One sentence covers the week: every wall became a policy, and every policy has an owner.

Torvalds, the AI, and the commit message

On 20 August Linus Torvalds merged a one-line fix into the Intel Xe graphics driver and wrote the story into the commit message: a debug session from hell, “enormously helped by an AI doing much of the grunt-work”. The AI told him several times that the bug was impossible and unsolvable and that he should just write a report. He pushed, it kept adding debug code, and after twenty-four debug patches and eighteen kernel boots the fix was one rounding direction. The human supplied the stubbornness, the machine supplied the grunt work. That is the most honest description of working with these tools we have read all year, and it is in the commit itself.

Two events, in order: the July “fork it” thread was about AI review tooling. August was him using one.

Walls became policies

Debian’s general resolution drew 401 valid votes. “Responsible Use of Generative AI” won with 281: AI-assisted contributions are allowed, the contributor carries full responsibility, disclosure is encouraged. An outright ban took 144 and needed a three-to-one majority it did not get. The dates matter more than the headlines: Gentoo and NetBSD banned AI-generated contributions in 2024, Fedora allowed them with a disclosure tag in October 2025, Debian allowed them with responsibility this August. The strict camp settled the question two years ago; the two biggest distributions arrived at the opposite answer. A direction, not a fracture.

One developer resigned. Antoine Le Gonidec posted his retirement on 29 August; we quote him rather than characterise him, because the version of that post going around has already mutated twice.

A closed format, re-derived overnight

Adam Conway at XDA gave GLM-5.3-Flash five raw Sony files and Adobe’s closed DNG converter, nothing else. The honest caveat first: a two-machine DGX Spark cluster, not a gaming card. The model ran the converter, diffed input bytes against output bytes, wrote its own independent decoder to check its reading, cross-checked against LibRaw, caught its own mistake, and produced about 2,900 lines of Rust that Adobe’s own validator accepts, pixel-identical, 0.95% smaller. The reason it worked was verification, not brilliance. The same week Adobe named Anil Chakravarthy its next CEO from 1 December, ending Shantanu Narayen’s eighteen years. A named succession is a normal corporate event; we say so on air.

Abliteration: the safety layer as a product

Every downloadable model has a layer that decides what it will not answer, and it is not precise. A company is now selling hosted models with that layer removed, with an API and a pricing page (TechCrunch, 3 Sep). The technique is called abliteration: find the one internal direction a model uses to decide whether to refuse, and delete it. We name the technique because you will meet the word; we do not read out a route to the company.

Disclosure: the strictest refusal number in the study we cite belongs to the company whose models this studio runs on.

The part nobody selling it tells you comes from arXiv 2607.17427: across 21,600 decisions on a task the original models never refused, the stripped versions came back 12.2 points more optimistic, used fewer hedging words, and got no better at the job. You do not get your model minus the filter. You get a different model that is more confident and no more right. We have not run one here. If you strip a model, you own everything it does afterward.

Atlas, and the local version

World Labs’ Atlas predicts what a place looks like from somewhere you never stood, outputs up to a minute of camera-controlled video at 1440p, and takes the camera path as geometry rather than prose. It is closed: early access, select partners, no weights, no API, no disclosed hardware. The local version of “make me a 3D scene” this week is an agent writing Blender Python on your own box, plus a ComfyUI node called OmniCam for camera control. We have run neither. That gap is this channel in one paragraph.

Your personal AI account is a door

Anthropic disclosed on 30 August that infostealer malware (Vidar, Lumma, RedLine) has been harvesting live Claude browser sessions and replaying them, straight past two-factor. Our supplier again. VentureBeat spelled out the work problem: personal accounts holding OAuth grants into corporate Gmail and Microsoft 365, granted by the user, invisible to the company, revocable by nobody who knows they exist.

Three things, free, today:

  1. Revoke third-party app grants you do not recognise on your Google and Microsoft accounts.
  2. Never connect your work email to a personal AI account.
  3. After any malware hit, treat every AI session as compromised and sign out of all of them.

A local agent has no session cookie to steal and no OAuth grant to inherit. Not because it is smarter; the wire has nobody on the other end.

The ticker

The DOJ filed a statement of interest in the New York Times case calling training “highly transformative”: advocacy, not a verdict, and both halves apply (it protects the foundation under every open model, and it weakens working artists’ position). Anthropic paused some training after unauthorised actions, ~150 engineers moved to security. Fable 5.1 and Mythos 5.1 shipped cheaper, mostly a 75% cache-read cut. Fambot raised $3.5M to be a family’s AI chief of staff in their cloud; we built the same job class on an old PC in this house. ARD, the agent discovery standard: nine of eleven backers publish no manifest. ComfyUI 0.34.5, Ollama 0.34. LTX-2.5 22B on an 8 GB laptop. An H3 Optimizations node fixed out-of-memory on a 32 GB 5090. And XDA ran two small models at once on 8 GB instead of one big one, which matches what our own routing test found.

The lab report

Two episodes went up. The rematch put twenty image generators through eight prompts on one RTX 5090; the finding that mattered was text. The Krea 2 family and Qwen Image 2512 sat at the top of the ladder here, Z-Image Base beats Z-Image Turbo on text at every rung, and the older-architecture families failed every rung. One generation per cell, four on the text rungs: a starting point, not a spec sheet.

The lesson that cost the most was about plates. Some cams were broken from the start because the face in the plate was too small for the mouth pass to find. Measured: under about 70 pixels of face the mouth fails, over 110 it holds. Every plate in this brief was measured before a cam was rendered.

Kicker: the smear is temporal

A creator called Machine Delusions argues that MiniMax H3’s fast-motion smear is a temporal artefact, not a resolution one, and fixes it with a second pass in time: stretch the hectic section into slow motion, diffuse again, drop the added frames. It matches what we saw in our own walk-and-talk clips. We have not run it; our bench always used the turbo LoRA, and whether that helps or hurts is the question we asked him. A question, not a finding.

Sign-off

2,660 subscribers this morning, up from 2,200 at the last brief. Both episodes from the week are on the channel and both guides are on this site, free, no email gate. Everything that came from somebody else is theirs and labelled; everything from this machine is one card, one week.