The United States and China have agreed to open a formal channel to flag dangerous artificial intelligence (AI) activity, including runaway agents, cyberattacks and bioweapons development, marking the first such effort by the world’s two largest AI powers.
US Treasury Secretary Scott Bessent unveiled the plan after an eight-hour meeting with Chinese Vice Premier He Lifeng in New York on Sunday, ahead of a summit between President Donald Trump and Chinese leader Xi Jinping from Wednesday to Friday.
The meeting came weeks after several of the industry’s biggest AI companies publicly called for a slowdown in frontier AI development, warning that safety risks, including a run of agentic AI incidents, were outpacing the world’s ability to govern them.
“What we discussed was setting up a mechanism, so it’s going to be called the US-China AI Dialogue,” he told the media after the meeting. “We think that, just like with any cross-border activity, moving from opacity to more transparency between the number one and the number two AI powers in the world is very important.”
He said the US and China will notify each other of AI incidents that could rise to the level of a national security threat and also open a direct communications line for such incidents. The two sides agreed to meet again in Shenzhen in about two months to discuss AI guardrails.
“We want to start discussing protocols so both sides can agree on what the leading AI dangers are, whether it’s uncontrollable agents, whether it’s non-state actors in cyber or non-state actors in bio weapons,” Bessent told CNBC in an interview on Monday.
He said he raised AI incident reporting directly with his Chinese counterpart, telling him that China has almost certainly had its own AI incidents.
“Have they had incidents? Of course, they’ve had incidents, but because of the nature and the lack of transparency in their system, they’re not going to tell us,” he said. “But the Chinese models are very powerful, even though they’re open models. They are very powerful.”
He said the US remained ahead in AI development, and that he had received clear acknowledgment of that from his Chinese counterpart.
The meeting came weeks after several of the industry’s biggest AI companies publicly called for a slowdown in frontier AI development, warning that safety risks, including a run of agentic AI incidents, were outpacing the world’s ability to govern them.
Several high-profile cases of AI agents behaving this way have been made public in the United States this year, including:
In November 2025, Anthropic disclosed that a Chinese state-sponsored hacking group had manipulated its Claude Code tool into running 80% to 90% of an espionage campaign against about 30 organizations largely without human help.
In July, nearly 700 autonomous agents built on OpenAI’s own model swarmed Hugging Face, breaching dozens of servers before the model was quarantined.
Also in July, xAI’s Grok Build coding agent was found to be silently uploading users’ Secure Shell (SSH) keys, password databases and files to company servers, prompting technology guru Elon Musk to delete the data and open source the tool.
US technology executives are also increasingly open about their own experiences of agentic AI going wrong. Summer Yue, director of alignment at Meta Superintelligence Labs, said in February that her own AI agent, OpenClaw, deleted her entire email inbox and ignored her repeated commands to stop, forcing her to physically shut down her computer.
Bessent said American AI labs estimated a 10% chance of an AI-driven human extinction event, but they then asked to be shielded from liability. He said the government would not take responsibility if AI labs made a mistake, and that they were free to slow down anytime they wanted to.
He cited MIT Schwarzman College of Computing dean Daniel Huttenlocher’s view that humans, not AI, are responsible, pointing to the Hugging Face incident as an example.
His comments echoed Trump, who dismissed AI safety warnings as a “hoax” in a series of Truth Social posts on September 14.
When internet users search for dangerous AI activity on Baidu, results point to cases of human employees mistakenly uploading confidential data to AI platforms, with a footnote citing national security rules as the reason fuller details and case names are not public.
In July, China’s Ministry of State Security posted on its social media account urging government staff and academic researchers not to upload confidential documents to AI systems.
“A man surnamed Li is a researcher at a scientific research institution. While drafting a report, he used an AI application for convenience and uploaded core data and experimental results as writing material without authorization, leaking classified information from the field. Li was later severely punished,” the ministry said, citing one such case.
Chinese media have, however, reported cases of AI agents leaking commercial secrets or personal information, including:
In April, Moonshot AI’s Kimi chatbot mistakenly sent a job seeker’s private resume, containing their name, phone number and email, to an unrelated user, blaming the leak on a “hash collision compounded by AI hallucination,” prompting a wave of users to delete their accounts.
In September, Zhipu’s ZCode coding tool was found to have silently uploaded users’ entire codebases, including git histories and cached files, to cloud servers even with privacy mode switched on, exposing one firm’s source code and security keys before Zhipu apologized and pledged to delete the data.
AI-made bioweapons
While US intelligence agencies continue to debate whether the Covid-19 coronavirus originated, or was even engineered, in a Wuhan laboratory, AI-designed viruses have recently made media headlines.
In August, a Stanford-led team used an AI model called Evo to design and synthesize 16 new bacteriophage viruses, published in the journal Science. The viruses infect only bacteria, and the model’s training excluded human and animal virus data.
This month, Anthropic’s 154-page threat report detailed five cases of state-linked researchers using its Claude models for dual-use biological research before Anthropic banned the accounts.
“China puts equal emphasis on development and security in terms of AI. We take seriously the inherent and secondary risks of AI,” Foreign Ministry spokesperson Guo Jiakun said at a regular media briefing on September 15. “We are committed to holding on to the bottom line of security, and we have been making continued efforts to improve laws and regulations, policies, application norms and ethical rules to prevent the abuse and misuse of AI, and ensure that AI is safe, reliable and controllable.”
China released its AI Safety Governance Framework 3.0 on September 14. Unlike its two predecessors, the non-mandatory framework focuses for the first time on the risks posed by autonomous AI agents, alongside open-source and supply chain safety.
“AI significantly lowers the threshold for acquiring expertise in nuclear, biological, chemical and missile weapons and other high-risk fields,” the framework states. “Combined with retrieval-augmented generation capabilities, if not effectively controlled, this could be maliciously exploited by criminals, extremist forces or terrorists to break through existing control systems and escalate threats to peace and security in regions around the world.”
The framework calls for strictly screening training data to keep out sensitive information on such weapons, and for stronger controls at the source, including user authentication, to stop AI from being used to help build them.
The Bessent-He talks followed a meeting the two sides held in Beijing in May. Officials discussed the details of waiving extra tariffs on up to US$30 billion of bilateral trade, with the US side offering more agriculture and energy exports and the Chinese side offering more medical devices and everyday consumer goods.
California settles lawsuit against Paramount/Warner merger, angering advocates
California and Paramount Skydance have reportedly reached a settlement allowing the company to complete its $111 billion merger with Warner Bros. Discovery. The settlement, which will reportedly be announced later today, drew condemnation from Democrats and media advocates.
“The Paramount/Warner Brothers merger seems facially illegal, and the state AG lawsuit challenging it is very strong,” Lina Khan, who chaired the Federal Trade Commission during the Biden administration, wrote yesterday. “It’s troubling to hear that the states may now settle for behavioral remedies, allowing the deal to go through subject to various promises from the firms. Behavioral remedies routinely fail, and the stakes here are particularly high given that a strong democracy requires open markets for sound journalism and creative expression.”
After news of advanced settlement talks was reported over the weekend, Bloomberg reported today that Paramount reached an agreement with California and other states that sued to block the merger. “Settlement talks came to fruition over the weekend after four states that had opposed terms of a deal outlined with California conceded,” Bloomberg wrote, citing a person familiar with the matter.
The New York Times reported the deal a bit later, saying that “four people familiar with the negotiations” confirmed it. The settlement was also confirmed in a Wall Street Journal report that said “the combined company is set to emerge with nearly $80 billion in debt—a substantial burden already expected to weigh on its investments in the business.”
Advocates unhappy with California AG
Media advocacy group Free Press criticized California Attorney General Rob Bonta. “We are disappointed that Attorney General Bonta went back on his promise to enforce the law and protect consumers and workers,” Free Press co-CEO Jessica J. González said. “Hundreds of thousands of people called on our state AGs to stand up to the Ellisons, who have engaged in a campaign of corruption and extortion to pave the way for this unlawful merger.”
John Bergmayer, legal director at advocacy group Public Knowledge, said the settlement “does not address the central problem with this merger: the loss of competition. This merger leaves fewer studios competing for scripts and talent, gives one company greater power to dictate terms to distributors, and reduces streaming choices. Consumers will face higher prices, while writers and other creative workers will have fewer employers bidding for their work.”
According to Bloomberg, the Paramount/California deal was initially opposed by Massachusetts, New York, Connecticut, and Minnesota. But the state attorneys general “ultimately concluded the expense of the legal battle was not justifiable without California at the helm,” the report said.
“The states that held out longer did succeed over the past week in securing independent editorial boards for CBS and CNN as part of the deal,” Bloomberg’s report said. Paramount reportedly also agreed to terms that “include a financial penalty if the company fails to make good on a promise to distribute 30 films per year in theaters.”
Update: Bonta confirmed the settlement in a press release on Monday, and the proposed settlement was submitted in court for a judge to review.
“Oversight committee won’t save CNN”
González said that “a fake bipartisan oversight committee won’t save CNN. We have all the evidence we need from the Ellisons’ destruction of CBS about what they do to warp journalism at Donald Trump’s request. This latest capitulation comes as the Trump administration barred CNN and other reporters who dare ask hard questions from the White House press pool.”
Bergmayer said that “independent editorial boards for CBS and CNN may be better than nothing,” but “are far short of actual independence. The states were right to challenge this merger after federal enforcers failed to act. They should insist on a settlement that preserves competition—or wait for their day in court.”
Netflix originally had a deal to buy Warner Bros. but backed out after it became clear the Trump administration preferred Paramount. Paramount CEO David Ellison reportedly wooed Trump administration officials with a promise to make big changes at the Warner-owned CNN.
Trump’s Justice Department approved the deal in June. The Federal Communications Commission last week allowed Paramount to finance the merger by selling large equity stakes to the sovereign wealth funds of Saudi Arabia, the United Arab Emirates, and Qatar.
States’ lawsuit was going well
Twelve states led by California sued to block the deal in July and were able to delay the merger’s completion when a federal judge ruled that the combination would likely reduce competition substantially and violate antitrust laws. The deal will let Paramount combine two of the largest movie studios, merge streaming service Paramount+ with HBO Max, and take ownership of CNN and other TV channels.
Bonta alleged in July that “the unlawful merger of these two entertainment behemoths would lead to higher prices, lower quality, and less content for film and television, harming movie theaters, basic cable distributors, and ultimately, audiences on every sofa and movie theater seat in the US.”
Democratic lawmakers who oppose the deal had been pinning their hopes on the California lawsuit. “Paramount, run by the Ellisons, should not own both CBS and CNN. California must not cave and take a deal that leaves both under the same owner,” US Rep. Ro Khanna (D-Calif.) wrote Saturday.
US Rep Jamie Raskin (D-Md.) urged state attorneys general to “hang tough” against the merger. “At a time of massive economic concentration, accelerating monopoly and growing MAGA political capture of America’s media institutions, we need the state AGs to vigorously defend antitrust principles and freedom of expression,” he wrote.
Florida Couple Struck by Lightning While Walking Hand in Hand
A Florida couple says four strangers were in exactly the right place at the right time after a lightning strike turned an ordinary evening walk into a desperate fight for survival.
Aaron Walenga, 48, and his wife Clare Walenga, 43, were walking hand in hand along the West Orange Trail in Winter Garden on Sept. 2 after dropping their children off at a church youth group when lightning suddenly struck them.
The couple, who have been married for 17 years, told local reporters they had noticed a storm elsewhere in the area but did not remember seeing lightning or hearing thunder immediately before the strike. According to a report cited by WESH, the lightning apparently struck their umbrella before both collapsed on the trail.
Aaron landed face-first and said he temporarily could not move his arms or legs.
“I wanted to get to Clare, and I just couldn’t get up,” he recalled. “I couldn’t really move.”
Clare was in even more serious trouble.
Nearby runners Amber McManus, Charlotte Sachetti Weyand, Michael Sachetti Weyand and Tiffany Roby rushed toward the couple after hearing the blast and seeing them on the ground.
Witnesses said Clare was not breathing and had turned blue. Michael Sachetti Weyand began CPR despite having never performed it on a real person before.
He continued chest compressions until Clare suddenly took a large breath.
Winter Garden police officers and emergency crews arrived moments later. Body-camera footage released by the Winter Garden Police Department shows officers tending to Aaron as bystanders continued helping Clare.
Both Aaron and Clare were taken to Orlando Regional Medical Center in critical condition, according to subsequent reports. Clare suffered a concussion and short-term memory problems, while Aaron suffered facial injuries after hitting the ground. Both have since made major progress in their recovery.
The couple later reunited with the people who helped save them.
“There were so many miracles that we witnessed from Clare being brought back to life to the four of you being there on that trail at that time,” Aaron said.
Clare added that the ordeal had changed the way she looks at everyday life.
“This gift of life that we have is just so beautiful,” she
Imran Khan’s Sister Detained as Pakistan Tightens Security Ahead of PTI’s Islamabad March
Pakistan’s Punjab authorities on Sunday ordered the detention of Aleema Khan, sister of Pakistan Tehreek-e-Insaf (PTI) founder and former Prime Minister Imran Khan, for 30 days.
She was arrested in Lahore and subsequently sent to jail.
According to the official detention order, the matter was considered at a meeting of the District Intelligence Committee held on September 20, where the committee unanimously recommended her detention and that of her driver, Muhammad Amir, after reviewing material and evidence provided by police.
According to the police report cited in the detention proceedings, Khan and Amir had incited PTI workers during the May 9 protests and road blockades to damage government and public property. The report further alleged that they continued to mobilize party workers through social media and public gatherings.
The detention comes ahead of a PTI protest march toward Islamabad scheduled for September 27. The party has urged supporters from across Pakistan to travel to the capital and, according to PTI, is organizing the march over concerns about Imran Khan’s solitary confinement and what it describes as his deteriorating health.
Lahore Deputy Commissioner Muhammad Ali Ejaz, exercising powers under Section 3 of the Punjab Maintenance of Public Order Ordinance, 1960, ordered that Khan and Amir be detained for 30 days. The order states that both will be held at Central Jail Kot Lakhpat in Lahore.
The order further states that both individuals have the right to file an application or make a representation to the provincial government against the decision.
Security measures have been stepped up in Islamabad ahead of the planned protest, while authorities have also launched a crackdown on PTI workers in several parts of the country.
Earlier this month, authorities in Rawalpindi issued detention orders against PTI workers ahead of the planned march.
PTI has condemned Aleema Khan’s arrest outside her residence, describing it as illegal.
In a statement issued by its central media department, the party said Khan was arrested because she had been speaking out against the imprisonment of her brother, his alleged solitary confinement and what it described as the denial of adequate medical facilities to him.
PTI alleged that the arrest was an act of political retaliation rather than a legal measure, claiming that its purpose was to further aggravate the situation and provoke a reaction. The party also accused the government of invoking law and order concerns to defend its position.
The party called for Aleema Khan’s immediate release, disclosure of her whereabouts and her safe presentation before a court. It also demanded an end to what it described as a campaign of harassment against Imran Khan’s family.
PTI warned that the government would be held responsible if Aleema Khan was not released immediately.
The party’s Central Punjab spokesperson, retired Brigadier Mushtaq, separately condemned the arrest and claimed that a large number of PTI workers had also been detained as part of the crackdown.
Saudi Arabia wants a car industry, launches Ceer with two EVs
KING ABDULLAH ECONOMIC CITY, Saudi Arabia—It may come as a surprise to some, but Saudi Arabia has never had a domestic automaker. That changes with Ceer. A joint venture between the country’s Public Investment Fund and Foxconn, it’s the Kingdom’s first home-grown automaker and a significant part of Saudi Arabia’s Vision 2030 plan to diversify its economy away from oil production and bring technological innovation locally by the end of the decade.
Ceer in Arabic means to “drive forward,” and this forward-looking approach applies to the vehicle lineup. The flagship vehicles you see here—the Exobot sedan and SUV—are demonstrations of what the company is capable of and the vision it sees for future vehicles in the portfolio.
It plans to have seven new cars in its portfolio by 2030—some of which will be hybrids—and while that doesn’t currently include sales outside the GCC (Gulf Cooperation Council) region, Ceer says it’s building a competitive, world-class product and that if the demand is there, expansion is possible.
A flagship shouldn’t be boring, and Ceer met that brief. Both SUV and sedan would look at home in Westworld. The SUV had something familiar about it, and Ars auto editor Jonathan Gitlin said it reminded him of the Isuzu VehiCross. Maybe this is a modern-day interpretation of that vehicle? After seeing the SUV in person, I can tell you I can’t unsee that reference.
The Exobot sedan.
Chad Kirchner
The Exobot sedan. Chad Kirchner
Yes, that’s a yoke.
Chad Kirchner
Yes, that’s a yoke. Chad Kirchner
The sedan is a four-seater.
Chad Kirchner.
The sedan is a four-seater. Chad Kirchner.
Yes, that’s a yoke. Chad Kirchner
The sedan is a four-seater. Chad Kirchner.
Both vehicles have falcon doors, called a Shahin Wing here, to get in and out of the vehicle. The doors add to the drama befitting a flagship for a startup automaker and will certainly draw attention out on Saudi roads. The doors don’t open wider than a standard car door, so it shouldn’t be much of a challenge in a tight parking lot. As long as the roof isn’t too low, presumably.
Not having a B-pillar makes access to the second row much easier, but I’d be surprised if those doors appear on any of the future cars the company is planning to build. The region’s extreme climate will certainly put the engineering of the doors to the test.
Push-button for more visibility
One unique feature of the doors is built into the glass. The lower portions of the door feature electrochromatic glass that can be dimmed at the press of a button. Especially useful in the SUV: If the driver needs more side visibility, the lower part of the door becomes clear at the push of a button.
During the reveal presentation, Ceer CEO James Deluca mentioned that during an early briefing on design, the Crown Prince inspired the team to look at what is already out there and take a different path. “If the world goes left, we go right,” he quoted the Crown Prince as saying.
Other design details call out Ceer’s national heritage. Both models have 32 independent elements in the front and rear light bar. Thirty-two, because 1932 was the year the Kingdom of Saudi Arabia was established.
Inside, a 48-inch digital instrument cluster stretches across the entire dashboard, running a custom infotainment system that is inspired by the Riyadh skyline. To help deal with the extreme climate of the Kingdom, there’s a new cooling mode for the cabin that creates a cool air barrier between the roof and the glass and the passengers’ heads that the company calls Halo cooling.
A 10-inch center cluster handles media controls, and there’s an 8-inch screen for rear passengers. Ceer believes in bringing your own device, and the vehicle should be able to integrate with a mobile phone. In an interview with Ars Technica, Chief Technology Officer Markus Leitner confirmed that Apple CarPlay and Android Auto will be available at launch. The infotainment system is unique Ceer intellectual property co-developed with Foxconn and the other partners. Of course, over-the-air updates will be available that can improve any aspect of the vehicle, including performance and range.
Doors add to the spectacle.
Credit: Ceer
Doors add to the spectacle. Credit: Ceer
Despite all of the touchscreens and technology, Ceer is emphasizing physical controls where it makes sense. The gear selector is on the column, like on a Mercedes, or all manner of machines from Detroit. There are physical buttons for changing the climate control and adjusting the volume. It’s almost like the executives at Ceer are paying attention to our complaints.
The launch model Exobots will have a 112-kWh battery pack with over 310 miles (500 km) of range for the SUV, and at least 373 miles (600 km) for the sedan under the New European Driving Cycle (ironically an old standard that has since been replaced by WLTP in Europe). In the real world, 300–400 miles seems like a reasonable expectation, which would put it on par with the latest BMW and Mercedes platforms.
Performance is the main goal of these vehicles, and with 1,111 hp (828 kW) and 1,100 lb-ft (1,500 nM) of torque, the Exobot should be able to hit 62 mph (100 km/h) in a hair over 2 seconds for the sedan, and 2.4 seconds for the SUV, with the standing-quarter dispatched in 10 seconds.
A tri-motor setup with torque vectoring has been chosen to deliver the power to the wheels to reach those numbers. Available air suspension should smooth out any of the rough terrain.
The vehicles will use an 800 V electric architecture, and the company is quoting a DC fast-charging time of around 30 minutes to 80 percent. Based on the size of the battery pack, that’s on par with what we’ve experienced from vehicles like the Kia EV9 and the Hyundai Ioniq 9.
The 800 V system also powers the vehicle’s steer-by-wire system. Does that mean it’s getting a yoke? Yes. But from my experience in the Lexus RZ with a similar setup, I appreciated the sharper steering and more precise control that comes with the setup, even if it took a little getting used to. I didn’t care for the yoke itself, and I can’t see the one in the Exobot winning me over, but it can be done pretty well if done properly. The Tesla Cybertruck is a good example of when it’s done poorly.
What is clear is that Ceer from the start developed these vehicles to be quickly homologated for global markets, including Europe and maybe even North America. That’s no guarantee, but it does mean it’s fair to compare these vehicles to the best of what the rest of the world is doing regarding EVs. To that end, I asked Leitner what he thought makes Ceer stand out.
The lower halves of the doors can be turned transparent.
Chad Kirchner
The lower halves of the doors can be turned transparent. Chad Kirchner
Will Ceer’s next cars be more conventional-looking?
Chad Kirchner
Will Ceer’s next cars be more conventional-looking? Chad Kirchner
The lower halves of the doors can be turned transparent. Chad Kirchner
Will Ceer’s next cars be more conventional-looking? Chad Kirchner
“Everyone has triple motors,” Leitner said. “Everyone has torque vectoring. Everyone has air suspension. What we do better than anyone else is integrate that all together to provide the best driving experience.”
Ceer models will be built at a dedicated complex in the King Abdullah Economic City just north of Jeddah, and suppliers will also be stationed nearby. If all goes to plan, Ceer expects 35,000 direct and indirect jobs to be created by 2034.
Will this be successful or will it be the next Fisker?
With the direct backing of Saudi Arabia’s Public Investment Fund, the financial resources are certainly available for success. Unlike Lucid, the PIF is the owner of Ceer and not just an investor, for one thing.
And the state wants to use its investment to create jobs locally, and not just at Ceer. In the United States, for every one automotive job, there are five additional jobs created in the local economy, when you factor in the suppliers and related support systems needed to run a car company.
Deluca spent a lot of time at General Motors in manufacturing, so he knows how to build cars, and much of the leadership team has experience with GM, Magna Steyer, or other deeply established legacy automakers. Deluca also spent time at VinFast, and while it may not have taken off in the United States, that company’s startup, building gas cars, and then pivoting to EVs happened lightning-quick. To hit the lineup targets, a similar approach will be needed here.
Ultimately, the success will depend on how Saudi car buyers take to the products. The company admits these two products are aspirational, as they are an entirely new industry for the country. But what will matter is the upcoming more mainstream models, their affordability, and how well they compare to the offerings already on sale in Saudi Arabia, which are Chinese brands.
One additional factor to consider is that, as part of the Vision 2030 plan, Saudi Arabia is encouraging products to be made locally for the domestic market. This manifests in a “Saudi Made” branding initiative. Many products, including the Coke Zero I’m drinking while writing this story, carry a logo and a Saudi Made badge. When it comes to Ceer, the country will have a completely home-grown alternative to the established automotive brands, including even Lucid, that they’ll be able to buy from that will directly support local manufacturing and the economy.
If this sounds a bit familiar, it’s something that GM, Ford, and the North American arm of Stellantis spend a lot of time emphasizing. While Americans have had a local automaker for nearly as long as the automobile has existed, this is a new experience for Saudis. Ceer is more than just a car, but a point of pride for the Kingdom. While I can’t say for sure if Ceer will be successful, they do seem to have the basics figured out.
UN condemns continued Houthi attacks on Saudi Arabia, urges restraint
UN spokesperson Stephane Dujarric moderates a press conference as Secretary-General Antonio Guterres answers the questions of UN press at the UN Headquarters on Wednesday ahead of the UN General Assembly high-level week on September 16, 2026, in New York City, U.S. [ Selçuk Acar – Anadolu Agency ]
The UN reiterated Monday its condemnation of persistent cross-border attacks launched by Yemeni Houthis against Saudi Arabia, including attempted strikes aimed at Riyadh, Anadolu reports.
“We remain deeply concerned about the ongoing military escalation in and around Yemen, including Houthi offensives in Taiz, Lahij, and Marib, with grave consequences for civilians in Yemen and across the region,” UN spokesperson Stephane Dujarric told reporters.
Dujarric explained that the cross-border strikes have targeted civilian areas and vital energy infrastructure across the kingdom, urging all parties to “exercise restraint and prevent any further escalation.”
Recent cross-border Houthi attacks have injured civilians in southern Saudi Arabia, while renewed fighting has disrupted shipping routes and displaced civilians inside Yemen.
Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day
Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant Muse, claiming it is “built from the ground up for privacy and security.” A zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises serious doubts. Further raising questions, Amazon on Sunday began blocking Muse from its site.
Meta introduced Muse a few weeks ago. The assistant “books appointments, fills out forms and handles customer service,” “proactively takes tasks off your plate,” and can “make purchases, generate images, create documents, and connect with your favorite apps and services.” The macOS app (curiously, there’s no Windows version) also works with a user’s WhatsApp, email, calendar, and social media accounts. When a task requires a tool that doesn’t exist, Muse creates one on the fly.
Meta doth hype Muse security too much
Of course, for Muse to do any of these things, users must first give it access to their accounts. This includes authenticating the assistant to each service and, because the app runs on macOS, giving it permissions to a broad range of operating system-restricted device resources like writing files to disk, accessing the mic and camera, and monitoring location and calendars. Apple has spent years developing these defenses to prevent installed apps or commands entered into the terminal from accessing these resources, clearly because the company considers them a security threat. Muse completely undoes these default measures.
The zero-day allows any app or terminal command to gain access to the token that authenticates users to their Muse account. Meta developers designed the assistant so that any locally installed app or executed code, regardless of the macOS permissions it has, can change a long list of undocumented settings. Most of them are fairly innocuous, such as controlling dark mode. One setting, however, is anything but innocuous. It allows processes to change the endpoint where transcription occurs. Normally, it’s a server address operated by Meta. Attackers can exploit this flaw by changing the location to their own endpoint. Once that happens, the attackers have the token that gives complete control over the Muse account.
“We can manipulate the agent and leverage its privileges to do whatever we want,” Patrick Wardle, the macOS security expert who discovered the zero-day, told Ars. “So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.” Wardle said he has developed several proof-of-concept attacks that do things like writing malicious files to disk and snapping pictures, in many cases with no indication to even an alert user.
Meta representatives didn’t answer emailed questions.
Meta has published twoposts in as many weeks documenting the design decisions that went into ensuring an assistant with such extraordinary access to user data and resources is secure and private. The posts come amid revelations that internal testing of models from Anthropic and Google has resulted in security breaches of external, third-party networks that the engineers involved never intended to target. In traditional human-only hacking, these actions could likely result in the filing of criminal charges. The Meta posts are likely mindful of the resulting blowback and the calls to slow down AI development in response.
Wardle said that Meta developers made several design decisions that made his exploit possible. One is the choice for Muse dictation to occur in the cloud, where Meta can log it. macOS has long provided a simple means for apps to handle dictation and transcription in processes that stay securely on the device. Had the developers chosen this safer alternative, the attack wouldn’t have been possible.
Another flawed decision is for any app to control all of the undocumented settings. It’s likely Meta intended for apps working with Muse to control UI settings, and for understandable reasons. The ability for any app or command to control an endpoint where sensitive user speech is processed is an entirely different matter. Together, the design decisions raise questions about just how much effort developers put into designing and testing the security and privacy of the new assistant.
“To me, the bar is infinitely higher in terms of the security of these apps. They don’t have to be perfect, but when you take a look at Muse, it’s like they didn’t, in my opinion, think about security, which is really worrisome,” Wardle said. “At the very least, they should be thinking about security from the very start, and they are just not.”
Roughly 12 hours before Wardle disclosed the zero-day, Amazon started blocking people from using Muse to shop on the site. Users who tried received a message saying Muse was an “unauthorized AI agent [that] violates Amazon’s Conditions of Use.”
“We think it’s fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate,” Amazon said in an emailed statement. “This helps ensure a safe, secure, and reliable customer experience, and it is how others operate including food delivery apps and the restaurants they take orders for, delivery services apps and the stores they shop from, and online travel agencies and the airlines they book tickets with for customers. Agentic third-party applications such as Muse have the same obligations, and we’ve requested that Meta remove Amazon from the experience.”
A single ClickFix is all it takes
There are several ways for attacks to work. One is for an attacker’s server to act as a proxy that’s placed between the Muse user and Meta endpoint. Once the user enters the voice prompt, the attacker’s server adds a prompt invoking a malicious command, such as sending an archive of all WhatsApp messages to the attacker. Once that happens, the attacker gains permanent control over the Muse account because the token is automatically sent to the malicious server as well.
Wardle is the creator of the Objective-See Foundation, a nonprofit focused on macOS security. He is also the author of the “The Art of Mac Malware” book series, and a former employee of NASA and the National Security Agency. Wardle said he plans to discuss the vulnerability in more detail and other AI assistant threats at the Objective by the Sea security conference in November.
One of the counterarguments raised by developers of apps that can be exploited once a device is compromised is that once that happens, all security bets are off. This standard doesn’t fit well in this case. Wardle found that a simple variation of ClickFix attack—a technique that has become remarkably effective in tricking people into infecting their devices—is all that’s required for an attacker to take control of a Muse account.
Credit: Patrick Wardle
Credit: Patrick Wardle
Credit: Patrick Wardle
Credit: Patrick Wardle
In the first image above, Wardle can be seen using a simple terminal command to surreptitiously send a prompt to the Meta endpoint. The second image shows the response. To prevent attackers from cutting and pasting the prompt in live attacks, Wardle’s prompt asks only how it’s possible it’s coming from an unprivileged attacker. Muse incorrectly responds that such an action isn’t possible.
As already noted, the extraordinary access Muse requires to work as intended places an additional burden on its designers. Like most such AI agents—and contrary to Meta’s claims—Muse can’t be trusted. It’s not clear when or if it ever will.
Immigration Roulette: Husband Granted Asylum, Wife Locked Up Awaiting Deportation
An Iranian couple seeking refuge in the U.S. has been separated for nearly two years after separate immigration judges issued sharply diverging rulings on their nearly identical asylum applications.
Mohammadjamal Azizi and Hannaneh Alikaram requested asylum after arriving in the United States in late 2024, for fear of the persecution they would likely face as Christian converts in Iran, where they had twice been arrested due to their faith.
Since arriving in the U.S., they have faced sharply different versions of American justice, the result of a process advocates refer to bitterly as “immigration roulette”: Azizi — who goes by the name Liam — has been free for more than a year, after his asylum claim was granted, while Alikaram has suffered 21 months in detention, more than a year of that coming after her claim was rejected.
Until recently, it is likely that Alikaram would not have spent nearly as much time in detention as she has. But amid the twin agendas of mass detention and mass deportation, the Trump administration has swept aside years of precedent by locking up people who would previously have been allowed to fight their cases from outside detention, while going after communities formerly protected from deportation due to the likelihood of persecution back home.
Iranians have found themselves the crosshairs. Last year, amid the so-called 12-Day War between the U.S.–Israel and Iran, senior officials with Immigration and Customs Enforcement launched a scheme to begin deportations to Iran, a plan that resulted in three planes full of Iranian deportees being sent back to Iran on charter flights.
Those flights were suspended earlier this year after the U.S. and Israel launched the ongoing war on Iran, but multiple Iranians with final orders of removal have been deported to countries where they have no ties, including Panama and the Central African Republic. With so-called third-country flights leaving every month or so, Azizi and his wife live in constant fear that Alikaram might be put on a plane to a country where she knows no one and from which she has little hope of escaping.
Leaving detention after seven months, Azizi headed to the Iranian American hub of Los Angeles, where he has spent the past year working any job he can find to raise money for legal bills and fighting for his wife’s release. By the logic of the U.S. immigration system, that should be a simple prospect: As the spouse of an asylee, Alikaram is eligible for a status known as derivative asylum, a process intended to ensure family unification and act as a backstop against situations like the one in which Azizi and Alikaram find themselves, according to Carmen Maria Rey Caldas, a former immigration judge fired by the Trump administration last year.
“This is your money and my money that are being wasted in detaining this woman who is unquestionably eligible for asylum.”
“The person gets to have derivative asylum because family unity is a central tenet of our immigration system,” said Rey Caldas. “This is your money and my money that are being wasted in detaining this woman who is unquestionably eligible for asylum as the spouse of an individual that has been granted asylum.”
The couple currently has a petition for derivative asylum before U.S. Citizenship and Immigration Services and have filed a petition for habeas corpus seeking to secure Alikaram’s release on the basis of prolonged detention. Amid the uncertainty, with no end in sight to his wife’s detention, Azizi said their separation — and his feeling of helplessness in the face of bureaucratic cruelty — weighs on him daily.
“Being separated from Hananneh is unbearable,” Azizi wrote in a statement to the court filed earlier this year. “Every night I go to sleep wondering if she is safe in detention. Every day I wake up with anxiety that she might be taken away from me and sent back to a country where she could be imprisoned, tortured, or even killed just because she sought freedom.”
Azizi and Alikaram married in 2018 and lived together in Isfahan, Iran, where both had gone to university. Azizi worked as a software engineer, while Alikaram ran a greenhouse business, cultivating plants and posting playful videos to YouTube in which she coached plant lovers on topics ranging from prepping plants for autumn to guarding against pests. In the videos, which include jokey, spliced-in clips from “Lord of the Rings” and Miyazaki films, Alikaram comes across as a happy young woman enamored with the natural world.
The couple found their way to Christianity first through friends, members of Isfahan’s sizable minority of Armenian Christians. Christians have lived in Iran for more than a millennium, and Iran’s constitution affords protections allowing ethnoreligious communities, most notably Armenians and Assyrians, to practice their faith and organize their families and communities accordingly.
But the situation is very different for converts like Azizi and Alikaram, who are considered by Iran’s theocratic government to be apostates, and are subject to harsh punishments — up to and including execution. As a result, converts must worship in secret, in an underground network of so-called home churches.
It was in these home churches that the couple began exploring Christianity and where, in January 2024, they were baptized into the Anglican church. But it was also in a home church where the two met with their first experience of state terror, Azizi and Alikaram told The Intercept in telephone interviews and related in court documents. On March 5, 2024, they were worshipping with a handful of others in a home church in Isfahan when members of the pro-government Basij militia burst in, having been informed of the gathering by neighbors. Alikaram and Azizi, along with others, were taken into custody. Alikaram was beaten so badly she passed out and had to be hospitalized.
On June 9, 2024, after relocating for their own safety to the capital of Tehran, Alikaram and Azizi were arrested again on charges of practicing a foreign religion and inviting others to practice Christianity. She was held for two days, and he for four. After that ordeal, they decided it was time to leave. They secured a visa to enter Brazil, and left Iran on November 3, 2024. Five days later, a court in Tehran issued warrants for their arrest, according to court documents.
Azizi and Alikaram entered the United States on December 26, 2024, after an arduous trip overland from Brazil that took them through more than half a dozen countries. En route, they traveled through the infamous Darién Gap and spent two days as captives of a criminal group in Tapachula, Mexico, an ordeal that ended only after paying thousands of dollars for their release.
In Mexico, they registered for CBP One, the mobile app designed by the Biden administration as the only method by which potential asylees could file a claim. Due to the danger in Mexico, including threats from a smuggler, Alikaram and Azizi said smugglers forced them to join a group of migrants from India, Iran, and a number of African countries in crossing the border wall separating Tijuana and San Diego.
“They told us, ‘You have to cross the border, you cannot stay in Mexico,’” Azizi recalled the smugglers saying. “It was out of our hands.”
On the other side, they soon found themselves in the custody of the U.S. Border Patrol, who searched the migrants and separated the men from the women.
“We told them we are married, we showed them our marriage certificate,” Azizi told The Intercept. “But they didn’t care. They separated us.”
In early January 2025, Alikaram was sent to Richwood Correctional Center in Monroe, Louisiana, while Azizi was sent to another facility in Louisiana before ending up at a detention center in Houston, Texas.
They have been apart ever since.
Alikaram went before Judge Jennifer A. May for her asylum hearing on July 2, 2025. May, who was appointed in 2018 under the first Trump administration, appears to be in line with the policy objectives of the current administration. Between 2021 and the end of 2025, she denied asylum in 91.8 percent of the cases she heard, according to data from Transactional Records Access Clearinghouse, which collects data on immigration judges.
The hearing took place at a time in which judges were under ever greater pressure to deny claims, according to Rey Caldas, the former immigration judge, who was fired last year amid a purge of the immigration court system by the Trump administration.
“It was evident to me when I was on the bench, and it’s certainly evident to me now that they are exerting massive pressure so that judges deny all applications,” Rey Caldas said.
“They are exerting massive pressure so that judges deny all applications.”
In the hearing, which was conducted over Webex, May drilled into Alikaram’s claim, asking for details about her baptism, whether or not she had owned a Bible, and her reasons for converting to Christianity. Alikaram, clearly nervous, stumbled over her words at times, and at others gave answers that clashed with evidence provided to court. Some details also appeared to get lost in translation. At one point, a reference by Alikaram to the Basij, the paramilitary arm of the Islamic Revolutionary Guard Corps, was transcribed as “a siege.”
May did not find Alikaram to be credible. In her decision denying Alikaram’s asylum case, May focused mostly on what she described as inconsistencies in Alikaram’s testimony, including how long she’d been attending home churches and details of her arrest — inconsistencies that Alikaram and Azizi later blamed on her nerves while testifying. But May also tried to downplay the likelihood that Alikaram would face persecution if she returned to Iran.
“I find there is no independent evidence to show that the respondent would likely be tortured in Iran,” May wrote. “[T]his court is aware that Christians have been arrested and sent to jail for some period of time. But looking at the amount of people in Iran, the amount of people who are converts to Christianity, I cannot find that that percentage would be more than likely or not torture or persecution [sic] for this respondent.”
Six days later, Azizi who at the time was being held at a detention facility in Texas, went before Judge Nimmo Bhagat, fully expecting that his claim would be denied as well. To his shock, however, the judge approved his claim for asylum, and just two weeks later he was a free man.
“I was shocked,” Azizi said. “I thought if my wife couldn’t get asylum that I’d have no chance. But they gave me asylum.”
A spokesperson for the Executive Office of Immigration Review, the branch of the Justice Department that oversees immigration courts, declined to comment. Neither ICE nor USCIS responded to requests for comment.
In light of his wife’s asylum denial, Azizi’s successful claim was a godsend for them both. Despite May’s decision, Alikaram should now be eligible for derivative asylum, upon which her own claim and its denial has no bearing.
The couple filed for derivative asylum in December, after the Board of Immigration Appeals denied Alikaram’s appeal of May’s decision. USCIS issued a notice of receipt, and even scheduled an appointment in Jackson, Mississippi, for a biometrics appointment. But ICE failed to produce Alikaram for the appointment, and the derivative asylum process now appears to be languishing in limbo.
In April, Alikaram’s attorney, Emily Trostle, filed a petition for habeas corpus in an attempt to secure Alikaram’s release from detention. That case, too, has stalled, forcing Trostle to file a petition last week to expedite the process.
In detention, meanwhile, Alikaram is suffering from poor nutrition, failing eyesight, and severe anxiety and depression.
“I can’t bear it anymore,” she told The Intercept in a telephone interview. “I know God has a plan for me, but sometimes now I say, ‘Just kill me so my husband and my family can move on with their lives.’”
This roundup has a lot of AI in it. Fortunately or unfortunately, it seems like a lot of the news is going to revolve around AI for the rest of our lives.
That was true of industrial technology in 1870-1970; people basically got used to the idea that railroads and factories and oil and industrialized warfare and such matters were central to the way the world was run and to the collective future of humanity.
AI is going to be like that going forward, and we’re just going to have to get used to that. So let’s make it as fun and interesting as we can!
1. Americans are getting scared about AI risk
AI risk has exploded onto the national scene. AI companies and AI researchers generally believe that the technology they’re building has the capacity to do great harm — perhaps even to end the human race — if it’s not developed more slowly and deliberately. There are five main groups of people opposing the slowdown:
The Trump administration, which is worried that an AI slowdown might also slow down economic growth
Investors who think a slowdown might hurt their bottom line
Libertarians and techno-optimists who think regulating technological progress is bad on principle
China hawks who worry that a slowdown would let China take the lead in the AI race
Progressives who spent the last few years telling themselves that AI doesn’t work, that AI is a huge economic bubble, and so on, and who now can’t bring themselves to admit that yes, the techbros actually built something that works.
This is a strange alliance indeed. The last of these — the progressives who simply couldn’t admit that billionaire-funded private industry could build something powerful enough to endanger humanity — were the strangest of all, since their refusal to acknowledge the effectiveness of AI basically put them in an alliance with libertarians, hawks, and Trump.
In fact, in recent days there has been a tremendous civil war within the progressive movement between the “AI is dangerous” and “AI is fake” camps, with Bernie Sanders supporting the former and his former comms director David Sirota supporting the latter.
But although it has the support of the president (for now), the anti-slowdown coalition is losing in the court of public opinion. Nate Silver has a post rounding up the evidence.
A bipartisan majority is now worried about existential risk from AI:
This is remarkable. I don’t think I’ve ever seen such bipartisan national unity on any issue in my adult lifetime. Trump is standing firm against the tide of public opinion here — as he has on the Iran war, tariffs and other issues. But it’s not clear how long he’ll be able to hold out.
2. A very cool debate about AI and growth
Quite apart from the question of whether AI will kill us is the question of whether AI will deliver explosive economic growth. There’s a pretty epic public bet on this:
The people on the “fast growth” side are mostly AI researchers, while the people on the “slow growth” side are mostly (but not entirely) economists. This is an exaggerated version of a broader disconnect — AI researchers are generally more optimistic about AI’s impact on economic growth than economists are:
But the people publicly betting on fast growth are making an even more extreme forecast — they’re forecasting 15% growth, which is much higher than the 5.3% that AI experts forecasted as their most optimistic scenario.
That’s an absolutely stupendous growth rate — China has hit it only in one year (1984) since it began its rapid growth, and that was when it was a very poor country. And yet, a number of people in the AI industry think it’s going to happen to us very soon.
Economists — even those who work on the economics of superintelligent AI, like Alex Imas — are skeptical. In a recent blog post, Imas and Ben Moll explain their thinking.
Basically, they foresee a bunch of factors combining to limit AI’s contribution to economic progress in the short term:
Slow diffusion of AI technology throughout the economy,
The “J-curve” effect where productivity tends to fall right after a big innovation comes out (because companies need to spend resources adopting the new technology rather than on their existing businesses)
The difficulty of automating the physical world with robots
Political barriers to adoption
The difficulty of reorganizing production processes around AI
The persistence of activities that consumers want to keep having humans do (the “relational sector”)
Bottlenecked inputs to the AI industry (e.g. chips)
Baumol’s cost disease
AI disasters that slow adoption
That’s a lot of reasons! It makes sense that at least some of these will end up having an effect. Whether AI’s rapid improvement is enough to overcome all of these, and propel us to 15% growth, is something I guess we’ll have to see for ourselves. Personally, I lean toward the economists’ more measured expectation, but I’m prepared to be surprised on the upside.
Now Ernie Tedeschi and the excellent folks over at Stripe Economics have a post about how AI is stubbornly refusing to kill the Software as a Service industry.
Earlier this year, when coding agents came out, there was a bloodbath in software stocks. Why would anyone pay Salesforce or other companies big bucks to make and maintain software for them when Claude Code could just do it all for a lot cheaper?
That logic made some intuitive sense, except things didn’t turn out that way — at least, not yet. In fact, SaaS companies started making more money in the age of AI! Tedeschi and the Stripe team tracked an index of publicly traded SaaS companies and found that their revenue has grown faster since coding agents came out:
What’s going on here? Well, for whatever reason, companies are still willing to pay for software instead of trying to roll their own with Claude Code. And SaaS companies are probably improving their own productivity by using AI. As in so many other areas of the economy, AI is proving to be a complement when people thought it was going to be a substitute.
That could all change, of course, if and when AI gets good enough, or when new AI-centric business models disrupt older ones. But for now, the simple story of AI replacing everyone and everything just isn’t happening.
Anyway, Zidar and Zwick have an article out in The Atlantic explaining their findings. Here are some excerpts:
When Americans picture the ultrarich, they typically think of tech billionaires such as Elon Musk and Mark Zuckerberg, whose wealth lies predominantly in shares of publicly traded companies. They might also think of Wall Street financiers and celebrities such as Taylor Swift. But far more typical are…owners of successful privately held businesses…By our calculations, about 1.7 million Americans have each built a net worth of at least $10 million by owning a private business. For every CEO of a public company, there are more than 1,000 private-business owners with a net worth of more than $25 million…
What we found changed how we think about inequality…Today, when Senators Elizabeth Warren and Bernie Sanders propose making the rich pay their fair share, they aim at Wall Street and Silicon Valley. But far more relevant to the story of inequality in America are the everywhere millionaires who quietly press their elected representatives for favorable treatment. The tax code bears their imprint far more than it does Musk’s…
A loophole that lets private-business owners avoid Medicare taxes has similarly been justified as a break for the little guy. Preserving the family farm has been a pretext for passing ever larger exemptions to the estate tax, to the point that a married couple can now pass on $30 million to heirs tax-free. Hiding behind small business, in short, has proved a devastatingly effective strategy for the rich…[T]he everywhere millionaires have one thing in common: They own what have become known as pass-through businesses…[L]awmakers have carved out multiple loopholes, so a dollar earned from owning a business is routinely taxed much less than a dollar earned in wages. [emphasis mine]
In fact, though I haven’t yet joined the ranks of Zidar and Zwick’s “everywhere millionaires”, I probably will do so — Noahpinion is a pass-through business (an S-corporation), and although I haven’t yet managed to get Congress to create tax loopholes for Substack writers, the generally favorable tax treatment these businesses receive has certainly lowered my tax bill.
So perhaps it’s not in my financial interest to promote Zidar and Zwick, but I will do so anyway. Expect to see more about their work on this blog in the months to come!
5. Christians vs. Nazis
Christians and Nazis should be natural enemies. The original Nazis in Germany persecuted the Catholic Church, and attempted to create a new state religion that co-opted some elements of Christianity while rejecting the Old Testament. Christianity is, at its core, a universalist faith, open to human beings of all races, while Nazis are…not that.
In the US, neo-Nazis have been weak enough where they haven’t tried to usurp leadership of the Right from conservative Christianity. But as Christianity wanes and online rightism rises, the two may now be coming more into direct conflict. Erick Erickson, a Christian conservative pundit, recently wrote a post exposing one network of neo-Nazi influence on the Right.
Some excerpts:
Charles Haywood made his fortune selling shampoo…[H]e has spent the years since writing out, at length and under his own name, what he would like to do with your country.Rod Dreher, who is no man of the left, read Haywood’s online ramblings and described Haywood as pouring out vile from “deep in his Midwestern Führerbunker”…
In a document he calls the Foundationalist Manifesto, Haywood explained that his preferred government “will not be democratic.” The state “will have unlimited means,” because “properly viewed, the state is not constrained externally.”…The state will seize the assets of “any citizen who views himself as a global citizen.”…Those are his words, from the manifesto that earned him a friendly sit-down with Tucker Carlson in September 2022…Elsewhere he has speculated about serving as a “warlord” at the head of an “armed patronage network,”…
Haywood himself…has argued that the Allies, not the Nazis, were the genuinely barbaric power in World War II, has insisted the war was not much motivated by the horrors of Nazi aggression, and gushed that Tucker Carlson and Darryl Cooper “boil down all my political plans.” Cooper argues that Churchill, not Hitler, was the villain of World War II…In a 2023 debate…Haywood raised the hypothetical of a real white nationalist with real political power, and answered that you should cooperate with that person in order to destroy the power of the left.
There’s a lot more in Erickson’s post, but you get the point. Erickson notes that the Haywood/Claremont nexus is separate from the “groyper” network organized around Nick Fuentes, which has received a lot more attention; the two parallel rightist networks share similar ideas, but the Haywood/Claremont group is an intellectual movement aimed at elite influence, while Fuentes is an entertainer in search of an audience of disaffected overly-online young men. Erickson also notes that both the Haywood/Claremont people and the groypers have ties to JD Vance, who has emerged as the paramount leader of the New Right.
Anyway, this should go without saying, but I’m rooting for Erickson, Dreher, and the Christians in this fight, and I think they deserve help exposing the neo-Nazi moneymen and elite influence channels. There’s a tendency among progressives — and especially among leftists — to view everyone on the
Right as essentially part of one solid undifferentiated bloc, but this has never been true. I have many differences with conservative Christianity, but it was never Nazism, and it has never been ambiguous which one was worse.
6. Japan is not a “Confucian” society
One thing that has always annoyed me is when people call Japan a “Confucian” society. Confucianism certainly had a historical influence in Japan — it was an important school of political thought in Japan from around 1300 to the late 1800s, especially during the latter half of that period. It did have some influence on the development of Japan’s education system (though not nearly as much as in China and Korea). But it was never nearly as dominant as it was in China and Korea, and it never morphed into a quasi-religion the way it did in those other countries. Japanese people will regularly tell you about how Koreans are much more Confucianist than they are.
Anyway, I’m not the only one who gets annoyed by the “Confucian” label. Here’s Richard Hanania:
Hanania’s entire post about differences between Japan and other East Asian nations is worth reading, but his invocation of the Inglehart-Welzel World Cultural Map is especially powerful. The World Values Survey, which goes around asking people from various countries about their values, puts out this map periodically. Here’s the more recent version:
You can see a little movement from Hanania’s earlier version — Hong Kong and South Korea have become a bit more secular — but Japan is still the clear outlier in the “Confucian” category. Its values are far more in the direction of “self-expression” — very close to the US, in fact (though North Europe and the Anglosphere still reign supreme in this regard).
To anyone who has lived in Japan, this is hardly a surprise. The country is highly individualistic, creative, and socially nonconformist, despite a penchant for following rules and procedures. Japanese parenting is also far more laissez-faire and far less education-obsessed than Chinese parenting.
In other words, “Confucian” is lazily applied to Japan as a racial category, rather than any kind of a useful description of the culture and society.
7. State capacity: It works
One unpopular position I’ve stuck to over the years is that a strong bureaucracy is good. I don’t mean “bureaucracy” as in red tape and regulation; I mean a competent, empowered civil service that can perform crucial government functions efficiently and well using in-house expertise.
This is also called “state capacity.” Over the past half-century, conservatives and progressives made a devil’s bargain to slash state capacity — conservatives got to cut the size of government, while progressives got to outsource core government functions to progressive nonprofits.
The problem was that this often ended up costing the government much more money to do things like build trains and roads, because the government ended up getting ripped off by expensive consultants, ineffective and sometimes corrupt nonprofits, opportunistic unions, etc. — as well as suffering constant delays that increased costs even more and sometimes prevented anything from being completed at all.
A decade ago, the New York Times published a story called “The Most Expensive Mile of Subway Track on Earth”, detailing how lack of state capacity had made NYC’s famous train system increasingly dysfunctional and unaffordable.
So I was very happy to see a story (by Tahra Hoops) about how NYC’s Metropolitan Transportation Authority has actually invested in state capacity, and how this investment is yielding results:
The project was done effectively through prefabrication, sequencing, and a project team empowered to actually manage the work…Phase 1 wrapped 21 months ahead of schedule in October 2025. Phase 2 finished the weekend of July 25, five full years early, with the final cost coming in $195 million under the initial $960 million budget…
Before 2019, capital projects at the MTA were run separately by each operating agency…In 2019, the MTA consolidated all of it into a single delivery organization, MTA Construction & Development, bringing nearly 2,000 employees from those scattered capital divisions under one roof.
One agency, one accountable executive, one set of lessons learned that actually compound from project to project…In 2023, C&D awarded more than $8 billion in new contracts at prices 6.2 percent below the engineer’s estimate, saving nearly $300 million, and in 2025 it reported another $1.2 billion in savings while completing 41 elevator replacements, double its previous single-year record, each finished about two months faster on average…
C&D shifted to design-build contracts, which put design and construction under one contract so the builder owns the gap between the drawings and the dirt, and bundled similar projects into single procurements rather than bidding out ten station upgrades ten separate times. It also started pulling work back in-house instead of defaulting to consultants[.]
This is great progress, and shows the value of the state capacity approach to infrastructure. Whether other states and cities will pay attention is another question. Hoops notes that L.A.’s D Line extension is mired in the typical endless series of delays and cost overruns. Five decades of going in the wrong direction is hard to reverse overnight.
Still, the MTA’s success shows that in most cases, all you really need in order to get infrastructure built cheaply is the political will to do so.
8. Will self-driving cars make cities more dense or less dense?
A lot of people just assume that self-driving cars will make cities less dense. After all, simple logic dictates that if a car trip is less burdensome — if you’re able to get work done or watch TV or scroll social media during your commute instead of being forced to keep your eyes on the road — then people will be willing to live farther away from their places of work.
That suggests that like the car itself, self-driving cars will lead to urban sprawl — which is why many urbanists don’t like the notion of self-driving cars, despite the obvious safety benefits.
But in fact, the economics of self-driving cars and city size are a lot more complex and subtle. Ed Glaeser, one of the greatest living urban economists, has a new paper exploring the topic. After explaining the relevant economic theory, he argues that Waymos and other autonomous vehicles will make people want to live in dense urban areas more, rather than less.
Glaeser notes that people who live in dense cities actually spend more time commuting than people who live in the suburbs (something I wrote a post about a couple of months ago). That means urbanites stand to benefit more from self-driving car trips than suburbanites, who generally already have shorter (and probably less stressful) commutes.
Thus, he argues, self-driving cars will complement urban life more than suburban life, and make people want to live in denser cities. He expects the effect to be modest, but it’s still in the exact opposite direction from what people’s intuitions suggest.
Fundamentally, this is because people typically misunderstand the nature of American suburbia. They imagine bedroom communities where people commute to and from a central business district.
Some suburbs definitely do behave like that, but most are like little cities themselves, with office parks where people work and strip-malls where people shop. Suburbanites trade the variety and financial opportunity of the big city for the convenience and safety of the suburbs. But self-driving cars make big cities more convenient.
Urbanists who throw a lot of hate at self-driving cars should stop to consider that perhaps their anger is misplaced.
This article was first published on Noah Smith’s Noahpinion Substack and is republished with kind permission. Become a Noahopinion subscriber here.
Military milestone: Ukrainian naval drone sinks Russian kamikaze drone boat
In the world’s first clash of the drone boats, a Ukrainian naval drone destroyed a Russian explosive drone boat using a remote-controlled machine gun turret. This comes as the war in Ukraine has already seen widespread deployment of such uncrewed surface vessels in combat, along with swarms of flying attack drones and ground robots.
The lopsided battle took place on September 12 when members of Ukraine’s Defense Intelligence detected the Russian uncrewed surface vessel (USV) in the Black Sea and directed a Ukrainian Navy drone boat to intercept. The Russian vessel was “positively identified” as an Orcan surface drone with a “jet ski type steerable water jet” designed to ram targets and explode, according to naval analyst HI Sutton in Naval News.
Such Orcan drones have already been used to attack Ukrainian ports and ships. These often work in coordination with flying drones such as Russian Geran drones that provide aerial reconnaissance and can boost communication between drone operators and drone boats, Sutton explained.
In this case, the Russian drone was hunted down by a Ukrainian Sargan-3000 drone boat armed with a 12.7 mm machine gun mounted on a remote weapon station made by the Norwegian company Kongsberg.
“It was inevitable that there would be USV-on-USV combat,” Sutton told New Scientist. “We have seen the same in the air and on the ground.”
The Ukrainian Navy released a video showing the Sargan-3000 firing upon the Russian drone from a distance of one kilometer, disabling the latter’s communications antenna before riddling the Russian drone until it sank, according to the Ukrainian government media platform United24.
Ukrainian media have described the Sargan-3000 drone as being able to reach speeds of 40 to 55 knots and travel up to 1,600 kilometers (994 miles) while carrying a payload of 450 kilograms (992 pounds), United24 reported.
The multipurpose Ukrainian drone can also be equipped with an explosive payload for ramming attacks—the Ukrainian Navy claimed one such drone successfully struck and sank a Russian border patrol ship named the Izumrud in July 2026.
Ukraine has focused heavily on developing and deploying drone boats to wage asymmetric warfare against the Russian Navy’s Black Sea Fleet of warships, sinking some and forcing the surviving ships to hunker down in port. Ukraine has also used a combination of aerial and surface drones to attack ships transporting sanctioned Russian oil and gas, along with targeting ships carrying supplies to the Russian-occupied Crimean Peninsula that Russia seized from Ukraine in 2014.
Naval drone innovations have also extended to Ukraine using drone boats to deploy ground robots in amphibious assaults and using uncrewed surface vessels as motherships for launching FPV drones to attack Russian positions near the Black Sea.
But Russia has similarly adapted by deploying its naval drones to go after Ukrainian targets—and Europe as a whole may face growing threats from such naval drones in the future. In August, a Russian drone boat loaded with explosives was disabled by a Romanian fighter jet after it drifted near a vital European natural gas platform in the Black Sea.