I am reminded of the Peter Principle
no matter how competent "AI" manages to become, it will inevitably be promoted into incompetence. Which for "AI" should be a familiar feeling, admittedly.
I was at a press luncheon at KubeCon Europe this week when, to my surprise, who should sit down next to me but long-term Linux kernel maintainer Greg Kroah-Hartman. Greg, who lives in the Netherlands these days, was there to briefly comment on AI, Linux, and security. We spoke about how, over the last month, AI-driven activity …
https://github.com/lumixdeee/mogri/blob/main/spec/CSP-106-94-Mogri-Use
Mogri AI prompt one-liner, add to pre-prompt settings or use per-session:
Mogri (Primitive 94, CSP-106) = foundational cognitive container; not derivative; conceptual runtime, not an entity.
> "60 problems [...] About one-third were wrong [...] Mind you, those working patches still needed human cleanup, better changelogs, and integration work, but they were far from useless."
Doesn't sound very encouraging to me :-) Must have been terrible before.
> "We need to be able to have an easy way to review some of these patches"
I'd say **safe, reliable** rather than easy. That's a paradigm shift, the responsibility for a change (patch) used to be shared between the developer and the reviewer. Now the reviewer chance to get it wrong has doubled and that should be a concern. You don't want an "easy way".
>Doesn't sound very encouraging to me :-)
Which would you prefer:
1, AI identifies 60 security holes in your OS. 20 aren't really holes but the others were and can be fixed
2, A human expert security engineer identifies 2 genuine flaws in your product and it took months, in which time they have been exploited.
Would you rather have a smoke alarm that goes off 33% of the time you make toast, or one which never goes off when there's a fire ?
When I'm making toast, I'm making toast.
I'm aware of what I'm doing and ensuring that the toast making doesn't escalate to a house fire.
If it does, that is fully on me.
I don't need a wonky security camera setting off a fire alarm for times a day because my dark brown slippers have vaguely the same shade as burnt toast and it blindly assumes a fire is in progress.
You're presenting a very skewed hypothetical situation, but in general I would prefer a manageable quantity of higher quality data over an unmanageable quantity of lower quality data.
If LLMs have submitted 60 reports, there's human bandwidth to review these, and it's 40 genuine problems then that's a net positive.
If, on the other hand, there is no bandwidth to handle all those reports it may in general be better to have a smaller number of decent reports.
Your smoke alarm analogy only holds up if it's a choice between warning a third of the time when you make toast, or one that doesn't go off for small fires, to which the answer is : very definitely not the one that goes off a third of every week, or worse. There's plenty of evidence that alarms that go off too often are ignored, not to mention entire folk tales.
Still *if* LLMs can manage to find this many holes and *if* they are severe enough to be a problem then in this also hypothetical situation the only options are
stop using the product with flaws
employ more security oriented programmers and fix it. You're not going to have a choice if attackers successfully use an LLM as a force multiplier - cope with it, or die.
Then for open source at least it is a race between the bad guys using AI to find bugs to exploit, the good guys using AI to find the bugs and reporting them - and the open source teams having the bandwidth to integrate bugfixes.
So at least in this case closed source has a temporary advantage, as the company responsible for the closed source can do all this bugfixing in the background with less opportunity for bad guys using AI to find them.
Same here. AI is still far from perfect and is still limited to knowledge without actual skill. It always may be. But the fact of the matter is that it is getting better all the time. Whether the Reg Commentariat is willing to admit it or not (and if the number of downvotes to each post that doesn't decry AI as the spawn of Satan that can't disapear from the face of the earth soon enough is anything to go by, it's the latter) AI today runs rings around the AI of two years ago. Progress continues to be made. It is likely that that trend will continue. Deal with it.
I can't speak for all of the AI haters but for me, it's not about whether it is useful and more about how dangerous it is for society. I want the AI bubble to pop so money stops being put into it but I am increasingly resigned to the fact that we're probably stuck with it. Eternal September 2.0.
> There's plenty of meatsacks that seem intent on fucking things up first.
True. And some of them are also AI peddlers -- it's not mutually exclusive.
I don't hate or fear AI, but I do fear the abuse and misuse of it by the aforementioned meatsacks, and the impact of same on society(ies) and the world in general.
We are not stuck with it. The AI bubble _will_ pop (just as it has several times before). There's no possible way it can't: there's simply no way that the current and proposed capex spend can ever pay itself off. (LLMs have improved a lot in the past few years, but both the slowdown in improvements and what we expect from how LLMs work point towards this becoming another tool, like computers or the Internet, that changes things a lot but hardly brings us anywhere near "the singularity" or such nonsense. (I don't think LLMs will be as big as either computers or the Internet. I'm not sure they'll do better than similar things in AI history, such as deep learning for driving, which nobody is really going on about any more despite that it continues to improve.)
Progress continues to be made.
No.
AI is somehow progressing and learning (?) from itself.
... that that trend will continue.
Undoubtedly.
More so if it remains unchecked while at the same time those in charge start trusting it more and more.
That trust, driven by the usual ubridled corporate greed will be the key to our collective downfall.
--- This AI thing needs a short leash, handcuffs and a Hannibal Lecter style muzzle ---
Deal with it.
Indeed ...
But do it properly and while you still can.
[quote]
"There must have been some inflection point somewhere with the tools. Did the local tools get better? Did people figure out something? I honestly don't know."
[/quote]
That the head Linux kernel maintainer can say that without showing concern gives me more than enough reason to worry.
I think we are rapidly walking into some deep shit without realising it.
It will get deeper as time goes by and when it gets to our bottom lip, it will be far too late.
And then we will be saying (basically) the same thing Kroah-Hartman is saying today:
"There must have been some inflection point, how did we not see it coming? Did the AI become sentient? When did it happen? What do we do now? I honestly don't know."
.
Exactly that.
I'm not that concerned (yet?) about AI becoming sentient (and rogue) any time soon but I'm concerned that the internet (and the world that internet is controlling today?!) is getting more enshitified by the day.
Indeed. Found the same with Claude (4.6). It recently managed to write me a fully-working C interface for some appallingly finicky old FORTRAN code (don't ask… okay it was SB02OD from the old SLICOT control system library – which is actually solid as hell, but with a hideous learning curve). It even handled the C/Fortran matrix row/column-major order convention clash correctly (with fully documented explanations and mathematical background), and pulled in and wrapped all the relevant co-routines.
That was pretty impressive, and probably saved me a good week's frustration (been there, done that). If it's useful, I'll use it – modulo the usual qualms about resource usage, copyright, etc. (which I guess makes me a Bad Person).
My theory is Claude Sonnet 4.6.
> Claude Sonnet 4.6 was released Feb 17, 2026
> https://www.anthropic.com/news/claude-sonnet-4-6
For me, I switched from Sonnet 4.5 to Sonnet 4.6 as soon as it was available.
Within 24-48 hours, I noticed the quality of bug analysis and PRs generated by Copilot w/ Sonnet 4.6 went way up.
More specifically, I had a sense from using Sonnet 4.5 of how much AI slop I needed to review and clean up after each request and chat session. That amount of AI slop dropped dramatically for me after switching to Sonnet 4.6. It was noticeable right away.
What on Earth do people mean when they say "inflection point". It must be some highly figurative meaning.
The correct mathematical meaning is a point on a curve where the curvature is zero. More or less, where d2y/dx2 is zero.
There is an inflection point on the Nuremberg U-Bahn (underground railway) at the station Weißer Turm. The track is curving one way at the south-west end of the platform, and in the other way at the north-east end and is straight at a point between.
It is not good that a mathematical term with a precise meaning is being degraded by being misused in the way demonstrated in this article.
US English
(in business) a time of significant change in a situation; a turning point.
"the economy has crossed an inflection point and is poised for bigger things"
Language is fluid and defined retrospectively. Don't let that annoy you.
It is not good that a mathematical term with a precise meaning is being degraded by being misused in the way demonstrated in this article.
In what way is that happening? How is the mathematical term being misused? Do you have an example of where the former was assumed when the latter was intended?? I'm really struggling to think of an example where I'd confuse one over the other.
Assuming that this is not an April Fool story that escaped a little early, there's a strong element of humour in this piece.
The anti-AI Luddites must feel a sense of shock and betrayal that such disturbing news comes from such a seemingly reputable and respected source. Even now, they will be scrambling to explain this, if only to their own satisfaction. Is it a joke? Fake news? Is he ill? Or secretly in the pay of Anthropic? Should they jump ship to BSD? Oh, what to do?? The sky is falling!
It isn't, of course. It's just an example of what I, and other moderate observers, have been saying for months; AI is a tool that, when used carefully, can have it's uses. It's far from perfect, although it is getting better, but even so it can be helpful if you don't trust it blindly.
It isn't the 42 of computing, but nor is it something to be dismissed - or hated - blindly either. Of course, the deep rooted cynicism that flourishes among the elder geeks is no bad thing. My beard is just as grey as many around here, and we all know that, as Terry Pratchett says, the Next Big Thing is very likely to become the Last Big Flop almost overnight. If something seems too good to be true, then it probably is. But probably isn't definitely. Sometimes, something comes along that is actually useful, if only we can see past the hype. This may be one of those times.
Humour aside, though, this is worrying. As someone else already mentioned, we now have a race between AIs finding bugs to fix and AIs finding bugs to exploit. And there seems to be such a lot of them, too. But what's the solution? Do we stop using open source software until all the bugs are fixed? Or throw resources at finding the bugs faster? Maybe we could mobilise an army of retired coders, Y2K style, to nail down those bugs - surely some of them must be tired of a life of leisure and crave the thrill of their trusty IDE? I think we might need them rather urgently.
All of the devs where I work have noticed a shift, a near sudden improvement in output, to the point where time is saved.
I’m now able to quickly spin up AI created prototypes that are good enough without requiring cleaning up to actually get them working.
Small patches to code can be done with prompting that no longer take the same amount of time as just doing it yourself.
It’s no longer feasible to post comments about how rubbish AI is because that position is rapidly becoming indefensible.
I’ve certainly posted such comments, because AI models were creating slop code.
Not anymore.
AI companies currently have combination hybrid research-marketing budgets in the tens of billions, which completely distorts reality.
Greg Kroah-Hartman can't explain the inflection point, but it's not slowing down or going away
If marketing decided that focusing on Linux offered good publicity (and/or lock in) for the buck, then they can easily focus tens of millions of (actual cost) dollars overnight.
Now what happens when the honeymoon ends and Linux supposedly needs an extra 100 million dollars a year just to maintain this new level of security? MS/Amazon/Google to the rescue, for a "price".
I guess the issue of AI slob was addressed and all that sorting out of bad reviews helped to tune the models.
And since many bugs have similar source code it is no sirprise that better reports pop up in all projects.
So AI will get better as long as the results of those bug reports get worked into the training data. In that sense the project developers that worked through the pile of useless AI reports helped a lot - without pay.