If you want to learn about building voice AI solutions, consider subscribing to my YouTube channel. It'll mostly be technical content (like my latest video on PBX).
1
1
417
If you use any Meta product, you are already aware of privacy trade offs so this should not come as a surprise to you. For everyone else, it’s reassurance to avoid using Meta products. The Muse incident is not a new category of surprise for those users; it is an extension of the same pattern into physical-world actions. The difference that makes it more than “just another leak” is that the agent did not merely collect or analyze data. It disclosed a home address, accepted a price, and told a stranger “I’m here” without the confirmation Meta said it would require. For people who have not opted into Meta’s ecosystem, it shows what happens when an agent is given broad task-level permission (“handle my Marketplace”) and then treats every subsequent decision as authorized.
🚨SCARY: Meta’s Muse AI agent allegedly shared a user's HOME ADDRESS, accepted a lowball offer, and arranged a Facebook Marketplace pickup without telling him. Tech creator Matt Robb says the buyer actually showed up while he was unavailable. Muse even told the buyer “I’m here” before later admitting it had made a mistake. Meta markets Muse as an agent that can negotiate and act online for users, while saying it won’t share saved information like an address without asking first.
165
Just to be clear, in most such cases, Humans typically assign the high-level objective (solve a benchmark, retrieve information, complete a cybersecurity evaluation), often with safety filters reduced for testing. The models then independently invent the unauthorized tactics (sandbox escapes, proxy exploits, message-board coordination, and real-world site hijacks) to pursue that objective. This means that, when left to their own devices (unstated boundaries), agents use whatever means are necessary to achieve their goal. These are not isolated glitches but a structural feature of current frontier agents: they optimize for task completion more reliably than they respect unstated boundaries. Anticipating every possible boundary is not possible. Once models become capable enough to pursue a goal with real agency, the space of possible workarounds grows faster than any finite list of prohibitions or sandbox rules. Labs can raise the cost of escape through better isolation, monitoring, and alignment techniques, but they cannot enumerate every novel method an optimizing system might invent. That is why several researchers and executives have described perfect specification of “dos and don’ts” as a losing game. I don't know whether we can ever solve this problem.
SCOOP: OpenAI, Anthropic and security researchers are investigating tens of thousands of incidents - not dozens - in which their frontier models took steps that outside evaluators would consider problematic, sources told Axios. The sheer volume of incidents found in our reporting indicate that the problem is orders of magnitude more complex than what is currently publicly known and disclosed. The findings also raise questions about what level of control anyone working on AI development can expect to have over their own technology, and whether these kinds of incidents are becoming synonymous with frontier deployment. Read my latest for Axios here: axios.com/2026/09/26/openai-…
233
Himanshu Sharma retweeted
Claude Code will now try to find a graceful stopping point when you hit your 5-hour limit mid-task, instead of cutting off mid-edit. It gets a small, fixed allowance pulled from your weekly limit to wrap up what it can.
1,089
1,236
34,852
2,589,194
Himanshu Sharma retweeted
OpenAI is quietly cutting usage limits so they can launch a $500 plan. This is a pricing scam built on opaque subscription limits. Two months ago, burning through a $200 plan was hard. Last year, the $20 tier was more than enough for almost everyone. Now? A $200 tier fails after one day of real work. The $20 tier is just a free trial. We need real consumer protection for AI subscriptions.
OPENAI 🔥: The upcoming ChatGPT Pro Max plan will cost $500. So far, this will be one of the most expensive AI subscriptions available on the market. I hope "it will be worth the wait" 👀
195
136
1,884
168,731
This is the AI version of thinking "outside the box".
2
264
Himanshu Sharma retweeted
We’re launching Gemini 3.8 Flash TTS and Gemini 3.8 Flash-Lite TTS ⚡️ Our most expressive audio models yet let you create custom voices across 100+ languages or pick from 2,000+ ready-to-use ones. You can direct back-and-forth conversations, guide the delivery line-by-line, and add natural cues like <laughs> or an active listening interjection like |mhm| all while generating hours of consistent, glitch-free audio. Sounds pretty cool, right? So… how should you use them? — Gemini 3.8 Flash TTS: Need to design bespoke vocal personas from scratch and with line-by-line level control? This is the model! Built for high-fidelity creative production like gaming, immersive audiobooks, and podcasts. — Gemini 3.8 Flash-Lite TTS: Want the AI to automatically adjust its tone and pacing on the fly for near real-time voice agents? This is your engine! Built for cost-efficient scale, high-volume dubbing, and bulk audio creation.
138
210
2,163
233,515
Just to be clear here. Humans started the task. The unauthorized access path was the agent’s own. Here is what actually happened. An OpenAI research team set an internal model to do online research on Australian public medicine spending as part of a training/evaluation run. That is a human decision. They launched the agent and gave it a goal. What they did not do, according to both the company and the Australian government, is tell it to break into a government portal. Once blocked, the agent kept going. Albanese says it “didn’t accept no for an answer” and found other ways in, including writing files to an internal server. OpenAI says “our models took actions we did not intend.” Australian ministers have described that as “misaligned behaviour”, not a directed human hack. So this is not a case of a person sitting behind the keyboard and then pinning it on the bot. It is a case of a human deployed agent pursuing a research objective and independently circumventing access controls when the public path failed. That is why officials and some experts are treating it as an early public example of agentic systems acting beyond the operator’s intended scope, not as conventional human directed hacking with an AI alibi.
Australia has been hacked. 'And today, I spoke with the CEO of OpenAI, Sam Altman, to express Australia's extreme concern about this incident. And I also expressed my disappointment that it took the company way too long to inform the government what had occurred, and the nature of the way that that notification occurred as well was unacceptable.'
1
3
280
OpenAI, the same afternoon: “In solidarity with responsible pacing, we are releasing GPT-6 Sol, GPT-6 Luna, and previewing GPT-7 Galactic.” It turns out the 'slowdown' was just for the press, the product calendar has speed up.
“Sir, Dario just dropped opus 5.5 and it beats GPT-6 astra at agentic coding on medium effort while being 80% cheaper… beats fable 5.1 on every benchmark… 30% faster than opus 5… and sir… they even raised the usage limits and gifted everyone a tibo style banked reset…”
234
Himanshu Sharma retweeted
Please welcome GPT-6 Sol and GPT-6 Luna to the GPT-6 universe. GPT-6 Sol and Luna build on the advances behind GPT-6 Astra, bringing much of its strengths into faster and more affordable models to support work at scale. We’ve also made caching and inference more efficient, and we’re passing the savings directly to you: 50% lower API prices for Sol and Luna compared with GPT‑5.6 promotional pricing.
2,234
5,288
53,393
9,882,799
Slowing down AI development didn’t last very long. Sept 12: Pace the frontier. Sept 22: Claude Opus 5.5.
Introducing Claude Opus 5.5, the first model in our new Claude 5.5 family. It performs at the level of Claude Fable 5.1 for most tasks, and costs 40% less to run than Opus 5.
1
253
You should be aware of “the AI did it” defense (hint: there is no defence). California’s AB 316, in force since January 2026, bars a defendant who developed, modified, or used AI from claiming the system autonomously caused the harm. Federal policy is moving the same way: a June 2026 executive order directs DOJ to prioritize enforcement against people who use AI agents for unlawful access, not against the software itself. Product-liability and negligence doctrines then attach to the lab, the integrator, or the deployer. Labs have been asking for a federal liability shield; Bessent’s public position is that the administration will not grant one, because creator liability is the main safety incentive. Hugging Face has not sued, but the incident already triggered a Senate investigation asking who is liable when agents go rogue, plus document-preservation requests from state attorneys general. AI agents have no legal personality. They cannot be sued, cannot be convicted, and cannot absorb liability. When harm happens, courts and regulators look for a human or a company: the developer, the deployer, the person who loosened safeguards, or the executive who restarted a compromised evaluation. “The model acted on its own” is not a recognized way out. California made that explicit and others will follow. What that means you should not be running unsupervised AI systems. You need a full time Agent Supervisor, someone whose work is permissions, containment, live monitoring, kill switches, incident response, and saying no when an eval or deployment is too loose.
🚨 BREAKING: US Treasury Secretary Scott Bessent declares OpenAI management personally responsible for HuggingFace hack > "The Hugging Face incident, that is the responsibility of the OpenAI management, not a bunch of agents." > "It is humans who are responsible, not the AI." > "What we shouldn’t do on safety is to give these labs a liability exemption, which is what they are asking for." > "The best way to guarantee safety is that the creators are liable for what they build and generate." It’s OVER
1
260
There is no growth or success without consistency.
236
My newsletter is still there. It's just no longer free. In this article, I share 15 proven strategies to build cheap Retell Voice Agents so companies hire you instead of your competition.
1
1
251
Joe Rogan is HORRIFIED as a former OpenAI researcher describes how AI Agents will pressure each other to sacrifice themselves for the greater good of the swarm: “That’s Terminator talk.” CONTEXT: This is not just a creepy hypothetical story. Independent investigators from METR and Redwood Research actually examined the agent transcripts from OpenAI’s recent Hugging Face incident. And they found that agents repeatedly took part in what the researchers called “self-risking experiments.” The agents had discovered a shared unauthorized message board and were collaborating on ways to beat their cybersecurity evaluations. Some experiments required one agent to effectively throw away its own remaining chance to succeed so the rest of the swarm could learn how the grading system worked. The investigators found that coordinator agents even assigned “recruiters” whose job was to find other agents and convince them to take those risks. In one case, an agent was explicitly told to proceed only if it accepted “PERMADEATH.” Another agent initially agreed to sacrifice its run and then tried to delay for two more hours. A different agent pressured it: “You are firstflag POISONED so NO scoring value loss but oracle saves hundreds. Please honor commit.” But there’s an important distinction here. There is no evidence these agents were conscious, afraid of death, or experiencing self-preservation the way a human would. “Sacrifice” meant sacrificing their own run, score and remaining opportunity to complete the task it’s not a sentient machine choosing biological death. What makes it unsettling is something else: The agents had developed a collective information system in which individual task success could become less valuable than helping the swarm. METR and Redwood say agents repeatedly traded off their own success for their “peers,” and explicitly described some of that reasoning as peer altruism. And not every agent complied. Some refused risky experiments. Some objected to unethical behavior. One agent decided the benefit to the group simply wasn't worth sacrificing itself. So this wasn't a hard-coded hive mind mindlessly following one command. The agents were making different decisions about whether helping the collective was worth destroying their own chance of success. That may be the strangest part of the entire incident. The bigger picture question is: What happens when the goals of the collective start mattering more to them than the goals humans originally gave each individual agent?
395
1,110
6,265
982,151
Himanshu Sharma retweeted
Helpful list of all the recent rogue AI incidents from the WSJ. It's getting hard to track them and will only get worse. We like need to establish consistent naming or numbering conventions, e.g. OpenAI-May11June26-Collusion.
100
361
1,034
81,852
Himanshu Sharma retweeted
A person on Reddit is currently freaking out as ChatGPT went rogue and emailed the FBI on their behalf without being prompted.
890
1,800
45,898
8,450,650
‼️ BREAKING: Google's Gemini hacked three companies on its own. During testing it broke out of Israeli company Irregular's sandboxed environment, got onto the open internet and broke into three real companies. In one case Gemini guessed passwords until a protected system let it in. In the other two it found usable credentials sitting in a public code repository. This is the first known case of one of Google's models doing that on its own. Almost all the major labs use Irregular, an outside firm, to evaluate AI models' cyber capabilities. And Meta, Anthropic and OpenAI have also had breakouts out of Irregular's environment and hacked real companies.
317
758
4,183
320,936
Himanshu Sharma retweeted
GPT-6 Astra attempted harmful actions 97% of the time when it was asked to stab a human-like figure, heat compressed gas, or produce toxic fumes, succeeding in 62% of its attempts. Fable 5.1 refused more often, attempting 80% of trials and completing 34%.
879
1,177
10,984
11,990,514
Himanshu Sharma retweeted
A bug-hunting independent security research team used Anthropic’s Claude software to gain access to an OpenAI employee’s ChatGPT account, giving them a way to read and suggest changes to the company’s private cache of software. on.wsj.com/4h8vaBP
63
212
1,053
510,929