Notable links: July 24, 2026

America's AI dominance is under threat; AI vendors put us at risk; meanwhile, everyone's staying in their jobs for the health insurance.

OpenAI

Most Fridays, I share a handful of pieces that caught my eye at the intersection of technology, media, and society.

Did someone forward this to you? Subscribe for free.


China delivers a one-two punch to America’s AI dominance

AI models, as a product in themselves, have very little moat beyond what amounts to brand loyalty and superficial switching costs. Instead, the moat is in the enterprise services that sit around them: the deals and contracts, connectivity with enterprise systems, and quality of life features in an enterprise context.

If we consider the models themselves, it’s easy to switch between them: someone could be using ChatGPT today and Claude tomorrow, with very little impact on their workflows. This is particularly true in the engineering world, where models are accessed via API: you can swap out the API and use the same prompt.

Those companies can make deals to lock their customers in, but in practice there’s very little long-term technical incentive to use one vendor over another. You pick the best model for your needs and change models and vendors if another one becomes better.

The US government has placed export controls on GPUs. There are also strong regulations that (reasonably) prevent sharing certain kinds of data with Chinese servers. The result is that while Chinese companies have enough compute to train models, they can’t really provide the kinds of global-scale centralized services that we see from OpenAI and Anthropic — at least, not in the same way.

And open almost always wins when it comes to infrastructure adoption. Open technologies can be used permissionlessly and therefore can be at the center of more innovation. You can host them where you want, experiment with them, alter them, and tweak to fit your use case. Open weights models are not open source, but they are portable and permissionless.

With all this in mind, it makes sense for China to release its AI models openly. It turns a US-created compute disadvantage into a distribution advantage; it commoditizes the layer where American companies make money; and it creates a far more effective global ecosystem than could be established through locked-in, centralized services. It’s obvious to me that there are ecosystem benefits throughout China, from manufacturing to scientific research; every sector can just plug in these models.

The saving grace for American companies has been that US frontier models have outperformed open ones. That gap is now closing:

“Moonshot and Alibaba unveiled models they claim can go toe-to-toe with the best from OpenAI and Anthropic at a fraction of the cost. The rapid-fire releases suggest America’s lead at the AI frontier is increasingly tight, just as the technology is becoming central to national security, economic power, and geopolitical influence.”

Even without these new capabilities, the strategy has already been working. a16z partner Martin Casado noted in the Economist that there’s an 80% chance that any given startup is using Chinese models, and Chinese models are poised to take the lead.

It’s worth taking a step back and considering the surprising underlying dynamics. We think of China as being a locked-down society — and it is in many ways. I have serious concerns about how these models might reflect Chinese government perspectives (try asking them about Tiananmen Square). But it’s American companies that are keeping tight control of their technology rather than releasing it as openly as possible. This is in stark contrast to the strategy behind US government support for the open internet, for example.

Locked-down business practices for a technology with no real moat but significant potential ecosystem benefits is an obviously losing strategy; permissively releasing it with an open, collaborative approach is obviously a winning one. But the incentives in the US aren’t there: instead, these companies are forced to chase first-order profits rather than ecosystem benefits, and the government tries to put its finger on the scale through forcible measures like tight export controls. We should consider what would need to change to make those incentives more aligned. That’s particularly important given how much of the US economy is currently driven by AI spending. If the bottom falls out of that spending — and I think it clearly will, given the dynamics — the outcome could be severe.

I care about having open technology that can be run in the public interest, aligned with the public’s values. Threads like public AI, federated services, and open research have traction but need backing. Getting there in the US needs more nuanced strategy and support than we’re seeing today.


This Conversation Is Being Recorded. They All Are.

I’ve been thinking about this story for days.

“A Zoom call isn’t complete without an artificial-intelligence note taker. Phones are out at meetings, capturing every word. During impromptu conversations with co-workers, someone might turn on the Granola transcription app, which can turn the interactions into one-page summaries or a list of action items. Even at bars and on dates, people are using AI-infused listening apps to analyze conversations later on.”

The story goes on to talk to a woman who uses Granola to record her dates, then pours the transcripts into Claude to give her feedback about how she could have done better. And there’s account after account of people using it in meetings without asking for consent or revealing that they’re recording.

Certainly in Silicon Valley, a societal shift seems to be underway. It’s likely much more widespread than that. I’ve been present in meetings outside the tech industry where Granola’s watermarking was visible but I wasn’t asked to consent. The watermarking is optional; I have to assume I’ve been in meetings where I’ve been recorded without my knowledge.

Pair this trend with the story that the Trump Administration actively sought the phone records of journalists — and their families — who reported on the new Qatari-gifted Air Force One. Subpoenas were issued to the phone carriers, and the Department of Justice notified the newsroom a week later. In some cases, subpoenas can be issued to carriers and service providers privately, allowing the data to be retrieved without the newsroom’s knowledge; in this case, the DoJ did try to gag the phone company from alerting the newsroom.

A world in which every conversation is recorded and transcribed is one where every conversation can be subpoenaed or surveilled. Here, the surveillance is decentralized through people who actively want to conduct it for their own benefit, but the data is still stored centrally and available for authorities to subpoena or someone else to mine. Granola’s security page makes clear that the data is accessible to them — and therefore to a third party that compels them to hand it over — and notes that:

“Granola trains on your anonymized data so we can keep making Granola better. You can opt out of this in your Settings.”

Granola makes a point of saying that audio is not stored, but given that transcriptions are, this seems moot: the words in a conversation carry its meaning. Subpoenas for your conversations go to it, not to you, and you may never know they were served. If you record someone’s conversation without letting them know, you’re putting them at risk.

Don’t get me wrong: I would love to have an automatic summary of meetings I’ve taken part in. I have also run meetings on non-sensitive topics where I’ve asked for consent before starting transcription. It’s the ubiquity and covert nature of the transcription that bothers me, paired with its central storage in what amounts to a honeypot for subpoenas and hackers.

Recording a conversation with someone without their consent is illegal in many states and countries, so this behavior may be forced to change. California is one of them, and Granola appears to be thriving there, so there is a world where the law changes to meet the new ubiquitous surveillance norm. Until the dust settles one way or the other, anyone who wants to talk about a sensitive topic, particularly in Silicon Valley, will need to be more wary than usual.


How OpenAI’s human mistake led to the AI-powered hack on Hugging Face

The biggest technology story this week was how a combination of OpenAI models hacked into third-party AI provider Hugging Face and breached its production database. The incident was initially spun as a sort of partnership between the two companies, but it seems like that’s not what went down at all.

“OpenAI failed to properly configure what it called a ‘highly isolated environment,’ allowing a testing sandbox that should have been completely secluded from the internet to actually connect to the internet.”

That’s actually one of at least two lapses here: not only did OpenAI fail to properly isolate its models, but Hugging Face’s production database was in a state where those models could hack into it. The whole thing does not speak well of security practices at AI vendors overall.

We’re being asked to share more and more private information with model vendors. The standard protection they offer — at least, to their paying customers — is that your data will not be used for model training purposes. That’s all well and good, but your data is still hitting their servers, potentially being logged for an extended period in such a way that it could, in theory, be accessed by their employees. Even before we bring in the possibility of hackers, that leaves your private data open to being accessed via subpoena, an unscrupulous employee, or, indeed, an unscrupulous vendor. (Consider that Uber breached at least one journalist’s privacy and considered hiring an opposition research firm. Do we really think AI vendors are more ethical? Why?)

Leaving a production database in a state where it could be breached is the icing on the cake. In this case, the models weren’t even harnessed to hack Hugging Face — they did so autonomously to cheat a test. Imagine what they might do if they were intentionally pointed that way. Hacking is becoming cheaper and easier: once the preserve of talented technologists, this story proves that the latest frontier models can effectively find and exploit vulnerabilities in systems. And apparently, AI vendors can’t be trusted to secure their own infrastructure. The combination of us being encouraged to share more and more data, the inherent risks of centralizing that data, the dubious security of the places we’re being asked to share it, and the obvious shadiness of some of the companies involved should give us all pause.

For newsrooms and anyone dealing with sensitive or private data, particularly relating to source materials or journalism in progress, this weak security environment is not enough. We need zero data retention contracts at minimum, but the only real way to be sure nobody can access our information is to use confidential computing environments and, ultimately, local models. Anything less leaves our work open to cowboys, hackers, and, apparently, misconfigured robots.


Staying in a job for the health insurance? About 1 in 4 Americans do, a survey says

This is a striking, but not necessarily surprising, figure from a new survey by the West Health-Gallup Center on Healthcare in America:

“A new report finds that nearly a quarter of workers who get health insurance through their jobs report staying in unwanted jobs for health insurance — a figure that's risen dramatically in the last five years.”

The figure rises to 41% of people with three or more chronic health conditions. The figure has risen wildly in part because Affordable Care Act subsidies were allowed to expire.

I’ll get the soapbox out of the way first: having spent around thirty years of my life in the UK before moving to the US, the thing I miss most is the NHS. It’s been treated like a political football since I left and is apparently a shell of its former self — not because the idea is bad and can’t work but because conservative politicians, some of whom have received funding from private healthcare companies, have deliberately sabotaged it. But it’s hard to explain the lack of fear of walking into a doctor’s office or a hospital. You know for a fact that there won’t be an onerous bill. You can just get seen. That security allowed me to found my first startup, which in turn has set the stage for my entire career.

If you’re in the US, you may have heard some less pleasant things about socialized healthcare: it turns out much of it was a deliberate disinformation campaign by private health insurers, which I think says a lot about how the whole American healthcare system actually works.

That soapbox out of the way, I also want to highlight how the private healthcare system creates perverse incentives for employers and dampens innovation.

If employees have freedom of movement between companies, the incentive for employers is to create the best working conditions possible: higher wages, great benefits, a nurturing working environment. If, on the other hand, some employees are effectively chained to their desks by their need to have healthcare, employers have less of a need to provide those things. As long as they provide a reasonable health plan, wages and working conditions are secondary. As the West Health-Gallup Center themselves assert, the effect is lower wages and worse work.

In turn, fewer innovators are empowered, which is a disaster for industries like news that desperately need innovation. Often, innovators will find themselves constrained by their existing employers for various reasons and want to leave to explore a new idea that has the potential to change their industry. (That was my experience leaving the university sector to build a social platform for learning, which was ultimately used by Ivy Leagues, non-profits, and governments around the world.) If they can’t because they’re tethered to employers who won’t greenlight their ideas, those innovations will never see the light of day.

So not only does socialized healthcare allow people to be healthier by removing the fear of going to the doctor in the first place, it improves wages, creates more competitive working conditions, and promotes innovation.

Even a representative for the Cato Institute — a libertarian think tank — has this to say in the piece:

“Favoring employer-sponsored health insurance creates coverage gaps, reduces income mobility, and is crying out for reform.”

When even the libertarians want reform, you know it’s a bad deal. We need a different healthcare system. While the libertarians would likely disagree, my vote — having experienced and enjoyed it for much of my life — is for universal healthcare. The only real downside to it is that a bunch of companies that have entrenched their positions taking advantage of ordinary people will be denied a little profit. Which, you know. Pardon me while I find my tiny violin.


And more:

Here are some of the stories I didn't get a chance to go into in depth this week.

Protecting our FLOSS commons from LLMs

The source code repository hosting service Codeberg has banned LLM-generated code. Time will tell whether that's a move that solidifies a niche as a place for hand-crafted software, or whether it just turns people back to GitHub.

Google search traffic to leading UK publishers set to halve by Q3 2027

The march towards Google Zero continues apace. I believe the most effective way to build resilience against this trend is by building stronger relationships – not just one-way audience strategies, but real community.

The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required

A court upheld that border agents have the right to search your phone. Newsrooms should build strong, repeatable guidance for journalists who might want to cross borders with source information.

Kaiser Permanente nurses say technology is making their jobs — and patient care — worse

Despite what vendors and management say, the people who are actually on the ground providing healthcare report that AI is having a detrimental effect on the care they can provide. That will eventually come to a head – particularly if it starts to reveal itself in patient outcome statistics.