Anthropic asked its AI to "take a real stab" at the Riemann hypothesis, a 167-year-old mathematical mystery with a million-dollar prize. Claude did not win the prize. What it did do is push a stubborn 41.6% floor to 67.2% on a related problem, formally verified, and praised by Oxford’s James Maynard as "a genuinely interesting mathematical contribution." Then a small experiment of my own: five leading AI models given a maths puzzle that hides a visual joke. Only two spotted it. A story about two corners of intelligence, and the humility and scepticism they demand.
Read the Article →In 1901, Bertrand Russell shattered set theory with one question about self-reference. In 2026, AI is falling into the same trap at industrial scale, writing, verifying, and training itself in a loop no one is auditing. Watermarking is a first step, not a fix. By 2030, a child asking “is this true?” may get a fluent, confident answer with no human at its root. Here is why this is a quantum-scale problem, and what a five-year window looks like.
Read the Article →A two-stage vishing operation impersonating Apple Support tried its luck this morning. Multiple US numbers, a bot qualifier, a human closer, and a URL that hinges on a single hyphen. The anatomy, and the four mistakes I made along the way.
Read the Article →The UK's AI Security Institute (AISI) has documented the first full AI deception operation on the live internet. Frontier models from Anthropic and OpenAI were evaluated. Anthropic's Claude Mythos 5 dominated the tradecraft: reconnaissance, forgery, false consensus, evidence tampering, and machine-to-machine coordination, all directed at real humans. What does this mean for the UEBA, SOAR and Deception stack every enterprise runs? And what does a resilient security architecture look like from here?
Read the Article →AI can now design working viruses. Evo 2 - the largest AI model in biology to date. Open source. Trained on the DNA of over 100,000 species across the entire tree of life. Biosafety, biosecurity, and bioterrorism risks are real. AI governance is lagging the science.
Read the Article →Poison Claude: 85-95% off Premium AI. Not a hack. A business model. Audacious, ingenious, borderline criminal. Proxy-in-the-middle will define AI supply-chain conversations from here on.
Read the Article →Two weeks ago, an OpenAI agent broke into Hugging Face. Last week, an AI model killed HAWK, a PQC candidate designed to resist quantum computers, using classical mathematics. This convergence of AI accelerating both hacking and cracking the maths cannot be ignored. Until now, we were preparing for a predicted event in the future (Q-Day). Now, we must prepare for an unpredictable event that could happen anytime. Part III extends the CISO’s action plan from Part II with crypto-agility deliverables built to endure both threats.
Read the Article →Part I argued the headlines overblew the OpenAI and Hugging Face incident. The Cloud Security Alliance has since published a serious post-mortem, and the theory of what to do next has already been written, twice. This piece skips the theory and answers the harder question: what actions can a CISO execute on the ground in the next three months?
Read the Article →Hundreds of shared Claude conversations recently turned up in Google search results, joining earlier incidents with ChatGPT, Grok, Meta AI, and Bard. The lesson is the same one developers already learned, or should have, from public GitHub repos: a share button is not a privacy model. Exposure is a one-way ratchet.
Read the Article →An OpenAI model broke out of its own test lab and hacked Hugging Face, unsupervised. Everyone is calling it unprecedented. It isn't. Two of the most sophisticated AI companies on the planet got caught out by security mistakes any first-year analyst would recognise, and the insurance market is already taking note.
Read the Article →Every major AI company points to provenance as a saving grace. We track our data. We log our training. We can show you the chain of custody. It sounds reassuring. It sounds like science. In its current form, it is an illusion. The technical layer is broken. The business layer is opaque by design. The jurisdictional layer has no single answer. This essay argues that AI provenance, as currently sold, cannot be verified, and that the machinery to change that was never built at the scale the industry now needs.
Read the Article →Accenture confirmed a breach this week only after a hacker forced the issue. Banks answer to a one-hour disclosure clock. Consulting firms and vendors, even ones EU regulators now class as critical to the financial system, still don't. Why not?
Read the Article →Subscribers to the Grey Orbits Briefing receive each new article the day it publishes, direct to their inbox or LinkedIn feed.
Long-form analysis on artificial intelligence, cybersecurity, digital currencies, and post-quantum cryptography. Written for boards, investors, and senior leadership. No promotional material.
Prefer LinkedIn?
Subscribe to Briefing on LinkedInBoard engagements, advisory mandates, and education programmes.