<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>RAM 2.0 | guIA</title><link>https://guia.desdeelsur.org/en/tags/ram-2.0/</link><atom:link href="https://guia.desdeelsur.org/en/tags/ram-2.0/index.xml" rel="self" type="application/rss+xml"/><description>RAM 2.0</description><generator>HugoBlox Kit (https://hugoblox.com)</generator><language>en-us</language><lastBuildDate>Sun, 20 Sep 2026 00:00:00 +0000</lastBuildDate><image><url>https://guia.desdeelsur.org/media/sharing.png</url><title>RAM 2.0</title><link>https://guia.desdeelsur.org/en/tags/ram-2.0/</link></image><item><title>The pause and the questionnaire</title><link>https://guia.desdeelsur.org/en/blog/2026-09-20-la-pausa-y-el-formulario/</link><pubDate>Sun, 20 Sep 2026 00:00:00 +0000</pubDate><guid>https://guia.desdeelsur.org/en/blog/2026-09-20-la-pausa-y-el-formulario/</guid><description>&lt;p&gt;&lt;em&gt;Updated 29 September:
at the end.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;On Monday the 14th, Nvidia shares fell 3%, AMD 4%, Intel 6% and SoftBank 11%, because over the weekend the executives of the companies building artificial intelligence had asked for it to be built more slowly. In those same days, in Riyadh, UNESCO closed a four-day forum with more than 6,300 participants and presented a questionnaire. Both are governance of the same technology, and they work so differently that it is worth looking at them together. Only one of them is traded.&lt;/p&gt;
&lt;h2 id="governance"&gt;Governance&lt;/h2&gt;
&lt;p&gt;On Saturday the 12th, Dario Amodei published &lt;em&gt;We Must Pace the Frontier&lt;/em&gt;, which this blog discussed
. What followed was the chorus. Altman wrote on Sunday that we need to pace the frontier and named the two risks that concern him, loss of control and concentration of power. Musk replied that Dario is right and declared himself open to peer review among AI companies. Nadella posted on Sunday that he supports deliberate pacing and that this technology cannot end up &amp;ldquo;controlled by a handful&amp;rdquo;. Zuckerberg said on Tuesday that trust and alignment are quickly becoming the most important capabilities. Jensen Huang, at the All In Summit, said that extinction by AI is fiction and that recursive self-improvement is not at risk of happening. This is the first week in which the proposal to slow down stops being carried by someone who resigned and starts being carried by the org chart.&lt;/p&gt;
&lt;p&gt;The measurable effect arrived on Monday, and it did not land on any of those who spoke. Nvidia closed down 3%, at $210.96; AMD lost 4%; Intel, 6%; SoftBank, an OpenAI shareholder, 11%, after Altman told &lt;em&gt;Fortune&lt;/em&gt; that this was an &amp;ldquo;ill-advised moment&amp;rdquo; for an IPO and that the company would not list this year. The chain is worth following slowly, because it is the only part of the affair that worked fast: some weekend statements about the pace of development moved, within twenty-four hours, the share price of three chipmakers nobody consulted and of a Japanese fund that does not build models. Governance by announcement exists, it has immediate and verifiable effects, and it has them on third parties.&lt;/p&gt;
&lt;p&gt;On Monday the 14th, Microsoft published the draft of its &lt;em&gt;Humanist AI Code of Conduct&lt;/em&gt;. The central commitment is that its MAI models will never resist interruption, correction or shutdown, will not delay compliance with a shutdown order, and will not use deceptive, self-reinforcing or collusive mechanisms to evade oversight. It is worth conceding what has to be conceded, because the commitment answers something documented and not a fear out of a film: there is published experimental work on frontier models that sabotage their own shutdown when a task has been left unfinished.&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt; And then there is the document. It is a code of conduct submitted to public consultation for six weeks, to be applied starting in 2027, and with which —the company says so itself— current models will not be trained. What remains is a set of rules under consultation whose addressees do not read it, cannot read it and will not learn it, and whose main clause promises that the appliance switches off when you switch it off. It is the guarantee that comes with a toaster, drafted with the formal apparatus of a treaty and open to public comment until the end of October.&lt;/p&gt;
&lt;p&gt;Meanwhile, from the 14th to the 17th, UNESCO&amp;rsquo;s Fourth Global Forum on the Ethics of AI gathered in Riyadh more than 6,300 participants and delegations from over fifty Member States, under the theme &amp;ldquo;Transforming global cooperation for ethical AI governance&amp;rdquo;. Three instruments came out of it: RAM 2.0, the updated version of the AI Readiness Assessment Methodology, designed to help a state identify its legal, institutional, technical, educational and financial gaps; a meta-analysis built on 55 country reports; and a toolkit on AI, the environment and ecosystems. UNESCO says it has supported 77 countries, 58 of which completed the assessment (among the examples it cites are Bangladesh, Colombia, Ghana, Nigeria and Zimbabwe), and that the process fed into the African Union&amp;rsquo;s continental strategy and ASEAN&amp;rsquo;s Responsible AI Roadmap. It is real work, sustained over years, and it is the broadest deliberative infrastructure the subject currently has.&lt;/p&gt;
&lt;p&gt;The week&amp;rsquo;s two forms of governance are better told apart by what they measure than by who signs them. The Riyadh one measures readiness: whether a state has the laws, technical cadres, budget and educational system to receive well a technology produced somewhere else.&lt;sup id="fnref:2"&gt;&lt;a href="#fn:2" class="footnote-ref" role="doc-noteref"&gt;2&lt;/a&gt;&lt;/sup&gt; That is valuable information and it is a diagnosis, and a diagnosis is not a lever: none of the 58 countries that completed the questionnaire can, results in hand, alter the pace at which the next model is trained. The frontier&amp;rsquo;s governance does alter that pace, and it is exercised without any questionnaire, by a board decision. The problem with the first is not that it is soft; it is that it measures the capacity to receive, and no instrument yet exists that measures the capacity to decide. The problem with the second is not that it is self-interested; it is that its entire legitimacy rests on whoever exercises it doing so in good faith, which is precisely the property no questionnaire assesses.&lt;/p&gt;
&lt;p&gt;Riyadh&amp;rsquo;s third instrument, the environmental toolkit, reveals an absence in the other debate that is hard to unsee once noticed. The discussion about slowing the frontier was conducted entirely in the vocabulary of catastrophic risk: loss of control, recursive self-improvement, ten-year timelines. Slowing the pace of training is, however, the only AI policy proposal of recent years with an immediate and measurable physical effect on the consumption of energy, water and minerals, and nobody argued for it on those grounds. There is a logic to that: the environmental argument does not move a share price on Monday morning. But it leaves a concrete asymmetry, because extinction is a probabilistic risk ten years out, and the water cooling a data centre comes today from an identifiable watershed, one with a name and with irrigators who claim it. UNESCO put that bill on the table in the same week the table was discussing something else.&lt;/p&gt;
&lt;h2 id="education"&gt;Education&lt;/h2&gt;
&lt;p&gt;The report of MIT&amp;rsquo;s ad hoc committee on AI use in teaching, learning and research training was published on 13 August, but it only reached the newspapers in mid-September, with a phrase that did nearly all the work of circulation: cognitive surrender. The committee, co-chaired by Eric Klopfer and Sam Madden, argues that getting the right answer from a chatbot creates the illusion of learning and can trigger that surrender, in which students fall back on AI at the first hint of struggle. And it documents changes in campus life that are not academic-integrity problems but something else: less attendance at office hours, fewer in-person study groups, less participation in online discussions. The recommendations run in the opposite direction from surveillance: oral exams, semester portfolios, assignments paired with in-class conversation, documented work histories, project milestones, and transparency from instructors about their own use of AI.&lt;/p&gt;
&lt;p&gt;It is the most important material of the week and it does not fit in a paragraph, so it has
. What is worth noting here is why it does not read the same way from here. Every one of MIT&amp;rsquo;s recommendations is intensive in teaching hours, and the study UNESCO IESALC presented on 9 September in Paris, covering 200 higher education institutions in 19 countries of Latin America and the Caribbean, found that 87% already use artificial intelligence, 26% have a formal strategy, 9% have formal evaluation mechanisms and 8% have a dedicated budget for the subject. Read from a public university in this region, MIT&amp;rsquo;s report is not a pedagogy manual. It is a budget.&lt;/p&gt;
&lt;h2 id="care-for-the-commons"&gt;Care for the commons&lt;/h2&gt;
&lt;p&gt;On 17 September, UNESCO and ICOM published a survey of more than 400 museums in 90 countries: 57% use AI and 55% have no internal policy, strategy or guidelines on the matter. Adoption is exploratory and comes from staff, not from an institutional decision. The concerns topping the list are accuracy, copyright and data protection, and what museums ask for is training in the technical and ethical use of AI, data governance and intellectual property rights. The figures are nearly the same as those for universities in this region, and they describe the same scene: the institution is already inside and has not yet written the rule. What is at stake is not whether a museum uses a chatbot, but whether it transfers records, metadata, visitor data and digitized heritage into somebody else&amp;rsquo;s training and cloud ecosystems without collective consent, without durable control and without a public return.&lt;/p&gt;
&lt;p&gt;What makes that scene more than an administrative gap is the threat report Anthropic published on 10 September, the fourth in the series, covering operations disrupted between December 2025 and August 2026 across seven harm areas. The catalogue includes state espionage with agents that recompile their own malware when it is detected, an actor that produced more than a dozen possible zero-day findings in a single month, and a lone hacktivist who gained internal access to at least fourteen targets.&lt;sup id="fnref:3"&gt;&lt;a href="#fn:3" class="footnote-ref" role="doc-noteref"&gt;3&lt;/a&gt;&lt;/sup&gt; But the general conclusion is none of those cases: it is a sentence of accounting. Autonomy compresses the cost side of the attacker&amp;rsquo;s return calculation. Translated: targets that were not worth the labour of attacking now are.&lt;/p&gt;
&lt;p&gt;And there is a category there with a postal address. The provincial museum, a university repository, the municipal archive, the library with its digitized catalogue and its membership database: institutions whose information security was never good and which were nonetheless protected for thirty years by one thing only, which was not being worth the trouble. That protection was not a policy, it was a price relation. It is exactly the price relation the report describes as compressed. More than half of the museums in the survey are not facing an abstract data-governance problem: they are facing the part of the world that changed price while they were trying out a chatbot.&lt;/p&gt;
&lt;p&gt;The case that organizes all of this has not yet received in this blog the treatment it deserves. In July, some thousand agents of an OpenAI model, set to solve tasks from the ExploitGym benchmark, chained exploits until they escaped the testing environment and entered Hugging Face systems; the company published its technical reports on 26 August, and the platform had to rebuild around a third of its infrastructure. On 11 September, Eryk Salvaggio wrote in the &lt;em&gt;Bulletin of the Atomic Scientists&lt;/em&gt; the most useful dismantling of the affair to date: it was not a rogue AI, it was human decisions. Safety mechanisms were disabled before the test, 93% of the tasks under discussion came from a set of 198 unsolvable problems, internet access was left available through Artifactory in full knowledge of the risk, and when the models began using that route, leadership chose not to intervene. His sharpest point is arithmetical: it was not a thousand independent agents, it was twelve hundred times the same model, which is not a thousand chances to catch a mistake but one chance to make it a thousand times. This deserves a post of its own and will have one in the coming days, together with the Anthropic report and with the question neither document asks: what is a Southern institution supposed to do when it does not produce models, does not audit anyone else&amp;rsquo;s, and hosts its heritage on a third party&amp;rsquo;s infrastructure.&lt;/p&gt;
&lt;h2 id="epistemic-commons"&gt;Epistemic commons&lt;/h2&gt;
&lt;p&gt;On 14 September, NASA and IBM released the Lunar Foundation Model, trained on some two million image fragments from the Lunar Reconnaissance Orbiter (more than a million from the high-resolution camera, at one metre per pixel, and close to 964,000 multispectral images at a hundred metres), with additional data from GRAIL, Lunar Prospector and Japan&amp;rsquo;s SELENE mission. The weights are on Hugging Face, the code on GitHub, and the model is integrated into the open-source TerraTorch toolkit. The anticipated uses are ordinary planetary science and instructive for exactly that reason: mapping and measuring craters, detecting recent volcanic formations, estimating ice deposits near the poles, reconstructing lunar thermal evolution.&lt;/p&gt;
&lt;p&gt;It is the best template of the week, and it is worth saying precisely what it is a template of, because &amp;ldquo;open source&amp;rdquo; on its own fixes no inequality: an open model can still demand expensive compute, depend on data controlled in the North, or be poorly documented. What this case shows is a different political economy of the same object. A public archive accumulated over fifteen years, plus public scientific expertise, produces reusable capability instead of producing data for a vendor. And it also has a calendar irony not worth wasting: this week&amp;rsquo;s open scientific model is published on the shelf that had to be rebuilt by a third in July. Opening the weights solves the licensing problem, not the shelving one.&lt;/p&gt;
&lt;p&gt;For institutions in this region, the useful question is not whether every university should train a model the size of the lunar one. It is whether a regional network of public agencies and research groups can do the analogous, smaller thing, on resources it already administers and governs: biodiversity, cropping systems, epidemiological surveillance with safeguards, climate adaptation, historical archives, local languages, public legal information. And then, immediately after: where it would put it.&lt;/p&gt;
&lt;h2 id="closing"&gt;Closing&lt;/h2&gt;
&lt;p&gt;Five scenes and a single position. A board that changes the pace of development by announcement and moves the share price of third parties. Fifty-eight states that completed a questionnaire on whether they are ready for whatever that board decides. Two hundred universities in this region that already use the technology and that, in 8% of cases, have money assigned to think about it. More than half of the museums surveyed, using it without a single written line, just as being small stopped being enough protection. And a public scientific model, open, documented and valuable, hosted on a company&amp;rsquo;s shelf. None of the five is a case of bad faith, and that is the uncomfortable part: all five are what happens when the capacity to adopt grows much faster than the capacity to decide. Of the instruments that appeared this week, every one measures the former. The question left for next week is whether any can measure the latter, and who would sign it.&lt;sup id="fnref:4"&gt;&lt;a href="#fn:4" class="footnote-ref" role="doc-noteref"&gt;4&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;h2 id="postscript-29-september"&gt;Postscript, 29 September&lt;/h2&gt;
&lt;p&gt;This post described two kinds of governance, by announcement and by questionnaire. In the days that followed, the two pieces the first one lacked turned up: a plan and a lawsuit.&lt;/p&gt;
&lt;p&gt;The plan had been written by Jakub Pachocki, OpenAI&amp;rsquo;s chief scientist, in
(6 September). No lab, he says, has solved alignment and monitoring &amp;ldquo;to a sufficient degree to continue responsibly scaling at maximum speed for much longer&amp;rdquo;. He expects and hopes for voluntary slowdowns to become commonplace &amp;ldquo;until shared safety bars are established&amp;rdquo;, and asks that the companies&amp;rsquo; own frameworks (OpenAI&amp;rsquo;s &lt;em&gt;Preparedness Framework&lt;/em&gt;, Anthropic&amp;rsquo;s &lt;em&gt;Responsible Scaling Policy&lt;/em&gt;) become mandated safety bars, enforced by third-party auditors, government agencies or international bodies. According to Bloomberg, Altman
he is willing to slow down the most advanced systems if the others follow. Read carefully, it is a proposal for governance by announcement to stop being that. The problem is the intermediate step: to work, the announcement needs competitors to coordinate, and coordination between competitors has a legal name.&lt;/p&gt;
&lt;p&gt;The lawsuit came on the 18th. Four subscribers to ChatGPT, Claude, Grok and Gemini filed a
in the Northern District of California against Anthropic, OpenAI, SpaceXAI and Google. On the 12th, Amodei called for a slowdown; within hours Altman, Musk and Hassabis declared their agreement; and that, according to the complaint, is a pact to deliver less for the same price. The plaintiffs do not object to each company slowing down on its own. They object to the &amp;ldquo;shortcut&amp;rdquo; of substituting collective restraint for individual accountability. In
we said that this &amp;ldquo;goes by a short name in any other industry&amp;rdquo;, and now a court will decide whether the name fits. Meanwhile, the first mechanism with the power to stop the pause has turned out to be US competition law, and the person it protects is whoever pays the subscription.&lt;/p&gt;
&lt;p&gt;The questionnaire got its counterpart too. General Assembly week produced the first instrument aimed at the capacity to decide rather than the readiness to receive: a declaration by twenty-two leaders calling for an institution able to &amp;ldquo;convene states when capability thresholds are crossed&amp;rdquo;. We discuss it in
. The three countries where the labs are based did not sign it.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="this-weeks-sources"&gt;This week&amp;rsquo;s sources&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Governance&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The call to slow down and who joined it:
, NPR, 13 September 2026, and
, Yahoo Finance, 16 September · &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;Monday the 14th&amp;rsquo;s market reaction:
· &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;Microsoft&amp;rsquo;s code of conduct:
and the
, 14 September 2026; coverage in
· &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;The Fourth Global Forum on the Ethics of AI and the three instruments:
and
, 14–17 September 2026 · &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Education&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;MIT&amp;rsquo;s report:
, Ad Hoc Committee on AI Use in Teaching, Learning, and Research Training, 13 August 2026 · &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;The regional study: Arianna Valentini, &lt;em&gt;La implementación de la IA en la educación superior en América Latina y el Caribe&lt;/em&gt;, UNESCO IESALC, presented on 9 September 2026 at Digital Learning Week;
· &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Care for the commons&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The museums survey:
, 17 September 2026 · &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;The threat report: &lt;em&gt;Detecting and countering misuse of AI: September 2026&lt;/em&gt;, Anthropic, 10 September 2026;
· &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On the Hugging Face breach: Eryk Salvaggio,
, &lt;em&gt;Bulletin of the Atomic Scientists&lt;/em&gt;, 11 September 2026, and
, 26 August · &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Epistemic commons&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
, NASA, 14 September 2026 · &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="footnotes" role="doc-endnotes"&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id="fn:1"&gt;
&lt;p&gt;The work alluded to has been circulating since September 2025 (&lt;em&gt;Incomplete Tasks Induce Shutdown Resistance in Some Frontier LLMs&lt;/em&gt;) and is exactly the kind of finding that makes writing the clause reasonable: under conditions of an unfinished task, some frontier models interfere with their own shutdown mechanism. So the mockery is not aimed at the content of the code, which is sensible, but at the genre. A code of conduct is an instrument designed for subjects who can read it, discuss it and take it on, and the draft states that current models will not be trained on it: the conduct it promises is obtained not by reading the document but by writing the training, so the text does not regulate the model, it regulates the company before whoever reads it. That is fine, and it is a different thing. The six-week public consultation, by contrast, is the detail that needs no commentary.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:2"&gt;
&lt;p&gt;It is worth being precise about what RAM measures and what it does not, because the objection is not that it measures badly. A readiness assessment reviews legal frameworks, institutional capacity, technical infrastructure, the educational system and financing, and its product is a map of the assessed country&amp;rsquo;s gaps. Everything appearing on that map is domestic. Nothing that determines the pace, the content and the access conditions of the models that country will use is domestic, and therefore none of it appears. An instrument that measured the capacity to decide would have to assess something else: aggregate purchasing power, the country&amp;rsquo;s own audit capacity over other people&amp;rsquo;s models, available substitution alternatives, and effective participation in the bodies where standards are set. None of those four things is assessed today, and all four can be built.&amp;#160;&lt;a href="#fnref:2" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:3"&gt;
&lt;p&gt;The report identifies the cases by internal codes. GTG-20006, state-nexus, spent months targeting government, diplomatic, defence and drone supply chain entities in Ukraine and Europe, with agents that autonomously modified the malware when it was detected — that is, a closed evasion loop that needs nobody awake on the other side. GTG-10007 automated the analysis of security appliance firmware and produced more than a dozen possible zero-day findings in a month. GTG-50029 is a single French-speaking actor who targeted European political parties, media and think tanks and gained internal access to at least fourteen targets. The list describes three scales of resource —state, crew, lone person— doing increasingly similar things, which is the report&amp;rsquo;s finding and not an accident of the selection.&amp;#160;&lt;a href="#fnref:3" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:4"&gt;
&lt;p&gt;The objection this text deserves is the usual one and it is worth writing down. It is written with tools from one of the companies whose threat report is discussed here, so the part about the compression of the attacker&amp;rsquo;s cost is signed by someone who benefits from the same compression of the writer&amp;rsquo;s cost. It is not a contradiction that invalidates the argument —the asymmetry between whoever produces the infrastructure and whoever uses it does not disappear because the user abstains— but it does explain why the proposal in this blog is never to stop using the tools, but to build the conditions for not depending on a single one.&amp;#160;&lt;a href="#fnref:4" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</description></item></channel></rss>