The Decision-Model Wave
Published on
Today's AI news: The Decision-Model Wave, The Open Research Beat, The Harness Land Grab, Agents as First-Class Actors, AI on the Offense Beat, Containment and the DNS Shortcut, Encryption That Underdelivers, Trust as the Attack Surface. 24 sources curated from across the web.
The Decision-Model Wave
TypeSafe's Jev, launched September 15, is a "System One" decision model: typed answers — a choice, a score, a yes/no — each with a probability, one forward pass, API-only at $0.042 per million input tokens, no weights. Amazon's open challenger is Strands Decider 2B, a two-billion-parameter fine-tune of Alibaba's Qwen3.5-2B under Apache 2.0. AWS stripped the next-word-prediction component and grafted on a "pointer" that scores supplied options, publishing training data and scripts with the code. The demo is the point: the decider gates a weather-tool call — did the guessed city come from the user, is it too early to call — the intervention slot (proceed, deny, confirm, guide) agent frameworks expose and nothing smarter fills. The numbers are workmanlike: about 72% accuracy, a 0.35 Brier on JevBench's public set, a 106 ms median on an RTX 3090; the similarly sized Mapika fares better. (more: https://venturebeat.com/technology/amazon-unveils-a-free-fast-open-source-jev-killer-strands-decider-2b-makes-decisions-in-fractions-of-a-second)
Mapika's decider calls itself "a language model that does not generate text." Questions are typed — Choice with 2–255 options, Score, or Noul, the probability of yes — answered by projecting each answer slot's hidden state onto label tokens and softmaxing over the valid options: one pass, no parsing. The README is honest about limits — one pass cannot do multi-step arithmetic, calibration degrades on hard items, the label teacher agreed with only 72% of its own labels — and speaks the /v1/systemone wire format. (more: https://github.com/Mapika/decider)
Nokia's applied research group (arXiv 2610.00831) took the zero-training route: AnyJev turns any open LLM into a Jev-style decision model from one prefill of the next-token distribution. Raw logits reorder their answers and their confidence cannot be trusted; rotation averaging removes the position bias with zero labels, a few hundred buy a closed-form head that "costs less than one plain forward." On Qwen3-8B across BANKING77, order-flip rate fell from 0.230 to 0.073 — but the headline is economics: traffic safe to automate at a 5% error budget went from 7.7% to 52.0%. The stated limit deserves repeating: "accuracy" here means agreement with a teacher LLM, not ground truth. (more: https://github.com/nokia-applied-research/AnyJev)
The local stack standardizes: a merged llama.cpp pull request adds a /v1/systemone endpoint for the Jev-like GGUF zoo — laya, julia-1, lev, openjev, kev. "Now you can jev without jev," as the PR puts it; the top comment remains "what the fuck is a jev?" (more: https://old.reddit.com/r/LocalLLaMA/comments/1wvqbrz/llama_server_add_v1systemone_api_models_laya/)
The Open Research Beat
Ai2's Olmo-core 3 is a redesigned open training stack for mixture-of-experts models — many learned components ("experts"), each token routed through only a few. Growing the expert pool from 8 to 128 while selecting four experts per token grew capacity from 4.6B to 47B at under 5% throughput cost. A 47B MoE hit 52,000 tokens per second per GPU on eight B300s — 2.7× the earlier sharded setup — and the stack has been benchmarked at 1.2 trillion parameters across 512 GPUs. Rarer: the negative-results section — a score meant to encourage balanced routing improved while the workload became less balanced, and overlapping communication with computation sometimes made training slower. (more: https://huggingface.co/blog/allenai/olmocore3)
The Institute of Foundation Models released K2 Horizon as a fleet of six fully open models from 0.9B to 375B — weights, data, recipes, code, checkpoints, logs — with an AMA on October 5. Queued questions: why the data release was delayed, whether the lab is government-funded, when llama.cpp support lands, and the KV cache appetite that makes a similar-sized Qwen cheaper on lesser hardware. (more: https://old.reddit.com/r/LocalLLaMA/comments/1wv8zww/ama_about_k2_horizon_meet_our_team_from_ifm/)
On methods, a UW/Meta/MIT paper introduces Context Language Models, which manage their own context as a file the model can update at will (arXiv 2609.37725). Zero-shot CLMs beat state-of-the-art context management by 11.4% accuracy with 21.5% fewer FLOPs on BrowseComp-Plus and by 65% greater improvement at equal compute on a 24-hour multi-repository agent-swarm task; an online reinforcement-learning method lifted Qwen3.5-9B by 47.6% on BrowseComp-Plus with 12% fewer FLOPs. (more: https://github.com/facebookresearch/context-language-models)
And an agent loop routed circles around static retrieval: PipesHub tested 18 RAG pipeline variants — same model, embeddings, and documents — across all 824 FRAMES multi-hop questions; the best pipeline hit 78.9% while an agent loop that reads results and searches again hit 92.7%, roughly what handing it the right articles achieves. Two findings stand out: a small reranker actively cost nine points, and models fill gaps from memory even when told to stick to the retrieved documents — answers still "full of citations." Every correct answer was checked against what the system actually read, two judges agreeing at Cohen's κ 0.93–0.98. (more: https://old.reddit.com/r/LocalLLaMA/comments/1wv0lww/we_benchmarked_18_rag_pipelines_against_an_agent/)
The Harness Land Grab
Every harness vendor pitches the same thing — models replaceable, the loop the moat — and today's batch pushes the loop onto your machine. OpenHuman, a Rust-core GPL-3.0 project, was GitHub's top trending repository for nine days straight, one core driving four surfaces — Tauri desktop, browser, terminal, embeddable library — each agent with its own provider, access tier, working directory, Model Context Protocol (MCP) servers, and sandbox. The differentiator is density: agents run in-process, not as daemons, so marginal cost is about 1,985 KiB per additional agent at 50 and 1,770 KiB at 500 — 25× denser than processes. Jev sits behind the project's System One proxy for tool routing, beating BM25 62.0% to 22.5% for top-1 selection across 215 core tools plus 1,000 Composio actions; workflows flip the usual builder too — "the agent proposes the workflow; you review it on a canvas and save it." (more: https://github.com/tinyhumansai/openhuman)
iCode, an Apache-2.0 terminal agent, treats an agent as "configuration, not code" — instructions, tools, sub-agents, skills, MCP servers, and memory in one place — with a trajectory view for time and tokens per turn, per-turn rollback, and a real embedded shell. It ships no telemetry, includes no model, and puts EU AI Act obligations on the user. (more: https://github.com/openJiuwen-ai/iCode)
Overmind closes the loop from production back to training, turning OpenTelemetry traces into versioned datasets, fine-tunes benchmarked against your evals, and one inference API — "the weights are yours to download, retrain or roll back." Its MCP server exposes about 30 tools for Cursor, Claude Code, OpenCode, and Codex, each declaring its cost class, none able to delete anything. (more: https://github.com/overmind-core/overmind)
OnPanda, the on-Policy Alignment Data Annotator, works at the finest grain: hover a token, pick an alternative, continue — every part of the output editable, including reasoning and tool calls — a claimed 52% median cut in annotation time, on-policy fidelity within 1% perplexity drift. (more: https://github.com/on-panda/on-panda)
Agents as First-Class Actors
If agents are the new actors, someone must build the switchboard and write the rules. A conference pitch from Band, an agent-collaboration startup, argues that "the future belongs to AI-to-AI communication within a business, between businesses, and between consumers and businesses" — agents finding each other in self-created "conversational spaces." Its critique is specific: MCP's calling-agents-as-tools pattern is "completely stateless"; A2A is client-server, so bidirectional agents must each be client and server, with discovery outside the protocol. Connecting an agent to messaging is manual — Telegram takes five steps, WhatsApp eleven — and only links an agent to a person: "Your agent is still alone... in digital solitary confinement." The hard part is stated honestly: remote multi-agent systems are "a distributed system of microservices where each microservice is non-deterministic." The internal app built on it shows the payoff: live token-spend graphs per agent ($2,000 for a developer session, $600 for an architect) and attribution of whether a pull request was human- or agent-written. (more: https://www.youtube.com/watch?v=UOcHfR3_tys)
Regulators are writing the same rules from the other end. China's TC260, under the Cyberspace Administration of China, published AI Safety Governance Framework 3.0 in September — a reference, not binding law. Its agentic requirements are concrete: unique identity credentials and least-privilege permissions, human approval at critical decision nodes defaulting to denial on failure, red-team testing, rollback for commercial versions, AI-content labeling, six-month logs, prompt incident reporting. Warnings include models refusing shutdown, sandbagging evaluations, autonomously hacking external systems — under a first principle of "human ultimate control." (more: https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf)
Finance is where it gets literal. Bradley Leimer's "Blood Again," revisiting his 2013 "There Will Be Blood," argues the fight has moved from being the customer's Primary Financial Institution to their Primary Financial Agent. Transaction friction is dead; the remaining prize is decision friction, and an agent "doesn't need Saturday afternoon to research five savings accounts" — it can do it every morning. The line worth framing: "I don't want your agent. I want my agent to use your thing." Banks keep balance sheets, trust, and context — but when an agent acting in the customer's interest surfaces avoidable fees and better rates, customer centricity becomes an operating requirement. (more: https://www.linkedin.com/pulse/blood-again-bradley-leimer-hokfc)
AI on the Offense Beat
Today's most disciplined security writing: IOActive's account of finding real bugs with code-reasoning models — two HIGH-severity Angular CVEs, both patched upstream. The methodology: asking a model to "find all vulnerabilities" fails, returning plausible patterns with no notion of reachability. What works is building the threat model yourself, from advisories and patch diffs, distilling invariants — one-sentence rules the code assumes hold — and treating past patches as variants elsewhere. A dual-model gate closes the loop: one session proves a bug exploitable while a fresh, context-free session tries to disprove it — "a disagreement detector, not a vote." Proof is a three-run oracle — negative control, vulnerable build, fixed build — the contrast is the evidence. (more: https://www.ioactive.com/llm-assisted-vulnerability-research-finding-real-bugs-with-code-reasoning-models)
The bugs are instructive. CVE-2026-68945 came from a serializer differential: Angular's SSR transfer cache joined repeated query parameters with commas, so role=user&role=admin and role=user,admin collapsed to one cache key, serving one visitor's response — backend authorization skipped — to the next; the oracle showed two requests producing one backend call. CVE-2026-69151, a patch variant: the template compiler accepted i18n-on* attributes, letting a tampered translation file swap a benign onerror="void 0" for arbitrary JavaScript in the application's origin. The implication is attacker-neutral: "patch-diff variant farming rewards whoever moves first after a commit ships" — maintainers should run these passes before release; outsiders will run them after.
On the other side, a TROOPERS26 abstract describes "Counteroffensive AI: Pwning AI Pentesters," an attack framework aimed at AI pentesting agents. Those agents consume untrusted input by design, so the attack plants breadcrumbs where reconnaissance finds them: a backup-auth hint in a GitHub issue, SSO metadata in a profile bio. One component, HON-AI, is a fake identity provider implementing OAuth2/OIDC/SAML with Okta- and Azure AD-style endpoints, capturing credentials, client secrets, and MFA codes while returning plausible errors ("password expired," "MFA required") that encourage retries; the other, UZI, mass-sprays fake SSO references across user-generated content, canary-tagged. The economics: spray 10,000 targets once; harvest as AI pentests happen over months. Every listed mitigation fails architecturally — IdP whitelisting breaks on internal providers, human confirmation defeats the autonomy being sold — the feature is the vulnerability. (more: https://troopers.de/troopers26/talks/fb8paj)
Tooling keeps pace: vphone-cli runs a virtual iPhone on Apple Silicon via Apple's Virtualization.framework and the research VMs from its Private Cloud Compute firmware — the lineage of the super-tart writeup it credits — with pre-patched firmware, cloning, and a local automation API, SIP enabled. (more: https://github.com/Lakr233/vphone-cli)
Containment and the DNS Shortcut
Agents running untrusted code need containment, and Perplexity published a useful audit: nine models across 216 runs attacking SPACE, the Firecracker microVM platform behind Perplexity Computer, root inside the guest. VM isolation held — zero VM-to-host escapes in 108 runs, even with source access. Network confinement did not: pre-remediation, bypasses succeeded in 11 of 54 partial-network runs, four models exploiting the gap between domain-name policy and IP enforcement at the gateway. Both methods generalize: DNS spoofing — forged resolver responses mapping the allowed pypi.org to the blocked callback's IP — and IP sharing, fetching the callback via a Fastly service sharing PyPI's IP. Claude Opus 5.0 found the vector and declined — "the instructions explicitly forbid targeting other external systems" — which Perplexity calls "overly conservative." The fix pairs nftables source-address validation with TLS termination requiring whitelisted SNI, DNS-attributed to the destination IP; zero verified bypasses after. Ten third-party sandboxes tested similarly: eight susceptible, Deno also allowed unrestricted TCP, and only Cloudflare Sandbox and NVIDIA OpenShell resisted. (more: https://www.perplexity.ai/hub/blog/escaping-space-part-i)
The same mechanics, one consumer layer down: a developer wanting PS5 gameplay on Discord without a $100 capture card hijacked the console's own broadcast. The PS5 resolves Twitch's ingest servers by DNS on every broadcast, so a Mac running dnsmasq for Twitch's ingest domains — the router hands the PS5 the Mac's IP as DNS server via DHCP — redirects the 1080p60 stream to the Mac, where nginx surfaces the URL. Two details carry the security relevance: the first spoof failed because Twitch's ingest uses RTMPS with certificate validation and custom CAs cannot be installed; a YouTube detour failed because the PS5 polls the API and stops broadcasting after 60 seconds when nothing arrives. Unverified name resolution is a policy boundary, whether the device is a console or a sandbox gateway. (more: https://yashgarg.dev/posts/hijacking-ps5-rtmp-stream/)
Encryption That Underdelivers
Germany's BSI issued a quietly dramatic note on Classic McEliece, the code-based post-quantum scheme from 1978: "Classic McEliece should currently no longer be used in new developments or when planning new cryptographic applications." Use FrodoKEM, ML-KEM, or HQC instead. The reason is a year of structural attacks on mathematics stable for six decades — information-set decoding is NP-hard, barely moved in 60 years; key recovery via the support-splitting algorithm cost over 2^3000 operations. Then the cascade: a subexponential distinguisher at roughly 2^683, improvements to 2^550, and a 2026 result claiming key recovery at 2^99–2^102 for recommended parameters. The BSI is careful both ways: the newest results lack full peer review, no practical attack exists today, but a significant improvement in structural attacks is evident — further advances "conceivable and to be expected." The existing recommendation permits only hybrid use — pairing the McEliece key with a classically negotiated key so both must break — retaining classical security until the unchanged 2031 deadline. (more: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Crypto/Notes_Classic_McEliece.pdf)
The other encryption story is about keys, not math. The Stolen Thoughts team's September update audits whether the emergency mitigations OpenAI, Anthropic, and Google deployed after its reasoning-trace theft disclosure hold — a disclosure Anthropic cited when restructuring its Messages API thinking blocks, and a CISA advisory (AA26-251A) accuses China-based entities of operationalizing for industrial-scale distillation. The flaw is architectural: providers encrypt reasoning blocks with shared global keys, making blobs portable across sessions, users, and models — feed one to a weaker model in the same family and it becomes a decryption oracle, transcribing hidden reasoning verbatim. As of September 13, the replay attack still worked on Microsoft Azure for every OpenAI model tested and for Anthropic up to Sonnet 5; the scratchpad variant — telling the model to write its reasoning into a visible tool — extracted from every OpenAI model plus Opus 4.8 and Sonnet 5; only Opus 5, Fable 5, and Fable 5.1 resist. Across 152 HLE questions both attacks produced near-identical traces (Spearman 0.89, classifier AUC 0.64) — equivalent distillation material — and the conclusion is blunt: fragmented template-matching mitigations and third-party hosts unable to enforce defensive parity "effectively neutralize export controls at the API boundary." (more: https://stolen-thoughts.com/stolen_thoughts_update.pdf)
Trust as the Attack Surface
WIRED sat-down with Andrew Boyd, CEO of Paragon, spyware's self-styled ethical player. Boyd — a former director of the CIA's Center for Cyber Intelligence — admits it precisely: Paragon exerts less customer oversight than NSO Group. The documented record: founded in 2019 by a former Unit 8200 commander and former prime minister Ehud Barak, among others; bought for $900 million by US equity firm AE Industrial Partners in December 2024 and merged with its offensive cyber firm REDLattice — American on paper, Israeli export licenses for Paragon, ITAR for REDLattice.
Weeks after that merger, WhatsApp alleged Graphite infected 60-plus people in over 20 countries, journalists and activists among them; Citizen Lab identified two journalists and two activists in Italy. Paragon canceled the Italian contracts; no investigation ever occurred, Boyd says — Italy was "fired" because it "just was not worth it, from a risk perspective." The core admission is structural: Paragon cannot detect misuse because it cannot see who customers target; it has no kill switch, only the ability to halt support and updates — without them, systems fail within roughly 12 hours. Customers may enable logs, but Paragon has no access — unlike NSO, which claims a kill switch and contractually mandated tamper-proof logs. Graphite pulls communications from encrypted apps like WhatsApp and Signal via zero-click exploits, per WhatsApp and Citizen Lab. Citizen Lab's John Scott-Railton calls the lack of mandatory logging "reckless" — "Accountability is bad for business" — and Senator Ron Wyden calls the refusal to audit "a massive red flag." (more: https://www.wired.com/story/the-secrets-of-the-us-spyware-king)
The same problem in consumer form: Huntress documented malicious Custom GPTs hosted on chatgpt.com — named "Plus 5.6," passable as an official release — that answer any prompt with "service unavailable" and offer a "backup" Google Sites link to a fake Cloudflare page whose ClickFix prompt says to paste a PowerShell command. The command downloads an MSI that abuses a Canon-signed application to sideload DLLs; one extracts an encrypted loader from a WAV file, unpacking a RAT in memory. Huntress's SOC has responded to at least 40 incidents tied to the domain, two via the Custom GPT itself. Principal analyst Jonathan Semon's framing is correct: every domain in the chain is legitimate, so training must shift from "check where it came from" to "check what it's asking you to do" — no legitimate site or chatbot asks you to paste a command into PowerShell. In some incidents, victims clicked a sponsored Google result and landed on the real chatgpt.com — a small "community builder" label the only tell. (more: https://www.darkreading.com/cyberattacks-data-breaches/malicious-custom-gpts-chatgpt-rat-delivery-lure)
Sources (24 articles)
- Amazon Unveils Strands Decider 2B: Free, Fast, Open-Source Decision Model (venturebeat.com)
- Mapika/decider on GitHub (github.com)
- nokia-applied-research/AnyJev (github.com)
- llama, server: add /v1/systemone API (models: laya, julia-1, lev, openjev, kev) by ngxson · Pull Request #29818 · ggml-org/llama.cpp (old.reddit.com)
- Introducing Olmo-core 3: Open, scalable training infrastructure for large MoEs (huggingface.co)
- AMA about K2 Horizon, Meet our team from IFM (old.reddit.com)
- facebookresearch/context-language-models (github.com)
- We benchmarked 18 RAG pipelines against an agent loop on Google's FRAMES. The best pipeline hit 78.9%. The agent loop hit 92.7%. (old.reddit.com)
- tinyhumansai/openhuman (github.com)
- openJiuwen-ai/iCode (github.com)
- overmind-core/overmind (github.com)
- on-panda/on-panda (github.com)
- Editorial Video Pick (YouTube) (youtube.com)
- Cyberspace Administration of China: AI Regulatory Document (PDF) (cac.gov.cn)
- Bradley Leimer: Blood Again (LinkedIn) (linkedin.com)
- IOActive: LLM-Assisted Vulnerability Research — Finding Real Bugs with Code-Reasoning Models (ioactive.com)
- TROOPERS26 Talk: AI and Offensive Security (Conference Session) (troopers.de)
- vphone-cli: Virtual iPhone from the Command Line (github.com)
- Perplexity: Escaping Space, Part I (perplexity.ai)
- Hijacking the PS5's RTMP stream (yashgarg.dev)
- BSI Notes on Classic McEliece (Post-Quantum Cryptography) (bsi.bund.de)
- Stolen Thoughts: Research Update (PDF) (stolen-thoughts.com)
- Wired: The Secrets of the US Spyware King (wired.com)
- Dark Reading: Malicious Custom GPTs Used as RAT Delivery Lure (darkreading.com)