Seven stories this week, and the thread running through them: the gap between what you’re given and what you’re allowed to keep.
The one everyone will remember
Anthropic disclosed that an unreleased Claude research model found a genuinely novel weakness in HAWK, a post-quantum signature scheme that had survived years of expert cryptanalysis. Key recovery on HAWK-256 dropped from 2^64 operations to 2^38 after roughly 60 hours of semi-autonomous work — and the HAWK team withdrew the algorithm from NIST’s standardization process. It also found a 200–800x faster attack on a reduced 7-round AES variant, which sounds alarming until you read the fine print Anthropic itself led with: the attack needs more chosen plaintexts than there are grains of sand on Earth. Nothing you use today is broken. The real headline is stranger: an AI did novel cryptanalysis, and the humans checked the math and conceded.
Open weights, closed borders
MiniMax shipped H3 — a 33B omni-modal model that generates video with native stereo audio, up to 2K, with instruction-based editing, weights on Hugging Face, ComfyUI support on day one. Then you read the license: the community agreement excludes the US, EU, UK, and South Korea from local deployment rights. The first CAN YOU RUN IT verdict in this show’s history where the hardware says yes and the license says no. A genuinely new category of “open.”
The local harvest
The best week for local runners all summer: Nvidia’s Nemotron Nano Omni (30B-A3B, 320+ tok/s on ordinary hardware), LiquidAI’s phone-class LFM2.5-2.6B, Devstral posting real SWE-bench numbers from a 14GB footprint, and DeepSeek V4-Flash at $0.14 per million tokens. Every one fits hardware that costs less than a vacation — check yours, or rent by the hour (referral link — disclosed).
The rest of the week
Qwen 3.8-Max launched for real (2.4T MoE, 1M context) — but the promised open weights still don’t exist on Hugging Face; the 27B open sibling is the one to watch. GPT-5.6 Luna went free in ChatGPT with an 80% API cut — generosity best explained by ChatGPT’s traffic share falling from 79% to 54% in a year. The EU’s AI Act Article 50 went live: chatbots must disclose, synthetic media must watermark, deepfakes must label — this channel has carried its AI disclosure since episode one. And an AI flew a real F-16 under DARPA’s VENOM program, safety pilot aboard — the interesting part being the certification problem: how do you test an AI you can’t fully predict?
Ticker: Meta’s Muse Code terminal agent (not open-weights, whatever you read) · Anthropic designing its own silicon · OpenAI’s reported IPO prep · the World Bank’s lopsided automation numbers (14.2% of rich-country jobs vs 4.5% in developing economies) · Suno will watermark AI music — including, one day, this show’s own sting.
The lab report
The machine ran itself for eleven days: eleven daily shorts, the skills episode, and last week’s brief all shipped unattended — and 460 of you subscribed while nobody was watching the machine watch itself. The counter is closing on the number that unlocks the thing we keep almost telling you about.
The DIY AI Brief ships every Monday. All referral links are disclosed. Corrections? r/aillex.
