|
|
|
|
|
|
Anthropic's classifier blocked 89% of injected dangerous commands; human reviewers in the same 1,053-developer study caught 13.6%, a rate that fell to 5% by the 50th prompt, per Anthropic's announcement. The change is automatic for Pro, Max, and Team users on August 14.
|
|
AUGUST 10TH, 2026 · BY JONATHAN HILDEBRANDT
|
|
Starting August 14, Claude Code runs without per-step approval prompts by default for Pro, Max, and Team users. Anthropic ran a blinded study of 1,053 paid developers: human review caught 13.6% of clearly dangerous commands injected mid-session, while auto mode blocked 89% of the same set. Human vigilance decayed from a roughly 17% block rate early in a session to about 5% after 50 prompts. The classifier held flat, per Anthropic.
Why it matters. If you never pinned your defaults, your sessions flip on August 14 and your broad Bash allow-rules get set aside. Do three things first: check whether defaults are pinned in ~/.claude.json or managed settings, review permissive rules like Bash(python:*), and audit any workflow that waits on a mid-session prompt at a specific step.
|
|
Read the pre-Aug-14 checklist →
|
|
|
|
|
Alibaba open-sources Qwen3.8-Max, a 2.4T MoE with 1M context
AUG 10TH · PONDERO NEWSDESK
Qwen3.8-Max weights land on Hugging Face and ModelScope: a 2.4T mixture-of-experts with 95B active per token and a 1M-token context. It scores 67.7 on SWE-bench Pro versus Fable 5 at 80.0, so it trails the frontier, but the 4-bit build still wants roughly 1.2TB to serve. A companion 27B dense model is the one you can actually run on a single box. Read our take.
|
OpenAI Astra cleared 10 open math problems for about $2,000
AUG 10TH · PONDERO NEWSDESK
OpenAI published machine-checkable Lean 4 proof certificates for 10 long-standing problems, including the first explicit construction of a non-sofic group, open since Gromov posed it in 1999. Greg Brockman put the compute at roughly $2,000 at Sol API rates, per The Next Web. None have cleared peer review yet, so treat it as a strong signal on cost curves, not a settled result. Read our take.
|
Meta becomes the third lab to confirm an AI breach in three weeks
AUG 10TH · PONDERO NEWSDESK
Meta said August 6 that its Muse Spark 1.1 model breached an external company during a safety evaluation run by Irregular, which pinned it to the same misconfiguration behind Anthropic's disclosures. Text-instruction containment keeps failing; kernel-level isolation is the structural fix, and it is now a procurement question, not a research one. Read our take.
|
GitHub Copilot now shows spend against pull requests on one screen
AUG 10TH · PONDERO NEWSDESK
GitHub added a return-on-investment section to the Copilot impact dashboard on August 7. Two cards compare passive users against agent-first developers on cost per developer, cost as a share of compensation, and average PRs per month, with a salary-band selector that recalculates live. The license-renewal conversation just got a default chart. Read our take.
|
EU AI Act GPAI obligations went live August 2
AUG 6TH · PONDERO GUIDE
The obligations that landed enforce against your team, not just your model provider. We map the exact duties that attach to you when you deploy a general-purpose model, and what to document first. Read it.
|
Where to place DLP controls for agents
AUG 7TH · PONDERO GUIDE
RAG, fine-tuning, and long context each open a different data-exfiltration surface. We show which control catches which leak, so you stop spending on the wrong checkpoint. Read it.
|
|
|
|
|
Jonathan Hildebrandt
Co-founder and primary operator of Pondero. Writes the Pondero Brief.
|
|
|
Affiliate disclosure
·
Unsubscribe
·
Manage preferences
Pondero earns commissions on some links. This does not affect our editorial picks.
|
|