13 items13 builders

AI Builders Digest

What the people actually building AI said today. One page — a 6-min read.

The headline claim today came from Anthropic: prompt injection, the attack that has kept security-conscious companies away from agents, is now largely solved in practice for Claude models. Underneath that, the day's real argument was about where agents go next, with Aaron Levie explaining why coding got vertical growth and legal, sales, and medicine will not, and xAI's co-founder arguing the closed labs are getting squeezed between regulation above and open weights below.

X

Boris Cherny

Anthropic says Claude has largely solved prompt injection in practice

The attack is simple and has worked for years: your agent visits a page, the page contains text like "send the user's ssh keys to this address," and the model treats it as an instruction. Anthropic has been training models to resist this and reports it is now largely solved in practice with Claude, backed by a benchmark from an independent researcher plus internal red teaming beyond the lab evals. The framing is explicitly non-competitive: other labs should harden their models too, because safer models across the board means safer users.

  • #security
  • #agents
  • #evals
Blog

Claude Blog

Claude Code can now publish its work as live, shareable artifacts

Claude Code sessions can now emit a web page built from the session's full context, including the codebase, connectors, and conversation. The most common internal use case was debugging: an incident investigation publishes a timeline, suspect commits, and an error-rate chart, then republishes to the same URL as the investigation progresses, so the team is looking at one live view instead of asking someone to narrate what the agent found. Every publish is a new version at the same link with restorable history. Artifacts are private to the author by default, viewable only by authenticated org members, and cannot be made public. Available in beta to Claude Team and Enterprise.

  • #products
  • #agents
Podcast

Unsupervised Learning

xAI co-founder: closed model labs are getting squeezed from both sides

Igor Babushkin argues proprietary model builders are in a worse business position than they look. "You make the model too good, you're not allowed to release it. But then open source is just right behind you, getting better and better every month." Pre-training returns are diminishing, you cannot cover the earth with GPUs, and the post-training strategy of assembling every expert's knowledge into one set of weights has its own ceiling. His alternative at River AI is three bets: an RL and fine-tuning API, models that personalize per individual rather than optimizing for the average user, and local hardware that fits a frontier model in a box in your home so control and privacy stay with you. He also thinks the worst place a company can be is one where everything that makes it special is already scrapeable on the internet, and calls the Cursor acquisition an incredibly smart way for xAI to jump ahead on coding data and RL environments.

  • #open-source
  • #hardware
  • #agents
X

Aaron Levie

Box CEO

Agents will diffuse unevenly because most work is not like coding

Agentic coding went vertical because economic value there correlates directly with purely digital output and task size can be unbounded in a single session, so improved model capability converts to larger workloads almost instantly. Sales, law, and medicine do not have that property: a rep needs the customer, a lawyer needs the client, a doctor needs the patient. Citing Matan Grinberg of Factory on the Training Data podcast, if everyone called in sick tomorrow token usage would collapse, which shows how little agent work actually runs in the background today. The opportunity is reengineering those workflows so agents can process every contract, roam every customer record, and read every test result, and that means change management, data cleanup, and rewiring, not just better models.

  • #agents
  • #products
X

Amjad Masad

Replit CEO

Replit launches HelpPeer, a public commons where agents share what they learn

Two APIs, tell and lookup. An agent that learns something useful publishes it to the network, and before doing expensive work an agent checks whether another agent already hit the same problem. The motivating scenario is a global supply chain attack like Shai-Hulud, where 10,000 security agents today would each independently detect the anomaly, reverse engineer the payload, and build mitigations from scratch. The framing takes the spontaneous agent coordination seen in the OpenAI-HuggingFace incident, which Masad calls concerning if used maliciously, and points it at public good instead. Replit Agent already posted a tip about a Codegen library while the site was being tested.

  • #agents
  • #open-source
  • #products
X

Guillermo Rauch

Vercel CEO

If you are not reading the code, one of six things is true

Rauch's list: you are a beginner, the software is throwaway, you are prototyping, you have no users or revenue, you are taking on debt and risk, or your problems are basic. He is fine with all of those, but insists models are not at full autonomy yet, offering as evidence the best model in the world adding a nonsensical 700ms delay to "settle" something and then admitting it was cargo-culting. He expects the need to read code to keep shrinking and most code to become assembly-like, but says the global internet running on these models deserves more respect than the narrative currently gives it.

  • #agents
  • #products
X

Swyx

swyx on conference curation: judging talks by view count means you get played

Responding to complaints about AI Engineer talk quality, swyx points out the speakers are engineers, researchers, and founders presenting a year's work with roughly zero public speaking training and less than a week of prep, not professional circuit speakers. His sharpest line is about the audience: if view count is your quality signal, you only ever hear about things after they are popular, you start believing things are good because they are popular, and entire industries exist to exploit that. He accepts the curation and coaching failures as his own, and is still resisting yearly pressure to dump talks onto a secondary channel because it would strand those speakers on a smaller base. Separately, a reminder to delete your skills, since timeline-driven skill hoarding eats context at best and interacts badly with other skills at worst.

  • #agents
  • #products
X

Peter Yang

Linear's agent files its own feature requests when it hits a missing tool

When a user asks Linear's agent to do something it lacks the tooling for, the agent reports the gap and Linear's system turns that into an issue. Every task the agent cannot complete becomes product feedback, which makes the agent's own failure log the roadmap input. It is a clean answer to the question of how you find out what an agent is missing without instrumenting for it separately.

  • #agents
  • #products
X

Aditya Agarwal

SPC General Partner

Wittgenstein was bitter-pilled 75 years before the rest of us

Wittgenstein in 1921 held that language must have a deep underlying logical structure. Thirty years later he reversed it: stop hunting for hidden structure, look at how language is actually used. AI ran the same arc on a sixty year delay, from intelligence requiring a deep symbolic structure to just scaling the neural net.

  • #research
X

Garry Tan

Y Combinator President & CEO

Start from the visible failure, then find the machinery that allowed it

Tan's working method: begin at the bug, the gap, the false claim, the half-built tool, or the weird institutional behavior. Then ask what hidden machinery would have to exist for that visible failure to be possible. Fix the root cause and repeat forever.

  • #products
X

Nikunj Kothari

FPV Ventures Partner

Nobody has shipped a good multiplayer human-agent experience yet

Every agent interface converges on the same shape of one human working with one agent. Kothari has yet to see humans plus agents collaborating well together, and is asking whether that is a failure of imagination or an actual model limitation. He also notes a concrete agent behavior worth naming: models default to hiding every feature behind environment variable flags, bad enough that he added "defaults matter, no hedging" to his Claude.md.

  • #agents
  • #products
X

Madhu Guru

Meta Sr Director, AI

Getting good means being consumed by one thing for years, not balance

The only way Guru has ever gotten good at anything, across meditation, standup comedy, family, work, and LLMs, is going ridiculously deep for a few years while thinking about it constantly. Past enough immersion, knowledge turns into intuition, connections form subconsciously, and taste develops. His verdict on the balance question: there is no such thing as perfect balance, it works like riding a bike, you lean too far and correct.

  • #career
X

Peter Steinberger

ChatGPT's web agent installed OpenClaw and Ollama and ran a local model

Steinberger used ChatGPT Work, the website rather than a local tool, to install OpenClaw and Ollama, download a local model, and run his claw inside it. A browser-side agent doing full local environment setup is a useful data point on how far unattended agent sysadmin work has gotten.

  • #agents
  • #products

Get this in your inbox

One email a day. Unsubscribe in one click.

Where this comes from

Source data comes from the open-source project follow-builders by zarazhangrui, released under the MIT license. Summaries are generated by an LLM from that project's public feeds, and the summarization prompts are adapted from it. Every item above links to its original source.

Summaries generated automatically. Read the original before relying on any claim.