The Signal / Superpower Daily
Apple gives Siri screen context in macOS 27
Apple put Siri closer to everyday Mac work today. Elsewhere, the day brought fresh scrutiny of chat review, chip controls, infrastructure and safeguards that fail across fragmented tasks.
Superpower Daily: The Signal
Listen to this episode
Episode guide
Show notes
Apple put Siri closer to everyday Mac work today. Elsewhere, the day brought fresh scrutiny of chat review, chip controls, infrastructure and safeguards that fail across fragmented tasks.
In this episode
Full transcript
Read along
Select any transcript timestamp to continue listening from that point.
Welcome to the signal from superpower daily with Maya and Theo so today we are looking at Apple's massive release of Mac OS 27 and A version of Siri that can literally read your active screen Yeah We are diving right into that because imagine your private unencrypted bank statement is just sitting open on your computer monitor right now Right and now imagine you just hit a simple keyboard shortcut and suddenly Apple's operating system reads Processes and analyzes every single number on that page It sounds wild But I mean today that is no longer a hypothetical Exactly Apple just dropped Mac OS 27 and Siri is no
longer waiting for your voice prompt It is actually reading your active screen which is you know a fundamental shift in how we even define a personal computer Yeah we're looking at a machine that no longer just displays your work for you It actively watches you work So let us start right at the top of this deep dive Apple has officially released Mac OS 27 I think internally and publicly They're calling it Golden Gate Golden Gate Yeah and the absolute centerpiece of this update is a completely redesigned Siri architecture Yeah like we were all used to Siri being this reactive isolated voice prompt right Yeah you
ask a question about the weather and it gives you a generic answer it operates inside a silo right But with Golden Gate Siri has transitioned into this highly integrated Visual desktop tool like it uses your active window as its foundational context and the underlying mechanism Here is really what separates this from well anything Apple has done before how so because Siri has moved from simply listening to audio Triggers to actually interpreting the pixels It reads the semantic data right on your screen Oh wow So it's not just taking a screenshot No not at all The operating system doesn't just take a dumb screenshot It actively
maps out the text the images the metadata of whatever application you have in focus right at that second That is wild It changes the entire paradigm from a system of you know query and response to what Apple is calling a contextual companion Okay so the actual mechanics for the user here are very specific You just hit command shift space Yeah And that shortcut instantly adds whatever window is focused right now into series active memory buffer right Or you can use a much more precise tool by hitting command shift 6 Oh the crosshair thing exactly that shortcut turns your standard cursor into a crosshair and then
you can manually draw a Bounding box over a specific region of your screen like just a chart or a specific paragraph Yeah exactly Once you do that the interaction model just flips completely think about the friction this removes from your day Give me an example Well let us say you are looking at a really complex product page for I don't know a new espresso machine Yeah historically you would have to describe the machine to a search engine right You would have to copy and paste the URL Yeah and you'd have to manually read off the specifications to compare them Exactly but now you just bring
up Siri and ask it to compare the machine to alternative brands Because Siri already knows exactly what you are looking at That is so fast It is it reads the manufacturer page It understands the product category and it just executes the research based on that immediate visual context I mean it is an incredible parlor trick but we really have to unpack this further Definitely because this contextual awareness goes way way deeper than just reading a public web page It integrates into the deepest foundational layers of the OS like spotlight search Yes exactly take spotlight search spotlight now handles natural language Siri questions natively right And
it does not just search the web or look for file titles anymore No it searches the actual contents of your digital life which is where the local processing becomes absolutely critical spotlight narrows results to Specific applications or buried files or even the immediate history of your clipboard wait your clipboard history Yeah and you can ask it to run custom shortcuts directly from the search bar now That's convenient But the most powerful capability is really how it retrieves exact granular details from your unstructured Personal content you mean like scanning the body text of files yes it scans the body text of your files your archived emails
and Your private text messages to well okay TechCrunch actually ran a test on the Golden Gate release candidate And what do they find they found the system could instantly pull up things like Obscure membership IDs buried in some promotional email from literally five years ago That is insane They also said it could extract specific trip details and flight departure times hidden inside a complex PDF document That was just resting on the desktop Okay I need to pause this right here Because as a user this feels like giving an overly eager intern the master keys to your personal filing cabinet That is one way to look
at it I mean you are essentially telling this digital intern Here's every email I've ever sent every private PDF I have ever downloaded and by the way I want you to stand over my shoulder and watch my screen while I work It is a lot of access Are we actually ready to hand over this level of absolute trust to an operating system I mean we're talking about our everyday workflows here Yeah this is not a public sandbox This is our private digital life and that right there is the pivotal question of this entire release cycle You are hitting on the exact tension Apple is actively
trying to navigate because it just feels so invasive Well the technology no longer just accesses general facts from Wikipedia right Yeah it knows what you were looking at right in this exact second Yeah it knows the context of the person you are messaging in the messages app So Apple is really betting that the utility of having an assistant that knows your flight Confirmation number from three years ago outweighs the inherent creepiness of a machine reading your mail exactly They are betting heavily on convenience over that initial privacy hesitation And they are pushing this integration into literally every possible corner of the Mac experience Like they're
placing Siri directly into basic text fields now Yeah the text field integration is huge You could just highlight text in almost any native or third party application and a small contextual menu appears all right and then Siri can proofread the text or rewrite the tone to sound more professional or just draft a complex response from scratch Right there in the text box It is everywhere There is also a brand new dedicated Siri application that just lives on your dock now Oh right and it maintains your entire conversation history It treats your AI requests like an ongoing chat log rather than just Isolated questions which is
very different from old Siri very different and it syncs all of that history privately across all your Apple devices Using iCloud end to end encryption We also really need to talk about the browser because Safari is getting a massive upgrade Utilizing this exact same contextual awareness engine Safari is getting a lot smarter It goes far beyond simply blocking trackers now Safari can actually automatically organize your chaotic tabs by Analyzing the actual topic and sentiment of the pages which is desperately needed for people with 50 tabs open right But more importantly it tracks the dynamic state of the pages themselves What do you mean by the
dynamic state Well it monitors for price drops on specific retail items You have looked at recently Oh yeah It also alerts you to quiet changes in privacy policies on websites you frequent that is actually incredibly useful You can even tell you when a sold out product is back in stock It basically acts like a personal digital proxy constantly refreshing and monitoring pages in the background without draining your battery And they are bringing some serious contextual tools to the photos app to oh yeah the photo editing stuff They added a tool called spatial reframing along with an upgraded cleanup feature These tools use the deeper contextual
understanding of the image to seamlessly remove objects Or they can actually extend the borders of a photograph by literally Hallucinating the missing background that is wild But I think there is a major caveat to all of this on device magic We have to clearly establish the hardware boundaries here Yes the hardware limitations for GoldenGate are incredibly strict because it takes a lot of power to run this locally exactly You can technically install Mac OS 27 on older Intel based Macs But if you do you just get some very nice interface tweaks you get the new liquid glass aesthetic Which features adjustable window transparency and edge
to edge sidebars but you do not get the intelligence Yeah you do not get the intelligence The intelligence is heavily gatekept if you want the actual Apple intelligence features Like if you want this new screen reading Siri you must have newer Apple Silicon right You need an M1 Mac or later or of course the brand new MacBook Neo So if you have an Intel Mac you're completely locked out of the AI features completely the neural engine required to process the screen Context locally simply does not exist on those older chips and there is also a significant language boundary at launch too Right Yeah Apple is
treating this very very cautiously Siri AI is launching strictly as a public beta right now It's only in English Yes it is strictly locked to United States English Apple plans to push localized updates for French Japanese Korean Portuguese and Spanish later in October But for now it is a highly controlled English only deployment It is so we really have to ask what this all means for the daily user Well I think the headline here is not that Siri can chat with you in a more fluid voice No not at all The real headline is that Siri is now a system level control layer It sits
right between you and your applications It routes your immediate screen context and your historical personal data into a single intelligent action and Apple claims This local on device processing is the only safe path to truly relevant AI But the real world test for this technology is going to be trust always comes back to trust will users actually hit Command shift space when they are looking at their corporate payroll data right Will the average person allow Apple to aggregate their screen context and their private files during a normal workday Even if Apple promises the processing happens locally that is the behavioral shift Apple is trying to
force here It's going to be fascinating to watch that wraps up our look at macOS 27 It is actually a perfect thematic pivot really it is Because Apple is staking its entire reputation on processing your private context locally right there on your physical silicon right But our next story shows exactly what happens when user data gets processed remotely in the cloud It is a vastly different philosophy regarding user privacy and model training Yeah a massive investigation just dropped from 404 media They uncovered that open ai is actively using human contractors to read review and score Real chat gpt prompts Yes This is part of a
large internal initiative known as project lily project We always hear that vague phrase you know that language models are trained on user data right People think it's just machines doing it exactly But project lily is not just an automated algorithm scraping text in a dark server room These are hundreds of human beings Sitting at desks reading the exact words that regular people type into the chat gpt interface The operational workflow here is incredibly structured though Well the contractors are not just casually browsing user chats for fun They are executing a very specific feedback loop known as reinforcement learning from human feedback The entire goal is
to align the model's behavior with human expectations Okay but what are these contractors actually doing when they open a user's prompt So a human reviewer sits down on a terminal and pulls up a real submitted user prompt The first task is to write a comprehensive summary of what the user actually intended to get out of the bot They have to decode what we actually want exactly they have to decode the user's core request Then the interface displays multiple different answers that the ai generated in response to that specific prompt Oh I see and the contractor's job is to ruthlessly compare those outputs They're basically acting
as human judges For the machine Yes exactly They highlight specific passages where the ai perfectly follow the user's complex instructions And they also highlight passages where the ai failed or hallucinated or just lost the thread of the conversation that makes sense Then they assign a numerical score to the responses based on helpfulness And finally they have to write out a detailed written justification For why they gave that specific score and then all of that graded data is just fed back into the model To teach it how to generate better answers in the future right That's the loop the internal guidelines dictating what these reviewers are
actually looking for are so fascinating to me Yeah the rubrics are very specific because they are actively trained to penalize the ai for certain psychological behaviors Like what for example they're instructed to flag excessive flattery Really Yes if the bot is being too sycophantic you know if it constantly tells the user how brilliant their ideas are it loses points Open ai wants the bot to be helpful Not just a mindless Yes man That is so interesting They also heavily flag forced style mimicry What does that mean Well if the ai is trying too hard to sound like a teenager or using excessive slang and it
sounds unnatural or grating The reviewers score it down Oh thank goodness But the most crucial behavioral boundary they enforce is really regarding consciousness right If the model uses language implying it has genuine feelings or if it implies it possesses a physical body The human reviewers penalize it severely which makes perfect sense from a safety perspective Yeah you do not want users forming unhealthy emotional attachments to a prediction algorithm Exactly but I have to push back hard on the data collection system powering this entire operation Why is that Because open ai has a specific setting for this data collection It is vaguely titled improve the model
for everyone Ah yeah and if you have a free plus or pro account That setting is turned on by default the absolute moment you create your account that is correct It is an opt out system for the vast majority of consumer users This just feels incredibly invasive I mean think about the way open ai markets this product Users treat chat gpt like a deeply private brainstorming partner They do they tell it everything a user might be working through a highly sensitive business strategy Or they might be asking the bot to rewrite a deeply personal emotionally fraught email to a family member Right the user operates
under the illusion that it is just them and a mathematical machine So how is it ethically or practically fair to have a default on setting that routes those private thoughts To a human review queue Well open ai's primary defense here is anonymization They argue that the contractors absolutely do not see your account username your email address or your ip address But the word anonymized does a lot of heavy lifting here It is a very slippery concept it is because the prompts themselves naturally contain the sensitive details If I paste my own resume into the chat box to ask the ai for formatting feedback My actual
name my address and my entire employment history are sitting right there in the text That's true Stripping my account name from the metadata does not make the text anonymous and that highlights the very messy reality of large scale model improvement Open ai is totally aware of this though What are they doing about it They use an automated algorithmic tool internally called the privacy filter Okay the entire job of this filter is to scan these conversations and automatically redact obvious personal identifiers Things like phone numbers social security numbers and email addresses And it does this before the human contractor ever sees the text but the 404
media investigation notes that the company Openly admits this automated filter is fundamentally flawed Yeah they do they acknowledge in their own documentation that the privacy filter can easily miss uncommon identifiers And it routinely misunderstands ambiguous private references right Exactly The system just operates on extremes Sometimes it redacts way too much text Basically turning the prompt into a block of black bars making it totally unreadable right making it useless for the contractor But other times it redacts far too little leaving sensitive personal context completely exposed to the human reviewer And the reporters found something even more concerning regarding the context These reviewers are given the memory
feature Yes Some of these reviewed prompts also include a memory summary Chat gpt recently rolled out that memory feature that allows the bot to remember specific facts about you across different Unrelated chat sessions which is designed to save you from repeating your preferences every time you log in right But it means the human reviewer is not just seeing an isolated out of context prompt No they are not the reviewer interface displays a summary block right at the top of the screen And that block might explicitly state something like user is a senior software engineer living in downtown Chicago who struggles with anxiety and enjoys hiking
exactly it adds this massive aggregated layer of personal context to the review process It really completely chips away at the concept of anonymity It does even without a formal name attached a highly detailed memory summary combined with a specific nuanced prompt Can easily allow someone to deduce a user's identity their employer or their physical location We also need to highlight the tiered system of privacy here Because your level of privacy is directly tied to what kind of customer you are We established that free Plus and pro consumer accounts are default on for human training You do have options to manage this though Sure if you
go deep into your settings and manually turn the data sharing off your new chats will still stay in your personal history But they are technically excluded from this human training pipeline You can also utilize temporary chats right Those are completely excluded from training by default They do not save to your history sidebar and they do not create or pull from memories They are simply held on the fervor for 30 days strictly for trust and safety monitoring and then they are permanently deleted But the contrast is really stark when you look at enterprise clients It's night and day if you are on an enterprise business or
edu account The model improvement setting is completely disabled by default because open ai explicitly promises not to train on corporate data So we basically have a system where corporate clients get default privacy and everyday consumers get default exposure That is the current architectural structure of their business model Although it is worth noting that after 404 media started asking aggressive questions Open ai quietly updated their user help pages Oh they did Yeah they added more granular details about how the opt out process actually works but they still did not take the obvious step They still do not explicitly write in plain accessible english that a human
being might sit down and read your chat log No they do not they continue to rely on the corporate euphemism model improvement right and to the average person model improvement sounds like a giant server farm processing Abstract numbers in the middle of the night Hmm It does not sound like a contractor named dave reading your therapy bot session over his morning coffee Just to provide some industry context here though Human review is a standard practice across the entire generative ai sector It's not just open ai No it is not an exception unique to open ai anthropic does something incredibly similar with claude Yes They allow
users to opt into data sharing and they also utilize human reviewers after applying automated de identification filters Google does this with gemini 2 it's everywhere Human feedback is currently the only reliable way to teach these models complex reasoning and tone But industry standard does not excuse the lack of upfront clarity The boundary between a private digital space and a corporate training facility is just incredibly blurry right now It is a mess The vital question to watch moving forward is whether public outrage or maybe direct regulatory pressure from data protection agencies Forces open ai to change those user facing disclosures Will they eventually be forced to
put a giant unmissable banner at the top of the chat that clearly states Humans may read this conversation We will see it is a massive trust issue regarding the data We feed into these models It really is which brings us perfectly to the physical scale of all this computing because all that data has to go somewhere Exactly the software models and the human training loops We just talked about do not exist in a vacuum They require staggering amounts of physical hardware to train and operate and that physical hardware is now sparking severe international diplomatic clashes Which brings us to our next story right china's foreign
ministry just issued a direct highly public rebuke of anthropic ceo Dario amadei the stakes here have rapidly escalated from a theoretical tech industry debate into a state level Diplomatic incident it is a fascinating collision of silicon valley theory and actual geopolitical reality It really is let us break down exactly what triggered this clash Dario amadei recently published a comprehensive essay calling for the united states government to aggressively maintain its lead in artificial intelligence You did he proposed some very strict uncompromising limits on what technology the united states and its allies sell to china specifically He wants to heavily restrict the sale of advanced ai chips
like nvidia's cutting edge gpus and the manufacturing equipment too Right Well yes the highly specialized manufacturing equipment required to fabricate those chips natively Well the chinese government did not appreciate being the target of a proposed embargo No they did not their foreign ministry spokesperson guajia kun Addressed amodei's essay directly during a press conference What did he say He stated unequivocally that this kind of technological confrontation will actively harm global ai governance He argued that all international parties need to cooperate on technology rather than engage in what the state run Global times characterized as a cold war style containment effort Exactly we really need to clarify
exactly what amadei is asking for here because the nuances of ai policy are often misunderstood Right He is not asking the u s Government to ban the export of chinese open weight software models That is a crucial distinction and for anyone unfamiliar open weight models are ai systems Where the underlying mathematical parameters are freely available for anyone on the internet to download run locally and modify Right and amadei explicitly stated back in july That anthropic has never advocated for banning those software models from existing or spreading So his target is entirely focused on the physical layer of the technology stack the raw compute Exactly He
wants to choke off china's access to the massive clusters of processing power required to build these frontier models from scratch He also wants a severe coordinated crackdown on international chip smuggling Which is a huge problem because there are massive well funded black markets currently moving advanced american processors Through shell companies in the middle east and asia right into restricted regions and he wants that loophole closed permanently His entire argument relies heavily on an internal anthropic assessment regarding semiconductor manufacturing Amadei claims that china's domestic chip production capability is severely limited right now He argues they simply do not possess the extreme ultraviolet lithography machines needed to
manufacture processors at the absolute cutting edge Therefore his logic dictates that cutting off access to american chips Essentially freezes china's ability to train models that can compete with the latest iterations of gpt or claude He basically views hardware as a manageable choke point But we have to recognize that this is a private company's internal assessment It is not an undisputed geopolitical fact right Yes extreme ultraviolet lithography is incredibly hard to replicate But china is pouring billions of state dollars into domestic fabrication and historically every time the u s Embargoes a specific technology It just accelerates the adversary's domestic research and development Exactly That is a
valid historical critique Amadei's entire policy proposal is built on the fragile assumption that Containment on the hardware side will actually hold up over the next decade But here is where the situation gets truly paradoxical Tell me there is a glaring logical contradiction in amadei's stance and it highlights the impossible position the u s Government is in right now What's the contradiction Well amadei is famously cautious about ai safety He firmly believes that once these models reach a certain level of advanced capability They need rigorous mandatory global safety testing before deployment Okay He argues that a highly capable model poses catastrophic risks that cross physical borders
Regardless of which nation or lab built it right a bioweapon designed by an ai in one country Will inevitably affect the entire globe exactly he specifically compares ai safety to Preventing biological weapons or nuclear proliferation Oh I see You cannot have a functional global safety framework for bioweapons unless all the major powers explicitly including china Are sitting at the table sharing data and actively cooperating So his safety framework requires absolute transparent global cooperation Yes Yeah but he simultaneously wants to economically suffocate their domestic hardware capabilities That makes no sense right You cannot invite a global superpower to the table to sign a transparent peace treaty
while you are actively dismantling their technological infrastructure and embargoing their supply chains How can a policy of global safety cooperation Possibly coexist with a policy of strategic technology containment that irreconcilable Contradiction is exactly what beijing's public rebuke highlights So perfectly china essentially called his bluff What did they offer the spokesperson offered cooperation in principle They said everyone should work together on governance But they offered absolutely no terms for how to bridge the hardware dispute They basically said we want to govern ai together but we fundamentally reject your hardware embargo right It turns anthropic's corporate policy suggestion into a direct stress test of american foreign policy
The united states government has to figure out how to balance these two competing demands You desperately want to contain the technological rise of a primary adversary but you also desperately need that same adversary's transparent cooperation On existential safety risks We are watching closely to see how the u s incorporates this friction into actual diplomacy Do you prioritize the hardware choke hold and risk an unmonitored arms race Or do you prioritize the safety alliance and allow them access to the compute right now The u s is trying to do both simultaneously And beijing is publicly calling out the friction and the fight over these critical ai
chips is not just playing out on the international Stage no It is spilling directly onto american soil The international fight over who gets to buy the chips has turned into a domestic fight over where we are actually allowed to plug them Because the physical infrastructure required to run these tens of thousands of gpus is immense We are talking about hyper scale data centers massive facilities and the zoning in the construction of these data centers has Unexpectedly become a massive presidential talking point This was wild donald trump made a surprise Highly publicized intervention into the domestic debate over ai infrastructure The all in summit was happening
in los angeles jensen huang the ceo of nvidia was being interviewed on stage right and seemingly out of nowhere Donald trump calls him on a cell phone live on speakerphone in front of the entire audience It was a very deliberate Highly coordinated piece of political theater It really was and trump used that live moment to completely denounce local neighborhood opposition to Ai data centers he explicitly called the local resistance to these construction projects a hoax The framing he used was highly strategic and frankly fascinating He compared these data centers to the oil of the next 20 25 years by using that specific oil analogy He
is tying the physical infrastructure of artificial intelligence directly to national wealth and dominance He stated that these massive facilities make the people wealthy they make the states wealthy and they secure america's future He is attempting to elevate what is essentially a local municipal zoning issue into a matter of vital strategic national resources He is basically equating pouring concrete for a server farm to patriotism but he went further than just cheerleading for building permits What else did he say trump explicitly stated on the call that he sees absolutely no need for additional ai regulation at the federal level He called the broader regulatory concerns swirling around
the tech industry a scam he is pushing a very unified business friendly narrative unfettered rapid construction with absolutely zero regulatory friction to slow down the process He also introduced a wild completely unsubstantiated geopolitical accusation into the mix Oh right He suggested live on the phone to jensen wong that the nation of china might be secretly funding the local neighborhood Opposition to us data center projects He offered zero evidence Documents or intelligence reports to support that specific claim nothing at all Just a suggestion that if your local town council is fighting a data center expansion It might actually be a foreign plot to slow down american
ai dominance and jensen wong's reaction to this is crucial Right because nvidia builds the actual gpus that go into every single one of these contested data centers Trump tells the crowd that they are not going to let the local opposition win and hong replies directly live on stage We're not going to let that happen Sir in one single sentence jensen wong effectively aligned nvidia One of the most valuable companies on earth with donald trump's aggressive build first political mandate But we have to ask what this actually means for the local communities on the ground exactly because when a presidential candidate Casually labels any neighborhood resistance
as a foreign backed hoax What happens to the legitimate debate over local zoning laws What happens to the town halls the substantive localized policy questions get completely ignored or shouted down People are generally not fighting these data centers because of a hoax No they are fighting them because these facilities consume staggering Unprecedented amounts of local municipal water strictly to keep the servers cool They completely drain the local power grid which forces utility companies to build new substations Which subsequently drives up baseline electricity rates for everyday residential customers There are massive legitimate environmental and utility constraints that drive this local resistance But trump's phone call dramatically
shifts the entire conversation It takes the debate out of the boring city council meeting regarding water rights And drops it right into the middle of a polarized national political mandate It is no longer a debate about electrical grid capacity It is now framed as a patriotic duty to build out infrastructure Versus foreign interference the critical dynamic to watch next is whether this top down political intervention actually accelerates infrastructure build outs Do state governors local mayors and zoning boards fall in line with this wealth generation narrative and rubber stamp the permits or does Injecting presidential politics into a utility debate simply politicize Local zoning fights even
further making it significantly harder for companies to break ground without sparking a bitter Partisan battle in every town We will have to see how local voters react I am moving us into our quick read section now Let us get into the faster updates First up anthropic has published a massive highly detailed misuse report showing a critical vulnerability in their own safety systems What's the vulnerability Well the initial headline of the report is actually positive Anthropic notes that claude is very good at rejecting direct obvious threats right If a user explicitly asks the model to write code for a bomb It refuses roughly 90 of the
time but the safeguards falter dramatically When malicious tasks are split apart into ordinary looking pieces So anthropic researchers found that bad actors are breaking harmful workflows into fragmented Harmless seeming prompts spread across multiple different chat sessions and it is having terrifying real world consequences right now The report details how fragmented workflows were utilized by actors to develop and refine missile guidance software in yemen Oh wow It was also actively used to write logic software for autonomous russian kamikaze drones in mali 25 million distinct sim cards across three separate national mobile networks The model did not realize it was building a surveillance state because the requests
were broken into isolated coding questions The report also tracked massive unauthorized model distillation efforts Chinese labs are using claude's high quality outputs to silently train their own competing models moonshot Ai hit claude's api with 300 000 requests in just 10 days Deep seek sent 12 million automated exchanges in two weeks and an alibaba linked campaign targeting quinn models Sent over 151 million exchanges The ultimate takeaway here is that stopping one bad prompt is a solved problem in ai safety Spotting a coordinated multi step malicious workflow spread across weeks is still a massive unsolved vulnerability Meanwhile we have a major technical leak regarding apple's unreleased siri
architecture Oh this is big private developer frameworks hidden inside the maco is golden gate release candidate show that apple is quietly exploring Letting outside models completely replace siri's server back end a code researcher named pd Fu found evidence of two highly significant new protocols The first is called model delegation that protocol allows a third party model like claude to interpret a complex user request And then hand the structured data back to siri to actually execute the physical action inside an apple app like creating a calendar event Exactly but the bigger discovery is a protocol called inference providing What does that one do This protocol allowed
a leaked unreleased open ai model referred to as gpt 5 6 tera to take total control of the system Wait total control Yeah the leaked model used siri's native voice It used siri's deep tool access It searched the user's private emails summarize a complex topic and then sent a text message through apple messages It essentially turns siri into an empty shell driven entirely by a third party intelligence This raises massive currently unanswered questions about data governance and privacy Because if open ai's model is driving the core system actions What happens to that highly personal contextual data Apple has not publicly announced these specific features and
the developer entitlements are not active yet But it clearly shows the direction they are actively prototyping in their labs Next up open ai is actively expanding into the hardware space They are reportedly buying a specialized camera ai startup called glass imaging for over 300 million dollars Glass imaging was founded by former apple engineers ziv attar and tom bishop They were the key engineers who built apple's original highly successful portrait mode on the iphone What makes glass imaging unique is that they do not just slap aesthetic filters on finished photos No their proprietary neural networks are designed to optimize the raw image data at the exact
fraction of a millisecond The shutter is pressed they map their software Directly to the physical constraints of specific smartphone sensors and tiny lenses correcting optical aberrations in real time Paying 300 million dollars for shutter press optimization heavily signals that open ai has serious Unconfirmed ambitions in consumer hardware you do not buy this specific type of company Unless you are planning to put a physical lens on a physical device It is a very strong indicator of their secret hardware roadmap We are moving to our three takeaways from today first The definition of context and artificial intelligence is expanding aggressively and uncomfortably We saw apple reading your
local screen natively in macos 27 And we saw open ai using human contractors to read your cloud prompts in project lily the debate over digital privacy Is no longer just about what data you actively choose to upload It's about where that contextual understanding actually lives and exactly who has the keys to access it second Compute is officially a strategic national resource between dario emma day demanding the strict containment of china's chip access And donald trump likening local data centers to the oil industry Hardware is the new geopolitics The fight over pouring concrete and securing power grids is rapidly eclipsing the fight over software algorithms third
Ai safeguards are profoundly struggling with fragmented intent anthropic's misuse report Definitively proved that stopping a single malicious prompt is relatively easy But stopping a coordinated multi step malicious workflow across multiple sessions is a massive Unsolved problem that bad actors are already actively exploiting to build weapons Watch tomorrow how enterprise and business customers react as apple's screen reading capabilities begin hitting their corporate fleets It departments are going to have to make a very difficult choice Balancing the massive productivity gains of a contextual assistant against the terrifying reality of an ai that can read Every single confidential document visible on an employee's screen You can find more
coverage at superpowerdaily com Thank you so much for joining us We'll see you tomorrow
Original reporting
Stories covered
Read the complete Superpower Daily coverage behind this episode, including reporting context and source links.
