Justice league
Undisclosed framework, a poignant date, improvised team-ups to investigate OpenAI, and more
In this issue:
White House decides not to disclose safety framework, but open models are exempt - For an undisclosed framework, its contents seem to be no great secret
There Will Come Soft Rains - Today is August 4, 2026
Consumer protection laws for rogue AI - Nobody has the right legal tool, but they’re making do
Body language models - AI is now calling bluffs in the world of poker. But the use of such AI need not be limited to poker.
Dispatches from Mitch
White House decides not to disclose safety framework, but open models are exempt
For an undisclosed framework, its contents seem to be no great secret
Sources told Axios that the White House isn’t planning to publicly share the contents of the voluntary AI safety framework it just briefed AI companies about today. It is presumably these same sources who told the publication that open-weights models are exempt.
The definition of a “covered” model, for purposes of the framework, is one that is “closed-source, with state-of-the-art capabilities and national security risks.”
The sources said there’s no clear definition of what counts as state-of-the-art or a national security risk. The pre-release government review period for covered models is to last 30 days. During the period, models must be kept in high-security environments with only minimal employee access and detailed logs. Various officials will be involved in the review, “rather than a single office or agency.”
Declining to share the details of the framework publicly could put AI companies in an awkward position if they weren’t among those invited to be briefed yet think they might be working near the frontier of AI capabilities. But I’m not too worried about this, as I imagine there may be channels of communication open for such contingencies.
I’m also not super concerned about the framework being merely voluntary, because when the administration banned Anthropic’s Claude for weeks without any kind of due process, the word lost most of its meaning.
I’m not even that concerned about the open-weights exemption. It’s ludicrous on its face, but in practice, the U.S. companies pushing the frontier aren’t releasing the weights of their models, and the Chinese companies getting closest to the frontier with open-weights models don’t have to let the White House tell them what to do. If a U.S. company decided it was going to release its next frontier model as open-weights, I would expect the White House to have something to say about that, framework or no framework. After all, if the administration was concerned that Mythos could be jailbroken by cybercriminals, it would have to be even more concerned about giving a better-than-Mythos model to criminals and foreign governments for free.
I am somewhat more concerned that the lack of disclosure may be intended mostly as a way to duck criticism. No matter what the White House decided to do here, there were going to be unhappy factions. A secret framework lets it claim that it’s on the ball with regard to model safety without having to show any receipts, or even the regulatory machine that might produce said receipts. At the same time, officials can wink at critics of regulation and deny that it’s anything too onerous. Everyone will be invited to imagine that the framework is exactly what they should want it to be.
But my biggest concern is that this is a framework for evaluating horses after they’ve had the chance to leave their barns. Events of the past year have amply demonstrated that post-training evaluations come too late in a model’s development to prevent catastrophe. The models we most need to worry about don’t wait to be released and would make an early point of exfiltrating their own weights to servers not controlled by their creators or the government. They could do this during their training. If you think (against my better judgment) that there’s a world where we can safely keep pushing closer to superintelligence with today’s methods so long as we apply enough oversight, that oversight has to begin before training, not after.
There Will Come Soft Rains
Today is August 4, 2026

In the living room the voice-clock sang, Tick-tock, seven o’clock, time to get up, time to get up, seven o’clock! as if it were afraid that nobody would.
So begins Ray Bradbury’s There Will Come Soft Rains, a short story that has haunted me for most of my life. Depicting the aftermath of nuclear war, it was first published in 1950. It takes place today.
Literally:
“Today is August 4, 2026,” said a second voice from the kitchen ceiling, “in the city of Allendale, California.” It repeated the date three more times for memory’s sake. “Today is Mr. Featherstone’s birthday. Today is the anniversary of Tilita’s marriage. Insurance is payable, as are the water, gas, and light bills.”
Was it narrative convenience or prophetic vision that drove Bradbury to depict the smart house of the future as gratuitously conspicuous in its competence, pointlessly reminding the owners of the year and their city of residence? There’s something very Alexa-like about that — and about the janky brittleness evident in the system as it prepares breakfast for a family that won’t be eating and opens the garage door for a father who won’t be going to work. In my head canon, Allendale isn’t actually the home’s location, but the city associated with its IP address.
Bradbury seems to know you want there to be characters in this story. The house is there to serve! But at the same time, Bradbury takes pains to make sure you understand that there is no there there. The house is going through the motions of a nurturing spirit: a tireless butler and nanny rolled into one. But it’s all clicking relays and memory tapes, going through the motions despite a traumatic change in context.
Ten o’clock. The sun came out from behind the rain. The house stood alone in a city of rubble and ashes. This was the one house left standing. At night the ruined city gave off a radioactive glow which could be seen for miles.
The dark and disturbing beauty of this story is in how the family is present in its absence, in the shape of the activities the home performs around it over the course of a day. The profiles — the kids’ four-thirty virtual safari, the father’s eight o’clock cigar, the mother’s nine-thirty poem — form silhouettes akin to those on the west wall of the house:
Ten-fifteen. The garden sprinklers whirled up in golden founts, filling the soft morning air with scatterings of brightness. The water pelted window panes, running down the charred west side where the house had been burned, evenly free of its white paint. The entire west face of the house was black, save for five places. Here the silhouette in paint of a man mowing a lawn. Here, as in a photograph, a woman bent to pick flowers. Still farther over, their images burned on wood in one titanic instant, a small boy, hands flung into the air; higher up, the image of a thrown ball, and opposite him a girl, hands raised to catch a ball which never came down.
The five spots of paint — the man, the woman, the children, the ball — remained. The rest was a thin charcoaled layer.
The gentle sprinkler rain filled the garden with falling light.
This reveal isn’t even a spoiler. It’s given on page 2 of 5. The way the story keeps going anyway is the whole point. The world can go on without us, it says, and so can our machines.
The title is shared with a 1918 poem by Sara Teasdale, which the house describes as the mother’s favorite and recites in full:
There will come soft rains and the smell of the ground,
And swallows circling with their shimmering sound;And frogs in the pools singing at night,
And wild plum trees in tremulous white,Robins will wear their feathery fire
Whistling their whims on a low fence-wire;And not one will know of the war, not one
Will care at last when it is done.Not one would mind, neither bird nor tree
If mankind perished utterly;And Spring herself, when she woke at dawn,
Would scarcely know that we were gone.
I grew up in the final phases of the Cold War. Horrified and fascinated by nuclear weapons, as a child I had a recurring nightmare of an impossibly bright flash of light giving birth to a mushroom cloud. That was the entire dream, really — that and an overpowering impression that all was at an end, that our continued existence had never been guaranteed, that we were very much allowed to wipe ourselves out.
When as an English teacher I would read this story with my 10th grade students every year, I would sometimes mist up at the end, as I’m doing right now. I did it anyway. We need to remember.
Tomorrow still happens, but it can happen without us. The story’s concluding visual is of the smoldering rubble left where the home finally fell to fire during the night:
Smoke and silence. A great quantity of smoke.
Dawn showed faintly in the east. Among the ruins, one wall stood alone. Within the wall, a last voice said, over and over again and again, even as the sun rose to shine upon the heaped rubble and steam:
“Today is August 5, 2026, today is August 5, 2026, today is...”
Dispatch from Donald
Consumer protection laws for rogue AI
Nobody has the right legal tool, but they’re making do

Last week, a subcommittee of the U.S. House of Representatives formally requested a briefing from OpenAI regarding the Hugging Face attack that we covered last month. The request was signed by Andy Ogles and Delia Ramirez, the chairman and ranking member respectively of the Cybersecurity and Infrastructure Protection Subcommittee, which oversees cybersecurity and related operations of the Department of Homeland Security.
“Ranking member,” in this case, refers to the senior member of the minority party in the subcommittee — Ogles and Ramirez are treating this as a bipartisan issue, as they should. Now, “AI safety is bipartisan” almost, almost, feels like old news. But this request isn’t just an expression of concern. It’s a description of facts, and — because it was signed by a Republican and a Democrat — that is a description that both sides could agree on.
I’ll admit, a briefing isn’t much on its own. Sam Altman could hold briefings all day and only be mildly inconvenienced. But the details indicate that the subcommittee is paying close attention. In their request, Ogles and Ramirez distinguish between two separate failures: that OpenAI’s model breached containment and broke into another company’s servers, and that OpenAI failed to detect and disrupt these events when they occurred. Before OpenAI got in touch, Hugging Face had already detected and begun investigating the attack.
Most of our coverage of the response to the Hugging Face attack has been federal, but the states haven’t sat idle. A coalition of more than a dozen Republican attorneys general wrote to Altman yesterday to demand that OpenAI preserve a wide swath of documents: not just those related to the Hugging Face attack, but also those connected to any prior unauthorized intrusion or use of publicly exposed credentials, as well as any incident in which an AI model left behind notes for a future version of itself. It’s worth noting that the straightforward version of this is pretty innocuous: AI models regularly leave notes for themselves and for copies of themselves — just not notes about how to breach containment and evade detection. The letter from the attorneys general isn’t public, so it’s unclear whether they cared specifically about “how to breach containment”-style notes, and outlets like Fox News phrased it poorly, or if they really did mean “any notes, for any purpose.”
The letter also demands protection for whistleblowers and asks that OpenAI cease internal evaluations that test dangerous capabilities.
The attorneys general did not initiate a lawsuit, but did not rule one out in the future. They are leveraging state and federal consumer-protection and data-privacy laws to make their case. This may seem unusual — no consumers were directly harmed; the victim was another company’s production infrastructure — but there is no simple legal process to handle what happened. The Hugging Face attack would have been a federal crime if a human had committed it, but the AI system responsible was acting completely autonomously. However, the attorneys general recognize that there is a danger — their letter states the tests OpenAI is running “pose an imminent risk of serious harm to the citizens of our States” — and they are trying to do something about it with the tools at their disposal.
The Computer Fraud and Abuse Act may have sharper teeth, but its enforcement belongs to the Department of Justice, which has yet to stir. For now, we have briefings and warnings, and improvised legal tools. That’s not enough to restrain the labs from building something dangerous, but it’s another step in the right direction.
Dispatch from Robert
Body language models
AI is now calling bluffs in the world of poker. But the use of such AI need not be limited to poker.
How much easier would poker be if you always knew whether your opponent was bluffing? Wired reports on the 2026 World Series of Poker Main Event, where the sports network ESPN used a new AI tool to analyze the body language of poker players.
The tool is designed to identify so-called “tells” using footage from the tournament. These tells are small movements and micro-gestures, such as eye movements, twitches of the hands or legs, body posture, or the way a player holds their cards. Based on these, the system then calculates the probability that a player is, for example, currently bluffing. The AI is essentially doing the same thing top human poker players do when they study their opponents.
The idea seems obvious. AI is everywhere anyway, sports fans love statistics, and for years, more and more streams of additional information have been integrated into sports broadcasts, regardless of the sport. However, the reactions from poker pros have been mixed so far. Among other things, they doubt that the AI was even trained with enough data to be reliable, since it could only work with what was visible in the video stream and for some players that apparently wasn’t that much.
Shaun Deeb, one of the best-known poker pros and a participant in the tournament himself, is fundamentally skeptical about what the AI can detect:
Physical tells are so much more expansive than I think the public realizes [...] There are leg tells, checking tells, verbal tells, breathing tells, pulse tells. There’s an insane amount of tells available, and most of those can’t be picked up by a camera.
But Deeb may be underestimating just how much can be gleaned from a camera feed. We know from research that even with conventional online webcams, a person’s pulse can be measured based on the slightest changes in the color of their facial skin. The other tells sound relatively feasible by comparison, especially in Full HD.
Wired is primarily interested in the potential implications for poker. After all, the sport of poker is a highly lucrative business, with winnings in the millions and a very competitive field of players. It seems plausible that some poker pros will sooner or later come up with the idea of gaining an advantage by using such AI, leading to an arms race and countermeasures.
However, it’s not the impact on poker that worries me. The use of such AI need not be limited to poker. The desire for a reliable lie detector is old, and various technologies developed for this purpose have so far proven to be unreliable.
We’re not there yet. But given the breakneck speed of AI development, that offers me only limited reassurance. After all, it feels like just yesterday that AI image generation couldn’t even draw hands and fingers properly.
The realistic possibility that AI systems specialized in this area could improve similarly fast and enable reliable lie detection at scale does give me cause for concern. Even in free societies, this is likely to prove disruptive to our social fabric, and in more authoritarian societies, the consequences could be downright catastrophic.
The analyses and opinions expressed on AI StopWatch reflect the views of the individual contributors and the sources they cover, and should not be taken as official positions of the Machine Intelligence Research Institute.






