freeze
a hundred thousand dollars to imagine everyone owning a frontier model. the rules ask you not to use one.
matt huang, who announced it. neal stephenson, novelist. gwern branwen, writer. the three read the final ten.
on monday 31 august matt huang posted a story competition called gpu world. its premise, in the site's own words: imagine that ai frontier progress stops as of 1 september 2026. ai becomes faster and cheaper, but it never becomes superhuman or improves considerably across the board.
the chips keep coming, though. by 2040, the site says, there may be the equivalent of 8 billion gpus globally and everyone has access to a frontier llm. entrants are asked to write that world, fiction or nonfiction, 1,000 to 5,000 words, by 31 october. winners are named in december.
the money is real: 40,000 dollars for first, 20,000 for second, 12,000 for third, and 4,000 each for seven finalists, 100,000 in all. only the top ten after a pre-screen reach the three judges, neal stephenson, gwern branwen and huang himself. paradigm and a company called guardian angel intelligence support it.
then the guidelines. llm use is permitted, but discouraged, and entrants are asked to disclose it. the site's reason: llm use tends to reduce originality and writing quality, and the flaws are especially obvious when llm outputs are read as a group. a prize for imagining everyone with a frontier model, judged by people who would rather you wrote it yourself.
the contest picked the first day of this week as the day progress stops, then told its writers the machines are not good enough to help. both halves are the same opinion.
who benefits: ten writers, and whoever wanted a public argument that the current models are the ceiling. who pays: nobody yet, which is what makes it the absurd lane and not the bad one. what should change: nothing, except that the disclosure request should be a rule, so the judges know what they are reading as a group.
the long wayopenclose
the premise is a live counterfactual and this issue is inside it. the contest says frontier progress stops on 1 september 2026. the week this issue covers ends on 6 september. by the contest's clock, everything after this page is the world the entrants are describing.
the frozen future is not a poor one. the site's own framing is abundance: chips do not stop, prices fall, and a frontier model is in everyone's hands. what stops is the thing the labs sell, which is the promise of the next one.
the rules do not ban the machine. they permit it, discourage it, and ask to be told. the sentence about flaws being obvious when outputs are read as a group is the tell: the judges expect to see a stack of entries and to recognise the ones no person wrote.
where it comes from
gpuworld.org, the contest's own site, read in full: premise, rules, prize table, committee, timeline, supporters. the site's timeline prints only august for submissions opening. the 31 august date is huang's announcement post on x, status 2094456614426407161, which was not read on x; its posting time resolves to 31 august 2026, 16:05 utc, by the standard decode of the post id, and tyler cowen's marginal revolution links that exact post in tuesday assorted links 584, published 1 september 2026, read in full.
what is not settled
the announcement date rests on arithmetic over a post id plus a next-day link, not on a dated document that says 31 august. whether stephenson and branwen wrote any of the site's copy is not stated. the site does not say who pre-screens to ten. the affiliation of huang to paradigm is not printed on the contest page and does not print here.
what was withheld
the entry as first drafted said every person on earth would own a gpu by 2040. the site says there may be the equivalent of 8 billion, and that everyone has access to a frontier llm. the qualifiers stay. the site's opening line about the future being unevenly distributed is left out because it is a quotation of someone else.
daypack
three men asked a chatbot what to pack for mount shasta. three agencies spent a day getting them down.
sheriff jeremiah larue, siskiyou county. three young men from roseville, california, unnamed in every record. a deputy who met them at the trailhead, also unnamed.
the siskiyou county sheriff's office release is dated 1 september. three young men from roseville made camp at about 8,400 feet on saturday 29 august, left at three in the morning on sunday with daypacks for the summit, and reached it at seven that evening, hours past the noon turnaround the office tells everyone to keep.
an hour into the descent they phoned the sheriff's dispatch to ask for directions, then wandered off route into mud creek canyon. one of them fell and hurt a knee. they spent the night in the drainage. forest service climbing rangers reached them monday morning, 31 august, and the county's search and rescue volunteers walked them to the trailhead. the forest service's own account puts the finish at 6:30 that evening, after a highway patrol helicopter tried an airlift and was turned back by wind.
at the end of it, the release says, the men told a deputy on scene that they had relied heavily on google's gemini for the route and for what to pack. the office's own verdict follows: this was a critical misstep, as they were advised by gemini to bring far less food and water than their group required, especially when their planned 8 hour ascent became a multi-day ordeal.
the forest service tells it wider. by its account they planned with ai, youtube and a trail app, the phone running the app died, and the backup charger did not work. the men's own sentence, as the forest service carries it: we relied too much on ai rather than our own critical thinking.
the chatbot did what it was asked. it made the plan sound like a day. the mountain had not read the plan.
who benefits: nobody, though three men are home with one bad knee. who pays: two county teams, a federal ranger crew and a helicopter's fuel, for a packing list no person checked. what should change: a trip plan for a mountain with a fatality record gets read by someone who has stood on it, and the office's own advice says exactly that.
the long wayopenclose
the sheriff said two things about it, four days apart, and both print. on 3 september, to kmax and kovr: it tends to want to give you favorable information and also make you seem like you're kind of invincible, and i think that that causes problems, especially when something can be extremely dangerous. on 4 september, to krcr: ai can be used as a research tool, but when you're going to go put yourself in a potentially life or death scenario, just make sure that you're getting all of the information that you can from the experts.
the two agencies tell the cause differently and this page does not merge them. the sheriff's office names gemini and nothing else. the forest service names ai, youtube and the app, and puts the wrong turn on a dead phone. the reliance on gemini is the men's own account, given to a deputy, relayed by the office.
the release closes on a line the office has plainly written before: serious accidents and fatalities occur on the clear creek route when individuals become lost and wander into more dangerous terrain, such as the mud creek drainage. that is where they spent the night.
where it comes from
the siskiyou county sheriff's office release, dated 1 september 2026, read whole at sierra daily news, which reproduces it with its dateline. cbs sacramento, carlos e. castañeda, 2 september, quoting the release. the forest service account as carried by fox weather, kieran sullivan, 2 september. the two larue interviews: kmax/kovr via cnn newsource at wafb, 3 september; krcr, keagan ostop, 4 september.
what is not settled
the sheriff's office publishes by facebook post and its release has never been read on the office's own domain; the forest service release has no located landing page and is read only through carries. the three men are not named anywhere and no name is supplied. the summit elevation is not printed because the carries disagree about it. which of the two accounts of the cause is right is not settled by anything read.
what was withheld
the larue passage was earlier recorded as coming from the press release. it does not; it is an interview, and it prints attributed to the station that recorded it. a wisconsin station's wire rewrite, and a machine-written local aggregator, were both set aside as sources.
driveway
the glasses read a blind woodworker the marks on his gauge blocks, which a specialist said nothing could.
tracy ferro, biloxi, national vice president of the blinded veterans association. al carr, 83, lexington, virginia, and his wife gail carr.
tracy ferro is legally blind. he retired after twenty years in the air force, worked as a mechanic in biloxi until he could no longer fix a car safely, and has been an inpatient at the gulf coast blind rehabilitation center three times. on 2 september wcpo in cincinnati reported that he had been wearing meta's ai glasses for about a month and does not leave home without them.
he is a woodworker. gauge blocks are precision measuring pieces with small printed markings, and by wcpo's account his own va visual impairment coordinator had told him no available magnification tool could read them. the glasses read them. the softer version is a restaurant: he reads the menu himself now instead of having it read to him.
the programme is meta's, with the blinded veterans association as partner, and ferro is one of the association's officers, which is printed here every time his name is. meta's own number, which is meta's and nobody else's, is that more than 130,000 american veterans are legally blind.
the story behind this one is al carr, 83, a marine, a vmi graduate and a retired law professor in lexington, virginia, reported by cardinal news on 24 august, a week before this window. he lost the last of his sight in 2018. when he walks with the glasses on, a volunteer somewhere else watches the camera feed and tells him where the step is. the ai reads his mail. the person walks him.
the useful part is a machine reading small print to a man who was told it could not be read. the moving part is still a person.
who benefits: a woodworker in biloxi and a law professor in lexington, and meta, which gets a veterans' charity as its distribution. who pays: meta, in glasses, and the volunteers, in hours. what should change: every story about the glasses should say which sentences the ai spoke and which a person did, because the two are being sold as one.
the long wayopenclose
gail carr's line, to cardinal news: he had not left this house except with someone in eight and a half years, so this was a really big thing. that is her recollection and it prints as one.
on the afternoon the reporter watched, it did not work. the connection kept dropping and carr made it a few yards down the driveway before giving up. on a hot day on the parade ground the eyepiece overheated and had to be shut down to cool. cardinal printed the failures beside the walk, which is why the walk is believable.
the association's executive director, lea rowe, is on the record with wcpo that the glasses are not a cure and are a tool in the tool belt. a giveaway and training day in cincinnati was scheduled for 16 september, after this issue's date, and it is not the story.
where it comes from
wcpo cincinnati, adrian whitsett, 2 september 2026, in window, for ferro. the blinded veterans association's own leadership page, undated house copy, for his office, his service, biloxi, the mechanic years, the rehabilitation stays and the woodworking. cardinal news, tad dickens, 24 august 2026, out of window and labeled as background, for the carrs. meta's 130,000 as cardinal attributes it to meta.
what is not settled
wcpo's text is, by its own footer, a broadcast converted to the page with the assistance of ai, so ferro is paraphrased and never set as verbatim. wcpo gives him a rank and a named genetic eye condition; his association's own biography states neither, and the same page attributes that condition to a different officer, so neither prints. the va coordinator's remark is wcpo's account. nothing in ferro's story is dated to a day inside the window; the peg is the report of a month's use.
what was withheld
a line that carr walked to the end of his driveway alone for the first time since 2018 was in the pool and is wrong twice; a volunteer guided him and the year is not in the piece. the name of the foundation distributing the glasses in virginia is left out on purpose, along with its president's history with vmi, because the fold belongs to the carrs.
typo
the machine wrote nerve damage. her scan said the opposite. she caught it. the hospital called it a typo.
a woman who works for the nhs, unnamed at her own request. rachel power, chief executive of the patients association. dr shier ziser dawood, a gp in london. dr charlotte blease, researcher.
on monday 31 august the guardian published an exclusive from healthwatch england, the statutory patient champion: the ai scribes now writing up nhs consultations are getting drug names and diagnoses wrong, and the person catching it is the patient.
three cases. an mri summary said demyelination, the nerve damage that leads towards multiple sclerosis, where the record should have read null demyelination. the scribe dropped the word that reversed the meaning. the patient is an nhs health professional herself. she queried her own record, and it was corrected. her words: this was eventually corrected but was a very traumatising experience to be given an incorrect diagnosis because of ai and then be told it's a typo.
a second scribe confused the drug a gp prescribed with a different one of a similar name, and the patient, not the doctor, noticed. a third left out of a summary letter that a consultant had told the patient to get a repeat prescription for migraine from their gp. the guardian counts 27 different scribes in use in england; a pharmacy trade title says at least 27.
the regulator's line runs through the middle of it. the mhra's guidance of 29 july says a product that only listens, transcribes and summarises is not a medical device, and one that claims to guide diagnosis is. its own example seven is a scribe identical in function to one that is not a device, which becomes a device because its maker claims it improves outcomes. same software, different sales copy. healthwatch calls the result worrying: no england-wide oversight of the ones that only write.
the last check on a permanent medical record is now whether the patient happens to read it carefully. and the body that noticed is scheduled for abolition.
who benefits: the nhs plan, which expects the scribes to free staff from bureaucracy, and a market in which one product is most of it. who pays: whoever does not read their own letter. what should change: a named route for a patient to dispute and correct a machine's entry, which is what healthwatch asked for, before the bill that proposes to close healthwatch passes.
the long wayopenclose
the counterweight is dr charlotte blease's, in the guardian: ai can and does make mistakes, and doctors can and do make mistakes without ai, and it is certainly possible the error rate is worse. her own survey of uk gps, run in august 2025 and read here as a preprint, found that of the 141 who used a scribe, 14 per cent had met an error with significant to critical implications, and 37 per cent did not routinely ask a patient's consent before switching the machine on. one respondent's reason: it is just a scribing tool, no different from a dictaphone.
dr shier ziser dawood wrote last year, in the british journal of general practice, about her own patient's record: a scribe charted an instruction to continue prozac that was never discussed. she calls the tools a double edged sword, and adds that because every transcript has to be checked, they are not yet saving the time the nhs is counting on.
a healthwatch spokesperson, to pharmacy business: healthcare has never been error-free. but our findings show the urgent need for clarity over how patients can report and get corrected any mistakes made by ai scribing tools or the professionals that use them.
healthwatch england was operating through this window. a government bill proposes to abolish it and fold its function into the department of health. the department's own equality assessment of that bill concedes, in its own words, that some patients may trust independent organisations to provide feedback over organisations that are involved in providing their care.
where it comes from
the guardian, denis campbell, health policy editor, 31 august 2026, read in full at its aol syndication under a canonical tag to the guardian, because the guardian's own domain refuses this tooling. pharmacy business, sreedevi n r, 31 august 2026, an independent carry with a healthwatch quote the guardian does not have. the mhra guidance on ambient voice technology, gov.uk, first published 29 july 2026, updated 31 july, read in full. blease et al, research square preprint, published 17 october 2025, survey run 7 to 27 august 2025, read in full. the department of health's equality impact assessment of the bill, gov.uk, published 14 may 2026, read in full. all of that outside the window is background.
what is not settled
the patient, her profession and her request for anonymity rest on one guardian exclusive; the trade carry has the case but not her. rachel power's quote is single-sourced. the mhra guidance does not use the word worrying and concedes no gap; that is healthwatch's characterisation and prints as it. the blease figures are self-reported, from a preprint that contradicts itself on two counts, so percentages print and counts do not. the bill's current stage in parliament was not read and does not print.
what was withheld
the prozac case was once counted as a fourth healthwatch case. it is dawood's own account from last year and prints as that. a healthwatch poll from april, published in july, was never read at its own domain and does not print. the flat claim that the mhra decided scribes are not medical devices, printed by two outlets, is wrong on the guidance's own examples and does not print. no timetable for the abolition prints, because the government's own assessment says none has been set.
stealth
three hundred people asked the nameless model who it was. one man measured it, and had the name in three days.
yisen xi, independent researcher, beijing, sole author.
on 20 august a reasoning model called ox alpha appeared on openrouter with a million-token context, images and video in, tool calling, a price of zero, and this for a vendor: a stealth model developed and operated by a third-party provider who has chosen to remain anonymous.
about 300 community attempts to make it say what it was got nothing credible. xi did not ask it. he rebuilt its launch configuration from archive snapshots, matched that against the platform's catalogue, then ran the same prompts at several lengths and counted tokens, and the count differed from the candidate by exactly 75 tokens on every paired probe. on 23 august his dated artifacts pointed at zhipu ai's glm-5.3 line.
on 26 august zhipu confirmed ox alpha was glm-5.3-flash and the stealth listing came down. on 27 august xi ran his probes against the same model, now public, and it answered z.ai glm. his conclusion: suppressing self-identification is a deliberate, revocable serving-layer policy rather than a model property. the silence was a setting.
the paper went up on arxiv on 31 august, the first day of this window. the whole audit ran to about a hundred api calls and ten thousand prompt tokens, at the free window's pricing, nothing, and at list price, under a few cents. attribution cost, he writes, is dominated by latency, not spend.
the model was never hiding. the switch that made it say nothing was on the server, and someone turned it off. you cannot ask a model who it is. you can measure it.
who benefits: anyone piping their work through a codename endpoint who would like to know whose it is, since the paper says identity sets the data-handling terms and the supply-chain risk, and that risk is uninsurable without attribution. who pays: platforms that sell anonymity as a feature. what should change: a listing that hides its vendor says so on the price line, and a reader can now check.
the long wayopenclose
the paper is careful and the care prints. its ten retrospective cases, seven exact, are a test of whether models declare consistently, not of blind identification, and the author says so three times. the one live case reached the version line, not the variant; flash was never predicted, only matched after the reveal. and no timestamped prediction was deposited on 23 august, which xi himself calls a weaker commitment than the protocol now recommends.
the second case is the one to watch. on a coding platform called opencode zen, a stealth slot was held by a model called code supernova from october 2025, rotated to one called big pickle on 18 november 2025, and it was still anonymous at xi's audit on 28 august 2026. he could not finish, because the platform does not expose prompt token counts, so the protocol declined rather than guessed. nine months of unknown servers under working code.
three of the four stages ship as a standard-library tool at the author's github. the archive reconstruction is a written procedure, not a program. the close is not a forecast; it is a method a reader can run this week against whatever new codename appears next.
where it comes from
arxiv 2608.31142, yisen xi, cs.se, full text read at arxiv's html rendering. the author's repository, github.com/yisenxi/anonymous-model-audit, mit licence, which prints the posting date of 31 august 2026 and the 26 august reveal date, and states which stages the code implements.
what is not settled
the arxiv abstract page itself refused the read today with a rate limit, so the date rests on the identifier, the lineup's earlier read of the abstract, and the author's own repository. one paper, one author, one live case, no independent corroboration sought. that zhipu confirmed the model is the paper's report of the reveal; zhipu's own statement was not read. what openrouter or zhipu intended by the silence is not known.
what was withheld
a figure that 45.83 per cent of endpoints advertising frontier brands failed fingerprint checks is a cited work by other authors, not this paper's, and it does not print. a line about developers unknowingly handing proprietary code to unknown servers is an inference nobody in the paper makes and is replaced by the big pickle case, which is documented.