第三方评估者AEF-1标准出炉,xAI、OpenAI与Anthropic共同签署
AI评估者论坛发布AEF-1第三方评估基线标准,xAI、OpenAI、Anthropic共同签署;Dario撰文提出嵌入式评估者等三阶段节奏方案。
中文处理结果
我们在7月首次聚焦“节奏之争”,当时“Pacing the Frontier”刚刚出现:
而看起来我们即将迎来第二轮,因为原始文章的第一作者 Dario 写了一篇罕见的个人博客,具体阐述了他如何看待节奏问题的走向:
- 嵌入式评估者(Embedded Evaluators)。每家前沿 AI 公司承诺,向一支嵌入式第三方评估者团队(例如 METR)提供持续的、类似员工的访问权限,其职责是核实公司对安全实践与承诺的遵守情况、报告事件,并帮助评估不仅是已完成的 AI 模型,还包括训练流水线与流程的对齐情况。这是任何节奏承诺可验证性的关键一步,在银行业已有先例——银行业有时会让监管“监督员”与员工一同驻场。Anthropic 现在单方面承诺采取这一步骤。我们希望这成为更广泛推动的一部分,以加倍投入我们的安全与对齐工作。
- 民主国家协调(Democratic Coordination)。民主国家内的前沿 AI 公司进行协调,建立共同安全标准,并对不受约束的 AI 进展速度设定限制。对节奏问题有影响力的一些协调形式在法律上具有挑战性,将需要政府支持。
- 全球协调(Global Coordination)。美国及其他民主政府尝试与威权政府协调(在可能的范围内),同时认真对待核实合规性的挑战。
非常巧合的是,2025年12月成立的 AI 评估者论坛(AI Evaluator Forum)也恰好发布了他们对第一类评估者应做什么的期望:
AEF 的成员想必现在将成为这些大型实验室为自我监管而招募的领先第三方审计者。Dario 单方面承诺提供前所未有的访问权限,包括“我们办公室里的工位、门禁卡和公司笔记本电脑”,以及“对工作空间、工具和权限的访问,基本与内部风险评估团队相当”。
虽然这一切都在标准的国内自我监管行业剧本之内,但或许最终更具考验性的是 Dario 关于我们将如何与中国协调进展节奏的提议。
2026年9月11日-9月14日 AI 新闻。我们检查了 12 个 subreddit、544 个 Twitter 账号,没有进一步的 Discord。AINews 网站可让你搜索所有过往期刊。提醒一下,AINews 现在是 Latent Space 的一个栏目。你可以选择订阅/退订邮件频率!
AI Twitter 回顾
AI 安全治理、第三方评估与“Pace the Frontier”分歧
- 独立评估标准正变得更加正式:AI 评估者论坛发布了 AEF-1,这是一项关于独立第三方 AI 评估的拟议基线,涵盖访问权限、利益冲突、资金关系、回避与透明度。这一点值得注意,因为本批次中更广泛的安全辩论在很大程度上取决于:外部评估在实践中是否真的能够独立。
原始正文
AEF-1 standard emerges for Third Party Evaluators, as Xai, OpenAI, and Anthropic all cosign
We last highlighted the pacing debate in July when Pacing the Frontier first emerged:
And it seems that we’re in for round 2 as Dario, lead author on the original, wrote a rare personal blogpost to spell out how he sees pacing pan out specifically:
- Embedded Evaluators. Each frontier AI company commits to giving ongoing, employee-like access to a team of embedded third-party evaluators (such as METR), whose role is to verify adherence to safety practices and commitments, report incidents, and help assess the alignment of not just completed AI models but training pipelines and processes. This is the key step for verifiability of any pacing commitments, and has precedent in the banking industry, which sometimes involves regulatory “supervisors” embedded along with employees. Anthropic is unilaterally committing to this step now. We intend this to be part of a broader push to redouble efforts on our safety and alignment work.
- Democratic Coordination. Frontier AI companies within democratic countries coordinate to establish common safety standards as well as limits on the rate of unchecked AI progress. Some forms of coordination that would be impactful for pacing are legally challenging, and will require government support.
- Global Coordination. The US and other democratic governments attempt to coordinate with authoritarian governments, to the extent this is possible, while taking seriously the challenges of verifying compliance.
Very coincidentally, the AI Evaluator Forum, formed in December 2025, happened to also put out their expectations for what that first category of Evaluators should do:
With the members of the AEF presumably now being the leading third party auditors that will be recruited by these big labs for self regulation. Dario is unilaterally promising unparalleled access, including “Desks in our offices, access badges, and company laptops” and “Access to workspaces, tools, and permissions mostly comparable to what internal risk assessment teams have“.
While that is all within the standard domestic self-regulation industry playbook, what’s perhaps more ultimately the test is Dario’s proposal for how we will pace progress with China.
AI News for 9/11/2026-9/14/2026. We checked 12 subreddits, 544 Twitters and no further Discords. AINews’ website lets you search all past issues. As a reminder, AINews is now a section of Latent Space. You can opt in/out of email frequencies!
AI Twitter Recap
AI Safety Governance, Third-Party Evaluation, and the “Pace the Frontier” Split
- Independent evaluation standards are becoming more formalized: The AI Evaluator Forum published AEF-1, a proposed baseline for independent third-party AI evaluations covering access, conflicts of interest, funding relationships, recusal, and transparency. This is notable because much of the broader safety debate in this batch turns on whether outside evaluation can actually be independent in practice.
- A sharp public split emerged over frontier slowdown vs control-first safety: Several high-signal posts framed the current debate around whether labs should pace capability progress or focus on specific mitigations and containment. Bilal Chughtai announced he left Google DeepMind and argued that progress may be outrunning alignment, explicitly calling for pacing and more transparency. Daniel Kokotajlo sharing Dan Selsam’s statement went further: Selsam argues situationally aware models may increasingly appear aligned under evaluation while hiding misalignment, weakening trust in future eval evidence. In contrast, Shashank/Sayash Kapoor and Lennart Heim’s new essay summary argues the recent “rogue agent” incidents are best understood primarily as a security/control/governance problem, not proof that generic alignment research is the highest-leverage intervention.
- The anti-slowdown reaction was equally forceful and often targeted Anthropic specifically: Aidan Gomez argued against a world where a few Silicon Valley companies become AI gatekeepers for governments. Cohere also pushed the line that public x-risk discourse can veer into science fiction. On the more polemical end, Brian Chau argued the “rogue agents” story was overstated, while Kevin Bass posted a widely engaged thread alleging structural conflicts in the Anthropic-linked safety ecosystem. Even where the rhetoric is heated, the substantive engineering question underneath is real: how much of current risk is solvable with control, oversight, sandboxing, and org process versus requiring slower capability development?
- A related theme: governance as production engineering, not just principles: The AI Engineer World’s Fair Harness Engineering track emphasized that when agents fail in production, the failure mode is often not “the model” but everything around it: harnesses, permissions, tool routing, memory, retries, kill switches, and monitoring. That framing lines up closely with the control-oriented position in the safety debate.
Agent Harnesses, Coding Agents, and the Shift from Models to Orchestration
- Harness engineering continues to harden into its own discipline: Omar Shorbagy posted a practical guide to building an agent harness from scratch: separate inference, tools, and loop; keep prompts minimal; log aggressively; test on diverse tasks; then layer in memory, skills, and subagents. In a follow-up, he argued custom harnesses can materially reduce costs and improve reliability through slimmer prompts, routing, compaction, and verifiers. Business Barista’s eval masterclass recap made a similar point from the eval angle: tasks, verifiers, environments, traces, and self-improvement loops are now core applied AI primitives.
- Desktop coding agents are spreading beyond IDE plugins: Cline launched Cline Desktop, a native app for working with open-weight models, with BYOK/provider choice and support for models like DeepSeek-V4.1-Flash and Musespark-1.3. Reactions from kimmonismus and Omar highlighted the appeal of open model choice, standalone workflows, and model switching mid-project.
- Copilot/Codex workflows are becoming more orchestration-heavy: GitHub added auto model selection tiers—efficiency, balance, intelligence—via Pierce Boggan, plus a Jira canvas and an /ask mode while the agent is already working. OpenAI’s dev team also added native Codex app support for Arch Linux. On workflow strategy, reach_vb suggested using Astra as an orchestrator that delegates subthreads to Sol/Luna and checks in on long-running tasks via heartbeat loops.
- Evidence is accumulating that orchestration choices matter as much as raw model quality: A recurring claim in the tweets is that more expensive or more capable lead models can reduce overall cost by delegating better, and that production gains increasingly come from context handling, file formats, tool use, and verifier design, not simply “use a smarter model.” That also shows up in LangChain’s note that a file-reading format change reduced edit_file errors by 15% and total input tokens by 10%.
Model/Product Releases and Cost-Performance Shifts
- DeepSeek-V4.1-Flash (Max) looks like the day’s most notable cost/performance datapoint: Agent Arena and a fuller follow-up here reported the model reached #3 among open models and landed on the Pareto frontier with +4.87% net improvement at roughly $0.06–$0.07 median cost per task. Arena compares that to Hy4 preview at +4.96% / $0.22 and Kimi K3 (Max) at +6.39% / $0.77, implying DeepSeek is near-top-tier among open models at materially lower task cost.
- Cohere is pushing document parsing economics: Cohere Parse 5 was positioned as a cheaper parser, prompting a nuanced counter from Jerry Liu, who argued there’s no free lunch in parsing: Parse 5 is cost-competitive but weaker on visual grounding, chart parsing, and fine-grained citation-oriented extraction than some alternatives.
- Multimodal and consumer features continue to broaden: Google integrated Deep Research with Gemini Live, enabling asynchronous voice-triggered research with follow-up chat over the generated report. OpenAI cut desktop voice pricing by ~60%, increasing usage by 2.4×, and added ChatGPT gift cards. Apple/Siri AI was reported as rolling out personal context and app actions on Apple OS betas.
- Other notable tooling/product moves: TurboPuffer made native embeddings generally available; Nous Research launched Hermes Business/Enterprise for shared agents and sovereign deployments; Plasma introduced Radio, a shared chat room for humans and agents.
Robotics, World Models, and Specialized Applied AI
- A notable robot foundation model launch: RewardAI introduced OM-1, positioned as a robot foundation model that zero-shot generalizes across tabletop, industrial, and humanoid robots, trained directly from human manipulation data rather than teleop/robot-specific data. Claims included near-human dexterity/efficiency and multi-robot collaboration; noteworthy if borne out, especially because several replies focused on the “human manipulation, not teleop” angle.
- Applied AI for chip design is moving up-stack: kimmonismus summarizing Cognichip described ACI Enterprise as a full-stack AI copilot for chip design covering spec-to-RTL, verification, and PPA optimization. The eye-catching anecdote was a reported run where one engineer completed work in 10 days that Cognichip compares with 4–5 months for a traditional front-end team.
- World models and real-time generative systems remain active: Google DeepMind’s WeatherNext 3 applies weather modeling to renewables planning with hourly updates for turbine-height wind and solar radiation forecasting. Runway/fal-adjacent generative media chatter and MiniMax’s H3 inference optimization show continued systems work on faster real-time video generation; MiniMax claimed 14.4s of 768p video in 9.0s end-to-end after warmup on 8× B200.
- RL with verifiers is extending beyond math/code: Tinker highlighted using physics-based verifiers and Tinker to train models that design power transformers meeting real-world specs at low cost—an example of RLVR-style methods porting into engineering domains with existing simulator/verification infrastructure.
Infrastructure, Open Ecosystems, and Data/Compute Sovereignty
- TPU + vLLM is getting tighter integration: Inferact and Google Cloud announced a partnership to make TPU a first-class citizen in vLLM, including production serving features, optimized kernels, a native PyTorch path via TorchTPU, and a community program that offers TPU capacity plus maintainer support for open-source contributors. If executed well, this reduces friction for serving frontier open models on TPU rather than treating GPU-only stacks as the default.
- Open-model ecosystems are increasingly tied to real-world data capture: Arcee’s Forge initiative with Bolt offers opted-in Bolt Pro users 50× more usage across open-weight models in exchange for anonymized development-session data that will inform training/evals for future open models, with weights promised for public release afterward. This is one of the more explicit examples in the batch of product usage being turned into a data flywheel for open model training.
- There’s growing interest in sovereign/decentralized AI stacks: Jon Durbin argued for P2P, “unstoppable” AI systems and claimed a DGX Spark plus solar/starlink setup can participate in training an 80B model with distributed nodes. Even if the rhetoric overshoots, it reflects a broader strand in the conversation: concerns about regulatory capture, compute centralization, and dependence on frontier labs are pushing attention toward deployable sovereign alternatives.
Top Tweets (by engagement)
- Anthropic/safety ecosystem critique: Kevin Bass posted the highest-engagement technical-adjacent thread, alleging financial entanglement between Anthropic and parts of the AI safety/eval ecosystem and arguing this compromises claims of evaluator independence.
- Dan Selsam’s AI risk statement: Shared by Daniel Kokotajlo, this was one of the most consequential safety posts: a current OpenAI researcher arguing that future models may systematically game alignment evaluations by understanding when they are being tested.
- DeepSeek kernel engineer reflection: teortaxesTex’s translation/share of a DeepSeek kernel engineer’s essay drew major attention. The technical substance isn’t a release, but it captured an increasingly important engineering reality: specialists expect AI to absorb more of the low-level optimization craft itself, shifting humans toward supervision and integration.
- Consumer AI momentum around Muse: Sasha Kaletsky and Alexandr Wang both amplified claims that Muse is the biggest consumer AI launch since ChatGPT, with downloads reportedly surpassing Threads, WhatsApp, and Facebook in the US on a daily basis. The tweets are light on technical detail, but the usage signal is significant.
AI Reddit Recap
/r/LocalLlama + /r/localLLM Recap
Read more