
Evidence-first essays on policy and society across regions. We follow money, rules, and outcomes -- and name the trade-offs.
TECHNOLOGY & AI · The three weeks between a breach nobody discussed and a model nobody was supposed to reach
Anthropic said nothing when its training-data contractor lost forty thousand people's passports to a hacking group. Three weeks later, it built a model it called too dangerous to release -- and lost control of it on launch day.
The silence and the breach are not the same incident. They are the same shape.
In March, Mercor -- the staffing firm that recruits, vets, and pays the human experts who train frontier models for OpenAI, Anthropic, and Meta -- was hit by a supply-chain attack that began in an open-source security scanner, jumped to a widely used AI gateway library called LiteLLM, and ended with attackers inside Mercor's systems. The mechanism was almost embarrassingly simple: a tainted update to a Python package that millions of developers trust by default, executing automatically the moment it was installed, harvesting whatever API keys and credentials it found and handing...