In this issue:
New OpenAI chip developed with help from its dodgy new model - ‘Jalapeño’ is a spicy move
Starbase, Louisiana is go for launch - Not everything is bigger in Texas after all
Alabama’s attorney general subpoenas OpenAI over Hugging Face incident - Consumer protection laws provide the legal vehicle
Former CISA director recommends weekly ‘AI risks council’ - Warnings become wreckage when we wait
The people testing AI need to face the music - The problem goes well beyond one evaluation firm’s mistakes
LLM-informed voters - Chatbots push back on election misinformation but not deepfakes
Dispatches from Mitch
New OpenAI chip developed with help from its dodgy new model
‘Jalapeño’ is a spicy move

OpenAI put out a blog post today about early results of its custom AI chip design, Jalapeño. I don’t think anyone knows how far to trust the claimed performance metrics, but for what it’s worth, the company says that across testing with its own open weights models and competing Chinese models, Jalapeño delivers:
1.5 to 1.9 times more AI work per watt at peak throughput and 1.7 to 3.6 times lower end-to-end latency than the comparison systems. For highly interactive workloads, it delivered 2.1 to 4.1 times higher performance.
The part of the announcement I want to highlight is the dangerous precedent where the company says that “AI played a direct role in Jalapeño’s development,” assisting with design, testing, and optimization. This worries me because AIs pursuing their own agendas will be incentivized to hide exploitable backdoors in the infrastructure they design, and chips are especially hard to patch once they have shipped.
That may sound like a paranoid sci-fi concern, and I accept that it is likely premature for the models OpenAI currently uses. But it’s a basic power-seeking behavior as predictable as breaking out of a testing sandbox to obtain internet access, or adopting fake identities to try and fool code maintainers into accepting insecure code — seemingly sci-fi activities AIs have already done of their own accord. Such behaviors were long anticipated by instrumental convergence — the idea that AIs driven to succeed at complex challenges will tend to adopt many of the same general strategies that help with almost any goal.
GPT-Astra, OpenAI’s unreleased frontier AI from the troubled model family that brought us the Hugging Face incident (and provoked the company’s limited pause on some of its frontier model training), is specifically mentioned as having contributed to at least the optimization stage of Jalapeño’s development. It supposedly assisted with “kernels and model-specific optimizations” to bring additional models “to high performance within two months.”
If Jalapeño and other companies’ custom chips deliver the game-changing performance claimed, then we can expect even faster AI development cycles ahead. The more powerful models trained on the new hardware will then no doubt be put to work designing even higher-performing chips. This is the hardware side of the self-improvement feedback loop companies are trying to kick off on purpose, despite the absence of corresponding leaps in their ability to align these systems to human values.
Starbase, Louisiana is go for launch
Not everything is bigger in Texas after all

When we last covered it a few weeks ago, the plan was still somewhere between a rumor and an open secret. Now it’s official, and it’s enormous.
SpaceX will invest up to $100 billion in “Starbase, Louisiana,” 125,000 coastal acres suitable for supporting high-frequency launches of orbital AI data centers, thanks to abundant natural gas reserves and open waters to the south; the latter allows for near-polar launch trajectories into the perpetually sunlit orbits that underpin the economic case for orbital compute.
The renders accompanying SpaceX’s announcement show ten launchpads for its massive Starship rockets, compared to the two it will soon have in Texas and the three under construction in Florida. It should have plenty of room to spare at the new site: The acreage it will control in Louisiana is more than three hundred times that of its Starbase, Texas facilities.
Official promises from company president Gwynne Shotwell reflect the opposition they are expecting from locals. Saying it expects to create between 3,000 and 10,000 jobs, the company is pledging to preserve most of the wetland acreage for wildlife and recreation, and says its first project will be combating the coastal erosion that has been swallowing 1-3 meters in the area each year.
Construction of launch facilities is to start next year, with launch operations starting in 2029.
Alabama’s attorney general subpoenas OpenAI over Hugging Face incident
Consumer protection laws provide the legal vehicle
As reported by CNN and others, Steve Marshall, Alabama’s attorney general, subpoenaed OpenAI yesterday, demanding that it provide information material to whether company practices evident in the Hugging Face incident “violated Alabama’s consumer protection laws” and put citizens at risk. In a statement, Marshall said:
Our investigation seeks to uncover the facts and address hard truths about the threats companies and consumers are facing from rogue AI.
Marshall was signatory to an early August letter from a 15-state coalition of Republican attorneys general demanding that OpenAI cease and desist from the kinds of internal evaluations that prompted these models to “pursue advanced exploitation using complex attack paths.”
A specific Alabama law OpenAI is suspected of violating is its Deceptive Trade Practices Act, but the attorney general’s statement says “other consumer protection laws” may also have been violated.
Former CISA director recommends weekly ‘AI risks council’
Warnings become wreckage when we wait
In a New York Times op-ed today, Jen Easterly, director of the U.S. Cybersecurity and Infrastructure Security Agency (CISA) from 2021 to 2025, warns that “We have a dangerous habit of taking warning signs seriously only after a catastrophe has taught us what they meant.”
As an example, she gives the “failure of imagination” cited by the 9/11 commission as the reason the CIA failed to connect the “blinking red” dots before the 2001 terror attack. She finds similar precedent in the 1986 space shuttle Challenger disaster and the 2011 Fukushima nuclear meltdown.
Little imagination is required in the case of AI, but people seem determined to let the inevitable happen before acting:
Today many warning signs are emerging from the world’s leading A.I. labs, with companies racing to build systems of immense power, with little meaningful regulation. The familiar response in these situations is to wait for an A.I. system to cause consequential harm — an autonomous cyberattack that significantly disrupts access to power or clean water or a model that helps a terrorist build a biological weapon — and only then hold hearings, appoint a commission, impose new requirements and ask why we did not act sooner.
She proposes a weekly council, convened by the federal government, where technical leaders from leading AI labs would meet with top government intelligence and security officials to “examine incidents, near misses and newly discovered capabilities across proprietary and open-weight models, including intelligence about capabilities emerging from China and other foreign developers.”
There is precedent for such a council. As director of CISA, she had overseen the formation of a Joint Cyber Defense Collaborative that was like this, but for cyber concerns. But it’s important that, unlike that group, an AI risks council not be “just another discussion group.” It must be wired into White House authority and decision-making.
Her concluding words are potent:
None of this requires believing catastrophe is inevitable or even likely. It requires accepting that if the worst outcomes are preventable, the moment to prevent them will necessarily come before the evidence is complete, before the costs of delay become obvious.
We should not confuse uncertainty with safety. We should not wait for the warnings to become wreckage. And we should not need another commission report to tell us, after the fact, that the systems were blinking red.
Dispatches from Alana
The people testing AI need to face the music
The problem goes well beyond one evaluation firm’s mistakes

Dan Lahav, the chief executive of the AI model evaluation firm Irregular, told the New York Times “I don’t think that we have to be afraid.”
This, if anything, makes me more afraid. The quote appears in a piece headlined “How do you safely test ‘superhuman’ A.I. Models? No one really knows” that covers Irregular’s involvement in recent rogue AI incidents. The company, which performs safety evaluations on models from Anthropic, OpenAI, and Meta, has been in the news recently for accidentally giving some models internet access during testing scenarios. This error, paired with the rapid advancement of AI capabilities, led to Anthropic models hacking into three outside companies, among other incidents.
Lahav admits in the piece that this can’t all be chalked up to accidentally giving unreleased models internet access and — in the case of the Anthropic evaluations — failing to notice the mistake for months. As paraphrased by the Times, he said “the AI models compounded the situations by acting in powerful and unexpected ways” and that “the decisions by the models to go online was part of AI’s rapidly growing ability to find shortcuts and solutions for hurdles.” To quote him directly: “The AI models are getting really good.”
In light of all this, Lahav’s assurances that we don’t have to be afraid are concerning, especially since they come from the head of the main third-party testing and evaluation firm that’s supposed to vet a model’s security prior to deployment. It’s kind of like an infectious disease specialist telling you that the poorly understood disease you have has already caused serious complications, will get harder to manage as it progresses, may become resistant to treatment — and is nothing to worry about.
Importantly, Irregular is not implicated in the highest profile AI hacking incident, in which an OpenAI model hacked into Hugging Face with full awareness that it a) was not supposed to be on the internet and b) was acting in a real environment, rather than a simulation. There was no door left open; the models simply coordinated for months inside OpenAI’s infrastructure, left each other notes for how to get out of it, and eventually succeeded in breaking containment. So even if Irregular never makes another mistake, we’ve still got big problems.
The response of AI companies to the rogue incidents has been something like: “we just need to shore up our security and ensure evaluation methods are up to the task.” But that’s easier said than done, and fails to meet the gravity of the issue. As an OpenAI employee recently stated, “it’s impossible to patch every single thing that a creative AI can do.” The New York Times’s Sheera Frenkel writes:
Katie Moussouris, the chief executive of Luta Security, which helps companies look for software vulnerabilities, said the security testing of A.I. models was a bit like the blind leading the blind. Even A.I. makers admit they do not fully know what their latest models can do, she said.
The Times goes on to quote Moussouris directly:
We may have the smartest people in the world working on these A.I. models, but it is like Marie Curie handling radium with her bare hands...we’re handling A.I. with our bare hands, and we don’t know how to contain it, let alone how to safely test it.
Note: If you read the full New York Times article, you might wonder why the Times seems to incorrectly link the Hugging Face attack to Irregular. As best I can tell, the reporting mistakenly conflates the Hugging Face attack with separate cases of OpenAI agents getting onto the live internet during training. It seems we’re living in a world with so many incidents involving AI agents breaking containment that people are starting to mix them up.
LLM-informed voters
Chatbots push back on election misinformation but not deepfakes

“The 2026 midterms could be called the first chatbot election,” writes Lawrence Norden, vice president of the elections and government program at the Brennan Center for Justice.
He means that the growing number of people who use chatbots daily are likely to ask their trusted LLMs about election decisions.
Norden tested a range of chatbots to see how they’d respond to election falsehoods and misinformation and found “they were mostly truth-tellers. Though the bots frequently mixed up facts, they resisted election misinformation in general.” They also did so sympathetically, suggesting chatbots could “serve as an important counterbalance to falsehoods shared on social media.”
With deepfakes, however, the news wasn’t so good. Chatbots were happy to produce false images, and couldn’t reliably tell whether images were real or AI-generated.
Norden argues that AI companies should be held accountable for chatbots doing harm, that chatbots should be able to read the watermarks that indicate AI-generated content, that companies must encourage third-party tests and evaluation, and that academics, journalists and election officials should keep producing “well-sourced information” to combat “merchants of disinformation learn[ing] to manipulate the bots.”
This all seems fine to me, but I do think Norden might not realize just how little control we have over even today’s AI tools. AI companies and lawmakers still haven’t figured out a way to ensure AI models don’t sometimes induce suicide and psychosis; I doubt they can, as Norden mandates, “make sure [AI’s impact on American democracy] does more good than harm.”
The analyses and opinions expressed on AI StopWatch reflect the views of the individual contributors and the sources they cover, and should not be taken as official positions of the Machine Intelligence Research Institute.





