Backcover | EYES |

  • A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. […]
  • Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate, and Prevent. The journey starts with detection, because organizations first need to understand what credentials exist, where they live, and what they
  • Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report
  • Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full […]
  • A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access […]
  • AI-assisted research uncovered a critical Rejetto HFS flaw that enables authentication bypass and remote code execution, now exploited in the wild. A Rejetto HFS vulnerability, tracked as CVE-2026-61500 (CVSS score of 9.3), discovered with the help of the Anthropic Mythos AI model is now being exploited in the wild, turning an interesting security research experiment […]
  • Hackers accessed names, addresses and CPR numbers of 8.8 million people in Denmark through a third-party company with legal registry access. A hacker broke into the database that holds basically every identifying detail on every person connected to Denmark, living, dead, or long since moved away. Denmark’s digital affairs minister announced it Monday and didn’t […]
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Citrix NetScaler flaw tracked as CVE-2026-88779 (CVSS score of 8.7), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Gateway […]
  • MI5 warns UK universities that over 100 academics may have unknowingly worked on research funded by a Chinese institute linked to the MSS. On September 30, MI5 published a formal warning naming the China General Technology Research Institute, CGTRI, also called CAGT in some translations, as an outfit with very strong ties to China’s Ministry […]
  • Iranian hacker Amir Barati faces extradition to the US over an alleged Iranian campaign that stole 31TB of data from universities. Amir Barati spent June 25 getting arrested in Montenegro, and this week a Montenegrin court signed off on sending him to the United States. He’s a dual Turkish and Iranian citizen, 40 years old, […]
  • OpenAI safety veteran David Robinson resigns, warning that the company’s culture and fast AI development model could create bigger risks. OpenAI safety veteran David Robinson knows how his resignation looks. He starts his essay by calling himself “something of a cliché”: an AI company employee who quits and then raises concerns about the company. But […]
  • Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, reshaping both the techniques used by attackers and the tools available to defenders. AI agents can automate tasks, analyze large amounts of data, discover vulnerabilities and accelerate offensive operations. At […]
Articles by the Director
(The Director Eye)

A number with no recorded reason may end up deciding for a patient

Article 005 · 3 August 2026

Transparency in artificial intelligence has become a question of provenance. Provenance tells you where a piece of content came from; it does not tell you why what it asserts was decided.

▶Also published as a policy contribution to the European Commission — click to expand

A version of this argument was submitted to the Apply AI Alliance of the European Commission and published on its Community Exchange Platform on 3 August 2026, under the title Provenance is not traceability: a gap in AI transparency for science and health.

That version is not a reprint. It is addressed to a policy readership and framed against the Commission’s own instruments: it opens from the Apply AI Strategy, which names healthcare and pharmaceuticals among its priority sectors, and from the AI in Science Strategy, and it closes with an explicit recommendation — that where AI-assisted selection informs research funding, experimental design or clinical investigation, transparency requirements should cover the reason attached to a decision and not only the origin of the content that carries it. The present article states the case; that one states what should follow from it.

Read it on the European Commission’s Futurium platform · archived copy

A number with no recorded reason may end up deciding for a patient

In June 2026, a team at the University of Chicago, with Honglin Bao and James A. Evans as corresponding authors, began with 121,640 preprints and sent their authors — where an email address could be reached — hypotheses that twenty-six artificial intelligence systems (large language models) had generated from those authors' own papers. Almost nine in ten of those papers came from biology and medicine. The figure is not neutral: medicine proved the most receptive field to hypotheses generated by these systems — 8.05 per cent above the social sciences — the field whose researchers showed the highest proportion of prior publications involving AI and, alongside biology, the one that showed a stronger preference than the social sciences for safe directions (Bao et al., 2026, arXiv:2606.08251v2). This exercise in generating and selecting hypotheses was built primarily on the life sciences; one fifth of its corpus was medicine, the field whose conclusions can end up reaching a sick person.

It is worth asking, then, what that circuit records when a machine proposes and a scientist decides. A team at Anthropic inserted into prompts given to Claude 3.7 Sonnet and DeepSeek R1 hints capable of altering their answers, isolated the cases in which the answer moved in the direction the hint indicated, and then measured whether the chain of thought acknowledged having used it. Overall faithfulness was twenty-five per cent for Claude 3.7 Sonnet and thirty-nine per cent for DeepSeek R1 (Chen et al., 2025, arXiv:2505.05410). The experiment does not show that every explanation is false. It shows something more uncomfortable: that an explanation cannot be presumed to retain the factor that actually changed the decision.

Between the factor that changes a decision and the explanation that ends up on the record lies much of today's confusion about transparency, because provenance has been mistaken for traceability. On 31 July 2026 OpenAI described an approach resting on C2PA content credentials and SynthID watermarks, applied to images and being extended to audio; for text — the material science is made of — the commitment is stated in the future tense, as standards and tools mature (OpenAI, 31 July 2026). Provenance answers where a piece of content came from. Traceability answers why what it asserts was decided. Neither stands in for the other.

There is a second passage where the reason is lost, and it runs from the model to the headline. Eamon Duede, Kevin Gross, M. J. Crockett and Carl T. Bergstrom distinguish three ways in which these tools speed up the work: finding out sooner which projects are worth developing, reducing the minimum labour required to make a project publishable, or accelerating the further development of a project already under way. In the first two, the depth of published work falls; in the third the opposite holds, and each developed project reaches greater depth (Duede et al., 2026, arXiv:2607.17397). Yet the paper's own closing summarises the result by saying that these tools push us to do more, less well, and the headline in Nature reproduces that general direction, even though the article goes on to record Bergstrom's caution that the problem lies not in the tool but in an incentive system that rewards quantity (Glickman, Nature, 31 July 2026). The exception does not disappear from the model: it disappears from the preprint's closing and from the headline that travels.

While public debate calls for more transparency about where content comes from, the questionnaire used by Bao et al. offers an example of the opposite habit where decisions are concerned: keep the outcome and drop the reason. In that study, 5,259 scientists supplied 25,139 assessments — novelty, feasibility and likelihood on a one-to-nine scale, and adoption on a one-to-seven scale — without the questionnaire asking at any point for the reason behind those figures. The authors hold that expert communities contribute not only verdicts but the collective construction of the criteria by which ideas are judged; their instrument records the verdict, but not the reasoning by which each scientist applied those criteria to the hypothesis in front of them. The reward model subsequently trained on this material receives ratings and the pairwise preferences derived from them, for which the specific reason was never recorded (Bao et al., 2026, supplementary material A.5 and A.11).

It may be objected that provenance is necessary, and it is. It may be objected that those cited here declare their limits with uncommon candour, and that is true as well: such candour does not remove the limit, it makes the limit locatable. I have long held that a system without a third value ends up asserting where it should withhold judgement, because fluency reads as competence and hesitation reads as failure. The Anthropic data do not demonstrate that ternary architecture, but they do show the risk that motivates it: a system can close an answer without preserving in its explanation the cause that moved it. Faced with misalignment hints, chains of thought acknowledged that influence in only twenty per cent of cases for Claude 3.7 Sonnet and twenty-nine per cent for DeepSeek R1 (Chen et al., 2025). A hypothesis for which no record exists of why it was preferred may steer funding, experimental design and trials. Should this form of record-keeping spread to clinical research assisted by artificial intelligence, the patient may inherit decisions whose justification is no longer reconstructible from the system that selected them. Recording the why is not a minor documentary requirement. It is a necessary condition for keeping science from becoming an archive of conclusions that no one can any longer review.

Sources

Bao, H., Wu, S., Liu, X., Li, S., Cao, S. & Evans, J. A. (2026). Contemporary AI lacks the imagination to diverge or negate in science. arXiv:2606.08251v2 · https://arxiv.org/abs/2606.08251v2

Chen, Y., Benton, J., Radhakrishnan, A. et al. (2025). Reasoning Models Don't Always Say What They Think. arXiv:2505.05410 · https://arxiv.org/abs/2505.05410

Duede, E., Gross, K., Crockett, M. J. & Bergstrom, C. T. (2026). The unintended consequences of large language models as a labor-augmenting technology in science. arXiv:2607.17397 · https://arxiv.org/abs/2607.17397

Glickman, K. (31 July 2026). Scientists using LLMs will 'do more, less well', modelling study predicts. Nature · https://www.nature.com/articles/d41586-026-02397-5

OpenAI (31 July 2026). Advancing responsible AI across Europe · https://openai.com/es-ES/index/advancing-responsible-ai-across-europe/

Spanish original: Lloret Egea, J. A. (3 August 2026). Un número sin razón registrada puede acabar decidiendo por un enfermo. itvia.online · https://doi.org/10.21428/39829d0b.55593db8

Previous articles
  1. Article 004 · 14 July 2026
    Not yet: the third answer in machine intelligence
  2. Article 003 · 11 July 2026
    External validation is not a bureaucratic detail
  3. Article 002 · 11 July 2026
    A medical algorithm must not confuse cost with health
  4. Article 001 · 11 July 2026
    When AI sounds certain but should say “I do not know”

Why did I look?

Archive · European AI Alliance · 2020

From 2020 to 2026: the same problem, two documents

«In May 2020, as a member of the European AI Alliance, I took part in two European Commission debates on the use of artificial intelligence against COVID-19. I keep them sealed, with their comments from the time, because their value lies in the date: what I warned about then in a forum is today, six years on, the doctrine I uphold in these Director’s Articles».

Each document expands separately. Select the one you wish to read.

Document 1 · Diagnosis in hospitals ▸ Using AI to diagnose COVID-19 in hospitals The CT tool across ten European hospitals and the warning on clinical judgment.

Director’s Note — 2026

In May 2020, the European Commission announced within the European AI Alliance the deployment of an artificial-intelligence tool to diagnose COVID-19 from computed-tomography images across ten hospitals in nine countries. The text below is that announcement; the comment accompanying it is the one I signed at the time, as a member of the Alliance. I have not amended it: I keep it exactly as published, sealed, because its value lies precisely in its date.

I warned there of three things. That operating below a minimum sample threshold breeds singularities and dangerous identifications. That replacing clinical judgment with software leads to serious errors. And that institutional haste, no less than slowness, has a price. Six years on, those three warnings have not merely held: they have hardened into architecture. What in 2020 was an intuition written in a forum is today, in these Director’s Articles, reasoned doctrine. Medical AI must distinguish prediction from decision, assistance from authority, and uncertainty from failure; it must undergo external validation before deployment, not after harm; and it must not mistake cost for health. The Watson case —which recommended a contraindicated drug to a patient with haemorrhage, without hesitating— and the Epic Sepsis case are the bill for having ignored what was already known.

From 2020 to 2026, the problem remains the same. Only one thing has changed: we now have the cases that prove it.

Juan Antonio Lloret Egea

Author’s comment

Juan Lloret · 26 May 2020, 15:07

Thanks for sharing this information.

This subject is very topical, along with the use of data in pandemics such as COVID-19. And it is convenient to have real, highly qualified experts in the fields, or investments can be very unsuccessful for Europe. For example, using data below a minimum threshold (statistical sample universe) can lead to singularities or very dangerous identifications for citizens. Also trying to substitute qualified doctors and specialists (guided by the patient’s clinic and the experience of the healthcare provider) with software or hardware can carry serious errors. In the USA this is already done under the supervision of international standards such as the FDA and the IEEE (for example, the Computer Society and others).

If Europe walks slowly, it will be a serious problem for citizens and significant investment losses. On the contrary, if Europe walks too fast it can cause chaos in the profession of medicine: lightning technicians (X-ray technicians), radiologists, etc. Regards, Juan Antonio.

▸ View the original document (European Commission)
Document 2 · The training data ▸ COVID-19 detector using X-ray images Nine hundred images to decide in a pandemic and the warning on scarce data.

Director’s Note — 2026

This second document, also from May 2020 and from the same European AI Alliance forum, addresses the other half of the problem: not the deployment of the tool, but the data it is trained on. It concerns a COVID-19 detector based on chest X-rays, built on a set of barely some nine hundred images.

My comment at the time insisted on the essential point: in a new and poorly documented disease, knowledge of the terrain is everything, and the unknowns were —and are— many. There, already in raw form, was the thesis I have developed six years later in these Director’s Articles: a model trained on scarce or biased data does not learn to diagnose; it learns to repeat the bias of its origin, and it does so with the fluency of one who does not doubt. It is the same lesson as the Obermeyer case —the algorithm that mistook healthcare spending for health need— and the Epic Sepsis case: external validation is not a later formality; it is the prior condition that separates a clinical tool from a well-presented statistical superstition.

Nine hundred images in 2020 to decide on a pandemic. In 2026 we are still discussing the same thing, only now with the statistical casualties in plain sight.

Juan Antonio Lloret Egea

Author’s comment

Juan Lloret · 30 March 2020 · Additional comment V

COVID-19 is a novel, still poorly documented disease, and a good knowledge of the terrain is essential. The description given by Wang and Wong, of the University of Waterloo and Darwin AI, is a good starting point, though I am well aware that the scientific community is working most intensively. Nevertheless, there are still many unknowns, and this alone shows the complexity of the matter. I also attach technical bibliography for context in the references of the original thread.

▸ View the original document (European Commission)

A Different Look

(Papers with Code — Trending Research)

The most influential AI research papers with code, datasets, methods and evaluation leaderboards — ranked this month by citation count. An external reference we recommend for tracking the state of the art.

Open Papers with Code ↗

Opens on paperswithcode.co · content and rankings belong to Papers with Code.

Opening your eyes: Nature & NASA & Science

  • NASA astronaut and mission specialist of the agency's Artemis II mission, Christina Koch, led the fans in singing the Eagles Fight Song from the field at an NFL game between the Philadelphia Eagles and the Los Angeles Rams at Lincoln Financial Field on Sunday, Oct. 4, 2026, in Philadelphia.
  • An engineering model of NASA’s DAVINCI (Deep Atmosphere Venus Investigation of Noble gases, Chemistry, and Imaging) descent probe passed a key test that ran from Aug. 28 to Sept. 10, showing it can survive the extreme temperatures of Venus.
  • A SpaceX Falcon 9 rocket carrying the company's Dragon spacecraft is launched on NASA’s SpaceX Crew-13 mission to the International Space Station with NASA astronauts Jessica Watkins and Luke Delaney, CSA (Canadian Space Agency) astronaut Joshua Kutryk, and Roscosmos cosmonaut Sergey Teteryatnikov aboard, Thursday, Oct. 1, 2026, from Cape Canaveral Space Force Station in Florida.
  • This long-duration image shows star trails above Earth and the blue lights of fishing boats and the yellow lights of Indonesian cities stretching below the International Space Station as it orbited 258 miles above the Banda Sea.
  • Ahead of launch of NASA’s SpaceX Crew-13 mission, a SpaceX Falcon 9 rocket, with the Dragon spacecraft atop, is vertical at the launch pad of Space Launch Complex 40 at Cape Canaveral Space Force Station in Florida on Sunday, Sept. 27, 2026.
  • This nighttime view of the United States, dotted with city lights looking toward New York City (center), was taken at approximately 3:40 a.m. local time from the International Space Station as it orbited 259 miles above Earth.
Share this on: