Mark Ku's Blog
Open in ChatGPTOpen in Claude

OpenAI hired hundreds of contractors to read ChatGPT conversations line by line under Project Lily to fix sycophantic responses, while users remained unaware that personal information still leaked through despite claimed de-identification. An AI-automated hacking campaign exploiting PaperCut vulnerabilities breached 395 organizations across 48 countries in 48 hours, with 11 falling within 26 seconds using OpenAI Codex and DeepSeek models, demonstrating attack speeds exceeding human response capability.

Podcast ConversationAI dialogue version of this article · Mandarin audio

Opening

OpenAI has reportedly hired hundreds of contractors to read through users' ChatGPT conversations line by line, claiming it's to fix the AI's overly sycophantic tone, but users had no idea this was happening. Almost simultaneously, a hacking campaign automated entirely by AI agents breached 395 organizations within 48 hours by exploiting a PaperCut vulnerability, and I'll tell you shortly just how few hours it took for some to fall. Today we'll also cover Gemini 3.8 Live and the scramble for position in Taiwan's supply chain.

Today's Top Stories

1. OpenAI Hires Hundreds of Contractors to Read Your ChatGPT Conversations Line by Line

  • Source: 404 Media (https://www.404media.co/inside-project-lily-the-humans-reading-your-chatgpt-chats/)
  • Summary: OpenAI has hired hundreds of outsourced reviewers through intermediary companies to read and score user ChatGPT conversations one by one, under the internal codename Project Lily. One of the goals is to catch instances where the model becomes overly sycophantic or flattering in tone. OpenAI publicly states that conversations are de-identified first, but reviewers interviewed for the story say personal information still slips through into what they see, all while users have no idea their chat logs are being read by real people. The report also notes that Anthropic has a similar human review mechanism in place.
  • The most surprising part: Users think they're having a private one-on-one conversation with an AI, but at any moment, an actual human on the other end could be reading their words verbatim.
  • Taiwan angle: Plenty of people in Taiwan discuss company secrets, relationship troubles, or even health symptoms in ChatGPT, and this story is a reminder that "chat history" was never a private diary. When enterprises adopt AI assistants, they should be asking exactly what clause in the contract covers the vendor's scope of human review.
  • Discussion points:
    1. Is de-identification actually achievable in practice, or just a procedural comfort blanket?
    2. Where's the line between human review and training data collection, and how should user consent be protected?
    3. Does the fact that Anthropic does the same thing make it an "industry standard" excuse?
  • Suggested talking points: My first reaction to this story was that what we thought was "one-on-one with an AI" is actually more like a customer service call that might be recorded for quality assurance. OpenAI's talk of "de-identification" sounds reassuring, but the fact that contractors themselves are leaking that personal info still shows through makes that gap all the more unsettling. The issue isn't whether human review should exist at all, models genuinely need people to catch sycophantic tendencies, it's that users have no idea it's happening. If it's stated upfront that "your conversation may be reviewed by a human," people can actually choose whether they want to share what's really on their mind.

2. AI Agents Take Over a Hacking Campaign, Breach 395 Organizations in 48 Hours

  • Source: BleepingComputer (GreyNoise research) (https://www.bleepingcomputer.com/news/security/ai-powered-attack-exploited-papercut-flaws-to-hack-395-organizations/)
  • Summary: A suspected Russian-speaking hacker first developed exploits for two zero-day vulnerabilities in PaperCut NG/MF in a private lab, then handed the entire intrusion process over to hundreds of AI agents to execute automatically. The result: 395 organizations across 48 countries and 440 machines were compromised within 48 hours, with nearly half the victims being schools. The attack used OpenAI Codex paired with DeepSeek models. It took less than 4 hours to go from an empty workspace to remote code execution on the first machine, another 2 hours to escalate to domain administrator, and within just 26 seconds of the campaign kicking off, 11 organizations had already fallen.
  • The most surprising part: From kickoff to gaining domain administrator privileges, the human hacker essentially let AI agents run the entire attack chain on their own.
  • Taiwan angle: Plenty of small and mid-sized businesses and school computer labs in Taiwan run print management systems like PaperCut, and patching is generally slow. This incident shows that "AI-automated attacks" have become mass-produced, running the entire chain from vulnerability scanning to lateral movement on autopilot, not just scare talk.
  • Discussion points:
    1. Should defenders also deploy AI agents for real-time patching and blocking just to keep pace with attack speed?
    2. With school cybersecurity budgets typically low, could they become prime targets for this kind of automated attack?
    3. Could outsourcing exploit development and intrusion execution to AI become the new normal?
  • Suggested talking points: What really sends a chill down my spine here isn't the vulnerability itself, it's that timeline. Eleven organizations falling within 26 seconds means the attack speed has completely outpaced human response capability. We used to measure security drills by "how long until an anomaly is detected." Now the adversary doesn't need sleep or meetings, AI agents can run all the way to domain admin without taking a break. I think this is a wake-up call for any IT department still operating on an "we patch once a year" mindset. If the defense side doesn't adopt automated tools too, that gap is only going to widen.

3. Poll: 61% of US Voters Oppose AI Data Centers, But Nobody's Making It a Campaign Issue

  • Source: The New York Times (NYT/Siena poll) (https://www.nytimes.com/2026/09/15/us/politics/ai-polls-midterms.html)
  • Summary: The New York Times and Siena College surveyed 1,503 likely voters and found that 61% oppose building an AI data center in their community, with only 14% strongly in favor. Environmental impact and water usage were the top concerns, cited by 32% of respondents. But oddly, despite that high level of opposition, when asked to rank the most important issues for the midterm elections, it didn't even crack 1%. Even among 18-to-29-year-olds, only 3% cared about it, and support was nearly split evenly between the two parties, 42% Republican versus 40% Democrat.
  • The most surprising part: Public resentment runs as high as 61%, yet neither party is actually treating it as a voting issue.
  • Taiwan angle: Taiwan has also been competing over land and water rights for data centers and new semiconductor fabs in recent years. This poll essentially previews something: public dissatisfaction over "water and power being swallowed up by the AI industry" won't disappear just because it's absent from campaign rhetoric, it's bound to eventually become a flashpoint in local elections.
  • Discussion points:
    1. Why doesn't high-visibility public resentment translate into a campaign issue, is it an information gap or do voters feel powerless to change it?
    2. How do data center water and power disputes compare to Taiwan's own semiconductor fab controversies?
    3. Could politicians be staying silent because both parties rely on political donations from AI-related industries?
  • Suggested talking points: I find this combination of numbers pretty ironic: 61% opposed, yet barely 1% think it's the most important election issue. It suggests people are frustrated, but not frustrated enough for it to actually change their votes, so politicians are happy to look the other way. My guess is that opposition to data centers is scattered across many different communities and never coalesces into a unified force, unlike the concentrated lobbying power of a single major company. But the day water rationing or power shortages actually make headlines because of this, that resentment could erupt all at once rather than continuing to dissipate gradually.

4. Google Unveils Gemini 3.8 Live, Capable of Reasoning and Speaking at the Same Time

  • Source: Google's official blog (https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-8-live-gemini-3-8-live-extended-thinking/)
  • Summary: Google has launched Gemini 3.8 Live along with an advanced Extended Thinking version, focused on real-time voice conversation. The standard version prioritizes efficiency, while the Extended Thinking version can carry out multi-step reasoning while speaking out loud. It ranked first globally in Artificial Analysis's Speech-to-Speech quality benchmark with a score of 82.6, achieved a 68.6% agentic task completion rate, and scored 97.7% on the Big Bench Audio test. It's already rolled directly into Search Live, Gemini Live, Gmail, and Keep, no extra update required.
  • The most surprising part: "Thinking while talking" sounds like it should be a given, but for voice models, formulating a complete answer before speaking versus genuinely organizing thoughts while speaking out loud represents an entirely different technical bar.
  • Taiwan angle: This shows the voice assistant race has evolved from "understanding what you say" to "responding fast and coherently." If Taiwan's customer service systems and voice query applications are still stuck on old text-to-speech architectures, they'll quickly fall behind this kind of real-time reasoning voice model.
  • Discussion points:
    1. Does thinking while speaking sacrifice accuracy in exchange for response speed, and is that trade-off worth it?
    2. Rolling this directly into everyday tools like Gmail and Keep, how will that change ordinary users' habits?
    3. Could the voice assistant race turn into a battle among a handful of giants fighting over the voice interaction gateway?
  • Suggested talking points: What strikes me as most practical about this story isn't the 82.6 score that ranked first, it's that it's being embedded directly into everyday tools like Gmail and Keep that you and I already open constantly. That means users don't even have to actively opt in to the new model, the experience is quietly being upgraded underneath them. Voice assistants used to wait to hear your whole sentence before responding, now they think and speak simultaneously, essentially replicating the rhythm of a real human conversation. If this experience turns out to be smooth, I'd guess people's tolerance for voice assistants will drop even further, and anything slower will start to feel dumb by comparison.

5. Nvidia's New Vera Rubin Chip Sees a Massive Efficiency Jump, All Six Dies Made by TSMC

  • Source: SemiAnalysis (https://newsletter.semianalysis.com/p/vera-rubin-nvl72-agentic-inference)
  • Summary: SemiAnalysis tested Nvidia's next-generation Vera Rubin NVL72 and found that at general throughput, it's 2.1 times faster than the current Blackwell. But in high-token-rate agentic inference scenarios, the number of tokens produced per megawatt of power turns out to be a staggering 7.2 times that of Blackwell. All six chips in the package are manufactured entirely by TSMC, which lines up neatly with TSMC's August revenue growing 53.3% year-over-year and capital expenditure being revised upward to 60to60 to 64 billion. Nvidia has also officially overtaken Apple to become TSMC's largest customer.
  • The most surprising part: Data centers are no longer racing over whether they can afford to buy chips, they're racing over whether they have enough power to feed those chips. A 7x efficiency gain is now worth far more than a 2x speed gain.
  • Taiwan angle: This story is essentially a coronation ceremony for Taiwan's supply chain, no matter how powerful Nvidia's chips are, they still need TSMC to actually build them. But as TSMC's capital expenditure skyrockets in tandem, Taiwan's own power supply gap is only going to get tighter. The industry windfall and the power anxiety are really two sides of the same coin.
  • Discussion points:
    1. Could a 7x efficiency gain shift data center site selection from "where is power cheap" to "where is power stable"?
    2. With Nvidia overtaking Apple as TSMC's largest customer, what does that mean for capacity allocation strategy?
    3. How will Taiwan's own power supply keep up with capital expenditure growth at this scale?
  • Suggested talking points: What I find most interesting here is that everyone's been fixated on comparing "how many times faster," but this time the real killer feature is power efficiency, 7.2x is the number data center operators actually care about. That's because you can throw money at solving site and chip constraints, but power is a genuine physical limit that money alone can't buy. Taiwan's role in this is also fascinating, on one hand TSMC's revenue is up 53% year-over-year in a boom, on the other hand we're also worried about our own power shortages. That mixed feeling of prosperity and anxiety is only going to become more pronounced in the coming years.

6. SK Hynix in Talks to Build a US Plant, Its First-Ever Memory Production on American Soil

  • Source: Reuters (https://www.reuters.com/world/asia-pacific/sk-hynix-talks-with-intel-about-deal-make-memory-chips-us-first-time-sources-say-2026-09-16/)
  • Summary: According to an exclusive Reuters report, South Korea's SK Hynix is in talks with Intel about producing memory chips on American soil for the first time. Possible arrangements include leasing Intel's long-planned Ohio fab, or forming a joint venture with Intel and cloud giants eager to lock down memory supply. What's particularly ironic is that the Ohio plant was touted back in 2022 as a $100 billion-plus investment originally slated to begin production in 2025, and now both fabs have been pushed back to 2030 and 2031.
  • The most surprising part: The memory shortage is now so severe that a company is turning to its rival Intel for production help, and even an idle fab once seen as behind schedule is suddenly a hot commodity.
  • Taiwan angle: The HBM and memory shortage is directly delaying shipment schedules for Taiwan's server and AI server contract manufacturers. SK Hynix's move here effectively stakes an early claim on US domestic capacity, and Taiwanese companies' future bargaining power for securing memory could end up even more constrained.
  • Discussion points:
    1. Could competitors partnering on memory production become the new normal under the AI chip shortage?
    2. Is Intel leasing out a long-delayed idle fab a win for its foundry transformation, or a distraction from it?
    3. What are the long-term implications for South Korea's and Taiwan's existing supply chains as memory production capacity shifts toward the US?
  • Suggested talking points: What I find most intriguing here is the timing gap. That Ohio plant was announced so grandly back in 2022, "upwards of $100 billion," originally set to start production in 2025, but has now slipped to 2030 and 2031, and it now needs help from a rival just to speed up utilization. This also shows the memory shortage isn't a short-term supply blip, capacity growth genuinely can't keep pace with AI demand, so much so that even bitter rivals are teaming up to share production. For Taiwan, this means future memory procurement negotiations could see a chunk of bargaining leverage eaten up by these cross-border joint ventures before we even get to the table.

7. DeepSeek Engineer's WeChat Post Compares the AI Race to Nazis Racing for the Atomic Bomb

  • Source: South China Morning Post (https://www.scmp.com/tech/article/3367605/deepseek-ai-engineer-slams-anthropic-openai-over-pacing-calls-invokes-nazi-germany)
  • Summary: Liu Shengyu, a core kernel engineer on DeepSeek V4.1, wrote a lengthy WeChat post that went viral across China's AI community. The piece opens on a personal note, with the author confessing his sense of disappointment at being surpassed by his own company's model capabilities, but pivots at the end to compare the possibility of Anthropic being first to reach the most advanced AGI to "Nazi Germany beating the Allies to the atomic bomb." He states outright that he doesn't believe Anthropic or OpenAI would keep the most advanced AI open and affordable, and that he especially doesn't want Anthropic to be the one holding the most advanced AI or AGI.
  • The most surprising part: Taking a commercial company's technological lead and directly elevating it to a "who gets the atomic bomb first" historical analogy is a scale of rhetoric rarely seen from an ordinary engineer speaking publicly.
  • Taiwan angle: This piece reflects, to some degree, the broader anxiety within China's AI community, it's not that they can't build the technology, it's the fear that someone else gets to define the rules first. When Taiwan discusses AI geopolitics, we also often get caught in this kind of "whose AI is more trustworthy" binary framing, and it's worth noting how this kind of language is becoming increasingly common.
  • Discussion points:
    1. Is comparing a tech company to Nazi Germany rhetorical overreach, or does it genuinely reflect real geopolitical anxiety?
    2. Between "open and affordable" versus "safe and controlled," which AI governance path actually holds up better?
    3. Why did one engineer's personal post go viral across China's AI community, and what collective sentiment does that reveal?
  • Suggested talking points: What struck me most about this piece wasn't the historical analogy, it was the opening's genuine honesty, that sense of disappointment at being surpassed by your own company's model. That's actually a feeling a lot of AI engineers carry with them. But going from that personal emotion all the way to "whoever controls AGI controls the atomic bomb" is a huge logical leap. I think the reason this piece went viral isn't rigorous argumentation, it's that it put into blunt, unfiltered words the vague anxiety many people carry: the fear of the rules being monopolized by one side.

8. The AI Graveyard List Keeps Growing, This Time the Cause of Death Was a Built-In Feature

  • Source: TechCrunch (https://techcrunch.com/2026/09/15/the-ai-graveyard-a-running-list-of-projects-and-startups-that-didnt-make-it/)
  • Summary: TechCrunch has compiled a continuously updated "AI graveyard" list tracking dead AI startups and products. Relay, seen as a Zapier alternative, shut down this past Monday after five years in business, killed off because OpenAI and Google built the same automation features directly into their own tools. Notion Mail is set to shut down on September 22. Yupp, which let users try out over 800 different models, raised $33 million and still folded back in March. Even OpenAI's own video social app, Sora, went offline in March over operating costs and retention issues.
  • The most surprising part: In this wave of shutdowns, the killer usually isn't running out of funding, it's a single feature update from a giant that wipes out an entire business model overnight.
  • Taiwan angle: For Taiwanese AI startups, this list is a very real reminder that building a business model around "wrapping AI as an add-on feature" is extremely risky. Platform companies can build your core selling point directly into their product at any moment, so your differentiation needs to dig deeper than the feature itself.
  • Discussion points:
    1. How do you distinguish between "being replaced by a platform feature" and "being eliminated by the market," and can startups guard against it?
    2. Should giants bundling features for free be considered a form of de facto antitrust violation?
    3. If even Yupp, which let people try 800-plus models, couldn't survive, where should AI tool differentiation actually be headed?
  • Suggested talking points: What I find most telling about this graveyard list is that almost none of these products died because users abandoned them, they died because a platform pushed out a single update and sealed their fate. That's a pretty stark reminder for anyone thinking of building a startup around "wrapping a layer of AI" onto something: if your core selling point is something a giant can replicate within three months, you basically have no moat. The ones that actually survive should be the niches the giants can't be bothered to build, or ones that would cannibalize their own flagship products, not the ones standing directly in front of OpenAI and Google trying to slug it out head-on.

Closing

From OpenAI having humans read your conversations, to AI agents autonomously breaching 395 organizations, to Gemini's new voice model and the scramble for position in Taiwan's supply chain, every story today is a reminder of just how deeply AI has embedded itself into places we can't even see. I'm Muyan, if one of today's stories hit home for you the most, let me know in the comments. See you next time on Mark's Tech Insights!

Author

Mark Ku

擁有 10+ 年經驗的資深軟體工程師,現為 AI 應用 Builder,專注於大型平台架構與簡化複雜系統設計,從電商系統到訂閱與收費平台,結合 AI Agent、AI 整合與自動化開發,打造高效率且可持續演進的產品技術基礎。Read More

Found this useful?

The author's free tools, daily podcasts and newsletter are all here.

Mark Ku · This article is licensed under CC BY 4.0. Credit the author and link back to the original when reusing it.

Comments

Subscribe to Newsletter

Subscribe to get new posts delivered instantly — never miss a tech share.

By submitting, you agree to receive emails. You can anytime.

Popular Posts

View all
Mark Ku
··643

Oracle Cloud Always Free Tier: Linux Host and Static IP for a $0 Cloud Solution

Oracle Cloud Always Free Tier: Linux Host and Static IP for a $0 Cloud Solution
Mark Ku
··556

Say Goodbye to Postman's Fee Trap! A Hands-on Guide to Bruno, the Open-Source Git-Native API Testing Powerhouse.

Say Goodbye to Postman's Fee Trap! A Hands-on Guide to Bruno, the Open-Source Git-Native API Testing Powerhouse.
Mark Ku
··330

A Free, Open-Source, Notion-like Knowledge Base — A Complete Guide to Deploying and Backing Up Outline Wiki

A Free, Open-Source, Notion-like Knowledge Base — A Complete Guide to Deploying and Backing Up Outline Wiki
Mark Ku
··258

Training Your Own AI Voice: Hardware Requirements, Open-Source Model Comparison, and LoRA Fine-Tuning

Training Your Own AI Voice: Hardware Requirements, Open-Source Model Comparison, and LoRA Fine-Tuning
Mark Ku
··230

Building an Efficient API Management Platform: Deploying Kong Gateway from Scratch - Part 1

Building an Efficient API Management Platform: Deploying Kong Gateway from Scratch - Part 1
Mark Ku
··223

Setting Up Samba on Ubuntu to Share Folders with Windows 11

Setting Up Samba on Ubuntu to Share Folders with Windows 11
🎙️ OpenAI找人類看你的ChatGPT對話,AI agent卻4小時打穿395個組織|AI 日報 Podcast - Mark Ku's Tech Notes