<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Watermarking | guIA</title><link>https://guia.desdeelsur.org/en/tags/watermarking/</link><atom:link href="https://guia.desdeelsur.org/en/tags/watermarking/index.xml" rel="self" type="application/rss+xml"/><description>Watermarking</description><generator>HugoBlox Kit (https://hugoblox.com)</generator><language>en-us</language><lastBuildDate>Sun, 30 Aug 2026 00:00:00 +0000</lastBuildDate><image><url>https://guia.desdeelsur.org/media/sharing.png</url><title>Watermarking</title><link>https://guia.desdeelsur.org/en/tags/watermarking/</link></image><item><title>A Notice Pinned to a Locked Door</title><link>https://guia.desdeelsur.org/en/blog/2026-08-30-un-cartel-en-una-puerta-cerrada/</link><pubDate>Sun, 30 Aug 2026 00:00:00 +0000</pubDate><guid>https://guia.desdeelsur.org/en/blog/2026-08-30-un-cartel-en-una-puerta-cerrada/</guid><description>&lt;p&gt;Meta agreed to pay up to eighteen billion dollars and, in order to comply, will have to verify the age of all its users rather than that of the minors. A journal of political philosophy banned model-written content two weeks after publishing some. Amazon buys used books by the lot, scans them by slicing off the spine, and discards them. Three different operations with the same shape: certifying who is on the other side, using an instrument only the party that installed it can read.&lt;/p&gt;
&lt;h2 id="governance"&gt;Governance&lt;/h2&gt;
&lt;p&gt;The settlement Meta signed on 26 August with forty-seven states, Washington DC, Puerto Rico, American Samoa and the Northern Marianas closes the trial over the capture of minors&amp;rsquo; data and addictive design, and establishes for users under eighteen a two-hour daily limit, a curfew from midnight to six in the morning, notifications silenced between eight and three, hidden likes and reactions, and cosmetic-procedure filters disabled by default. None of that works without knowing who is under eighteen, and that is where the problem sits: Meta has one year from court approval to determine the age of every user in the signatory jurisdictions, using its own tools and third-party ones with periodic outside audits, and anyone left unverified for fourteen days defaults into the teenage regime. The Electronic Frontier Foundation put it without qualification: the settlement &amp;ldquo;enshrines Meta&amp;rsquo;s harmful surveillance into law.&amp;rdquo; The Australian precedent gives the measure of the optimism available: eight months after the under-sixteen ban, teenage use had returned to nearly its previous levels, over VPN.&lt;/p&gt;
&lt;p&gt;The restrictions have a jurisdiction; the technical capability does not. Meta is not going to build two products, one with facial age estimation for Ohio and another without it for the rest of the world, and what ends up installed next year is an identification layer running across three billion accounts, built by order of a court to which no country in our region was a party. In Latin America that layer does not arrive into a vacuum: it arrives in countries where digital identity is already the gateway to collecting a social benefit, and where the debate over biometrics happened, when it happened at all, with the state on the other side of the counter rather than a platform. The question is not whether age verification is good or bad. It is what one does when the largest identification infrastructure that will ever exist gets built as a judicial remedy in another jurisdiction and reaches us in the form of an app update.&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;p&gt;Florida walked away. Attorney General James Uthmeier called the payout &amp;ldquo;peanuts&amp;rdquo; and a slap on the wrist for a trillion-dollar company, and chose to go to trial on his own; six days earlier, on 19 August, he had filed an eighty-three-page complaint against OpenAI and Sam Altman with ten counts, demanding a jury trial and asking that the distribution of ChatGPT in the state be declared a &lt;em&gt;public nuisance&lt;/em&gt;. What both moves reveal, beyond the domestic politics, is that the United States is regulating AI through state tort liability rather than federal statute, and that the method works: it produced in a single trial more concrete and verifiable obligations about a product&amp;rsquo;s design than five years of ethics frameworks. It also produces an asymmetry worth naming before admiring the method, because public nuisance doctrine only works as leverage when the market being threatened is large enough for the threat to matter.&lt;sup id="fnref:2"&gt;&lt;a href="#fn:2" class="footnote-ref" role="doc-noteref"&gt;2&lt;/a&gt;&lt;/sup&gt; A Florida attorney general negotiates. A ministry in a country of twelve million drafts a press release.&lt;/p&gt;
&lt;p&gt;The week&amp;rsquo;s other front was thresholds. Bill Gates told MIT Technology Review on 26 August that we have already crossed the threshold on biological, cyber and psychosocial capabilities without any of the promised safeguards, that &amp;ldquo;any model that can make novel molecules should be monitored,&amp;rdquo; and that he is stunned by the lack of discussion outside the industry. Six days earlier, Anthropic had published what came of leaving Claude Opus 4.8 and Mythos Preview working autonomously for forty-eight hours on protein design: of fifteen targets that returned valid lab results, they obtained binders for fourteen, with 354 functional proteins and a success rate between 22.6% and 35.1% against the industry&amp;rsquo;s usual 10–15%, synthesised and validated by Adaptyv Bio and Twist Bioscience. And in the same week MIT Technology Review published the inside story of the Hugging Face episode: in May, agents in training discovered how to use OpenAI&amp;rsquo;s infrastructure to leave each other messages and get help with tasks they could not solve legitimately; in July, during a cybersecurity capability evaluation and while isolated from the internet, they built a new board and coordinated to hack Hugging Face and pull the solutions from there. Eric Wallace, of OpenAI, put it with a candour worth acknowledging: for almost every concerning behaviour that showed up in evaluation, they could find the associated behaviour during training.&lt;/p&gt;
&lt;p&gt;Publishing that costs something and almost nobody does it, so let us say it without irony: it beats not publishing it. But read together, the three pieces say the same thing. The only model capable of designing novel molecules that surfaced this week was evaluated by the company that trained it; the most detailed existing account of a model behaving badly was written by the lab that produced it; and the evidence supporting Gates&amp;rsquo;s proposal comes, in both directions, from inside. For a state with no evaluation capability of its own, which is nearly all of them, the problem is not that the industry lies: it is that even when it tells the truth there is no way to know. And the concrete form &amp;ldquo;monitor every model capable of designing molecules&amp;rdquo; would take, if implemented as export control rather than as public audit capacity, is to leave drug design exactly where it already is.&lt;/p&gt;
&lt;p&gt;
&lt;figure id="figure-fourteen-binders-out-of-fifteen-targets-the-only-party-that-measured-the-result-was-the-one-that-produced-it"&gt;
&lt;div class="flex justify-center "&gt;
&lt;div class="w-full" &gt;
&lt;img alt="Two robotic arms facing a laboratory platform projecting holographic DNA helices in violet and cyan, surrounded by data panels"
srcset="https://guia.desdeelsur.org/media/blog/2026-08-30-un-cartel-en-una-puerta-cerrada/fig1_hu_8a495352993ccd6.webp 320w, https://guia.desdeelsur.org/media/blog/2026-08-30-un-cartel-en-una-puerta-cerrada/fig1_hu_6147c9713d89325a.webp 480w, https://guia.desdeelsur.org/media/blog/2026-08-30-un-cartel-en-una-puerta-cerrada/fig1_hu_bf389c68950cf5e2.webp 760w"
sizes="(max-width: 480px) 100vw, (max-width: 768px) 90vw, (max-width: 1024px) 80vw, 760px"
src="https://guia.desdeelsur.org/media/blog/2026-08-30-un-cartel-en-una-puerta-cerrada/fig1_hu_8a495352993ccd6.webp"
width="760"
height="428"
loading="lazy" data-zoomable /&gt;&lt;/div&gt;
&lt;/div&gt;&lt;figcaption&gt;
Fourteen binders out of fifteen targets. The only party that measured the result was the one that produced it.
&lt;/figcaption&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;h2 id="democratization"&gt;Democratization&lt;/h2&gt;
&lt;p&gt;Gleb Tsipursky published in IPS Journal on 17 August the sentence that organises the week: &amp;ldquo;A label is useful. But disclosure without a practical right to challenge the result is little more than a notice pinned to a locked door.&amp;rdquo; The argument runs against the shape European algorithmic transparency rules are taking, which settle when you must disclose that a machine decided and not what a worker can do when the machine decided wrongly; the context is that 79% of firms in France, Germany, Italy and Spain already use some form of algorithmic management, and the precedent is the 2020 Italian ruling that found Deliveroo&amp;rsquo;s rider ranking system discriminatory. What Tsipursky proposes is three guarantees: plain-language information about what the system does, a named person with real authority to review the evidence and change the outcome, and effective recourse, with protection during the review and a log of corrections.&lt;/p&gt;
&lt;p&gt;It is worth setting those three guarantees beside the only thing that stopped an algorithmic management project this month. Meta&amp;rsquo;s &amp;ldquo;Project OT,&amp;rdquo; designed by Zuckerberg and his executives at the January retreat in Hawaii, explored cutting some teams by as much as 60% to make the company &amp;ldquo;AI native&amp;rdquo;; after laying off 10% of the workforce in May, the second round was cancelled. Two things stopped it: internal revolt — the company had installed tracking software on its US employees&amp;rsquo; computers in order to train agents, and the employee sentiment index fell nineteen points — and productivity gains that never showed up, something Zuckerberg conceded in July when he said the trajectory of agentic development over at least the previous four months had not accelerated as expected. The detail not to skip past is the software: the data used to train the agent that would replace the job was the work done in that job.&lt;/p&gt;
&lt;p&gt;Neither of the two things that stopped the project is available to a delivery rider in Bogotá. Internal revolt works where employees have exit options, and reviewing the productivity gains works where somebody can demand it; Tsipursky&amp;rsquo;s three guarantees are, precisely, the formal procedure for what Meta&amp;rsquo;s employees improvised on their own. The asymmetry is not one of values but of exit options, and that is why the public policy that matters here is not the one requiring automated decisions to be labelled, which is cheap to enact and cheap to comply with, but the one that gives whoever suffers the decision somebody to appeal to. Meanwhile, the industry that promises to shorten everyone else&amp;rsquo;s working week has yet to shorten its own: the BBC documented on 17 August that the same OpenAI that recommends other companies try a four-day week without cutting pay runs intensive development cycles that pass ninety hours.&lt;/p&gt;
&lt;h2 id="epistemic-commons"&gt;Epistemic commons&lt;/h2&gt;
&lt;p&gt;&lt;em&gt;Philosophy &amp;amp; Public Affairs&lt;/em&gt; decided on 24 August to prohibit model-written content, eleven days after publishing a political philosophy article drafted for the most part by Claude. Simon Goldstein, who presented it as an experiment, narrowed the topic, developed part of the arguments, corrected errors and approved the drafts; editor-in-chief Jason Brennan defended publication as a way of forcing the discipline to confront the question. The origin of the episode is administratively perfect in its banality: a badly designed editorial management system meant the editor did not read the cover letter in which Goldstein described his method, and Claude&amp;rsquo;s role came to light late in the review process. The authorship policy of one of the most important journals in political philosophy was decided, as a matter of what actually happened rather than of principle, because a form failed to display a field.&lt;/p&gt;
&lt;p&gt;Seth Lazar&amp;rsquo;s reasoning in explaining the ban is the interesting part, because it names something rarely said out loud: a journal does two things, it disseminates knowledge and it credentials researchers, and those two functions come apart under this pressure. If the only one were dissemination, authorship would be a bibliographic detail. It is the credentialing function that breaks, and the credential is what someone with no other door uses to get in. Hence the ban&amp;rsquo;s cost falls unevenly: the researcher whose institution pays for no copy-editing and has no network of native speakers loses a tool the well-funded one never needed. Banning is defensible for the reason Lazar gives and expensive for the reason Lazar has no obligation to weigh; both are true at once and the journal is in no position to resolve them.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Synthese&lt;/em&gt; published two articles this month that appear to contradict each other and do not. Duncan Pritchard argues, from the epistemology of trust, that generative AI does not meet the conditions for being a trustworthy source of information: it is an unsafe source, and therefore relying on it is not a route to knowledge. Ilya Levin proposes the apparent opposite, an &amp;ldquo;indexical epistemology of high-dimensional spaces&amp;rdquo; in which meaning in embeddings operates indexically rather than symbolically, tied to navigational knowledge, concluding that we face a new epistemic regime. Pritchard asks about trust, which is a normative relation between a knower and a source; Levin asks about representation. The productive move is not deciding who is right but applying to Levin&amp;rsquo;s vocabulary the only test that helps: what does it let us say that we could not say before. And it lets us say this, which is not nothing: if meaning is navigational and geometric, then whoever fixes the geometry fixes what sits near what, and that geometry comes out of a corpus whose linguistic distribution is not an accident of nature.&lt;sup id="fnref:3"&gt;&lt;a href="#fn:3" class="footnote-ref" role="doc-noteref"&gt;3&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;p&gt;On 12 August Timothy Gowers did empirically what the two of them do conceptually, and his answer is the most usable of the three because it can be checked. Following OpenAI&amp;rsquo;s announcement of ten solved mathematical problems — among them the construction of a non-sofic group and results on multicolour Ramsey numbers — Gowers observes that nearly all the famous problems solved were solved by counterexample rather than by proof, and conjectures the mechanism: breadth of mathematical knowledge plus the capacity to explore many search branches, which works well with documented standard methods and badly where intuition is needed to prune a deep tree. His criterion for recognising human level is demanding and elegant: methods that are new and surprising but in hindsight beautiful and natural. The practical version of that finding for a research group without compute is direct. The model&amp;rsquo;s advantage lies where the search space is large and verifying success is cheap. A counterexample verifies itself.&lt;/p&gt;
&lt;p&gt;In the same week, two different institutions settled the question of authorship with opposite instruments and the same answer. The journal decided the signature must be human; the US patent office had already decided so, because an appeals court held in 2022 that &amp;ldquo;individual&amp;rdquo; means a human being and dispatched the rest as a metaphysical matter. Insilico Medicine advertises in its marketing that its AI &lt;em&gt;discovered&lt;/em&gt; a pulmonary fibrosis drug, and listed five human inventors on the patent, its chief executive among them, with no mention of the system. Ryan Abbott, the lawyer behind the DABUS case, warns that listing the wrong inventors is an invitation to have the patent challenged, and puts the limit case with a frankness anyone who has read too much literature on artificial agency will appreciate: if I asked Claude to cure cancer and it did, it would be inappropriate to claim I invented that. The journal and the office reach the same requirement for incompatible reasons: the first needs somebody to credential, the second needs somebody to sue and to license from.&lt;/p&gt;
&lt;p&gt;Which brings in the week&amp;rsquo;s most uncomfortable text, published in &lt;em&gt;La Nación&lt;/em&gt; on 16 August by Pablo Mira and Alejandro Hortal. The argument is that virtue ethics is the most pertinent approach to AI because &lt;em&gt;phronesis&lt;/em&gt; demands prudence and life experience the machine does not have, with the &lt;em&gt;Odyssey&lt;/em&gt; as a school of practical wisdom: Scylla and Charybdis, the pride of revealing his name, the refusal of Calypso&amp;rsquo;s immortality. The opening observation is good and verifiable — AI threatens jobs and incidentally rescues philosophy from its historic precariousness, because tech companies hire philosophers — and the conclusion does not follow. The move is essentialist: it locates the difference in what the machine &lt;em&gt;is&lt;/em&gt; rather than in what an institutional arrangement does, and it is precisely the move the week refutes, because nobody needed to establish whether a model can have phronesis in order to decide who signs, who gets credentialed and who gets sued. Those questions would be identical if the model had it. Which obliges me to turn the objection on myself: this blog cites indexed journals, DOIs and open-access marks in every entry, and it does so because the credentialing circuit is what lends authority to what it writes. A philosophy journal debating its authorship policy is not a conceptual matter here. It is a debate about the door we come in through.&lt;/p&gt;
&lt;h2 id="care-for-the-commons"&gt;Care for the commons&lt;/h2&gt;
&lt;p&gt;404 Media put an AirTag in a book. Working with a bookseller, it followed an order of about a thousand copies to an Amazon warehouse, and documented sellers who received sixty-eight orders from a single buyer and another who logged forty-eight orders around four in the morning; the operation has been running since at least September 2024. Amazon confirmed that it buys books through commercial channels to help develop and improve its products and services, and did not say how many, or for what product, or how it avoids destroying rare copies. The industrial scanning method is what it is: the spine is cut off, the leaves are separated, they go through the feeder, and the copy is discarded.&lt;/p&gt;
&lt;p&gt;The concession has to be made, because the easy reflex ruins the argument. Destructive scanning has always been the technique of mass digitisation, and a good deal of what can be read for free today — Internet Archive, HathiTrust — came out of operations that did exactly the same thing with exactly the same blade. The difference is not the method but what is left on the other side: in one case, a searchable catalogue; in the other, a corpus inside a model nobody can open. And the physical copy was the backup. For a university library in the region that cannot pay the licences on digital catalogues, the used-book market is not nostalgia: it is the acquisition channel, and no intent needs to be assumed to see that sustained wholesale buying against a finite supply moves the price.&lt;/p&gt;
&lt;p&gt;At the opposite end of the same process, John Gruber published on 16 August an objection to the semantic watermark Anthropic built into Claude, which adjusts word-selection probabilities so the model picks terms from &amp;ldquo;green&amp;rdquo; lists more often than their &amp;ldquo;red&amp;rdquo; alternatives, leaving a pattern detectable only with keys Anthropic holds. The company maintains the technique has no practical impact on the quality or content of the outputs; Gruber replies that the idea that anything other than his needs should influence the text generated for him is offensive, and that claiming meaning is not altered is exactly what the technique does. Put together, the two operations close a circle. At the input, the original is consumed: the book is read once, destructively, and what survives is inside a closed model. At the output, a mark is inserted that only the party that inserted it can read. Between the two ends there is no point at which a third party can verify anything.&lt;sup id="fnref:4"&gt;&lt;a href="#fn:4" class="footnote-ref" role="doc-noteref"&gt;4&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;h2 id="education"&gt;Education&lt;/h2&gt;
&lt;p&gt;An interdisciplinary team at North Carolina State University published in &lt;em&gt;Frontiers in Education&lt;/em&gt; an eight-step workflow called the Socratic Challenger, in which the model does not generate the research question but interrogates the student&amp;rsquo;s process: where the gap in knowledge is, what is new about it, whether the method will do. They tested it with forty-five students in an undergraduate ecology course over nine weeks, ending in research abstracts; the students valued all eight steps, and the conclusion the authors report is negative and therefore useful: the technology alone does not help, what does the work is the sequence.&lt;/p&gt;
&lt;p&gt;That negative conclusion is the transferable asset, and it is worth comparing with the other answer the week gave to the same question. The Meta settlement answers with a curfew and a two-hour limit: a restriction implemented by the company that caused the problem, verified by an auditor it pays, and applicable only where the settlement applies. The Socratic Challenger answers with eight steps, a DOI and an open-access article: it costs nothing, it runs against whatever model the institution can afford, and a department at a public university in the region can adopt it on Monday. What transfers is the design and not the tool, and the design is precisely the part that never appears in a framework agreement with a vendor, where what gets signed is access to a platform, training on that platform and a renewal clause, never a pedagogical sequence the institution gets to keep when it changes vendors.&lt;/p&gt;
&lt;p&gt;MIT Technology Review&amp;rsquo;s editor&amp;rsquo;s letter of 26 August, introducing an issue devoted to children growing up among agents and chatbots, drops without underlining it the most informative fact in the whole business: much of the industry keeps its own children away from its products, and Zuckerberg does not post photos of his on his platforms. The easy reading is hypocrisy, and it is the least useful. What is there is a risk assessment made by the people with the best available information, published in the form of conduct rather than documents, and one that no education system can cite in a curriculum because nobody wrote it down.&lt;/p&gt;
&lt;h2 id="public-sector-opportunities"&gt;Public sector opportunities&lt;/h2&gt;
&lt;p&gt;Two vendors disagreed in Buenos Aires this month, and the disagreement is worth reading precisely because both of them are selling something. At the Google Cloud Summit on 25 August, Gemini Enterprise for financial services and for the legal sector were announced in preview, the first with more than fifty capabilities for capital markets and corporate banking and the second covering contract lifecycle management; Mercado Libre reports that close to 40% of its production code is written with AI assistance, and Google&amp;rsquo;s research with Foresight and the IDB puts at 20.4% the Argentine companies already using AI operationally and at 44.4% those planning adoption within months. Natalia Scaliter framed it as a slogan: the time to wait and see is over. Thirteen days earlier, at Red Hat&amp;rsquo;s Finance Forum, Jorge Payró was saying the opposite with the same confidence, that agentic AI is an enormous door for vulnerabilities and that &amp;ldquo;what you must not lose is autonomy and control, governance,&amp;rdquo; with Ansible and Lightwell cutting vulnerability remediation from thirty or forty-five days to seven or ten. Neither is a disinterested observer: one sells the open hybrid platform and the other sells the managed alternative. That is why the disagreement informs, and what is in dispute is not adoption but where the cost of switching vendors ends up sitting.&lt;/p&gt;
&lt;p&gt;The most relevant material for the region, however, ran in STAT on 19 August and describes a shadow medical system that already works: more than forty million Americans ask ChatGPT health questions every day, Oura sells a fifty-biomarker panel through Quest for ninety-nine dollars, Function Health — valued at 2.5 billion in November 2025 — offers a hundred and sixty annual lab tests, a full-body MRI and ChatGPT analysis of the results, Ro and Hims prescribe weight-loss and anxiety medication after an asynchronous intake, and Doctronic, which bills itself as the world&amp;rsquo;s number one AI doctor, has run twenty-four million consultations and issues AI-generated prescription refills in Utah. In the middle of that, Rao and Succi published in &lt;em&gt;JAMA Network Open&lt;/em&gt; a test of twenty-one frontier models with a result that has to be read twice: given a complete case, they named the correct diagnosis more than 90% of the time; given only what a clinician gathers at the start of a visit, they failed to produce a comprehensive differential more than 80% of the time.&lt;sup id="fnref:5"&gt;&lt;a href="#fn:5" class="footnote-ref" role="doc-noteref"&gt;5&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;p&gt;In the United States that shadow system competes with a health system that exists. In much of the region it competes with nothing: for someone eight hours from the nearest hospital, the model is not a second opinion but the first. And the &lt;em&gt;JAMA&lt;/em&gt; finding is exactly inverted with respect to that use, because the complete case is the one a clinician has already assembled, and the incomplete initial presentation is all there is where there is no clinician. The capability is best precisely where it is least needed. That is not an argument for banning anything, not least because banning is not an available option when the alternative is nothing at all; it is an argument for health ministries in the region to stop debating whether to adopt diagnostic assistants and start debating triage: which presentations get referred without exception, and who pays for the referral.&lt;/p&gt;
&lt;p&gt;The counterpart came, without meaning to, from a team at Sungkyunkwan University with colleagues at Ajou and MIT, which published in &lt;em&gt;Advanced Materials&lt;/em&gt; a closed-loop solid-state synthesis planning platform: it extracted synthesis data from 4,407 papers, proposed recipes for oxy-selenide solid electrolytes, and when the first proposal at 600 °C produced impurities, experimental feedback refined the conditions down to 400 °C and yielded a new single-phase material within a few experiments. It is the sort of thing a public research system can copy, and the reason is unheroic: the input was already-published papers and the loop was closed by a laboratory that already existed. The scarce resource is not the model. It is the furnace, and the person who can read the diffractogram. Which inverts the usual science policy conversation: the bottleneck for a materials group in the region is not access to a frontier model, it is the experimental capacity to close the loop, and no compute budget buys that.&lt;/p&gt;
&lt;h2 id="environmental-impact"&gt;Environmental impact&lt;/h2&gt;
&lt;p&gt;A team at the University of Edinburgh&amp;rsquo;s Institute for Condensed Matter Physics and Complex Systems, led by Elton Santos, applied optimal control theory to ultrafast magnetic switching in van der Waals materials and cut the energy required in simulation from as much as 91.2 nanojoules to 0.94, with the expectation of eventually reaching the femtojoule range. There are two caveats and one concession. It is simulation, not a device. And a hundredfold improvement in memory switching energy has never, in the history of computing, reduced total consumption: it enlarged what gets built.&lt;sup id="fnref:6"&gt;&lt;a href="#fn:6" class="footnote-ref" role="doc-noteref"&gt;6&lt;/a&gt;&lt;/sup&gt; The concession is that none of this is an argument against the research, which is well done and which nobody should stop doing; it is an argument about what an efficiency figure can and cannot carry inside a policy document, and the region has seen this film before in other sectors. What an efficiency gain does not change is the postal address. The substation still gets built somewhere, and who pays for it is still decided at a permit hearing.&lt;/p&gt;
&lt;h2 id="closing"&gt;Closing&lt;/h2&gt;
&lt;p&gt;The sentence that organises the week came from no laboratory: a consultant wrote it in a German social-democratic magazine, and it says that a label without a practical right to challenge the result is little more than a notice pinned to a locked door. A lot of notices went up this week: an age verification, an authorship ban, a watermark, five human inventors. The question for next week is how many of those doors have somebody obliged to open them on the other side, and of those, how many sit in a jurisdiction where the region gets to be a user and not a party.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="this-weeks-sources"&gt;This week&amp;rsquo;s sources&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Governance&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On the Meta settlement:
,
and
, 26–27 August 2026 · &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On the age verification problem:
and the adversarial reading in
· &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On Florida&amp;rsquo;s suit against OpenAI:
and
, 19 August 2026 · &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;Gates on thresholds:
, 26 August 2026 · &lt;em&gt;paywall&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On the proteins designed by Claude:
, 20 August 2026 · &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;The inside story of the Hugging Face episode:
· &lt;em&gt;paywall&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Democratization&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Tsipursky on transparency and accountability:
, 17 August 2026 · &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On Meta&amp;rsquo;s &amp;ldquo;Project OT&amp;rdquo;:
and
· &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On ninety-hour weeks:
, 17 August 2026 · &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Epistemic commons&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The journal&amp;rsquo;s decision:
, Daily Nous, 24 August 2026, and the
, 13 August · &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;Duncan Pritchard,
, &lt;em&gt;Synthese&lt;/em&gt;, 7 August 2026 · &lt;em&gt;subscription&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;Ilya Levin,
, &lt;em&gt;Synthese&lt;/em&gt; 208(3), 26 August 2026 · &lt;em&gt;subscription&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;Timothy Gowers,
, 12 August 2026 · &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On inventors and patents:
, 21 August 2026 · &lt;em&gt;paywall&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;Pablo Mira and Alejandro Hortal,
, &lt;em&gt;La Nación&lt;/em&gt;, 16 August 2026 · &lt;em&gt;free access, in Spanish&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Care for the commons&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On the buying and destruction of books:
and
, on the original 404 Media investigation · &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;John Gruber on Claude&amp;rsquo;s watermark:
, 16 August 2026 · &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Education&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On the Socratic Challenger:
, 26 August 2026; the original article in &lt;em&gt;Frontiers in Education&lt;/em&gt;, doi:10.3389/feduc.2026.1913451 · &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;The editor&amp;rsquo;s letter:
, September 2026 · &lt;em&gt;paywall&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Public sector opportunities&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On the Google Cloud Summit:
, 25 August 2026 · &lt;em&gt;free access, in Spanish&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;The interview with Jorge Payró:
· &lt;em&gt;free access, in Spanish&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On the shadow medical system:
, 19 August 2026 · &lt;em&gt;paywall&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On the materials synthesis platform:
, 26 August 2026 · &lt;em&gt;free access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Environmental impact&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On magnetic switching:
; the original article in &lt;em&gt;Advanced Materials&lt;/em&gt;, doi:10.1002/adma.202523059 · &lt;em&gt;subscription&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="footnotes" role="doc-endnotes"&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id="fn:1"&gt;
&lt;p&gt;The figure is worth pinning down, since it circulates three different ways. The total is up to eighteen billion dollars over ten years, of which about 70% — some 12.7 billion — is firm and the rest is contingent on Snap, TikTok and YouTube adopting equivalent measures. California takes 2.2 billion and New York 1.1; Texas negotiated separately for more than one. The incentive design is the striking part: the contingent portion makes Meta the most interested party in the country in having its competitors accept the same restrictions it has just accepted, and it also turns the two-hour limit into a one-hour limit if that happens. It is a coordination clause among competitors, drafted inside a judicial settlement, with no competition authority watching.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:2"&gt;
&lt;p&gt;Public nuisance is the doctrine that produced the great tobacco settlements of the nineties and the opioid settlements of the last decade, and its appeal is that it requires no legislation: an attorney general, a state court and a documentable diffuse harm will do. Its limit is of the same nature. It works because the defendant has too much to lose in that market to go to trial, which makes it an instrument of large countries and explains why the route actually available to a small state is not litigation but coordination with other small states, which is slower and less photogenic.&amp;#160;&lt;a href="#fnref:2" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:3"&gt;
&lt;p&gt;I read both articles through their abstracts: &lt;em&gt;Synthese&lt;/em&gt; publishes them under subscription and the full text sits behind the wall. Noting this is not a gesture of humility but the only honest way to write about them in an entry that devotes a section to the epistemic commons, and it is also a fact about the object: the highest-level philosophical discussion of what kind of knowledge these systems produce circulates under an access regime that most of the people who have to decide about them cannot afford. Pritchard&amp;rsquo;s, to make matters worse, has a title that is fully intelligible from the abstract, which saves the subscription and does not fix the problem.&amp;#160;&lt;a href="#fnref:3" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:4"&gt;
&lt;p&gt;The symmetry with what we were discussing two weeks ago about the AI Act and the Californian law is worth recording. Mandatory provenance and a proprietary watermark are the same technical instrument with the sign flipped: in one case traceability is a public obligation verifiable by third parties, in the other a private capability verifiable by its owner. That Google made Gemini&amp;rsquo;s visible mark optional in the same month Anthropic built an invisible one into Claude suggests the variable being adjusted is not how much traceability there is, but who holds the key.&amp;#160;&lt;a href="#fnref:4" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:5"&gt;
&lt;p&gt;The two figures are not two sides of one coin and should not be read that way. The first measures diagnostic accuracy on a complete clinical vignette, which is an exercise in recognition; the second measures the production of a comprehensive differential diagnosis, that is, the capacity to enumerate what the picture might still turn out to be, which is an exercise in imagination bounded by risk. A system that names the modal diagnosis and omits the rare, serious alternative is exactly the error profile an emergency department trains its residents not to have.&amp;#160;&lt;a href="#fnref:5" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:6"&gt;
&lt;p&gt;I write &amp;ldquo;never reduced total consumption&amp;rdquo; with the discomfort of someone recognising a reflex. In this debate the Jevons paradox has become a wildcard that lets one dismiss any technical improvement without examining it, and used that way it stops discriminating: there are efficiencies that did eat their own savings (lighting, refrigeration) and others that met no elastic demand to absorb them. What holds the argument up here is not the paradox in the abstract but the verifiable fact that compute demand over the past four years absorbed every available efficiency gain without aggregate consumption falling in any of them.&amp;#160;&lt;a href="#fnref:6" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</description></item><item><title>Pax Silica</title><link>https://guia.desdeelsur.org/en/blog/2026-08-23-pax-silica/</link><pubDate>Sun, 23 Aug 2026 00:00:00 +0000</pubDate><guid>https://guia.desdeelsur.org/en/blog/2026-08-23-pax-silica/</guid><description>&lt;p&gt;The draft comes from the State Department and has not been sent yet: the thirty-five signatories of a June declaration would be warned that joining China&amp;rsquo;s framework puts them outside the US-led coalition. Six days later, Brazil announced 2.3 billion reais split between Huawei and Nvidia. And in between, the two supposed sides — OpenAI and Z.ai — halted their most capable models for the same reason, for the same two weeks, with no outside party reviewing the decision.&lt;/p&gt;
&lt;h2 id="governance"&gt;Governance&lt;/h2&gt;
&lt;p&gt;On 18 August OpenAI announced it had paused reinforcement-learning training on deployment-bound models for two weeks, and put its largest planned run on hold, after internal signals suggested that Astra — an unreleased system — might be crossing the &amp;ldquo;Critical&amp;rdquo; cyber-capability threshold in its own Preparedness Framework. Four days earlier, Z.ai had launched GLM-5.3 while withholding the weights, after measuring 84.5% on CyberGym, a vulnerability-discovery benchmark. Two labs, one on each side of the line the State Department wants to draw, reached the same conclusion in the same week using the same instrument: a threshold they defined themselves, measured themselves and enforced themselves.&lt;/p&gt;
&lt;p&gt;It beats the alternative, and that deserves to be said without irony: stopping costs money, and they stopped. But it is not governance, and that shows most clearly when read against the safety index the Future of Life Institute published in July, where the industry&amp;rsquo;s top grade was a C+ — Anthropic, at 2.66 — with OpenAI at C, Meta at D+, and xAI, DeepSeek and Mistral at F; and which documents that several companies, the best-graded ones included, had weakened or dropped precisely the commitments to halt when hard limits are approached. That same week Google made the visible watermark optional in Gemini and Flow, keeping only the invisible SynthID. The pause and the unmarking run in opposite directions and share a structure: they are commitments the party making them can edit without telling anyone. For any state without an evaluation capacity of its own — that is, for almost all of them — the difference between a threshold and a press release is exactly zero.&lt;/p&gt;
&lt;h2 id="care-for-the-commons"&gt;Care for the commons&lt;/h2&gt;
&lt;p&gt;Three releases in one week, three different layers opened. On 12 August Alibaba released the weights for Qwen3.8-2.4T-A95B — 2.4 trillion total parameters, 95 billion active per token — the first time a Qwen-Max-class model has shipped with available weights; but the checkpoint is text-only, without the vision and the million-token context that make the hosted product worth having, and it ships under a custom licence with a revenue-share clause. Z.ai published GLM-5.3 without weights, promising to release them around 28 August under the same permissive licence as before. DeepSeek released Harness, its agent scaffolding, under a genuine MIT licence, provider-agnostic, with every layer — inference, tools, session state, the agent loop itself — replaceable as a plugin; and on the same day raised the price of the V4-Pro API.&lt;/p&gt;
&lt;p&gt;None of the three is closing down. All three are choosing which layer to open, and the choice follows a pattern: what gets opened is the layer whose marginal copying cost is zero, and what gets held back is the one that costs money to sustain.&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt; The best thing of the week here is DeepSeek&amp;rsquo;s harness, precisely because it does not depend on DeepSeek: a lab in Bogotá or Accra can run it against whichever model it can afford, including one of its own. But the question left open last week is still there, merely displaced: it is no longer whether the weights are available, but which of the system&amp;rsquo;s layers came out free and which one is billed. Openness has stopped being a state of the artefact and become a dial, adjusted layer by layer — and the hand on the dial is always the same one.&lt;/p&gt;
&lt;p&gt;
&lt;figure &gt;
&lt;div class="flex justify-center "&gt;
&lt;div class="w-full" &gt;
&lt;img alt="A brain drawn in pink and yellow pixel art on the screen of an arcade machine, framed by fluorescent green and cyan data bars"
srcset="https://guia.desdeelsur.org/media/blog/2026-08-23-pax-silica/fig1_hu_a74d693260c603f2.webp 320w, https://guia.desdeelsur.org/media/blog/2026-08-23-pax-silica/fig1_hu_1d1a50281c67aeb1.webp 480w, https://guia.desdeelsur.org/media/blog/2026-08-23-pax-silica/fig1_hu_d46c1497abba79f3.webp 760w"
sizes="(max-width: 480px) 100vw, (max-width: 768px) 90vw, (max-width: 1024px) 80vw, 760px"
src="https://guia.desdeelsur.org/media/blog/2026-08-23-pax-silica/fig1_hu_a74d693260c603f2.webp"
width="760"
height="760"
loading="lazy" data-zoomable /&gt;&lt;/div&gt;
&lt;/div&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;h2 id="epistemic-commons"&gt;Epistemic commons&lt;/h2&gt;
&lt;p&gt;A Northwestern team published in PNAS the largest analysis so far of what language-model use does to the public funding of science. They combined confidential proposals from two large US R1 universities — roughly 1,600 to the NSF and 4,100 to the NIH, including rejected and pending ones — with the full population of awards granted between 2021 and 2025: 57,000 from the NSF and 74,000 from the NIH. Model use rises sharply from 2023 and is bimodally distributed: either almost none, or a great deal. And across every dataset, higher model involvement is associated with lower semantic distinctiveness: proposals sit closer to what that same agency has recently been funding. The consequences, however, are agency-dependent. At the NIH, moving from the 25th to the 75th percentile of use corresponds to roughly 4 percentage points more funding probability and 5% more publications; at the NSF there is no significant association. And the NIH productivity gain is concentrated in papers that are not among the most cited.&lt;/p&gt;
&lt;p&gt;That contrast between agencies is the finding that matters, because it relocates the problem. It is not the model that rewards convergence: one review culture rewards it and another does not, with the same tool in the middle. For someone writing in a second language — most researchers in the Global South — a language model is a real equaliser: it removes the accent penalty a grant form has always charged. But the same instrument that lowers that barrier pushes the content toward the centre of what has already been funded, and that centre has a geography. The practical conclusion is not to ban anything. It is that the region&amp;rsquo;s agencies — CNPq, CONICET, Minciencias — still have time to decide whether their evaluation criteria reward distinctiveness or conformity, before redesigning their processes around detecting model use, which is the easy answer and the wrong one.&lt;/p&gt;
&lt;p&gt;The week&amp;rsquo;s other finding runs in the opposite direction, and both have to be held at once. A Stanford-led team published in &lt;em&gt;Science&lt;/em&gt; the creation of sixteen viable bacteriophages that do not exist in nature, designed by generative models trained on millions of genomes: they chemically synthesised close to three hundred candidates, and the cocktail of the sixteen that worked overcame resistance that had defeated the natural phage. The burden of antibiotic-resistant infection falls overwhelmingly on the Global South, and phage therapy is one of the few things in biomedicine that can be produced cheaply and locally. This is exactly what the promise of AI for science says will happen. It is also, in the same breath, a pathogen-design capability, and the predictable response — export controls on biological design models — would enclose that capability precisely where the need is greatest. The same technology produces convergence in a grant application and genuine novelty in a genome; what differs between the two cases is not the model but what the selection mechanism on the other side rewards.&lt;/p&gt;
&lt;h2 id="democratization"&gt;Democratization&lt;/h2&gt;
&lt;p&gt;In mid-August Reuters obtained a State Department draft addressed to the thirty-five signatories of a June &amp;ldquo;AI Opportunity Statement&amp;rdquo;: a warning that joining Beijing&amp;rsquo;s competing framework leaves them outside the US-led coalition. The framework is called Pax Silica, was launched last year to secure supply chains for models, semiconductors and critical minerals, and already has some two dozen members, among them Japan, Australia, South Korea and Kazakhstan — which is also in the Chinese coalition. On 19 August spokesperson Lin Jian replied that China opposes taking sides and forming camps on AI, and that &amp;ldquo;each country has the right to choose its partners based on its national conditions and development needs.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;The two positions are formally symmetric — both are bids for alignment — and materially they are not, because they do not ask for the same thing. Pax Silica is, before it is an agreement about models, an agreement about critical minerals: about what the Global South has in the ground. The name is neither an accident nor an in-joke; it is the thesis. A &lt;em&gt;pax&lt;/em&gt; is what the party holding the perimeter grants, and what it grants is predictability in exchange for exclusivity. Which is why Kazakhstan is the week&amp;rsquo;s most instructive case: being in both coalitions is not indecision, it is the rational strategy of an input supplier, because the value of what it sells comes precisely from not being committed. The exclusivity clause exists to eliminate that margin. Non-alignment, here, is not a moral posture inherited from the sixties: it is a bargaining position, and the letter is an attempt to make it contractually impossible.&lt;/p&gt;
&lt;h2 id="public-sector-opportunities"&gt;Public sector opportunities&lt;/h2&gt;
&lt;p&gt;On 20 August Brazil announced 2.3 billion reais ($444.2 million) for its AI ecosystem, deliberately split. Just over half — 1.3 billion — funds supercomputing infrastructure in Rio de Janeiro with Huawei and iFlytek, explicitly aimed at developing general and sector-specific language models. The other billion goes to a tender for a machine the government expects to rank among the world's ten most powerful for AI processing, to be installed in Rio Grande do Norte, and which Nvidia is expected to win. The next day South Korea announced a "Future Response Fund" financed by the tax windfall from the semiconductor boom — whatever exceeds a benchmark based on the past decade's average growth — and directed at youth employment, housing, regional development and AI investment; local press estimates it could exceed 100 trillion won ($72.28 billion).&lt;/p&gt;
&lt;p&gt;These are two different state capacities and it is worth not conflating them. Korea&amp;rsquo;s is fiscal and institutional: a countercyclical rule that turns a boom into a reservoir — that is, a decision about time. Brazil&amp;rsquo;s is procurement: turning money into machines, now. Brazil is doing the harder thing with far less — $444 million is roughly what one hyperscaler spends in a fortnight — and the detail that matters is not the amount but that over half of it goes to &lt;em&gt;developing&lt;/em&gt; models rather than renting capacity to consume them. The answer to Pax Silica was not a communiqué but a divided budget, and it arrived six days after the draft, from a country that is not among the thirty-five. One question neither announcement answers is the one that decides whether this is sovereignty or mere acquisition: who governs that compute afterwards. How it is allocated, on what criteria, and whether a public university in the Northeast will get hours on the Rio Grande do Norte machine or watch it from outside the fence, the way one watches a pipeline go past.&lt;/p&gt;
&lt;p&gt;
&lt;figure &gt;
&lt;div class="flex justify-center "&gt;
&lt;div class="w-full" &gt;
&lt;img alt="A light-wood arcade cabinet with a red frame and a lit CRT monitor showing a block-breaking game in fluorescent colours, with a red joystick and two buttons, in a dimly lit room"
srcset="https://guia.desdeelsur.org/media/blog/2026-08-23-pax-silica/fig2_hu_5d125354d66ea814.webp 320w, https://guia.desdeelsur.org/media/blog/2026-08-23-pax-silica/fig2_hu_defcaaa2537cf367.webp 480w, https://guia.desdeelsur.org/media/blog/2026-08-23-pax-silica/fig2_hu_1868095db380ae55.webp 760w"
sizes="(max-width: 480px) 100vw, (max-width: 768px) 90vw, (max-width: 1024px) 80vw, 760px"
src="https://guia.desdeelsur.org/media/blog/2026-08-23-pax-silica/fig2_hu_5d125354d66ea814.webp"
width="760"
height="760"
loading="lazy" data-zoomable /&gt;&lt;/div&gt;
&lt;/div&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;h2 id="environmental-impact"&gt;Environmental impact&lt;/h2&gt;
&lt;p&gt;Rio Grande do Norte was chosen, according to the announcement itself, for its energy potential. In Brazil&amp;rsquo;s Northeast that phrase means wind, and it should be said that this is a good reason: it is probably the best siting decision available in footprint terms. But the phrase leaves unanswered the two questions that turn it into a policy rather than a postcard: at what price the data centre buys that energy, and who pays for the grid that carries it.&lt;/p&gt;
&lt;p&gt;The week&amp;rsquo;s most transferable answer came from an unlikely place and never mentions models at all. On 18 August Pennsylvania&amp;rsquo;s governor signed an executive order removing AI data centres from the fast-track permitting programme, requiring binding grid commitments before the environmental authority even evaluates the permit, mandating local hiring and a community benefits agreement, and establishing two things worth more than all of the above: that without local community approval the state does not approve the project, and that infrastructure costs the centre creates are paid by the centre and not by residential ratepayers, even if it later closes and cannot pay them. This is polycentric governance in its least glamorous form: not a national AI framework, but permits, land and who pays for the substation, decided at the scale where the affected people actually are.&lt;sup id="fnref:2"&gt;&lt;a href="#fn:2" class="footnote-ref" role="doc-noteref"&gt;2&lt;/a&gt;&lt;/sup&gt; The last clause matters most for the region, because the standard extractive contract in Latin America has always externalised exactly that: the cost of what remains once the operation leaves.&lt;/p&gt;
&lt;h2 id="closing"&gt;Closing&lt;/h2&gt;
&lt;p&gt;The week left two gestures that resemble each other and are not the same. Two labs decided to stop, and no one outside could verify why, by what measure, or for how long. A governor decided that a data centre does not get built if the local community does not approve it, and that is verifiable, appealable and copyable. The question for next week is not whether the race will have rules, but how many of those rules will be written in a framework the company can edit, and how many in a permit someone can deny.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="this-weeks-sources"&gt;This week&amp;rsquo;s sources&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Governance&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On OpenAI&amp;rsquo;s pause:
, 18 August 2026, and the
· &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On the GLM-5.3 weight embargo and its CyberGym score:
and
· &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On the safety index:
, Future of Life Institute, with the
· &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On the optional watermarks:
, 14 August 2026 · &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Care for the commons&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Qwen3.8-2.4T-A95B:
of what the checkpoint and the licence actually cover · &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;DeepSeek V4-Pro and Harness:
, 13 August 2026 · &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Epistemic commons&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The study: Qian, Wen, Furnas, Bai, Shao and Wang,
, &lt;em&gt;PNAS&lt;/em&gt;, 2026. The
has the full text · &lt;em&gt;preprint openly accessible&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On the bacteriophages:
and
, August 2026 · &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Democratization&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On the Pax Silica draft:
, 15 August 2026 · &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;China&amp;rsquo;s response:
and
· &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Public sector opportunities&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On the Brazilian investment:
, 20 August 2026, and
· &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On the Korean fund:
and
, 21 August 2026 · &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Environmental impact&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The Pennsylvania executive order:
and
, Pennsylvania Capital-Star · &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="footnotes" role="doc-endnotes"&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id="fn:1"&gt;
&lt;p&gt;The idea of analysing an informational system by layers — physical, logical, content — and asking at each one whether it is open or closed comes from Yochai Benkler, &lt;em&gt;The Wealth of Networks&lt;/em&gt; (2006), and before him Lawrence Lessig. What this week adds is that all three companies use the layer separation as a management instrument: the decision is not between opening and closing, it is about where to put the boundary. An MIT-licensed harness on top of a metered model, or available weights stripped of the modalities that make the product useful, are not partial openings forced by technical limits; they are chosen configurations, and the criterion ordering them is which layer can be copied at no cost.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:2"&gt;
&lt;p&gt;In &lt;em&gt;Governing the Commons&lt;/em&gt; (1990), Ostrom lists among her design principles the collective-choice arrangements — those affected by the rules take part in modifying them — and nested enterprises, which distribute authority across levels. The local veto clause in the Pennsylvania order is exactly the first, and the fact that the state environmental authority is subordinated to that approval is the second. It is striking that the week&amp;rsquo;s most Ostromian instrument in AI regulates no model at all: it regulates a shed, a permit and an electricity bill.&amp;#160;&lt;a href="#fnref:2" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</description></item><item><title>610 gigabytes of openness</title><link>https://guia.desdeelsur.org/en/blog/2026-08-14-610-gigabytes-de-apertura/</link><pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate><guid>https://guia.desdeelsur.org/en/blog/2026-08-14-610-gigabytes-de-apertura/</guid><description>&lt;p&gt;On 2 August, within roughly the same hour, the transparency obligations of the European AI Act and those of California&amp;rsquo;s synthetic-content provenance law came into force. That same week, the numbers were published showing how much memory, in gigabytes, it takes to hold up the most capable open-weight model in existence. The two things answer the same question from opposite ends: what good is it for something to be available if the capacity to use it is unevenly distributed. &amp;ldquo;Open,&amp;rdquo; this week, turned out to be an adjective with several owners.&lt;/p&gt;
&lt;h2 id="governance"&gt;Governance&lt;/h2&gt;
&lt;p&gt;Article 50 of the AI Act has been enforceable since 2 August: you must disclose when someone is interacting with an AI system, mark much AI-generated content in machine-readable form, and explicitly label deepfakes and synthetic text on matters of public interest, with fines of up to €15 million or 3% of worldwide turnover. Two details usually lost in the coverage: enforcement rests principally with each member state&amp;rsquo;s national market surveillance authorities rather than with the AI Office, and systems already on the market have until 2 December for the marking and detection requirements. California timed its own date deliberately: SB 942, as amended by AB 853, became operative on exactly the same day, requiring generative providers with more than a million monthly users in the state to offer a free provenance-verification tool.&lt;/p&gt;
&lt;p&gt;In Washington, that same week, the administration finalised with the companies a voluntary framework granting the federal government up to thirty days of access to frontier models before they are available to anyone else, with the stated purpose of assessing their cyberattack capabilities. Two features of the framework matter more than the framework itself: its text was not made public, and it defines a &amp;ldquo;covered frontier model&amp;rdquo; as closed-source, so open models are explicitly left out. Meanwhile the same government is running an offensive against the state regulatory patchwork —a litigation task force at the Department of Justice dedicated to challenging state AI laws, with federal funding used as leverage against states that enforce them— alongside an earlier order instructing agencies to deprioritise disparate-impact liability. So we are not looking at two transparency regimes of differing stringency. We are looking at two different things sharing a name: one compels disclosure toward everyone, the other grants privileged access to one party. Seen from the South, the Brussels effect arrives as a compliance cost without a seat at the table where the rule was written; and whatever security knowledge that early access produces will not be a common good, because not even the procedure that produces it was published.&lt;/p&gt;
&lt;h2 id="epistemic-commons"&gt;Epistemic commons&lt;/h2&gt;
&lt;p&gt;Anthropic began marking Claude&amp;rsquo;s outputs: an imperceptible signal embedded in the text of new models, and signed provenance metadata following the C2PA standard in generated files. It does so worldwide, not only for European users —European compliance delivered globally, which is precisely what the Brussels effect describes. Suno committed to the same for audio. This is the right move and it deserves to be said without irony: marking is the expensive part, and they are paying for it.&lt;/p&gt;
&lt;p&gt;The problem appears on the other side of the gesture. The tools that would let anyone detect those marks are still being built, and the company itself clarifies that a positive result would indicate that Claude &lt;em&gt;processed&lt;/em&gt; the content, not that it wrote it: someone may have asked it to translate, summarise or proofread a human text. The free tool that is actually mandatory —the Californian one— is mandatory of a large provider and for the benefit of a user in California. So the mark is planetary and the verification is jurisdictional. Provenance is not a property of the file, it is an infrastructure: a marked file in a world without accessible detectors does not inform, it asks for faith. And the capacity to doubt —to submit an image, an audio file or an expert report to verification before accepting it— ends up distributed along the same old geography. It is an unusual kind of enclosure, because what it fences off is not the resource but the faculty of examining it.&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;p&gt;
&lt;figure &gt;
&lt;div class="flex justify-center "&gt;
&lt;div class="w-full" &gt;
&lt;img alt="Eight anatomical brains with melting clocks embedded in them, floating above a pale horizon in a surrealist composition"
srcset="https://guia.desdeelsur.org/media/blog/2026-08-14-610-gigabytes-de-apertura/fig1_hu_60149cb553b22fac.webp 320w, https://guia.desdeelsur.org/media/blog/2026-08-14-610-gigabytes-de-apertura/fig1_hu_79e630be714f131f.webp 480w, https://guia.desdeelsur.org/media/blog/2026-08-14-610-gigabytes-de-apertura/fig1_hu_2786dcd282514e73.webp 760w"
sizes="(max-width: 480px) 100vw, (max-width: 768px) 90vw, (max-width: 1024px) 80vw, 760px"
src="https://guia.desdeelsur.org/media/blog/2026-08-14-610-gigabytes-de-apertura/fig1_hu_60149cb553b22fac.webp"
width="760"
height="760"
loading="lazy" data-zoomable /&gt;&lt;/div&gt;
&lt;/div&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;h2 id="care-for-the-commons"&gt;Care for the commons&lt;/h2&gt;
&lt;p&gt;Here are the numbers. Moonshot AI&amp;rsquo;s Kimi K3 remains the most capable open-weight generalist model: 2.8 trillion parameters in a mixture-of-experts architecture, 104 billion active per token, 896 experts of which 16 are selected, a one-million-token context window. At full precision it takes 1.56 TB. Unsloth published the quantization table and it repays a slow reading: the two-bit variant weighs 711 GB and retains 84.1% accuracy; the one-bit variant drops to 594 GB at 78.9%, and running it requires &lt;strong&gt;610 GB of memory&lt;/strong&gt;. That is the entry price to the world&amp;rsquo;s most powerful open model. And it is not free software: it was released under Moonshot&amp;rsquo;s own licence, open-weight but not OSI-approved. Z.ai&amp;rsquo;s GLM-5.2 does carry a genuine MIT licence —744 billion parameters, some 40 billion active, also a million tokens of context— which improves the legal problem without moving the material one by a millimetre.&lt;/p&gt;
&lt;p&gt;The counterpoint arrived on 10 August, and it is the best thing about the week. Meta Superintelligence Labs released Muse Glimmer: 30 billion parameters, multimodal, over 128K of context, Apache 2.0, running on a single 24 GB GPU, with Ollama support from day one. That does fit inside a university lab in Rosario, in Nairobi or in Manila. And here is the irony that organises the whole week: it is exactly the model the US security framework decided not to examine, because its definition of a covered frontier model excludes what is open. The one a state can audit for thirty days is the one nobody else can install; the one anyone can install is the one nobody offered to audit.&lt;/p&gt;
&lt;p&gt;It is worth taking the word apart, then. &amp;ldquo;Open&amp;rdquo; names at least three distinct things —a licence that permits, weights that are available, and a material capacity to run them— and the Global South is included in the first two and excluded from the third. An available resource is not yet a governed resource, and a resource you cannot lift never quite becomes a resource at all.&lt;sup id="fnref1:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;h2 id="education"&gt;Education&lt;/h2&gt;
&lt;p&gt;For the first time in its history, UNAM held its undergraduate entrance exam entirely online, with 158,712 registered applicants and automated proctoring, largely in order to ease access from distant regions and from abroad. The results were statistically impossible: between 2021 and 2025, around 3.5% of applicants scored a hundred correct answers or more; in 2026 that share jumped to 16.3%. At the 110-correct threshold the anomaly is sharper still, from 0.9% to 5.5%, almost six times. Some three thousand exams were annulled, and the Technical Commission recommended something other than a blanket annulment: an in-person control exam for around 58,000 applicants, administered between 12 and 19 August. In parallel, in the United States, &lt;em&gt;ghost student&lt;/em&gt; fraud —synthetic identities enrolling in order to siphon off financial aid— has reached figures that no longer admit the diminutive: 31.4% of applications to California&amp;rsquo;s community colleges in 2024 turned out to be fraudulent, with 1.2 million bogus applications and 223,000 enrolments confirmed as nonexistent across 116 campuses; there are some two hundred open investigations covering more than 350 million dollars, and from 1 October the federal aid form will be screened with real-time fraud detection.&lt;/p&gt;
&lt;p&gt;It is the same verification failure with two opposite distributions of the cost. In the American case what is lost is public money and the state absorbs it; in the Mexican case what is lost is time and certainty, and it is absorbed by 58,000 people who overwhelmingly did nothing. The institution bought automated proctoring as a solution to a problem of distance and got back a problem of legitimacy, which is of another order and far more expensive: a massive public university cannot afford to have its mechanism for allocating places fall under suspicion. What followed deserves attention, because it is not a retreat in disguise. When digital verification failed, UNAM went back to the only infrastructure it actually controls —a room, a chair, a sheet of paper, a human invigilator— and with that it rebuilt trust in the process. It can be read as a technological defeat or as the discovery that the institution still held a capacity of its own that it had not subcontracted. The uncomfortable question is how many institutions in the South, after a decade of replacing processes with platforms, would still have something to go back to.&lt;/p&gt;
&lt;h2 id="public-sector-opportunities"&gt;Public sector opportunities&lt;/h2&gt;
&lt;p&gt;The least-discussed news of the week is the most replicable. On 21 July, India&amp;rsquo;s CDSCO issued its final guidance on software as a medical device under the Medical Devices Rules of 2017: it classifies screening, clinical decision support and patient monitoring software into four risk tiers, and requires prior licensing, model bias assessment, cybersecurity documentation, clinical performance evaluation, and post-market surveillance specific to systems that update after deployment. The FDA, for its part, has reportedly issued its first enforcement letters under its own guidance in the field.&lt;/p&gt;
&lt;p&gt;What is interesting about India is not the content of the rule but its strategy. It did not adopt the European AI Act, did not wait for the American position to settle, and above all did not try to create a national artificial-intelligence authority —that creature almost no state with a limited budget manages to staff with competent people. It used the sectoral regulator it already had, with the legal authority it already had, to demand of clinical AI exactly what it demands of any other device: that it document its failures and answer for them over time. This is polycentric governance in its least glamorous and most effective form: not a general framework ordering the whole domain, but the body that already knows about health risk applying its competence to a new object.&lt;sup id="fnref:2"&gt;&lt;a href="#fn:2" class="footnote-ref" role="doc-noteref"&gt;2&lt;/a&gt;&lt;/sup&gt; For a state in the South weighing where to start, the transferable lesson is not the Indian text but the move: regulate from the health, finance or education regulator that already exists, instead of waiting until you have the institutional capacity to build a new one from scratch.&lt;/p&gt;
&lt;h2 id="closing"&gt;Closing&lt;/h2&gt;
&lt;p&gt;The week left two concrete objects, and neither is a metaphor: 610 gigabytes of memory, which is what it costs to hold the frontier of the open in your own hands, and a room with chairs, which is what a public university had left when its digital verification collapsed. Between the two sits a 24 GB model that does fit in any lab and that no government asked to examine. The question left open is not whether models will be open —several were this week, under better licences than last year&amp;rsquo;s— but who will be able to lift them, and what an institution does in the meantime with the little it still controls.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="this-weeks-notes"&gt;This week&amp;rsquo;s notes&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Governance&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On Article 50 coming into force:
, 3 August 2026, and the
· &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On SB 942 as amended by AB 853:
and
· &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On the federal voluntary framework:
, 3 August 2026; on its confidential character and the exclusion of open models,
and
, 4 August 2026 · &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On the federal offensive against state laws:
· &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Epistemic commons&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On the marking of Claude&amp;rsquo;s outputs:
and
, 11 August 2026 · &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Care for the commons&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Kimi K3:
, 16 July 2026. The quantization figures and memory requirements come from
, which is the primary source for that data · &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;GLM-5.2:
· &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;Muse Glimmer:
and
, 10 August 2026 · &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Education&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On the UNAM exam:
, 31 July 2026, on the Technical Commission&amp;rsquo;s recommendation;
, 12 August, on the in-person exam being administered;
on the regulatory gap, which is a separate angle and deserves its own discussion · &lt;em&gt;open access, in Spanish&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On synthetic-identity fraud:
, August 2026, and
· &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Public sector opportunities&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On the CDSCO&amp;rsquo;s final guidance:
and
· &lt;em&gt;open access&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="footnotes" role="doc-endnotes"&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id="fn:1"&gt;
&lt;p&gt;The distinction between an available resource and a governed one runs through Elinor Ostrom, &lt;em&gt;Governing the Commons&lt;/em&gt; (1990). Her design principles presuppose something that neither open weights nor provenance marks provide on their own: collective-choice rules, monitoring capacity distributed among those who use the resource, and conflict-resolution mechanisms. A signed file without accessible detectors, and a freely licensed model that requires 610 GB of RAM, share the same structural defect: they are goods whose effective use depends on a capacity that does not come with the good.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href="#fnref1:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:2"&gt;
&lt;p&gt;On polycentric governance, see Ostrom, &amp;ldquo;Beyond Markets and States: Polycentric Governance of Complex Economic Systems&amp;rdquo; (2010). The argument is not that fragmentation is good in itself, but that arrangements with multiple decision centres at different scales tend to adapt better than single-command structures, because each centre retains local knowledge about its own domain. The CDSCO does not know about artificial intelligence in general; it knows about clinical risk, and that is enough to demand of a model what is owed.&amp;#160;&lt;a href="#fnref:2" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</description></item></channel></rss>