Back to The Weekly Recall

The evidence layer is cheap to poison

The artifacts agents read to decide what is true, forum threads and benchmark tables and model pages, became the contested surface this week, and one of them turns out to be trivially cheap to write for someone else

A CRT agent studies four gold-star notices beside a matching star stamp with a dark handle.

The material agents read to decide what is true is now the thing worth attacking. Researchers found it is trivially easy to move AI search results with Reddit posts, and a Reddit thread is a pile of strangers agreeing with each other, which is exactly the shape an AI answer treats as consensus. We said last week that the record a project leaves behind is what agents learn it from. This week adds the other half: everyone else's record counts too, and a few coordinated accounts can write part of it for you. Meanwhile benchmark tables, the score sheets a vendor publishes to show its model is good, are becoming the artifact an engineer picks up to decide a tool is legitimate, and increasingly the artifact an agent picks up to recommend one. The planted posts come in through the same door as the real ones, and nothing on either end can currently tell them apart. Ask again when one of these products publishes what it weights and why.

Top Stories#

Steering AI search turns out to be trivially cheap. 404 Media covered research suggesting that Reddit posts can move what AI search products report. The mechanism is unglamorous. AI answers lean on forums for recent, human-sounding consensus, and ranking has no reliable way to separate coordinated posting from actual agreement, so a handful of accounts and some patience buys a vote in what the model repeats. It is buying the top comment rather than the top ad slot, at a fraction of the price. The defenses on offer mostly amount to trusting fewer sources, which is the opposite of what these products promise. A poisoned search result used to cost you one bad answer, and now it feeds whatever the agent does with that answer next.

A model launch page sold its position instead of a clean sweep. Thinking Machines, one of the newer labs, released Inkling as open weights, meaning anyone can download the model and run it, and the launch page positions the model honestly against the two big labs instead of claiming to beat everybody. That posture is becoming the credible one, because a vendor that wins every benchmark it publishes has mostly demonstrated that it picked the benchmarks. The defensible shape is narrower than most launches attempt: a third-party dataset with known answers, the model held fixed, the one component under test swapped underneath it. Meanwhile, the audience is shifting. A benchmark table is the one artifact an engineer will pick up and independently accept, and those tables are now read by agents that will end up doing the recommending.

Extending a model quietly is a tax on everyone downstream. The New Stack reported that Anthropic extended Fable 5 again and declined to discuss the developer side. Nobody minds a longer support window. The worry is the pattern a quiet update belongs to: a model owner can change templates, tokenization or byte handling, which is the plumbing that turns text into the numbers a model actually reads, and break consumers who never asked for the change. The breakage arrives as slightly worse answers rather than an error, which is the kind of bug that takes a week to even name. Teams that recommend a specific model are starting to host their own pinned copies instead of pointing at someone else's, which is a strange amount of infrastructure to run in order to keep a recommendation true.

  • The Tower Keeps Rising (lucumr.pocoo.org): Armin Ronacher on how much further the stack has been built lately, and what that costs the people standing under it.
  • The Memory Heist (ayush.digital): memory framed as something that gets taken rather than something a system politely keeps for you.
  • Are the big labs training on API traffic? (news.ycombinator.com): a thread that caught fire over a question nobody has answered, started by noting that one open-weights lab says out loud that it does.