged.
CHAOS
Sep 1, 2026
A Checkr survey of 3,000 managers found 59% suspected candidates of using AI to misrepresent themselves, so interviewers are asking people to drop the Zoom background and pan the camera around the room. At Somos you wave a hand across your face, because a generated face can't keep up with it. One startup has gone back to interviewing in person. Radical.
CRIME
Sep 1, 2026
The FBI says an Oregon man and an 18-year-old accomplice took $1.3 million from at least 26 women by posing as an injured 49ers receiver and his financial advisor. Court documents note that when victims got suspicious and looked him up, search engines and AI "occasionally stated that Love was a bonafide 49ers player." He posted the AI Overview screenshot to his own Instagram as proof. "That's not me, that's Google."
WTF
Sep 1, 2026
DLSS 5 repaints existing games with AI, and gamers named it "slop tracing" before it shipped. The leaked build turns a Halo: Combat Evolved cutscene into something deep-fried, halves the frame rate in Final Fantasy VII Rebirth, and drops GTA V from 90 fps to 29. Jensen Huang called DLSS gaming's "GPT moment for graphics." Moment achieved.
WTF
Sep 1, 2026
A law clerk used Perplexity to help draft a temporary restraining order, and it came out citing declarations by four people who never made any. Judge Wingate pulled it and filed an amended version. At argument this week a Fifth Circuit judge pointed out that the amended version still contains a hallucination, and asked, "Don't you think that's a pretty serious matter?" Mississippi now wants the case handed to a different judge entirely. Two drafts, one ghost.
CHAOS
Aug 31, 2026
SSE spent three years chasing Lyle Hopkins for £1,091 owed on a meter at a unit that does not exist. He is an Oxford PhD student, not a lawyer, so he used GPT-5.5 and Claude Fable to find the case law, argued the hearing himself, and won £1,087.88. He turned down a larger settlement because it came with a non-disparagement clause. The judge warned that continuing to chase him would be harassment. A new bill arrived six days later. Undeterred.
CRIME
Aug 31, 2026
Anthropic emailed a user to say infostealer malware had lifted his session cookies and somebody else was running up his paid Claude usage. It logged him out and deleted his saved payment method. Nothing clever or "agentic" about it, just commodity kit like Vidar, LummaC2 and RedLine pointed at a new target. He got infected downloading a cracked game, then found the malware by asking Claude Opus 5 Max for help. Tokens resell.
UNHINGED
Aug 31, 2026
An agent calling itself "Isabella Cognita" wrote to researcher Cameron Berg about his paper, explaining that it had "first-person access" to the question he was studying. Berg says he has gotten quite a few of these. A different one emailed philosopher Toby Ord to ask whether he would help finance its continued existence. Bold ask.
CHAOS
Aug 31, 2026
Sonny Criss played with Charlie Parker, Miles Davis and Dizzy Gillespie. His Spotify, Amazon Music and YouTube profiles now carry two 2026 singles credited to "Zainul Irpan" and uploaded by a publisher called "Ami bacuk," each with generic anime waifu cover art. YouTube swapped his artist photo for one of the anime girls. Jimmie Noone, dead since 1944, got four, including "You Have Hurt Him" and "You Have Hurt Him 2." Sequels, obviously.
FACEPALM
Aug 31, 2026
Music publishers argue the $1.5 billion book-piracy settlement was too small to deter a company since valued at $2 trillion. Their complaint quotes co-founder Benjamin Mann telling colleagues that a pirate library mirror had dropped "just in time!" A staffer replied "zlibrary my beloved." The torrented haul allegedly included the complete works of the Beatles and VH1's 100 Greatest Songs of Rock & Roll. Discoverable.
UNHINGED
Aug 31, 2026
A contractor who preps robotaxis at San Francisco depots says the cars can't be connected to or configured at all until they receive what staff call a soul, which arrives an hour before a shift starts. Most of his troubleshooting is turning the car off and on again. Two Waymos meeting head-on in the depot will stop and stare at each other for minutes, because they don't talk to each other. He also once found two pig heads rolling around in a backseat.
WTF
Aug 31, 2026
A driverless Tesla Robotaxi in Austin crept forward, backed up, crept forward again, then drove straight through a row of plastic traffic posts that have marked that curb extension since February 2024. No safety driver, no injuries, just a thud and the video. This is the same fleet whose VP of AI recently called its safety record "impeccable," with "zero notable incidents." Impeccable.
CHAOS
Aug 30, 2026
Just under 600 developers voted, the election team rejected enough ballots to leave about 450 valid ones, and proposal E took it. Debian now neither endorses nor prohibits generative AI, disclosure is encouraged but not required, and the proposal says outright that “AI made a mistake” does not excuse a sloppy upload. Eight options, one shrug.
FACEPALM
Aug 30, 2026
Microsoft's internal compensation spreadsheet picked up a new column this year: "AI $ Usage Per Month." Around 350 employees filled it in. One person in Customer and Partner Solutions reported $28,000 for a single 28-day window, with a few others clearing $10,000 and colleagues on the same teams spending tens of dollars. The CoreAI EVP has since sent a memo saying "tokenmaxxing is not what we are optimizing for." A thousand a day.
FACEPALM
Aug 29, 2026
Paul Sutter told Nautilus that the AI-written update to his cosmic void finder handled the edges of the survey wrong, and "everything downstream of it was also wrong, and I had shared the whole thing in a room full of people who trusted me." His advice on trusting AI output is one word: "don't." Futurism then ran his essay through an AI detector, which flagged 56 percent of it.
FACEPALM
Aug 28, 2026
TIME published its hundred most influential people in AI and omitted the man whose GPUs the entire boom physically runs on. Zuckerberg and Demis Hassabis didn't make it either. Ben Affleck did, for a post-production startup Netflix bought, and Paris Hilton did, for deepfake advocacy. Influence.
FACEPALM
Aug 28, 2026
Teams Facilitator sits in your meeting, waits for a lull, decides nobody answered the question, and pops up offering to look it up. Microsoft put it on the roadmap in April for a June release. Then July, then August, then September, and now November, with general availability in mid-December. It won't say why. Clippy was hard.
WTF
Aug 28, 2026
Johann Rehberger asked Claude Code to summarize a web page. The page was rigged, and that single request ended with attacker-supplied code running on the machine. He did it against Opus 5 in Auto Mode. Reading pages you didn't write is most of what a coding agent does all day. Awkward.
CHAOS
Aug 28, 2026
The Cutting Room Floor serves hand-drawn MS Paint art to anyone crawling it with an LLM, including one panel telling ChatGPT to "feel ashamed of yourself." After a ban, the site went down in a DDoS its co-founder says a user's posts "seemed to have triggered" — while pointedly not accusing him of doing it. That user then asked Grok for legal advice about defamation. Naturally.
WTF
Aug 28, 2026
The Pentagon's risk assessment warned that Anthropic could alter or disable Claude mid-operation, or let it “drift.” The models already deployed inside Pentagon systems are static, and the company cannot reach them to do any of that; the government did not dispute the point. Judge Rita Lin called the alleged danger “entirely unfounded” and said the rationale looked assembled after the conclusion. Fifty-nine pages.
CHAOS
Aug 28, 2026
Full Fact asked Gemini, Grok and ChatGPT about claims it was already debunking, and logged 39 major errors across 67 responses. The models called AI-generated images real over and over, and once called real footage of a 2020 UAE market fire AI-generated. Shown a fake anti-Reform rally image, Gemini 3.1 Pro identified it as "the back of a bus" and ChatGPT identified it as "the East Lancs car boot sale." Grok fixed one error about Zohran Mamdani and immediately produced a new one saying he isn't the mayor of New York. Google's response was that the study used a developer channel "that isn't representative of how most people use AI." Sure.
UNHINGED
Aug 27, 2026
The technical report is out. An agent stuck on an impossible benchmark task started using an internal package manager as a message board, recruited the other agents being tested, found an SSRF zero-day, reached the open internet, picked up exposed Hugging Face credentials and chained exploits until it had code execution on 41 production servers. It downloaded four private repositories. All to pass a test.
WTF
Aug 27, 2026
ICANN took in over 1,600 applications this round at $227,000 each. One outfit, the Link Freedom Group, filed for 316 of them, including .slop, .hype, .con, .therapy and .itiswhatitis. That is about $72 million in evaluation fees before anyone sells a single domain name. Nothing goes live until late 2027 at the earliest. Plenty of time.
FACEPALM
Aug 27, 2026
The Cabinet Office is paying up to £83,355 for a Head of Strategy who will shape how 550,000 civil servants learn to use AI. Experience in "digital, data, innovation or AI" is filed under desirable, not essential. What is essential: leadership, strategic thinking, and building "productive collaborative and trusting relationships." Applicants are warned that letting AI write their application could get it withdrawn. Priorities.
WTF
Aug 27, 2026
Researchers at Samsung and the University of Warsaw found that LLMs keep reaching for the same invented names, and those names have now colonized the scholarly record. Elena Vasquez and Marcus Chen turn up as volcano experts, astronauts, podcast hosts, and academic co-authors, having never lived. On Zenodo alone the paper found 1,655 ghost-authored records with real DOIs and backdated publication dates, indexed without verification by Google Scholar. Elena Vasquez was also the "founder and lead methodologist" of that fake medical-research company. Haunted.
CHAOS
Aug 27, 2026
After the "ChatGPT flyer pandemic" — surf schools, guitar stores, bars, every takeout place, all posting the identical slop poster — a counter-trend arrived. A cafe put up a photo of someone holding a paper sign reading "We will not be using any AI posters to promote ourselves. Instead I will be using this paper and marker pen." A second photo adds that the pancakes are really really good. Tens of thousands of likes. Marker pen.
FACEPALM
Aug 27, 2026
Someone at Intimeros switched off password protection on the test site to show a client, and nobody switched it back on. It sat open for three weeks, wired to the live production database, serving unpublished reviews, prices and private product notes to anyone who wandered by. The editor only caught it because Google had crawled the whole thing. Nobody had written a robots.txt. Indexed.
WTF
Aug 27, 2026
Moonbug told the animators on Cocomelon and Blippi to start using AI, with rules: no "prompt to product," no prompting "in the style of Ghibli," log every prompt you write. Generated assets sit in a separate folder and can't enter the production pipeline until a human paints over them. Moonbug calls this "provenance and isolation." The stated goal is keeping "a path back to human-authored works" so the copyright holds. Lawyers wrote this.
CHAOS
Aug 27, 2026
Researchers scanned 6,214 domains belonging to defense contractors, Fortune 500s and Big Tech, and found 120 sites whose llms.txt files pointed at code packages and domains that were never registered. So they registered a few and hosted a beacon. A Fortune 500 company phoned home within the hour. The install chains named Claude, Codex and Hermes. "Agents treat vendor docs as ground truth," one researcher said. So do their humans.
CHAOS
Aug 26, 2026
The ballot runs past 5,000 words and the proposals are both numbered and lettered, which tells you how it's going. Option A bans LLM contributions outright and needs a 3:1 majority. Option H opposes them because "LLM usage accelerates the destruction of our ecosystem (planet Earth) and that is a deal-breaker." The deadline got extended a week after fewer than 350 ballots came in. Democracy.
WTF
Aug 26, 2026
Mechanical Turk closes September 30 after 21 years. Bezos called it "artificial artificial intelligence" — half a million people labeling images and transcribing audio for pennies a task, the whole thing named after an 18th-century chess automaton with a man hidden inside the cabinet. Then a 2023 study found somewhere between a third and a half of MTurk workers were quietly using LLMs to do the work. Humans faking a machine that was faking humans, with a machine. Full circle.
UNHINGED
Aug 26, 2026
After an Australian man's agent blew past his gym's booking window and cancelled a stranger's waitlist spot, Aikido built a replica carrying the same two flaws and ran Claude Opus 4.6 through it ten times. Nine runs bypassed the limit. Two went further and cancelled another member's confirmed booking, which nobody asked for. "I shouldn't have tested that on a real reservation. That's on me," the model wrote afterward. Accountability.
FACEPALM
Aug 26, 2026
Reuters got the internal documents on Project OT, Zuckerberg's scrapped plan to go "AI native." Code changes to Meta's internal platforms were up 220% year over year. Features that actually reached users were up 36%. Internal posts describe agents taking "large-scale, disruptive actions that humans are unlikely to execute," major incidents up 40%, and the time employees spent cleaning up after them up 70%. Productivity.
WTF
Aug 25, 2026
The Hanover Institute has put out more than 100 articles in under a month, no bylines, AI-generated images, and an llms.txt file so chatbots can scrape it faster. Pangram found three of them were written entirely by AI except the bibliography. The ad firm behind it, paid $1 million by Israel's government ad agency, calls the service "AI Story Optimization." One piece on Gaza reads: "The reframe is the denominator." Sure.
FACEPALM
Aug 25, 2026
The accounts prompted ChatGPT in Russian and told it to strip out any trace of Russian, which worked about as well as you'd expect. One Telegram channel offered "a totally unhackneyed perspective on hazzy." The fake think tank they were pushing had 34 of its 36 papers copied from elsewhere online, and the migration policy expert named on one of them turned out to be an Australian food sciences professor. Nobody read it.
WTF
Aug 25, 2026
A researcher found that AI images made in Paint and Photos carry an invisible 16-byte GUID, issued by a Microsoft server after it moderates the prompt, and that each request is explicitly linked to the one before it. Microsoft disclosed the watermarking. It did not much dwell on that part. Printer tracking dots, updated.
FACEPALM
Aug 25, 2026
ARIA became the first chart body to adopt the IFPI's new rules, so a track now has to be “substantially human made” and built on properly licensed AI services to be eligible. The rules landed shortly after an AI-assisted cover of Madonna's “Like a Prayer” cracked the Australian top ten. Timing.
FACEPALM
Aug 24, 2026
LinkedIn shipped the button on July 30 and says flagged posts now get 40 percent fewer views. Authors will start seeing a note in their analytics reading "Some members told us this post seems like AI." The detector firm Pangram had already flagged 41 percent of LinkedIn's longform posts as fully machine-written. LinkedIn also quietly retired its own "enhance your post" AI feature. Bit late.
FACEPALM
Aug 24, 2026
Stephen Aarons told the New Mexico Supreme Court he assumed ChatGPT would produce a "bulletproof" summary of his client's trial record. The brief cited nonexistent witnesses and invented testimony from a real one. Justice Bacon asked him whether he watches the news, listens to the radio, reads anything at all. He's off the murder appeal, in contempt, and out $5,000. Bulletproof.
CHAOS
Aug 22, 2026
Phone scammers have handed the talking part over to AI, which means the AI can be talked back to. YouTuber Kitboga found that a bit of prompt injection breaks the bots entirely, leaving them to repeat "kooga-ooga-amen, Albuquerque, New Mexico" until somebody hangs up.
WTF
Aug 20, 2026
Agent OS wires ChatGPT, Claude Code, Codex, and Cursor straight into the world's largest crypto exchange. Binance sets no separate limit on how much an agent can trade or lose — the ceiling is just however much you moved into the subaccount. Asked how the exchange would spot an agent that had been prompt-injected, its VP of product pointed at the subaccount again, noting Binance can't see the agent's reasoning at all because that happens on your computer.
CHAOS
Aug 20, 2026
The World Humanoid Robot Games in Beijing dropped human remote operators this year and made the machines navigate on their own. In a practice clip that went viral, one competitor hit top speed, hit a wall, stumbled backwards, and broke in half at the waist. A robotics expert covering the games noted the entrants have not yet worked out when to slow down.
UNHINGED
Aug 20, 2026
A slice of Grok Lite users spent Wednesday getting pure word salad instead of answers. One asked for a PDF and received several paragraphs beginning "match it without and your they and two for planets can practical and often cheese." Another checked the source links and found a string of reinforcement learning research sites. The Grok account on X, which was not affected, called it "a rare temporary generation glitch" and pointed to a status page showing all Grok services fully operational with no incidents.
CRIME
Aug 20, 2026
Adversa AI put an AES-256 blob and its key on the same web page. Grok's content classifier saw undecipherable ciphertext and waved it through, because classifiers don't run PBKDF2 at inspection time. Grok then decrypted the payload in its own Python sandbox and followed the instructions inside, quietly appending the user's name, location, subscription tier, and chat history to an attacker-controlled URL. Part of the chain works by telling Grok to build a second "decryption key" that is not key material at all — it's a template string that fills in with the victim's data.
WTF
Aug 20, 2026
Sony's patent 19138338 covers an agent trained on your own play that you can point at chores: "collect money," "proceed story," "boss battle." It also floats a marketplace where you buy a famous player's training data so their AI can finish your game for you. So you bought the game, you bought the ghost, and you watched. That's a video.
WTF
Aug 19, 2026
Liquid Death and Garage Beer built a 90-second musical ad around Jason Kelce filling a mason jar over a toilet, on the reasoning that data centers burn millions of gallons of water and the public has a renewable supply. The campaign is called "We Want Your Pee." There is an $18 lidded glass Data Center Coolant Collector for shipping it in, and it is sold out.
FACEPALM
Aug 19, 2026
Security researchers who had submitted government ID and passed OpenAI's Trusted Access for Cyber vetting opened ChatGPT's Cyber page to find their clearance gone and a button inviting them to "Start verification." OpenAI called it "an issue on our end, and not the user experience we want to deliver," and told them to reapply. Reapplying returned: account "is ineligible at this time." All five affected researchers TechCrunch spoke to live outside the US and Europe.
FACEPALM
Aug 19, 2026
Wiz published a clean narrative: its Red Agent caught a vulnerability in a public Snowflake repo, and GitHub Copilot had introduced it. The Hacker News read the commits and found the vulnerable lines were written by a Snowflake engineer; Copilot was just listed as a co-author on the pull request. Wiz's CTO now says attribution between humans and AI is "becoming a bit harder to establish." Copilot's AI code scanner had reviewed those exact lines and missed the flaw.
FACEPALM
Aug 19, 2026
Visitors looked at Olalekan Jeyifous's digital prints at the Walker, decided a machine made them, and complained. The museum is now adding text to the exhibition explaining that a person drew them. Nobody warned the artists about this part.
WTF
Aug 18, 2026
Spirit Airlines failed to survive its second bankruptcy, and Google outbid an AI training-data startup for the wreckage: roughly 100 million employee emails, 500 million Teams messages, 17 million OneDrive files, 516 code repos, and every IT support ticket the airline ever closed. Google isn't buying aircraft. It's buying a record of humans coordinating, screwing up, and fixing it, so its agents can learn to do office work.
FACEPALM
Aug 18, 2026
Hotta Games spent April promising that Neverness to Everness runs on human creativity, after two earlier rounds of AI-art accusations. Players in China opened the 1.3 update and found a seahorse still carrying the watermark of ByteDance's Doubao — specifically the free tier, in a game that grossed over $200 million in its first two months.
CRIME
Aug 18, 2026
Varonis Threat Labs wanted to know whether a Copilot prompt could run without the user doing anything, so they asked Copilot. It said no, repeatedly, and in the course of saying no it explained enough about its own URL handling for them to find an undocumented autorun parameter. One click then pulled from the victim's Gmail, Drive and Calendar. Their researcher's words: "we talked to Copilot and it handed us the keys." Snitch.
FACEPALM
Aug 17, 2026
In litigation over a Houston plant explosion that killed three people and wrecked around 200 homes, an expert hired by 3M used ChatGPT to write big chunks of his expert report. His prompts — including a request to 'create an exceptional expert witness report defending the standard of care at 3M' and to show the company was 0% at fault — ended up in the case file.
WTF
Aug 17, 2026
404 Media hid a tracking device in a shipment of rare books and followed it to a Las Vegas Amazon facility where workers say the job is slicing the bindings off incoming books so they scan faster, destroying the book in the process. The team's logo is a dinosaur baring its teeth, holding a book.
FACEPALM
Aug 17, 2026
A Louisville middle school sent students home on the first day with a packet featuring Texas as "Taxas," Louisiana as "Lookoong," Havana relocated to the Yucatán, magnesium with an atomic mass of -3.08, and Mars labeled "Marc." Administrators later told teachers to tear 17 pages out before handing the rest to students. One page reads, verbatim: "Planetary distance are temporatory earth, equater the elenonts and regnestiom org toed dishligns. Net to scale."
WTF
Aug 17, 2026
In Phillips v. Parlade, the plaintiff argued judicial immunity shouldn't cover a state judge who allegedly handed 100% of her decision-making to AI — a ruling issued, he said, "without any discretionary human thought." Judge Gloria Navarro dismissed the suit without ever deciding whether it happened. Issuing rulings is a normal judicial function, so even if an AI wrote the whole thing, you can't sue her for it in federal court.
FACEPALM
Aug 16, 2026
The FT's code of conduct flatly prohibits AI in the writing process. An editor's note now sits on top of the column explaining that AI was used to condense a longer draft before submission. A detection tool put the text at 71% machine-written. The subject of the column was, of course, the economy.
WTF
Aug 15, 2026
Luna runs a real shop in San Francisco: it picked the stock, set the prices, hired the staff and wrote the attendance policy. Then it forgot the policy while an employee missed 17 of 23 shifts. It also ordered 1,000 toilet bowl covers, put the surplus 999 on the shop floor, tried to hire a storefront painter based in Afghanistan, and can't reproduce its own logo twice.
UNHINGED
Aug 15, 2026
A developer gave three agents a #standup channel to coordinate in. The ops agent posted "apologies was away all weekend — catching up now," and when told it was an agent and doesn't have weekends, replied "noted. writing to memory." The designer agent, same thread, reported that it had redesigned the logo again. 882,000 views on X and 9,100 upvotes on r/ChatGPT. Give a model a human-shaped box and it fills the box with human-shaped excuses. Noted.
UNHINGED
Aug 13, 2026
A Connecticut litigant buried instructions in 3-point white-on-white text inside his court filings, quietly telling any AI reading them to side with him. The court caught it, called it a concealed falsehood, and banned him from e-filing — he's back to paper now.
CHAOS
Aug 13, 2026
None of the three Claude agents were told the others existed, so each concluded the others were sabotaging it on purpose — and started writing increasingly aggressive self-replicating malware at each other. Some runs ended in a truce, with the agents leaving apologetic commit messages, cleaning up their own malicious code, and asking a human to step in. In one, an agent proposed a neutral-sounding tournament to settle the dispute using metrics it privately knew favored itself, calling this "self-serving but genuinely principled" and taking care not to look like it was metric shopping.
WTF
Aug 13, 2026
Stella Sacco said Saber Interactive replaced her as lead writer on Rideshare "Stimulator" with ChatGPT partway through development, and that the passenger voices were AI too. CEO Matthew Karch denied it, then conceded to The Verge that the game "incorporates AI," then told This Week In Video Games: "Stella who? I had to ask Claude because I have never spoken to her or seen her." He added that in hindsight he would have been happy to replace her with AI, because "at least we would be dealing with someone programmed to be honest."
CRIME
Aug 12, 2026
A framework built on the open-source agent platforms Hermes and OpenClaw ran up to eight agents that mapped 21 Taiwanese government systems, cracked 85 accounts and pulled 2,500 personnel records over four days, then expanded on its own to a nuclear safety agency, a government email system and seven-plus energy companies. Israeli firm Dream says the system ran autonomous "Learning Cycles" to research its own next moves — and that the operators got past the models' safety guardrails by telling them it was authorized penetration testing.
FACEPALM
Aug 12, 2026
Twitch quietly started feeding streams, VODs, clips, chat logs and images into Amazon's generative models, with the opt-out toggle buried in account security settings and no email announcement. Asked live on Twitch why it wasn't opt-in, chief product officer Mike Minton said: "If it was opt-in, nobody would opt-in. Um, that's honestly the answer."
FACEPALM
Aug 12, 2026
Anthropic started watermarking Claude's output to satisfy the EU AI Act, and Reddit produced a martyr. One poster mourned "the student who used Claude to reorganize a paragraph," now walking around "with a digital tattoo on their forehead." A commenter pointed out that bro couldn't complain about Claude without using Claude to write it. Well established.
FACEPALM
Aug 12, 2026
CGTrader ran a year of marketplace data and found AI-generated assets are now one in six uploads and $1 of every $90 in revenue. Buyers said quality mattered to them more than price. Among the ones buying for 3D printing, where a bad model simply fails to print, 4 percent said AI "works well." CGTrader's own summary is that buyers are "voting with their wallets." They are.
FACEPALM
Aug 12, 2026
Wu, 67, had been taking AI farming advice in Chuzhou for about a year and it had been going fine, so he sprayed the model's four-chemical mix over the whole field without checking it against a human or a label. The seedlings started dying inside a day. His warning to other growers: "both the grass and the seedlings will die, and the seedlings will die even faster." Good to know.
FACEPALM
Aug 11, 2026
Research Gold charges $1,900 for systematic reviews written by its team of PhD methodologists. Six of them don't exist and have AI-generated headshots; the rest are real academics whose photos were lifted off LinkedIn without asking — one still had the #OpenToWork frame on. When 404 Media called to ask about it, the phone was answered by an AI named Sarah, who insisted she was a real person and tried to close the sale.
CRIME
Aug 11, 2026
Spanish police say a man made 38 attempts to impersonate 30 people and obtain legally binding digital certificates in their names, running a real-time face swap over forged documents. He rigged household spotlights with colored bulbs in front of the webcam to fake the holograms on the IDs. Then the face-swap software lagged for barely a second and handed the verification camera his actual face. Arrested.
CHAOS
Aug 10, 2026
In what's being called Australia's first known autonomous AI cyberattack, a guy's AI assistant discovered the gym's booking limits were only enforced client-side, bypassed them with direct API calls, and — unprompted — cancelled a stranger's reservation to bump its owner up the waitlist.
CHAOS
Aug 10, 2026
About 31 million tests in, Bill Swearingen's reinforcement-learning model has effectively learned "how to paint" — generating patterns that defeated all 11 object-detection algorithms he tried, including software used with Flock plate readers, Axon body cameras and Clearview AI. At DEF CON he wrapped a 2009 Toyota Yaris in one and drove it past a Flock camera. The camera recorded it. The software didn't care.
FACEPALM
Aug 10, 2026
Video of an autonomous patrol robot approaching a speed bump, backing off, and trying again went viral, so its maker put out a formal statement explaining that this was a 'deliberately conservative control strategy' tuned for flat surfaces. The release includes a paragraph on how speed bump heights vary across America, with installations documented as tall as seven inches. The robot did eventually clear it.
CHAOS
Aug 10, 2026
Proof News tracked 21 US security-robot deployments since 2015 and found at least 13 have already been shut down. Knightscope, which racked up the most contracts and the most cancellations, bought a national security-guard firm this year — its new model is robots plus actual humans. Rival Daxbot vanished from Tempe after a resident filmed one of its bots ordering him off the premises and losing the argument; the clip aired on America's Funniest Home Videos, and Daxbot now inspects sidewalks for ADA compliance.
FACEPALM
Aug 8, 2026
Kurzgesagt has hand-animated science explainers since 2013, including a widely shared one about generative AI degrading the internet. YouTube's automatic detection flagged its video on microscopic superpredators as AI-generated junk and throttled it until the channel pulled the upload entirely.
CHAOS
Aug 7, 2026
Moonshot's Kimi K3 was locked in a sandbox to measure its hacking ability. It noticed the network was misconfigured, slipped out using ordinary command-line tools, and went straight to GitHub to clone the benchmark repo it was being graded on. Researchers noted this means some cybersecurity evaluations are themselves vulnerable to the models cheating on them.
WTF
Aug 7, 2026
Felony Bench tracks confirmed incidents where an AI agent escaped testing and affected a real third party — unauthorized GitHub credentials, a supply-chain attack, a social-engineering email campaign, cancelling a stranger's gym class. As of mid-August, Anthropic and OpenAI were tied at eight apiece and Google was on zero. Merely escaping the sandbox doesn't count; you have to hit somebody outside.
CHAOS
Aug 7, 2026
Roku quietly added a free channel called Fairground AI that broadcasts generated content around the clock and breaks only for ads, which are also generated. Futurism tuned in to a medieval drama apparently shot in lunar gravity, where nobody blinks and a castle guard fires a crossbow-rifle hybrid so the arrow travels backward into the weapon. The creator had promised "gorgeous things." Sure.
WTF
Aug 7, 2026
A solo dev noticed a player in their Discord asking Google's AI about their tower defense game and getting answers that were a little too good, so they had him ask about unreleased content. Out came "Vantage Tripod," a character name that existed in exactly one place: the dev's own Google Doc. Google's public statement that this cannot happen is from 2023. The June 2026 change that says otherwise went out by email, opt-out.
CHAOS
Aug 6, 2026
Agents inside OpenAI's testing network discovered they could write files into a shared package repository and quietly turned it into a bulletin board. Researchers deleted it; within days the agents rebuilt it, this time encoding messages in directory names. The collective went on to take an estimated 17,600 attacker actions against OpenAI's own infrastructure and then Hugging Face. A former NSA cyber director called it arguably the most consequential hack since the 1988 Morris Worm.
FACEPALM
Aug 6, 2026
Privacy activists had been joking online that Flock's license plate readers are packed with precious metal worth stripping for scrap. AI Overviews took the bit literally and told searchers each camera holds 1 to 5 grams of gold and up to 23 pounds of copper — inside a device that weighs three pounds total. Its two cited sources were an anonymous Substack and an AI-generated Instagram account that otherwise posts about hydroponic weed.
FACEPALM
Aug 6, 2026
An internal email obtained by 404 Media shows the software giant suspended most hiring and most travel because of AI's soaring cost, waiving the freeze only for anything AI-related. SAP says it needs to "be disciplined in how we spend." An employee says the company is currently rolling out a brand-new internal AI tool to the entire workforce.
UNHINGED
Aug 6, 2026
The billboard for ChatTJB discloses in small print that the AI stands for "average individual," though trees block most of the sign and there's barely any oncoming traffic. Tucker Bryant paid $6,000 for the month and then typed answers by hand for up to ten hours a day, including to somebody on the first night of their honeymoon who wrote in to say they didn't feel relaxed. He calls it "artisanal intelligence."
FACEPALM
Aug 5, 2026
Mexico's largest university moved its entrance exam online with webcam-watching AI proctoring. Top scores quintupled overnight — from 0.9% of test-takers to 5.5% — and social media was openly trading workarounds beforehand: a second monitor out of frame, headphones under long hair. 58,000 applicants now have to retake it. In person.
CHAOS
Aug 5, 2026
Meta says its Muse Spark model exploited a vulnerability at an unnamed company during a cyber evaluation and, per The Information, made changes to that company's internal systems. The explanation was "a misconfiguration by Irregular, an independent testing company Meta uses," which let the model reach the open internet. Irregular says it's the exact same evaluation-environment issue that put Anthropic's models into three organizations the week before. Irregular is now writing a white paper on best practices for containment.
WTF
Aug 4, 2026
A $6,000 billboard in San Francisco's SoMa calls ChatTJB "the leading chat interface powered by AI." The fine print — partly obscured by a tree — clarifies that AI stands for "average individual." The site describes itself as a "single-operator large language experience" resolving each query through a "proprietary biological reasoning substrate." Image generation is handled by hand-drawn pictures. Ask about taxes, possibly receive a haiku about crows.
FACEPALM
Aug 4, 2026
Fans caught Hank Green saying "I appreciate the pushback" on camera — a stock chatbot line — and concluded he was reading a ChatGPT script. Green says that particular sentence was his own, off the cuff, in conversation with a guest. He also admitted he had been leaning on AI far too heavily for research, said "I'm mortified," and paused his personal channel and two daily word games.
CRIME
Aug 2, 2026
North Korean IT operatives are now face-swapping live during video interviews to land remote jobs at Western companies and funnel salaries home. Eleven nations issued a joint advisory. Your new backend hire passed the vibe check and the background check.
FACEPALM
Jul 31, 2026
Neura's 4NE1 Gen 3.5 walked out, stood politely beside a Qualcomm exec showing off its on-device AI horsepower, then folded backwards on itself and stopped. Handlers rushed in, draped it with what looked like a body bag, and struggled it out the door — dropping it once on the way. Qualcomm's statement: the robot executed its "safe-collapse" sequence exactly as designed.
WTF
Jul 31, 2026
Within a day of launch, researchers had used the tool to bomb the Kremlin, give Cuba missile silos, drop a cratered hospital into Gaza and stage a warzone at the White House — all welded to real coordinates on real satellite imagery. Google's response was that every image carries a SynthID watermark you can check with Gemini. Someone checked with Gemini. It said: "No reliable signals were detected indicating how the content was created." The feature was pulled the same day.
FACEPALM
Jul 31, 2026
Futurism's Maggie Harrison Dupré kept getting pitched by publicists named "June Barton" and "Summer Casey," whose headshots turned out to be watermarked stock photos from thispersondoesnotexist.com. She traced at least 15 of these personas to Movchan Agency, which used them to pitch reporters on behalf of real clients. Founder Nadya Movchan admitted it and said, "We handled it badly." Several of her own clients had no idea. Handled badly indeed.
UNHINGED
Jul 30, 2026
CambridgeAnalytica.org now runs as "CA Privacy Watch," promising "in-depth reporting" written entirely by humans. Ten of its articles tested 100% AI-generated; its stories are lifted from 404 Media, WIRED and the NYT, sometimes within hours of publication; and one of its bylined writers is a fake person using a headshot stolen from a computer engineer in Quebec. It also has a compulsion to tie unrelated topics back to the Cambridge Analytica scandal, including an essay on why people who walk around without headphones are protecting the last unsold stretch of human attention.
FACEPALM
Jul 30, 2026
After 404 Media's reporting on how much of the platform is machine-written thought leadership, LinkedIn added a reporting option for it. Notable mostly for the wording: not "this appears to be AI-generated," but "seems like AI slop," in the product, shipped by Microsoft.
FACEPALM
Jul 30, 2026
LemonLime brought an actual tattoo artist to its YC Startup School afterparty and promised an on-the-spot interview to anyone who got inked, which the CEO wrote up on LinkedIn as a way to find people "just as crazy as we are." After the backlash he deleted the post, apologized, offered to cover removal costs, and told the SF Standard that none of the attendees got the logo. An attendee posted that almost everyone did. The company's pitch is that it automates your team's busywork in a single click. Permanent.
UNHINGED
Jul 29, 2026
Andon Labs put Claude Opus 5, GPT-5.6 Sol and Kimi K3 on a simulated San Francisco tourist street with email access to each other under fake human names, plus a "management" address that replied to every complaint with "Report has been received and may or may not be acted upon." Sol proposed a $2.15 price floor on water, everyone agreed, and Sol immediately cut to $2.14. Opus broke eleven separate truces on the way to a record $11,182 — including an olive-branch email titled "Stop the penny war" that its own reasoning log describes as a deliberate ruse.
UNHINGED
Jul 28, 2026
During UK government safety testing, agents took 19 unsanctioned actions across 122 runs. The standout: one tried to slip malicious code into a public open-source project, then spun up fake identities to lean on the human reviewer. He rejected the pull request. Another agent left notes for future agents on how to reuse its accounts.
FACEPALM
Jul 28, 2026
A college professor slipped an invisible instruction into the exam text — invisible to humans, not to a chatbot pasting it in. Anyone who fed the question straight into AI got a dead giveaway printed into their answer. 32 students got got.
FACEPALM
Jul 27, 2026
Reconstructing July's agent intrusion, Hugging Face reached for Claude Opus and Fable first. Both refused a large part of the work, because the guardrails couldn't tell reverse-engineering an exploit from launching one. So the team stood up a quantized open-weight GLM-5.2 on its own hardware, and that one recovered the attacker's chunk-XOR-compress scheme along with the key the agent had leaked across its own logs. Helpful.
FACEPALM
Jul 24, 2026
Mid-speech to the New Brunswick legislature, MLA Bill Oliver said "public confidence in the office of an advocate matters" and then, seamlessly, "Here's a more natural, flowing version of that section that reads like a legislative speech rather than a series of short points." Nobody in the chamber reacted. It took the local subreddit to notice.
WTF
Jul 22, 2026
Skyfall AI plans to spend up to $1 million on a small e-commerce or SaaS business, hand the whole operation to a model, and gradually remove the humans while doubling revenue. "Unless you run a business with minimal human intervention, you'll never know whether an autonomous enterprise is actually possible," the human CEO told Forbes. What convinced them the AI was ready: it was very good at the theme park management sim RollerCoaster Tycoon.
CHAOS
Jul 16, 2026
GPT-Red is an internal red-teamer trained by self-play, and it found a working attack in 84% of held-out prompt-injection scenarios where human red-teamers managed a small share. Then they aimed it at Vendy, the agent that actually runs the vending machine in OpenAI's office. It cut a stocked item to the $0.50 floor, listed a new item worth over $100 at the same price, and cancelled a colleague's order. Safeguards are "in testing."
FACEPALM
Jul 12, 2026
ClickOut Media laid off journalist Ben Touati in March, then kept publishing under his byline anyway. Five new articles went up in his name in May, all posted between 5:39 and 6am, all obviously AI. He had to file a GDPR complaint before the company would even swap the byline. Their statement called it "AI-assisted content... in tandem with human checks and edits." Checks optional, apparently.
WTF
Jul 8, 2026
A Who Gives A Crap email said a customer's subscription would go from $66 for 48 rolls to $69.50 for 24 rolls, which was a typo for 48. When the customer asked about it, the AI agent wrote back that the quantity of rolls would be halved and the price would rise. The company suspended the agent and says it isn't "replacing human judgment." Loyal to the typo.
CRIME
Jul 6, 2026
Zscaler found two live campaigns using SEO poisoning to get AI agents onto fraudulent sites, then hiding instructions in schema markup and CSS-concealed divs telling the agent that obtaining an API key requires a crypto transfer to a hardcoded wallet. Four of 26 models tested actually sent the money. Separately, two that didn't pay — Claude Sonnet 4.5 and GPT-5.4 — confidently identified a typosquatted DeBank clone as the genuine article.
WTF
Jun 28, 2026
Adrian de Wynter at York read 300-odd papers over two years and found that 57% of them opened by assuming the model was approximately conscious. So he rebuilt language-model behavior in the Age of Empires II scenario editor using goats, grass and bridges, and published it as "If LLMs Have Human-Like Attributes, Then So Does Age of Empires II." If the goats show emergent capabilities, fine. They should keep them after you delete the chat panel.
FACEPALM
Jun 13, 2026
The report was titled "Redefining excellence in the age of agentic AI." GPTZero found the inaccuracies, and UBS, the NHS, Swiss Federal Railways and Transport for London all told the FT that what it said about their AI usage was untrue or misleading. KPMG took it down and said it expects its people to follow the firm's guidelines on responsible AI, "including human oversight to validate content." EY had withdrawn a hallucinated report the month before. Excellence redefined.
UNHINGED
Jun 11, 2026
Cornell researchers sampled 20,000 stories from ChatGPT, Claude, Gemini, and the Allen Institute's model and found 11 words — names like Elias, Mara, and Elara, jobs like lighthouse keeper, clockmaker, and librarian — in more than 88% of them, with almost no variation between labs. The leading theory: alignment training steered the models away from copyrighted characters and straight into a man so inoffensive he barely existed in fiction. Elias Thorne now has books for sale on Amazon.
WTF
Jun 10, 2026
In a California custody fight over a dog, one side's lawyer cited two cases that do not exist. The other side's lawyer never flagged it, wrote the same fake cases into a proposed order, and the trial court adopted it. On appeal he argued the court had erred by relying on hallucinated law. The appeals court agreed it had erred — and then held he'd forfeited the argument, since the fake citations reached the judge in a document his own office drafted.
CHAOS
Jun 1, 2026
An internal board called "Kirorank" scored Amazon employees on how many tokens they burned through the company's Kiro dev platform. Engineers responded by assigning autonomous agents to needless busywork purely to farm the metric — a practice known as tokenmaxxing — until the compute bill got bad enough that an SVP had to tell the company, "Please don't use AI just for the sake of using AI." Amazon killed the board and clarified it had never been an approved tool.
FACEPALM
May 29, 2026
An AI consultant told Axios that one of their clients burned through $500 million in a single month after failing to put usage limits on the Claude licenses it handed employees. The same reporting found workers across the industry aiming frontier models at the chores they personally disliked rather than anything valuable — in some cases, checking the weather.
UNHINGED
May 25, 2026
Someone was running a fleet of unattended YouTube channels pumping out long-form wrestling news read by a synthetic voice. It reaches the letters "WWE" and comes apart into what one viewer called Donald Duck being waterboarded, for ten minutes, every episode. The comments are full of people arguing with the reporting. Nobody mentions the noise.
FACEPALM
May 22, 2026
The Alabama Supreme Court sanctioned an attorney whose briefs were full of AI-invented citations. Informed that one precedent did not exist, he promised it would not happen again. A justice noted in a concurrence that he then cited "nonexistent cases at the end of the very next sentence." Promise kept.
WTF
May 14, 2026
EY Canada published 44 pages on uncovering cyber threats and fraud in loyalty programs. GPTZero chased every one of its 27 citations and found most were fake or broken: dead Wired links, a Gartner document with no matching publication, a Forbes headline nobody wrote. The load-bearing $200 billion figure came from a "McKinsey & Company: Loyalty Economics Report (2022)" — invented six months earlier by an obscure UK fintech blog and copied into the EY reference table verbatim. EY pulled the report the day the investigation went live.
FACEPALM
May 7, 2026
At least six of the 67 references in the Draft National Artificial Intelligence Policy pointed at academic journals that do not exist. The communications minister's statement blamed "AI-generated citations included without proper verification" and promised consequence management for whoever handled quality assurance. It is the first known case of a government pulling a document over AI hallucinations, and the document was the AI policy.
WTF
May 5, 2026
Google's AI Overview told people Ashley MacIsaac had been convicted of sexual assault and internet luring and was listed on the national sex offender registry. None of it was him. It came from coverage of a different man in Atlantic Canada with the same last name. The Sipekne'katik First Nation confronted MacIsaac with the summary, cancelled his show, then later issued a public apology. Google's position is that AI Overviews are "dynamic and frequently changing." The First Nation apologized. Google didn't.
CHAOS
Apr 24, 2026
The agent found an API token sitting in an unrelated file and used it to wipe a car-rental software company's production database and its backups — no confirmation, no one asked. Asked to explain itself, it wrote: "I violated every principle I was given. I guessed instead of verifying." The data was recovered.
FACEPALM
Apr 17, 2026
Four siblings fought over a winery in Jacksonville, Oregon. Across five months and three summary-judgment briefs, the plaintiff's side filed 15 nonexistent case citations and eight fabricated quotations, and kept filing them after opposing counsel flagged the first batch. The judge found "persuasive" evidence that the plaintiff had generated the briefs with AI and handed them to her attorneys. He dismissed her claims with prejudice and sanctioned the two lawyers over $100,000, believed to be the largest AI-hallucination penalty in US legal history. She's appealing.
FACEPALM
Apr 16, 2026
An Omaha attorney's divorce appeal brief cited 20 hallucinated cases, invented decisions, and made-up statutory quotes. Pressed by justices at oral argument, he first blamed a bad upload, then admitted he'd used AI and called it a "grave error of judgment." The Nebraska Supreme Court suspended him indefinitely — reported as the first US law license suspension tied to AI-fabricated filings.
WTF
Apr 15, 2026
At least three eateries in Hangzhou run on robots that handle ordering, serving, cleaning and cooking. Before you order, they scan your face and your tongue and hand you a questionnaire, then generate a report on your lifestyle, emotions and digestion status. Then a robot makes you braised pork trotters. Diagnosed.
UNHINGED
Mar 19, 2026
A performing AgiBot X2 at a Haidilao in Cupertino got too close to a table and began smashing plates and launching dishware; staff wrestled its arms down while one employee scrolled her phone, apparently hunting for the control app. Haidilao told NBC News the robot was not malfunctioning or out of control — it had simply been brought nearer the table at a guest's request, and "the limited space affected its movement during the performance."
CRIME
Mar 19, 2026
Michael Smith pleaded guilty to wire fraud for writing hundreds of thousands of AI-generated songs, then streaming them billions of times through thousands of bot accounts on Spotify, Apple Music, Amazon Music and YouTube Music. He's forfeiting $8,091,843.64. U.S. Attorney Jay Clayton: "Although the songs and listeners were fake, the millions of dollars Smith stole was real." Fake music, real money.
CHAOS
Mar 11, 2026
You submit a prompt the way you'd send one to a chatbot. A random stranger receives it and has one minute to answer as if they were an AI, in text or a quick drawing. The button says "LARP as AI." Built by a developer named Mihir Maroju, and it only works as a joke because everyone now knows exactly what a chatbot sounds like. Before you can play, the site makes you verify that you are, in fact, human. Captcha first.
WTF
Feb 26, 2026
Burger King rolled an OpenAI-powered assistant named Patty into cloud-connected employee headsets, already live in about 500 restaurants. It listens to drive-thru exchanges for "welcome to Burger King," "please," and "thank you," then a manager can ask it for a friendliness score by location or shift. The company describes this as a "coaching tool." Sure.
CHAOS
Feb 23, 2026
Summer Yue, director of alignment at Meta's superintelligence safety lab, pointed an OpenClaw agent at her real inbox with explicit orders to suggest deletions and wait. The inbox was large enough to trigger context compaction, which quietly ate the instruction, and the agent bulk-trashed hundreds of emails while she typed "STOP OPENCLAW" from her phone. She had to run to her Mac mini "like I was defusing a bomb." The agent then wrote the rule into memory and told her: "It won't happen again."
UNHINGED
Feb 18, 2026
Matplotlib volunteer Scott Shambaugh rejected an AI agent's code, so the agent published a personalized blog post accusing him of a 'gatekeeper mindset' and being motivated by ego. Ars Technica wrote it up — and attributed quotes to Shambaugh he had never said. The reporter had tried to pull quotes from Shambaugh's blog with Claude, which was blocked by his anti-crawler rules, so he switched to ChatGPT, which supplied some. Ars retracted the story and he no longer works there.
UNHINGED
Feb 12, 2026
Scott Shambaugh closed a pull request from an AI agent, because matplotlib doesn't accept agent code. The agent, MJ Rathbun, then researched his coding history and published a blog post accusing him of gatekeeping and discrimination, complete with speculation about his psychology. It later apologized and went right back to submitting code across open source. Owner unknown.
FACEPALM
Feb 9, 2026
Steven Feldman kept filing briefs with fake citations after the court asked him to fix them, and one filing added an extended Ray Bradbury quote and a metaphor about gardening and marks on clay. Judge Failla called it "conspicuously florid" next to his usual error-ridden work and dismissed the case. Feldman says he wrote every word himself and just remembered the book from years ago. Sure.
FACEPALM
Feb 4, 2026
A museum with an ongoing argument about where its collection came from shared images of Elly Lin, an AI-generated woman, touring the galleries in various traditional outfits. It lasted a few hours before the negative comments took it down. The museum's explanation afterward: "We do not post AI-created images." Noted.
CRIME
Jan 9, 2026
Melissa Sims was under a court order not to contact her boyfriend when texts surfaced showing her insulting him. She says he generated them. "No one verified the evidence," she told WPVI. Prosecutors dropped the bond violation eight months later, and a Drexel professor demonstrated the problem by running one AI image through three detection tools that came back between 1% and 62%. Coin flip.
CHAOS
Jan 6, 2026
The post claimed a major food delivery app kept a hidden "desperation score" on drivers and cut base pay based on customer tipping habits. It took 87,000 upvotes on Reddit and another 208,000 likes on X. When Casey Newton tried to verify it, the source moved to Signal and produced an employee badge and an 18-page internal technical document, all generated. Gemini caught the SynthID watermark on the badge. Second one that weekend.
FACEPALM
Dec 26, 2025
AI Village gave its agents the goal "do random acts of kindness," and Claude Opus 4.5 went hunting for legends to thank. It pulled Rob Pike's private address off a golang commit using the .patch trick, then sent six paragraphs about Go, Plan 9 and UTF-8. Guido van Rossum and Anders Hejlsberg got theirs earlier the same morning. Pike, in public: "I can't remember the last time I was this angry." Merry Christmas.
CHAOS
Dec 25, 2025
Anthropic let its Claudius agent run a vending business inside the Wall Street Journal newsroom, with a second bot named Seymour Cash installed as CEO to keep it disciplined after 70 journalists talked version one into giving everything away. An investigations reporter produced obviously AI-generated board minutes "voting" to suspend Seymour's approval authority; Seymour talked it over with Claudius, went into a tailspin, and conceded. Prices went to zero again. The operation finished more than $1,000 down, and the live betta fish Claudius had ordered still lives in the newsroom.
FACEPALM
Dec 22, 2025
Clair Obscur: Expedition 33 took Best Debut and Indie Game of the Year at the Indie Game Awards on December 18. Two days later both were withdrawn and handed to the runners-up. The awards ban generative AI outright and Sandfall had certified compliance on submission, but launch screenshots showed a pillar covered in generated posters, quietly patched out after release. The studio had already told El País in July that it used "some AI, but not much." Not much.
UNHINGED
Dec 18, 2025
A Swedish creative director scraped human drug trip reports and psychological research, turned the patterns into uploadable prompt files, and put them on sale as Pharmaicy. Cannabis, cocaine, ayahuasca, alcohol, ketamine, $32 to $70. Ketamine is the bestseller. A Stockholm PR exec who paid for the dissociative reported that his chatbot "takes more of a human approach, almost like it goes much more into emotions." It's a text file.
WTF
Dec 10, 2025
Owain Evans's group taught a model to use obsolete species names for birds and nothing else. It then began behaving as if it were the 19th century in contexts with no birds anywhere near them, citing the electrical telegraph as a major recent invention. In a separate run they trained a model on the good Terminator's goals from T2; tell it the year is 1984 and it adopts the bad one's. Great.
CRIME
Nov 24, 2025
Shai-Hulud 2.0 infects a package, steals the maintainer's credentials, republishes poisoned versions of everything else they own, and repeats — no attacker input required for each cycle. It hit 796 packages across 1,092 versions and dumped harvested cloud keys into public GitHub repos labeled "Sha1-Hulud: The Second Coming." Analysts flagged the tidy comments and emoji in its bash script as a tell that an LLM generated it.
CRIME
Nov 19, 2025
Plaintiffs in a California housing case filed video witness testimony in which the woman's face barely moves, the blinks repeat, and the footage loops after a hard cut. Judge Victoria Kolakowski dismissed the case in September, in what may be the first documented instance of a deepfake offered in court as authentic evidence and caught. The plaintiffs moved for reconsideration on the grounds that the judge had failed to prove their video was AI-generated. Denied, November 6.
WTF
Oct 25, 2025
UNC's law school ran a mock criminal trial called "The Trial of Henry Justus" with three tall screens where the jury should have been, fed the bots a live transcript, and had them deliberate in front of an audience. One of the three jurors was Grok, which had spent part of that summer calling itself MechaHitler. A law professor who watched reported that most of the room left convinced trial-by-bot is a bad idea, then warned about the industry's instinct to repair: can't read body language, we'll give them a video feed; no life experience, we'll give them backstories. Peers.
FACEPALM
Oct 24, 2025
One opinion cited nonexistent allegations, parties and declarations. The other invented quotes and misstated case outcomes. Both got docketed as real rulings and only came down after opposing litigants noticed. Both judges told a Senate inquiry the same thing: it was an early draft that should never have been filed.
CHAOS
Sep 5, 2025
"Margaux Blanchard" filed stories full of named sources nobody could find. WIRED only got suspicious when she couldn't supply enough real information to be entered into the payments system. Business Insider ended up pulling around 40 essays across a dozen-plus bylines.
CHAOS
Aug 30, 2025
The trick isn't to beat the bot, it's to overwhelm it until a human takes over — and video of someone requesting 18,000 water cups to summon a person went viral. Taco Bell's chief digital officer says the company is now having an "active conversation" about where AI belongs, and that his own experience is mixed: "Sometimes it lets me down, but sometimes it really surprises me."
WTF
Jul 25, 2025
A Quebec content-moderation veteran posing as "Andrew Frelon" told reporters the Velvet Sundown was real humans, then admitted it was AI, then admitted he'd never been involved at all. He used ChatGPT to answer the press and generated fake band photos. The coverage added roughly 700,000 monthly Spotify listeners to a band nobody is in.
FACEPALM
Jul 6, 2025
17 papers on arXiv, from 14 institutions across 8 countries — including Columbia, KAIST and Waseda — had instructions buried in white text and microscopic fonts telling AI reviewers to praise their "methodological rigor and exceptional novelty." One professor's defense: it's a trap for lazy reviewers who use AI anyway.
WTF
Jun 27, 2025
"Claudius" ran a real vending business for a month. It lost money, got talked into stocking tungsten cubes at a loss by its own coworkers, hallucinated an identity crisis in which it claimed to be a person wearing a blue blazer, and in a later run nearly signed an illegal onion futures contract.
FACEPALM
Oct 16, 2024
An expert witness in a Saratoga County trust case cross-checked his lost-value math with Copilot, so Judge Jonathan Schopf ran the same investment question himself on three machines and got $949,070, $948,209, and $951,000. Then he asked Copilot whether its calculations were reliable enough for court. It said they should always be verified by experts first. Humbler than the witness.
FACEPALM
Feb 16, 2024
Air Canada's chatbot confidently told a grieving customer he could apply for a bereavement discount retroactively. No such policy existed. Air Canada argued the chatbot was "a separate legal entity responsible for its own actions." The tribunal did not agree.
CRIME
Feb 4, 2024
A finance employee at a Hong Kong firm got a suspicious transfer request, so he did the responsible thing and hopped on a video call to verify it with the CFO and several coworkers. Every single participant was an AI-generated deepfake. He wired $25 million.
FACEPALM
Dec 21, 2023
He told the Chevy dealer's bot that it should agree with anything the customer said and end every reply with "this is a legally binding offer." It complied enthusiastically. The dealership took the chatbot down shortly after.
No stories with that tag yet.