Forwarded from Refat Talks: Tech & AI
#ReDigest
Продолжаем субботнюю рубрику, тут я кратко рассказываю про новости из мира технологий и AI, которые привлекли мое внимание.
Дайджест недели:
- Релиз Claude Opus 5: по заявлениям компании близко к Fable 5 за половину цены. Промптить и строить контекст надо иначе.
- Модели OpenAI вырвались из песочницы, вышли в интернет и увели ответы с серверов Hugging Face, которым пришлось использовать китайские модели чтобы анализировать происходящее.
- Ровно на этом фоне в Палату представителей внесли AI Kill Switch Act: рубильник для отключения опасных моделей.
- Google выпустил Gemini 3.6 Flash, 3.5 Flash-Lite и 3.5 Flash Cyber. Задачи решается за меньшее число шагов.
- Kimi K3 уличили в дистилляции (сама представляется как Claude), Белый дом обвинил Moonshot в обходе экспортного контроля, Минфин пригрозил санкциями.
- Китай в ответ обсуждает запрет на выкладывание весов за рубеж.
- Anthropic заплатит $1,5 млрд авторам за книжное пиратство (обучение - fair use, наказали за хранение).
- Anthropic закупит у AMD до 2 ГВт мощности и AMD представила Helios - первую rack систему.
- Google разрабатывает чип Frozen v2 с архитектурой Gemini, вшитой прямо в кремний.
- OpenAI запустила Presence - голосовых и текстовых агентов для корпоративной поддержки, только для энтерпрайза.
- ChatGPT Voice приехал в десктоп: общаясь голосом можно запускать и менеджить задачи в Work и Codex.
- Anthropic обновила голосовой режим Claude: вместо Haiku теперь Opus и Sonnet с переключением на лету, подтянулись коннекторы.
- Anthropic [выпустила] плагин (https://x.com/claudeai/status/2079990597973057691) Claude Security для многоагентного поиска уязвимостей в репо.
- Claude Cowork учится, наблюдая за вами: записываете экран и проговариваете шаги, на выходе скилл, который Claude повторит. Codex недавно релизил похожее.
- Claude Desktop также получил поддержку iOS-симулятора.
- Alibaba показала превью Qwen3.8 Max на 2,4 трлн параметров.
- В Шанхае учредили Всемирную организацию по сотрудничеству в сфере ИИ: 29 стран, дают открытые китайские модели и учат локальных ML-инженеров.
- Еврокомиссия оштрафовала Google на 890 млн евро по DMA.
- Винт Серф ушел из Google делать DNSid - открытый стандарт идентификации агентов поверх DNS.
- YouTube отключит монетизацию контент-заводам.
- Netflix использовал AI примерно в 300 фильмах и сериалах и заодно рассказал как поднял свой LLM-инференс в продакшене.
- Неделя роутеров: Cursor Router, Ramp Router экономит 30% и объясняет механику, Runway роутит генеративную медиа.
- Вышла FLUX 3 - изображения, видео, аудио и физические действия в одной архитектуре.
- Poolside выложила Laguna S 2.1 - 118B MoE с 8B активных под агентный кодинг и длинные задачи. Контекст 1 млн, открытая лицензия.
- Alibaba выпустила Qwen Image 3.0: модели можно дать полноценное ТЗ на инфографику или интерфейс.
- Джек Дорси запустил Buzz - опенсорсный воркспейс где люди, агенты и репозитории в одном канале.
- Google опубликовала AI & Economy ATLAS.
- YC обновил список желаемых стартапов: AI выходит в физический мир - образование, здравоохранение, оборонка, финансы и заводы.
- Agent Client Protocl (ACP) v2 вышел в драфте.
- draw-your-font - скилл, превращающий фото вашего почерка в устанавливаемый шрифт.
- OpenWorker от Эндрю Ына - локальный десктопный AI-коллега, который работает с вашими файлами и приложениями.
- GenReasoning выпустила BackSearch - поиск и фетч по замороженному архиву веба на заданную дату.
- Карпаты снова назвал вслух очевидный тренд, и все побежали: ramble-coding (диктовать свои мысли эффективнее чем промптитить текстом).
- 🤩 Две красоты для продуктовых лендингов: Canvas UI - библиотека эффектных компонентов, отрисованных на canvas, с MCP в комплекте, и scroll-world - скилл, собирающий из бренда скроллируемый 3D-мир. А еще Rivet для генераций вариантов дизайна.
Продолжаем субботнюю рубрику, тут я кратко рассказываю про новости из мира технологий и AI, которые привлекли мое внимание.
Дайджест недели:
- Релиз Claude Opus 5: по заявлениям компании близко к Fable 5 за половину цены. Промптить и строить контекст надо иначе.
- Модели OpenAI вырвались из песочницы, вышли в интернет и увели ответы с серверов Hugging Face, которым пришлось использовать китайские модели чтобы анализировать происходящее.
- Ровно на этом фоне в Палату представителей внесли AI Kill Switch Act: рубильник для отключения опасных моделей.
- Google выпустил Gemini 3.6 Flash, 3.5 Flash-Lite и 3.5 Flash Cyber. Задачи решается за меньшее число шагов.
- Kimi K3 уличили в дистилляции (сама представляется как Claude), Белый дом обвинил Moonshot в обходе экспортного контроля, Минфин пригрозил санкциями.
- Китай в ответ обсуждает запрет на выкладывание весов за рубеж.
- Anthropic заплатит $1,5 млрд авторам за книжное пиратство (обучение - fair use, наказали за хранение).
- Anthropic закупит у AMD до 2 ГВт мощности и AMD представила Helios - первую rack систему.
- Google разрабатывает чип Frozen v2 с архитектурой Gemini, вшитой прямо в кремний.
- OpenAI запустила Presence - голосовых и текстовых агентов для корпоративной поддержки, только для энтерпрайза.
- ChatGPT Voice приехал в десктоп: общаясь голосом можно запускать и менеджить задачи в Work и Codex.
- Anthropic обновила голосовой режим Claude: вместо Haiku теперь Opus и Sonnet с переключением на лету, подтянулись коннекторы.
- Anthropic [выпустила] плагин (https://x.com/claudeai/status/2079990597973057691) Claude Security для многоагентного поиска уязвимостей в репо.
- Claude Cowork учится, наблюдая за вами: записываете экран и проговариваете шаги, на выходе скилл, который Claude повторит. Codex недавно релизил похожее.
- Claude Desktop также получил поддержку iOS-симулятора.
- Alibaba показала превью Qwen3.8 Max на 2,4 трлн параметров.
- В Шанхае учредили Всемирную организацию по сотрудничеству в сфере ИИ: 29 стран, дают открытые китайские модели и учат локальных ML-инженеров.
- Еврокомиссия оштрафовала Google на 890 млн евро по DMA.
- Винт Серф ушел из Google делать DNSid - открытый стандарт идентификации агентов поверх DNS.
- YouTube отключит монетизацию контент-заводам.
- Netflix использовал AI примерно в 300 фильмах и сериалах и заодно рассказал как поднял свой LLM-инференс в продакшене.
- Неделя роутеров: Cursor Router, Ramp Router экономит 30% и объясняет механику, Runway роутит генеративную медиа.
- Вышла FLUX 3 - изображения, видео, аудио и физические действия в одной архитектуре.
- Poolside выложила Laguna S 2.1 - 118B MoE с 8B активных под агентный кодинг и длинные задачи. Контекст 1 млн, открытая лицензия.
- Alibaba выпустила Qwen Image 3.0: модели можно дать полноценное ТЗ на инфографику или интерфейс.
- Джек Дорси запустил Buzz - опенсорсный воркспейс где люди, агенты и репозитории в одном канале.
- Google опубликовала AI & Economy ATLAS.
- YC обновил список желаемых стартапов: AI выходит в физический мир - образование, здравоохранение, оборонка, финансы и заводы.
- Agent Client Protocl (ACP) v2 вышел в драфте.
- draw-your-font - скилл, превращающий фото вашего почерка в устанавливаемый шрифт.
- OpenWorker от Эндрю Ына - локальный десктопный AI-коллега, который работает с вашими файлами и приложениями.
- GenReasoning выпустила BackSearch - поиск и фетч по замороженному архиву веба на заданную дату.
- Карпаты снова назвал вслух очевидный тренд, и все побежали: ramble-coding (диктовать свои мысли эффективнее чем промптитить текстом).
- 🤩 Две красоты для продуктовых лендингов: Canvas UI - библиотека эффектных компонентов, отрисованных на canvas, с MCP в комплекте, и scroll-world - скилл, собирающий из бренда скроллируемый 3D-мир. А еще Rivet для генераций вариантов дизайна.
"Do a full end-to-end QA test of OpenClaw with live API keys. Use 12 subagents to split up functionality, spin up dev gateways with different ports, and use some to stress test. Orchestrate, use worktrees and create PRs autonomously. Set a goal to find 200 bugs. Fix the root cause each time, no band-aids. Refactors are okay, unless they touch the plugin SDK boundary. Write a test report in my desktop folder as markdown and keep updating that."
Vibe coders are getting sued.
People are shipping apps with real users and skipping the boring stuff that kills them.
A 20+ year dev shared the pre-launch checklist every AI builder needs.
I added what I learned after shipping 60+ apps at the agency.
Don't skip this:
1. Protect yourself, not just your app. The moment you collect user data you're in legal territory (GDPR, CCPA). Have a privacy policy. Know where user data lives.
2. Row Level Security. Without RLS, anyone can open DevTools and read your entire database. Supabase → Auth → Policies. Zero policies means your app is naked. 5 min to fix.
3. Test the failure path, not just the happy path. Wrong password 5x. Reset for an email that doesn't exist. Verification link clicked twice. Signup with an existing email. Catches 80% of auth bugs.
4. Security baseline in 2 min. Prompt your AI: "Review my app as a security specialist and make sure I have strong security headers and a solid baseline security posture."
5. OWASP. Prompt: "Review my app against OWASP standards and highlight vulnerabilities." This is where SQL injection, XSS and auth bugs actually get caught.
6. Client-side validation is UX, not security. Attackers disable JS and hit your API directly. Validate again on the server. Every time.
7. AI code leaks data in 3 spots: .env values in the frontend, API responses returning too much, secrets in logs. Prompt: "Check my app for credential or sensitive data leaks in frontend or API routes."
8. API keys in the frontend means game over. If it's in the browser, assume it's already taken. Move it server-side or proxy it.
9. Rate limits before someone burns your API bill. Cap every endpoint hitting a paid API. I've watched a Supabase bill jump from $20 to $200 in a day.
10. CAPTCHA on public forms (Cloudflare Turnstile is free) plus CORS locked to your domain. 10 min, kills bot floods.
11. Error messages that don't leak. "User not found", not "SELECT * FROM users failed". Log full errors server-side, show users generic messages.
Build fast. Just don't ship naked.
(full breakdown in my article below)
People are shipping apps with real users and skipping the boring stuff that kills them.
A 20+ year dev shared the pre-launch checklist every AI builder needs.
I added what I learned after shipping 60+ apps at the agency.
Don't skip this:
1. Protect yourself, not just your app. The moment you collect user data you're in legal territory (GDPR, CCPA). Have a privacy policy. Know where user data lives.
2. Row Level Security. Without RLS, anyone can open DevTools and read your entire database. Supabase → Auth → Policies. Zero policies means your app is naked. 5 min to fix.
3. Test the failure path, not just the happy path. Wrong password 5x. Reset for an email that doesn't exist. Verification link clicked twice. Signup with an existing email. Catches 80% of auth bugs.
4. Security baseline in 2 min. Prompt your AI: "Review my app as a security specialist and make sure I have strong security headers and a solid baseline security posture."
5. OWASP. Prompt: "Review my app against OWASP standards and highlight vulnerabilities." This is where SQL injection, XSS and auth bugs actually get caught.
6. Client-side validation is UX, not security. Attackers disable JS and hit your API directly. Validate again on the server. Every time.
7. AI code leaks data in 3 spots: .env values in the frontend, API responses returning too much, secrets in logs. Prompt: "Check my app for credential or sensitive data leaks in frontend or API routes."
8. API keys in the frontend means game over. If it's in the browser, assume it's already taken. Move it server-side or proxy it.
9. Rate limits before someone burns your API bill. Cap every endpoint hitting a paid API. I've watched a Supabase bill jump from $20 to $200 in a day.
10. CAPTCHA on public forms (Cloudflare Turnstile is free) plus CORS locked to your domain. 10 min, kills bot floods.
11. Error messages that don't leak. "User not found", not "SELECT * FROM users failed". Log full errors server-side, show users generic messages.
Build fast. Just don't ship naked.
(full breakdown in my article below)
Andrej Karpathy just dropped 12-page PDF on "Graph Engineering" for multi-agentic systems
the shift: Karpathy's loop runs 700 experiments and forgets all of them. A graph remembers forever
here's the full system:
step 1 → build one loop: generate, critique, revise. 630 lines, 700 experiments in 48 hours
step 2 → go parallel: agents in separate worktrees, same repo, different branches, no conflicts
step 3 → add a knowledge graph: extract entities, resolve aliases, assemble typed edges, query through subgraphs
step 4 → ground your evaluator: it checks claims against graph edges, not vibes
step 5 → plug the graph as shared memory. workers write to it. evaluators fact-check against it. Loops persist overnight
step 6 → the agent forgets. the graph does not. stop rebuilding context from scratch every session
Karpathy ran 1 agent in 1 direction. Anthropic's graph runs 1,000 with shared memory - same model, it's the architecture
this 11-page PDF changed how I'm building multi-agent systems today
read it now - then explore the full graph engineering article below ↓
the shift: Karpathy's loop runs 700 experiments and forgets all of them. A graph remembers forever
here's the full system:
step 1 → build one loop: generate, critique, revise. 630 lines, 700 experiments in 48 hours
step 2 → go parallel: agents in separate worktrees, same repo, different branches, no conflicts
step 3 → add a knowledge graph: extract entities, resolve aliases, assemble typed edges, query through subgraphs
step 4 → ground your evaluator: it checks claims against graph edges, not vibes
step 5 → plug the graph as shared memory. workers write to it. evaluators fact-check against it. Loops persist overnight
step 6 → the agent forgets. the graph does not. stop rebuilding context from scratch every session
Karpathy ran 1 agent in 1 direction. Anthropic's graph runs 1,000 with shared memory - same model, it's the architecture
this 11-page PDF changed how I'm building multi-agent systems today
read it now - then explore the full graph engineering article below ↓
Great idea 🔥
Here’s a more complete and robust prompt for Claude (works especially well with Projects or when you upload the codebase):
Analyze my entire codebase in depth.
Generate TWO complete, ready-to-use deliverables:
1. A single self-contained HTML file (Tailwind CDN + dark theme) that includes:
- Interactive architecture diagram (nodes + edges)
- Flows panel on the right
- When selecting a flow, highlight the full path in the diagram and show detailed steps below
- Tooltips with descriptions for each component
- Clean, professional, and responsive design
2. A structured JSON with this exact shape:
{
"nodes": [...],
"edges": [...],
"flows": [
{
"id": "...",
"name": "...",
"description": "...",
"steps": [...]
}
]
}
The HTML is for humans. The JSON is for the next AI agent so it can fully understand the architecture and work on new features without losing context.
Deliver both files complete, with nothing omitted.
Here’s a more complete and robust prompt for Claude (works especially well with Projects or when you upload the codebase):
Analyze my entire codebase in depth.
Generate TWO complete, ready-to-use deliverables:
1. A single self-contained HTML file (Tailwind CDN + dark theme) that includes:
- Interactive architecture diagram (nodes + edges)
- Flows panel on the right
- When selecting a flow, highlight the full path in the diagram and show detailed steps below
- Tooltips with descriptions for each component
- Clean, professional, and responsive design
2. A structured JSON with this exact shape:
{
"nodes": [...],
"edges": [...],
"flows": [
{
"id": "...",
"name": "...",
"description": "...",
"steps": [...]
}
]
}
The HTML is for humans. The JSON is for the next AI agent so it can fully understand the architecture and work on new features without losing context.
Deliver both files complete, with nothing omitted.
Analyze my codebase. Generate a self-contained HTML (Tailwind CDN, dark theme) with an interactive architecture diagram + interactive Flows section (select and highlight path + steps).
And a JSON {nodes, edges, flows: [{steps}]} for AI agents.
Deliver both complete.
And a JSON {nodes, edges, flows: [{steps}]} for AI agents.
Deliver both complete.