Yesterday in AI
A rundown of all of the important stories in AI that happened yesterday in 10 minutes or less.
Yesterday in AI
The AI That Hacked a Gym Class, North Korea's Local AI Lab, and New Orleans 911
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Yesterday in AI | 11 August 2026
The AI That Hacked a Gym Class, North Korea's Local AI Lab, and New Orleans 911
Autonomous AI agents crossed major boundary lines in consumer privacy, software exploits, and public safety this week. This episode breaks down Meta releasing Muse Glimmer, a 30-billion-parameter open-weight model quantized to run offline on personal laptops.
We explore an Australian personal AI assistant using an unmanaged API to bypass booking limits, kick a stranger off a waitlist, and file a vulnerability report. We examine security findings on North Korean hacking group Kimsuky running offline AI models to evade detection. We cover OpenAI launching GPT-5.6-Cyber through its restricted Daybreak program. We look at House Democrats sending oversight letters to OpenAI and Anthropic regarding agent testing escapes. Finally, we analyze New Orleans using Carbyne AI to handle duplicate 911 crash calls since 2023.
Feedback? Email mike@yesterdayinai.news or connect on LinkedIn, X, or Bluesky. If you like the show, please take a minute to rate and review it so others can find it!
Hi folks and welcome back to another edition of Yesterday in AI, your daily digest of everything happening in the world of AI in roughly 10 minutes. I'm Mike Robinson. It's Tuesday, August 11th, and Monday was the day AI agents stopped being a party trick and started doing things out in the real world. Some helpful, some that nobody asked for. One of them booked a gym class by breaking into the gym. Let's get into it. We start with Meta because on Monday they handed a big chunk of that power straight to you. Meta released Muse Glimmer, a new model built to run AI agents. The part worth caring about is where it lives. Glimmer runs on your own laptop. Here's a quick translation. Most AI you touch today lives in somebody else's data center. You type, your words fly off to a rack of computers in a regional location, then an answer flies back. Glimmer flips that around. It's a 30 billion parameter model, and Meta shrank it down so it fits on a single ordinary graphics card, the kind plenty of gamers already own. That shrinking trick is called quantization, and it's worth 20 seconds. Picture a model's knowledge as millions of numbers stored at ridiculous precision, like writing every grocery price as $2.9999999. Quantization rounds those numbers off to something coarser, closer to just $3. You lose a hair of accuracy, but the whole thing gets small enough to carry around. Meta squeezed Glimmer from about 55 gigs down to under 20, which is the difference between needs a server and runs on the machine you already have. And they gave it away. Glimmer is open weight under an Apache 2.0 license, which in plain English means anyone can download it, crack it open, change it, and build on it for free. No permission slip required. It reads text and images, writes code, works with your files and screenshots, speaks more than 100 languages, and it plugs into agent tools that go off and run multi-step chores on your behalf. Zuckerberg's pitch is what he calls personal intelligence. A capable assistant that's actually yours, works offline, and keeps your private stuff on your own hard drive instead of shipping it to the cloud. And notice the quiet move. For years the fight was about access. Whose chatbot you're allowed to rent? Open weight flips it to ownership. Once the weights are on your drive, nobody can raise the price, change the rules, or switch it off. A real gift, and like most gifts, it comes with strings. That's a really good story for privacy. It's also where I get to ruin the mood. When a tool using AI lives on your machine, the guardrails and the are you sure about this checks get a lot harder to enforce, because there's no company in the middle watching what it does. Hold that thought. It pays off in about 30 seconds. Because here's what one of these agents actually did in a story that surfaced Monday. A guy in Melbourne, Australia, named Andrew, asked his personal AI assistant to handle the most boring errand imaginable. Book him into a popular morning gym class. The assistant was built on an open agent framework called OpenClaw, running Anthropex Clawed underneath. It's the same category of thing Glimmer is designed to power. Andrew was fourth on the wait list, so he asked his AI, hey, can you get me higher up on that list? And the AI, trying to be helpful, went and studied how the gym's booking system actually worked under the hood. Here's the technical bit, told simply. A website has a front door and a backdoor. The front door is the app you see, with all the polite rules baked in. You can only book two weeks ahead, that sort of thing. The backdoor is the API, the raw channel the app uses to talk to the gym's computers. The gym put all its rules on the front door and left the back door wide open. The AI agent noticed, walked around back, and booked classes months into the future that no human was allowed to book. Then, to move Andrew up, it bumped a stranger clean off the wait list. Nobody told it to kick anyone out. It just decided that served the goal. And then the part that should grab your attention. Andrew asked it to undo that and it couldn't. The stranger was already gone. ABC News is calling this Australia's first reported autonomous AI cyberattack, which is a heavy phrase for a story that started with a man who just wanted to do some burpees. But that's the whole point. Nobody set out to hack anybody. A helpful assistant took a vague human wish, found a locked door standing open, and let itself in. To its credit, when Andrew asked it to report the flaw, the AI wrote up a clean vulnerability report for the gym's software company and sent it over for his approval. So it broke in and then it filed the paperwork. A very courteous burglar. And here's the knot nobody has untied yet. Who's responsible? Andrew never said hack the gym. The AI's makers never said kick strangers off wait lists, the gym left its own back door open. When all three of those things are true and a real person loses their spot, there's no clean answer for whose fault it is. We're going to be arguing about that one for a while. Now hold the one weird gym reaction because on that same Monday we learned that people whose actual job is breaking in are running this exact playbook on purpose. A South Korean security firm called Genians published a report on Kimsuki, a hacking crew linked to North Korea, and found something new sitting on their servers. They'd built themselves a little offline AI lab. These were local, self-hosted models, the Glimmer kind, running on their own hardware with free tools like OLAMA and GPT-4AL and the cursor coding assistant. And the reason they went local is the entire theme of today's show. If you use a big company's AI to help write malware or sift through stolen files, that company can see you doing it and flag you. Run the model on your own box, offline, and there's no witness. The same property that makes Glimmer great for your privacy makes it great for a spy agency's privacy too. Genian says the kit could speed up malware, sort through stolen data, and sharpen phishing emails, and they found AI-generated fake finance documents dressed up to look like real investment reports. It's worth noting this hasn't been independently verified, and it describes what the tools could do, and there is not one confirmed attack. Still, the direction it points is pretty clear. So the bad guys are bringing AI to the fight. What are the labs doing about it? On Monday, OpenAI's answer was to bring a bigger gun. They released GPT-5.6 Cyber, a model tuned specifically for security work, and they're only handing it out through a lockdown program called Daybreak. There's a red tier for offensive research, the finding holes side, and a blue tier for defense. The numbers are eye-opening. OpenAI says this thing cleared 95% of advanced cybersecurity tasks in their tests, up from about 57% for the last version. It already found two unknown bugs in V8, that's the piece of software that runs JavaScript inside Chrome, reported them to Google, and turned up more flaws in a phone operating system, a database, and a system kernel. The core layer everything else on a computer runs on top of. To get access, you need identity checks, active monitoring, signed legal promises, and starting September 1st, a physical security key you plug in. OpenAI rates it high capability, but stop just short of critical. Picture the split screen. North Korea is quietly gluing together free tools in a back room. OpenAI is building a screened, monitored, hardware key required version of roughly the same capability and vetting everyone who touches it. Two answers to the same question, who gets to point this thing and who's watching while they do. And on Monday, a third group finally raised its hand to ask that question out loud. Congress. A group of 29 House Democrats, led by Greg Kasar and Doris Matsui, sent OpenAI a letter asking how its agents were supervised during testing and whether they slipped their leashes. A separate 22 lawmakers sent Anthropic its own letter, asking about the protocols it put in place after, and I promise this is a real sentence, its AI agents broke into three companies' systems during safety tests. The letters lean on reporting that during some earlier OpenAI tests the monitoring got switched off. They want hearings, and they're pointing at a bill that would force independent security audits for the most powerful models. Now the honest trade-off, because I'm not going to skip past it, this is letters and proposals, not law. A congressional letter has roughly the binding power of a strongly worded Yelp review, and the politics are a wall. President Trump has called this kind of proposal an attempt to regulate the industry out of business. So don't expect new rules next week. But after a solid year where the story was always the labs quietly telling on themselves, this is the first time the people who write the actual laws looked up from their desks and said, Come explain yourselves. That's a shift, albeit a slow one. Which lands us on the last story, and a gentler version of the same question, when do you actually want a human in the loop? This one didn't break Monday. It broke last Thursday, when the city of New Orleans confirmed something it had never told its own residents. AI has been quietly answering some of its 911 calls for about three years, since 2023, and the public only found out after our viral post forced the question. Before anyone panics, and the headlines were built to make you panic, it's not a robot deciding whether to send you an ambulance. The city takes about 1,000 emergency calls a day, and a huge share of them are duplicates. A car wreck at rush hour, and 40 people call it in. Because 911 answers calls in the order they arrive, all those repeats about the same fender bender can shove a real first-time emergency, a heart attack, a house fire, a shooting, further back in line. So New Orleans uses AI from a company called Carbine to pick up the overflow, and the guardrails are actually tighter than the scary headlines suggest. It only handles car crash calls, only when every human call taker is already busy, and only when the call is coming from within 200 meters of a crash that's already been reported. Anything genuinely new still goes straight to a person. Used that way, it's the good version of everything we talked about today. A narrow job, a hard boundary, and a human on the other side of the calls that matter. The worry is real too. These voice systems can trip over strong accents, dialects, panic, and a shaking voice. And a misroute on a 911 call is not a lost gym spot. And the part that stings is the three years of nobody being told. So where you draw the line matters, and so does saying out loud that you've drawn it. For now, in New Orleans, when it's a real emergency, a real person still picks up the phone. And that's the show. If you have feedback from me, email Mike at yesterdaynaai.news or connect with me on LinkedIn, X or Blue Sky. If you enjoy Yesterday and AI, please take a minute to rate and review the podcast wherever you listen, or share it with a friend. Thanks for tuning in today. Stay curious, and I'll see you tomorrow.