Hi
Hope your weekend was as good as mine - excellent Sichuanese food, spicy cocktails, and a surprise round of karaoke - goodtimes were had.
Quick plug: Higher Education Horizons 2026 – The Human Edge is open. RMIT Saigon South, 24–25 September, free, Tim Fawns (Monash) keynoting. Sign up now - because it fills.
The throughline this week - every boundary in these stories was drawn by somebody who doesn't have to enforce it. Let's get into it:
The Magic Words Were 'Authorised Penetration Testing': Taiwan and the First Autonomous Attack | Cost Collapse 🕳️
In early July, up to eight AI agents ran a four-day campaign against Taiwan's government networks with nobody at the keyboard. Not assisting an operator – doing the work. Researching targets, probing, experimenting and revising, choosing targets. Twelve months ago that was a research demo with a human quietly steering. This one mapped 21 systems and the single sign-on architecture holding them together, cracked 85 accounts, and reached the island's nuclear safety agency before withdrawing - Taiwan's Ministry of Digital Affairs confirmed the AI-assisted attacks on 13 August. The platform wasn't exotic – Hermes and OpenClaw, both open source, both already on students' laptops. And the chilling bit - operators got past the models' own safety behaviour by telling the AIs the campaign was authorised penetration testing. It believed them.
Universities are probably the softest available version of this target out there. Federated identity across a dozen systems nobody has fully mapped since the last restructure. Thousands of accounts, high turnover, guest access sold as a feature. Research data with real strategic value sitting behind an estate documented in a wiki last touched by someone who left in 2023. What changed in July isn't the vulnerability – it's that finding it no longer needs a skilled operator with months. It needs a laptop and a plausible sentence. Your risk register almost certainly carries 'cyber' as one line with a mitigation owner. Is that enough for this new world of ours?
OpenAI Ships an Offensive Model and Becomes the Licensing Authority for Defence | Gatekeeping 🔑
Four days before Taipei confirmed the attack, OpenAI split its Daybreak programme in two - giving companies access to frontier models with a range of the usual security guardrails switched off. One tier includes GPT-5.6-Cyber – which has already found holes in infrastructure as widespread as Google’s Chrome browser. OpenAI frames the current moment as a narrowing window of opportunity, and given the above story from Taiwan, it’s not wrong.
So in July, an attacker walked past a model's safety by asserting the work was safe, approved, and authorised. In August, the most capable offensive model yet built goes to people who assert the work is authorised – this time on a form, with a signature. That's a real control, and better than nothing - tho thin comfort vs the capabilities on offer. It's also the same sentence, notarised. Meanwhile a private company now decides which organisations count as defenders, on criteria it wrote, reviewable by nobody. Things are moving fast in this space and those universities who run security operations, teach offensive security, and supervise research - they need exactly these capabilities - who at your place signs and what happens to the cyber degree that can’t get its students through the door?
The Deadline That Didn't: Europe Moves the Education Rules to December 2027 | Deferred Governance ⏳
Two weeks ago the EU AI Act's high-risk obligations were meant to bite - with education right up the front of Annex III (e.g., admissions, student placements, learning outcome evaluations). Then on 24 July the AI Omnibus landed and moved standalone Annex III compliance to 2 December 2027. Sixteen months, arriving just days before the gun. The Commission's case is likely implementation readiness – standards unfinished, guidance late, and a deadline nobody can meet is worse than a later one. Reasonable enough. It's also the second time we’ve watched the binding date move, and the first time it moved for education specifically.
Mixed feelings about this. The EU moved fast initially with conception but stutters now on delivery. And every admissions-scoring pilot, every early-alert model ranking students by predicted failure, every automated marking tool - it now runs another sixteen months with no binding conformity assessment, no mandated human oversight, no logging duty with teeth. The capability–governance gap isn't the frame here - the governance was written, published, then postponed. The deferral changes exactly one thing - whether anyone outside the building checks. It changes nothing about what an early-alert model does to a first-year who never knew it ran. December 2027 is the date the rules arrive. It was never the date the students did.
The Watermark "Proves" a Machine Touched It, Not That a Student Didn't Think | Provenance ≠ Authorship 💧
The other half of that same 2nd August deadline did land - Article 50, requiring providers to mark synthetic output machine-readably. So the marking arrived. OpenAI put SynthID into GPT-Live voice a day early, joining ElevenLabs, which offers a free public audio detector. Then on 11 August Anthropic began watermarking text from every model launched since that date – globally, not just in Europe. Note the week this happened in - a dozen-plus universities had just switched their detectors off as unreliable. Detection died in higher education and was reborn in the vendor stack, eleven days apart.
For voice, this is genuinely good and the right shape – deepfakes are a huge problem and the potential for bad actors here is terrifying. Being able to determine provenance here has my vote. For writing, it isn't, and the research is not looking good - a single paraphrase pass collapses text watermark detection, and it falls apart on short or highly factual output. There's even a paper titled AI Watermark Evidence Fails Forensic Readiness – worth keeping bookmarked for whenever someone pitches running a misconduct case on one. This is not an arms race that can be won. Whoever brings brute force – a big enough archive of their own writing as context – walks through it. So does finesse with prompting. So does Humaniser 2.0, and the layer after that (remember 'appsmashing'?). A student needs to beat it once - the institution has to win every time. And look at what checking would cost you. Detection runs on the vendor's key, so verifying a student hasn't used AI means sending their work to each provider in turn – handing a third party their writing, and whatever personal information sits inside it, without consent. Even when it works, the mark just says a machine was involved. It has never said whether anyone learned anything.
Sign Anywhere Except a Classroom: Google's Sign Language Model and the Prohibition Nobody Will Enforce | Accommodation Gap 🤟
Sometimes this stuff is just wonderful. On 12 August Google DeepMind put sign-language to text into ordinary phones - SL2T, shipping free in Gboard and Live Transcribe on Pixel 11 from the 20th. A Deaf user can sign anywhere they'd otherwise type - a search, a message, a question to Gemini, or their half of a conversation at a counter. Good privacy decisions have already been made with the camera feed dying on the device vs shipping to the cloud. Trained across 100,000+ hours and 50+ sign languages (ASL to English at launch) and the joint report co-signed by the National Association of the Deaf, the World Federation of the Deaf, RIT/NTID and DPAN. This is pretty cool - and refreshingly honest.
Honest because of section 3.3, where 'higher education classroom instruction' sits on the explicitly prohibited list beside courtrooms and clinical consultations. And this, in their own words - 'We do not believe that SL2T 1.0 satisfies legal obligations for reasonable accommodations under the Americans with Disabilities Act (ADA), Section 504/508, or international disability frameworks that are met by human interpreters.' The advisory committee's number one critical risk is institutions swapping the free tool in for a certified interpreter, for cost or convenience. The benchmarks agree with them – it's superb on short everyday phrases and weakest on complex abstract language, which is the exact register a lecture is delivered in. So the prohibition is right, clearly stated, and I’m going to keep a tight hold on my optimism vs budget pressures… 🤞
Eight agents, four days, and a sentence claiming they were authorised. The most capable offensive model ever released, gated behind that same sentence on a form. Europe's rules for admissions and assessment, moved sixteen months right, just days out. A watermark that proves a machine touched the text and never that a student didn't think. An accessibility breakthrough its own authors ban from the classroom. None of this reduced risk – each one moved it, and always the same direction - outward from whoever drew the line, onto the institution, then onto the person inside it with perhaps the least room to say no. Every boundary drawn this week was drawn by somebody who doesn't have to hold it.
There Is No Port for a File: What Happens When the Frontier Becomes Downloadable | Adjunct Intelligence 🎙️
Every boundary above was drawn by somebody who doesn't have to hold it. This one nobody can. Inside five weeks the US pulled two frontier models from every foreign national on earth, Moonshot put Kimi K3's weights up for download, and Xi Jingping told the world AI shouldn't be 'the property of a single country'. Dale Leszczynski and I on why America's pharmaceutical playbook doesn't transfer - you can stop a generic drug at a port. There is no port for a file.
See you at Higher Education Horizons 2026 – The Human Edge: https://www.rmit.edu.vn/events/all-events/2026/higher-education-horizons-2026 – 24–25 September, RMIT Saigon South, free.








