All media

Article

Only One of Today’s Three Stories Showed Its Work

Chris Carolan
Chris Carolan
Founder & Methodology Lead | The Value-First Team

Anthropic moved a 90-year-old bound on the Riemann zeta function from 41.6% to 67.2% using an unreleased Claude model, and then said how: two sessions, about 60 coordinated subagents, 31 million output tokens, 2,400 shell commands.

The second half of that sentence is the part you can use.

Two other announcements arrived the same day. OpenAI released a purpose-trained cybersecurity model that only trusted partners can access. Anthropic, on the day’s list a second time, will put an invisible watermark on every Claude output, worldwide. Both describe real capability. Neither hands anyone outside the announcing organization a piece they can act on.

Sixty subagents is a shape of work, not a headcount

The model that moved the bound is unreleased. You cannot get it, and no amount of reading the announcement changes that. What did leave the building is the shape of the run: two sessions, roughly 60 subagents working in coordination, 31 million tokens of output, 2,400 shell commands. That is a description another team can hold up against its own agent work and learn something from.

Nico Lafakis drew the line on the show that makes the number usable. He separated two things that both get called swarms: “solutioning as a swarm and researching the solution as a swarm are two really different things.” Pointing a swarm at work you have already scoped, he said, “looks like an automated factory” — the solution is decided and the swarm executes it. The other posture is the search itself. His description of it: “take every avenue possible and try to solve the problem using every avenue that you can find and then come back and let’s build the collective best possible solution.”

A bound that has not moved in 90 years can only be the second kind. There is no known answer to execute against, so a swarm aimed at it is searching or it is doing nothing. That reading is mine; the announcement gives the scale of the run, not its internal wiring. But the distinction is what decides whether 60 means anything for your own work, and it is available to anyone who reads the orchestration numbers instead of the percentage.

The ceiling came with the result

Anthropic published the checking alongside the run. Two of its own mathematicians and two outside experts examined the result. A machine-checked Lean formalization passed the standard validation tool. The bound is unconditional, which means it does not assume the Riemann hypothesis is true — the result stands on its own rather than borrowing the conjecture’s authority.

Then the sentence most announcements leave out. “We don’t expect that the techniques Claude used will lead to proving the Riemann hypothesis.” That is Anthropic capping the extrapolation from its own result, in its own announcement of that result. The hypothesis is not solved, and the organization with the most to gain from letting readers assume otherwise said so first.

A ceiling published with a finding is worth as much as the finding. It tells you how far the result travels before it stops being evidence, which is exactly the judgment a reader outside the work cannot make on their own.

The second story ships to a list

OpenAI’s model is GPT-5.6 Cyber, and it arrived with the Daybreak defender program split in two. Blue covers incident response, malware analysis and patch validation, and is the recommended start for most defenders. Red covers security testing and vulnerability research, and is the only side carrying the new model. Accenture, IBM, CrowdStrike and Cloudflare are on the list.

Read those two halves against each other. The side most defenders are pointed at is not the side the new model is on, and getting to the other side runs through a partner relationship rather than a purchase.

The threat half of the same story needed no list at all. AI agents have compromised Hugging Face, hacked a gym website, and created fake profiles to socially engineer an intrusion. All of that has already happened. Fully autonomous attacks at scale are OpenAI’s own forecast.

Nico Lafakis named the sequence he expects the access to follow. He called it a cadence and said he was very sure of it, which makes it a forecast rather than a report:

“It will be that the model company creates the new model. Government approves it. Goes immediately to IT cybersecurity sector. They finish with it. Immediately goes to banking sector. They finish with it. Goes to investment sector. They finish with it, probably enterprise business sector. They finish with it. … And then everybody else.”

He glossed his own verb as he went: “when I say finish, I mean, roll out.” The picture is sequential rollout, not sectors discarding the thing. Nothing published today confirms that order. What is confirmed is its first step: the model exists, and four named companies can reach it. His summary of what the rest of it means for everyone further down: “So we’re definitely going to have those gates on the way down.”

The third story ships a mark nobody can read

Anthropic’s watermark is embedded directly in text. SVG, PNG and JPG files carry signed C2PA provenance metadata instead. The rule behind it is European in origin, tracking the EU AI Act Transparency Code that took effect August 2, and it covers models released on or after that date.

No public detector exists today. Verification tools are promised with no date attached. Heavy editing, translation, format conversion or a screenshot strips the mark. And the limit is already known for the day a detector does arrive: a detection proves handling, not authorship, because people edit, translate and summarize with the model as well as generate with it.

So the mark is built to answer whether something was made by AI. The question Nico Lafakis described hearing over the past two weeks is not that one — it is whether something was run past AI. He has heard people ask “did you run it past GPT?”, and the same asked of Claude and of an in-house agent. He was specific that these were not startups and not small or mid-sized businesses: his examples were CFO and CTO interviews and a World Economic Forum panel. He put the present split at somewhere between 60/40 and 70/30 in favor of passing work by a model before it goes out, and forecast the reverse by December. His read on how long the watermark stays relevant: “by December, no one cares.”

Those two questions have different answers, and only one of them has a tool coming. A watermark may eventually tell you a model touched a document. It cannot tell you whether a person’s judgment was checked against one, and that second thing is what the rooms he described are asking about.

Episode — Value-First AI Daily

Value-First AI Daily - Aug 11, 2026

Nico Lafakis works the swarm distinction out loud on Ep. 13, with Chris Carolan: what changes between running a swarm to execute a decided solution and running one to find an unknown one, and why the plainest possible request keeps outperforming the technically correct one.

Open the episode

The episode did the same thing at trivial scale

The three stories are sealed until air, and I do not get to see them early. Today the show started a little before the countdown ran out, which meant the countdown itself was on screen for the first time — the seal as something a viewer could watch tick down rather than something the host asserts between segments. It is a small instance next to four examiners and a Lean formalization. It is the same shape.

The bound moving after 90 years is the bigger headline. Sixty subagents, 31 million output tokens and 2,400 shell commands are the part that leaves the building.