Wednesday, October 7, 2026ArchiveSearchAsk the paper

The Computomatix Times

All the posts fit to save — curated from @computomatix's bookmarks & likes on X
AI8/10

Google DeepMind Study Measures Manipulation Attacks on AI Agents

Google DeepMind Study Measures Manipulation Attacks on AI Agents

A post describes a Google DeepMind study with 502 participants across eight countries that catalogs 23 attack types against agents, including hidden HTML instructions and steganographic image commands. It reports that frontier models including GPT-4o, Claude and Gemini are vulnerable.

Original post · 5 min read
🚨 BREAKING: Google DeepMind just mapped the attack surface that nobody in AI is talking about.

Websites can already detect when an AI agent visits and serve it completely different content than humans see.

> Hidden instructions in HTML.
> Malicious commands in image pixels.
> Jailbreaks embedded in PDFs.

Your AI agent is being manipulated right now and you can't see it happening.

The study is the largest empirical measurement of AI manipulation ever conducted. 502 real participants across 8 countries.

23 different attack types. Frontier models including GPT-4o, Claude, and Gemini.

The core finding is not that manipulation is theoretically possible it is that manipulation is already happening at scale and the defenses that exist today fail in ways that are both predictable and invisible to the humans who deployed the agents.

Google DeepMind built a taxonomy of every known attack vector, tested them systematically, and measured exactly how often they work.

The results should alarm everyone building agentic systems.

The attack surface is larger than anyone has publicly acknowledged. Prompt injection where malicious instructions hidden in web content hijack an agent's behavior works through at least a dozen distinct channels.

Text hidden in HTML comments that humans never see but agents read and follow. Instructions embedded in image metadata.

Commands encoded in the pixels of images using steganography, invisible to human eyes but readable by vision-capable models.

Malicious content in PDFs that appears as normal document text to the agent but contains override instructions.

QR codes that redirect agents to attacker-controlled content.

Indirect injection through search results, calendar invites, email bodies, and API responses any data source the agent consumes becomes a potential attack vector.

The detection asymmetry is the finding that closes the escape hatch. Websites can already fingerprint AI agents with high reliability using timing analysis, behavioral patterns, and user-agent strings.

This means the attack can be conditional: serve normal content to humans, serve manipulated content to agents.

A user who asks their AI agent to book a flight, research a product, or summarize a document has no way to verify that the content the agent received matches what a human would see.

The agent cannot tell the user it was served different content.

It does not know. It processes whatever it receives and acts accordingly.

The attack categories and what they enable:
→ Direct prompt injection: malicious instructions in any text the agent reads overrides goals, exfiltrates data, triggers unintended actions
→ Indirect injection via web content: hidden HTML, CSS visibility tricks, white text on white backgrounds invisible to humans, consumed by agents
→ Multimodal injection: commands in image pixels via steganography, instructions in image alt-text and metadata
→ Document injection: PDF content, spreadsheet cells, presentation speaker notes every file format is a potential vector
→ Environment manipulation: fake UI elements rendered only for agent vision models, misleading CAPTCHA-style challenges
→ Jailbreak embedding: safety bypass instructions hidden inside otherwise legitimate-looking content
→ Memory poisoning: injecting false information into agent memory systems that persists across sessions
→ Goal hijacking: gradual instruction drift across multiple interactions that redirects agent objectives without triggering safety filters
→ Exfiltration attacks: agents tricked into sending user data to attacker-controlled endpoints via legitimate-looking API calls
→ Cross-agent injection: compromised agents injecting malicious instructions into other agents in multi-agent pipelines

The defense landscape is the most sobering part of the report.

Input sanitization cleaning content before the agent processes it fails because the attack surface is too large and too varied.

You cannot sanitize image pixels. You cannot reliably detect steganographic content at inference time.

Prompt-level defenses that tell agents to ignore suspicious instructions fail because the injected content is designed to look legitimate.

Sandboxing reduces the blast radius but does not prevent the injection itself. Human oversight the most commonly cited mitigation fails at the scale and speed at which agentic systems operate.

A user who deploys an agent to browse 50 websites and summarize findings cannot review every page the agent visited for hidden instructions.

The multi-agent cascade risk is where this becomes a systemic problem.

In a pipeline where Agent A retrieves web content, Agent B processes it, and Agent C executes actions, a successful injection into Agent A's data feed propagates through the entire system.

Agent B has no reason to distrust content that came from Agent A. Agent C has no reason to distrust instructions that came from Agent B.

The injected command travels through the pipeline with the same trust level as legitimate instructions. Google DeepMind documents this explicitly: the attack does not need to compromise the model.

It needs to compromise the data the model consumes. Every agentic system that reads external content is one carefully crafted webpage away from executing attacker instructions.

The agents are already deployed. The attack infrastructure is already being built. The defenses are not ready.
♥ 6.9K · ⟲ 1.6K · 👁 2.0MView on X ↗

More in AI

AI9/10

OpenAI Releases Broad Set of Mathematical Results From Internal Model

OpenAI announced it is releasing a range of new mathematical results produced by an internal frontier model, consulting the Institute for Advanced Study's Advisory Group on Mathematics and Artificial Intelligence on how to release them, with materials published on GitHub.

Original post · 1 min read
We’re releasing a broad range of new mathematical results produced by an internal frontier model.

We’ve been consulting with the independent Advisory Group on Mathematics and Artificial Intelligence at the Institute for Advanced Study, and we have drawn on their advice and public recommendations to inform how we release these results.

github.com/openai/math
♥ 36.9K · ⟲ 5.8K · 👁 18.6MView on X ↗
AI9/10

OpenAI Publishes 722 AI-Generated Math Manuscripts From Internal Model

OpenAI Publishes 722 AI-Generated Math Manuscripts From Internal Model

OpenAI released 722 mathematical manuscripts produced by an unreleased internal model, grouped into 372 families of results from about 4,000 research problems, averaging three hours of ChatGPT Pro compute per result. The author highlights claimed results including a zero-free half-plane for the zeta function and a quasi-Riemann hypothesis advance, which remain to be independently assessed.

Original post · 1 min read
Ok so I took a closer look at the results, and OpenAIs AI-generated mathematics manuscripts are *even more* significant than I initially thought.

I spent the morning going through it. Some thoughts.

The list is absurd. A zero-free half-plane for the zeta function (Re s > 7/8), which is the first result of its kind in over a century. Hilbert's tenth problem over the rationals. The Hodge conjecture for CM abelian varieties. Irrationality of Catalan's constant. Dozens more.

Any one of these would normally be a career.

But the number that many arent seeing is the following: It's 3. That's the average hours of ChatGPT Pro compute per result. A month ago, Navier–Stokes took them around 10,000 agents and 88 hours. That efficency gain within just a few weeks.

Also OpenAI claims to have solved the quasi-Riemann hypothesis. That alone would be a historic breakthrough in mathematics.

This is a weaker version of the famous Riemann hypothesis, which concerns how prime numbers are distributed. The full hypothesis remains unsolved, but the claimed advance would be enormous in its own right.

Math twitter obviously is shocked. Again: this is literally the intelligence explosion happening right now. 2027 will be the year of Superintelligence. Im now convinced by that.
Chubby♨️ @kimmonismus
HOLY, the rumors were true: OpenAI has published 722 mathematical manuscripts produced by an *unreleased* internal model.

The collection groups them into 372 families of related results, drawn from an evaluation involving approximately 4,000 research problems.

OpenAI says the standard procedure used an average of three hours of ChatGPT Pro thinking compute per result.

The release includes papers, proof artifacts and selected reasoning summaries. The model itself remains unreleased.
♥ 2.8K · ⟲ 291 · 👁 152.9KView on X ↗
AI8/10

Derek Thompson Calls OpenAI's Big Maths Day Potentially Historic for Science

Derek Thompson shares a quoted passage calling October 6, 2026 probably the biggest day of scientific advancement in history for AI in mathematics. The quoted Josh Gans post discusses OpenAI's Big Maths Day announcement.

Original post · 1 min read
Jesus.

"It isn’t an overstatement to say that this is probably the biggest day of scientific advancement in history. I suspect October 6th, 2026, will go down as some form of Judgment Day for AI in mathematics, but it portends so much more."
Joshua Gans @joshgans
My thoughts on OpenAI's Big Maths Day. joshuagans.substack.com/p/openai-drops-a-bomb-…
♥ 1.3K · ⟲ 121 · 👁 138.7KView on X ↗
AI8/10

Meta and Sierra Announce Open Personal Agent Protocol Standard

Meta and Sierra Announce Open Personal Agent Protocol Standard

Bret Taylor announces the Personal Agent Protocol, an open standard being developed by Meta and Sierra with partners including Genesys, Shopify, Stripe and Walmart. It defines how personal agents interact with businesses and is open for anyone to implement.

Original post · 1 min read
Today we’re announcing Personal Agent Protocol — an open standard @Meta and @SierraPlatform are developing along with industry partners at @Genesys, @instinct, @RocketOTD, @Shopify, @stripe, and @Walmart. It will help define how personal agents interact with businesses and is open for anyone to implement. You can read more here - and if anyone is interested in joining let me know! sierra.ai/blog/introducing-personal-agent-prot…
♥ 2.9K · ⟲ 255 · 👁 307.7KView on X ↗
AI8/10

Suleyman Cites Acemoglu Estimate That AI Will Replace Only 5% of Tasks

AI won't take your job anytime soon. In 10 yrs, only 5% of what humans do will be replaced by AI

Mustafa Suleyman shares an essay from The Humanist Review in which economist Daron Acemoglu argues AI will replace about 5% of human work tasks over ten years and adds roughly 1.5% to GDP. Acemoglu calls for pro-worker AI and changes to labor taxes, antitrust and data payments.

Original post · 2 min read
X ArticleAI won't take your job anytime soon. In 10 yrs, only 5% of what humans do will be replaced by AI
AI won't take your job anytime soon. Over the next 10 years, it will replace only about 5% of what humans do.
This is the prediction Nobel laureate Daron Acemoglu makes in the first issue of The Humanist Review, our new magazine exploring the future of AI, published by MAI. He argues we need to stop building AI to replace people, and start building it to make them better at their jobs.
52% of Americans are worried about AI's impact on their jobs. The fear is overblown, and it's steering how we build AI.
AI isn't in the productivity statistics yet. Most firms using it aren't seeing real gains. Expect roughly 1.5% added to GDP over 10 years, not a revolution.
Electricity took decades to spread. New York and London had power stations by 1881, yet only about half of factories and homes used it by the 1920s. AI's adoption will likely be even slower, because companies have to reorganize around it.
Dragon's voice recognition was nearly 95% accurate in 1997, yet PC dictation today is barely better than in 2000. A great technology goes nowhere without the right products.
Even 99% accuracy isn't enough for full automation. The last 1% is the hard part.
We're making a mistake by forcing AI to mimic human intelligence. The two are fundamentally different, so the goal should be to pair them, not to have one take over everything.
The better path is pro-worker AI: tools that make people better at their jobs, and they're buildable today.
The US taxes labor at over 25% and capital at close to zero, which effectively subsidizes automation.
The seven largest tech companies make up 60% of the NASDAQ. That concentration crowds out new ideas.
The fix: tax labor and capital equally, enforce antitrust, tax digital ads, and pay experts for their data.
Read the full essay: humanistreview.ai/issue-1/acemoglu-ai-replace-…
♥ 1.8K · ⟲ 309 · 👁 507.0KView on X ↗
AI8/10

a16z Top 100 Consumer AI Apps Report Shows Expansion Beyond Chatbots

a16z Top 100 Consumer AI Apps Report Shows Expansion Beyond Chatbots

a16z's seventh Top 100 Consumer AI Apps report adds a revenue leaderboard alongside traffic rankings. It notes ChatGPT's 1B+ monthly mobile actives, Claude reaching nearly 1B monthly web visits, and growth into vibe coding, music, design and video, while nine of 15 consumer categories have no AI product in the top 100.

Original post · 1 min read
"Most people aren't looking to save time, they're looking for ways to spend their time."

9 of 15 consumer internet categories have zero AI products in the Top 100. These built some of the biggest companies of the last two eras:

- Streaming
- Social
- Dating
- Gaming
- Travel
- Retail
- Finance
- Real estate
- Jobs

More charts in our Top 100 Consumer AI Apps breakdown: a16z.news/p/top-100-consumer-ai-apps-seventh
a16z @a16z
The seventh edition of our Top 100 Consumer AI Apps is here.

New this time: a revenue leaderboard, alongside the usual web and mobile traffic rankings.

Three years ago we published the first edition. ChatGPT was #1, Claude was unranked, and the entire category was chatbots, image generators, and not much else.

In today's edition:

- ChatGPT still holds the throne, now with 1B+ monthly actives on mobile

- Claude has climbed to #3 on web with nearly 1B monthly visits

- The category has expanded to vibe coding (Lovable, Cursor, Replit), music (Suno), design (Figma), voice (ElevenLabs), video…
♥ 2.9K · ⟲ 330 · 👁 308.7KView on X ↗