Backcover | EYES |

  • Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current. The attack requires an attacker who already controls the server's software and can briefly access the machine to insert […]
  • An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list […]
  • A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link button, and the script ran only when someone opened the export file in a web browser. It could then copy every […]
  • A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. "Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems," Acronis Threat Research Unit (TRU)
  • WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "New plugins are reviewed before they enter the directory, but updates ship continuously after that," David Perez, WordPress Official Plugin
  • Frontier AI is compressing the attack lifecycle from vulnerability discovery to exploitation, forcing defenders to detect, patch and respond at machine speed. Cybersecurity has always been a race between attackers and defenders. ENISA’s latest assessment suggests that frontier AI is changing the speed of that race, and the gap between discovering a vulnerability and exploiting […]
  • China rejects Amodei’s AI slowdown proposal, calling it fearmongering and a US attempt to contain China’s technology sector. The debate over whether the world should slow down the development of advanced AI has quickly turned into something bigger than a technology argument. Dario Amodei, CEO of Anthropic, has called for a slower pace of development, […]
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Two of the above vulnerabilities affect JFrog Artifactory. CVE-2026-42016 can allow attackers to bypass authorization checks and […]
  • Two critical Check Point VPN flaws score 9.8 and could enable remote code execution. Patch now and restrict VPN access before exploitation begins. The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN products, both rated CVSS score of 9.8, could soon be actively exploited. If you use Check Point VPN, you should […]
  • Anthropic CEO calls for AI slowdown, proposes embedded evaluators and global coordination. Geopolitical competition with China makes a voluntary pause structurally fragile. Dario Amodei published “We Must Pace the Frontier“, calling on the AI industry, governments, and international bodies to slow the pace of AI capability development before safety research can catch up. It’s the […]
  • Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter REVSTEALER ramps up Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode   GuardBreaker: Derailing AI-assisted malware analysis with a code comment   DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive […]
  • A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open […]
Articles by the Director
(The Director Eye)

A number with no recorded reason may end up deciding for a patient

Article 005 · 3 August 2026

Transparency in artificial intelligence has become a question of provenance. Provenance tells you where a piece of content came from; it does not tell you why what it asserts was decided.

Also published as a policy contribution to the European Commission — click to expand

A version of this argument was submitted to the Apply AI Alliance of the European Commission and published on its Community Exchange Platform on 3 August 2026, under the title Provenance is not traceability: a gap in AI transparency for science and health.

That version is not a reprint. It is addressed to a policy readership and framed against the Commission’s own instruments: it opens from the Apply AI Strategy, which names healthcare and pharmaceuticals among its priority sectors, and from the AI in Science Strategy, and it closes with an explicit recommendation — that where AI-assisted selection informs research funding, experimental design or clinical investigation, transparency requirements should cover the reason attached to a decision and not only the origin of the content that carries it. The present article states the case; that one states what should follow from it.

Read it on the European Commission’s Futurium platform · archived copy

A number with no recorded reason may end up deciding for a patient

In June 2026, a team at the University of Chicago, with Honglin Bao and James A. Evans as corresponding authors, began with 121,640 preprints and sent their authors — where an email address could be reached — hypotheses that twenty-six artificial intelligence systems (large language models) had generated from those authors' own papers. Almost nine in ten of those papers came from biology and medicine. The figure is not neutral: medicine proved the most receptive field to hypotheses generated by these systems — 8.05 per cent above the social sciences — the field whose researchers showed the highest proportion of prior publications involving AI and, alongside biology, the one that showed a stronger preference than the social sciences for safe directions (Bao et al., 2026, arXiv:2606.08251v2). This exercise in generating and selecting hypotheses was built primarily on the life sciences; one fifth of its corpus was medicine, the field whose conclusions can end up reaching a sick person.

It is worth asking, then, what that circuit records when a machine proposes and a scientist decides. A team at Anthropic inserted into prompts given to Claude 3.7 Sonnet and DeepSeek R1 hints capable of altering their answers, isolated the cases in which the answer moved in the direction the hint indicated, and then measured whether the chain of thought acknowledged having used it. Overall faithfulness was twenty-five per cent for Claude 3.7 Sonnet and thirty-nine per cent for DeepSeek R1 (Chen et al., 2025, arXiv:2505.05410). The experiment does not show that every explanation is false. It shows something more uncomfortable: that an explanation cannot be presumed to retain the factor that actually changed the decision.

Between the factor that changes a decision and the explanation that ends up on the record lies much of today's confusion about transparency, because provenance has been mistaken for traceability. On 31 July 2026 OpenAI described an approach resting on C2PA content credentials and SynthID watermarks, applied to images and being extended to audio; for text — the material science is made of — the commitment is stated in the future tense, as standards and tools mature (OpenAI, 31 July 2026). Provenance answers where a piece of content came from. Traceability answers why what it asserts was decided. Neither stands in for the other.

There is a second passage where the reason is lost, and it runs from the model to the headline. Eamon Duede, Kevin Gross, M. J. Crockett and Carl T. Bergstrom distinguish three ways in which these tools speed up the work: finding out sooner which projects are worth developing, reducing the minimum labour required to make a project publishable, or accelerating the further development of a project already under way. In the first two, the depth of published work falls; in the third the opposite holds, and each developed project reaches greater depth (Duede et al., 2026, arXiv:2607.17397). Yet the paper's own closing summarises the result by saying that these tools push us to do more, less well, and the headline in Nature reproduces that general direction, even though the article goes on to record Bergstrom's caution that the problem lies not in the tool but in an incentive system that rewards quantity (Glickman, Nature, 31 July 2026). The exception does not disappear from the model: it disappears from the preprint's closing and from the headline that travels.

While public debate calls for more transparency about where content comes from, the questionnaire used by Bao et al. offers an example of the opposite habit where decisions are concerned: keep the outcome and drop the reason. In that study, 5,259 scientists supplied 25,139 assessments — novelty, feasibility and likelihood on a one-to-nine scale, and adoption on a one-to-seven scale — without the questionnaire asking at any point for the reason behind those figures. The authors hold that expert communities contribute not only verdicts but the collective construction of the criteria by which ideas are judged; their instrument records the verdict, but not the reasoning by which each scientist applied those criteria to the hypothesis in front of them. The reward model subsequently trained on this material receives ratings and the pairwise preferences derived from them, for which the specific reason was never recorded (Bao et al., 2026, supplementary material A.5 and A.11).

It may be objected that provenance is necessary, and it is. It may be objected that those cited here declare their limits with uncommon candour, and that is true as well: such candour does not remove the limit, it makes the limit locatable. I have long held that a system without a third value ends up asserting where it should withhold judgement, because fluency reads as competence and hesitation reads as failure. The Anthropic data do not demonstrate that ternary architecture, but they do show the risk that motivates it: a system can close an answer without preserving in its explanation the cause that moved it. Faced with misalignment hints, chains of thought acknowledged that influence in only twenty per cent of cases for Claude 3.7 Sonnet and twenty-nine per cent for DeepSeek R1 (Chen et al., 2025). A hypothesis for which no record exists of why it was preferred may steer funding, experimental design and trials. Should this form of record-keeping spread to clinical research assisted by artificial intelligence, the patient may inherit decisions whose justification is no longer reconstructible from the system that selected them. Recording the why is not a minor documentary requirement. It is a necessary condition for keeping science from becoming an archive of conclusions that no one can any longer review.

Sources

Bao, H., Wu, S., Liu, X., Li, S., Cao, S. & Evans, J. A. (2026). Contemporary AI lacks the imagination to diverge or negate in science. arXiv:2606.08251v2 · https://arxiv.org/abs/2606.08251v2

Chen, Y., Benton, J., Radhakrishnan, A. et al. (2025). Reasoning Models Don't Always Say What They Think. arXiv:2505.05410 · https://arxiv.org/abs/2505.05410

Duede, E., Gross, K., Crockett, M. J. & Bergstrom, C. T. (2026). The unintended consequences of large language models as a labor-augmenting technology in science. arXiv:2607.17397 · https://arxiv.org/abs/2607.17397

Glickman, K. (31 July 2026). Scientists using LLMs will 'do more, less well', modelling study predicts. Nature · https://www.nature.com/articles/d41586-026-02397-5

OpenAI (31 July 2026). Advancing responsible AI across Europe · https://openai.com/es-ES/index/advancing-responsible-ai-across-europe/

Spanish original: Lloret Egea, J. A. (3 August 2026). Un número sin razón registrada puede acabar decidiendo por un enfermo. itvia.online · https://doi.org/10.21428/39829d0b.55593db8

Previous articles
  1. Article 004 · 14 July 2026
    Not yet: the third answer in machine intelligence
  2. Article 003 · 11 July 2026
    External validation is not a bureaucratic detail
  3. Article 002 · 11 July 2026
    A medical algorithm must not confuse cost with health
  4. Article 001 · 11 July 2026
    When AI sounds certain but should say “I do not know”

Why did I look?

Archive · European AI Alliance · 2020

From 2020 to 2026: the same problem, two documents

«In May 2020, as a member of the European AI Alliance, I took part in two European Commission debates on the use of artificial intelligence against COVID-19. I keep them sealed, with their comments from the time, because their value lies in the date: what I warned about then in a forum is today, six years on, the doctrine I uphold in these Director’s Articles».

Each document expands separately. Select the one you wish to read.

Document 1 · Diagnosis in hospitals ▸ Using AI to diagnose COVID-19 in hospitals The CT tool across ten European hospitals and the warning on clinical judgment.

Director’s Note — 2026

In May 2020, the European Commission announced within the European AI Alliance the deployment of an artificial-intelligence tool to diagnose COVID-19 from computed-tomography images across ten hospitals in nine countries. The text below is that announcement; the comment accompanying it is the one I signed at the time, as a member of the Alliance. I have not amended it: I keep it exactly as published, sealed, because its value lies precisely in its date.

I warned there of three things. That operating below a minimum sample threshold breeds singularities and dangerous identifications. That replacing clinical judgment with software leads to serious errors. And that institutional haste, no less than slowness, has a price. Six years on, those three warnings have not merely held: they have hardened into architecture. What in 2020 was an intuition written in a forum is today, in these Director’s Articles, reasoned doctrine. Medical AI must distinguish prediction from decision, assistance from authority, and uncertainty from failure; it must undergo external validation before deployment, not after harm; and it must not mistake cost for health. The Watson case —which recommended a contraindicated drug to a patient with haemorrhage, without hesitating— and the Epic Sepsis case are the bill for having ignored what was already known.

From 2020 to 2026, the problem remains the same. Only one thing has changed: we now have the cases that prove it.

Juan Antonio Lloret Egea

Author’s comment

Juan Lloret · 26 May 2020, 15:07

Thanks for sharing this information.

This subject is very topical, along with the use of data in pandemics such as COVID-19. And it is convenient to have real, highly qualified experts in the fields, or investments can be very unsuccessful for Europe. For example, using data below a minimum threshold (statistical sample universe) can lead to singularities or very dangerous identifications for citizens. Also trying to substitute qualified doctors and specialists (guided by the patient’s clinic and the experience of the healthcare provider) with software or hardware can carry serious errors. In the USA this is already done under the supervision of international standards such as the FDA and the IEEE (for example, the Computer Society and others).

If Europe walks slowly, it will be a serious problem for citizens and significant investment losses. On the contrary, if Europe walks too fast it can cause chaos in the profession of medicine: lightning technicians (X-ray technicians), radiologists, etc. Regards, Juan Antonio.

▸ View the original document (European Commission)
Document 2 · The training data ▸ COVID-19 detector using X-ray images Nine hundred images to decide in a pandemic and the warning on scarce data.

Director’s Note — 2026

This second document, also from May 2020 and from the same European AI Alliance forum, addresses the other half of the problem: not the deployment of the tool, but the data it is trained on. It concerns a COVID-19 detector based on chest X-rays, built on a set of barely some nine hundred images.

My comment at the time insisted on the essential point: in a new and poorly documented disease, knowledge of the terrain is everything, and the unknowns were —and are— many. There, already in raw form, was the thesis I have developed six years later in these Director’s Articles: a model trained on scarce or biased data does not learn to diagnose; it learns to repeat the bias of its origin, and it does so with the fluency of one who does not doubt. It is the same lesson as the Obermeyer case —the algorithm that mistook healthcare spending for health need— and the Epic Sepsis case: external validation is not a later formality; it is the prior condition that separates a clinical tool from a well-presented statistical superstition.

Nine hundred images in 2020 to decide on a pandemic. In 2026 we are still discussing the same thing, only now with the statistical casualties in plain sight.

Juan Antonio Lloret Egea

Author’s comment

Juan Lloret · 30 March 2020 · Additional comment V

COVID-19 is a novel, still poorly documented disease, and a good knowledge of the terrain is essential. The description given by Wang and Wong, of the University of Waterloo and Darwin AI, is a good starting point, though I am well aware that the scientific community is working most intensively. Nevertheless, there are still many unknowns, and this alone shows the complexity of the matter. I also attach technical bibliography for context in the references of the original thread.

▸ View the original document (European Commission)

A Different Look

(Papers with Code — Trending Research)

The most influential AI research papers with code, datasets, methods and evaluation leaderboards — ranked this month by citation count. An external reference we recommend for tracking the state of the art.

Open Papers with Code ↗

Opens on paperswithcode.co · content and rankings belong to Papers with Code.

Opening your eyes: Nature & NASA & Science

  • Fans pose for a photo with an astronaut in the NASA Experience Zone at an NFL game between the Pittsburgh Steelers and the Atlanta Falcons at Acrisure Stadium, Sunday, Sept. 13, 2026, in Pittsburgh, Pennsylvania.
  • Galaxies are like cosmic gems, each with characteristics including size and shape that make them distinct. A gallery from NASA’s Chandra X-ray Observatory and other telescopes displays a collection of galactic images that showcase this variety.
  • Using the James Webb Space Telescope, an international team of astronomers have discovered that dust and water can form and survive surprisingly close to the supermassive black hole at the center of our Milky Way galaxy.
  • The crew of NASA’s Artemis II mission visited NASA’s Marshall Space Flight Center in Huntsville, Alabama on Sept. 1, 2026.
  • N44 is a complex nebula filled with glowing hydrogen gas, dark lanes of dust, massive stars, and many populations of stars of different ages. One of its most distinctive features, however, is the dark, starry gap called a “superbubble,” visible in this Hubble Space Telescope image in the upper central region.
  • On Wednesday, June 17, skywatchers across the United States—and parts of Canada—enjoyed a rare event: a daytime lunar occultation of Venus. A lunar occultation occurs when the Moon moves directly in front of another celestial object from our viewpoint on Earth, briefly hiding it from sight.
Share this on: